I mentioned in my last post, "xml48.com - again a Abbey Bank phish and a malware installer .." that I also received another phishing spam that day, for Halifax.
I checked a bit around that one today. Either the spammer screwed up the link in the spam or the phishing page has been taken down.
The link was: http://ww4.halifax-secure.co.uk.lvozx90.com/mem_bin/formssecure.aspsource=halifaxcoukHOME1/
But I had a look at the hosting for ww4.halifax-secure.co.uk.lvozx90.com:
ww4.halifax-secure.co.uk.lvozx90.com. 180 IN A 75.75.182.238
Just in, this one.
Spamvertised domain is mycamchicks.com. With further links to camcrush.com and camgenie.com.
Whois info and "hosting" for mycamchicks.com is a bit interesting.
First the whois info:
Domain Name: MYCAMCHICKS.COM Registrar: BEIJING INNOVATIVE LINKAGE TECHNOLOGY LTD. DBA DNS.COM.CN Whois Server: whois.dns.com.cn Referral URL: http://www.dns.com.cn Name Server: NS4.MYOOODNS.COM Name Server: NS5.MYOOODNS.COM Name Server: NS6.MYOOODNS.COM Name Server: NS7.MYOOODNS.COM Status: clientTransferProhibited Updated Date: 05-may-2008
Recent comments
41 weeks 3 days ago
41 weeks 6 days ago
42 weeks 2 days ago
42 weeks 3 days ago
43 weeks 5 days ago
1 year 22 weeks ago
1 year 22 weeks ago
1 year 24 weeks ago
1 year 24 weeks ago
1 year 26 weeks ago