In this side note we provide an overview of the source IP addresses of potential victims in the UK phishing attack against a major US bank described in phishing technique one. The data below was collected with the help of the compromised UK honeypot and network packet captures. Over a period of about 4 days we observed 265 inbound HTTP requests to the honeypot, presumably recipients of a spam phishing email who were tricked into accessing the redirected content by clicking on the link provided. All were potential victims of the phishing attack, but none actually submitted personal data and therefore the phishing attack was unsucessful.

IPISPCountryOS
4.138.NNN.NNNLevel 3 US Windows XP, 2000 SP2+ (NAT!)
4.224.NNN.NNNLevel 3 US Windows 98
4.235.NNN.NNNLevel 3 US Windows XP, 2000 SP2+ (NAT!)
4.239.NNN.NNNLevel 3 US Windows XP, 2000 SP2+
12.202.NNN.NNNAT&T US FreeBSD 4.7
12.217.NNN.NNNAT&T US Windows 2000 SP2+, XP SP1 (seldom 98 4.10.2222)
12.218.NNN.NNNAT&T US UNKNOWN
24.16.NNN.NNNComcast Cable US Windows XP Pro SP1, 2000 SP3
24.58.NNN.NNNRoad Runner US Windows XP Pro SP1, 2000 SP3
24.59.NNN.NNNRoad Runner US Windows 2000 SP2+, XP SP1 (seldom 98 4.10.2222)
24.62.NNN.NNNComcast Cable US Windows 2000 SP2+, XP SP1 (seldom 98 4.10.2222)
24.90.NNN.NNNRoad Runner US Windows 2000 SP2+, XP SP1 (seldom 98 4.10.2222)
24.93.NNN.NNNRoad Runner US Windows XP Pro SP1, 2000 SP3
24.107.NNN.NNNCharter Comms US Windows 2000 SP2+, XP SP1 (seldom 98 4.10.2222)
24.129.NNN.NNNComcast Cable US Windows XP Pro SP1, 2000 SP3 (NAT!)
24.140.NNN.NNNMassillon Cable US Windows XP, 2000 SP2+
24.154.NNN.NNNArmstrong Cable US Windows 2000 SP2+, XP SP1 (seldom 98 4.10.2222)
24.160.NNN.NNNRoad Runner US UNKNOWN
24.161.NNN.NNNRoad Runner US Windows 2000 SP2+, XP SP1 (seldom 98 4.10.2222)
24.162.NNN.NNNRoad Runner US Windows 2000 SP2+, XP SP1 (seldom 98 4.10.2222)
24.163.NNN.NNNRoad Runner US Windows 2000 SP4, XP SP1
24.165.NNN.NNNRoad Runner US Windows XP Pro SP1, 2000 SP3
24.166.NNN.NNNRoad Runner US Windows 2000 SP2+, XP SP1 (seldom 98 4.10.2222)
24.208.NNN.NNNRoad Runner US Windows 2000 SP2+, XP SP1 (seldom 98 4.10.2222)
24.209.NNN.NNNRoad Runner US Windows XP Pro SP1, 2000 SP3 (firewall!)
24.220.NNN.NNNMidcontinent Comms US UNKNOWN
24.231.NNN.NNNCharter Comms US Windows XP SP1, 2000 SP3
24.239.NNN.NNNArmstrong Cable US Windows XP/2000
24.243.NNN.NNNService Co LLC US Windows XP Pro SP1, 2000 SP3
63.165.NNN.NNNDIGITELProb USOpenBSD 3.0
63.192.NNN.NNNPacific Bell US Windows 2000 SP4, XP SP1
64.12.NNN.NNNAOL US Linux 2.4 w/o timestamps
64.33.NNN.NNNWest Winconsin Telecomn US Windows XP, 2000 SP2+
64.58.NNN.NNNMarlowe & Associates US Windows 98 (2) (NAT!)
64.136.NNN.NNNJuno Online US OpenBSD 3.0
64.136.NNN.NNNJuno Online US OpenBSD 3.0
64.136.NNN.NNNJuno Online US OpenBSD 3.0
64.161.NNN.NNNPacific Bell Internet US Windows XP Pro SP1, 2000 SP3 (NAT!)
64.216.NNN.NNNSBC Internet US Windows XP Pro SP1, 2000 SP3 (NAT!)
64.222.NNN.NNNVerizon Internet US Windows 2000 SP4, XP SP 1
65.78.NNN.NNNRCN Corporation US FreeBSD 4.7
65.166.NNN.NNNSprint US Windows 98
65.204.NNN.NNNEagle Mountain Telecom US FreeBSD 4.8
65.221.NNN.NNNBuckeye Cablevision US Windows 2000 SP2+, XP SP1 (seldom 98 4.10.2222)
65.229.NNN.NNNUUNET US Windows XP/2000
66.38.NNN.NNNBrandenburg Telephone Company US Windows 2000 SP2+, XP SP1 (seldom 98 4.10.2222)
66.41.NNN.NNNComcast Cable US Windows 2000 SP2+, XP SP1 (seldom 98 4.10.2222)
66.45.NNN.NNNWholeSecurity, Inc US Windows 2000 SP4, XP SP1
66.61.NNN.NNNRoad Runner US Windows XP Pro SP1, 2000 SP3
66.67.NNN.NNNRoad Runnner US Windows 2000 SP2+, XP SP1 (seldom 98 4.10.2222)
66.68.NNN.NNNRoad Runner US Windows XP Pro SP1, 2000 SP3
66.82.NNN.NNNHughes Network Systems US UNKNOWN
66.170.NNN.NNNT-NET, Inc US Windows XP, 2000 SP2+
66.188.NNN.NNNCharter Comms US Windows 2000 SP2+, XP SP1 (seldom 98 4.10.2222) (firewall!)
