CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

[PIRT#522534] Rock Phish LINE45.HK/TOWN312.HK

 
Post new topic   Reply to topic       All -> FavForums -> PIRT Fried Phish Reports [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
LoPhatPhuud

Security Expert
Microsoft MVP

Joined: Mar 09, 2002
Posts: 2232

MVP Phishing Squad Premium Security Experts

PostPosted: Tue Aug 07, 2007 4:03 am    Post subject: [PIRT#522534] Rock Phish LINE45.HK/TOWN312.HK
Reply with quote

Phish Alert
 
 Full Report: CastleCops Link/Citizens_Bank_GoDaddy_Rock_Phish_Royal_Bank_of_Scotland_phish522534.html
 
 Consumed following related reports:

[522329] http://sessionid-1721486.rbs.co.uk.line45.hk/customerdirectory/direct/ccf.aspx
[522493] http://sessionid-525393151.rbs.co.uk.line45.hk/customerdirectory/direct/ccf.aspx
[522523] http://sessionid-889769.rbs.co.uk.line45.hk/customerdirectory/direct/ccf.aspx
[522649] http://moneymanagergps.session-207077429.citizensbank.com.line45.hk/forms/clientcare.apx


The URL accesses a phishing site with multiple fake banks.
IP address 219.240.198.70 was active at Tue, 07 Aug 2007 03:47:30 +0000 (GMT).
Nameservers
NS1.TOWN312.HK [211.189.84.20] response 219.240.198.70 in 148 mSec
NS2.TOWN312.HK [202.142.157.41] response 219.240.198.70 in 358 mSec
were active at the same time
Changed status to confirmed phish.
REGISTRAR HKDNR:
Domains LINE45.HK, TOWN312.HK have been registered with HKDNR for fraudulent purposes.
They are part of a network of phishing sites with multiple fake banks.
Please suspend these domains immediately to prevent further criminal activity.
Please also check for any domains registered using the same (stolen) identity and credit card details, or the same email address.
HOST Hanaro Telecom Inc:
The machine at IP address
219.240.198.70
is acting as proxy for the real server for these criminal websites. Please shut it down.
PLEASE check the logs for this IP to find the address that it was forwarding
requests to at the time given above , and pass the information to us or to Law Enforcement.
IP Converted: 219.240.198.70

dword = 3689989702
hex1 = 0xdbf0c646
hex2 = 0xdb.0xf0.0xc6.0x46
oct = 0333.0360.0306.0106

View CIDR AS9318 Report: http://www.cidr-report.org/cgi-bin/as-report?as=9318

"9318 | | NA | NA | HANARO-AS Hanaro Telecom Inc."<br />

Extended information for AS9318:
State/Province:
Country: kr
Responsible Domain: hananet.net
Abuse Email: abuse@hananet.net

NAMESERVER HOST Samsung Networks Inc:
Nameserver
NS1.TOWN312.HK [211.189.84.20] - response 148 mSec
has been set up on your network to serve addresses for this phishing domain and others.
No legitimate domains use this nameserver.
Please shut it down urgently.
Please close the customer's account.
If possible please also be alert for anyone setting up other nameservers on your network for this domain.
IP Converted: 211.189.84.20

dword = 3552400404
hex1 = 0xd3bd5414
hex2 = 0xd3.0xbd.0x54.0x14
oct = 0323.0275.0124.024

View CIDR AS6619 Report: http://www.cidr-report.org/cgi-bin/as-report?as=6619

"6619 | KR | apnic | 2002-08-01 | SAMSUNGNETWORKS-AS-KR Samsung Networks Inc."<br />

Extended information for AS6619:
State/Province:
Country: kr
Responsible Domain: rnd.sec.samsung.co.kr
Abuse Email: postmaster@samsung.co.kr

NAMESERVER HOST Gerrys Information Technology (Pvt.) Ltd:
Nameserver
NS2.TOWN312.HK [202.142.157.41] - response 358 mSec
has been set up on your network to serve addresses for this phishing domain and others.
No legitimate domains use this nameserver.
Please shut it down urgently.
Please close the customer's account.
If possible please also be alert for anyone setting up other nameservers on your network for this domain.
IP Converted: 202.142.157.41

dword = 3398343977
hex1 = 0xca8e9d29
hex2 = 0xca.0x8e.0x9d.0x29
oct = 0312.0216.0235.051

View CIDR AS23750 Report: http://www.cidr-report.org/cgi-bin/as-report?as=23750

"23750 | PK | apnic | 2003-05-21 | GERRYS-AS-AP GEERRYS INFORMATION TECHNOLOGY PVT LTD."<br />

Extended information for AS23750:
State/Province:
Country: pk
Responsible Domain: gerrys.net
Abuse Email: postmaster@gerrys.net

Quote:
http://myaccount.session-59870368.godaddy.com.line45.hk/AccountConfirmation/account.aspx

Back to top
View users profile Send private message Visit posters website AIM Address Yahoo Messenger MSN Messenger
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> PIRT Fried Phish Reports All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer