Donation/Premium
Fried Phish(TM)
Phishing Incident Reporting and Termination (PIRT) Squad(SM)
A global phishing termination and intelligence system operated by CastleCops.
Become a PIRT Squad terminator by reporting phish today!
[ How-To / FAQ ]
Fried Phish -> Confirmed Phish |
Terminated Phish
Select Report Range -------------------- 0-49 50-99 100-149 150-199 200-249 250-299 300-349 350-399 400-449 450-499 500-549 550-599 600-649 650-699 700-749 750-799 800-849 850-899 900-949 950-999
status: terminated HTTP Response 13 Jul, 2008 17:12:29 HTTP/1.1 200 OK
ID 883281 (termination link) Title Bank of America, Barclays, HSBC, Halifax, Lloyds TSB, eBay Entry PIRT Squad Reporter Submitted anonymously thru the web, or sent to pirt (at) castlecops (dot) com. Timestamp 01 Jul, 2008 @ 14:39:41 Topic ID 224565 - Read/respond to PIRT commentary.Handler Note: 03 Jul, 2008 18:01:35 downie : Consumed following related reports:
[876716]
http://57.204-78-194.adsl-fix.skynet.be/ws2/eBayISAPI.php?cmd=SignIn&co_partnerId=2&pUserId=&siteid=0&pa
geType=&pa1=&i1=&bshowgif=&UsingSSL=&ru=&pp=&pa2=&errmsg=&runameTYPE=eBay
[876718]
http://57.204-78-194.adsl-fix.skynet.be/ws2/eBayISAPI.php?cmd=SignIn&co_partnerId=2&pUserId=&siteid=0&pa
geType=&pa1=&i1=&bshowgif=&UsingSSL=&ru=&pp=&pa2=&errmsg=&runameMessage-Id:
[879974] http://57.204-78-194.adsl-fix.skynet.be/ws2/
[881615]
http://57.204-78-194.adsl-fix.skynet.be/bpol/bancoposta/CartePre/formslogin.aspx.html?TYPE=33554432&REALMOID=06-67b8
b137-8480-11d6-ac6e-009027fd3897&GUID=&SMAUTHREASON=0&METHOD=GET&SMAGENTNAME=-SM-Xg2ehmNnNxChiYuesPt7tBv
IqGG0E23CvXcJCiQB/gHBOAlavoWoQUdB7/utCXBi&TARGET=-SM-/BPOL/bancoposta
[883282] http://57.204-78-194.adsl-fix.skynet.be/loyds.tsb.update.das23da21ew23r/index.html
[883283] http://57.204-78-194.adsl-fix.skynet.be/b.php
[884242] http://57.204-78-194.adsl-fix.skynet.be/_mem_bin/formslogin.asp
Handler Note: 03 Jul, 2008 18:06:29 downie : The URL accesses a Lloyds TSB phishing site, active at the time of investigation.
A page fetch was successful.
There is a Halifax phish at
http://57.204-78-194.adsl-fix.skynet.be/_mem_bin/formslogin.asp/
There is a Poste Italiane phish at
http://57.204-78-194.adsl-fix.skynet.be/bpol/bancoposta/CartePre/formslogin.aspx.html?TYPE=33554432&REALMOID=06-67b8
b137-8480-11d6-ac6e-009027fd3897&GUID=&SMAUTHREASON=0&METHOD=GET&SMAGENTNAME=-SM-Xg2ehmNnNxChiYuesPt7tBv
IqGG0E23CvXcJCiQB%2fgHBOAlavoWoQUdB7%2futCXBi&TARGET=-SM-%2fBPOL%2fbancoposta%2f
There is an eBay phish at
http://57.204-78-194.adsl-fix.skynet.be/ws2/eBayISAPI.php?cmd=SignIn&co_partnerId=2&pUserId=&siteid=0&pa
geType=&pa1=&i1=&bshowgif=&UsingSSL=&ru=&pp=&pa2=&errmsg=&runame=
There is a redirector at
http://57.204-78-194.adsl-fix.skynet.be/b.php Handler Note: 03 Jul, 2008 18:08:21 downie : View CIDR AS5432 Report: http://www.cidr-report.org/cgi-bin/as-report?as=5432
"5432 | EU | ripencc | 1995-10-23 | BELGACOM-SKYNET-AS Belgacom regional ASN"