67.5.NNN.NNNQwest US Windows XP, 2000 SP2+
67.23.NNN.NNNAdelphia Cable Comms US Windows XP Pro SP1, 2000 SP3
67.38.NNN.NNNAmeritech Electronic Commerce US Windows XP, 2000 SP2+
67.66.NNN.NNNSBC Internet Services US Windows XP SP1, 2000 SP3
67.122.NNN.NNNPac Bell Internet US Windows 2000 SP2+, XP SP1 (seldom 98 4.10.2222)
67.160.NNN.NNNComcast Cable US Windows 2000 SP2+, XP SP1 (seldom 98 4.10.2222)
67.164.NNN.NNNComcast Cable US Windows XP Pro SP1, 2000 SP3 (NAT!)
67.167.NNN.NNNComcast Cable US UNKNOWN
68.10.NNN.NNNCox Communications Inc US Windows XP Pro SP1, 2000 SP3
68.14.NNN.NNNCox Communications Inc US FreeBSD 4.7
68.32.NNN.NNNComcast Cable US Windows 2000 SP2+, XP SP1 (seldom 98 4.10.2222)
68.53.NNN.NNNComcast Cable US Windows XP Pro SP1, 2000 SP3
68.88.NNN.NNNSBC Internet Services US Windows 2000 SP4, XP SP 1
68.89.NNN.NNNSBC Internet Services US Windows 2000 SP2+, XP SP1 (seldom 98 4.10.2222)
68.94.NNN.NNNSBC Internet Services US Windows XP Pro SP1, 2000 SP3 (NAT!)
68.103.NNN.NNNCox Communications Inc US Windows XP Pro SP1, 2000 SP3
68.109.NNN.NNNCox Communications Inc US Windows 2000 SP4, XP SP1
68.205.NNN.NNNRoad Runner US UNKNOWN
68.254.NNN.NNNSBC Internet Services US Windows 2000 SP2+, XP SP1 (seldom 98 4.10.2222)
69.23.NNN.NNN--Windows XP Pro SP1, 2000 SP3
69.48.NNN.NNNChoice One Comms US Windows XP, 2000 SP2+
69.59.NNN.NNNPeak Inc US Windows XP/2000 via Cisco
69.132.NNN.NNNRoad Runner US Windows 2000 SP2+, XP SP1 (seldom 98 4.10.2222)
69.133.NNN.NNNRoad Runner US Windows XP Pro SP1, 2000 SP3
69.134.NNN.NNNRoad Runner US UNKNOWN
69.135.NNN.NNNRoad Runner US Windows 2000 SP4, XP SP1
69.135.NNN.NNNRoad Runner US Windows 2000 SP2+, XP SP1 (seldom 98 4.10.2222)
69.151.NNN.NNNSBC Internet Services US Windows XP Pro SP1, 2000 SP3 (NAT!)
69.162.NNN.NNNAdelphia Cable Comms US FreeBSD 4.7
137.229.NNN.NNNUniversity of Alaska US Windows XP Pro SP1, 2000 SP3
141.154.NNN.NNNVerizon Internet US Windows XP SP1, 2000 SP3
148.78.NNN.NNNStarband Comms US CacheFlow CacheOS 4.1 (up
149.174.NNN.NNNCompuServe US Linux 2.4 w/o timestamps
152.163.NNN.NNNAOL US Linux 2.4 w/o timestamps
156.36.NNN.NNNUS Bancorp US OpenBSD 3.0
162.83.NNN.NNNVerizon Internet US Windows 2000 SP4, XP SP1
166.102.NNN.NNNWRK Internet-Windows XP, 2000 SP2+
166.102.NNN.NNNWRK Internet-Windows XP, 2000 SP2+
169.207.NNN.NNNExecutive PC, Inc US Windows 98
170.94.NNN.NNNState of Arkansas US Windows 2000 SP4, XP SP1
172.131.NNN.NNNAOL US Windows 2000 SP2+, XP SP1 (seldom 98 4.10.2222)
172.131.NNN.NNNAOL US Windows 2000 SP2+, XP SP1 (seldom 98 4.10.2222)
204.95.NNN.NNNSprint US Windows XP, 2000 SP2+
204.210.NNN.NNNRoad Runner US Windows 2000 SP4, XP SP1
204.210.NNN.NNNRoad Runner US Windows 2000 SP2+, XP SP1 (seldom 98 4.10.2222)
205.162.NNN.NNNBuckeye Cablevision US Windows 2000 SP2+, XP SP1 (seldom 98 4.10.2222)
206.148.NNN.NNNAGIS US Windows XP, 2000 SP2+
206.196.NNN.NNNUS West Internet Services US Windows XP Pro SP1, 2000 SP3
207.89.NNN.NNNNetLink Systems LLC US Windows XP, 2000 SP2+
207.89.NNN.NNNNetLink Systems LLC US Linux 2.4/2.6 (up
207.231.NNN.NNNSurewest Internet US BSD/OS 3.1
208.60.NNN.NNNLocal Link US Windows XP, 2000 SP2+
208.187.NNN.NNNLanset Comms US Windows XP, 2000 SP2+
208.191.NNN.NNNSBC Internet US Windows XP Pro SP1, 2000 SP3 (NAT!)
209.43.NNN.NNNIQuest Internet US Windows XP, 2000 SP2+
209.131.NNN.NNNCenturyTel Internet Holdings Inc US Windows 98
209.206.NNN.NNNIQuest Internet US Windows XP, 2000 SP2+
209.247.NNN.NNNBend Cable US Linux 2.4/2.6 (up
216.93.NNN.NNNVoyager Information Networks US Windows XP, 2000 SP2+
216.228.NNN.NNNBend Cable US Cisco Content Engine

Click here to return to the main paper.