<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-26986700</id><updated>2011-12-14T18:34:26.948-08:00</updated><title type='text'>Mr. Phish Finder</title><subtitle type='html'>This blog is here to track down and expose the scambags behind the bogus scam email known as "phishing".</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://phish-finder.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26986700/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://phish-finder.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Mr. Phish Finder</name><uri>http://www.blogger.com/profile/07920773754442475692</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>12</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-26986700.post-114732308431794440</id><published>2006-05-10T21:38:00.000-07:00</published><updated>2006-05-10T21:51:24.900-07:00</updated><title type='text'>Romania emailed me with some pfresh phish!</title><content type='html'>Romania emailed me with some pfresh phish!&lt;br /&gt;&lt;br /&gt;Oh Dear another eBay unpaid item dispute today! Whatever shall I do.&lt;br /&gt;&lt;br /&gt;Here is the latest scam to hit my inbox today.&lt;br /&gt;&lt;br /&gt;Looks like the client sending this is in Romania : 86-107-49-159.asconet.ro (86.107.49.159)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;X-Apparently-To:     mrlinuxhead@yahoo.com via 68.142.200.99; Wed, 10 May 2006 17:26:38 -0700&lt;br /&gt;X-Originating-IP:    [63.247.69.130]&lt;br /&gt;Return-Path:    &lt;aw-confirm@ebay.com&gt;&lt;br /&gt;Authentication-Results:    mta180.mail.re4.yahoo.com from=ebay.com; domainkeys=neutral (no sig)&lt;br /&gt;Received:    from 63.247.69.130 (EHLO server3.unifiedns.com) (63.247.69.130) by mta180.mail.re4.yahoo.com with SMTP; Wed, 10 May 2006 17:26:36 -0700&lt;br /&gt;Received:    from 86-107-49-159.asconet.ro ([86.107.49.159] helo=User) by server3.unifiedns.com with esmtpa (Exim 4.52) id 1Fdz0J-0006v8-EQ; Wed, 10 May 2006 20:26:07 -0400&lt;br /&gt;Reply-to:    &lt;aw-confirm@ebay.com&gt;&lt;br /&gt;From:    "eBay" &lt;aw-confirm@ebay.com&gt;  Add to Address BookAdd to Address Book  Add Mobile Alert&lt;br /&gt;Subject:    eBay Unpaid Item Dispute #4870988286 -- response required&lt;br /&gt;Date:    Thu, 11 May 2006 03:27:55 +0300&lt;br /&gt;MIME-Version:    1.0&lt;br /&gt;Content-Type:    text/html; charset="Windows-1251"&lt;br /&gt;Content-Transfer-Encoding:    7bit&lt;br /&gt;X-Priority:    3&lt;br /&gt;X-MSMail-Priority:    Normal&lt;br /&gt;X-Mailer:    Microsoft Outlook Express 6.00.2600.0000&lt;br /&gt;X-MimeOLE:    Produced By Microsoft MimeOLE V6.00.2600.0000&lt;br /&gt;X-AntiAbuse:    This header was added to track abuse, please include it with any abuse report&lt;br /&gt;X-AntiAbuse:    Primary Hostname - server3.unifiedns.com&lt;br /&gt;X-AntiAbuse:    Original Domain - yahoo.com&lt;br /&gt;X-AntiAbuse:    Originator/Caller UID/GID - [0 0] / [47 12]&lt;br /&gt;X-AntiAbuse:    Sender Address Domain - ebay.com&lt;br /&gt;X-Source:  &lt;br /&gt;X-Source-Args:  &lt;br /&gt;X-Source-Dir:  &lt;br /&gt;Content-Length:    688&lt;br /&gt;&lt;br /&gt;eBay Unpaid Item Dispute #4870988286 -- response required   &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Dear member,&lt;br /&gt;&lt;br /&gt;eBay member alkaza has indicated that they already paid for item #4870988286&lt;br /&gt;&lt;br /&gt;Review the submitted details regarding the payment.&lt;br /&gt;&lt;br /&gt;Regards,&lt;br /&gt;eBay International AG&lt;br /&gt;&lt;br /&gt;Here is the URL of the scammers:&lt;br /&gt;http://shop.whg-walzstahl.de/.sign/eBayISAPI.dllSignInco_partnerIdpUserIdsiteidpageTypepa1i1bshowgifUsingSSL862984con462msgMNSIEhufem37ajhd84Sllencrypt378/signin.ebay.com/&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Lets look these up.&lt;br /&gt;&lt;br /&gt;Client is here:&lt;br /&gt;&lt;a href="http://www.dnsstuff.com/tools/ipall.ch?domain=86.107.49.159"&gt;http://www.dnsstuff.com/tools/ipall.ch?domain=86.107.49.159&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;IP address:                     86.107.49.159&lt;br /&gt;Reverse DNS:                    86-107-49-159.asconet.ro.&lt;br /&gt;Reverse DNS authenticity:       [Verified]&lt;br /&gt;ASN:                            0&lt;br /&gt;ASN Name:                       IANA-RSVD-0&lt;br /&gt;IP range connectivity:          0&lt;br /&gt;Registrar (per ASN):            Unknown&lt;br /&gt;Country (per IP registrar):     RO [Romania]&lt;br /&gt;Country Currency:               ROL [Romania Lei]&lt;br /&gt;Country IP Range:               86.104.0.0 to 86.107.255.255&lt;br /&gt;Country fraud profile:          High&lt;br /&gt;&lt;br /&gt;ISP info in Romania as follows:&lt;br /&gt;&lt;br /&gt;inetnum:        86.107.48.0 - 86.107.55.255&lt;br /&gt;netname:        SC-ASCO-SYSTEMS-SRL&lt;br /&gt;descr:          SC Asco Systems SRL&lt;br /&gt;descr:          Calea Dumbravii nr.89&lt;br /&gt;descr:          Sibiu 550399 Romania&lt;br /&gt;country:        ro&lt;br /&gt;admin-c:        AN951-RIPE&lt;br /&gt;tech-c:         AN951-RIPE&lt;br /&gt;status:         ASSIGNED PA&lt;br /&gt;remarks:        Registered trough http://www.jump.ro/ip.html&lt;br /&gt;mnt-by:         RO-MNT&lt;br /&gt;mnt-lower:      RO-MNT&lt;br /&gt;mnt-routes:     ASCONET-MNT&lt;br /&gt;changed:        hostmaster@jump.ro 20051114&lt;br /&gt;source:         RIPE&lt;br /&gt;&lt;br /&gt;role:           Asconet NOC&lt;br /&gt;address:        Calea Dumnbravii nr.89&lt;br /&gt;address:        550399 Sibiu, Romania&lt;br /&gt;phone:          +40269233914&lt;br /&gt;phone:          +40369591003&lt;br /&gt;phone:          +40788327170&lt;br /&gt;fax-no:         +40269214505&lt;br /&gt;org:            ORG-AA80-RIPE&lt;br /&gt;e-mail:         tech@asconet.ro&lt;br /&gt;admin-c:        EC655-RIPE&lt;br /&gt;admin-c:        OC297-RIPE&lt;br /&gt;admin-c:        SL1371-RIPE&lt;br /&gt;tech-c:         EC655-RIPE&lt;br /&gt;tech-c:         OC297-RIPE&lt;br /&gt;nic-hdl:        AN951-RIPE&lt;br /&gt;remarks:        Spam mail/news complaints: abuse@asconet.ro&lt;br /&gt;remarks:        Security complaints: abuse@asconet.ro&lt;br /&gt;remarks:        Call center (24x7) +40269233914&lt;br /&gt;abuse-mailbox:  abuse@asconet.ro&lt;br /&gt;notify:         tech@asconet.ro&lt;br /&gt;mnt-by:         ASCONET-MNT&lt;br /&gt;changed:        hostmaster@asconet.ro 20031009&lt;br /&gt;changed:        hostmaster@asconet.ro 20031010&lt;br /&gt;changed:        hostmaster@asconet.ro 20040724&lt;br /&gt;changed:        hostmaster@asconet.ro 20051016&lt;br /&gt;source:         RIPE&lt;br /&gt;&lt;br /&gt;% Information related to '86.107.48.0/21AS29523'&lt;br /&gt;&lt;br /&gt;route:          86.107.48.0/21&lt;br /&gt;descr:          Asco Networks&lt;br /&gt;origin:         AS29523&lt;br /&gt;mnt-by:         ASCONET-MNT&lt;br /&gt;changed:        hostmaster@asconet.ro 20051115&lt;br /&gt;source:         RIPE&lt;br /&gt;&lt;br /&gt;The email server is server3.unifiedns.com (63.247.69.130)&lt;a href="Link%20is%20here:%20%20http://www.dnsstuff.com/tools/ipall.ch?domain=63.247.69.130"&gt;&lt;br /&gt;&lt;/a&gt;Link is here:  &lt;a href="Link%20is%20here:%20%20http://www.dnsstuff.com/tools/ipall.ch?domain=63.247.69.130"&gt;http://www.dnsstuff.com/tools/ipall.ch?domain=63.247.69.130&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;WHOIS info for this netblock is:&lt;br /&gt;OrgName:    Global Net Access, LLC&lt;br /&gt;OrgID:      GNAL-2&lt;br /&gt;Address:    55 Marietta St, NW&lt;br /&gt;Address:    Suite 1720&lt;br /&gt;City:       Atlanta&lt;br /&gt;StateProv:  GA&lt;br /&gt;PostalCode: 30303&lt;br /&gt;Country:    US&lt;br /&gt;&lt;br /&gt;ReferralServer: rwhois://rwhois.gnax.net:4321&lt;br /&gt;&lt;br /&gt;NetRange:   63.247.64.0 - 63.247.95.255&lt;br /&gt;CIDR:       63.247.64.0/19&lt;br /&gt;NetName:    GNAXNET&lt;br /&gt;NetHandle:  NET-63-247-64-0-1&lt;br /&gt;Parent:     NET-63-0-0-0-0&lt;br /&gt;NetType:    Direct Allocation&lt;br /&gt;NameServer: DNS1.GNAX.NET&lt;br /&gt;NameServer: DNS2.GNAX.NET&lt;br /&gt;Comment:    Comment: ADDRESSES WITHIN THIS BLOCK ARE NON-PORTABLE&lt;br /&gt;Comment:    Comment: ********************************************&lt;br /&gt;Comment:    Comment: Reassignment information for this block is&lt;br /&gt;Comment:    Comment: available at rwhois.gnax.net port 4321&lt;br /&gt;Comment:    Comment: ********************************************&lt;br /&gt;RegDate:    2003-04-11&lt;br /&gt;Updated:    2004-02-06&lt;br /&gt;&lt;br /&gt;OrgAbuseHandle: ABUSE745-ARIN&lt;br /&gt;OrgAbuseName:   Abuse&lt;br /&gt;OrgAbusePhone:  +1-404-230-9150&lt;br /&gt;OrgAbuseEmail:  abuse@gnax.net&lt;br /&gt;&lt;br /&gt;WHOIS info on server3.unifiedns.com is locked. Don't know who owns the domain...&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;And the web server that's serveing up this tasty phish treat is here:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.dnsstuff.com/tools/ipall.ch?domain=83.236.133.102"&gt;http://www.dnsstuff.com/tools/ipall.ch?domain=83.236.133.102&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;IP address:                     83.236.133.102&lt;br /&gt;Reverse DNS:                    port-83-236-133-102.static.qsc.de.&lt;br /&gt;Reverse DNS authenticity:       [Verified]&lt;br /&gt;ASN:                            20676&lt;br /&gt;ASN Name:                       QSC-1 (QSC AG)&lt;br /&gt;IP range connectivity:          4&lt;br /&gt;Registrar (per ASN):            RIPE&lt;br /&gt;Country (per IP registrar):     DE [Germany]&lt;br /&gt;Country Currency:               EUR [euros]&lt;br /&gt;Country IP Range:               83.236.0.0 to 83.236.255.255&lt;br /&gt;Country fraud profile:          Normal&lt;br /&gt;City (per outside source):      Frankfurt, Hessen&lt;br /&gt;Private (internal) IP?          No&lt;br /&gt;IP address registrar:           whois.ripe.net&lt;br /&gt;Known Proxy?                    No&lt;br /&gt;Link for WHOIS:                 83.236.133.102&lt;br /&gt;&lt;br /&gt;http://shop.whg-walzstahl.de/.sign/eBayISAPI.dllSignInco_partnerIdpUserIdsiteidpageTypepa1i1bshowgifUsingSSL862984con462msgMNSIEhufem37ajhd84Sllencrypt378/signin.ebay.com/&lt;br /&gt;&lt;br /&gt;Here is a port scan. It's running Apache on Suse Linux.&lt;br /&gt;&lt;br /&gt;&lt;/aw-confirm@ebay.com&gt;&lt;/aw-confirm@ebay.com&gt;&lt;/aw-confirm@ebay.com&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://photos1.blogger.com/blogger/7050/2831/1600/83.236.133.102.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://photos1.blogger.com/blogger/7050/2831/400/83.236.133.102.jpg" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;aw-confirm@ebay.com&gt;&lt;aw-confirm@ebay.com&gt;&lt;aw-confirm@ebay.com&gt;&lt;br /&gt;The web server (shop.whg-walzstahl.de) resolves to : 83.236.133.102&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.dnsstuff.com/tools/ipall.ch?domain=83.236.133.102"&gt;http://www.dnsstuff.com/tools/ipall.ch?domain=83.236.133.102&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;This is the domain info..&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Domain:      whg-walzstahl.de&lt;br /&gt;Nserver:     ns01.qsc.de&lt;br /&gt;Nserver:     ns02.qsc.de&lt;br /&gt;Status:      connect&lt;br /&gt;Changed:     2005-12-03T07:18:29+01:00&lt;br /&gt;&lt;br /&gt;[Holder]&lt;br /&gt;Type:         PERSON&lt;br /&gt;Name:         The Company&lt;br /&gt;Address:      WHG WALZSTAHL Handels GmbH&amp;Co. KG&lt;br /&gt;Address:      Uferstr. 14&lt;br /&gt;Pcode:        45881&lt;br /&gt;City:         Gelsenkirchen&lt;br /&gt;Country:      DE&lt;br /&gt;Changed:      2005-12-03T06:58:06+01:00&lt;br /&gt;&lt;br /&gt;[Admin-C]&lt;br /&gt;Type:         PERSON&lt;br /&gt;Name:         Renate Behrs&lt;br /&gt;Address:      WHG WALZSTAHL Handels GmbH&amp;amp;Co. KG&lt;br /&gt;Address:      Uferstr. 14&lt;br /&gt;Pcode:        45881&lt;br /&gt;City:         Gelsenkirchen&lt;br /&gt;Country:      DE&lt;br /&gt;Changed:      2005-12-02T21:19:07+01:00&lt;br /&gt;&lt;br /&gt;[Tech-C][Zone-C]&lt;br /&gt;Type:         PERSON&lt;br /&gt;Name:         The BDSL-Support&lt;br /&gt;Address:      QSC AG&lt;br /&gt;Address:      Mathias-Brueggen-Str. 55&lt;br /&gt;Pcode:        50829&lt;br /&gt;City:         Koeln&lt;br /&gt;Country:      DE&lt;br /&gt;Phone:        +4942120259876&lt;br /&gt;Fax:          +494212025969&lt;br /&gt;Email:        bdsl-support@qsc.de&lt;br /&gt;Changed:      2005-09-07T09:05:08+02:00&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;And this is the netblock information:&lt;br /&gt;&lt;br /&gt;inetnum:        83.236.133.102 - 83.236.133.102&lt;br /&gt;netname:        QSC-CUSTOMER-538736-105045&lt;br /&gt;descr:          WHG Walzstahl-GmbH &amp;amp;&lt;br /&gt;country:        DE&lt;br /&gt;admin-c:        QSC1-RIPE&lt;br /&gt;tech-c:         QSC1-RIPE&lt;br /&gt;status:         ASSIGNED PA&lt;br /&gt;mnt-by:         QSC-NOC&lt;br /&gt;mnt-lower:      QSC-NOC&lt;br /&gt;changed:        inetnum-robot@qsc.de 20060331&lt;br /&gt;source:         RIPE&lt;br /&gt;&lt;br /&gt;role:         QSC Internet Services&lt;br /&gt;address:      QSC AG&lt;br /&gt;address:      Mathias-Brueggen-Str. 55&lt;br /&gt;address:      D-50829 Koeln&lt;br /&gt;address:      Germany&lt;br /&gt;phone:        +49 221 66 98 000&lt;br /&gt;fax-no:       +49 221 66 98 009&lt;br /&gt;e-mail:       abuse@qsc.de&lt;br /&gt;remarks:      ********************************************&lt;br /&gt;remarks:      QSC AG - Network Design Department&lt;br /&gt;remarks:&lt;br /&gt;remarks:      Fuer Fragen zu SPAM, Portscans, Trojanern&lt;br /&gt;remarks:      usw. wenden Sie sich bitte an abuse@qsc.de&lt;br /&gt;remarks:&lt;br /&gt;remarks:      To report SPAM/UCE/Portscans/Hacks please&lt;br /&gt;remarks:      contact abuse@qsc.de.