LoPhatPhuud: The URL accesses a phishing site with multiple fake banks.
IP address 219.240.198.70 was active at Tue, 07 Aug 2007 03:47:30 +0000 (GMT).
Nameservers
NS1.TOWN312.HK [211.189.84.20] response 219.240.198.70 in 148 mSec
NS2.TOWN312.HK [202.142.157.41] response 219.240.198.70 in 358 mSec
were active at the same time
Handler Note: 07 Aug, 2007 03:53:05
LoPhatPhuud: REGISTRAR HKDNR:
Domains LINE45.HK, TOWN312.HK have been registered with HKDNR for fraudulent purposes.
They are part of a network of phishing sites with multiple fake banks.
Please suspend these domains immediately to prevent further criminal activity.
Please also check for any domains registered using the same (stolen) identity and credit card details, or the same email
address.
Handler Note: 07 Aug, 2007 03:54:24
LoPhatPhuud: HOST Hanaro Telecom Inc:
The machine at IP address
219.240.198.70
is acting as proxy for the real server for these criminal websites. Please shut it down.
PLEASE check the logs for this IP to find the address that it was forwarding
requests to at the time given above , and pass the information to us or to Law Enforcement.
"9318 | | NA | NA | HANARO-AS Hanaro Telecom Inc."
Handler Note: 07 Aug, 2007 03:57:15
LoPhatPhuud: Extended information for AS9318:
State/Province:
Country: kr
Responsible Domain: hananet.net
Abuse Email: abuse@hananet.net
Handler Note: 07 Aug, 2007 03:58:28
LoPhatPhuud: NAMESERVER HOST Samsung Networks Inc:
Nameserver
NS1.TOWN312.HK [211.189.84.20] - response 148 mSec
has been set up on your network to serve addresses for this phishing domain and others.
No legitimate domains use this nameserver.
Please shut it down urgently.
Please close the customer's account.
If possible please also be alert for anyone setting up other nameservers on your network for this domain.
LoPhatPhuud: Extended information for AS6619:
State/Province:
Country: kr
Responsible Domain: rnd.sec.samsung.co.kr
Abuse Email: postmaster@samsung.co.kr
Handler Note: 07 Aug, 2007 04:00:43
LoPhatPhuud: NAMESERVER HOST Gerrys Information Technology (Pvt.) Ltd:
Nameserver
NS2.TOWN312.HK [202.142.157.41] - response 358 mSec
has been set up on your network to serve addresses for this phishing domain and others.
No legitimate domains use this nameserver.
Please shut it down urgently.
Please close the customer's account.
If possible please also be alert for anyone setting up other nameservers on your network for this domain.
LoPhatPhuud: Extended information for AS23750:
State/Province:
Country: pk
Responsible Domain: gerrys.net
Abuse Email: postmaster@gerrys.net
Handler Note: 07 Aug, 2007 04:03:54
LoPhatPhuud: Generated and sent email phish alert to respective parties.
Handler Note: 07 Aug, 2007 23:38:13
LoPhatPhuud:
Resent to GoDaddy as BCL and included link to report but did not send the report. Trying to get around bounced mail to
the private address