CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 934
Comments: 25
block bottom
spacer spacer PIRT Squad

Fried Phish(TM)

Phishing Incident Reporting and Termination (PIRT) Squad(SM)

A global phishing termination and intelligence system operated by CastleCops. Become a PIRT Squad terminator by reporting phish today!

[ How-To / FAQ ]

Fried Phish -> Confirmed Phish | Terminated Phish


status: terminated

HTTP Response
09 Jul, 2008
09:20:17
HTTP/1.1 404 Not Found
ID881940 (termination link)
TitleHotmail, Lloyds TSB, Orange, postbank.de
Entry
PIRT Squad
Reporter
Submitted anonymously thru the web, or sent to pirt (at) castlecops (dot) com.
Timestamp30 Jun, 2008 @ 09:13:04
Topic ID224449 - Read/respond to PIRT commentary.
Handler Note:
01 Jul, 2008
10:16:43
downie: The URL accesses a Lloyds TSB phishing site, active at the time of investigation.
A page fetch was successful.
Handler Note:
01 Jul, 2008
10:18:25
downie: View CIDR AS25973 Report: http://www.cidr-report.org/cgi-bin/as-report?as=25973

"25973 | US | arin | 2002-06-11 | MZIMA - Mzima Networks, Inc."

Handler Note:
01 Jul, 2008
10:18:25
downie: Extended information for AS25973:
State/Province: ca
Country: us
Responsible Domain: mzima.net
Abuse Email: postmaster@mzima.net
Handler Note:
01 Jul, 2008
11:35:43
downie: Postbank phish at
http://site-order4.com/sohoadmin/program/modules/site_templates/plugins/update.htm
Handler Note:
01 Jul, 2008
11:44:04
downie: Another Postbank phish at
http://site-order4.com/sohoadmin/program/modules/site_templates/includes/update.htm
Handler Note:
01 Jul, 2008
12:02:15
downie: Windows Live Hotmail (Spanish) phish at
http://site-order4.com/sohoadmin/program/modules/site_templates/pages/NEWSLETTER-Simple_Borders-Red/live.login.com/by103 w.bay103.mail.live.com/mail/ReadMessageLight.aspxAux/
Handler Note:
01 Jul, 2008
12:11:38
downie: Another Lloyds TSB phish at
http://site-order4.com/sohoadmin/program/modules/site_templates/pages/AGRICULTURE-FarmSickle_Autumn-None/loyds.tsb.updat e.das23da21ew23r/customer.php?ibc=customer.ibc
Handler Note:
01 Jul, 2008
13:03:12
downie: Generated and sent email phish alert to respective parties.
Handler Note:
04 Jul, 2008
19:03:11
downie: Orange phish at
sohoadmin/program/modules/site_templates/pages/NEUTRAL-KISS-gold/orange/index.htm
Handler Note:
10 Jul, 2008
17:46:08
downie: Consumed following related reports:

[881939] http://site-order4.com/sohoadmin/program/modules/site_templates/unzip/b.php
[890671] http://site-order4.com/sohoadmin/program/modules/site_templates/pages/AGRICULTURE-FarmSickle_Autumn-None/loyds.tsb.updat e.das23da21ew23r/customer.php?ibc=customer.ibc
Handler Note:
10 Jul, 2008
17:46:58
downie: All 404
Fetched URLs
Slaves881939, 890671,

Report for at 30 Jun, 2008 @ 09:13:05


fetched page

thumbnail
at 30 Jun, 2008 @ 09:13:15
MD5 Fingerprint: 74251f97fe35ccf1bea32e9228f135c7
SHA1 Fingerprint: 1b13ec37286eb38faf4c4f26838f2cd75c2cb9a4

fetched page

thumbnail
at 01 Jul, 2008 @ 10:16:52
MD5 Fingerprint: d41d8cd98f00b204e9800998ecf8427e
SHA1 Fingerprint: da39a3ee5e6b4b0d3255bfef95601890afd80709

fetched page

thumbnail
at 01 Jul, 2008 @ 11:35:49
MD5 Fingerprint: 1c2f2007bdcb61e0c8cd659224b58a69
SHA1 Fingerprint: efb7d621f2c862ba69698f89326fe5eac270fd4b

fetched page

thumbnail
at 01 Jul, 2008 @ 11:36:54
MD5 Fingerprint: d41d8cd98f00b204e9800998ecf8427e
SHA1 Fingerprint: da39a3ee5e6b4b0d3255bfef95601890afd80709

fetched page

thumbnail
at 01 Jul, 2008 @ 11:44:07
MD5 Fingerprint: 1c2f2007bdcb61e0c8cd659224b58a69
SHA1 Fingerprint: efb7d621f2c862ba69698f89326fe5eac270fd4b

fetched page

thumbnail
at 01 Jul, 2008 @ 11:46:16
MD5 Fingerprint: d41d8cd98f00b204e9800998ecf8427e
SHA1 Fingerprint: da39a3ee5e6b4b0d3255bfef95601890afd80709

fetched page

thumbnail
at 01 Jul, 2008 @ 12:02:18
MD5 Fingerprint: 467fefab2fb594f39c07692a6718f62f
SHA1 Fingerprint: a86d2ed638c4b93164c9895c7094abb0a4711808

fetched page

thumbnail
at 01 Jul, 2008 @ 12:06:11
MD5 Fingerprint: 05a417dfd1cebc036cb7493a97970990
SHA1 Fingerprint: 934c1cc1b73200faddf3d340009d258c062cce6f

fetched page

thumbnail
at 01 Jul, 2008 @ 12:11:41
MD5 Fingerprint: 74251f97fe35ccf1bea32e9228f135c7
SHA1 Fingerprint: 1b13ec37286eb38faf4c4f26838f2cd75c2cb9a4

fetched page

at 04 Jul, 2008 @ 19:03:11
MD5 Fingerprint: d41d8cd98f00b204e9800998ecf8427e
SHA1 Fingerprint: da39a3ee5e6b4b0d3255bfef95601890afd80709

fetched page

thumbnail
at 04 Jul, 2008 @ 19:04:49
MD5 Fingerprint: 060e21edd22631fbbbd648a4ecfbb9f2
SHA1 Fingerprint: 0068ac048b80f9de86c1b68ae95a629e779e3770

fetched page

thumbnail
at 04 Jul, 2008 @ 19:06:38
MD5 Fingerprint: 5b9ce0ddd3b7c914c1245f09a1cbac1f
SHA1 Fingerprint: 9fcafccee08ec9c5cbe3d8017c16fd3594f45879