CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer PIRT Squad

Fried Phish(TM)

Phishing Incident Reporting and Termination (PIRT) Squad(SM)

A global phishing termination and intelligence system operated by CastleCops. Become a PIRT Squad terminator by reporting phish today!

[ How-To / FAQ ]

Fried Phish -> Confirmed Phish | Terminated Phish


status: terminated

HTTP Response
13 Jul, 2008
17:12:29
HTTP/1.1 200 OK
ID883281 (termination link)
TitleBank of America, Barclays, HSBC, Halifax, Lloyds TSB, eBay
Entry
PIRT Squad
Reporter
Submitted anonymously thru the web, or sent to pirt (at) castlecops (dot) com.
Timestamp01 Jul, 2008 @ 14:39:41
Topic ID224565 - Read/respond to PIRT commentary.
Handler Note:
03 Jul, 2008
18:01:35
downie: Consumed following related reports:

[876716] http://57.204-78-194.adsl-fix.skynet.be/ws2/eBayISAPI.php?cmd=SignIn&co_partnerId=2&pUserId=&siteid=0&pa geType=&pa1=&i1=&bshowgif=&UsingSSL=&ru=&pp=&pa2=&errmsg=&runameTYPE=eBay
[876718] http://57.204-78-194.adsl-fix.skynet.be/ws2/eBayISAPI.php?cmd=SignIn&co_partnerId=2&pUserId=&siteid=0&pa geType=&pa1=&i1=&bshowgif=&UsingSSL=&ru=&pp=&pa2=&errmsg=&runameMessage-Id:
[879974] http://57.204-78-194.adsl-fix.skynet.be/ws2/
[881615] http://57.204-78-194.adsl-fix.skynet.be/bpol/bancoposta/CartePre/formslogin.aspx.html?TYPE=33554432&REALMOID=06-67b8 b137-8480-11d6-ac6e-009027fd3897&GUID=&SMAUTHREASON=0&METHOD=GET&SMAGENTNAME=-SM-Xg2ehmNnNxChiYuesPt7tBv IqGG0E23CvXcJCiQB/gHBOAlavoWoQUdB7/utCXBi&TARGET=-SM-/BPOL/bancoposta
[883282] http://57.204-78-194.adsl-fix.skynet.be/loyds.tsb.update.das23da21ew23r/index.html
[883283] http://57.204-78-194.adsl-fix.skynet.be/b.php
[884242] http://57.204-78-194.adsl-fix.skynet.be/_mem_bin/formslogin.asp
Handler Note:
03 Jul, 2008
18:06:29
downie: The URL accesses a Lloyds TSB phishing site, active at the time of investigation.
A page fetch was successful.
There is a Halifax phish at
http://57.204-78-194.adsl-fix.skynet.be/_mem_bin/formslogin.asp/
There is a Poste Italiane phish at
http://57.204-78-194.adsl-fix.skynet.be/bpol/bancoposta/CartePre/formslogin.aspx.html?TYPE=33554432&REALMOID=06-67b8 b137-8480-11d6-ac6e-009027fd3897&GUID=&SMAUTHREASON=0&METHOD=GET&SMAGENTNAME=-SM-Xg2ehmNnNxChiYuesPt7tBv IqGG0E23CvXcJCiQB%2fgHBOAlavoWoQUdB7%2futCXBi&TARGET=-SM-%2fBPOL%2fbancoposta%2f
There is an eBay phish at
http://57.204-78-194.adsl-fix.skynet.be/ws2/eBayISAPI.php?cmd=SignIn&co_partnerId=2&pUserId=&siteid=0&pa geType=&pa1=&i1=&bshowgif=&UsingSSL=&ru=&pp=&pa2=&errmsg=&runame=
There is a redirector at
http://57.204-78-194.adsl-fix.skynet.be/b.php
Handler Note:
03 Jul, 2008
18:08:21
downie: View CIDR AS5432 Report: http://www.cidr-report.org/cgi-bin/as-report?as=5432

"5432 | EU | ripencc | 1995-10-23 | BELGACOM-SKYNET-AS Belgacom regional ASN"

