CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 940
Comments: 25
block bottom
spacer spacer PIRT Squad

Fried Phish(TM)

Phishing Incident Reporting and Termination (PIRT) Squad(SM)

A global phishing termination and intelligence system operated by CastleCops. Become a PIRT Squad terminator by reporting phish today!

[ How-To / FAQ ]

Fried Phish -> Confirmed Phish | Terminated Phish


status: terminated

ID898670 (termination link)
TitleChase, Salin Bank
Entry
PIRT Squad
Reporter
Submitted anonymously thru the web, or sent to pirt (at) castlecops (dot) com.
Timestamp17 Jul, 2008 @ 04:16:56
Topic ID225152 - Read/respond to PIRT commentary.
Handler Note:
17 Jul, 2008
20:10:55
downie: The URL accesses a Chase phishing site, active at the time of investigation.
A page fetch was successful.
Handler Note:
17 Jul, 2008
20:17:05
downie: View CIDR AS4812 Report: http://www.cidr-report.org/cgi-bin/as-report?as=4812

"4812 | CN | apnic | 1996-01-09 | CHINANET-SH-AP China Telecom (Group)"

Handler Note:
17 Jul, 2008
20:17:06
downie: Extended information for AS4812:
State/Province:
Country: cn
Responsible Domain: chinanet.cn.net
Abuse Email: cncert@cert.org.cn
Handler Note:
17 Jul, 2008
21:56:41
downie: Consumed following related reports:

[897710] http://billscarlet.com/%20%20%20/www.salinbank.com/
Handler Note:
17 Jul, 2008
21:58:03
downie: There is a redirect at
http://mylamp.info/%20%20/ind.html
to a Salin Bank phish at
http://billscarlet.com/%20%20%20/www.salinbank.com/
This site needs cleaning up also.
Handler Note:
17 Jul, 2008
22:01:35
downie: View CIDR AS25767 Report: http://www.cidr-report.org/cgi-bin/as-report?as=25767

"25767 | US | arin | 2002-05-03 | WAVEFORM - Waveform Technology, LLC"

Handler Note:
17 Jul, 2008
22:01:36
downie: Extended information for AS25767:
State/Province: mi
Country: us
Responsible Domain: waveform.net
Abuse Email: postmaster@waveform.net
Handler Note:
17 Jul, 2008
22:20:38
downie: Generated and sent email phish alert to respective parties.
Handler Note:
18 Jul, 2008
20:00:56
downie: Neither connecting.
Fetched URLs
Slaves897710,

Report for at 17 Jul, 2008 @ 20:10:55


fetched page

at 17 Jul, 2008 @ 20:15:11
MD5 Fingerprint: 4b46c8be93cb655c067cde2ea8c8d4d3
SHA1 Fingerprint: 075584c35df8832946d18da932de502fbdf27457

fetched page

at 17 Jul, 2008 @ 20:17:06
MD5 Fingerprint: d41d8cd98f00b204e9800998ecf8427e
SHA1 Fingerprint: da39a3ee5e6b4b0d3255bfef95601890afd80709

fetched page

at 17 Jul, 2008 @ 21:58:06
MD5 Fingerprint: e4bcd4441fc6611e2ae17122345d77ab
SHA1 Fingerprint: 91a3d18f387b5fbec9060539f5b697d482bf6d24

fetched page

at 17 Jul, 2008 @ 22:04:02
MD5 Fingerprint: bd4035d85b883e914ab3a3736372c0d7
SHA1 Fingerprint: 8cc3ff500ee41586fdacb80b28a86d7e924fc995

fetched page

at 17 Jul, 2008 @ 22:04:34
MD5 Fingerprint: 355639f2d67e95a62e73c02144769712
SHA1 Fingerprint: 41ddcbf566bde33bb07905f17de676112ef070f9

fetched page

at 17 Jul, 2008 @ 22:06:04
MD5 Fingerprint: cacce8380a24136e9548576140848c3a
SHA1 Fingerprint: 306149ed5813893aa8e20f94e39b4abc0f716fd3

fetched page

at 17 Jul, 2008 @ 22:06:44
MD5 Fingerprint: 461d7e72bc5bdd244b88169ad8055bd5
SHA1 Fingerprint: 558258505f934f3ddd53dfc6f6fef7f4a5f66015
Version 1.0
spacer spacer