CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 937
Comments: 25
block bottom
spacer spacer PIRT Squad

Fried Phish(TM)

Phishing Incident Reporting and Termination (PIRT) Squad(SM)

A global phishing termination and intelligence system operated by CastleCops. Become a PIRT Squad terminator by reporting phish today!

[ How-To / FAQ ]

Fried Phish -> Confirmed Phish | Terminated Phish


status: terminated

ID901843 (termination link)
TitleANZ Bank, Bank of America, HSBC, St. George Bank
Entry
PIRT Squad
Reporter
Submitted anonymously thru the web, or sent to pirt (at) castlecops (dot) com.
Timestamp21 Jul, 2008 @ 15:47:26
Topic ID225327 - Read/respond to PIRT commentary.
Handler Note:
23 Jul, 2008
04:33:23
downie: Consumed following related reports:

[901486] http://www.heavenlyvisitation.com/sec/www.hsbc.co.uk/hsbc/1.php?jsessionid=CAM10:jsessionid=0000RcSVT4vYF7HNB8AsppR8HRo: 11j71fovq?IDV_URL=hsbc.MyHSBC_pib
Handler Note:
23 Jul, 2008
04:51:26
downie: The URL accesses a Bank of America phishing site, active at the time of investigation.
A page fetch was successful.
There is another BofA phish at
http://www.heavenlyvisitation.com/sec/BankofAmerica.Com1/bankofamerica/signon.php?section=signinpage&update=&coo kiecheck=yes&destination=nba/signin
There is an HSBC phish at
http://www.heavenlyvisitation.com/sec/www.hsbc.co.uk/hsbc/1.php?jsessionid=CAM10:jsessionid=0000RcSVT4vYF7HNB8AsppR8HRo: 11j71fovq?IDV_URL=hsbc.MyHSBC_pib
There is a Verified by Visa phish at
http://www.heavenlyvisitation.com/sec/usa.visa.com/usa.visa.com/
There are St.George Bank phish at
http://www.heavenlyvisitation.com/sec/Stgeorge.Com.Au/stgeorge/logon.php?safeAndSecurepage=Y&bhcp=1
http://www.heavenlyvisitation.com/sec/Stgeorge.Com/logon.php?safeAndSecurepage=Y&bhcp=1
http://www.heavenlyvisitation.com/sec/www.stgeorge.com/logon.php?safeAndSecurepage=Y&bhcp=1
Handler Note:
23 Jul, 2008
04:56:31
downie: View CIDR AS15055 Report: http://www.cidr-report.org/cgi-bin/as-report?as=15055

"15055 | US | arin | 2007-07-05 | YOURCOLO-AS-1 - FastPC Inc."

Handler Note:
23 Jul, 2008
04:56:32
downie: Extended information for AS15055:
State/Province: ny
Country: us
Responsible Domain: worldnet.att.net
Abuse Email: security@worldnet.att.net
Handler Note:
23 Jul, 2008
05:41:29
downie: ANZ phish at
http://www.heavenlyvisitation.com/swi/_vti_cnf/anz.com/anz.com/ANZ/Bankmain.htm
Handler Note:
23 Jul, 2008
05:48:52
downie: Generated and sent email phish alert to respective parties.
Handler Note:
24 Jul, 2008
17:24:04
downie: All 404
Fetched URLs
Slaves901486,

Report for at 23 Jul, 2008 @ 04:33:23


fetched page

at 23 Jul, 2008 @ 04:54:30
MD5 Fingerprint: 0378c9c28591ab035d41f18b06bfb5a9
SHA1 Fingerprint: 9818dd7526f4033952bca525237035d547ed18fc

fetched page

at 23 Jul, 2008 @ 04:58:33
MD5 Fingerprint: 051a390479b0ec022254031a906251f4
SHA1 Fingerprint: fb1373246687cbf8d5c12f1e449a29e1388bf317

fetched page

at 23 Jul, 2008 @ 05:01:00
MD5 Fingerprint: 2287462fbf46e87b164d6322d1349d58
SHA1 Fingerprint: 8798227890b4906e09ccb81c9af31d2be9e064f8

fetched page

at 23 Jul, 2008 @ 05:07:38
MD5 Fingerprint: 68b1aabe921ae5dab4c0a4cc89f65acf
SHA1 Fingerprint: fc6a423afa95e8cc66ce225a3fe01469856616bb

fetched page

at 23 Jul, 2008 @ 05:10:13
MD5 Fingerprint: 8dad2a4046041eede42e801660025478
SHA1 Fingerprint: 561dd1d1dca91c315961dc084b14b843fb23b4e7

fetched page

at 23 Jul, 2008 @ 05:41:30
MD5 Fingerprint: 35f12b729e57fc00507ab66aacbc7ae8
SHA1 Fingerprint: 0780ce18ea7556c6459df29f491d10dc8a01c0da