
I caught, among the (literally) hundreds of WAMU phishes this morning, a live Visa attack. It's live on a standard port, so I began investigating so I could contact the correct authority.
The 404 error page on the server tells me it's at ebay.dyns.cx - But that means nothing. Except that this webserver may have been installed specifically to be a phishing server...
OK. Apache webserver at 62.73.115.24. Usually you can get a quick clue by going to the main webpage, even if it's a name virtual host there's usually some info there that will point you to the correct authorities.
So I hit http://62.73.115.24/ expecting to see a default Apache page, or maybe some site that's not effectively managed.
Image my surprise when I see:
The main page on this server is a PayPal phishing scheme.
The server is hosted at an ISP in Bulgaria. It's possible it's (severely) hacked, but it's just as likely that this server is actually owned by the scammers, and they're using it for multiple schemes.
The only good news is that maybe the authorities can actually track these guys.
UPDATE abuse@ignet.bg and hostmaster@ignet.bg both bounced. I submitted them to
RFC-Ignorant.org.