Handler Note:
03 Jul, 2008
18:08:21
downie: Extended information for AS5432:
State/Province:
Country: be
Responsible Domain: skynet.be
Abuse Email: abuse@skynet.be
Handler Note:
03 Jul, 2008
18:53:32
downie: Bank of America phish at
http://57.204-78-194.adsl-fix.skynet.be/bankofamerica/do.php?cmd=SignIn
Handler Note:
03 Jul, 2008
19:26:54
downie: Generated and sent email phish alert to respective parties.
Handler Note:
04 Jul, 2008
17:57:20
downie: Barclays phish at
http://57.204-78-194.adsl-fix.skynet.be/olb/d/LoginMember.do.htm
Handler Note:
04 Jul, 2008
17:58:59
downie: Consumed following related reports:

[886453] http://57.204-78-194.adsl-fix.skynet.be/olb/d/
Handler Note:
08 Jul, 2008
10:34:56
downie: HSBC phish at
http://57.204-78-194.adsl-fix.skynet.be/hsbc.co.uk/1/2/submit.php?cmd=login
Handler Note:
16 Jul, 2008
14:11:32
downie: Consumed following related reports:

[890304] http://57.204-78-194.adsl-fix.skynet.be/hsbc.co.uk/1/2/submit.php?cmd=login
[890407] http://57.204-78-194.adsl-fix.skynet.be/olb/d/LoginMember.do.htm
Handler Note:
16 Jul, 2008
14:12:22
downie: all 404
Fetched URLs
Slaves876716, 876718, 879974, 881615, 883282, 883283, 884242, 886453, 890304, 890407,

Report for at 01 Jul, 2008 @ 14:39:42


fetched page

thumbnail
at 01 Jul, 2008 @ 14:39:48
MD5 Fingerprint: b53f0714cb03ff06fe8db3035c778361
SHA1 Fingerprint: f51fb2f9124c75118c86827603d70557d57a9d81

fetched page

thumbnail
at 03 Jul, 2008 @ 18:06:33
MD5 Fingerprint: 89d841e1b76f4789862fbcc0f5eb3dc1
SHA1 Fingerprint: b976d8030170885b75f5ab47fcba8c88b35761d2

fetched page

thumbnail
at 03 Jul, 2008 @ 18:09:15
MD5 Fingerprint: d41d8cd98f00b204e9800998ecf8427e
SHA1 Fingerprint: da39a3ee5e6b4b0d3255bfef95601890afd80709

fetched page

thumbnail
at 03 Jul, 2008 @ 18:10:31
MD5 Fingerprint: b4e5a42e0b5a646f70221ac84ff9aada
SHA1 Fingerprint: 2c412990d373f94aebd7be3ef9c15adc85508ba0

fetched page

thumbnail
at 03 Jul, 2008 @ 18:11:22
MD5 Fingerprint: 30048c5228cb4d76f3614e3c4321d2a8
SHA1 Fingerprint: 547043f5581ebc1d0d5783d0e5bd3f9c4223b7e1

fetched page

thumbnail
at 03 Jul, 2008 @ 18:22:43
MD5 Fingerprint: f8a7c90ca3a63fe60ade38d410bede3c
SHA1 Fingerprint: c0ab64a8c9256d4f66265943af09eca784fe2f85

fetched page

thumbnail
at 03 Jul, 2008 @ 18:24:24
MD5 Fingerprint: 6a465b2cc5361797cac2d3f41c8bdceb
SHA1 Fingerprint: 7cbc9837ab2b2ef452c0b8a41e12d623506492c6

fetched page

thumbnail
at 03 Jul, 2008 @ 18:25:03
MD5 Fingerprint: 137585e641fe79820dc7c3ce49e5b1f6
SHA1 Fingerprint: 68dad00267f81087d16266ff4d18e223e470cb60

fetched page

thumbnail
at 03 Jul, 2008 @ 18:25:46
MD5 Fingerprint: 137585e641fe79820dc7c3ce49e5b1f6
SHA1 Fingerprint: 68dad00267f81087d16266ff4d18e223e470cb60

fetched page

thumbnail
at 03 Jul, 2008 @ 18:53:36
MD5 Fingerprint: 8c7aa2193e4727967e9d616f120b9279
SHA1 Fingerprint: 0849698f2bf7b996e1614df2f77e6c03136237c1