<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>PhishTank Blog &#187; Verifying phishes</title>
	<atom:link href="http://www.phishtank.com/blog/category/verifying-phishes/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.phishtank.com/blog</link>
	<description>A blog about and from PhishTank, a collaborative clearinghouse for data about phishing.</description>
	<lastBuildDate>Fri, 05 Mar 2010 23:01:36 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Phishing for clicks, at my expense</title>
		<link>http://www.phishtank.com/blog/2007/09/07/phishing-for-ad-clicks/</link>
		<comments>http://www.phishtank.com/blog/2007/09/07/phishing-for-ad-clicks/#comments</comments>
		<pubDate>Fri, 07 Sep 2007 19:50:39 +0000</pubDate>
		<dc:creator>John Roberts</dc:creator>
				<category><![CDATA[PhishTank]]></category>
		<category><![CDATA[Verifying phishes]]></category>
		<category><![CDATA[Yahoo]]></category>

		<guid isPermaLink="false">http://www.phishtank.com/blog/2007/09/07/phishing-for-ad-clicks/</guid>
		<description><![CDATA[Phishers keep following the money, even via more indirect routes, like sponsored search advertising.]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.phishtank.com/images/status_isaphish.gif" align="right" valign="top" height="51" width="51" />Banks, credit unions, PayPal, eBay, Amazon, the IRS&#8230; all of these organizations suffer from phishing attacks on a regular basis. (Sad, but true.)</p>
<p>Yesterday morning, I personally received an example of a new (to me) category of phish: someone trying to get me to provide Yahoo credentials. Not my personal Yahoo credentials, but my &#8220;Sponsored Search&#8221; account, where I&#8217;d control my advertising spend with Yahoo Search Marketing&#8230;if I had an account!</p>
<p>I suppose the purpose was to steal my credentials and then have &#8220;me&#8221; schedule <strong>and pay for</strong> pay-per-click advertising on behalf of the criminal. Phishers keep following the money, even via more indirect routes.</p>
<ul class="bulleted">
<li>The phish: http://yahincmarketing.com/Login.html (purposefully not linked)</li>
<li>PhishTank submission: <a href="http://www.phishtank.com/phish_detail.php?phish_id=316499">http://www.phishtank.com/phish_detail.php?phish_id=316499</a></li>
<li>Real URL: <a href="https://login.marketingsolutions.yahoo.com/">https://login.marketingsolutions.yahoo.com/</a> (redirects to another Yahoo.com URL, but totally legitimate!)</li>
</ul>
<p>The phisher even copied the Javascript popup from the legitimate site encouraging me to bookmark this new location!</p>
<p>Note: Besides the community&#8217;s vote (thank you!), I&#8217;ve notified someone at Yahoo Search Marketing, so I would expect and hope this site will be taken offline rapidly. It&#8217;s already blocked for <a href="http://www.opendns.com/">OpenDNS</a> customers, of course.</p>
<p><strong>whois info:</strong></p>
<pre>
Domain name: yahincmarketing.com

Registrant:
   Jim Johnson  (SROW-615849)
   mdumi82u@aol.com
   5 rue de Thorigny
   PAris   PARIS
   75003   FR
   +33 42719715
</pre>
]]></content:encoded>
			<wfw:commentRss>http://www.phishtank.com/blog/2007/09/07/phishing-for-ad-clicks/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>PhishTank on WashingonPost.com; phishers pretend to be Uncle Sam on tax day</title>
		<link>http://www.phishtank.com/blog/2007/04/17/phishtank-on-washingonpostcom-phishers-pretend-to-be-uncle-sam-on-tax-day/</link>
		<comments>http://www.phishtank.com/blog/2007/04/17/phishtank-on-washingonpostcom-phishers-pretend-to-be-uncle-sam-on-tax-day/#comments</comments>
		<pubDate>Tue, 17 Apr 2007 22:40:17 +0000</pubDate>
		<dc:creator>Allison</dc:creator>
				<category><![CDATA[Community]]></category>
		<category><![CDATA[PhishTank]]></category>
		<category><![CDATA[PhishTank in the news]]></category>
		<category><![CDATA[Verifying phishes]]></category>

		<guid isPermaLink="false">http://www.phishtank.com/blog/2007/04/17/phishtank-on-washingonpostcom-phishers-pretend-to-be-uncle-sam-on-tax-day/</guid>
		<description><![CDATA[PhishTank on WashingtonPost.com]]></description>
