
I'm getting a few of these just right now and site is active (
http://www.turf-enuff.com/_vti_cgi/kiwibank/ ) for those that want to
block their customers.
Full email below for those who want to take further etc.
Delivered-To: ian.mcdonald(a)jandi.co.nz
Received: by 10.114.196.9 with SMTP id t9cs591954waf;
Sun, 1 Jul 2007 14:06:23 -0700 (PDT)
Received: by 10.100.14.19 with SMTP id 19mr3328957ann.1183323983222;
Sun, 01 Jul 2007 14:06:23 -0700 (PDT)
Return-Path: http://www.kiwibank.co.nz/images/products/products_nav_accounts.gif"
</td></tr>
<tr>
<td><img
SRC="http://www.commbank.com.au/commonimages/arrow.gif" alt="Arrow"
hspace="5"><a rel="nofollow"
target="_blank" href="http://turf-enuff.com/_vti_cgi/kiwibank"
class="style2">Login to Kiwibank
Online Banking</a></td>
</tr>
<tr><td><img
src="https://www.anz.com/common/img/misc/trans_dot.gif" width="1"
height="4"></td></tr>
</table>
</td>
</tr>
</table>
</td>
</tr>
<tr valign="top">
<td> </td>
<td align="center"> </td>
</tr>
</table>
</td>
</tr>
</table>
<table width="100%" border="0" cellspacing="0" cellpadding="0" align="center">
<tr>
<td><hr noshade color="#CCCCCC" size="1"></td>
</tr>
<tr>
<td>
<p align="center" class="textfooter1"><span class="discsmallgrey">
� Kiwibank 1996, 2002, 2003-2007</span> </p>
</td>
</tr>
</table>
<br>
</html>
</div>
--
Web: http://wand.net.nz/~iam4/
Blog: http://iansblog.jandi.co.nz
WAND Network Research Group

Hi, team. Just a bit of insight to share.
Received: from ls4.ilvu.net (ls4.ilvu.net [67.19.38.132])
This IP shows up as bot'd as far back as 2007-01-10 at 07:55:51 GMT. I'm not surprised it's sending spam or participating in a phishing excursion. The turf-enuff.com host on which the phishing site appears to reside has been hosting both malware and phishing sites. We've seen the following URLs there (URLs slightly obfuscated to protect folks - be CAREFUL!): timestamp | ip | asn | category | comment ---------------------+-----------------+-------+------------ +----------------------------------------------------------------------- ----------------------------- 2007-06-23 13:07:20 | 206.221.179.151 | 32445 | malwareurl | hxxp:// www.allyoumiss.net/phpwcms_ftp/ 2007-06-23 13:18:12 | 206.221.179.151 | 32445 | malwareurl | hxxp:// www.alpine-framing.com/e107_files/ 2007-06-24 00:36:00 | 206.221.179.151 | 32445 | phishing | hxxp:// www.allyoumiss.net/phpwcms_ftp/www.banamex.com/ bancanetempresarial.banamex.com.mx/index.htm 2007-06-24 00:36:00 | 206.221.179.151 | 32445 | phishing | hxxp:// www.allyoumiss.net/phpwcms_ftp/www.banamex.com/boveda.banamex.com.mx/ serban/ 2007-07-01 03:57:15 | 206.221.179.151 | 32445 | phishing | hxxp:// www.warranty-tracking.com/warranty/logins/updates/us/webscr.php I don't believe we know anyone at AS32445, so we'll reach out to their upstreams AS174 and AS5769 and see if we can get this host cleaned. Thanks, Rob. -- Rob Thomas Team Cymru http://www.cymru.com/ cmn_err(do_panic, "Out of coffee!");
participants (2)
-
Ian McDonald
-
Rob Thomas