SIRT Handler Premium Member Joined: Nov 20, 2003 Posts: 2705
Posted: Mon Jun 30, 2008 12:58 pm Post subject: Moldova phish
I received a phishing email for this today:
http://onlinetreasurymanager.suntrust.ibswebsuntrust.cmserver.verify0e82u52qe90p0z2.portalserver.
[insert line break for forum]
ptcontrol.SetCommunityCommunityID44809.CommunityPage.exacttarget.Login62s9k14b.members.
[insert line break for forum]
sntrst.md/login.htm
The .md TLD is Moldova's country code. The site isn't resolving. On traversal, most root servers say it has no a records, though central.dns.md, which I would expect to be the soonest to receive propagation from a domain suspension, resolves 5 IP addresses -- apparently botnet hosting. (Maybe it's still propagating a domain creation?)
China is no longer friendly to phishers; the roaches are scurring to find cover.
You can post new topics in this forum You can reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum You can attach files in this forum You can download files in this forum