Check out this hacker sting - poetry in motion
wpmu.org
wpmu.org
http://www.gamepron.com/news/2011/04/12/garrys-mod-catches-p...
They left in his real name in one of the screenshots BTW.
IMO it's quite an entertaining SocEng attack. And he just wanted to get the latest version of a commercial WP plugin! hahaha! I was kind of expecting something more malicious: I thought either the source file he requested contained login credentials or other sensitive info, or he was going to send back a "patched" version with a backdoor in it.
Odd, how he went through all that trouble. Anyone know what the plugin does BTW? I haven't looked, is it that good? :)
Of course, I removed the box :)