CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 934
Comments: 25
block bottom
spacer spacer PIRT Squad

Fried Phish(TM)

Phishing Incident Reporting and Termination (PIRT) Squad(SM)

A global phishing termination and intelligence system operated by CastleCops. Become a PIRT Squad terminator by reporting phish today!

[ How-To / FAQ ]

Fried Phish -> Confirmed Phish | Terminated Phish


status: terminated

HTTP Response
08 Jul, 2008
06:23:16
HTTP/1.1 200 OK
ID887149 (termination link)
TitleBank of Montreal, Lloyds TSB, Regions Bank, Royal Bank of Scotland, Scotia Bank, Wachovia, Wells Fargo, Yorkshire Bank
Entry
PIRT Squad
Reporter
Submitted anonymously thru the web, or sent to pirt (at) castlecops (dot) com.
Timestamp05 Jul, 2008 @ 06:00:24
Topic ID224684 - Read/respond to PIRT commentary.
Handler Note:
06 Jul, 2008
00:34:17
downie: Consumed following related reports:

[886330] http://www.infofiesta.com/web/administrator/includes/pcl/update.htm
[887360] http://infofiesta.com/web/components/com_magazine/bmo.php
[887383] http://infofiesta.com/web/html/components/com_poll/index.htm
Handler Note:
06 Jul, 2008
00:37:06
downie: The URL accesses a Lloyds TSB phishing site, active at the time of investigation.
A page fetch was successful.
There is a WAchovia phish at
http://infofiesta.com/web/html/components/com_poll/index.htm
There is a BMO phish at
http://infofiesta.com/web/components/com_magazine/bmo.php
There is a Wells Fargo phish at
http://www.infofiesta.com/web/administrator/includes/pcl/update.htm
Handler Note:
06 Jul, 2008
00:39:30
downie: View CIDR AS27823 Report: http://www.cidr-report.org/cgi-bin/as-report?as=27823

"27823 | AR | lacnic | 2006-05-12 | Dattatec.com"

Handler Note:
06 Jul, 2008
00:39:31
downie: Extended information for AS27823:
State/Province:
Country: ar
Responsible Domain: dattatec.com
Abuse Email: marketing@dattatec.com
Handler Note:
06 Jul, 2008
02:04:43
downie: Yorkshire Bank phish at
http://infofiesta.com/portal/components/com_zoom/lib/home.ybonline.co.uk/index.html
Handler Note:
06 Jul, 2008
02:12:28
downie: Regions Bank phish at
http://infofiesta.com/web/editor/Login.htm
Handler Note:
06 Jul, 2008
02:32:45
downie: Generated and sent email phish alert to respective parties.
Handler Note:
06 Jul, 2008
15:49:33
downie: Royal Bank of Scotland phish at
http://infofiesta.com/web/language/cgi.php
Handler Note:
06 Jul, 2008
19:05:31
downie: Scotiabank phish at
http://infofiesta.com/portal/images/scotiaenliea.html
Handler Note:
09 Jul, 2008
00:04:49
downie: Site offline
Fetched URLs
Slaves886330, 887360, 887383,

Report for at 05 Jul, 2008 @ 06:23:10


fetched page

thumbnail
at 05 Jul, 2008 @ 06:23:14
MD5 Fingerprint: d94d874e8f5c655d795fe431d7944693
SHA1 Fingerprint: 6fc4106b0ff7f753a95f1e7477a6eaaa6cdd284c

fetched page

thumbnail
at 06 Jul, 2008 @ 00:39:34
MD5 Fingerprint: d41d8cd98f00b204e9800998ecf8427e
SHA1 Fingerprint: da39a3ee5e6b4b0d3255bfef95601890afd80709

fetched page

thumbnail
at 06 Jul, 2008 @ 00:42:18
MD5 Fingerprint: 6e404c7d6f9f1d30d0916ede4470166e
SHA1 Fingerprint: 6e6a9d66314e2051fe86c0aa1bcdc1d3961f3613

fetched page

thumbnail
at 06 Jul, 2008 @ 00:43:40
MD5 Fingerprint: 8b02a06b2f1204311d13d6d30ae1dd40
SHA1 Fingerprint: 469a65869989227c57c19c0ceb179b190b56753d