			<content:encoded><![CDATA[<p>&#8220;Tax time means fraud time,&#8221; writes <a href="http://blog.washingtonpost.com/securityfix/2007/04/tax_time_means_fraud_time.html">Washington Post</a> security blogger Brian Krebs. I know you agree with Brian because you voted &#8220;is a phish&#8221; on <a href="http://www.phishtank.com/phish_detail.php?phish_id=130719">submission #130719</a>, a phishing site posing as the U.S. Internal Revenue Service and offering visitors their tax refund credited to their Visa or Mastercard. </p>
<p>PhishTank caught five IRS phishes this tax season and prevented who knows how many people from readily handing over their personal information.</p>
<p>Now what are you doing reading this blog? Don&#8217;t you have taxes to do? <img src='http://www.phishtank.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://www.phishtank.com/blog/2007/04/17/phishtank-on-washingonpostcom-phishers-pretend-to-be-uncle-sam-on-tax-day/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>The case of the mysterious hostname</title>
		<link>http://www.phishtank.com/blog/2007/02/09/the-case-of-the-mysterious-hostname/</link>
		<comments>http://www.phishtank.com/blog/2007/02/09/the-case-of-the-mysterious-hostname/#comments</comments>
		<pubDate>Fri, 09 Feb 2007 20:23:48 +0000</pubDate>
		<dc:creator>John Roberts</dc:creator>
				<category><![CDATA[Community]]></category>
		<category><![CDATA[Hosts]]></category>
		<category><![CDATA[Moderators]]></category>
		<category><![CDATA[PhishTank]]></category>
		<category><![CDATA[Verifying phishes]]></category>
		<category><![CDATA[Voting]]></category>

		<guid isPermaLink="false">http://www.phishtank.com/blog/2007/02/09/the-case-of-the-mysterious-hostname/</guid>
		<description><![CDATA[<b>funchords</b> explains why 0x42 = 66... and why it matters for the PhishTank community.]]></description>
			<content:encoded><![CDATA[<p>The following post was written by <a href="http://www.phishtank.com/user.php?username=funchords">funchords</a> <img src="/images/moderator.gif" width="74" height="10" alt="Moderator" />. If you don&#8217;t recognize the username, check the <a href="http://www.phishtank.com/stats.php">stats page</a>. Without further ado&#8230;</p>
<hr />
<p>Question: What do the following web addresses have in common?</p>
<ol>
<li><a href="http://66.135.40.79/" target="_blank">http://66.135.40.79/</a></li>
<li><a href="http://1116153935/" target="_blank">http://1116153935/</a></li>
<li><a href="http://0x42.0207.10319/" target="_blank">http://0&#215;42.0207.10319/</a></li>
<li><a href="http://0102.8857679/" target="_blank">http://0102.8857679/</a></li>
</ol>
<p>Answer: <b>Don&#8217;t look here &#8212; try them out and see!</b> (Caveat: In most browsers and operating systems &#8212; all four URLs will work. If your computer had trouble with a link, see &#8220;<a href="#something_not_working">Something Not Working</a>&#8221; below to understand why.)</p>
<p>So why did that happen?</p>
<p>We websurfers are trained to think of Internet sites as Double-U, Double-U, Double-U, Dot, Google, Dot, Com &#8212; because that is easier to remember than <a href="http://1208941928/">http://1208941928/</a>. The network translates those names into numbers, so we don&#8217;t have to. But, every computer accessible on the Internet has a long and unique number as an address. It&#8217;s like a telephone number &#8212; uniquely yours.</p>
<p>The hostnames in the four web addresses at the top of this page are all different ways of expressing the same Internet address number.</p>
<p>Just as websurfers use a method that is easy to remember, programmers do, too. If they&#8217;re working in a system or programming language that prefers base-16 or hexadecimal numbers, they&#8217;re likely to express a 3 like 0&#215;3 and a 12 like 0xC. An octal system would likely replace those with base-8 numbers, expressed as 03 and 014.</p>
<p>Why do this, when the rest of the world speaks in base-10 (decimal)? You&#8217;ll see in a moment &#8212; multiplication and division are much easier when you&#8217;re speaking the same language as the system.</p>