&lt;br /&gt;remarks:&lt;br /&gt;remarks:      For peering requests, BGP policy changes&lt;br /&gt;remarks:      etc. contact peering@NOSPAM.qsc.de. For&lt;br /&gt;remarks:      Routing issues noc-ip@NOSPAM.qsc.de. Please&lt;br /&gt;remarks:      remove NOSPAM. from email address.&lt;br /&gt;remarks:      ********************************************&lt;br /&gt;admin-c:      RH168-RIPE&lt;br /&gt;tech-c:       RH168-RIPE&lt;br /&gt;tech-c:       OS101-RIPE&lt;br /&gt;tech-c:       RW590-RIPE&lt;br /&gt;tech-c:       BF359-RIPE&lt;br /&gt;tech-c:       MD1900-RIPE&lt;br /&gt;nic-hdl:      QSC1-RIPE&lt;br /&gt;mnt-by:       QSC-NOC&lt;br /&gt;changed:      rha@NOSPAM.qsc.de 20040127&lt;br /&gt;source:       RIPE&lt;br /&gt;&lt;br /&gt;% Information related to '83.236.0.0/16AS20676'&lt;br /&gt;&lt;br /&gt;route:        83.236.0.0/16&lt;br /&gt;descr:        QSC AG&lt;br /&gt;origin:       AS20676&lt;br /&gt;mnt-by:       QSC-NOC&lt;br /&gt;mnt-lower:    QSC-NOC&lt;br /&gt;changed:      ralf.weber@NOSPAM.qsc.de 20040212&lt;br /&gt;source:       RIPE&lt;br /&gt;&lt;br /&gt;OK, So email these people about the client who sent out these emails:&lt;br /&gt;&lt;br /&gt;The ISP in Romainia : abuse@asconet.ro&lt;br /&gt;The email server    : server3.unifiedns.com netblock owner abuse@gnax.net&lt;br /&gt;The web admin       : abuse@qsc.de postmaster@unifiedns.com&lt;br /&gt;&lt;br /&gt;OK jobs done. Who wants some phish for dinner?&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/aw-confirm@ebay.com&gt;&lt;/aw-confirm@ebay.com&gt;&lt;/aw-confirm@ebay.com&gt;&lt;div class="blogger-post-footer"&gt;
&lt;div class='adsense' style='text-align:center; padding: 0px 3px 0.5em 3px;'&gt;
&lt;script type="text/javascript"&gt;&lt;!--
google_ad_client="ca-pub-9456629394253923";
google_ad_width=468;
google_ad_height=60;
google_ad_format="468x60_as";
google_ad_type="text";
google_color_border="FFFFFF";
google_color_bg="FFFFFF";
google_color_link="333333";
google_color_url="333333";
google_color_text="993333";
//--&gt;&lt;/script&gt;
&lt;script type="text/javascript"
  src="http://pagead2.googlesyndication.com/pagead/show_ads.js"&gt;
&lt;/script&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26986700-114732308431794440?l=phish-finder.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phish-finder.blogspot.com/feeds/114732308431794440/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26986700&amp;postID=114732308431794440&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26986700/posts/default/114732308431794440'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26986700/posts/default/114732308431794440'/><link rel='alternate' type='text/html' href='http://phish-finder.blogspot.com/2006/05/romania-emailed-me-with-some-pfresh.html' title='Romania emailed me with some pfresh phish!'/><author><name>Mr. Phish Finder</name><uri>http://www.blogger.com/profile/07920773754442475692</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26986700.post-114717585733058731</id><published>2006-05-09T04:56:00.000-07:00</published><updated>2006-05-09T04:57:37.633-07:00</updated><title type='text'>Fresh Phish meat to hunt down and kill today!</title><content type='html'>Hi all,&lt;br /&gt;&lt;br /&gt;I love Fresh Phish in the morning!&lt;br /&gt;&lt;br /&gt;Here is the headers and body of another phish email today. These people give me cramps.&lt;br /&gt;&lt;br /&gt;I sent it to spoof@ebay.com and pasted the URL into phishfighting.com. Go Go Go!&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Return-Path:     &lt;test@web1.octelecom.net&gt;&lt;br /&gt;Authentication-Results:    mta163.mail.mud.yahoo.com from=ebay.com; domainkeys=neutral (no sig)&lt;br /&gt;Received: from 208.187.180.4 (EHLO web1.octelecom.net) (208.187.180.4) by mta163.mail.mud.yahoo.com with SMTP; Tue, 09 May 2006 02:05:11 -0700&lt;br /&gt;Received: from web1.octelecom.net (localhost.localdomain [127.0.0.1]) by web1.octelecom.net (8.13.1/8.13.1) with ESMTP id k499EL4f022387 for &lt;mrlinuxhead@yahoo.com&gt;; Tue, 9 May 2006 03:14:21 -0600&lt;br /&gt;Received: (from test@localhost) by web1.octelecom.net (8.13.1/8.13.1/Submit) id k499ELag022384 for mrlinuxhead@yahoo.com; Tue, 9 May 2006 03:14:21 -0600&lt;br /&gt;Date:    Tue, 9 May 2006 03:14:21 -0600&lt;br /&gt;To:    mrlinuxhead@yahoo.com&lt;br /&gt;Subject:    eBay Member wandasales&lt;br /&gt;Message-ID:    &lt;1147166061.70001.qmail@paypal&gt;&lt;br /&gt;From:    aw-confirm@ebay.com  Add to Address BookAdd to Address Book  Add Mobile Alert&lt;br /&gt;Content-Type:    text/html&lt;br /&gt;Content-Length:    3699&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Â Question from wandasales&lt;br /&gt;Item: (6876616738)&lt;br /&gt;This message was sent while the listing was active.&lt;br /&gt;wandasales is a potential buyer.&lt;br /&gt;Hello, What would the shipping cost be to West Virginia zip code 25511?&lt;br /&gt;&lt;br /&gt;Email server is at : 208.187.180.4&lt;br /&gt;&lt;br /&gt;Here is a port scan.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://photos1.blogger.com/blogger/182/2489/1600/208.187.180.4.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://photos1.blogger.com/blogger/182/2489/400/208.187.180.4.jpg" alt="" border="0" /&gt;&lt;/a&gt; Just a RH Linux box with too many ports open. Gee I wonder if the owner knows they are sending this crap out? Let see.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Using DNSStuff.com I see the box is at:&lt;br /&gt;&lt;br /&gt;IP address:                     208.187.180.4&lt;br /&gt;Reverse DNS:                    web1.octelecom.net.&lt;br /&gt;Reverse DNS authenticity:       [Verified]&lt;br /&gt;ASN:                            29933&lt;br /&gt;ASN Name:                       OFF-CAMPUS-TELECOMMUNICATIONS&lt;br /&gt;IP range connectivity:          1&lt;br /&gt;Registrar (per ASN):            ARIN&lt;br /&gt;Country (per IP registrar):     US [United States]&lt;br /&gt;Country Currency:               USD [United States Dollars]&lt;br /&gt;Country IP Range:               208.184.0.0 to 208.191.255.255&lt;br /&gt;Country fraud profile:          Normal&lt;br /&gt;City (per outside source):      Provo, Utah&lt;br /&gt;&lt;br /&gt;It looks like a campus ISP that is in Provo Utah.&lt;br /&gt;&lt;br /&gt;No email address for them but a phone number - call us at 379-3000&lt;br /&gt;(toll-free 1-800-370-1106)&lt;br /&gt;We're located in Provo at 379 North University Avenue, Suite 301.&lt;br /&gt;&lt;br /&gt;Well let's call them up and tell them they have a bad person using their RH server.&lt;br /&gt;&lt;br /&gt;WHOIS info is blocked but I can probably find the email address.&lt;br /&gt;&lt;br /&gt;On to the web site stealing people's passwords and user id's.&lt;br /&gt;&lt;br /&gt;Real URL of the scam is at: http://216.122.128.59/~admin/%20%20/index.html&lt;br /&gt;&lt;br /&gt;Going back to DNSStuff.com I learn that:&lt;br /&gt;&lt;br /&gt;&lt;/mrlinuxhead@yahoo.com&gt;&lt;/test@web1.octelecom.net&gt;&lt;pre&gt;IP address:                     216.122.128.59&lt;br /&gt;Reverse DNS:                    r59-128-dsl.sea.lightrealm.net.&lt;br /&gt;Reverse DNS authenticity:       [Could be forged: hostname r59-128-dsl.sea.lightrealm.net. does not exist]&lt;br /&gt;ASN:                            11305&lt;br /&gt;ASN Name:                       INTERLAND-NET1&lt;br /&gt;IP range connectivity:          1&lt;br /&gt;Registrar (per ASN):            ARIN&lt;br /&gt;Country (per IP registrar):     US [United States]&lt;br /&gt;Country Currency:               USD [United States Dollars]&lt;br /&gt;Country IP Range:               216.122.0.0 to 216.122.255.255&lt;br /&gt;Country fraud profile:          Normal&lt;br /&gt;City (per outside source):      Kirkland, Washington&lt;/pre&gt;&lt;br /&gt;Gotcha sucker, you are in the USA. Busted. Phish fry today!&lt;br /&gt;&lt;br /&gt;Looks like Lightrealm is getting upstream pipe from Interland.&lt;br /&gt;&lt;br /&gt;Interland, Inc. LR-BLK4 (NET-216-122-0-0-1)&lt;br /&gt;                              216.122.0.0 - 216.122.255.255&lt;br /&gt;Lightrealm, Inc. LR-ISP-GTEDHCP4-DSL (NET-216-122-128-0-1)&lt;br /&gt;                              216.122.128.0 - 216.122.128.255&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;A Google for Lightrealm points to http://www.lightrealm.net/&lt;br /&gt;&lt;br /&gt;It's a web hosting company. No surprise there.&lt;br /&gt;&lt;br /&gt;"Get your own web site, share your special day!" is on the home page.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://photos1.blogger.com/blogger/182/2489/1600/lightrealm.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://photos1.blogger.com/blogger/182/2489/400/lightrealm.jpg" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;One that looks like eBay login page? Maybe that's not what thay had in mind.&lt;br /&gt;&lt;br /&gt;Interland is a mass reseller of web hosts and a co-location facillity.&lt;br /&gt;&lt;br /&gt;I used to work for a company that was bought by them, Hostcentric.&lt;br /&gt;&lt;br /&gt;Here is a port scan of the host:&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://photos1.blogger.com/blogger/182/2489/1600/216.122.128.59.0.jpg"&gt;&lt;img style="cursor: pointer;" src="http://photos1.blogger.com/blogger/182/2489/400/216.122.128.59.0.jpg" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt; The web server is running Apache on FreeBSD,  got sendmail running as well.&lt;br /&gt;&lt;br /&gt;Email server is running as bearcomp.net. Hmm. Who are they?&lt;br /&gt;&lt;br /&gt;&lt;pre&gt;Asking b.ns.interland.net. for 59.128.122.216.in-addr.arpa PTR record:&lt;br /&gt;Reports r59-128-dsl.sea.lightrealm.net. [from 69.0.145.33]&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Answer&lt;/b&gt;:&lt;br /&gt;216.122.128.59 PTR record: &lt;b&gt;r59-128-dsl.sea.lightrealm.net.&lt;/b&gt; [TTL 1800s] [A=None]&lt;br /&gt;*&lt;b&gt;ERROR&lt;/b&gt;* There is no A record (may be cached).&lt;/pre&gt; That's our boy! I next find out who runs bearcomp.net with our trusty WHOIS lookup.&lt;br /&gt;&lt;br /&gt;&lt;table border="0" cellpadding="0" cellspacing="0"&gt; &lt;tbody&gt;&lt;tr&gt;&lt;td&gt; &lt;br /&gt;&lt;/td&gt;   &lt;td colspan="4"&gt;SoftPaw    &lt;/td&gt;  &lt;/tr&gt;                    &lt;tr&gt;   &lt;td&gt; &lt;br /&gt;&lt;/td&gt;   &lt;td colspan="4"&gt;41064 Riverock Lane&lt;/td&gt;   &lt;/tr&gt;      &lt;tr&gt;     &lt;td&gt; &lt;br /&gt;&lt;/td&gt;   &lt;td colspan="4"&gt;    Palmdale,      CA    93551-1834   &lt;/td&gt;    &lt;/tr&gt;    &lt;tr&gt;   &lt;td&gt; &lt;br /&gt;&lt;/td&gt;   &lt;td colspan="4"&gt;    US   &lt;/td&gt;  &lt;/tr&gt;             &lt;tr&gt;&lt;td&gt; &lt;br /&gt;&lt;/td&gt;&lt;td colspan="4"&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;             &lt;tr&gt;  &lt;td&gt; &lt;br /&gt;&lt;/td&gt;  &lt;td colspan="4"&gt;  &lt;strong&gt;Domain Name:&lt;/strong&gt; BEARCOMP.NET  &lt;/td&gt;  &lt;/tr&gt;  &lt;tr&gt;&lt;td colspan="4"&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;                        &lt;tr&gt;  &lt;td&gt; &lt;br /&gt;&lt;/td&gt;              &lt;td&gt;    &lt;strong&gt;Administrative Contact                :&lt;/strong&gt;    &lt;/td&gt;       &lt;td colspan="3"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;/tr&gt;                         &lt;tr&gt;   &lt;td&gt; &lt;br /&gt;&lt;/td&gt;   &lt;td colspan="4"&gt;Hess,   John    &lt;/td&gt;   &lt;/tr&gt;                      &lt;tr&gt;   &lt;td&gt; &lt;br /&gt;&lt;/td&gt;   &lt;td colspan="4"&gt;    jhh@bearcomp.net   &lt;/td&gt;  &lt;/tr&gt;         &lt;tr&gt;    &lt;td&gt; &lt;br /&gt;&lt;/td&gt;    &lt;td colspan="4"&gt;41064 Riverock Lane&lt;/td&gt;    &lt;/tr&gt;      &lt;tr&gt;     &lt;td&gt; &lt;br /&gt;&lt;/td&gt;   &lt;td colspan="4"&gt;    Palmdale,      CA    93551-1834   &lt;/td&gt;    &lt;/tr&gt;     &lt;tr&gt;    &lt;td&gt; &lt;br /&gt;&lt;/td&gt;    &lt;td colspan="4"&gt;     US    &lt;/td&gt;   &lt;/tr&gt;       &lt;tr&gt;    &lt;td&gt; &lt;br /&gt;&lt;/td&gt;    &lt;td colspan="4"&gt;     Phone: 800-725-8910     &lt;/td&gt;   &lt;/tr&gt;       &lt;tr&gt;    &lt;td&gt; &lt;br /&gt;&lt;/td&gt;    &lt;td colspan="4"&gt;     Fax: (661) 722-9010    &lt;/td&gt;   &lt;/tr&gt;             &lt;tr&gt;&lt;td&gt; &lt;br /&gt;&lt;/td&gt;&lt;td colspan="4"&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;                                  &lt;tr&gt;  &lt;td&gt; &lt;br /&gt;&lt;/td&gt;  &lt;td&gt;  &lt;strong&gt;Record expires on&lt;/strong&gt; 26-Aug-2006  &lt;/td&gt;  &lt;td colspan="3"&gt;         &lt;br /&gt;&lt;/td&gt;  &lt;/tr&gt;              &lt;tr&gt;  &lt;td&gt; &lt;br /&gt;&lt;/td&gt;  &lt;td colspan="4"&gt;  &lt;strong&gt;Record created on&lt;/strong&gt; 19-May-2004  &lt;/td&gt;  &lt;/tr&gt;             &lt;tr&gt;  &lt;td&gt; &lt;br /&gt;&lt;/td&gt;  &lt;td colspan="4"&gt;   &lt;strong&gt;Database last updated on&lt;/strong&gt; 13-Jun-2005&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt; &lt;/table&gt;&lt;br /&gt;OK game over. Let's call the cops in Palmdale and have them let Mr. Hess know his server is behaving badly.&lt;div class="blogger-post-footer"&gt;
