CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

[PIRT#953501] Equifax Rockphish on file3.org / LENGINESS.COM

 
Post new topic   Reply to topic       All -> FavForums -> PIRT Fried Phish Reports [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
s0tet

PIRT Handler


Joined: May 21, 2005
Posts: 2976

Phishing Squad

PostPosted: Tue Sep 09, 2008 12:31 am    Post subject: [PIRT#953501] Equifax Rockphish on file3.org / LENGINESS.COM
Reply with quote

Phish Alert
 
 Full Report: CastleCops Link/Equifax_Rock_Phish_phish953501.html
 
 Consumed following related reports:

[953588] http://www.eport.equifax.com.file3.org/eport/member_id.jsp?session=919512322152254472782944743809233864753714271130626023928129781614398952
[953597] http://www.eport.equifax.com.file3.org/eport/member_id.jsp?session=3D5162010754735904410811319843227168833393947476250572425827006836
Changed status to confirmed phish.IP Converted: 61.114.66.102

dword = 1030898278
hex1 = 0x3d724266
hex2 = 0x3d.0x72.0x42.0x66
oct = 075.0162.0102.0146
View CIDR AS10002 Report: http://www.cidr-report.org/cgi-bin/as-report?as=10002

"10002 | JP | apnic | 2000-04-27 | ICT IGAUENO CABLE TELEVISION CO.,LTD"<br />
Extended information for AS10002:
State/Province:
Country: jp
Responsible Domain: ict-tv.co.jp
Abuse Email: yoshi@ict-tv.co.jp
IP Converted: 59.25.174.151

dword = 991538839
hex1 = 0x3b19ae97
hex2 = 0x3b.0x19.0xae.0x97
oct = 073.031.0256.0227
View CIDR AS4766 Report: http://www.cidr-report.org/cgi-bin/as-report?as=4766

"4766 | KR | apnic | 1996-04-22 | KIXS-AS-KR Korea Telecom"<br />
Extended information for AS4766:
State/Province:
Country: kr
Responsible Domain: kornet.net
Abuse Email: abuse@kornet.net
IP Converted: 89.46.37.173

dword = 1496196525
hex1 = 0x592e25ad
hex2 = 0x59.0x2e.0x25.0xad
oct = 0131.056.045.0255
View CIDR AS32748 Report: http://www.cidr-report.org/cgi-bin/as-report?as=32748

"32748 | US | arin | 2004-07-16 | STEADFAST - NoZone, Inc."<br />
Extended information for AS32748:
State/Province: wi
Country: us
Responsible Domain: nozoneinc.com
Abuse Email: noc@nozoneinc.com
The URL accesses a phishing site hosted on a bot net.
IP addresses 12.202.108.211, 124.86.130.228, 142.177.231.216, 203.243.220.175, 59.25.174.151, 61.114.66.102, 80.73.12.66 were active at Mon, 08 Sep 2008 23:33:48 +0000 (GMT).
Nameservers
NS1.LENGINESS.COM [89.46.37.173] response 12.202.108.211, 124.86.130.228, 142.177.231.216, 203.243.220.175, 59.25.174.151, 61.114.66.102, 80.73.12.66 in 45 mSec
NS1.MORECCN.COM [89.46.37.173] response 12.202.108.211, 124.86.130.228, 142.177.231.216, 203.243.220.175, 59.25.174.151, 61.114.66.102, 80.73.12.66 in 45 mSec
were active at the same time
=================================
REGISTRAR :Internet Invest, Ltd. dba Imena.ua:
Domain FILE3.ORG has been registered with Imena.ua for fraudulent purposes.
It is part of a network of phishing sites hosted on a bot net.
Please suspend this domain immediately to prevent further criminal activity.
Please also check for any domains registered using the same (stolen) identity and credit card details, or the same email address.

This domain was used in reported phishing frauds dated 7/24/08:
http://chaseonline.chase.com.file3.org/Secure/webform/

=================================
REGISTRAR REGISTER.COM,:
Domain LENGINESS.COM has been registered with REGISTER.COM, for fraudulent purposes.
It is part of a network of phishing sites hosted on a bot net.
Please suspend this domain immediately to prevent further criminal activity.
Please also check for any domains registered using the same (stolen) identity and credit card details, or the same email address.
=================================
REGISTRAR eNom:
Domain MORECCN.COM has been registered with eNom for fraudulent purposes.
It is part of a network of phishing sites hosted on a bot net.
Please suspend this domain immediately to prevent further criminal activity.
Please also check for any domains registered using the same (stolen) identity and credit card details, or the same email address.
=================================
NAMESERVER HOST STEADFAST - NoZone, Inc:
Nameservers
NS1.LENGINESS.COM [89.46.37.173] - response 45 mSec
NS1.MORECCN.COM [89.46.37.173]
have been set up on your network to serve addresses for this phishing domain and others.
No legitimate domains use these nameservers.
Please shut them down urgently.
Please close the customer's account.
If possible please also be alert for anyone setting up other nameservers on your network for this domain.
=================================

Quote:
http://www.eport.equifax.com.file3.org/eport/member_id.jsp?session=34777323308551860767129928556331493504673346527101837793355861571296

Back to top
View users profile Send private message Send email
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> PIRT Fried Phish Reports All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer