CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 937
Comments: 25
block bottom
spacer spacer PIRT Squad

Fried Phish(TM)

Phishing Incident Reporting and Termination (PIRT) Squad(SM)

A global phishing termination and intelligence system operated by CastleCops. Become a PIRT Squad terminator by reporting phish today!

[ How-To / FAQ ]

Fried Phish -> Confirmed Phish | Terminated Phish


status: terminated

HTTP Response
28 May, 2008
06:24:58
HTTP/1.1 302 Found
HTTP/1.1 200 OK
ID822677 (termination link)
TitlePayPal
Entry
PIRT Squad
Reporter
Submitted anonymously thru the web, or sent to pirt (at) castlecops (dot) com.
Timestamp10 May, 2008 @ 05:36:58
Topic ID221608 - Read/respond to PIRT commentary.
Handler Note:
11 May, 2008
17:18:36
downie: The URL accesses a PayPal phishing site, active at the time of investigation.
A page fetch was successful.
Handler Note:
11 May, 2008
17:29:16
downie: Generated and sent email phish alert to respective parties.
Handler Note:
11 May, 2008
17:32:36
downie: sh ip bgp 222.255.237.158
BGP routing table entry for 222.255.224.0/19, version 628474482
Paths: (2 available, best #2, table Default-IP-Routing-Table)
Not advertised to any peer
701 7643
205.171.0.107 (metric 15) from 205.171.0.150 (205.171.0.150)
Origin IGP, metric 10000, localpref 80, valid, internal
Community: 209:888
Originator: 205.171.0.107, Cluster list: 205.171.0.149
701 7643
205.171.0.107 (metric 15) from 205.171.0.149 (205.171.0.149)
Origin IGP, metric 10000, localpref 80, valid, internal, best
Community: 209:888
Originator: 205.171.0.107, Cluster list: 205.171.0.149
Handler Note:
11 May, 2008
17:33:12
downie: View CIDR AS7643 Report: http://www.cidr-report.org/cgi-bin/as-report?as=7643

"7643 | VN | apnic | 1997-10-14 | VNN-AS-AP Vietnam Posts and Telecommunications (VNPT)"

Handler Note:
11 May, 2008
17:33:13
downie: Extended information for AS7643:
State/Province:
Country: vn
Responsible Domain: vnn.vn
Abuse Email: abuse@vnn.vn
Handler Note:
29 May, 2008
00:16:46
downie: Site suspended
Fetched URLs

Report for at 10 May, 2008 @ 05:53:16


fetched page

at 10 May, 2008 @ 05:53:20
MD5 Fingerprint: 03f47374651f2664fc1765a4ad1cf381
SHA1 Fingerprint: 4b7e7a983e29ed68cafca4b522f68d739c2dd655

fetched page

at 11 May, 2008 @ 17:18:59
MD5 Fingerprint: c62de2cb397aab0d146fd5834b28b1e0
SHA1 Fingerprint: 4bd62f7ff469f31281b4b5c681abde099d170278
Version 1.0
spacer spacer