CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 940
Comments: 25
block bottom
spacer spacer PIRT Squad

Fried Phish(TM)

Phishing Incident Reporting and Termination (PIRT) Squad(SM)

A global phishing termination and intelligence system operated by CastleCops. Become a PIRT Squad terminator by reporting phish today!

[ How-To / FAQ ]

Fried Phish -> Confirmed Phish | Terminated Phish


status: terminated

HTTP Response
14 May, 2008
21:58:06
HTTP/1.1 404 Not Found
ID824162 (termination link)
TitlePayPal
Entry
PIRT Squad
Reporter
Submitted anonymously thru the web, or sent to pirt (at) castlecops (dot) com.
Timestamp11 May, 2008 @ 21:55:19
Topic ID221627 - Read/respond to PIRT commentary.
Handler Note:
11 May, 2008
23:17:40
moike: Phish was active at time of investigation as a fake PayPal site
Handler Note:
11 May, 2008
23:21:34
moike: View CIDR AS21533 Report: http://www.cidr-report.org/cgi-bin/as-report?as=21533

"21533 | US | arin | 2001-05-18 | TERREMARK - Terremark Worldwide"

Handler Note:
11 May, 2008
23:21:35
moike: Extended information for AS21533:
State/Province: fl
Country: us
Responsible Domain: terremark.com
Abuse Email: security@terremark.com
Handler Note:
12 May, 2008
00:59:53
moike: Generated and sent email phish alert to respective parties.
Handler Note:
16 May, 2008
02:52:07
moike: Phish does not resolve - HTTP error 404
Handler Note:
03 Jun, 2008
00:58:55
moike: Consumed following related reports:

[840250] http://webuildwebsites.us/images22/banners/google/www.paypal.com/webscr.php?cmd=_login-run
Fetched URLs
Slaves840250,

Report for at 11 May, 2008 @ 21:56:39


fetched page

at 11 May, 2008 @ 21:56:39
MD5 Fingerprint: 1ad131ce3ce5fb02b2c6499f48bc016d
SHA1 Fingerprint: fd08e17cee7dcefea998ab8030e5abaee90a7f66

fetched page

at 11 May, 2008 @ 23:17:40
MD5 Fingerprint: 1ad131ce3ce5fb02b2c6499f48bc016d
SHA1 Fingerprint: fd08e17cee7dcefea998ab8030e5abaee90a7f66

fetched page

at 11 May, 2008 @ 23:32:47
MD5 Fingerprint: 1ad131ce3ce5fb02b2c6499f48bc016d
SHA1 Fingerprint: fd08e17cee7dcefea998ab8030e5abaee90a7f66

fetched page

at 11 May, 2008 @ 23:33:50
MD5 Fingerprint: 6e86becabc9dafc3e2869b57987328d3
SHA1 Fingerprint: b09916e339a9fc61bc8837e712ab4c525d44c53f
Version 1.0
spacer spacer