<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Nice Scam attempt! in Spam, Scam and Phishbusters</title>
<link>http://www.dslreports.com/forum/r20086554</link>
<description></description>
<language>en</language>
<pubDate>Sat, 30 Aug 2008 08:19:57 EDT</pubDate>
<lastBuildDate>Sat, 30 Aug 2008 08:19:57 EDT</lastBuildDate>

<item>
<title>Re: Nice Scam attempt!</title>
<link>http://www.dslreports.com/forum/remark,20428183</link>
<description><![CDATA[<A HREF="/useremail/u/795407"><b>SnowyOne</b></A> : <div class="bquote"><small>said by  Dude111 <A HREF="/useremail/u/853361"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>Well the redirector link is now down<br><br>&raquo;<A HREF="http://nwolb.com.606076a398.com/default.aspxrefererident=K4517E554A691503AD5945DAC57988718F5A0E10984A8&cookieid=92012&noscr=true/index.php" >nwolb.com.606076a398.com/default&middot;&middot;&middot;ndex.php</A><br><br>We are back to square 0......<br> </div>No, that's not true.<br>There's one less redirector on the net.<br>ps redirectors are not really special at all.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20428183</guid>
<pubDate>Sat, 03 May 2008 22:23:17 EDT</pubDate>
</item>

<item>
<title>Re: Nice Scam attempt!</title>
<link>http://www.dslreports.com/forum/remark,20427836</link>
<description><![CDATA[<A HREF="/useremail/u/853361"><b>Dude111</b></A> : Well the redirector link is now down<br><br>&raquo;<A HREF="http://nwolb.com.606076a398.com/default.aspxrefererident=K4517E554A691503AD5945DAC57988718F5A0E10984A8&cookieid=92012&noscr=true/index.php" >nwolb.com.606076a398.com/default&middot;&middot;&middot;ndex.php</A><br><br>We are back to square 0......]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20427836</guid>
<pubDate>Sat, 03 May 2008 21:06:08 EDT</pubDate>
</item>

<item>
<title>Re: Nice Scam attempt!</title>
<link>http://www.dslreports.com/forum/remark,20396447</link>
<description><![CDATA[<A HREF="/useremail/u/296798"><b>Dennis</b></A> : Stop the swearing, and stop the yelling.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20396447</guid>
<pubDate>Sun, 27 Apr 2008 19:14:20 EDT</pubDate>
</item>

<item>
<title>Re: Nice Scam attempt!</title>
<link>http://www.dslreports.com/forum/remark,20395774</link>
<description><![CDATA[<A HREF="/useremail/u/1195702"><b>Insder</b></A> : Right..But the amount of time it takes to GET those sites taken down is enough time for people to get scammed. The phishers have endless resources..we don't. Either post the redirector or shut the hell up, because you're not really helping anyone. The scams get taken down eventually either way, and our progress is little to none.<br><small>--<br>The one, the only, the <b>Insder</b>. :: Fighting phishing for life.</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20395774</guid>
<pubDate>Sun, 27 Apr 2008 16:22:55 EDT</pubDate>
</item>

<item>
<title>Re: Nice Scam attempt!</title>
<link>http://www.dslreports.com/forum/remark,20394931</link>
<description><![CDATA[<A HREF="/useremail/u/1003137"><b>garys_2k</b></A> : Stop shouting. The problem is that you're making no long term progress against the phisher's source machine but people here can do so IF you post that redirector. Whack-a-mole isn't going to go anywhere, it's just delaying the inevitable. If we can get to the redirector it CAN be traced back to the command and control box, get it?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20394931</guid>
<pubDate>Sun, 27 Apr 2008 12:43:15 EDT</pubDate>
</item>