&lt;div class='adsense' style='text-align:center; padding: 0px 3px 0.5em 3px;'&gt;
&lt;script type="text/javascript"&gt;&lt;!--
google_ad_client="ca-pub-9456629394253923";
google_ad_width=468;
google_ad_height=60;
google_ad_format="468x60_as";
google_ad_type="text";
google_color_border="FFFFFF";
google_color_bg="FFFFFF";
google_color_link="333333";
google_color_url="333333";
google_color_text="993333";
//--&gt;&lt;/script&gt;
&lt;script type="text/javascript"
  src="http://pagead2.googlesyndication.com/pagead/show_ads.js"&gt;
&lt;/script&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26986700-114717585733058731?l=phish-finder.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phish-finder.blogspot.com/feeds/114717585733058731/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26986700&amp;postID=114717585733058731&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26986700/posts/default/114717585733058731'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26986700/posts/default/114717585733058731'/><link rel='alternate' type='text/html' href='http://phish-finder.blogspot.com/2006/05/fresh-phish-meat-to-hunt-down-and-kill.html' title='Fresh Phish meat to hunt down and kill today!'/><author><name>Mr. Phish Finder</name><uri>http://www.blogger.com/profile/07920773754442475692</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26986700.post-114642052517294475</id><published>2006-04-30T11:00:00.000-07:00</published><updated>2006-04-30T11:08:45.190-07:00</updated><title type='text'>Paypay scam site from Russia - nnov.ru - KIS.RU</title><content type='html'>Got another Phisherman" today. Seems my PAypal account is in danger! OOOH!&lt;br /&gt;I set the link to spoof@paypal.com and pasted the URL into phishfighting.com.&lt;br /&gt;&lt;br /&gt; Phony PayPal URL points to:&lt;br /&gt;&lt;span style="font-style: italic;"&gt;http://a.citron.nnov.ru/~test/%20/.paypal.com/link.php&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Here is the full headers from the bogus email:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;X-Apparently-To:     mrlinuxhead@yahoo.com via 68.142.207.121; Sun, 30 Apr 2006 05:03:13 -0700&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;X-YahooFilteredBulk:    61.78.62.237&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;X-Originating-IP:    [61.78.62.237]&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Return-Path:    &lt;mysql@localhost.localdomain&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Authentication-Results:    mta222.mail.mud.yahoo.com from=paypal.com; domainkeys=neutral (no sig)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Received:    from 61.78.62.237 (EHLO localhost.localdomain) (61.78.62.237) by mta222.mail.mud.yahoo.com with SMTP; Sun, 30 Apr 2006 05:03:13 -0700&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Received:    from localhost.localdomain (dbslow [127.0.0.1]) by localhost.localdomain (8.13.1/8.13.1) with ESMTP id k3UBugDJ006814 for &lt;mrlinuxhead@yahoo.com&gt;; Sun, 30 Apr 2006 20:56:42 +0900&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Received:    (from mysql@localhost) by localhost.localdomain (8.13.1/8.13.1/Submit) id k3UBugwh006813; Sun, 30 Apr 2006 20:56:42 +0900&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Date:    Sun, 30 Apr 2006 20:56:42 +0900&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Message-Id:    &lt;200604301156.k3ubugwh006813@localhost.localdomain&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;To:    mrlinuxhead@yahoo.com&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Subject:    Restore Your Account Access - mrlinuxhead@yahoo.com (Routing Code: C840-L1581-Q120-1937)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;From:    "PayPal Security Service" &lt;service@paypal.com&gt;  Add to Address BookAdd to Address Book  Add Mobile Alert&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Content-Type:    multipart/alternative; boundary="msg_boundary_0000-03"&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Content-Length:    1653&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt; &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Dear  mrlinuxhead@yahoo.com,  &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;It has come to our attention that your PayPal® account information needs to be &lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;updated as part of our continuing commitment to protect your account and to &lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;reduce the instance of fraud on our website.  If you could please take 5-10 minutes &lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;out of your online experience and update your personal records you will not run into &lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;any future problems with the online service. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;                                   &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;However, failure to update your records will result in account suspension. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Please update your records on or before May 03, 2006. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Once you have updated your account records, your PayPal® session will not be &lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;interrupted and will continue as normal.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;To update your PayPal® records click on the following link: &lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;http://www.paypal.com/cgi-bin/webscr?cmd=p/gen/restrictedaccounts.asp&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt; &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Thank You.  &lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;PayPal® UPDATE TEAM                                    &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Accounts Management As outlined in our User Agreement, PayPal® will &lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;periodically send you information about site changes and enhancements.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Visit our Privacy Policy and User Agreement if you have any questions. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;http://www.paypal.com/cgi-bin/webscr?cmd=p/gen/ua/policy_privacy-outside&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Email header points to this box as the SMTP server&lt;br /&gt;&lt;br /&gt;IP address:                     61.78.62.237&lt;br /&gt;Reverse DNS:                    [No reverse DNS entry per ns1.siidc.net.]&lt;br /&gt;Reverse DNS authenticity:       [Unknown]&lt;br /&gt;ASN:                            4766&lt;br /&gt;ASN Name:                       KIXS-AS-KR (Korea Telecom)&lt;br /&gt;IP range connectivity:          5&lt;br /&gt;Registrar (per ASN):            APNIC&lt;br /&gt;Country (per IP registrar):     KR [Korea-KR]&lt;br /&gt;Country Currency:               KRW [Korea (South) Won]&lt;br /&gt;Country IP Range:               61.72.0.0 to 61.79.255.255&lt;br /&gt;Country fraud profile:          Normal&lt;br /&gt;City (per outside source):      Seoul, Kyonggi-Do&lt;br /&gt;Private (internal) IP?          No&lt;br /&gt;IP address registrar:           whois.apnic.net&lt;br /&gt;Known Proxy?                    No&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;This is where the phoney PayPal site is located&lt;br /&gt;&lt;br /&gt;195.98.59.34 PTR record: a.citron.nnov.ru. [TTL 86400s] [A=195.98.59.34]&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;WHOIS - NNOV.RU&lt;br /&gt;&lt;br /&gt;domain:     NNOV.RU&lt;br /&gt;type:       GEOGRAPHICAL&lt;br /&gt;descr:      Public geographical domain&lt;br /&gt;descr:      for Nizhny Novgorod region&lt;br /&gt;descr:      supported by Agenstvo Delovoj Svjazi, Ltd.&lt;br /&gt;nserver:    ns.kis.ru.&lt;br /&gt;nserver:    ns.nnov.ru. 195.98.32.114&lt;br /&gt;nserver:    ns1.cityline.ru.&lt;br /&gt;nserver:    ns1.kis.ru.&lt;br /&gt;nserver:    ns2.kis.ru.&lt;br /&gt;state:      REGISTERED, DELEGATED&lt;br /&gt;org:        "Agenstvo Delovoj Svjazi", Ltd&lt;br /&gt;phone:      +7 8312 777777&lt;br /&gt;fax-no:     +7 8312 777771&lt;br /&gt;e-mail:     agency@bca.ru&lt;br /&gt;registrar:  RIPN-REG-RIPN&lt;br /&gt;created:    1996.10.23&lt;br /&gt;paid-till:  2006.11.01&lt;br /&gt;source:     TC-RIPN&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;domain:  NNOV.RU&lt;br /&gt;type:    GEOGRAPHICAL&lt;br /&gt;descr:   Public geographical domain&lt;br /&gt;descr:   for Nizhny Novgorod region&lt;br /&gt;descr:   supported by Agenstvo Delovoj Svjazi, Ltd.&lt;br /&gt;admin-o: ADSL-ORG-RIPN&lt;br /&gt;nserver: ns.kis.ru.&lt;br /&gt;nserver: ns.nnov.ru. 195.98.32.114&lt;br /&gt;nserver: ns1.cityline.ru.&lt;br /&gt;nserver: ns1.kis.ru.&lt;br /&gt;nserver: ns2.kis.ru.&lt;br /&gt;created: 1996.10.23&lt;br /&gt;state:   Delegated till 2007.03.01&lt;br /&gt;changed: 2003.10.07&lt;br /&gt;mnt-by:  ADSL-MNT-RIPN&lt;br /&gt;source:  RIPN&lt;br /&gt;&lt;br /&gt;org:     "Agenstvo Delovoj Svjazi", Ltd&lt;br /&gt;nic-hdl: ADSL-ORG-RIPN&lt;br /&gt;admin-c: DM59-RIPE&lt;br /&gt;admin-c: ZOV3-RIPN&lt;br /&gt;bill-c:  DM59-RIPE&lt;br /&gt;bill-c:  DV15-RIPE&lt;br /&gt;bill-c:  AS14618-RIPE&lt;br /&gt;bill-c:  ZOV3-RIPN&lt;br /&gt;phone:   +7 8312 777777&lt;br /&gt;fax-no:  +7 8312 777771&lt;br /&gt;e-mail:  agency@bca.ru&lt;br /&gt;changed: 2004.10.06&lt;br /&gt;mnt-by:  ADSL-MNT-RIPN&lt;br /&gt;source:  RIPN&lt;br /&gt;&lt;br /&gt;person:  OLGA V ZAHRYAPINA&lt;br /&gt;nic-hdl: ZOV3-RIPN&lt;br /&gt;phone:   +7 8312 777777&lt;br /&gt;e-mail:  olya@bca.ru&lt;br /&gt;changed: 2004.10.06&lt;br /&gt;mnt-by:  ADSL-MNT-RIPN&lt;br /&gt;source:  RIPN&lt;br /&gt;&lt;br /&gt;Last updated on 2006.04.12 04:43:49 MSK/MSD&lt;br /&gt;&lt;br /&gt;DNS entries for nnov.ru&lt;br /&gt;&lt;br /&gt; nnov.ru.    A    IN    86400    195.98.32.114&lt;br /&gt; nnov.ru.    NS    IN    86400    ns.nnov.ru.&lt;br /&gt; nnov.ru.    NS    IN    86400    ns.kis.ru.&lt;br /&gt; nnov.ru.    NS    IN    86400    ns1.kis.ru.&lt;br /&gt; nnov.ru.    NS    IN    86400    ns2.kis.ru.&lt;br /&gt; nnov.ru.    NS    IN    86400    ns1.cityline.ru.&lt;br /&gt; ns.nnov.ru.    A    IN    86400    195.98.32.114&lt;br /&gt; ns.kis.ru.    A    IN    44456    195.98.32.193&lt;br /&gt; ns1.kis.ru.    A    IN    44456    195.98.32.200&lt;br /&gt; ns2.kis.ru.    A    IN    56534    195.98.51.60&lt;br /&gt; ns1.cityline.ru.    A    IN    217645    195.46.160.1&lt;br /&gt;&lt;br /&gt;IP Info on nnov.ru&lt;br /&gt;&lt;br /&gt;IP address:                     195.98.32.114&lt;br /&gt;Reverse DNS:                    nnov.kis.ru.&lt;br /&gt;Reverse DNS authenticity:       [Verified]&lt;br /&gt;ASN:                            8371&lt;br /&gt;ASN Name:                       KIS-ADS (Commercial Information Networks)&lt;br /&gt;IP range connectivity:          1&lt;br /&gt;Registrar (per ASN):            RIPE&lt;br /&gt;Country (per IP registrar):     RU [Russian Federation]&lt;br /&gt;Country Currency:               RUR [Russia Rubles]&lt;br /&gt;Country IP Range:               195.98.32.0 to 195.98.63.255&lt;br /&gt;Country fraud profile:          High&lt;br /&gt;City (per outside source):      New Westminster, British Columbia&lt;br /&gt;Private (internal) IP?          No&lt;br /&gt;IP address registrar:           whois.ripe.net&lt;br /&gt;Known Proxy?                    No&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;KIS.RU&lt;br /&gt;&lt;br /&gt;domain:     KIS.RU&lt;br /&gt;type:       CORPORATE&lt;br /&gt;nserver:    ns.kis.ru. 195.98.32.193&lt;br /&gt;nserver:    ns1.kis.ru. 195.98.32.200&lt;br /&gt;nserver:    ns2.kis.ru. 195.98.51.60&lt;br /&gt;state:      REGISTERED, DELEGATED&lt;br /&gt;org:        "Agenstvo Delovoj Svjazi", Ltd&lt;br /&gt;phone:      +7 8312 777777&lt;br /&gt;fax-no:     +7 8312 777771&lt;br /&gt;e-mail:     www@bca.ru&lt;br /&gt;registrar:  RUCENTER-REG-RIPN&lt;br /&gt;created:    1996.09.14&lt;br /&gt;paid-till:  2006.10.01&lt;br /&gt;source:     TC-RIPN&lt;br /&gt;&lt;br /&gt;So it seems that this NNOV.RU is aucually a sub-domain of  KIS.RU&lt;br /&gt;&lt;br /&gt;Some body email this clown and tell him to shut it down ??&lt;br /&gt;&lt;br /&gt;www@bca.ru&lt;br /&gt;olya@bca.ru&lt;div class="blogger-post-footer"&gt;
