CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 937
Comments: 25
block bottom
spacer spacer PIRT Squad

Fried Phish(TM)

Phishing Incident Reporting and Termination (PIRT) Squad(SM)

A global phishing termination and intelligence system operated by CastleCops. Become a PIRT Squad terminator by reporting phish today!

[ How-To / FAQ ]

Fried Phish -> Confirmed Phish | Terminated Phish


status: terminated

ID899347 (termination link)
TitleBank of America, NatWest, Wells Fargo
Entry
PIRT Squad
Reporter
Submitted anonymously thru the web, or sent to pirt (at) castlecops (dot) com.
Timestamp17 Jul, 2008 @ 18:35:53
Topic ID225222 - Read/respond to PIRT commentary.
Handler Note:
19 Jul, 2008
22:50:27
downie: Consumed following related reports:

[897912] http://freegiftcardcenter.net/~ohadev/wp-content/uploads/www.onlineservice.wellsfargo.com/number-youraccount/updating-ac cont/adlf23&=wkruavmblxdfjareabeta&=giewjaloginyouraccountwellsfargo.com&=welcometowellsfargo/open-account/l ogin.asp/
[898894] http://freegiftcardcenter.net/~ohadev/wp-content/uploads/2007/httpswww.nwolb.com/default.aspxrefererident=C5D601086CEC7E 55F65E5AB759709179A1558985&cookieid=31266&noscr/login.asp/Login.html
[899779] http://freegiftcardcenter.net/~ohadev/wp-content/uploads/2007/onlineservice.natwest.co.uk/www.nwolb.com/default.aspxrefe rerident=722883B47C704141D47B16DF96CCDDD38B5FF4C6&cookieid=102722&nosc/login.asp/Login.aspx.htm
Handler Note:
19 Jul, 2008
22:56:58
downie: The URL accesses a Bank of America phishing site, active at the time of investigation.
A page fetch was successful.
There is a Wells Fargo phish at
http://freegiftcardcenter.net/~ohadev/wp-content/uploads/www.onlineservice.wellsfargo.com/number-youraccount/updating-ac cont/adlf23&=wkruavmblxdfjareabeta&=giewjaloginyouraccountwellsfargo.com&=welcometowellsfargo/open-account/l ogin.asp/
There is a NatWest phish at
http://freegiftcardcenter.net/~ohadev/wp-content/uploads/2007/onlineservice.natwest.co.uk/www.nwolb.com/default.aspxrefe rerident=722883B47C704141D47B16DF96CCDDD38B5FF4C6&cookieid=102722&nosc/login.asp/Login.aspx.htm
Handler Note:
19 Jul, 2008
23:04:05
downie: View CIDR AS21844 Report: http://www.cidr-report.org/cgi-bin/as-report?as=21844

"21844 | US | arin | 2001-06-29 | THEPLANET-AS - ThePlanet.com Internet Services, Inc."

Handler Note:
19 Jul, 2008
23:04:07
downie: Extended information for AS21844:
State/Province: tx
Country: us
Responsible Domain: theplanet.com
Abuse Email: abuse@theplanet.com
Handler Note:
20 Jul, 2008
00:50:28
downie: Generated and sent email phish alert to respective parties.
Handler Note:
20 Jul, 2008
20:20:41
downie: Site suspended
Fetched URLs
Slaves897912, 898894, 899779,

Report for at 19 Jul, 2008 @ 22:50:27


fetched page

at 19 Jul, 2008 @ 22:57:02
MD5 Fingerprint: ae004502cf58e599846baba770f24b71
SHA1 Fingerprint: 00824612e7016cbce278baac5fbc8c912c351818

fetched page

at 19 Jul, 2008 @ 23:02:29
MD5 Fingerprint: baf3d04cc568d0294217e5f6794b4580
SHA1 Fingerprint: 51a0728ae94a2425f7e082cf848cda2e8a3dc41e

fetched page

at 19 Jul, 2008 @ 23:04:10
MD5 Fingerprint: d41d8cd98f00b204e9800998ecf8427e
SHA1 Fingerprint: da39a3ee5e6b4b0d3255bfef95601890afd80709

fetched page

at 19 Jul, 2008 @ 23:13:30
MD5 Fingerprint: 79814ec664855f9788be0bd2c9aef905
SHA1 Fingerprint: d0a76fe26d810370fabebca2db994956ba96c94c

fetched page

at 19 Jul, 2008 @ 23:14:48
MD5 Fingerprint: d41d8cd98f00b204e9800998ecf8427e
SHA1 Fingerprint: da39a3ee5e6b4b0d3255bfef95601890afd80709