<item>
<title>Re: Nice Scam attempt!</title>
<link>http://www.dslreports.com/forum/remark,20394046</link>
<description><![CDATA[<A HREF="/useremail/u/853361"><b>Dude111</b></A> : IF I POST THE RE-DIRECTOR IT WILL GO DOWN,THEY WILL JUST PUT UP ANOTHER ONE AND WE WONT KNOW ANY NEW SITES THEY PUT UP!!!!!<br><br>ITS BETTER CONTACTING THAT HOST THEY ARE WITH AND HAVING ALL SITES POINTED TO THAT LOCATION KILLED!!<br><br>YOUR NOT THINKING LOGICALLY......... IM TRYING TO HELP PEOPLE AND KILLING THE MAIN LINK WILL ONLY PUT US IN THE COLD!!]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20394046</guid>
<pubDate>Sun, 27 Apr 2008 06:00:09 EDT</pubDate>
</item>

<item>
<title>Re: Nice Scam attempt!</title>
<link>http://www.dslreports.com/forum/remark,20393168</link>
<description><![CDATA[<A HREF="/useremail/u/1195702"><b>Insder</b></A> : You're a moron. Please post the redirector link. All you're doing now is playing whack-a-mole, and I guarantee you'll lose (as we don't have an endless amount of cards to use to pay for those phished accounts). While you're at it...submit to the fucking &raquo;<A HREF="/phishtrack!">/phishtrack!</A><br><small>--<br>The one, the only, the <b>Insder</b>. :: Fighting phishing for life.</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20393168</guid>
<pubDate>Sat, 26 Apr 2008 22:22:34 EDT</pubDate>
</item>

<item>
<title>Re: Nice Scam attempt!</title>
<link>http://www.dslreports.com/forum/remark,20386905</link>
<description><![CDATA[<A HREF="/useremail/u/853361"><b>Dude111</b></A> : Yes but if thats taken down we are back to square 0 (We wont find out any of thier sites until they spam with another link) Its better getting the sites off the redirector and taking them down from there wouldnt you agree?<br><br>Contacting that host might be a start also....]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20386905</guid>
<pubDate>Fri, 25 Apr 2008 15:57:14 EDT</pubDate>
</item>

<item>
<title>Re: Nice Scam attempt!</title>
<link>http://www.dslreports.com/forum/remark,20386781</link>
<description><![CDATA[<A HREF="/useremail/u/666842"><b>MGD</b></A> : Are you sitting on a redirector link that you are holding, and it is pointing to the new sites as each one is taken down? Or are these new phish mails for each one ? I suspect the former.<br><br><div class="bquote"><small>said by  Dude111 <A HREF="/useremail/u/853361"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>They should just give it up!!  .......</div>Why?, it costs them nothing to do this, and they only have bank card data to gain.<br><br>They just registered a bunch of domains with prior phish victims cards, and paid for hosting the same way.<br><br>They were all hosted by &raquo;<A HREF="http://www.omnis.com/" >www.omnis.com/</A><br><br>[att=1][att=2]<br><br>If they do have a redirector as the phish link, they can play whack a mole with the host all day long, for free.<br><br>Is there a redirector link ?<br><br>MGD<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/20386781?c=1301107&ret=L2ZvcnVtL3IyMDA4NjU1NC54bWw%3D"><IMG class="apic" BORDER=0 TITLE="13805 bytes" WIDTH=600 HEIGHT=376 SRC="/r0/download/1301107.thumb600~ed896b199ce42892f0a8f20cfa752ad3/nakeplest.png/thumb.jpg" ALT="Click for full size"></A></TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/20386781?c=1301108&ret=L2ZvcnVtL3IyMDA4NjU1NC54bWw%3D"><IMG class="apic" BORDER=0 TITLE="13644 bytes" WIDTH=600 HEIGHT=382 SRC="/r0/download/1301108.thumb600~73a6c13cf08fbe652dbdde1feb8de2c5/abebale.png/thumb.jpg" ALT="Click for full size"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20386781</guid>
<pubDate>Fri, 25 Apr 2008 15:39:40 EDT</pubDate>
</item>