&lt;div class='adsense' style='text-align:center; padding: 0px 3px 0.5em 3px;'&gt;
&lt;script type="text/javascript"&gt;&lt;!--
google_ad_client="ca-pub-9456629394253923";
google_ad_width=468;
google_ad_height=60;
google_ad_format="468x60_as";
google_ad_type="text";
google_color_border="FFFFFF";
google_color_bg="FFFFFF";
google_color_link="333333";
google_color_url="333333";
google_color_text="993333";
//--&gt;&lt;/script&gt;
&lt;script type="text/javascript"
  src="http://pagead2.googlesyndication.com/pagead/show_ads.js"&gt;
&lt;/script&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26986700-114642052517294475?l=phish-finder.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phish-finder.blogspot.com/feeds/114642052517294475/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26986700&amp;postID=114642052517294475&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26986700/posts/default/114642052517294475'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26986700/posts/default/114642052517294475'/><link rel='alternate' type='text/html' href='http://phish-finder.blogspot.com/2006/04/paypay-scam-site-from-russia-nnovru.html' title='Paypay scam site from Russia - nnov.ru - KIS.RU'/><author><name>Mr. Phish Finder</name><uri>http://www.blogger.com/profile/07920773754442475692</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26986700.post-114610189063988554</id><published>2006-04-26T18:37:00.000-07:00</published><updated>2006-04-26T18:38:10.640-07:00</updated><title type='text'>Another ebay scammer from Finland...</title><content type='html'>Another ebay scammer at this address:&lt;br /&gt;&lt;br /&gt;http://1044980011/%20/signin.ebay.com/ws/eBayISAPI/index.html&lt;br /&gt;&lt;br /&gt;Pasted it into Phishfighing. com and emailed ebay and the ISP in Finland.&lt;br /&gt;&lt;br /&gt;http://1044980011/%20/signin.ebay.com/ws/eBayISAPI/index.html&lt;br /&gt;&lt;br /&gt;resolves to 62.73.33.43&lt;br /&gt;&lt;br /&gt;WHOIS info on 62.73.33.43&lt;br /&gt;&lt;br /&gt;IP address:                     62.73.33.43&lt;br /&gt;Reverse DNS:                    [No reverse DNS entry per ns1.auria.fi.]&lt;br /&gt;Reverse DNS authenticity:       [Unknown]&lt;br /&gt;ASN:                            16044&lt;br /&gt;ASN Name:                       AURIA (Auria Oy)&lt;br /&gt;IP range connectivity:          1&lt;br /&gt;Registrar (per ASN):            RIPE&lt;br /&gt;Country (per IP registrar):     FI [Finland]&lt;br /&gt;Country Currency:               EUR [euros]&lt;br /&gt;Country IP Range:               62.73.32.0 to 62.73.63.255&lt;br /&gt;Country fraud profile:          Normal&lt;br /&gt;City (per outside source):      Unknown&lt;br /&gt;Private (internal) IP?          No&lt;br /&gt;&lt;br /&gt;inetnum:      62.73.33.0 - 62.73.33.127&lt;br /&gt;netname:      AURIA-NET&lt;br /&gt;descr:        AURIA Turun Puhelin Oy&lt;br /&gt;descr:        Game server pool&lt;br /&gt;descr:        DATA-4&lt;br /&gt;descr:        20810, Turku&lt;br /&gt;country:      FI&lt;br /&gt;admin-c:      KPM-RIPE&lt;br /&gt;tech-c:       HOST7-RIPE&lt;br /&gt;status:       ASSIGNED PA&lt;br /&gt;remarks:      ---------------------------------------------------------&lt;br /&gt;remarks:      Please send abuse and spam notifications to abuse@auria.fi&lt;br /&gt;remarks:      ---------------------------------------------------------&lt;br /&gt;remarks:      INFRA-AW&lt;br /&gt;notify:       hostmaster@auria.fi&lt;br /&gt;mnt-by:       AURIATP-MNT&lt;br /&gt;changed:      kari.solja@auria.fi 20040802&lt;br /&gt;source:       RIPE&lt;br /&gt;&lt;br /&gt;role:           Auria Hostmaster&lt;br /&gt;address:        Auria  Oy&lt;br /&gt;address:        RIPE management&lt;br /&gt;address:        PL 231&lt;br /&gt;address:        20101 Turku&lt;br /&gt;phone:          +358 2 262121&lt;br /&gt;fax-no:         +358 2 261975&lt;br /&gt;e-mail:         hostmaster@auria.fi&lt;br /&gt;remarks:        trouble:      Please send abuse and spam notifications to abuse@auria.fi&lt;br /&gt;remarks:        trouble:      General information: http://www.auria.fi/&lt;br /&gt;admin-c:        KS1112-RIPE&lt;br /&gt;tech-c:         MH14627-RIPE&lt;br /&gt;tech-c:         RM7972-RIPE&lt;br /&gt;tech-c:         KK2824-RIPE&lt;br /&gt;tech-c:         JO2466-RIPE&lt;br /&gt;tech-c:         KS1112-RIPE&lt;br /&gt;nic-hdl:        HOST7-RIPE&lt;br /&gt;notify:         hostmaster@auria.fi&lt;br /&gt;mnt-by:         AURIATP-MNT&lt;br /&gt;changed:        rolf.moller@auria.fi 20041123&lt;br /&gt;source:         RIPE&lt;br /&gt;abuse-mailbox:  abuse@auria.fi&lt;br /&gt;&lt;br /&gt;person:       Kimmo Murto&lt;br /&gt;address:      Turku Telephone Company&lt;br /&gt;address:      Linnankatu 4, FIN-20100 Turku&lt;br /&gt;address:      Finland&lt;br /&gt;phone:        +358 2 262 1584&lt;br /&gt;fax-no:       +358 2 250 0417&lt;br /&gt;e-mail:       Kimmo.Murto@turunpuhelin.fi&lt;br /&gt;nic-hdl:      KPM-RIPE&lt;br /&gt;changed:      hostmaster@kolumbus.fi 19981221&lt;br /&gt;source:       RIPE&lt;br /&gt;&lt;br /&gt;% Information related to '62.73.32.0/19AS16044'&lt;br /&gt;&lt;br /&gt;route:        62.73.32.0/19&lt;br /&gt;descr:        Turun Puhelin Oy&lt;br /&gt;origin:       AS16044&lt;br /&gt;notify:       hostmaster@auria.fi&lt;br /&gt;mnt-by:       AURIATP-MNT&lt;br /&gt;changed:      marko.hakkarainen@auria.fi 20021014&lt;br /&gt;source:       RIPE&lt;div class="blogger-post-footer"&gt;
&lt;div class='adsense' style='text-align:center; padding: 0px 3px 0.5em 3px;'&gt;
&lt;script type="text/javascript"&gt;&lt;!--
google_ad_client="ca-pub-9456629394253923";
google_ad_width=468;
google_ad_height=60;
google_ad_format="468x60_as";
google_ad_type="text";
google_color_border="FFFFFF";
google_color_bg="FFFFFF";
google_color_link="333333";
google_color_url="333333";
google_color_text="993333";
//--&gt;&lt;/script&gt;
&lt;script type="text/javascript"
  src="http://pagead2.googlesyndication.com/pagead/show_ads.js"&gt;
&lt;/script&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26986700-114610189063988554?l=phish-finder.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phish-finder.blogspot.com/feeds/114610189063988554/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26986700&amp;postID=114610189063988554&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26986700/posts/default/114610189063988554'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26986700/posts/default/114610189063988554'/><link rel='alternate' type='text/html' href='http://phish-finder.blogspot.com/2006/04/another-ebay-scammer-from-finland.html' title='Another ebay scammer from Finland...'/><author><name>Mr. Phish Finder</name><uri>http://www.blogger.com/profile/07920773754442475692</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26986700.post-114610182100016759</id><published>2006-04-26T18:36:00.000-07:00</published><updated>2006-04-26T18:37:01.016-07:00</updated><title type='text'>Sure. I trust you. Lets fry this clown. mmjd1996</title><content type='html'>Another email from another eBay customer.&lt;br /&gt;Sure. I trust you. Lets fry this clown..&lt;br /&gt;&lt;br /&gt;Here is the text of the scam email :&lt;br /&gt;&lt;br /&gt;Ã Question from mmjd1996&lt;br /&gt;Item: (4629414062)&lt;br /&gt;This message was sent while the listing was active.&lt;br /&gt;mmjd1996 is a potential buyer.&lt;br /&gt;Hi, how much would be shipping to Germany? Thanks&lt;br /&gt;&lt;br /&gt;Using DNSStuff.com I find out our scammers IP address.&lt;br /&gt;&lt;br /&gt;eBay.com URL points to:&lt;br /&gt;http://1393442438/img/...bleh/signin.ebay.com/ws/eBayISAPI.dll/SignIn.htm&lt;br /&gt;&lt;br /&gt;1393442438 is decimal for 83.14.62.134&lt;br /&gt;&lt;br /&gt;Seems to be a box on some DSL line in Poland..&lt;br /&gt;&lt;br /&gt;IP address:                     83.14.62.134&lt;br /&gt;Reverse DNS:                    dyk134.internetdsl.tpnet.pl.&lt;br /&gt;Reverse DNS authenticity:       [Verified]&lt;br /&gt;ASN:                            5617&lt;br /&gt;ASN Name:                       TPNET (Polish Telecom's commercial IP network)&lt;br /&gt;IP range connectivity:          2&lt;br /&gt;Registrar (per ASN):            RIPE&lt;br /&gt;Country (per IP registrar):     PL [Poland]&lt;br /&gt;Country Currency:               PLN [Poland Zlotych]&lt;br /&gt;Country IP Range:               83.0.0.0 to 83.31.255.255&lt;br /&gt;&lt;br /&gt;The ISP is Poland Telecom. Here are the ISP contact numbers and email addresses.&lt;br /&gt;&lt;br /&gt;role:           TP S.A. Hostmaster&lt;br /&gt;address:        TP S.A. "POLPAK"&lt;br /&gt;address:        ul. Nowogrodzka 47A&lt;br /&gt;address:        00-695 Warszawa&lt;br /&gt;address:        Poland&lt;br /&gt;phone:          +48 22 6252383&lt;br /&gt;fax-no:         +48 22 6225182&lt;br /&gt;remarks:        trouble:      Network problems: hostmaster@tpnet.pl&lt;br /&gt;remarks:        trouble:      Abuse and spam notification: abuse@tpnet.pl&lt;br /&gt;remarks:        trouble:      DNS problems: dns@tpnet.pl&lt;br /&gt;remarks:        trouble:      Routing problems: registry@tpnet.pl&lt;br /&gt;admin-c:        TK569-RIPE&lt;br /&gt;tech-c:         TK569-RIPE&lt;br /&gt;tech-c:         JS1838-RIPE&lt;br /&gt;nic-hdl:        TPHT&lt;br /&gt;remarks:        ! - ! - ! - ! - ! - ! - ! - ! - ! - ! - !&lt;br /&gt;remarks:        Please send spam and abuse notification only to abuse@tpnet.pl&lt;br /&gt;remarks:        ! - ! - ! - ! - ! - ! - ! - ! - ! - ! - !&lt;br /&gt;mnt-by:         TPNET&lt;br /&gt;e-mail:         hostmaster@tpnet.pl&lt;br /&gt;abuse-mailbox:  abuse@tpnet.pl&lt;br /&gt;changed:        hostmaster@tpnet.pl 20030122&lt;br /&gt;changed:        hostmaster@tpnet.pl 20030904&lt;br /&gt;changed:        hostmaster@tpnet.pl 20060306&lt;br /&gt;source:         RIPE&lt;br /&gt;&lt;br /&gt;Port scan shows nothing but FTP and SSH. No UDP ports open.&lt;br /&gt;&lt;br /&gt;So I shoot a quick email to the boys at Polish Telecom (abuse@tpnet.pl).&lt;br /&gt;&lt;br /&gt;I also paste the bougus URL into PhishFighing.com.&lt;br /&gt;(That feeds our "Phisherman" with hundreds of bogus usernames and passwords.)&lt;br /&gt;&lt;br /&gt;That should keep him busy for a few days.&lt;br /&gt;&lt;br /&gt;Just another day ho hum.&lt;div class="blogger-post-footer"&gt;
&lt;div class='adsense' style='text-align:center; padding: 0px 3px 0.5em 3px;'&gt;
&lt;script type="text/javascript"&gt;&lt;!--
google_ad_client="ca-pub-9456629394253923";
google_ad_width=468;
google_ad_height=60;
google_ad_format="468x60_as";
google_ad_type="text";
google_color_border="FFFFFF";
google_color_bg="FFFFFF";
google_color_link="333333";
google_color_url="333333";
google_color_text="993333";
//--&gt;&lt;/script&gt;
&lt;script type="text/javascript"
  src="http://pagead2.googlesyndication.com/pagead/show_ads.js"&gt;
