11/11/2008

how we found these astonishing new Belgian hacked sites used for phishing

maybe someone should tell them that they are liable because they didn't secure and monitor their website as they should

we have made the following combination. We have used the indication by the monitoring and defense network of arbor and the ASN research of Phishtank 

Remember a phishing site only brings in money the first four hours after sending the spam and getting the server up.

mailserver of win.be is used to phish ebay

belgian server of VOIP services hacked to phish ebay 

http://flink.be/parcbooks/or.html   this is interesting because it only sends the surfer to another phishing site at blueoceannetwork.bonlive.com

this is a very strange hack, it gives a secure windows 2003 business server set up and the whois goes to Belgacom but it is being hacked to phish for the Italian Post and this is another one.

http://zwemvereniginglier.be/coppermine2/docs/runaccess.h... 

http://www.sill-harker.be/frppl/paypal.fr/secure.htm

http://babamase.eu/img/ibs.bankwest.com.au/BWLogin/rib.as... 

http://zulezuasz.net/img/bankroll/SrvPage.htm

http://www.phishtank.com/phish_detail.php?phish_id=510478  a very secure small enterprise as they are so secure....

gdieuntso.com

coloneldi.com 

http://www.everyoneweb.com/Habboti/  the most amateuristic one

http://134.78-78-194.adsl-static.isp.belgacom.be/aspnet_c... (this is a major website that has been hacked over and over again for all kinds of phish sites) see also http://134.78-78-194.adsl-static.isp.belgacom.be/Citrix/M...

http://mobitronics.be/pics/IRS/Internal%20Revenue%20Servi...   (since 26th of october) IRS hack The US tax By the way THIS IS a secure webshop .......

http://57.204-78-194.adsl-fix.skynet.be/login.php

http://wezembeek-oppem.info/cache/IRS/Internal...  Joomla server hacked for IRS fraud (the US tax man) as was the case with the site of this school http://sjca.be/IRS/Internal (both are cleaned now, but that will have been done after the 4 hours I suppose) and this http://control-it.be/portal/IRS_redirect.php offline like the whole site but the web never forgets

AND this is a site hosting probably malware downloads

http://www.phishtank.com/phish_detail.php?phish_id=548995 

and another one here

and some even greater organisations are hacked for phishing (a hack is a hack)

len56

 

 Belgian networks to look out for phishing (because they are not well secured or have non-secured servers)

http://rss.phishtank.com/rss/asn/?asn=5432

http://rss.phishtank.com/rss/asn/?asn=29587

http://rss.phishtank.com/rss/asn/?asn=3304

http://rss.phishtank.com/rss/asn/?asn=9031

http://rss.phishtank.com/rss/asn/?asn=2611

http://rss.phishtank.com/rss/asn/?asn=39318

the good news is that .tk is now much more quick in stopping service to phishing sites with its free domainextension. http://www.five-hotel.tk/ is an example

13:46 | Permalink | Comments (2) | Email this | |  del.icio.us | | Digg! Digg |  Facebook

Comments

http://www.five-hotel.tk/ is stopped by his original hoster (altervista.org - which is full of phished sites, fakes and scams, but generally manage to close them quite soon after signaling to phishtank).

Cya :)

Posted by: propriome | 11/12/2008

Respond to this comment

Oh... i almost forgot...

Happy birthday to belsec ;) :)

Posted by: propriome | 11/12/2008

Respond to this comment

Post a comment