<item>
<title>Re: Nice Scam attempt!</title>
<link>http://www.dslreports.com/forum/remark,20386319</link>
<description><![CDATA[<A HREF="/useremail/u/853361"><b>Dude111</b></A> : They should just give it up!!<br><br>NEW LINK: &raquo;<A HREF="http://abebale.com/www.nwolb.com/default.aspxrefererident=G2517E524A67037F945DAC57952718F5A0E041A8&cookieid=92012&noscr=true/Login.html" >abebale.com/www.nwolb.com/defaul&middot;&middot;&middot;gin.html</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20386319</guid>
<pubDate>Fri, 25 Apr 2008 14:17:08 EDT</pubDate>
</item>

<item>
<title>Re: Nice Scam attempt!</title>
<link>http://www.dslreports.com/forum/remark,20386225</link>
<description><![CDATA[<A HREF="/useremail/u/616961"><b>SatManWorkin</b></A> : Looks like the word is already out on that page Norton Flags it!  :D<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/20386225?c=1301077&ret=L2ZvcnVtL3IyMDA4NjU1NC54bWw%3D"><IMG class="apic" BORDER=0 TITLE="73348 bytes" WIDTH=600 HEIGHT=347 SRC="/r0/download/1301077.thumb600~05615c36fbf5d80420e406ddb586e41c/flag.jpg/thumb.jpg" ALT="Click for full size"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20386225</guid>
<pubDate>Fri, 25 Apr 2008 14:04:49 EDT</pubDate>
</item>

<item>
<title>Re: Nice Scam attempt!</title>
<link>http://www.dslreports.com/forum/remark,20386108</link>
<description><![CDATA[<A HREF="/useremail/u/853361"><b>Dude111</b></A> : Seems like when 1 goes down they slap another up,How is this possible so fast??<br><br>NEW LINK: &raquo;<A HREF="http://abtemanail.com/www.nwolb.com/default.aspxrefererident=G2517E524A67037F945DAC57952718F5A0E041A8&cookieid=92012&noscr=true/Login.html" >abtemanail.com/www.nwolb.com/def&middot;&middot;&middot;gin.html</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20386108</guid>
<pubDate>Fri, 25 Apr 2008 13:48:27 EDT</pubDate>
</item>

<item>
<title>Re: Nice Scam attempt!</title>
<link>http://www.dslreports.com/forum/remark,20383823</link>
<description><![CDATA[<A HREF="/useremail/u/853361"><b>Dude111</b></A> : Down already :D<br><br>New link: &raquo;<A HREF="http://nakeplest.co.uk/default.aspxrefererident=G2517E524A67037F945DAC57952718F5A0E041A8&cookieid=92012&noscr=true/Login.html" >nakeplest.co.uk/default.aspxrefe&middot;&middot;&middot;gin.html</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20383823</guid>
<pubDate>Fri, 25 Apr 2008 02:40:32 EDT</pubDate>
</item>

<item>
<title>Re: Nice Scam attempt!</title>
<link>http://www.dslreports.com/forum/remark,20383534</link>
<description><![CDATA[<A HREF="/useremail/u/666842"><b>MGD</b></A> : Help stop it, submit the entire email to -----> &raquo;<A HREF="/phishtrack">/phishtrack</A> or if unable, post the email headers and redact your personal info.<br><br>MGD]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20383534</guid>
<pubDate>Fri, 25 Apr 2008 00:50:10 EDT</pubDate>
</item>

<item>
<title>Re: Nice Scam attempt!</title>
<link>http://www.dslreports.com/forum/remark,20383380</link>
<description><![CDATA[<A HREF="/useremail/u/853361"><b>Dude111</b></A> : Still at it!!!<br><br>&raquo;<A HREF="http://nwalobi.com/default.aspxrefererident=G2517E524A67037F945DAC57952718F5A0E041A8&cookieid=92012&noscr=true/Login.html" >nwalobi.com/default.aspxrefereri&middot;&middot;&middot;gin.html</A><br><br>Unreal (Yhey dont seem to give up)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20383380</guid>
<pubDate>Fri, 25 Apr 2008 00:07:58 EDT</pubDate>
</item>

