CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 940
Comments: 25
block bottom
spacer spacer PIRT Squad

Fried Phish(TM)

Phishing Incident Reporting and Termination (PIRT) Squad(SM)

A global phishing termination and intelligence system operated by CastleCops. Become a PIRT Squad terminator by reporting phish today!

[ How-To / FAQ ]

Fried Phish -> Confirmed Phish | Terminated Phish


status: terminated

HTTP Response
26 May, 2008
19:45:13
HTTP/1.1 404 Not Found
ID824105 (termination link)
TitleBank of America
Entry
PIRT Squad
Reporter
Submitted anonymously thru the web, or sent to pirt (at) castlecops (dot) com.
Timestamp11 May, 2008 @ 18:43:55
Topic ID221626 - Read/respond to PIRT commentary.
Handler Note:
11 May, 2008
23:46:14
downie: Consumed following related reports:

[824106] http://host22.hrwebservices.net/~icorraa/css/2008/bofaa/bankofamerica/bank/acc/bankofamerica/do.php?cmd=3DSignIn
Handler Note:
11 May, 2008
23:50:52
downie: The URL accesses a Bank of America phishing site, active at the time of investigation.
A page fetch was successful.
Handler Note:
11 May, 2008
23:53:03
downie: View CIDR AS4323 Report: http://www.cidr-report.org/cgi-bin/as-report?as=4323

"4323 | US | arin | 1995-02-01 | TWTC - Time Warner Telecom, Inc."

Handler Note:
11 May, 2008
23:53:04
downie: Extended information for AS4323:
State/Province: co
Country: us
Responsible Domain: twtelecom.net
Abuse Email: abuse@twtelecom.net
Handler Note:
12 May, 2008
00:33:48
downie: Generated and sent email phish alert to respective parties.
Handler Note:
29 May, 2008
00:29:45
downie: 404
Fetched URLs
Slaves824106,

Report for at 11 May, 2008 @ 19:23:52


fetched page

at 11 May, 2008 @ 19:23:54
MD5 Fingerprint: 24043d88a94de2dd7cd3ce0a3ed1a3fa
SHA1 Fingerprint: 96619fe7a1d1b7c042aae09cfdb2f3f9562ae8cc

fetched page

at 11 May, 2008 @ 23:50:55
MD5 Fingerprint: 3e153fbcf923214aba9573a52487a441
SHA1 Fingerprint: 8020240d43a03d509ec1925fecb800e9d56e2416

fetched page

at 11 May, 2008 @ 23:53:05
MD5 Fingerprint: 98bba9abf8e4fbd7c28ae94b28e1147e
SHA1 Fingerprint: dc9f552c5436cdb98686e3ff2a89db015396a41a

fetched page

at 11 May, 2008 @ 23:53:53
MD5 Fingerprint: 48e72fb73f394de508ea544c0a8b1a9f
SHA1 Fingerprint: 594a25a4145ff0dabf68287ea6e994901ee0a6a3

fetched page

at 11 May, 2008 @ 23:54:41
MD5 Fingerprint: d41d8cd98f00b204e9800998ecf8427e
SHA1 Fingerprint: da39a3ee5e6b4b0d3255bfef95601890afd80709