First a screenshot from the phish site at
h||p://ww4.visa.com.82siddefault.com/creditcards/security/confirm
(Click on it for a bigger one)
And here is a screenshot of the location bar from the screenshot above:

It contains the domain name 82siddefault.com.
Then I substituted 82siddefault.com with advabnr.com:

Click on the image above for a screenshot of the full page, using advabnr.com.
advabnr.com is an "oldie, but goodie" from last years sql-injections.
You could insert other Asprox related domains in the link to see too:
etyj.ru, 63mode.me, vjhdo.com, pbtgr.ru
Other new domains (registered lately) used actively in the phishing on the botnet right now:
62ftpmsg.com, 91tcp-check.com, 96ini-lan.com, route-access92.net and token-html18.com.
Most likely there are others.
Related, but dead right now: 48rdirjava.com and 28sslput-search.com.
Thanks to phishtank.com (joewein), robtex.com and bfk.de.
Recent comments
41 weeks 5 days ago
42 weeks 1 day ago
42 weeks 5 days ago
42 weeks 5 days ago
44 weeks 15 hours ago
1 year 22 weeks ago
1 year 22 weeks ago
1 year 25 weeks ago
1 year 25 weeks ago
1 year 26 weeks ago