<item>
<title>Re: Nice Scam attempt!</title>
<link>http://www.dslreports.com/forum/remark,20290090</link>
<description><![CDATA[<A HREF="/useremail/u/795407"><b>SnowyOne</b></A> : Over several thousand dismantled phish I've never seen that type of code being hosted with the phish. It must have been the phisher checking his logs & seeing your IP multiple times in the data stash & then manually mounting the attack against it.<br>Nothing really exciting like that ever happens to me, you lucky dog! :)<br><br>EDIT to add: I might as well use the space to dispell that widely held belief. Filling garbage data into a phish does not have any negative effect on the phisher. :(]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20290090</guid>
<pubDate>Sat, 05 Apr 2008 23:41:04 EDT</pubDate>
</item>

<item>
<title>Re: Nice Scam attempt!</title>
<link>http://www.dslreports.com/forum/remark,20289987</link>
<description><![CDATA[<A HREF="/useremail/u/197199"><b>Doctor Four</b></A> : <div class="bquote"><small>said by  SnowyOne <A HREF="/useremail/u/795407"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>At one point in time that was an effective hassle for the phisher. Nowadays there are scripts that will strip out the garbage in 5MB's of data in about 3 seconds.<br>Truth be known, when people fill in garbage data today at a phish they are more likely to be wasting their own time more than the phishers time. Actually it's not even more likely, it's absolutely positive. <br>I do like your way of thinking though! :)<br> </div>Not only that, but I think some of the botnet hosted ones may<br>have defensive countermeasures. A few weeks ago, I did this<br>about a dozen times with a Franklin Bank one, then went to<br>report it to Phishtracker. I then closed Firefox, and<br>within a few minutes, my modem lit up solid (or rather<br>blinking very fast) with unsolicited traffic. I couldn't<br>even get Google, my home page, to load. It sure seemed to<br>me like I was being DDoS'd, but I simply power cycled my<br>modem and got a new IP address. When I checked it in <br>Phishtracker a few minutes later, it was already dead.<br><small>--<br>"The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)<br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20289987</guid>
<pubDate>Sat, 05 Apr 2008 23:12:10 EDT</pubDate>
</item>

<item>
<title>Re: Nice Scam attempt!</title>
<link>http://www.dslreports.com/forum/remark,20286197</link>
<description><![CDATA[<A HREF="/useremail/u/795407"><b>SnowyOne</b></A> : At one point in time that was an effective hassle for the phisher. Nowadays there are scripts that will strip out the garbage in 5MB's of data in about 3 seconds.<br>Truth be known, when people fill in garbage data today at a phish they are more likely to be wasting their own time more than the phishers time. Actually it's not even more likely, it's absolutely positive. <br>I do like your way of thinking though! :)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20286197</guid>
<pubDate>Sat, 05 Apr 2008 03:41:08 EDT</pubDate>
</item>

<item>
<title>Re: Nice Scam attempt!</title>
<link>http://www.dslreports.com/forum/remark,20286156</link>
<description><![CDATA[<A HREF="/useremail/u/435505"><b>voogru</b></A> : You know, it might be worth it to setup an army of bots to go to phishing sites and submit fake but realistic looking data.<br><br>Such a thing would spam the phish sites with so much garbage that they would have a hard time finding the real data.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20286156</guid>
<pubDate>Sat, 05 Apr 2008 03:10:36 EDT</pubDate>
</item>

