CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 934
Comments: 25
block bottom
spacer spacer PIRT Squad

Fried Phish(TM)

Phishing Incident Reporting and Termination (PIRT) Squad(SM)

A global phishing termination and intelligence system operated by CastleCops. Become a PIRT Squad terminator by reporting phish today!

[ How-To / FAQ ]

Fried Phish -> Confirmed Phish | Terminated Phish


status: terminated

HTTP Response
15 Jul, 2008
02:13:44
HTTP/1.1 404 Not Found
ID879702 (termination link)
TitleAbbey Bank, Bank of America, Lloyds TSB, NatWest, Orange, Wells Fargo
Entry
PIRT Squad
Reporter
160173
Timestamp27 Jun, 2008 @ 01:25:18
Topic ID224201 - Read/respond to PIRT commentary.
Handler Note:
27 Jun, 2008
01:29:14
downie: The URL accesses a Wachovia phishing site, active at the time of investigation.
A page fetch was successful.
Handler Note:
27 Jun, 2008
01:32:01
downie: View CIDR AS9758 Report: http://www.cidr-report.org/cgi-bin/as-report?as=9758

"9758 | KR | apnic | 1999-12-10 | HANNET-AS Serverbank"

Handler Note:
27 Jun, 2008
01:32:01
downie: Extended information for AS9758:
State/Province:
Country: kr
Responsible Domain: e-serverbank.com
Abuse Email: abuse@e-serverbank.com
Handler Note:
27 Jun, 2008
01:37:34
downie: Wells Fargo phish at
http://aum.co.kr/in/wells/
Handler Note:
27 Jun, 2008
01:43:36
downie: Another Wells Fargo phish at
http://aum.co.kr/rest/
Handler Note:
27 Jun, 2008
01:54:01
downie: Abbey Bank phish at
http://www.aum.co.kr/run/submit.php?cmd=validate
Handler Note:
27 Jun, 2008
02:47:39
downie: Orange phish at
http://www.aum.co.kr/log/images/bit/online/index.htm
Handler Note:
27 Jun, 2008
03:29:39
downie: Generated and sent email phish alert to respective parties.
Handler Note:
27 Jun, 2008
05:17:11
downie: All 404
Handler Note:
27 Jun, 2008
17:31:48
downie: New Bank of America phish at
http://aum.co.kr/help/bofa/
Handler Note:
28 Jun, 2008
01:56:17
downie: NatWest phish at
http://aum.co.kr/noname/bbs/table/notice/upload/Natwest.Com/natwest/default.php?refererident=29D46E&3F9236B44B3170FA 17BB9739036F896327&cookieid=41&noscr=false&CookieCheck=2008-06-28T10:52:13
Handler Note:
28 Jun, 2008
02:03:47
downie: Another BofA phish at
http://aum.co.kr/pds/
Handler Note:
28 Jun, 2008
02:09:04
downie: There is another NatWest phish at
http://aum.co.kr/Natwest.Com/natwest/default.php?refererident=29D46E&3F9236B44B3170FA17BB9739036F896327&cookieid =41&noscr=false&CookieCheck=2008-06-28T11:08:20
Handler Note:
29 Jun, 2008
00:13:50
downie: New Lloyds TSB phish at
http://www.aum.co.kr/login/lloydstsb/ibc.php?WTsvl=ibcplogon
Handler Note:
29 Jun, 2008
00:45:41
downie: Moved to
http://lloydstsb-co-uk.aum.co.kr/login/lloydstsb/ibc.php?WTsvl=ibcplogon
or
http://aum.co.kr/lloydstsb-co-uk/login/lloydstsb/ibc.php?WTsvl=ibcplogon
Handler Note:
01 Jul, 2008
01:41:36
downie: ********WARNING THERE IS MALWARE ON THIS SITE.*************
Handler Note:
01 Jul, 2008
19:35:40
downie: New Wells Fargo phish at
http://www.aum.co.kr/install/security-update/youraccounts/
New BofA phish at
http://aum.co.kr/www.bankofamerica.com/bofa/
Handler Note:
03 Jul, 2008
10:52:52
downie: New Lloyds TSB phish at
http://aum.co.kr/img/www.lloydstsb.com/www.lloydstsb.com/ibc.php?WTsvl=ibcplogon
Handler Note:
03 Jul, 2008
10:54:13
downie: New NatWest phish at
http://aum.co.kr/js/Natwest.Com/natwest/default.php?refererident=29D46E&3F9236B44B3170FA17BB9739036F896327&cooki eid=41&noscr=false&CookieCheck=2008-07-3T7:53:25
Handler Note:
04 Jul, 2008
14:16:50
downie: Wells Fargo phish moved to
http://aum.co.kr//file/security-update/youraccounts/
Handler Note:
05 Jul, 2008
21:32:40
downie: New Lloyds TSB phish at
http://aum.co.kr/root/cgi/2%20page/customer.html
Handler Note:
06 Jul, 2008
12:59:41
downie: New Lloyds TSB phish at
http://aum.co.kr/webmemo/S1A/ibc.php?WTsvl=ibcplogon
Handler Note:
08 Jul, 2008
23:54:04
downie: Suspended
Handler Note:
09 Jul, 2008
19:44:16
downie: Just http://aum.co.kr/noname/bbs/table/notice/upload/Natwest.Com/natwest/default.php?refererident=29D46E&3F9236B44B3170FA 17BB9739036F896327&cookieid=41&noscr=false&CookieCheck=2008-07-10T4:35:01
and http://aum.co.kr/pds/
remaining
Fetched URLs

Report for at 27 Jun, 2008 @ 01:25:19


fetched page

thumbnail
at 27 Jun, 2008 @ 01:25:44
MD5 Fingerprint: 1166b1c6359c6aa252d90f7eb1acbdd6
SHA1 Fingerprint: 328e9ef375a6a8b46b47e1c2d875869f0ecc0112

fetched page

thumbnail
at 27 Jun, 2008 @ 01:29:20
MD5 Fingerprint: b873fd7e842e54ebabc970035a0734fc
SHA1 Fingerprint: 58dae5a90f414814b4178b8c34a9f29aafce6ed9