<p>The third example at the top of the page begins with 0&#215;42, which is a hexadecimal number (66 in decimal). The next segment of example 3 is 0207, an octal number equal to 135. But what about that third number?</p>
<p>The &#8220;dots&#8221; in the address are meant for organization. Twenty-five years ago, our internet founders segmented the IP space into 255 (0xFF) segments. Those segments were split between five address types &#8212; large, medium, small, private, and special-use/future. The number before the first dot indicates this segment.</p>
<p>Knowing this, you can begin to do the math to make the above conversions. </p>
<p>If there is a first dot, the number before it is multiplied by 0&#215;1000000 (or 16777216 to us Base-10 users). The number after it is not multiplied. This would work just fine for a very large organization, they would have their unique organizational number and over 16 million IP addresses that they could use on the Internet.</p>
<p>A second dot would help mid-size organizations &#8212; the first two segments would be assigned to the business and the final segment was theirs to divide as they pleased. And so on, for smaller businesses and the fourth segment. That sounded good back in the early 1980s, and it worked for a while. But, more importantly for our topic, it set the stage for how IP addressing works.</p>
<p>Let&#8217;s untwist our 4th example. 0102 is the octal equal to 66. This means that <a href="http://66.8857679/" target="_blank">http://66.8857679/</a> should work? Does it? So we multiply that 66 by 16777216, and we get 1107296256. We add the last half of example 4 to that. 1107296256 plus 8857679 is <b>1116153935</b>. That number is hard to remember, but it is the same number we tried in Example 2, above! So, the unique network address to PhishTank is <b>1116153935</b>!</p>
<p>If there are two or three dots, the first number is multiplied by 0&#215;1000000, the second by 0&#215;10000, and the last is not multiplied. If there are four segments, the third segment is multiplied by 0&#215;100.</p>
<p>Remember that the dots are there for organization &#8212; for human convenience. Computers do not need them (as we have shown here).</p>
<p>Now <b>you</b> can turn any dotted decimal (what most would call &#8220;normal&#8221;) IP address into its actual single-integer address, <i>and back again</i>! Reverse the process using division&#8230;</p>
<table style="text-align: left; width: 100%;" border="0" cellpadding="2" cellspacing="2">
<tbody>
<tr>
<td style="text-align: right;">1116153935 &divide; 16777216 (0&#215;1000000) =</td>
<td><span style="font-weight: bold;">66</span>, with a remainder of 8857679</td>
</tr>
<tr>
<td style="text-align: right;">8857679  &divide; 65536 (0&#215;10000) =</td>
<td><b>135</b>, with a remainder of 10319</td>
</tr>
<tr>
<td style="text-align: right;">10319   &divide; 256 (0&#215;100) =</td>
<td><b>40</b>, with a remainder of 79</td>
</tr>
<tr>
<td style="text-align: right;">79    &divide; 1 (0&#215;1) =</td>
<td><b>79</b></td>
</tr>
</tbody>
</table>
<p>
&#8230; and that leaves us back at 66.135.40.79, the dotted-decimal IP address that we used in Example 1.</p>
<p><a name="something_not_working"></a><b>Something not working, or working differently?</b> In twenty-five years, programmers and administrators have grown accustomed to the four-segment dotted-decimal IP addresses, even in the largest organizations. While most network software still accepts these other forms of an address, some do not.</p>
<p>Although these forms of addressing are valid, almost nobody is used to them. Spammers and Phishing Fraudsters are taking advantage of this. They attempt to get around detection by changing the IP address into something other than a dotted-decimal form. It also tends to make a Phishing URL more legitimate. Here are some examples:</p>
<ul>
<li><a href="http://www.phishtank.com/phish_detail.php?phish_id=44124" target="_blank">Submission #44124</a>: <b>http://0&#215;4231ddb2/www.amazon.com/login/exec.php?cmd=sign-in</b></li>
<li><a href="http://www.phishtank.com/phish_detail.php?phish_id=48434" target="_blank">Submission #48434</a>: <b>http://0xd2.0xf3.0xe9.0&#215;22/www.paypal.com/</a></b></li>