<item>
<title>Re: Nice Scam attempt!</title>
<link>http://www.dslreports.com/forum/remark,20183187</link>
<description><![CDATA[<A HREF="/useremail/u/666842"><b>MGD</b></A> : You're obviously on their mailing list. Appears to be the same phishpak as the previous one &raquo;<A HREF="http://natwast.biz/natwest/updateurnatwestbillinginformations/updateurnatwestbillinginformations/updateurnatwestbillinginformations/updateurnatwestbillinginformations/updateurnatwestbillinginformations/natwest/" >natwast.biz/natwest/updateurnatw&middot;&middot;&middot;natwest/</A> except this time they are on bluehost &raquo;<A HREF="http://network-tools.com/default.asp?prog=whois&host=natwast.biz" >network-tools.com/default.asp?pr&middot;&middot;&middot;wast.biz</A><br><br>Submit the entire phishmail to &raquo;<A HREF="/phishtrack">/phishtrack</A> so that  SnowyOne <A HREF="/useremail/u/795407"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> and  scott1527 <A HREF="/useremail/u/755787"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> can take a look at it. There may be some valuable data in the headers, that could match an existing profile.<br><br>Also the link will be shared in real time with block lists, which will reduce the potential victim pool.<br><br>MGD]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20183187</guid>
<pubDate>Tue, 18 Mar 2008 03:13:31 EDT</pubDate>
</item>

<item>
<title>Re: Nice Scam attempt!</title>
<link>http://www.dslreports.com/forum/remark,20182928</link>
<description><![CDATA[<A HREF="/useremail/u/853361"><b>Dude111</b></A> : These idiots dont seem to give up!!<br><br>New link: &raquo;<A HREF="http://natwast.biz/natwest/updateurnatwestbillinginformations/updateurnatwestbillinginformations/updateurnatwestbillinginformations/updateurnatwestbillinginformations/updateurnatwestbillinginformations/natwest/Login.aspx.htm" >natwast.biz/natwest/updateurnatw&middot;&middot;&middot;aspx.htm</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20182928</guid>
<pubDate>Tue, 18 Mar 2008 01:17:32 EDT</pubDate>
</item>

<item>
<title>Re: Nice Scam attempt!</title>
<link>http://www.dslreports.com/forum/remark,20101086</link>
<description><![CDATA[<A HREF="/useremail/u/853361"><b>Dude111</b></A> : I cant believe they wouldnt take a site down IMMEDIATLEY when they get a report!!!!! <br><br>This doesnt make sense to me!<br><br>And that email address listed above (<b>moonbear@chinagirlson.net</b>) is probably where all the data is emailed to.......]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20101086</guid>
<pubDate>Mon, 03 Mar 2008 15:45:37 EDT</pubDate>
</item>

<item>
<title>Re: Nice Scam attempt!</title>
<link>http://www.dslreports.com/forum/remark,20100174</link>
<description><![CDATA[<A HREF="/useremail/u/101498"><b>Kibbles</b></A> : It look like Pipex does have a decent AUP.<br><br>&raquo;<A HREF="http://www.pipex.co.uk/legal/aup.php" >www.pipex.co.uk/legal/aup.php</A><br><br>&raquo;<A HREF="http://www.iwf.org.uk/" >www.iwf.org.uk/</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20100174</guid>
<pubDate>Mon, 03 Mar 2008 13:17:39 EDT</pubDate>
</item>

<item>
<title>Re: Nice Scam attempt!</title>
<link>http://www.dslreports.com/forum/remark,20100070</link>
<description><![CDATA[<A HREF="/useremail/u/666842"><b>MGD</b></A> : <div class="bquote"><small>said by  Dude111 <A HREF="/useremail/u/853361"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>  :</small><br><br>....... I hope they quickly act on your report!<br> </div>Not very likely, which is why I initially went via the "support" route. I was able to get a reply from the support staff within the hour. However, they will not do anything about it:<br><br>  <blockquote><small>quote:</small><hr>Response (Greg D) - 03 Mar. 2008 04:54<br>Dear MGD,<br><br>Thank you for your support request.<br><br>All abuse notifications must go to abuse[at]pipex.net.<br><br>All notifications sent to other addresses will be ignored.<br><br><hr></blockquote><br><br>Of course the notice sent to pipex abuse has not been acted upon in over 12 hours. I am also sure they must have received prior complaints from that phish mailing. You posted this back on 02/29, so this phish site is at least into its fourth day of uptime. That makes it a very successful phish run for the phisher. Most of the data comes in the first 24 to 48 hours of uptime.<br><br>The issue for the unresponsive Pipex is, that if the scenario that this is a phisher's carded account is correct, he will keep coming back. They are essentially providing phish hosting services for free.<br><br>While I knew that support would respond a lot quicker than abuse, I thought that they would intervene since it was such an obvious fraud issue. <br><br>Many good hosting companies have a "shoot on sight" policy for phishing. Not only is that effective in removing them quickly, it also acts as a deterrent to keep phishers away from their network.<br><br>Obviously Webfusion / Pipex are clueless in that respect. In fact Webfusion does not list any information about abuse reporting on their contact page: &raquo;<A HREF="http://www.webfusion.co.uk/contact.php" >www.webfusion.co.uk/contact.php</A><br><br>MGD]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20100070</guid>
<pubDate>Mon, 03 Mar 2008 13:00:53 EDT</pubDate>
</item>