&lt;/script&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26986700-114610182100016759?l=phish-finder.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phish-finder.blogspot.com/feeds/114610182100016759/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26986700&amp;postID=114610182100016759&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26986700/posts/default/114610182100016759'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26986700/posts/default/114610182100016759'/><link rel='alternate' type='text/html' href='http://phish-finder.blogspot.com/2006/04/sure-i-trust-you-lets-fry-this-clown.html' title='Sure. I trust you. Lets fry this clown. mmjd1996'/><author><name>Mr. Phish Finder</name><uri>http://www.blogger.com/profile/07920773754442475692</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26986700.post-114607322467413206</id><published>2006-04-26T10:40:00.000-07:00</published><updated>2006-04-26T18:38:52.540-07:00</updated><title type='text'>Another eBay scam artist emailed me tonight blackstump.com.au</title><content type='html'>Another eBay scam artist emailed me tonight. This one was just a little different.&lt;br /&gt;&lt;br /&gt;I guess now I have an "Unpaid Item Dispute" Points to 209.216.209.10 as the mail server.&lt;br /&gt;&lt;br /&gt;Here is the full email headers and all..&lt;br /&gt;&lt;br /&gt;X-Apparently-To:     mrlinuxhead@yahoo.com via 68.142.207.116; Mon, 24 Apr 2006 15:56:29 -0700&lt;br /&gt;X-Originating-IP:    [209.216.209.10]&lt;br /&gt;Return-Path:    &lt;test@admin.blackstump.com.au&gt;&lt;br /&gt;Authentication-Results:    mta244.mail.re2.yahoo.com from=ebay.com; domainkeys=neutral (no sig)&lt;br /&gt;Received: from 209.216.209.10 (EHLO admin.blackstump.com.au) (209.216.209.10) by mta244.mail.re2.yahoo.com with SMTP; Mon, 24 Apr 2006 15:56:29 -0700&lt;br /&gt;Received:    (qmail 15991 invoked by uid 10018); 24 Apr 2006 15:35:41 -0700&lt;br /&gt;Date:    24 Apr 2006 15:35:41 -0700&lt;br /&gt;Message-ID:    &lt;20060424223541.15990.qmail@admin.blackstump.com.au&gt;&lt;br /&gt;To:    mrlinuxhead@yahoo.com&lt;br /&gt;Subject:    eBay Unpaid Item Dispute #4858411651 -- response required&lt;br /&gt;From:    aw-confirm@ebay.com&lt;br /&gt;&lt;br /&gt;eBay Unpaid Item Dispute #4858411651 -- response required  &lt;br /&gt;&lt;br /&gt;Dear member,&lt;br /&gt;eBay member moviemars-uk has indicated that they already paid for item #4858411651&lt;br /&gt;Review the submitted details regarding the payment.&lt;br /&gt;&lt;br /&gt;Regards,&lt;br /&gt;eBay International AG&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Bogus eBay link points to:&lt;br /&gt;http://ns1.zerotrance.net/.sign/eBayISAPI.dllSignInco_partnerIdpUserIdsiteidpageTypepa1i1bshowgifUsingSSL862984con462msgMNSIEhufem37ajhd84Sllencrypt378/signin.ebay.com/&lt;br /&gt;&lt;br /&gt;Of couse I email "spoof@ebay.com and paste the bogus link into phishfighting.com.&lt;br /&gt;&lt;br /&gt;Using DNSStuff let's see who we are dealing with....&lt;br /&gt;&lt;br /&gt;The IP address of the email relay is: 209.216.209.10&lt;br /&gt;&lt;br /&gt;And they are .... in San Diego, Califorina.  Busted.&lt;br /&gt;This is just the email server that delivered the scam email.&lt;br /&gt;&lt;br /&gt;IP address:                     209.216.209.10&lt;br /&gt;Reverse DNS:                    admin.blackstump.com.au.&lt;br /&gt;Reverse DNS authenticity:       [Verified]&lt;br /&gt;ASN:                            6130&lt;br /&gt;ASN Name:                       ADN-WEST&lt;br /&gt;IP range connectivity:          0&lt;br /&gt;Registrar (per ASN):            ARIN&lt;br /&gt;Country (per IP registrar):     US [United States]&lt;br /&gt;Country Currency:               USD [United States Dollars]&lt;br /&gt;Country IP Range:               209.216.192.0 to 209.216.255.255&lt;br /&gt;Country fraud profile:          Normal&lt;br /&gt;City (per outside source):      San Diego, California&lt;br /&gt;Private (internal) IP?          No&lt;br /&gt;&lt;br /&gt;Sneaky little bastards blocked the WHOIS lookup, but I got the DNS servers..&lt;br /&gt;&lt;br /&gt;blackstump.com.au.    A    IN    3600    209.216.209.10&lt;br /&gt;blackstump.com.au.    NS    IN    3600    ns2.webintellects.com.&lt;br /&gt;blackstump.com.au.    NS    IN    3600    ns1.webintellects.com.&lt;br /&gt;ns2.webintellects.com.    A    IN    3600    209.126.236.3&lt;br /&gt;ns1.webintellects.com.    A    IN    3600    209.216.201.3&lt;br /&gt;&lt;br /&gt;Now lets see who is hosting the bogus web site. . .&lt;br /&gt;&lt;br /&gt;ns1.zerotrance.net.    A    IN    172800    85.234.144.88&lt;br /&gt;zerotrance.net.    NS    IN    172800    ns1.zerotrance.net.&lt;br /&gt;zerotrance.net.    NS    IN    172800    ns2.zerotrance.net.&lt;br /&gt;ns1.zerotrance.net.    A    IN    172800    85.234.144.88&lt;br /&gt;ns2.zerotrance.net.    A    IN    172800    85.234.144.89&lt;br /&gt;&lt;br /&gt;Chatchy name, eh? 85.234.144.88 is the IP of ns1.zerotrance.net&lt;br /&gt;&lt;br /&gt;That is located in. . The U.K.&lt;br /&gt;&lt;br /&gt;IP address:                     85.234.144.88&lt;br /&gt;Reverse DNS:                    ns1.zerotrance.net.&lt;br /&gt;Reverse DNS authenticity:       [Verified]&lt;br /&gt;ASN:                            29550&lt;br /&gt;ASN Name:                       EUROCONNEX-AS (Euroconnex Networks LLP)&lt;br /&gt;IP range connectivity:          5&lt;br /&gt;Registrar (per ASN):            RIPE&lt;br /&gt;Country (per IP registrar):     GB [United Kingdom]&lt;br /&gt;Country Currency:               GBP [United Kingdom Pounds]&lt;br /&gt;Country IP Range:               85.234.128.0 to 85.234.159.255&lt;br /&gt;Country fraud profile:          Normal&lt;br /&gt;City (per outside source):      Unknown&lt;br /&gt;Private (internal) IP?          No&lt;br /&gt;&lt;br /&gt;The ISP phone numbers are here:&lt;br /&gt;&lt;br /&gt;inetnum:        85.234.128.0 - 85.234.159.255&lt;br /&gt;org:            ORG-PIS3-RIPE&lt;br /&gt;netname:        UK-POUNDHOST-20050429&lt;br /&gt;descr:          PoundHost Internet Services&lt;br /&gt;country:        GB&lt;br /&gt;admin-c:        MM5420-RIPE&lt;br /&gt;admin-c:        KW725-RIPE&lt;br /&gt;tech-c:         MM5420-RIPE&lt;br /&gt;status:         ALLOCATED PA&lt;br /&gt;remarks:        PH-Network (Europe)&lt;br /&gt;mnt-by:         RIPE-NCC-HM-MNT&lt;br /&gt;mnt-lower:      POUNDHOST&lt;br /&gt;mnt-routes:     POUNDHOST&lt;br /&gt;mnt-routes:     AS5413-MNT&lt;br /&gt;notify:         Matthew@Poundhost.com&lt;br /&gt;changed:        hostmaster@ripe.net 20050429&lt;br /&gt;source:         RIPE&lt;br /&gt;&lt;br /&gt;organisation:   ORG-PIS3-RIPE&lt;br /&gt;org-name:       PoundHost Internet Services&lt;br /&gt;org-type:       LIR&lt;br /&gt;address:        PoundHost Internet Services,&lt;br /&gt;              Ginchy House,&lt;br /&gt;              Marsh Lane,&lt;br /&gt;              Taplow,&lt;br /&gt;              Maidenhead,&lt;br /&gt;              Berkshire.&lt;br /&gt;              SL6 0DE&lt;br /&gt;              ENGLAND&lt;br /&gt;phone:          +44 (0) 870 744 1700&lt;br /&gt;fax-no:         +44 1628 639977&lt;br /&gt;e-mail:         Info@poundhost.com&lt;br /&gt;admin-c:        MM5420-RIPE&lt;br /&gt;admin-c:        LP1106-RIPE&lt;br /&gt;mnt-ref:        POUNDHOST&lt;br /&gt;mnt-ref:        RIPE-NCC-HM-MNT&lt;br /&gt;mnt-by:         RIPE-NCC-HM-MNT&lt;br /&gt;source:         RIPE&lt;br /&gt;&lt;br /&gt;person:         Matthew Munson&lt;br /&gt;address:        Euroconnex Networks LLP,&lt;br /&gt;              Marsh Lane,&lt;br /&gt;              Taplow,&lt;br /&gt;              Maidenhead, UK&lt;br /&gt;phone:          +44 870 744 1700&lt;br /&gt;e-mail:         matthew@euroconnex.net&lt;br /&gt;nic-hdl:        MM5420-RIPE&lt;br /&gt;remarks:        ******************************************************&lt;br /&gt;remarks:        Please contact abuse@euroconnex.net for any abuse issues&lt;br /&gt;remarks:        E-mail sent to other addresses may not be acted upon.&lt;br /&gt;remarks:        ******************************************************&lt;br /&gt;mnt-by:         EUROCONNEX&lt;br /&gt;changed:        matthew@poundhost.com 20050721&lt;br /&gt;source:         RIPE&lt;br /&gt;&lt;br /&gt;person:       Katalin Weigand&lt;br /&gt;address:      PoundHost Internet Services,&lt;br /&gt;            Marsh Lane,&lt;br /&gt;            Taplow,&lt;br /&gt;            Maidenhead, UK&lt;br /&gt;phone:        +44 870 744 1700&lt;br /&gt;e-mail:       Katalin@poundhost.com&lt;br /&gt;nic-hdl:      KW725-RIPE&lt;br /&gt;remarks:      ******************************************************&lt;br /&gt;remarks:      Please contact abuse@PoundHost.com for all abuse issues&lt;br /&gt;remarks:      ******************************************************&lt;br /&gt;mnt-by:       POUNDHOST&lt;br /&gt;changed:      matthew@poundhost.com 20030827&lt;br /&gt;changed:      matthew@poundhost.com 20031009&lt;br /&gt;changed:      Katalin@poundhost.com 20031010&lt;br /&gt;source:       RIPE&lt;br /&gt;&lt;br /&gt;% Information related to '85.234.128.0/19AS29550'&lt;br /&gt;&lt;br /&gt;route:          85.234.128.0/19&lt;br /&gt;descr:          PH-Network Europe, operated by Euroconnex Networks LLP&lt;br /&gt;origin:         AS29550&lt;br /&gt;remarks:        *********************************************&lt;br /&gt;remarks:        For Peering and more info: www.euroconnex.net&lt;br /&gt;remarks:        *********************************************&lt;br /&gt;mnt-by:         POUNDHOST&lt;br /&gt;changed:        Matthew@PoundHost.com 20050601&lt;br /&gt;source:         RIPE&lt;br /&gt;&lt;br /&gt;email addresses are:&lt;br /&gt;abuse@PoundHost.com&lt;br /&gt;matthew@euroconnex.net&lt;br /&gt;Katalin@poundhost.com&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Now, lets see who owns the domain zerotrance.net, shall we..&lt;br /&gt;&lt;br /&gt;WHOIS info is blocked by these clowns:&lt;br /&gt;Whois Privacy Protection Service, Inc.&lt;br /&gt;&lt;br /&gt;Domain name: zerotrance.net&lt;br /&gt;&lt;br /&gt;Registrant Contact:&lt;br /&gt; Whois Privacy Protection Service, Inc.&lt;br /&gt; Whois Agent (sxdysbyxvq@whoisprivacyprotect.com)&lt;br /&gt; +1.4252740657&lt;br /&gt; Fax: +1.4256960234&lt;br /&gt; PMB 368, 14150 NE 20th St - F1&lt;br /&gt; C/O zerotrance.net&lt;br /&gt; Bellevue, WA 98007&lt;br /&gt; US&lt;br /&gt;&lt;br /&gt;Administrative Contact:&lt;br /&gt; Whois Privacy Protection Service, Inc.&lt;br /&gt; Whois Agent (sxdysbyxvq@whoisprivacyprotect.com)&lt;br /&gt; +1.4252740657&lt;br /&gt; Fax: +1.4256960234&lt;br /&gt; PMB 368, 14150 NE 20th St - F1&lt;br /&gt; C/O zerotrance.net&lt;br /&gt; Bellevue, WA 98007&lt;br /&gt; US&lt;br /&gt;&lt;br /&gt;Technical Contact:&lt;br /&gt; Whois Privacy Protection Service, Inc.&lt;br /&gt; Whois Agent (sxdysbyxvq@whoisprivacyprotect.com)&lt;br /&gt; +1.4252740657&lt;br /&gt; Fax: +1.4256960234&lt;br /&gt; PMB 368, 14150 NE 20th St - F1&lt;br /&gt; C/O zerotrance.net&lt;br /&gt; Bellevue, WA 98007&lt;br /&gt; US&lt;br /&gt;&lt;br /&gt;Status: Locked&lt;br /&gt;&lt;br /&gt;Name Servers:&lt;br /&gt; ns1.zerotrance.net&lt;br /&gt; ns2.zerotrance.net&lt;br /&gt;&lt;br /&gt;Creation date: 10 Nov 2005 05:18:38&lt;br /&gt;Expiration date: 10 Nov 2007 05:18:38&lt;br /&gt;&lt;br /&gt;I emailed the admin at the UK ISP to shut down these clowns.&lt;br /&gt;&lt;br /&gt;Later...&lt;/test@admin.blackstump.com.au&gt;&lt;div class="blogger-post-footer"&gt;
&lt;div class='adsense' style='text-align:center; padding: 0px 3px 0.5em 3px;'&gt;
&lt;script type="text/javascript"&gt;&lt;!--
google_ad_client="ca-pub-9456629394253923";
google_ad_width=468;
google_ad_height=60;
google_ad_format="468x60_as";
google_ad_type="text";
google_color_border="FFFFFF";
google_color_bg="FFFFFF";
google_color_link="333333";
google_color_url="333333";
google_color_text="993333";
//--&gt;&lt;/script&gt;
&lt;script type="text/javascript"
  src="http://pagead2.googlesyndication.com/pagead/show_ads.js"&gt;
&lt;/script&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26986700-114607322467413206?l=phish-finder.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phish-finder.blogspot.com/feeds/114607322467413206/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26986700&amp;postID=114607322467413206&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26986700/posts/default/114607322467413206'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26986700/posts/default/114607322467413206'/><link rel='alternate' type='text/html' href='http://phish-finder.blogspot.com/2006/04/another-ebay-scam-artist-emailed-me.html' title='Another eBay scam artist emailed me tonight blackstump.com.au'/><author><name>Mr. Phish Finder</name><uri>http://www.blogger.com/profile/07920773754442475692</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26986700.post-114607315096659262</id><published>2006-04-26T10:39:00.001-07:00</published><updated>2006-04-26T17:53:49.616-07:00</updated><title type='text'>I got a question from an eBay buyer tonight. How sweet.</title><content type='html'>I got a question from an eBay buyer tonight. How sweet. I don't have anything for sale on eBay.&lt;br /&gt;&lt;br /&gt;Game on. Your ass is mine soon. . .&lt;br /&gt;&lt;br /&gt;here is your real url: &lt;a href="http://3717423647/%7Esilverfoil/index.html/.ws/www.ebay.com/index.html" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)"&gt;http://3717423647/~silverfoil&lt;wbr&gt;/index.html/.ws/www.ebay.com&lt;wbr&gt;/index.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Here is the the message (for what is matters):&lt;br /&gt; &lt;br /&gt;Â Question from cdesteve&lt;br /&gt;Item: (8403494162)&lt;br /&gt;This message was sent while the listing was active.&lt;br /&gt;cdesteve is a potential buyer.&lt;br /&gt;Still no answer from you!Will this deal go through?At least send me a message please!&lt;br /&gt; &lt;br /&gt;Respond to this question in My Messages.&lt;br /&gt;Respond Now&lt;br /&gt; &lt;br /&gt;   Item Details&lt;br /&gt;Item number:     8403494162&lt;br /&gt;End date:     Apr-13-06 01:39:15 PDT&lt;br /&gt;View item description:&lt;br /&gt;&lt;a href="http://cgi.ebay.com/ws/eBayISAPI.dll?ViewItem&amp;item=8403494162&amp;amp;sspagename=ADME:B:AAQ:US:1" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)"&gt;http://cgi.ebay.com/ws/eBayISAP&lt;wbr&gt;I.dll?ViewItem&amp;item=8403494162&lt;wbr&gt;&amp;amp;sspagename=ADME:B:AAQ:US:1&lt;/a&gt;&lt;br /&gt;Thank you for using eBay!