[nsp-sec] Phishing form @ AS10929

Gabriel Iovino giovino at ren-isac.net
Mon Jan 4 08:49:46 EST 2010


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Greetings,

Can anyone assist in getting this Phishing form taken offline?

[url] hxxp://www.intrawave.com/forms/use/colls/form1.html

> dig www.intrawave.com +short
> intrawave.com.
> 205.236.58.143

> whois -h whois.cymru.com 205.236.58.143
> AS      | IP               | AS Name
> 10929   | 205.236.58.143   | NETELLIGENT - Netelligent Hosting Services Inc.

I sent an email to the contact info listed in ARIN on 1/1/2010, no
response.

Sample phishing email attached.

Thank you.

Gabe

- --
Gabriel Iovino
Principal Security Engineer, REN-ISAC
http://www.ren-isac.net
24x7 Watch Desk +1(317)278-6630
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (MingW32)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/

iEYEARECAAYFAktB8foACgkQwqygxIz+pTuoLACePtno4ke73ZAuZOY+pgncB1Ir
qfMAn0MzxjR2d0y1b1uVxq2O0NDdS4Ny
=K5YV
-----END PGP SIGNATURE-----
-------------- next part --------------
An embedded and charset-unspecified text was scrubbed...
Name: sample_phish_message.txt
URL: <https://puck.nether.net/mailman/private/nsp-security/attachments/20100104/a2d1946f/attachment-0001.txt>


More information about the nsp-security mailing list