On the url (
http://www.fraudwatchinternational.c...8_citibank.htm ) there is a description of a citibank phishing scam.
It describes people receiving an email and to click the link
https://web.da-us.citibank.com/sigin...user_setup.jsp When they click this link, a valid citibank opens up as well as a popup that has the scam page.
Isn't
https://web.da-us.citibank.com/sigin...user_setup.jsp a valid citibank webpage, how did they get the popup to occur?