<item>
<title>Re: Nice Scam attempt!</title>
<link>http://www.dslreports.com/forum/remark,20099789</link>
<description><![CDATA[<A HREF="/useremail/u/853361"><b>Dude111</b></A> : Yes i found all those directories but i couldnt find the LOG files for entered data.... (Must be stored somewhere else)<br><br>I hope they quickly act on your report!]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20099789</guid>
<pubDate>Mon, 03 Mar 2008 12:11:06 EDT</pubDate>
</item>

<item>
<title>Re: Nice Scam attempt!</title>
<link>http://www.dslreports.com/forum/remark,20097926</link>
<description><![CDATA[<A HREF="/useremail/u/666842"><b>MGD</b></A> : <div class="bquote"><small>said by  Kibbles <A HREF="/useremail/u/101498"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>Is wvps212-241-210-148.vps the actual account/website the scammer has hosted by webfusion...if so can they be reported for fraud..then again they more than likely are using a stolen credit card?<br> </div>Yes it is either as  removed <A HREF="/useremail/u/581232"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> and  nwrickert <A HREF="/useremail/u/1070900"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> suggested, or as you stated purchased hosting using a previous phish victim's card and personal data.<br><br>If the later then the phisher opted for the 2.0 plus plan or the pro plan here: &raquo;<A HREF="http://www.webfusion.co.uk/virtual-private-servers/" >www.webfusion.co.uk/virtual-private-servers/</A> I can tell it is either of those two Virtual Private Hosting (VPS) Plans running on IP 212.241.210.148. A quick audit reveals that the machine is named VPS 342830, and is one of the above two plans, because it is running Win2k3 server:<br><br>[att=1]<br><br>Also has FTP running and Remote Terminal Services. Not sure of the significance of the sendmail_from <b>moonbear@chinagirlson.net</b> <br><br>[att=2]<br><br>as that domain was never set up on that IP or hosting service. However it was infiltrated by Turkish hackers: &raquo;<A HREF="http://www.google.com/search?hl=en&q=@chinagirlson.net" >www.google.com/search?hl=en&q=@c&middot;&middot;&middot;lson.net</A><br><br><div class="bquote"><small>said by  Dude111 <A HREF="/useremail/u/853361"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>Is anyone filling out thier info?..... </div>ergo, the suggestion to submit to &raquo;<A HREF="/phishtrack">/phishtrack</A>, as the focus will be on taking it down, plus it will be picked up by block lists. <br><br><div class="bquote"><small>said by  Dude111 <A HREF="/useremail/u/853361"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>......I have tried searching for the files (log files of entered data) but i cant find it,it must be emailing the data off server.......<br> </div>Yes, it is emailing the data. loginfinish.do.php dated 02/29 contains the email address where the data is being sent.<br><br>[att=3]<br><br>The rest of the phish files are here:<br><br>[att=4]<br><br>Heads up sent to Webfusion.co.uk via the account support panel:<br><br>[att=5] <br><br>MGD<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/20097926?c=1281844&ret=L2ZvcnVtL3IyMDA4NjU1NC54bWw%3D"><IMG TITLE="9698 bytes" BORDER=0 WIDTH=515 HEIGHT=411 SRC="/r0/download/1281844~5bcab05967b54b75e742bfa24129feef/Nwolb_phish_stats.png"></A></TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/20097926?c=1281845&ret=L2ZvcnVtL3IyMDA4NjU1NC54bWw%3D"><IMG TITLE="3352 bytes" BORDER=0 WIDTH=412 HEIGHT=144 SRC="/r0/download/1281845~bc3a7a5454466a3a888a6a36c6629922/Nwolb_phish_smtp.png"></A></TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/20097926?c=1281846&ret=L2ZvcnVtL3IyMDA4NjU1NC54bWw%3D"><IMG TITLE="7452 bytes" BORDER=0 WIDTH=431 HEIGHT=344 SRC="/r0/download/1281846~752b9bb07bd90b6aa1a8ddf0c7a9553d/Nwolb_phish_dir.png"></A></TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/20097926?c=1281847&ret=L2ZvcnVtL3IyMDA4NjU1NC54bWw%3D"><IMG TITLE="14458 bytes" BORDER=0 WIDTH=431 HEIGHT=575 SRC="/r0/download/1281847~f947aa26b75409ccd904e2260b97c7eb/Nwolb_phish_dirsub.png"></A></TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/20097926?c=1281848&ret=L2ZvcnVtL3IyMDA4NjU1NC54bWw%3D"><IMG class="apic" BORDER=0 TITLE="17857 bytes" WIDTH=600 HEIGHT=376 SRC="/r0/download/1281848.thumb600~c87e0d3ef5e6b4ebef4f20692659b775/webfusion_phish.png/thumb.jpg" ALT="Click for full size"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20097926</guid>
<pubDate>Sun, 02 Mar 2008 23:46:00 EDT</pubDate>
</item>

