CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer PIRT Squad

Fried Phish(TM)

Phishing Incident Reporting and Termination (PIRT) Squad(SM)

A global phishing termination and intelligence system operated by CastleCops. Become a PIRT Squad terminator by reporting phish today!

[ How-To / FAQ ]

Fried Phish -> Confirmed Phish | Terminated Phish


status: terminated

ID900756 (termination link)
TitleHalifax
Entry
PIRT Squad
Reporter
Submitted anonymously thru the web, or sent to pirt (at) castlecops (dot) com.
Timestamp19 Jul, 2008 @ 15:29:58
Topic ID225210 - Read/respond to PIRT commentary.
Handler Note:
19 Jul, 2008
19:29:21
downie: Consumed following related reports:

[899041] http://asev.org.mx/components/com_user/https/www.halifax-online.co.uk/_mem_bin/
Handler Note:
19 Jul, 2008
19:31:56
downie: The URL accesses a Halifax phishing site, active at the time of investigation.
A page fetch was successful.
Handler Note:
19 Jul, 2008
19:35:49
downie: WARNING! THERE IS MALWARE ON THIS SITE!
Handler Note:
19 Jul, 2008
19:35:49
downie: View CIDR AS30315 Report: http://www.cidr-report.org/cgi-bin/as-report?as=30315

"30315 | US | arin | 2003-09-08 | ASN-THEPLANET-3 - ThePlanet.com Internet Services, Inc."

Handler Note:
19 Jul, 2008
19:35:50
downie: Extended information for AS30315:
State/Province: tx
Country: us
Responsible Domain: ev1.net
Abuse Email: abuse@ev1servers.net
Handler Note:
19 Jul, 2008
20:44:48
downie: Generated and sent email phish alert to respective parties.
Handler Note:
21 Jul, 2008
20:50:06
downie: 403
Fetched URLs
Slaves899041,

Report for at 19 Jul, 2008 @ 19:29:21


fetched page

at 19 Jul, 2008 @ 19:34:12
MD5 Fingerprint: 222d68e5f84e6326bcfde3b0f884c8cd
SHA1 Fingerprint: f45b79df8aadf253f06a7ea238ce2264ac529d1d

fetched page

at 19 Jul, 2008 @ 19:35:50
MD5 Fingerprint: 4dd39401fb760b518373f81d03fbadfc
SHA1 Fingerprint: d5944700ec7738eb9d2792dee9917c2ab2f0cd80
Version 1.0
spacer spacer