&lt;br /&gt;&lt;a href="http://www.ebay.com/" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)"&gt;http://www.ebay.com/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;URL is really pointing to : &lt;a href="http://3717423647/%7Esilverfoil/index.html/.ws/www.ebay.com/index.html" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)"&gt;http://3717423647/~silverfoil&lt;wbr&gt;/index.html/.ws/www.ebay.com&lt;wbr&gt;/index.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Do you really think I wont track you down?!&lt;br /&gt;http://3717423647/~silverfoil/index.html/.ws/www.ebay.com/index.html&lt;br /&gt;&lt;br /&gt;221.147.98.31&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;IP address:                     221.147.98.31&lt;br /&gt;Reverse DNS:                    [No reverse DNS entry per rev1.kornet.net.]&lt;br /&gt;Reverse DNS authenticity:       [Unknown]&lt;br /&gt;ASN:                            4766&lt;br /&gt;ASN Name:                       KIXS-AS-KR (Korea Telecom)&lt;br /&gt;IP range connectivity:          5&lt;br /&gt;Registrar (per ASN):            APNIC&lt;br /&gt;Country (per IP registrar):     KR [Korea-KR]&lt;br /&gt;Country Currency:               KRW [Korea (South) Won]&lt;br /&gt;Country IP Range:               221.144.0.0 to 221.159.255.255&lt;br /&gt;Country fraud profile:          Normal&lt;br /&gt;City (per outside source):      Unknown&lt;br /&gt;Private (internal) IP?          No&lt;br /&gt;IP address registrar:           whois.apnic.net&lt;br /&gt;Known Proxy?                    No&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;WHOIS results for 221.147.98.31&lt;br /&gt;Generated by www.DNSstuff.com&lt;br /&gt;&lt;br /&gt;Location: Korea-KR&lt;br /&gt;&lt;br /&gt;ARIN says that this IP belongs to APNIC; I'm looking it up there.&lt;br /&gt;&lt;br /&gt;APNIC says that this IP belongs to KRNIC; I'm looking it up there.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;query: 221.147.98.31&lt;br /&gt;&lt;br /&gt;??? ???          : +82-2-3674-5708&lt;br /&gt;???? ????          : **@ns.kornet.net&lt;br /&gt;&lt;br /&gt;??? ???          : +82-2-3674-5708&lt;br /&gt;???? ????          : **@ns.kornet.net&lt;br /&gt;??? ???          : 080-223-5577&lt;br /&gt;???? ????          : *****@kornet.net&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;IPv4 Address       : 221.147.98.0-221.147.98.255&lt;br /&gt;Network Name       : KORNET-10359345650&lt;br /&gt;Connect ISP Name   : KORNET&lt;br /&gt;Publishes          : N&lt;br /&gt;&lt;br /&gt;[ Organization Information ]&lt;br /&gt;Organization ID    : ORG526451&lt;br /&gt;Org Name           : KT&lt;br /&gt;Address            : Sinchon-dong, Seodaemun-gu&lt;br /&gt;Zip Code           : 120140&lt;br /&gt;&lt;br /&gt;[ Technical Contact Information ]&lt;br /&gt;Org Name           : KT&lt;br /&gt;Address            : Sinchon-dong, Seodaemun-gu&lt;br /&gt;Zip Code           : 120140&lt;br /&gt;&lt;br /&gt;--------------------------------------------------------------------------------&lt;br /&gt;&lt;br /&gt;If the above contacts are not reachable, please contact following ISP&lt;br /&gt;for further information.&lt;br /&gt;&lt;br /&gt;[ ISP IPv4 Admin Contact Information ]&lt;br /&gt;Name               : IP Administrator&lt;br /&gt;Phone              : +82-2-3674-5708&lt;br /&gt;E-Mail             : **@ns.kornet.net&lt;br /&gt;&lt;br /&gt;[ ISP IPv4 Tech Contact Information ]&lt;br /&gt;Name               : IP Manager&lt;br /&gt;Phone              : +82-2-3674-5708&lt;br /&gt;E-Mail             : **@ns.kornet.net&lt;br /&gt;&lt;br /&gt;[ ISP Network Abuse Contact Information ]&lt;br /&gt;Name               : Network Abuse&lt;br /&gt;Phone              : 080-223-5577&lt;br /&gt;E-Mail             : *****@kornet.net&lt;div class="blogger-post-footer"&gt;
&lt;div class='adsense' style='text-align:center; padding: 0px 3px 0.5em 3px;'&gt;
&lt;script type="text/javascript"&gt;&lt;!--
google_ad_client="ca-pub-9456629394253923";
google_ad_width=468;
google_ad_height=60;
google_ad_format="468x60_as";
google_ad_type="text";
google_color_border="FFFFFF";
google_color_bg="FFFFFF";
google_color_link="333333";
google_color_url="333333";
google_color_text="993333";
//--&gt;&lt;/script&gt;
&lt;script type="text/javascript"
  src="http://pagead2.googlesyndication.com/pagead/show_ads.js"&gt;
&lt;/script&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26986700-114607315096659262?l=phish-finder.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phish-finder.blogspot.com/feeds/114607315096659262/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26986700&amp;postID=114607315096659262&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26986700/posts/default/114607315096659262'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26986700/posts/default/114607315096659262'/><link rel='alternate' type='text/html' href='http://phish-finder.blogspot.com/2006/04/i-got-question-from-ebay-buyer-tonight.html' title='I got a question from an eBay buyer tonight. How sweet.'/><author><name>Mr. Phish Finder</name><uri>http://www.blogger.com/profile/07920773754442475692</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26986700.post-114607318959589874</id><published>2006-04-26T10:39:00.000-07:00</published><updated>2006-04-26T10:39:49.606-07:00</updated><title type='text'>How Sweet, letter from another eBay customer.</title><content type='html'>How Sweet, letter from another eBay customer. Lets fry this clown..&lt;br /&gt;Here is the text of the scam email :&lt;br /&gt;   &lt;br /&gt;Â Question from mmjd1996&lt;br /&gt;Item: (4629414062)&lt;br /&gt;This message was sent while the listing was active.&lt;br /&gt;mmjd1996 is a potential buyer.&lt;br /&gt;Hi, how much would be shipping to Germany? Thanks&lt;br /&gt;&lt;br /&gt;Using DNSStuff I find out our scammers IP address.&lt;br /&gt;&lt;br /&gt;eBay.com URL points to:&lt;br /&gt;http://1393442438/img/...bleh/signin.ebay.com/ws/eBayISAPI.dll/SignIn.htm&lt;br /&gt;&lt;br /&gt;1393442438 is decimal for 83.14.62.134&lt;br /&gt;&lt;br /&gt;Seems to be a box on some DSL line in Poland..&lt;br /&gt;&lt;br /&gt;IP address:                     83.14.62.134&lt;br /&gt;Reverse DNS:                    dyk134.internetdsl.tpnet.pl.&lt;br /&gt;Reverse DNS authenticity:       [Verified]&lt;br /&gt;ASN:                            5617&lt;br /&gt;ASN Name:                       TPNET (Polish Telecom's commercial IP network)&lt;br /&gt;IP range connectivity:          2&lt;br /&gt;Registrar (per ASN):            RIPE&lt;br /&gt;Country (per IP registrar):     PL [Poland]&lt;br /&gt;Country Currency:               PLN [Poland Zlotych]&lt;br /&gt;Country IP Range:               83.0.0.0 to 83.31.255.255&lt;br /&gt;&lt;br /&gt;The ISP is Poland Telecom. Here are the ISP contact numbers and email addresses.&lt;br /&gt;&lt;br /&gt;role:           TP S.A. Hostmaster&lt;br /&gt;address:        TP S.A. "POLPAK"&lt;br /&gt;address:        ul. Nowogrodzka 47A&lt;br /&gt;address:        00-695 Warszawa&lt;br /&gt;address:        Poland&lt;br /&gt;phone:          +48 22 6252383&lt;br /&gt;fax-no:         +48 22 6225182&lt;br /&gt;remarks:        trouble:      Network problems: hostmaster@tpnet.pl&lt;br /&gt;remarks:        trouble:      Abuse and spam notification: abuse@tpnet.pl&lt;br /&gt;remarks:        trouble:      DNS problems: dns@tpnet.pl&lt;br /&gt;remarks:        trouble:      Routing problems: registry@tpnet.pl&lt;br /&gt;admin-c:        TK569-RIPE&lt;br /&gt;tech-c:         TK569-RIPE&lt;br /&gt;tech-c:         JS1838-RIPE&lt;br /&gt;nic-hdl:        TPHT&lt;br /&gt;remarks:        ! - ! - ! - ! - ! - ! - ! - ! - ! - ! - !&lt;br /&gt;remarks:        Please send spam and abuse notification only to abuse@tpnet.pl&lt;br /&gt;remarks:        ! - ! - ! - ! - ! - ! - ! - ! - ! - ! - !&lt;br /&gt;mnt-by:         TPNET&lt;br /&gt;e-mail:         hostmaster@tpnet.pl&lt;br /&gt;abuse-mailbox:  abuse@tpnet.pl&lt;br /&gt;changed:        hostmaster@tpnet.pl 20030122&lt;br /&gt;changed:        hostmaster@tpnet.pl 20030904&lt;br /&gt;changed:        hostmaster@tpnet.pl 20060306&lt;br /&gt;source:         RIPE&lt;br /&gt;&lt;br /&gt;person:       Tomasz Kielb&lt;br /&gt;address:      TP S.A. - POLPAK&lt;br /&gt;address:      ul. Nowogrodzka 47A&lt;br /&gt;address:      00-695 Warszawa&lt;br /&gt;address:      POLAND&lt;br /&gt;remarks:      ! - ! - ! - ! - ! - ! - ! - ! - ! - ! - ! - ! - ! - !&lt;br /&gt;remarks:&lt;br /&gt;remarks:      In case of abuse (intrusion attempts, hacking,&lt;br /&gt;remarks:      spamming or other unaccepted behavior) from&lt;br /&gt;remarks:      TP S.A. address space, please contact only to:&lt;br /&gt;remarks:&lt;br /&gt;remarks:      abuse@tpnet.pl&lt;br /&gt;remarks:&lt;br /&gt;remarks:      ! - ! - ! - ! - ! - ! - ! - ! - ! - ! - ! - ! - ! - !&lt;br /&gt;phone:        +48 800 120 810&lt;br /&gt;phone:        +48 800 120 811&lt;br /&gt;fax-no:       +48 22 5230178&lt;br /&gt;e-mail:       Tomasz.Kielb@telekomunikacja.pl&lt;br /&gt;nic-hdl:      TK569-RIPE&lt;br /&gt;mnt-by:       TPNET&lt;br /&gt;changed:      tkielb@cst.tpsa.pl 19970730&lt;br /&gt;changed:      tkielb@cst.tpsa.pl 20011003&lt;br /&gt;changed:      tomasz.kielb@telekomunikacja.pl 20021129&lt;br /&gt;changed:      tomasz.kielb@telekomunikacja.pl 20030114&lt;br /&gt;changed:      hostmaster@tpnet.pl 20030904&lt;br /&gt;changed:      hostmaster@tpnet.pl 20041220&lt;br /&gt;source:       RIPE&lt;br /&gt;&lt;br /&gt;person:         Jaroslaw Salamon&lt;br /&gt;address:        TP S.A. -POLPAK&lt;br /&gt;address:        ul. Nowogrodzka 47A&lt;br /&gt;address:        00-695 Warszawa&lt;br /&gt;address:        POLAND&lt;br /&gt;remarks:&lt;br /&gt;remarks:        !=====================================================&lt;br /&gt;remarks:&lt;br /&gt;remarks:        In case of abuse (intrusion attempts, hacking,&lt;br /&gt;remarks:        spamming or other unaccepted behavior) from&lt;br /&gt;remarks:        TP S.A. address space, please contact only to:&lt;br /&gt;remarks:&lt;br /&gt;remarks:        abuse@telekomunikacja.pl&lt;br /&gt;remarks:&lt;br /&gt;remarks:        !=====================================================&lt;br /&gt;remarks:&lt;br /&gt;phone:          +48 800 120 810&lt;br /&gt;phone:          +48 800 120 811&lt;br /&gt;fax-no:         +48 22 5230178&lt;br /&gt;e-mail:         Jaroslaw.Salamon@telekomunikacja.pl&lt;br /&gt;nic-hdl:        JS1838-RIPE&lt;br /&gt;mnt-by:         TPNET&lt;br /&gt;changed:        tkielb@cst.tpsa.pl 20000727&lt;br /&gt;changed:        hostmaster@tpnet.pl 20030904&lt;br /&gt;changed:        hostmaster@tpnet.pl 20031211&lt;br /&gt;changed:        hostmaster@tpnet.pl 20060407&lt;br /&gt;source:         RIPE&lt;br /&gt;&lt;br /&gt;person:       Konrad Plich&lt;br /&gt;address:      TP S.A. CST POLPAK&lt;br /&gt;address:      ul. Sienkiewicza 9&lt;br /&gt;address:      97-300 Piotrkow Tryb.&lt;br /&gt;address:      Poland&lt;br /&gt;remarks:      ---------------------------------------------&lt;br /&gt;remarks:      In case of abuse (intrusion attempts, hacking,&lt;br /&gt;remarks:      spamming or other unaccepted behavior) from&lt;br /&gt;remarks:      TP S.A. address space, please mail only to:&lt;br /&gt;remarks:      abuse@tpnet.pl&lt;br /&gt;remarks:      ----------------------------------------------&lt;br /&gt;phone:        + 48 44 6480030&lt;br /&gt;fax-no:       + 48 44 6473572&lt;br /&gt;e-mail:       konradpl@piotrkow.tpsa.pl&lt;br /&gt;nic-hdl:      KP21-RIPE&lt;br /&gt;mnt-by:       AS5617-MNT&lt;br /&gt;changed:      konradpl@piotrkow.tpsa.pl 20031001&lt;br /&gt;source:       RIPE&lt;br /&gt;&lt;br /&gt;So I shoot a quick email to the boys at Polish Telecom (abuse@tpnet.pl)&lt;br /&gt;&lt;br /&gt;I also paste the bougus URL into PhishFighing.com.&lt;br /&gt;That feeds our "Phisherman" with hundreds of bogus usernames and passwords.&lt;br /&gt;That should keep him busy for a few days.&lt;br /&gt;Just another day ho hum.&lt;div class="blogger-post-footer"&gt;
&lt;div class='adsense' style='text-align:center; padding: 0px 3px 0.5em 3px;'&gt;
&lt;script type="text/javascript"&gt;&lt;!--
google_ad_client="ca-pub-9456629394253923";
google_ad_width=468;
google_ad_height=60;
google_ad_format="468x60_as";
google_ad_type="text";
google_color_border="FFFFFF";
google_color_bg="FFFFFF";
google_color_link="333333";
google_color_url="333333";
google_color_text="993333";
//--&gt;&lt;/script&gt;
&lt;script type="text/javascript"
  src="http://pagead2.googlesyndication.com/pagead/show_ads.js"&gt;
