CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer PIRT Squad

Fried Phish(TM)

Phishing Incident Reporting and Termination (PIRT) Squad(SM)

A global phishing termination and intelligence system operated by CastleCops. Become a PIRT Squad terminator by reporting phish today!

[ How-To / FAQ ]

Fried Phish -> Confirmed Phish | Terminated Phish


status: terminated

ID939553 (termination link)
TitleBank of America, Halifax, Lloyds TSB, TCF Bank
Entry
PIRT Squad
Reporter
Submitted anonymously thru the web, or sent to pirt (at) castlecops (dot) com.
Timestamp24 Aug, 2008 @ 00:21:46
Topic ID225907 - Read/respond to PIRT commentary.
Handler Note:
24 Aug, 2008
12:47:49
downie: Consumed following related reports:

[939549] http://bumbacahouses.com/blog/skins/www.bankofamerica.com/index.html
[939551] http://bumbacahouses.com/sec/lloydstsb.com/ibc.php?WTsvl=ibcplogon
[939552] http://bumbacahouses.com/sec/lloydstsb.com/
[939684] http://www.bumbacahouses.com/blog/skins/www.bankofamerica.com/index.html
Handler Note:
24 Aug, 2008
12:49:46
downie: The URL accesses a Halifax phishing site, active at the time of investigation.
A page fetch was successful.
There is a Bank of America phish at
http://bumbacahouses.com/blog/skins/www.bankofamerica.com/index.html
There is a Lloyds TSB phish at
http://bumbacahouses.com/sec/lloydstsb.com/ibc.php?WTsvl=ibcplogon
Handler Note:
24 Aug, 2008
12:54:34
downie: View CIDR AS15055 Report: http://www.cidr-report.org/cgi-bin/as-report?as=15055

"15055 | US | arin | 2007-07-05 | YOURCOLO-AS-1 - FastPC Inc."

Handler Note:
24 Aug, 2008
12:54:45
downie: Extended information for AS15055:
State/Province: ny
Country: us
Responsible Domain: worldnet.att.net
Abuse Email: security@worldnet.att.net
Handler Note:
24 Aug, 2008
14:26:43
downie: Another Bank of America phish at
http://bumbacahouses.com/blog/media/BankofAmerica.Com(T)/bankofamerica/signon.php?section=signinpage&update=&coo kiecheck=yes&destination=nba/signin
Handler Note:
24 Aug, 2008
14:43:51
downie: Generated and sent email phish alert to respective parties.
Handler Note:
27 Aug, 2008
00:00:11
downie: 404
Handler Note:
02 Sep, 2008
20:24:40
downie: Consumed following related reports:

[947734] http://bumbacahouses.com/images/Importand/ecure.tcfexpress.comtcfOnlineBanking/enterprise1.
[948188] http://bumbacahouses.com/images/Importand/ecure.tcfexpress.comtcfOnlineBanking/enterprise1.openbank.comfitcflogonuser/up date/tcfonlinesitekay.html
[948436] http://bumbacahouses.com/images/Importand/ecure.tcfexpress.comtcfOnlineBanking/enterprise1.openbank.comfitcflogonuser/up date/Important-update.html
Handler Note:
02 Sep, 2008
20:26:15
downie: There is now a TCF Bank phish at
http://bumbacahouses.com/images/Importand/ecure.tcfexpress.comtcfOnlineBanking/enterprise1.openbank.comfitcflogonuser/up date/Important-update.html
Handler Note:
07 Sep, 2008
00:15:52
downie: 404 again
Fetched URLs
Slaves939549, 939551, 939552, 939684, 947734, 948188, 948436,

Report for at 24 Aug, 2008 @ 12:47:49


fetched page

at 24 Aug, 2008 @ 12:49:48
MD5 Fingerprint: 20ad9b152d972050cb6aef36d51c2ff9
SHA1 Fingerprint: 6b0d30085eed3d7ad5a7870eb21284975258774b

fetched page

at 24 Aug, 2008 @ 12:51:26
MD5 Fingerprint: b52280661790d6654780946bc92603d2
SHA1 Fingerprint: 84c955127dc3da15bd219f565914503a7e505eca