CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 927
Comments: 25
block bottom
spacer spacer PIRT Squad

Fried Phish(TM)

Phishing Incident Reporting and Termination (PIRT) Squad(SM)

A global phishing termination and intelligence system operated by CastleCops. Become a PIRT Squad terminator by reporting phish today!

[ How-To / FAQ ]

Fried Phish -> Confirmed Phish | Terminated Phish


status: terminated

HTTP Response
26 May, 2008
21:05:32
HTTP/1.1 404 Not Found
ID827405 (termination link)
TitleCitiBank
Entry
PIRT Squad
Reporter
Submitted anonymously thru the web, or sent to pirt (at) castlecops (dot) com.
Timestamp14 May, 2008 @ 17:39:01
Topic ID221727 - Read/respond to PIRT commentary.
Handler Note:
14 May, 2008
19:08:02
downie: Consumed following related reports:

[827406] http://worlddancecentre.com/images/space/index.php?customerid=hazelshome@hotmail.com&co_partnerId=2&siteid=0& ;ru=&PageName=login_run&pp=pass&pageType=708XeMWZllWXS3AlBX+VShqAhQRfhgTDrf&co_partnerId=2&siteid=0& amp;ru=&pp=&pageType=708&MfcISAPICommand=ConfirmRegistration&708XeMWZllWXS3AlBXVShqAhQRfhgTDrfQRfhgTDrfA
[827407] http://worlddancecentre.com/images/space/index.php?customerid=3Dhazelshome@hotmail.com&co_partnerId=2&siteid=0&a mp;ru=&PageName=login_run&pp=pass&pageType=708XeMWZllWXS3AlBX+VShqAhQRfhgTDrf&co_partnerId=2&siteid= 0&ru=&pp=&pageType=708&MfcISAPICommand=ConfirmRegistration&708XeMWZllWXS3AlBXVShqAhQRfhgTDrfQRfhgTDr fA
Handler Note:
14 May, 2008
19:09:49
downie: The URL accesses a Citibank phishing site, active at the time of investigation.
A page fetch was successful.
Handler Note:
14 May, 2008
19:20:16
downie: View CIDR AS38877 Report: http://www.cidr-report.org/cgi-bin/as-report?as=38877

"38877 | | | | MD-WEB-HOSTING-AU-AP MD Web Hosting"

Handler Note:
14 May, 2008
19:20:17
downie: Extended information for AS38877:
State/Province:
Country:
Responsible Domain:
Abuse Email:
Handler Note:
14 May, 2008
20:28:01
downie: Generated and sent email phish alert to respective parties.
Handler Note:
16 May, 2008
01:49:50
downie: 404
Fetched URLs
Slaves827406, 827407,

Report for at 14 May, 2008 @ 19:08:02


fetched page

at 14 May, 2008 @ 19:09:54
MD5 Fingerprint: d41d8cd98f00b204e9800998ecf8427e
SHA1 Fingerprint: da39a3ee5e6b4b0d3255bfef95601890afd80709

fetched page

at 14 May, 2008 @ 19:20:23
MD5 Fingerprint: d41d8cd98f00b204e9800998ecf8427e
SHA1 Fingerprint: da39a3ee5e6b4b0d3255bfef95601890afd80709

fetched page

at 14 May, 2008 @ 21:00:17
MD5 Fingerprint: fd75af9439d4aa423cf1644a9a51369a
SHA1 Fingerprint: 6ac63c6b4f8f059346c5b08010f1fd7acc47aa48
Version 1.0
spacer spacer