&lt;/script&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26986700-114607318959589874?l=phish-finder.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phish-finder.blogspot.com/feeds/114607318959589874/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26986700&amp;postID=114607318959589874&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26986700/posts/default/114607318959589874'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26986700/posts/default/114607318959589874'/><link rel='alternate' type='text/html' href='http://phish-finder.blogspot.com/2006/04/how-sweet-letter-from-another-ebay.html' title='How Sweet, letter from another eBay customer.'/><author><name>Mr. Phish Finder</name><uri>http://www.blogger.com/profile/07920773754442475692</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26986700.post-114607311968279133</id><published>2006-04-26T10:38:00.000-07:00</published><updated>2006-04-26T10:38:39.683-07:00</updated><title type='text'></title><content type='html'>Â Question from snoboy2k&lt;br /&gt;Item: (6863632227)&lt;br /&gt;This message was sent while the listing was active.&lt;br /&gt;snoboy2k is a potential buyer.&lt;br /&gt;What would the shipping cost be to West Virginia zip code 25511?&lt;br /&gt;   &lt;br /&gt;Respond to this question in My Messages.&lt;br /&gt;Respond Now&lt;br /&gt;   &lt;br /&gt;    Item Details&lt;br /&gt;Item number:     6863632227&lt;br /&gt;End date:     Mar-27-06 01:43:11 PST&lt;br /&gt;View item description:&lt;br /&gt;http://cgi.ebay.com/ws/eBayISAPI.dll?ViewItem&amp;item=6863632227&amp;amp;sspagename=ADME:B:AAQ:US:1&lt;br /&gt;Thank you for using eBay!&lt;br /&gt;http://www.ebay.com/&lt;br /&gt;&lt;br /&gt;http://1121800143/test/.index/index.htm&lt;br /&gt;66.221.79.207&lt;br /&gt;&lt;br /&gt;IP address:                     66.221.79.207&lt;br /&gt;Reverse DNS:                    ez4.propagation.net.&lt;br /&gt;Reverse DNS authenticity:       [Verified]&lt;br /&gt;ASN:                            14501&lt;br /&gt;ASN Name:                       CIHOST&lt;br /&gt;IP range connectivity:          2&lt;br /&gt;Registrar (per ASN):            ARIN&lt;br /&gt;Country (per IP registrar):     US [United States]&lt;br /&gt;Country Currency:               USD [United States Dollars]&lt;br /&gt;Country IP Range:               66.221.0.0 to 66.221.255.255&lt;br /&gt;Country fraud profile:          Normal&lt;br /&gt;City (per outside source):      Ft. Worth, Texas&lt;br /&gt;Private (internal) IP?          No&lt;br /&gt;IP address registrar:           whois.arin.net&lt;br /&gt;Known Proxy?                    No&lt;br /&gt;&lt;br /&gt;OrgName:    C I Host&lt;br /&gt;OrgID:      CIHS&lt;br /&gt;Address:    1851 Central Drive&lt;br /&gt;Address:    #110&lt;br /&gt;City:       Bedford&lt;br /&gt;StateProv:  TX&lt;br /&gt;PostalCode: 76112&lt;br /&gt;Country:    US&lt;br /&gt;&lt;br /&gt;NetRange:   66.221.0.0 - 66.221.255.255&lt;br /&gt;CIDR:       66.221.0.0/16&lt;br /&gt;NetName:    CIHOST7&lt;br /&gt;NetHandle:  NET-66-221-0-0-1&lt;br /&gt;Parent:     NET-66-0-0-0-0&lt;br /&gt;NetType:    Direct Allocation&lt;br /&gt;NameServer: NS.CIHOST.COM&lt;br /&gt;NameServer: NS2.CIHOST.COM&lt;br /&gt;Comment:    ADDRESSES WITHIN THIS BLOCK ARE NON-PORTABLE&lt;br /&gt;RegDate:    2002-01-17&lt;br /&gt;Updated:    2002-06-17&lt;br /&gt;&lt;br /&gt;RTechHandle: NC61-ARIN&lt;br /&gt;RTechName:   Network Operations Center&lt;br /&gt;RTechPhone:  +1-888-868-9931&lt;br /&gt;RTechEmail:  noc@cihost.com&lt;br /&gt;&lt;br /&gt;OrgAbuseHandle: ABUSE821-ARIN&lt;br /&gt;OrgAbuseName:   Abuse&lt;br /&gt;OrgAbusePhone:  +1-888-868-9931&lt;br /&gt;OrgAbuseEmail:  abuse@cihost.com&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;       Administrative Contact :     &lt;br /&gt;       Propagation Networks&lt;br /&gt;       admin@PROPAGATION.NET&lt;br /&gt;       1851 CENTRAL DR STE 110&lt;br /&gt;       BEDFORD, TX 76021-5865&lt;br /&gt;       US&lt;br /&gt;       Phone: 800-607-0123&lt;br /&gt;      &lt;br /&gt;       Technical Contact :     &lt;br /&gt;       Propagation Networks,&lt;br /&gt;       noc@PROPAGATION.NET&lt;br /&gt;       1851 Central Drive Suite 110&lt;br /&gt;       Bedford, TX 76021&lt;br /&gt;       US&lt;br /&gt;       Phone: 800-605-5438&lt;br /&gt;       Fax: 888-242-7554&lt;br /&gt;      &lt;br /&gt;       Record expires on 31-May-2006    &lt;br /&gt;       Record created on 01-Jun-1998&lt;br /&gt;       Database last updated on 08-Jul-2004&lt;br /&gt;&lt;br /&gt;       Domain servers in listed order:     Manage DNS&lt;br /&gt;&lt;br /&gt;       NS.PROPAGATION.NET        216.221.160.10     &lt;br /&gt;       NS2.PROPAGATION.NET        216.221.162.106     &lt;br /&gt;       NS3.PROPAGATION.NET        63.249.128.204&lt;div class="blogger-post-footer"&gt;
&lt;div class='adsense' style='text-align:center; padding: 0px 3px 0.5em 3px;'&gt;
&lt;script type="text/javascript"&gt;&lt;!--
google_ad_client="ca-pub-9456629394253923";
google_ad_width=468;
google_ad_height=60;
google_ad_format="468x60_as";
google_ad_type="text";
google_color_border="FFFFFF";
google_color_bg="FFFFFF";
google_color_link="333333";
google_color_url="333333";
google_color_text="993333";
//--&gt;&lt;/script&gt;
&lt;script type="text/javascript"
  src="http://pagead2.googlesyndication.com/pagead/show_ads.js"&gt;
&lt;/script&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26986700-114607311968279133?l=phish-finder.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phish-finder.blogspot.com/feeds/114607311968279133/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26986700&amp;postID=114607311968279133&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26986700/posts/default/114607311968279133'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26986700/posts/default/114607311968279133'/><link rel='alternate' type='text/html' href='http://phish-finder.blogspot.com/2006/04/question-from-snoboy2k-item-6863632227.html' title=''/><author><name>Mr. Phish Finder</name><uri>http://www.blogger.com/profile/07920773754442475692</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26986700.post-114607309765697362</id><published>2006-04-26T10:37:00.001-07:00</published><updated>2006-04-26T10:38:17.656-07:00</updated><title type='text'>Â Question from bigmoney</title><content type='html'>Â Question from bigmoney&lt;br /&gt;Item: (6852613597)&lt;br /&gt;This message was sent while the listing was active.&lt;br /&gt;bigmoney is a potential buyer.&lt;br /&gt;What is the last price for this Item?&lt;br /&gt;   &lt;br /&gt;Respond to this question in My Messages.&lt;br /&gt;Respond Now&lt;br /&gt;   &lt;br /&gt;    Item Details&lt;br /&gt;Item number:     6852613597&lt;br /&gt;End date:     Mar-01-06 18:33:23 PST&lt;br /&gt;View item description:&lt;br /&gt;http://cgi.ebay.com/ws/eBayISAPI.dll?ViewItem&amp;item=7387869660&amp;amp;sspagename=ADME:B:AAQ:US:1&lt;br /&gt;Thank you for using eBay!&lt;br /&gt;http://www.ebay.com/&lt;br /&gt;&lt;br /&gt;http://1088880691/%20/signin.ebay.com/ws/eBayISAPI/index.html&lt;br /&gt;&lt;br /&gt;IP 64.231.0.51 is decimal 1088880691.&lt;br /&gt;&lt;br /&gt;IP address:                     64.231.0.51&lt;br /&gt;Reverse DNS:                    [No reverse DNS entry per ns3.bellglobal.com.]&lt;br /&gt;Reverse DNS authenticity:       [Unknown]&lt;br /&gt;ASN:                            577&lt;br /&gt;ASN Name:                       BACOM&lt;br /&gt;IP range connectivity:          1&lt;br /&gt;Registrar (per ASN):            ARIN&lt;br /&gt;Country (per IP registrar):     CA [Canada]&lt;br /&gt;Country Currency:               CAD [Canada Dollars]&lt;br /&gt;Country IP Range:               64.228.0.0 to 64.231.255.255&lt;br /&gt;Country fraud profile:          Normal&lt;br /&gt;City (per outside source):      Toronto, Ontario&lt;br /&gt;&lt;br /&gt;That's a BellCanada IP block:&lt;br /&gt;Bell Canada BELLCANADA-5 (NET-64-228-0-0-1)       64.228.0.0 - 64.231.255.255&lt;br /&gt;Bell Nexxia (HSE) NEXXIAJ10-CA (NET-64-231-0-0-1) 64.231.0.0 - 64.231.95.255&lt;br /&gt;&lt;br /&gt;No WHOIS records exist for this IP, and there was no reverse DNS information I could glean.&lt;br /&gt;It is probably a personal computer that has been hacked, and is under someone else's control.&lt;br /&gt;&lt;br /&gt;Time for us to take a collection and buy this poor sucker a firewall. Any donations?&lt;br /&gt;&lt;br /&gt;Here is a port scan. Our scammer box is infected with the W32.MyDoom virus, like many other hosts.&lt;br /&gt;&lt;br /&gt;This is probably the vector for the exploit. I see this on lots of other targets.&lt;br /&gt;I suspect that may be the port that receive control messages.&lt;br /&gt;Also it's running half-life engine (port 27015)! Lots of other exploited servers are as well.&lt;br /&gt;The HTTP deamon is Apache and return the ID Celestix celnx. Hmmm who could that be I wonder?&lt;br /&gt;&lt;br /&gt;WWhatever let's take them down. I called up phishfighing.com and pasted the URL in. Nothing happened!&lt;br /&gt;Whatever this one is doing, nothing shows up in the usernname/password box.&lt;br /&gt;He may be actively blocking phishfighing.com because that will poison their list of victims.&lt;br /&gt;&lt;br /&gt;Let's see if I can email the ISP and have this box shut down.&lt;div class="blogger-post-footer"&gt;
&lt;div class='adsense' style='text-align:center; padding: 0px 3px 0.5em 3px;'&gt;
&lt;script type="text/javascript"&gt;&lt;!--
google_ad_client="ca-pub-9456629394253923";
google_ad_width=468;
google_ad_height=60;
google_ad_format="468x60_as";
google_ad_type="text";
google_color_border="FFFFFF";
google_color_bg="FFFFFF";
google_color_link="333333";
google_color_url="333333";
google_color_text="993333";
//--&gt;&lt;/script&gt;
&lt;script type="text/javascript"
  src="http://pagead2.googlesyndication.com/pagead/show_ads.js"&gt;
&lt;/script&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26986700-114607309765697362?l=phish-finder.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phish-finder.blogspot.com/feeds/114607309765697362/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26986700&amp;postID=114607309765697362&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26986700/posts/default/114607309765697362'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26986700/posts/default/114607309765697362'/><link rel='alternate' type='text/html' href='http://phish-finder.blogspot.com/2006/04/question-from-bigmoney.html' title='Â Question from bigmoney'/><author><name>Mr. Phish Finder</name><uri>http://www.blogger.com/profile/07920773754442475692</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26986700.post-114607305558478272</id><published>2006-04-26T10:37:00.000-07:00</published><updated>2006-04-26T10:37:35.586-07:00</updated><title type='text'>Question from prescreened</title><content type='html'>Question from prescreened&lt;br /&gt;    About This Member&lt;br /&gt;    prescreened( 5792)&lt;br /&gt;    Positive Feedback:    100%&lt;br /&gt;    Member Since:    Apr-14-99&lt;br /&gt;    Location:    OH, United States&lt;br /&gt;    Registered On:    www.ebay.com&lt;br /&gt;&lt;br /&gt;Hey ,&lt;br /&gt;I'll send you the money today.When will you send the package ?&lt;br /&gt;&lt;br /&gt;Thanks !&lt;br /&gt;   &lt;br /&gt;Respond to this question in My Messages.&lt;br /&gt;Respond Now&lt;br /&gt;   &lt;br /&gt;prescreened&lt;br /&gt;Thank you for using eBay!&lt;br /&gt;http://www.ebay.com/&lt;br /&gt;&lt;br /&gt;http://www.steveariss.com/%20/Index.html&lt;br /&gt;&lt;br /&gt;Registrant:&lt;br /&gt; Steve Ariss&lt;br /&gt; 42 Lakefield Road&lt;br /&gt; Brampton, ON L7A 1W5&lt;br /&gt; CA&lt;br /&gt;&lt;br /&gt; Domain name: STEVEARISS.COM&lt;br /&gt;&lt;br /&gt; Administrative Contact:&lt;br /&gt;    Ariss, Steve  steveariss@rogers.com&lt;br /&gt;    42 Lakefield Road&lt;br /&gt;    Brampton, ON L7A 1W5&lt;br /&gt;    CA&lt;br /&gt;    416 508-8245&lt;br /&gt; Technical Contact:&lt;br /&gt;    Ariss, Steve  steveariss@rogers.com&lt;br /&gt;    42 Lakefield Road&lt;br /&gt;    Brampton, ON L7A 1W5&lt;br /&gt;    CA&lt;br /&gt;    416 508-8245&lt;br /&gt;&lt;br /&gt;&lt;br /&gt; Registrar of Record: easyDNS Technologies, Inc.&lt;br /&gt;&lt;br /&gt;Resolves to  69.194.147.254&lt;br /&gt;&lt;br /&gt;Reverse DNS:                    cpe000393086bfa-cm000f9f7f15b6.cpe.net.cable.rogers.com.&lt;br /&gt;Reverse DNS authenticity:       [Verified]&lt;br /&gt;ASN:                            812&lt;br /&gt;ASN Name:                       ROGERS-CABLE&lt;br /&gt;IP range connectivity:          1&lt;br /&gt;Registrar (per ASN):            ARIN&lt;br /&gt;Country (per IP registrar):     CA [Canada]&lt;br /&gt;Country Currency:               CAD [Canada Dollars]&lt;br /&gt;Country IP Range:               69.192.0.0 to 69.199.255.255&lt;br /&gt;Country fraud profile:          Normal&lt;br /&gt;City (per outside source):      Mississauga, Ontario&lt;br /&gt;Private (internal) IP?          