CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 927
Comments: 25
block bottom
spacer spacer PIRT Squad

Fried Phish(TM)

Phishing Incident Reporting and Termination (PIRT) Squad(SM)

A global phishing termination and intelligence system operated by CastleCops. Become a PIRT Squad terminator by reporting phish today!

[ How-To / FAQ ]

Fried Phish -> Confirmed Phish | Terminated Phish


status: terminated

HTTP Response
17 Jan, 2008
03:59:19
HTTP/1.1 502 Proxy Error
ID522534 (termination link)
TitleCitizens Bank, GoDaddy, Rock Phish, Royal Bank of Scotland
Entry
PIRT Squad
Reporter
Submitted anonymously thru the web, or sent to pirt (at) castlecops (dot) com.
Timestamp07 Aug, 2007 @ 01:27:19
Topic ID197069 - Read/respond to PIRT commentary.
Handler Note:
07 Aug, 2007
03:47:04
LoPhatPhuud: Consumed following related reports:

[522329] http://sessionid-1721486.rbs.co.uk.line45.hk/customerdirectory/direct/ccf.aspx
[522493] http://sessionid-525393151.rbs.co.uk.line45.hk/customerdirectory/direct/ccf.aspx
[522523] http://sessionid-889769.rbs.co.uk.line45.hk/customerdirectory/direct/ccf.aspx
[522649] http://moneymanagergps.session-207077429.citizensbank.com.line45.hk/forms/clientcare.apx
Handler Note:
07 Aug, 2007
03:49:07
LoPhatPhuud: The URL accesses a phishing site with multiple fake banks.
IP address 219.240.198.70 was active at Tue, 07 Aug 2007 03:47:30 +0000 (GMT).
Nameservers
NS1.TOWN312.HK [211.189.84.20] response 219.240.198.70 in 148 mSec
NS2.TOWN312.HK [202.142.157.41] response 219.240.198.70 in 358 mSec
were active at the same time
Handler Note:
07 Aug, 2007
03:53:05
LoPhatPhuud: REGISTRAR HKDNR:
Domains LINE45.HK, TOWN312.HK have been registered with HKDNR for fraudulent purposes.
They are part of a network of phishing sites with multiple fake banks.
Please suspend these domains immediately to prevent further criminal activity.
Please also check for any domains registered using the same (stolen) identity and credit card details, or the same email address.
Handler Note:
07 Aug, 2007
03:54:24
LoPhatPhuud: HOST Hanaro Telecom Inc:
The machine at IP address
219.240.198.70
is acting as proxy for the real server for these criminal websites. Please shut it down.
PLEASE check the logs for this IP to find the address that it was forwarding
requests to at the time given above , and pass the information to us or to Law Enforcement.
Handler Note:
07 Aug, 2007
03:57:14
LoPhatPhuud: View CIDR AS9318 Report: http://www.cidr-report.org/cgi-bin/as-report?as=9318

"9318 | | NA | NA | HANARO-AS Hanaro Telecom Inc."

Handler Note:
07 Aug, 2007
03:57:15
LoPhatPhuud: Extended information for AS9318:
State/Province:
Country: kr
Responsible Domain: hananet.net
Abuse Email: abuse@hananet.net
Handler Note:
07 Aug, 2007
03:58:28
LoPhatPhuud: NAMESERVER HOST Samsung Networks Inc:
Nameserver
NS1.TOWN312.HK [211.189.84.20] - response 148 mSec
has been set up on your network to serve addresses for this phishing domain and others.
No legitimate domains use this nameserver.
Please shut it down urgently.
Please close the customer's account.
If possible please also be alert for anyone setting up other nameservers on your network for this domain.
Handler Note:
07 Aug, 2007
03:58:57
LoPhatPhuud: View CIDR AS6619 Report: http://www.cidr-report.org/cgi-bin/as-report?as=6619

"6619 | KR | apnic | 2002-08-01 | SAMSUNGNETWORKS-AS-KR Samsung Networks Inc."

Handler Note:
07 Aug, 2007
03:58:57
LoPhatPhuud: Extended information for AS6619:
State/Province:
Country: kr
Responsible Domain: rnd.sec.samsung.co.kr
Abuse Email: postmaster@samsung.co.kr
Handler Note:
07 Aug, 2007
04:00:43
LoPhatPhuud: NAMESERVER HOST Gerrys Information Technology (Pvt.) Ltd:
Nameserver
NS2.TOWN312.HK [202.142.157.41] - response 358 mSec
has been set up on your network to serve addresses for this phishing domain and others.
No legitimate domains use this nameserver.
Please shut it down urgently.
Please close the customer's account.
If possible please also be alert for anyone setting up other nameservers on your network for this domain.
Handler Note:
07 Aug, 2007
04:01:08
LoPhatPhuud: View CIDR AS23750 Report: http://www.cidr-report.org/cgi-bin/as-report?as=23750

"23750 | PK | apnic | 2003-05-21 | GERRYS-AS-AP GEERRYS INFORMATION TECHNOLOGY PVT LTD."

Handler Note:
07 Aug, 2007
04:01:09
LoPhatPhuud: Extended information for AS23750:
State/Province:
Country: pk
Responsible Domain: gerrys.net
Abuse Email: postmaster@gerrys.net
Handler Note:
07 Aug, 2007
04:03:54
LoPhatPhuud: Generated and sent email phish alert to respective parties.
Handler Note:
07 Aug, 2007
23:38:13
LoPhatPhuud:
Resent to GoDaddy as BCL and included link to report but did not send the report. Trying to get around bounced mail to the private address
Auto DupePaul: Auto Consumed following related reports:

07 Aug, 2007 @ 05:00:10
[522698] http://sessionid-438075451.rbs.co.uk.line45.hk/customerdirectory/direct/ccf.aspx
07 Aug, 2007 @ 05:34:07
[522719] http://userconfirmationform-id850232.ebay.com.line45.hk/userdirectory/eBayISAPI.dll
07 Aug, 2007 @ 06:13:58
[522853] http://line45.hk/confirm/cs70_banking/sbuser
07 Aug, 2007 @ 20:55:59
[523493] http://moneymanagergps.session-73216.citizensbank.com.line45.hk/forms/clientcare.apx
Fetched URLs
Slaves522329, 522493, 522523, 522649, 522698, 522719, 522853, 523493,

Report for at 07 Aug, 2007 @ 03:45:29


fetched page

at 07 Aug, 2007 @ 03:55:00
MD5 Fingerprint: 3ca97d5944bd341adefc21e190276782
SHA1 Fingerprint: b363802a1efc682d3dd1116c4f5577b4d6c4cb54

fetched page

at 07 Aug, 2007 @ 03:55:29
MD5 Fingerprint: d8ccaaa67c24535366ff2853e76537a0
SHA1 Fingerprint: 849eea7d12e4c8e60ebd4b6441ff7a6dd7cc6cd7

fetched page

at 07 Aug, 2007 @ 03:56:24
MD5 Fingerprint: ba8096d82ddf7e3c2398de699dfd10b8
SHA1 Fingerprint: 53432704ccdc9e03b566ebbb3c9cca8b5bc49f4b

fetched page

at 27 Nov, 2007 @ 03:10:06
MD5 Fingerprint: d41d8cd98f00b204e9800998ecf8427e
SHA1 Fingerprint: da39a3ee5e6b4b0d3255bfef95601890afd80709
Version 1.0
spacer spacer