<item>
<title>Re: Nice Scam attempt!</title>
<link>http://www.dslreports.com/forum/remark,20093981</link>
<description><![CDATA[<A HREF="/useremail/u/853361"><b>Dude111</b></A> : Is anyone filling out thier info?<br><br>We must do exactly what they want and fill out every line (I just hope they like thier entries)  <IMG SRC="http://www.vwvortex.com/zeroforum_graphics/biggrin_upper.gif"> <br><br>I have tried searching for the files (log files of entered data) but i cant find it,it must be emailing the data off server.......]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20093981</guid>
<pubDate>Sun, 02 Mar 2008 10:08:23 EDT</pubDate>
</item>

<item>
<title>Re: Nice Scam attempt!</title>
<link>http://www.dslreports.com/forum/remark,20091590</link>
<description><![CDATA[<A HREF="/useremail/u/581232"><b>removed</b></A> : <div class="bquote"><small>said by  Kibbles <A HREF="/useremail/u/101498"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>Is wvps212-241-210-148.vps the actual account/website the scammer has hosted by webfusion...if so can they be reported for fraud..then again they more than likely are using a stolen credit card?<br> </div>My personal experience is that 90% of these scams are simply being uploaded via insecure scripts. The server's administrator and the ISP have no idea that this is being done ... this is why it helps to submit phishing attempts to the phishtracker and services such as SpamCop. :)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20091590</guid>
<pubDate>Sat, 01 Mar 2008 19:33:10 EDT</pubDate>
</item>

<item>
<title>Re: Nice Scam attempt!</title>
<link>http://www.dslreports.com/forum/remark,20091418</link>
<description><![CDATA[<A HREF="/useremail/u/1070900"><b>nwrickert</b></A> : Yes, the actual website is at wvps212-241-211-79.vps.webfusion.co.uk.  However, the owner of that computer may not even be aware of the problem.  The computer has been trojanized, and the installed malware is running the phish page.<br><small>--<br>AT&T dsl; Westell 327w modem/router; SuSE 10.1; firefox 2.0.0.12</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20091418</guid>
<pubDate>Sat, 01 Mar 2008 18:54:01 EDT</pubDate>
</item>