No&lt;br /&gt;IP address registrar:           whois.arin.net&lt;br /&gt;Known Proxy?                    No&lt;br /&gt;&lt;br /&gt;Redirects to: http://www.domainsnipe.co.uk/.ebay/aw-cgi/index.html&lt;br /&gt;&lt;br /&gt; Domain name:&lt;br /&gt;        domainsnipe.co.uk&lt;br /&gt;&lt;br /&gt;    Registrant:&lt;br /&gt;        Matt Ashby&lt;br /&gt;&lt;br /&gt;    Registrant type:&lt;br /&gt;        UK Individual&lt;br /&gt;&lt;br /&gt;    Registrant's address:&lt;br /&gt;        Smallands Hall Farm&lt;br /&gt;        Spring Lane&lt;br /&gt;        Hatfield Peverel&lt;br /&gt;        CM3 2JW&lt;br /&gt;        GB&lt;br /&gt;&lt;br /&gt;    Registrant's agent:&lt;br /&gt;        Internet Assist Ltd [Tag = INTERNET-ASSIST]&lt;br /&gt;        URL: http://www.i-a.co.uk&lt;br /&gt;&lt;br /&gt;    Relevant dates:&lt;br /&gt;        Registered on: 08-Dec-2005&lt;br /&gt;        Renewal date:  08-Dec-2007&lt;br /&gt;&lt;br /&gt;    Registration status:&lt;br /&gt;        Registered until renewal date.&lt;br /&gt;&lt;br /&gt;    Name servers:&lt;br /&gt;        ns1.i-a.co.uk&lt;br /&gt;        ns2.i-a.co.uk&lt;br /&gt;&lt;br /&gt;IP address:                     217.151.101.69&lt;br /&gt;Reverse DNS:                    rack5.i-a.co.uk.&lt;br /&gt;Reverse DNS authenticity:       [Verified]&lt;br /&gt;ASN:                            21055&lt;br /&gt;ASN Name:                       WEBTAPESTRY-AS (Axamba Limited T/As Web Tapestry)&lt;br /&gt;IP range connectivity:          1&lt;br /&gt;Registrar (per ASN):            RIPE&lt;br /&gt;Country (per IP registrar):     GB [United Kingdom]&lt;br /&gt;Country Currency:               GBP [United Kingdom Pounds]&lt;br /&gt;Country IP Range:               217.151.96.0 to 217.151.111.255&lt;br /&gt;Country fraud profile:          Normal&lt;br /&gt;City (per outside source):      Unknown&lt;br /&gt;Private (internal) IP?          No&lt;br /&gt;IP address registrar:           whois.ripe.net&lt;br /&gt;Known Proxy?                    No&lt;br /&gt;&lt;br /&gt;steveariss@rogers.com&lt;br /&gt;info@i-a.co.uk&lt;div class="blogger-post-footer"&gt;
&lt;div class='adsense' style='text-align:center; padding: 0px 3px 0.5em 3px;'&gt;
&lt;script type="text/javascript"&gt;&lt;!--
google_ad_client="ca-pub-9456629394253923";
google_ad_width=468;
google_ad_height=60;
google_ad_format="468x60_as";
google_ad_type="text";
google_color_border="FFFFFF";
google_color_bg="FFFFFF";
google_color_link="333333";
google_color_url="333333";
google_color_text="993333";
//--&gt;&lt;/script&gt;
&lt;script type="text/javascript"
  src="http://pagead2.googlesyndication.com/pagead/show_ads.js"&gt;
&lt;/script&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26986700-114607305558478272?l=phish-finder.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phish-finder.blogspot.com/feeds/114607305558478272/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26986700&amp;postID=114607305558478272&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26986700/posts/default/114607305558478272'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26986700/posts/default/114607305558478272'/><link rel='alternate' type='text/html' href='http://phish-finder.blogspot.com/2006/04/question-from-prescreened.html' title='Question from prescreened'/><author><name>Mr. Phish Finder</name><uri>http://www.blogger.com/profile/07920773754442475692</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26986700.post-114607119009129110</id><published>2006-04-26T10:06:00.000-07:00</published><updated>2006-04-26T10:06:30.113-07:00</updated><title type='text'>I received ANOTHER "Phishing" attempt</title><content type='html'>I received ANOTHER "Phishing" attempt tonight. This one was a good laugh for me.&lt;br /&gt;It was to welcome me to join something called the "PowerSeller Silver Membership"&lt;br /&gt;What is so funny is I have sold exactly ONE item on eBay.&lt;br /&gt;I really don't think I qualify to be a "Power Seller", silver or any color!&lt;br /&gt;&lt;br /&gt;Of course I reported this to eBay, but they seem to be about as good at stopping these clowns as Bush seems to be at catching Osama BinLaden. I thought I would do some snooping on my own.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Here is the subject line. How thoughtful, they want ME to join their little club.&lt;br /&gt;&lt;br /&gt;Subject:Your PowerSeller Silver Membership&lt;br /&gt;From:    "eBay PowerSellers" &lt;ebay@noreply3.ebay.com&gt;&lt;br /&gt;Date:    Tue, 04 Apr 2006 22:10:35 +0000&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Orignal email link embedded in HTML of spoof email is:&lt;br /&gt;http://www.elitemarine.net/blog/archives/www.anaconda.com&lt;br /&gt;&lt;br /&gt;Reverse DNS points us to the evildoers:&lt;br /&gt;elitemarine.net.    A    IN    14400    66.228.123.163&lt;br /&gt;&lt;br /&gt;They are pretty sneaky about their information. They do however leave a email address:(spyhunter2000@bellsouth.net).&lt;br /&gt;&lt;br /&gt;Registration Service Provided By: Surpass Hosting&lt;br /&gt;Contact: enom@surpasshosting.com&lt;br /&gt;Visit: http://www.surpasshosting.com&lt;br /&gt;   &lt;br /&gt;Domain name: elitemarine.net&lt;br /&gt;Registrant Contact:&lt;br /&gt;   other&lt;br /&gt;   somename somename (spyhunter2000@bellsouth.net)&lt;br /&gt;   Fax: somephone&lt;br /&gt;   someaddress&lt;br /&gt;   somecity, SC somezip&lt;br /&gt;   US&lt;br /&gt;&lt;br /&gt;A google search for (spyhunter2000@bellsouth.net) lead to a page on www.teamxodus.com. Hmmm.&lt;br /&gt;&lt;br /&gt;This is only a jumping off point that points to the REAL spoof eBay site, as you will see here...&lt;br /&gt;&lt;br /&gt;That URL (www.elitemarine.net/blog/archives/www.anaconda.com) redirects to another site in Germany:&lt;br /&gt;&lt;br /&gt;http://projekt-pd.power-wlan.at/images/.PowerSellerpages.eBay.com/ws/eBayISAPII.dll/SignIn.html&lt;br /&gt;&lt;br /&gt;DNS reverse lookup using DNS Stuff&lt;br /&gt;&lt;br /&gt;projekt-pd.power-wlan.at.    A    IN    86400    62.141.48.148&lt;br /&gt;&lt;br /&gt;IP address:                     62.141.48.148&lt;br /&gt;Reverse DNS:                    ns.power-web34.net.&lt;br /&gt;Reverse DNS authenticity:       [Verified]&lt;br /&gt;ASN:                            31103&lt;br /&gt;ASN Name:                       KEYWEB-AS (Keyweb AG)&lt;br /&gt;IP range connectivity:          0&lt;br /&gt;Registrar (per ASN):            RIPE&lt;br /&gt;Country (per IP registrar):     DE [Germany]&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;WHOIS report on projekt-pd.power-wlan.at&lt;br /&gt;&lt;br /&gt;domain:         power-wlan.at&lt;br /&gt;registrant:     CD820810-NICAT&lt;br /&gt;admin-c:        CD820810-NICAT&lt;br /&gt;tech-c:         CD820810-NICAT&lt;br /&gt;zone-c:         CD820810-NICAT&lt;br /&gt;nserver:        ns.power-web34.net&lt;br /&gt;remarks:        62.141.48.148&lt;br /&gt;nserver:        ns2.power-web34.net&lt;br /&gt;remarks:        62.141.49.148&lt;br /&gt;changed:        20040503 16:31:12&lt;br /&gt;source:         AT-DOM&lt;br /&gt;&lt;br /&gt;personname:     Christian Dvorak&lt;br /&gt;organization:   power-web.at&lt;br /&gt;street address: Soedingberg 129&lt;br /&gt;postal code:    A-8152&lt;br /&gt;city:           Stallhofen&lt;br /&gt;country:        Austria&lt;br /&gt;phone:          +433142805280&lt;br /&gt;fax-no:         +433142805230&lt;br /&gt;e-mail:         domreg@power-web.at&lt;br /&gt;nic-hdl:        CD820810-NICAT&lt;br /&gt;changed:        20050409 10:35:11&lt;br /&gt;source:         AT-DOM&lt;br /&gt;&lt;br /&gt;inetnum:        62.141.48.0 - 62.141.55.255&lt;br /&gt;netname:        DE-KEYWEB-I&lt;br /&gt;descr:          Keyweb AG IP Network&lt;br /&gt;country:        DE&lt;br /&gt;admin-c:        MERO-RIPE&lt;br /&gt;tech-c:         MERO-RIPE&lt;br /&gt;status:         ASSIGNED PA&lt;br /&gt;mnt-by:         KEYWEB-MNT&lt;br /&gt;changed:        hostmaster@keyweb.de 20060217&lt;br /&gt;source:         RIPE&lt;br /&gt;&lt;br /&gt;WHOIS report on netblock:&lt;br /&gt;Information related to '62.141.48.0 - 62.141.55.255'&lt;br /&gt;&lt;br /&gt;person:         Holger Amberg&lt;br /&gt;address:        Keyweb AG&lt;br /&gt;address:        Neuwerkstrasse 45/46&lt;br /&gt;address:        99084 Erfurt&lt;br /&gt;address:        Germany&lt;br /&gt;e-mail:         ha@keyweb.de&lt;br /&gt;abuse-mailbox:  abuse@keyweb.de&lt;br /&gt;phone:          +49 361 658530&lt;br /&gt;fax-no:         +49 361 6585366&lt;br /&gt;nic-hdl:        MERO-RIPE&lt;br /&gt;mnt-by:         KEYWEB-MNT&lt;br /&gt;changed:        ha@keyweb.de 20050419&lt;br /&gt;source:         RIPE&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;A google for Mr. Christiian Dvorak leads to this web page and this contact info:&lt;br /&gt;&lt;br /&gt;POWER-WEB.AT, ING. CHRISTIAN DVORAK&lt;br /&gt;Eintrag korrigieren Kontakt  &lt;br /&gt;Strasse / Nr.:  SÖDINGBERG 6&lt;br /&gt;PLZ / Ort: 8152 STALLHOFEN&lt;br /&gt;Land  ÖSTERREICH&lt;br /&gt;E-Mail: office@power-web.at&lt;br /&gt;Telefon: 03142 80 52 80&lt;br /&gt;Fax: 03142 80 52 30&lt;br /&gt;URL: http://www.power-web.at&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;It is a web hosting company in SÖDINGBERG Austria.&lt;br /&gt;&lt;br /&gt;Someone should let Mr. Dvorak his server is being bad!&lt;br /&gt;&lt;br /&gt;What follows is the text of the email.&lt;br /&gt;&lt;br /&gt;To:    mrlinuxhead@yahoo.com&lt;br /&gt;Subject:Your PowerSeller Silver Membership&lt;br /&gt;From:    "eBay PowerSellers" &lt;ebay@noreply3.ebay.com&gt;&lt;br /&gt;Date:    Tue, 04 Apr 2006 22:10:35 +0000&lt;br /&gt;   &lt;br /&gt;Dear eBay Member,&lt;br /&gt;&lt;br /&gt;You've been on a super sales streak and since you've done so well, it's time to recognize you for your efforts. You are PowerSeller Silver!&lt;br /&gt;&lt;br /&gt;Congratulations! joining the eBay Silver PowerSeller Program. Come and join us. When you join the PowerSeller program, you'll be able to receive more of the support you'll need for continued success. So, why wait? Join now!&lt;br /&gt;   &lt;br /&gt;PowerSeller icon next to your User ID in recognition of your hard work.&lt;br /&gt;PowerSeller Priority Support via email webform and phone support at Silver level and above.&lt;br /&gt;Exclusive offerings on the PowerSeller portal--check in frequently to see updated program benefits and special offers!&lt;br /&gt;Discussion Board for you to network with other PowerSellers.&lt;br /&gt;Free PowerSeller Business Templates for business cards and letterhead.&lt;br /&gt;&lt;br /&gt;Membership to the PowerSeller program is FREE.&lt;br /&gt;&lt;br /&gt;Again, congratulations and best wishes for your continued success!&lt;br /&gt;&lt;br /&gt;Regards,&lt;br /&gt;eBay PowerSeller Team&lt;br /&gt;If you agree with this rank please Become an eBay Power Seller within 24 hours&lt;br /&gt;You are receiving this communication because you are part of the PowerSeller program. This is a one time communication. There is no need to unsubscribe. eBay will not request personal data (password, credit card/bank numbers) in an email.&lt;br /&gt;&lt;br /&gt;Copyright © 2003 eBay Inc. All Rights Reserved.&lt;br /&gt;Designated trademarks and brands are the property of their respective owners. eBay and the eBay logo are trademarks of eBay Inc.&lt;br /&gt;&lt;br /&gt;enom@surpasshosting.com&lt;br /&gt;domreg@power-web.at&lt;br /&gt;projekt-pd.power-wlan.at&lt;br /&gt;ha@keyweb.de&lt;br /&gt;abuse@keyweb.de&lt;br /&gt;hostmaster@keyweb.de&lt;div class="blogger-post-footer"&gt;
&lt;div class='adsense' style='text-align:center; padding: 0px 3px 0.5em 3px;'&gt;
&lt;script type="text/javascript"&gt;&lt;!--
google_ad_client="ca-pub-9456629394253923";
google_ad_width=468;
google_ad_height=60;
google_ad_format="468x60_as";
google_ad_type="text";
google_color_border="FFFFFF";
google_color_bg="FFFFFF";
google_color_link="333333";
google_color_url="333333";
google_color_text="993333";
//--&gt;&lt;/script&gt;
&lt;script type="text/javascript"
  src="http://pagead2.googlesyndication.com/pagead/show_ads.js"&gt;
&lt;/script&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26986700-114607119009129110?l=phish-finder.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://phish-finder.blogspot.com/feeds/114607119009129110/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26986700&amp;postID=114607119009129110&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26986700/posts/default/114607119009129110'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26986700/posts/default/114607119009129110'/><link rel='alternate' type='text/html' href='http://phish-finder.blogspot.com/2006/04/i-received-another-phishing-attempt.html' title='I received ANOTHER &quot;Phishing&quot; attempt'/><author><name>Mr. Phish Finder</name><uri>http://www.blogger.com/profile/07920773754442475692</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