<li><a href="http://www.phishtank.com/phish_detail.php?phish_id=91296" target="_blank">Submission #91296</a>: <b>http://3630742891/cgi-bin/webscr_cmd_login-submit/</b></li>
</ul>
<p>So when you see such an address, don&#8217;t panic. Know that the address is a number, and not a name that can be resolved in DNS. Submit the Phishing Site to the PhishTank &#8220;As-Is,&#8221; using the same style address that the Phisher put in his spam email. Then, if you want, deconstruct the dotted decimal IP address and submit the site using the more &#8220;normal&#8221; form. Doing this will help remove some of the confusion for verifiers, down-stream users, and others who aren&#8217;t as smart as you!</p>
<p>Isn&#8217;t that cool?</p>
<hr />
<p><i>Like to write a post for PhishTank? <a href="http://www.phishtank.com/contact.php">Let us know</a>.</i></p>
]]></content:encoded>
			<wfw:commentRss>http://www.phishtank.com/blog/2007/02/09/the-case-of-the-mysterious-hostname/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
		<item>
		<title>PayPal wants to wish you a Merry Christmas</title>
		<link>http://www.phishtank.com/blog/2006/12/09/paypal-wants-to-wish-you-a-merry-christmas/</link>
		<comments>http://www.phishtank.com/blog/2006/12/09/paypal-wants-to-wish-you-a-merry-christmas/#comments</comments>
		<pubDate>Sat, 09 Dec 2006 00:11:55 +0000</pubDate>
		<dc:creator>John Roberts</dc:creator>
				<category><![CDATA[PhishTank]]></category>
		<category><![CDATA[Verifying phishes]]></category>
		<category><![CDATA[Voting]]></category>

		<guid isPermaLink="false">http://www.phishtank.com/blog/2006/12/09/paypal-wants-to-wish-you-a-merry-christmas/</guid>
		<description><![CDATA[More examples of legitimate domains which make people think harder than necessary.]]></description>
			<content:encoded><![CDATA[<p>Submission <a href="http://www.phishtank.com/phish_detail.php?phish_id=40965">40965</a> is NOT a phish.</p>
<p>The PhishTank community is slowly reaching the right conclusion. Emphasis on slowly. But it&#8217;s hardly the community&#8217;s fault.</p>
<p>The site is <a href="http://www.paypalchristmas.co.uk/">http://www.paypalchristmas.co.uk/</a>. It is <strong>not</strong> operated by PayPal, as you can tell on the <a href="http://www.phishtank.com/phish_detail.php?phish_id=40965&#038;frame=details">Technical Details tab</a> of #40965, adding to the confusion!</p>
<p>But the site <strong>is affiliated with and approved by</strong> PayPal.</p>
<p>Given their high profile (#2 in <a href="http://www.phishtank.com/stats/2006/11/">November 2006</a>, for example), PayPal should think very carefully about using alternate URLs for <strong>anything</strong> with their name on it. Submissions <a href="http://www.phishtank.com/phish_detail.php?phish_id=42483">42483</a> and <a href="http://www.phishtank.com/phish_detail.php?phish_id=42482">42482</a> are additional examples where the site is legitimately affiliated with PayPal, but it is <strong>very hard</strong> to know that without digging deep.</p>
<p>But a company&#8217;s domains are their choice. I simply wanted to draw the attention of the PhishTank community to this example, as I&#8217;ve done with <a href="http://www.phishtank.com/blog/2006/11/30/another-real-bank-site-which-confuses-people-nwolbcom/">other</a> <a href="http://www.phishtank.com/blog/2006/10/31/53com-is-a-real-bank/">examples</a>.</p>
<p>Firefox 2.0 improperly <a href="http://www.gospelrhys.co.uk/2006/11/firefox-to-paypal-you-fraud.html">calls this site a phish</a>. IE 7 is confused, some times saying it&#8217;s a phish, some times saying it doesn&#8217;t know. I&#8217;d like to encourage PhishTank to get it right.</p>
<p>So, vote wisely. Vote <a href="http://www.phishtank.com/phish_detail.php?phish_id=40965">NOT a phish</a>. Please. <img src='http://www.phishtank.com/blog/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
<p>P.S. eBay (parent company of PayPal) hosts images and other, well, static content at the genuine domain <strong>ebaystatic.com</strong> is a genuine domain, so submission <a href="http://www.phishtank.com/phish_detail.php?phish_id=46522">46522</a> is also NOT a phish.</p>
