Oldfrog
Special Response Team
 Joined: Jun 27, 2004 Posts: 8575 Location: Deep in the Heart of Texas
|
Posted: Thu Mar 30, 2006 7:26 pm Post subject: Fried Phish Mar 30: PayPal @ Yahoo (US) |
|
|
Phish Alert Full Report: /modules.php?name=Fried_Phish&fp=phish&id=1589&in=1 The email hyperlink directs to a US server hosting an imitation PayPal login screen. The site was active at the time of investigation.
Dig A on the domain reveals six A records all on the same Yahoo netblock.
;; ANSWER SECTION:
arvecast.info. 600 IN A 216.39.58.63
arvecast.info. 600 IN A 216.39.58.64
arvecast.info. 600 IN A 216.39.58.65
arvecast.info. 600 IN A 216.39.58.66
arvecast.info. 600 IN A 216.39.58.48
arvecast.info. 600 IN A 216.39.58.62 View CIDR AS14779 Report: http://www.cidr-report.org/cgi-bin/as-report?as=14779
"14779 | US | arin | 2000-02-07 | INKTOMI-LAWSON - Inktomi Corporation"<br />
| Quote: |
From Thu Mar 30 13:54:53 2006
Received: from tombraider.mr.itd.umich.edu (smtp.mail.umich.edu [141.211.93.161])
by bugsbunny.castlecops.com (8.13.6/8.13.6) with ESMTP id k2UIsqmv030916
for <>; Thu, 30 Mar 2006 13:54:53 -0500
Received: FROM stargate.gpcc.itd.umich.edu (stargate.gpcc.itd.umich.edu [141.211.2.169])
BY tombraider.mr.itd.umich.edu ID 442C2984.3ABEC.26724 ;
30 Mar 2006 13:55:00 -0500
X-Received: FROM dave.mr.itd.umich.edu (dave.mr.itd.umich.edu [141.211.14.70])
BY stargate.gpcc.itd.umich.edu ID 442C294D.D236E.31741 ;
30 Mar 2006 13:54:05 -0500
X-Received: FROM 192.168.1.10 (mail.page-partners.com [65.65.171.245])
BY dave.mr.itd.umich.edu ID 442C27DE.F3EBA.27957 ;
30 Mar 2006 13:48:02 -0500
X-Received: from 52.1 |
|
|