<item>
<title>Re: Nice Scam attempt!</title>
<link>http://www.dslreports.com/forum/remark,20091015</link>
<description><![CDATA[<A HREF="/useremail/u/101498"><b>Kibbles</b></A> : Is wvps212-241-210-148.vps the actual account/website the scammer has hosted by webfusion...if so can they be reported for fraud..then again they more than likely are using a stolen credit card?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20091015</guid>
<pubDate>Sat, 01 Mar 2008 17:16:03 EDT</pubDate>
</item>

<item>
<title>Re: Nice Scam attempt!</title>
<link>http://www.dslreports.com/forum/remark,20089146</link>
<description><![CDATA[<A HREF="/useremail/u/197199"><b>Doctor Four</b></A> : If you use Firefox, it includes a phishing filter. If you<br>click on "help" on the top menu, there's an item named <br>"report web forgery". You'll have to enter some captcha in <br>order to continue, but you may have saved a less savvy <br>Firefox user from being scammed.<br><small>--<br>"The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)<br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20089146</guid>
<pubDate>Sat, 01 Mar 2008 10:50:04 EDT</pubDate>
</item>

<item>
<title>Re: Nice Scam attempt!</title>
<link>http://www.dslreports.com/forum/remark,20087565</link>
<description><![CDATA[<A HREF="/useremail/u/853361"><b>Dude111</b></A> :  <blockquote><small>said by removed :</small><hr>Just your run of the mill phishing site..<hr></blockquote>Yes..... Isnt it amazing how they all look the same?? (You can spot them a mile away :D)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20087565</guid>
<pubDate>Fri, 29 Feb 2008 23:23:08 EDT</pubDate>
</item>

<item>
<title>Re: Nice Scam attempt!</title>
<link>http://www.dslreports.com/forum/remark,20087509</link>
<description><![CDATA[<A HREF="/useremail/u/1070900"><b>nwrickert</b></A> : You can submit these to &raquo;<A HREF="/phishtrack">/phishtrack</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20087509</guid>
<pubDate>Fri, 29 Feb 2008 23:13:26 EDT</pubDate>
</item>

<item>
<title>Re: Nice Scam attempt!</title>
<link>http://www.dslreports.com/forum/remark,20087501</link>
<description><![CDATA[<A HREF="/useremail/u/581232"><b>removed</b></A> : Just your run of the mill phishing site...]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20087501</guid>
<pubDate>Fri, 29 Feb 2008 23:11:43 EDT</pubDate>
</item>

<item>
<title>Nice Scam attempt!</title>
<link>http://www.dslreports.com/forum/remark,20086554</link>
<description><![CDATA[<A HREF="/useremail/u/853361"><b>Dude111</b></A> : In one of my throw away email accounts i got this message with this link to "update my bank info" :D<br><br>&raquo;<A HREF="http://wvps212-241-211-79.vps.webfusion.co.uk/nwolb.com/default.aspxrefererident=B2517E554A67037F945DAC57988718F5A0E052A8&cookieid=92012&noscr=true/secure.php" >wvps212-241-211-79.vps.webfusion&middot;&middot;&middot;cure.php</A><br><br>Notice how you can enter ANYTHING and click next (I entered all bogus data :D)<br><br>Sadly though,there are people that do fall for these things and its sad.......<br><br>Here is the <b>real site</b> for this bank :)<br><br>&raquo;<small>https</small>://<A HREF="https://www.nwolb.com/default.aspx?refererident=5FF889BBC8F50527B062B0B2B213A078C2EBF89A&cookieid=7295&noscr=true&CookieCheck=2008-03-01T01:00:47">www.nwolb.com/default.aspx?refer&middot;&middot;&middot;01:00:47</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20086554</guid>
<pubDate>Fri, 29 Feb 2008 20:10:54 EDT</pubDate>
</item>

</channel>
</rss>
