CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer PIRT Squad

Fried Phish(TM)

Phishing Incident Reporting and Termination (PIRT) Squad(SM)

A global phishing termination and intelligence system operated by CastleCops. Become a PIRT Squad terminator by reporting phish today!

[ How-To / FAQ ]

Fried Phish -> Confirmed Phish | Terminated Phish


status: terminated

HTTP Response
19 Oct, 2008
19:00:00
HTTP/1.1 502 Proxy Error
ID990812 (termination link)
TitlePayPal
Entry
PIRT Squad
Reporter
Submitted anonymously thru the web, or sent to pirt (at) castlecops (dot) com.
Timestamp10 Oct, 2008 @ 04:00:25
Topic ID227322 - Read/respond to PIRT commentary.
Handler Note:
10 Oct, 2008
16:57:34
s0tet: Consumed following related reports:

[989799] http://111t1qcgkcv3868ws3.web.ve/cmd-confirm
Handler Note:
10 Oct, 2008
17:09:10
s0tet: View CIDR AS6867 Report: http://www.cidr-report.org/cgi-bin/as-report?as=6867

"6867 | GR | ripencc | 1996-12-11 | UCNET University of Crete"

Handler Note:
10 Oct, 2008
17:09:10
s0tet: Extended information for AS6867:
State/Province:
Country: gr
Responsible Domain: ucnet.uoc.gr
Abuse Email: postmaster@uoc.gr
Handler Note:
10 Oct, 2008
17:40:51
s0tet: www.paypal.com.rzgq1s90rmf7rzgnr.111t1qcgkcv3868ws3.web.ve is a fraudulent subdomain setup for PayPal phishing. Alerting owners of www.web.ve.
Handler Note:
10 Oct, 2008
17:45:03
s0tet: WHOIS of web.ve
Titular:
Merien Van der Velden (www.web.ve-dom) nameminesales@gmail.com
MHJ Van der Velden
Ligulastraat 21
Oosterhout gem Nijmegen NL
28549264 x+316

Nombre de Dominio: www.web.ve

Contacto Administrativo:
Name Mine (www.web.ve-adm) nameminesales@gmail.com
Name Mine LLP
DEPT 108 UNIT 9D1, CARCROFT ENTERPRISE PARK, STATION ROAD
Doncaster UNITED KINGDOM
+44 - 241411046 x+44

Contacto Tecnico:
Name Mine (www.web.ve-tec) nameminesales@gmail.com
Name Mine LLP
DEPT 108 UNIT 9D1, CARCROFT ENTERPRISE PARK, STATION ROAD
Doncaster UNITED KINGDOM
+44 - 241411046 x+44

Contacto de Cobranza:
Merien Van der Velden (www.web.ve-bil) nameminesales@gmail.com
MHJ Van der Velden
Ligulastraat 21
Oosterhout gem Nijmegen NL
28549264 x+316

Fecha de Vencimiento: 2009-01-19 09:56:40
Ultima Actualizacion: 2007-04-08 05:42:53
Fecha de Creacion: 2007-01-19 09:56:40

Estatus del dominio: ACTIVO

Servidor(es) de Nombres de Dominio:

- ns1.newnameserver.com
- ns2.newnameserver.com

NIC-Venezuela - CNTI
http://www.nic.ve
Handler Note:
10 Oct, 2008
17:49:20
s0tet: View CIDR AS5408 Report: http://www.cidr-report.org/cgi-bin/as-report?as=5408

"5408 | EU | ripencc | 1995-09-06 | GR-NET Greek Research & Technology Network, http://www.grnet.gr"

Handler Note:
10 Oct, 2008
17:49:21
s0tet: Extended information for AS5408:
State/Province:
Country: gr
Responsible Domain: grnet.gr
Abuse Email: abuse@grnet.gr
Handler Note:
10 Oct, 2008
17:49:42
s0tet: Generated and sent email phish alert to respective parties.
Handler Note:
26 Oct, 2008
14:10:21
s0tet: paypal.com.rzgq1s90rmf7rzgnr.111t1qcgkcv3868ws3.web.ve is a fraudulent subdomain used for PayPal phishing.

WHOIS FOR WEB.VE
Titular:
Merien Van der Velden (www.web.ve-dom) nameminesales@gmail.com
MHJ Van der Velden
Ligulastraat 21
Oosterhout gem Nijmegen NL
28549264 x+316

Nombre de Dominio: www.web.ve

Contacto Administrativo:
Name Mine (www.web.ve-adm) nameminesales@gmail.com
Name Mine LLP
DEPT 108 UNIT 9D1, CARCROFT ENTERPRISE PARK, STATION ROAD
Doncaster UNITED KINGDOM
+44 - 241411046 x+44

Contacto Tecnico:
Name Mine (www.web.ve-tec) nameminesales@gmail.com
Name Mine LLP
DEPT 108 UNIT 9D1, CARCROFT ENTERPRISE PARK, STATION ROAD
Doncaster UNITED KINGDOM
+44 - 241411046 x+44

Contacto de Cobranza:
Merien Van der Velden (www.web.ve-bil) nameminesales@gmail.com
MHJ Van der Velden
Ligulastraat 21
Oosterhout gem Nijmegen NL
28549264 x+316

Fecha de Vencimiento: 2009-01-19 09:56:40
Ultima Actualizacion: 2007-04-08 05:42:53
Fecha de Creacion: 2007-01-19 09:56:40

Estatus del dominio: ACTIVO
Fetched URLs
Slaves989799,

Report for at 10 Oct, 2008 @ 16:57:00


fetched page

thumbnail
at 10 Oct, 2008 @ 16:58:18
MD5 Fingerprint: 63694dc2b02605ad7a5bd404cb8f3ee9
SHA1 Fingerprint: ba7ae23ea163cd786a02d6a51ff25956e1d71d23
Version 1.0
spacer spacer