CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 937
Comments: 25
block bottom
spacer spacer PIRT Squad

Fried Phish(TM)

Phishing Incident Reporting and Termination (PIRT) Squad(SM)

A global phishing termination and intelligence system operated by CastleCops. Become a PIRT Squad terminator by reporting phish today!

[ How-To / FAQ ]

Fried Phish -> Confirmed Phish | Terminated Phish


status: terminated

ID903691 (termination link)
TitleWachovia, Wells Fargo
Entry
PIRT Squad
Reporter
Submitted anonymously thru the web, or sent to pirt (at) castlecops (dot) com.
Timestamp23 Jul, 2008 @ 15:41:53
Topic ID225354 - Read/respond to PIRT commentary.
Handler Note:
24 Jul, 2008
00:14:16
downie: The URL accesses a Wachovia phishing site, active at the time of investigation.
A page fetch was successful.
Handler Note:
24 Jul, 2008
00:22:43
downie: View CIDR AS29131 Report: http://www.cidr-report.org/cgi-bin/as-report?as=29131

"29131 | GB | ripencc | 2003-06-11 | RAPIDSWITCH-AS RapidSwitch Ltd"

Handler Note:
24 Jul, 2008
00:22:44
downie: Extended information for AS29131:
State/Province:
Country:
Responsible Domain: 49services.com
Abuse Email: postmaster@49services.com
Handler Note:
24 Jul, 2008
01:25:12
downie: There is anothe Wachovia phish at
http://dev.01s.in/dev/portal/WebCalendar/includes/classes/www.wachovia.com/AuthService.php?action=presentLogin&url=h ttps%3a//onlineservices.wachovia.com/NASApp/NavApp/Titanium%3faction%3dreturnHome
There is a Wells Fargo phish at
http://dev.01s.in/dev/portal/WebCalendar/includes/js/confirmation/index.html
Handler Note:
24 Jul, 2008
02:05:11
downie: Generated and sent email phish alert to respective parties.
Handler Note:
24 Jul, 2008
17:48:19
downie: All 404
Fetched URLs

Report for at 24 Jul, 2008 @ 00:14:16


fetched page

at 24 Jul, 2008 @ 00:14:19
MD5 Fingerprint: 4e3315edfb06d3bd45de8d3041585c6a
SHA1 Fingerprint: 6bf77eb9e3b2d40216e85cebe983875771fc7c6e

fetched page

at 24 Jul, 2008 @ 00:20:37
MD5 Fingerprint: 046ad0a5c1b59ddb5134f25b437d5404
SHA1 Fingerprint: 0f9b707ee90e32289df8b320c774c8ef28200d47

fetched page

at 24 Jul, 2008 @ 01:25:13
MD5 Fingerprint: 4e3315edfb06d3bd45de8d3041585c6a
SHA1 Fingerprint: 6bf77eb9e3b2d40216e85cebe983875771fc7c6e

fetched page

at 24 Jul, 2008 @ 01:47:32
MD5 Fingerprint: 97e5a2fce10e2fb01a8e0d7cbb7a712e
SHA1 Fingerprint: 5fd6fc8a438713758c6ac18efa0c03f3c16a8248

fetched page

at 24 Jul, 2008 @ 01:52:12
MD5 Fingerprint: dca9f4baab4b4434c5997dc72e035db2
SHA1 Fingerprint: 0b30333c2644978258db7d9fee90c30ed68d2b1b

fetched page

at 24 Jul, 2008 @ 01:55:20
MD5 Fingerprint: d41d8cd98f00b204e9800998ecf8427e
SHA1 Fingerprint: da39a3ee5e6b4b0d3255bfef95601890afd80709

fetched page

at 24 Jul, 2008 @ 02:03:33
MD5 Fingerprint: dbb6f2d63af34014034e8443690860af
SHA1 Fingerprint: cb48d378951233cbb1dc9053a722d4866ffd361f

fetched page

at 24 Jul, 2008 @ 02:37:52
MD5 Fingerprint: d41d8cd98f00b204e9800998ecf8427e
SHA1 Fingerprint: da39a3ee5e6b4b0d3255bfef95601890afd80709
Version 1.0
spacer spacer