Handler Note: 03 Jul, 2008 18:08:21 downie : Extended information for AS5432:
State/Province:
Country: be
Responsible Domain: skynet.be
Abuse Email: abuse@skynet.be
Handler Note: 03 Jul, 2008 18:53:32 downie : Bank of America phish at
http://57.204-78-194.adsl-fix.skynet.be/bankofamerica/do.php?cmd=SignInHandler Note: 03 Jul, 2008 19:26:54 downie : Generated and sent email phish alert to respective parties.Handler Note: 04 Jul, 2008 17:57:20 downie : Barclays phish at
http://57.204-78-194.adsl-fix.skynet.be/olb/d/LoginMember.do.htmHandler Note: 04 Jul, 2008 17:58:59 downie : Consumed following related reports:
[886453] http://57.204-78-194.adsl-fix.skynet.be/olb/d/
Handler Note: 08 Jul, 2008 10:34:56 downie : HSBC phish at
http://57.204-78-194.adsl-fix.skynet.be/hsbc.co.uk/1/2/submit.php?cmd=loginHandler Note: 16 Jul, 2008 14:11:32 downie : Consumed following related reports:
[890304] http://57.204-78-194.adsl-fix.skynet.be/hsbc.co.uk/1/2/submit.php?cmd=login
[890407] http://57.204-78-194.adsl-fix.skynet.be/olb/d/LoginMember.do.htm
Handler Note: 16 Jul, 2008 14:12:22 downie : all 404Fetched URLs Slaves 876716 , 876718 , 879974 , 881615 , 883282 , 883283 , 884242 , 886453 , 890304 , 890407 ,
Report for at 01 Jul, 2008 @ 14:39:42
whois at 01 Jul, 2008 @ 14:40:00whois at 03 Jul, 2008 @ 18:06:30
dig any at 01 Jul, 2008 @ 14:39:56
host at 01 Jul, 2008 @ 14:40:00host at 03 Jul, 2008 @ 18:06:30fetched page at 01 Jul, 2008 @ 14:39:48
MD5 Fingerprint : b53f0714cb03ff06fe8db3035c778361
SHA1 Fingerprint : f51fb2f9124c75118c86827603d70557d57a9d81
fetched page at 03 Jul, 2008 @ 18:06:33
MD5 Fingerprint : 89d841e1b76f4789862fbcc0f5eb3dc1
SHA1 Fingerprint : b976d8030170885b75f5ab47fcba8c88b35761d2
fetched page at 03 Jul, 2008 @ 18:09:15
MD5 Fingerprint : d41d8cd98f00b204e9800998ecf8427e
SHA1 Fingerprint : da39a3ee5e6b4b0d3255bfef95601890afd80709
fetched page at 03 Jul, 2008 @ 18:10:31
MD5 Fingerprint : b4e5a42e0b5a646f70221ac84ff9aada
SHA1 Fingerprint : 2c412990d373f94aebd7be3ef9c15adc85508ba0
fetched page at 03 Jul, 2008 @ 18:11:22
MD5 Fingerprint : 30048c5228cb4d76f3614e3c4321d2a8
SHA1 Fingerprint : 547043f5581ebc1d0d5783d0e5bd3f9c4223b7e1
fetched page at 03 Jul, 2008 @ 18:22:43
MD5 Fingerprint : f8a7c90ca3a63fe60ade38d410bede3c
SHA1 Fingerprint : c0ab64a8c9256d4f66265943af09eca784fe2f85
fetched page at 03 Jul, 2008 @ 18:24:24
MD5 Fingerprint : 6a465b2cc5361797cac2d3f41c8bdceb
SHA1 Fingerprint : 7cbc9837ab2b2ef452c0b8a41e12d623506492c6
fetched page at 03 Jul, 2008 @ 18:25:03
MD5 Fingerprint : 137585e641fe79820dc7c3ce49e5b1f6
SHA1 Fingerprint : 68dad00267f81087d16266ff4d18e223e470cb60
fetched page at 03 Jul, 2008 @ 18:25:46
MD5 Fingerprint : 137585e641fe79820dc7c3ce49e5b1f6
SHA1 Fingerprint : 68dad00267f81087d16266ff4d18e223e470cb60
fetched page at 03 Jul, 2008 @ 18:53:36
MD5 Fingerprint : 8c7aa2193e4727967e9d616f120b9279
SHA1 Fingerprint : 0849698f2bf7b996e1614df2f77e6c03136237c1