<p>P.P.S. <a href="http://www.phishtank.com/phish_detail.php?phish_id=42482">42482</a>, <a href="http://www.phishtank.com/phish_detail.php?phish_id=42483">42483</a> and <a href="http://www.phishtank.com/phish_detail.php?phish_id=40965">40965</a> were submitted by <a href="http://www.phishtank.com/user.php?username=MASA">MASA</a> as tests, with approval: they were known to be confusing, but legitimate. The community is passing the test, but I wanted to hurry the process along. Just wanted to make it clear that MASA is not polluting the Tank here; in fact, MASA is a moderator.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.phishtank.com/blog/2006/12/09/paypal-wants-to-wish-you-a-merry-christmas/feed/</wfw:commentRss>
		<slash:comments>9</slash:comments>
		</item>
		<item>
		<title>Another real bank site which confuses people: nwolb.com</title>
		<link>http://www.phishtank.com/blog/2006/11/30/another-real-bank-site-which-confuses-people-nwolbcom/</link>
		<comments>http://www.phishtank.com/blog/2006/11/30/another-real-bank-site-which-confuses-people-nwolbcom/#comments</comments>
		<pubDate>Thu, 30 Nov 2006 19:49:58 +0000</pubDate>
		<dc:creator>John Roberts</dc:creator>
				<category><![CDATA[Banks]]></category>
		<category><![CDATA[PhishTank]]></category>
		<category><![CDATA[Verifying phishes]]></category>
		<category><![CDATA[Voting]]></category>

		<guid isPermaLink="false">http://www.phishtank.com/blog/2006/11/30/another-real-bank-site-which-confuses-people-nwolbcom/</guid>
		<description><![CDATA[Banks use multiple domain names, even when it's not necessarily a good idea.]]></description>
			<content:encoded><![CDATA[<p>Four weeks ago, I shared the interesting case of <a href="http://www.phishtank.com/blog/2006/10/31/53com-is-a-real-bank/">53.com</a>, a real bank website whose numerical domain name confuses some members of the PhishTank community (not easy&#8230; discerning bunch!). The submission cited in that post remains undecided, although it&#8217;s (correctly) leaning toward &#8220;NOT a phish.&#8221;</p>
<p>I want to call attention to another example today.</p>
<p>The submission is <a href="https://www.phishtank.com/phish_detail.php?phish_id=36958">36895</a>. There are nearly 250 votes on this submission, with a slight majority <strong>correctly</strong> recognizing that this is NOT a phish.</p>
<p>Why the confusion? The website is branded as NatWest, a major bank in the United Kingdom, but the domain name is nwolb.com (go to the submission to see the entire URL submitted).</p>
<p>The registrant for nwolb.com is:<br />
<blockquote>The Royal Bank of Scotland Group plc<br />
Waterhouse Square<br />
138-142 Holborn<br />
London EC1N 2TH<br />
UK</p></blockquote>
<p>NatWest was <a href="http://www.rbs.com/global_options.asp?id=GLOBAL/FREQUENTLY_ASKED_QUESTIONS#heritage5">purchased</a> by Royal Bank of Scotland Group in 2000, so this is legit.</p>
<p>You can also simply start at <a href="http://www.natwest.com/">NatWest.com</a>. Click the button at the top right titled &#8220;Log in.&#8221; The link redirects to&#8230;you guessed it&#8230;<a href="https://www.nwolb.com/">https://www.nwolb.com/</a> (with lots of other session/security stuff on the end of the URL).</p>
<p>I&#8217;m sure there are technical reasons, or historical business reasons, why the online bank lives on a different URL than the corporate website, but it&#8217;s certainly led to some confusion among an ever-more cautious online crowd.</p>
<p>If you have not yet voted on <a href="https://www.phishtank.com/phish_detail.php?phish_id=36958">36895</a>, please vote &#8220;NOT a phish.&#8221;</p>
<h4>Related note</h4>
<p>In the comments about 53.com, some asked why we (the PhishTank administrators) don&#8217;t go ahead and decide this submission once and for all. My answer remains the same: as long as this is undecided, we will not step in. PhishTank administrators will step in to overrule false positives, if necessary. It rarely has been: maybe three times in nearly 25,000 submissions as I write this post.</p>
<p>The <a href="http://www.phishtank.com/blog/2006/11/23/introducing-the-first-phishtank-moderators/">moderators</a> are instrumental in flagging confusing submissions and drawing attention to possible problems, though they don&#8217;t overrule the community.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.phishtank.com/blog/2006/11/30/another-real-bank-site-which-confuses-people-nwolbcom/feed/</wfw:commentRss>
