11/11/2008
how we found these astonishing new Belgian hacked sites used for phishing
maybe someone should tell them that they are liable because they didn't secure and monitor their website as they should
we have made the following combination. We have used the indication by the monitoring and defense network of arbor and the ASN research of Phishtank
Remember a phishing site only brings in money the first four hours after sending the spam and getting the server up.
mailserver of win.be is used to phish ebay
belgian server of VOIP services hacked to phish ebay
http://flink.be/parcbooks/or.html this is interesting because it only sends the surfer to another phishing site at blueoceannetwork.bonlive.com
this is a very strange hack, it gives a secure windows 2003 business server set up and the whois goes to Belgacom but it is being hacked to phish for the Italian Post and this is another one.
http://zwemvereniginglier.be/coppermine2/docs/runaccess.h...
http://www.sill-harker.be/frppl/paypal.fr/secure.htm
http://babamase.eu/img/ibs.bankwest.com.au/BWLogin/rib.as...
http://zulezuasz.net/img/bankroll/SrvPage.htm
http://www.phishtank.com/phish_detail.php?phish_id=510478 a very secure small enterprise as they are so secure....
http://www.everyoneweb.com/Habboti/ the most amateuristic one
http://134.78-78-194.adsl-static.isp.belgacom.be/aspnet_c... (this is a major website that has been hacked over and over again for all kinds of phish sites) see also http://134.78-78-194.adsl-static.isp.belgacom.be/Citrix/M...
http://mobitronics.be/pics/IRS/Internal%20Revenue%20Servi... (since 26th of october) IRS hack The US tax By the way THIS IS a secure webshop .......
http://57.204-78-194.adsl-fix.skynet.be/login.php
http://wezembeek-oppem.info/cache/IRS/Internal... Joomla server hacked for IRS fraud (the US tax man) as was the case with the site of this school http://sjca.be/IRS/Internal (both are cleaned now, but that will have been done after the 4 hours I suppose) and this http://control-it.be/portal/IRS_redirect.php offline like the whole site but the web never forgets
AND this is a site hosting probably malware downloads
http://www.phishtank.com/phish_detail.php?phish_id=548995
and another one here
and some even greater organisations are hacked for phishing (a hack is a hack)

Belgian networks to look out for phishing (because they are not well secured or have non-secured servers)
http://rss.phishtank.com/rss/asn/?asn=5432
http://rss.phishtank.com/rss/asn/?asn=29587
http://rss.phishtank.com/rss/asn/?asn=3304
http://rss.phishtank.com/rss/asn/?asn=9031
http://rss.phishtank.com/rss/asn/?asn=2611
http://rss.phishtank.com/rss/asn/?asn=39318
the good news is that .tk is now much more quick in stopping service to phishing sites with its free domainextension. http://www.five-hotel.tk/ is an example
13:46 | Permalink | Comments (2) | Email this
|
|
del.icio.us
|
|
Digg |
Facebook




Comments
http://www.five-hotel.tk/ is stopped by his original hoster (altervista.org - which is full of phished sites, fakes and scams, but generally manage to close them quite soon after signaling to phishtank).
Cya :)
Posted by: propriome | 11/12/2008
Respond to this commentOh... i almost forgot...
Happy birthday to belsec ;) :)
Posted by: propriome | 11/12/2008
Respond to this commentPost a comment