LONDON FASHION PHISHING
Summary
Flylondonnederlands.com is a fishing site that processes credit card transactions for fake goods.
The site is part of a complex set of sites that often share payment details.
What makes the site dangerous is:
We know payment processing works for credit cards.
It tried to open a paypal account
It returns as the second entry when searching in Google for Flylondon
It shares code with other ake sites like www.brooks-netherland.comÂ
Analysis
This site is part of a larger network of sites working together to defraud online shoppers.
It has been operating successfully for more than 3 months.
The site is successfully operating in the Dutch language.
It is indexed as no 3 under Google so it means people searching for the brand will be end up on this site.
The site has not been blacklisted by reputation providers (however WOT does give it a low trust rating)
It tries to take payment via Paypal and very nearly succeeded with me.
The payment processing layer is written in Java using Tomcat as a container server and Spring for dependency injection.