		<slash:comments>13</slash:comments>
		</item>
		<item>
		<title>Money Mules: laundering out the phish smell</title>
		<link>http://www.phishtank.com/blog/2006/11/10/money-mules-laundering-out-the-phish-smell/</link>
		<comments>http://www.phishtank.com/blog/2006/11/10/money-mules-laundering-out-the-phish-smell/#comments</comments>
		<pubDate>Fri, 10 Nov 2006 16:42:12 +0000</pubDate>
		<dc:creator>John Roberts</dc:creator>
				<category><![CDATA[Members]]></category>
		<category><![CDATA[Mules]]></category>
		<category><![CDATA[PhishTank]]></category>
		<category><![CDATA[Safety]]></category>
		<category><![CDATA[Verifying phishes]]></category>
		<category><![CDATA[Voting]]></category>

		<guid isPermaLink="false">http://www.phishtank.com/blog/2006/11/10/money-mules-laundering-out-the-phish-smell/</guid>
		<description><![CDATA[Yet another type of Internet scam. Not a phish, but a mule!]]></description>
			<content:encoded><![CDATA[<p>The following post was written by PhishTank member <a href="http://www.phishtank.com/user.php?username=funchords">funchords</a>, a very active member of the community, and currently the <a href="http://www.phishtank.com/stats.php">top submitter</a> to PhishTank.</p>
<hr />
<p><b><a href="http://www.phishtank.com/phish_detail.php?phish_id=22779">Submission 22779</a></b> is such a professional-looking employment ad, one might even wonder why it was submitted as a suspected phish site. Most likely, <a href="http://www.phishtank.com/user.php?username=redpriest">redpriest</A> realized that the ad was looking for a <a href="http://www.eweek.com/article2/0,1895,2029953,00.asp">Money Mule</a> &#8212; a person who launders phishy money through their personal accounts and moves it overseas.</p>
<p>It&#8217;s both illegal and risky &#8212; and most Money Mules end up getting burned as soon as the phish-site victims realize that their credit cards or identities have been compromised.  In addition to possible trouble with the police, the Money Mule gets to pay back the banks and institutions that were involved in the fraud.  Money Mules take all the heat while the real crooks disappear into anonymity.</p>
<p>So why was <a href="http://www.phishtank.com/phish_detail.php?phish_id=22779">Submission 22779</a> marked &#8220;Verified: Is NOT a phish?&#8221;  Because, even though it probably is related to phishing, it really is not <a href="http://www.phishtank.com/what_is_phishing.php">a phish</a>. It isn&#8217;t masquerading as an institution one already trusts in order to obtain financial information.</p>
<p>While PhishTank endeavors to quickly and accurately identify Phish, our friends at CastleCops.com specialize in working with government and internet concerns to shut these criminals down.  CastleCops has an e-mail address to report suspected Money Mule advertisements: <a href="mailto:mules@castlecops.com">mules@castlecops.com</A>.</p>
<p>Got a phish? As always, throw it in the PhishTank.  But if the crooks are &#8220;fishing&#8221; for a Money Mule, then report it to <a href="mailto:mules@castlecops.com">mules@castlecops.com</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.phishtank.com/blog/2006/11/10/money-mules-laundering-out-the-phish-smell/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Submissions are virus scanned</title>
		<link>http://www.phishtank.com/blog/2006/11/03/submissions-are-virus-scanned/</link>
		<comments>http://www.phishtank.com/blog/2006/11/03/submissions-are-virus-scanned/#comments</comments>
		<pubDate>Fri, 03 Nov 2006 22:44:22 +0000</pubDate>
		<dc:creator>John Roberts</dc:creator>
				<category><![CDATA[PhishTank]]></category>
		<category><![CDATA[Safety]]></category>
		<category><![CDATA[Verifying phishes]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://www.phishtank.com/blog/2006/11/03/submissions-are-virus-scanned/</guid>
		<description><![CDATA[Additional protection for the PhishTank community, especially those verifying submissions.]]></description>
