CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 934
Comments: 25
block bottom
spacer spacer PIRT Squad

Fried Phish(TM)

Phishing Incident Reporting and Termination (PIRT) Squad(SM)

A global phishing termination and intelligence system operated by CastleCops. Become a PIRT Squad terminator by reporting phish today!

[ How-To / FAQ ]

Fried Phish -> Confirmed Phish | Terminated Phish


status: parked domain

ID903109 (termination link)
TitleHalifax
Entry
PIRT Squad
Reporter
160173
Timestamp23 Jul, 2008 @ 00:28:32
Topic ID225326 - Read/respond to PIRT commentary.
Handler Note:
23 Jul, 2008
00:41:57
downie: The URL accesses a Halifax phishing site, active at the time of investigation.
A page fetch was successful.
************************************
AMENWORL/CLARANET:
Domain halifax-support.co.uk has been registered with you for phishing fraud.
Please suspend it urgently to prevent further criminal use.
PLEASE CHECK FOR DOMAINS REGISTERED WITH THE SAME (STOLEN) IDENTITY AND CREDIT-CARD DETAILS, OR THE SAME EMAIL ADDRESS.
**********************************
Handler Note:
23 Jul, 2008
00:47:12
downie: View CIDR AS8426 Report: http://www.cidr-report.org/cgi-bin/as-report?as=8426

"8426 | GB | ripencc | 1997-08-15 | CLARANET-AS ClaraNET"

Handler Note:
23 Jul, 2008
00:47:13
downie: Extended information for AS8426:
State/Province:
Country: uk
Responsible Domain: clara.net
Abuse Email: abuse@clara.net
Handler Note:
23 Jul, 2008
01:45:35
downie: Generated and sent email phish alert to respective parties.
Handler Note:
23 Jul, 2008
02:54:38
downie: Consumed following related reports:

[902292] http://www.halifax-support.co.uk/Formslogin.php?AdditionalInfo=1
Handler Note:
25 Jul, 2008
18:08:28
downie: Phish moved to
http://www.halifax-support.co.uk/Formslogin.php?AdditionalInfo=1
Fetched URLs
Slaves902292,

Report for at 23 Jul, 2008 @ 00:41:57


fetched page

at 23 Jul, 2008 @ 00:48:42
MD5 Fingerprint: dd3f912f9de2f187dc821cec7b596ef7
SHA1 Fingerprint: 2490e509051cfc927f0c1da3d7ebdd22156d199b

fetched page

at 23 Jul, 2008 @ 00:57:38
MD5 Fingerprint: 4dd39401fb760b518373f81d03fbadfc
SHA1 Fingerprint: d5944700ec7738eb9d2792dee9917c2ab2f0cd80

fetched page

at 23 Jul, 2008 @ 01:01:07
MD5 Fingerprint: 7f5a8ef5284db4ccd3c1a432ef9a773e
SHA1 Fingerprint: 7d5ae7e3bcaa08626dab743f05f79e6ae6f75947

fetched page

at 25 Jul, 2008 @ 18:08:32
MD5 Fingerprint: dd3f912f9de2f187dc821cec7b596ef7
SHA1 Fingerprint: 2490e509051cfc927f0c1da3d7ebdd22156d199b
Version 1.0
spacer spacer