			<content:encoded><![CDATA[<p>At PhishTank, we focus on phish and phishing, and we leave other bad areas (viruses, malware, spam, botnets) to other communities, like <a href="http://www.projecthoneypot.org/home.php">Project Honey Pot</a> (anti-spam) for instance.</p>
<p>But some of the folks on the dark side of the Internet defy such categorization. They don&#8217;t limit themselves to phishing. So, we&#8217;ve had a few submissions of phish URLs which also try to infect the visitor with a virus.</p>
<p>In the past, we&#8217;ve deleted these submissions out of hand, but we don&#8217;t want to give phishers an easy way to avoid identification by compounding their crimes.</p>
<p>How we deal with these submissions now, thanks to <a href="http://www.phishtank.com/user.php?username=miked">miked</a>:</p>
<ol>
<li>All submissions are scanned for viruses.</li>
<li>We never display the actual suspected phishing site by default. (Always been the case.)</li>
<li>If our scan indicates a possible virus in the submission, then when you click the &#8220;View site in frame&#8221; tab, you will be warned. You will be able to continue, but you should be <strong>even more careful</strong> than usual.</li>
<li>Same general experience holds for the &#8220;View site in new window&#8221; link: a warning, with an option to continue.</li>
</ol>
<p>No virus scanning is perfect, and phishing sites change, so <strong>please</strong> make sure that if you venture over to the site itself, that you always do so in a very-up-to-date browser, with security settings at their highest levels. We hope the <a href="http://www.phishtank.com/blog/2006/10/26/technical-details-tab-provides-asn-and-whois-data/">technical information</a> tab also limits the need to visit the site itself.</p>
<p>If you want to see this in action, then take a look at <a href="http://www.phishtank.com/phish_detail.php?phish_id=19880">19880</a>, which is online still as I write this.</p>
<p>To cite <a href="http://www.museum.tv/archives/etv/H/htmlH/hillstreetb/hillstreetb.htm">Hill Street Blues</a> (long-gone TV show), let&#8217;s be careful out there. </p>
]]></content:encoded>
			<wfw:commentRss>http://www.phishtank.com/blog/2006/11/03/submissions-are-virus-scanned/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>53.com is a real bank</title>
		<link>http://www.phishtank.com/blog/2006/10/31/53com-is-a-real-bank/</link>
		<comments>http://www.phishtank.com/blog/2006/10/31/53com-is-a-real-bank/#comments</comments>
		<pubDate>Tue, 31 Oct 2006 23:49:37 +0000</pubDate>
		<dc:creator>John Roberts</dc:creator>
				<category><![CDATA[PhishTank]]></category>
		<category><![CDATA[Verifying phishes]]></category>
		<category><![CDATA[Voting]]></category>

		<guid isPermaLink="false">http://www.phishtank.com/blog/2006/10/31/53com-is-a-real-bank/</guid>
		<description><![CDATA[Gentle hint for marketers: number-only domain names do not inspire trust.]]></description>
			<content:encoded><![CDATA[<p>Submission <a href="http://www.phishtank.com/phish_detail.php?phish_id=19715">19715</a> continues to await final judgment from the community. The phish URL is:</p>
<p><strong>http://www.53.com/wps/portal/contenttype/secure/confirm_context.id</strong></p>
<p>The screenshot shows Fifth Third Bank.</p>
<p>The <a href="http://www.phishtank.com/phish_detail.php?phish_id=19715&#038;frame=details">technical details</a> give the strongest evidence. <i>Admittedly, the technical details tab did not exist when this was submitted on October 17, 2006.</i></p>
<blockquote><p>Registrant:<br />
Fifth Third Bank<br />
38 Fountain Square Plaza<br />
Cincinnati, OH 45263-0001<br />
US</p></blockquote>
<p>There are 250+ votes so far, with 60% saying &#8220;Is NOT a phish.&#8221;</p>
<p>Hint: This bank exists, and this site is real. If you have not voted, please vote <strong>Is NOT a phish</strong>.</p>
<p>The lesson is that number-only domain names do not inspire trust, but don&#8217;t dismiss them out of hand.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.phishtank.com/blog/2006/10/31/53com-is-a-real-bank/feed/</wfw:commentRss>
		<slash:comments>20</slash:comments>
		</item>
	</channel>
</rss>
