{"id":90084,"date":"2021-06-30T15:04:57","date_gmt":"2021-06-30T09:34:57","guid":{"rendered":"https:\/\/blogs.quickheal.com\/?p=90084"},"modified":"2023-08-08T18:14:47","modified_gmt":"2023-08-08T12:44:47","slug":"phishing-scam-alert-domain-name-expiration-notices-stealing-data-through-phishing-site","status":"publish","type":"post","link":"https:\/\/www.quickheal.com\/blogs\/phishing-scam-alert-domain-name-expiration-notices-stealing-data-through-phishing-site\/","title":{"rendered":"Phishing Scam Alert: Domain Name Expiration Notices stealing data through phishing site"},"content":{"rendered":"<p>Have you received an email notification that your domain is about to expire? Most website owners have. But do you pay close attention to who it is from and the renewal fee? If not, you may be throwing money away to a scammer.<\/p>\n<p><a href=\"https:\/\/www.quickheal.co.in\/\">Quick Heal<\/a> Security Labs has recently come across a phishing scam related to domain names. And we want to give some insights on ways to identify the scam and protect yourself from falling victim.<\/p>\n<p>Security researchers say expired domains can put data at risk. Hackers use expired domains to steal credit card data or contact information. Or they may target email accounts linked to the domain to scam clients and steal company secrets.<\/p>\n<h2 style=\"font-size: 27px;\"><strong>What is Phishing? <\/strong><\/h2>\n<p>Phishing is a fraudulent attempt to obtain sensitive information such as usernames, passwords, and payment information by disguising oneself as a trustworthy entity in an electronic communication.<\/p>\n<p>In other words, phishing is a type of <a href=\"https:\/\/blogs.quickheal.com\/be-careful-of-these-potential-online-scams\/\">online scam<\/a> where criminals or attackers send an email that appears to be from a legitimate source or company and ask you to provide sensitive information.<\/p>\n<p>There is a new <a href=\"https:\/\/blogs.quickheal.com\/what-is-phishing-a-deep-dive-into-the-phishing-attack-mechanisms-with-tips\/\">phishing attack<\/a> going on, which you need to be aware of a recent <a href=\"https:\/\/blogs.quickheal.com\/can-you-spot-a-phishing-email-take-this-test-and-find-out\/\">phishing email<\/a> out there, the <strong><b>\u2018Domain Name Expiration Scam.\u2019 <\/b><\/strong>The target of this scam is to trick people with fake Domain Name Expiration to steal sensitive payment information from consumers or make payments to them.<\/p>\n<p style=\"text-align: center;\"><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-90086 aligncenter\" src=\"https:\/\/blogs.quickheal.com\/wp-content\/uploads\/2021\/06\/Picture1-300x234.png\" alt=\"\" width=\"321\" height=\"250\" srcset=\"https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2021\/06\/Picture1-300x234.png 300w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2021\/06\/Picture1-500x390.png 500w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2021\/06\/Picture1.png 537w\" sizes=\"(max-width: 321px) 100vw, 321px\" \/><em>Fig. 1 Phishing attack flow<\/em><\/p>\n<p>&nbsp;<\/p>\n<p>We observed a <a href=\"https:\/\/blogs.quickheal.com\/5-ways-instantly-detect-phishing-email-save-phishing-attack\/\">phishing mail attack<\/a> during our analysis. The victim received multiple phishing emails on his registered mail from different Mail IDs. In the mail, attackers mentioned <strong>\u201cDomain Services Expiration Date.\u201d<\/strong> Attackers send fake Domain services expiration notices to the user. This date is not a correct expiration date.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-90102 aligncenter\" src=\"https:\/\/blogs.quickheal.com\/wp-content\/uploads\/2021\/06\/Picture2-1-300x154.png\" alt=\"\" width=\"551\" height=\"283\" srcset=\"https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2021\/06\/Picture2-1-300x154.png 300w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2021\/06\/Picture2-1-650x334.png 650w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2021\/06\/Picture2-1-768x395.png 768w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2021\/06\/Picture2-1-789x406.png 789w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2021\/06\/Picture2-1.png 1054w\" sizes=\"(max-width: 551px) 100vw, 551px\" \/><\/p>\n<p style=\"text-align: center;\"><em>Fig.2 Phishing Email<\/em><\/p>\n<p>&nbsp;<\/p>\n<p>In the above mail, shortened malicious URL is embedded which leads to a phishing attack.<\/p>\n<p><strong><b>https[:]\/\/bit.ly\/3l2vkND<\/b><\/strong><\/p>\n<p>This bitly URL redirects the user to another phishing website-<\/p>\n<p><strong><b>URL: \u00a0https[:]\/\/webdomainsrvcs.com<\/b><\/strong><\/p>\n<p>&nbsp;<\/p>\n<p><strong><b>Information about the above URL and their respective:<\/b><\/strong><\/p>\n<p><strong>URL:<\/strong>\u00a0\u00a0https[:]\/\/webdomainsrvcs.com<\/p>\n<ul>\n<li><strong>IP: <\/strong>105.65.125<\/li>\n<li><strong>Server Type: <\/strong>Apache<\/li>\n<li><strong>Country: <\/strong>Russia<\/li>\n<li><strong>City: <\/strong>Moscow<\/li>\n<li><strong>ISP: <\/strong>HOSTKEY B.V.<\/li>\n<li><strong>Organization: <\/strong>LLC Server v arendy (hostkey.ru)<\/li>\n<\/ul>\n<p><strong><b>\u00a0<\/b><\/strong><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-90088 aligncenter\" src=\"https:\/\/blogs.quickheal.com\/wp-content\/uploads\/2021\/06\/Picture3-300x174.png\" alt=\"\" width=\"500\" height=\"290\" srcset=\"https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2021\/06\/Picture3-300x174.png 300w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2021\/06\/Picture3.png 624w\" sizes=\"(max-width: 500px) 100vw, 500px\" \/><\/p>\n<p style=\"text-align: center;\"><em>Fig.3 Phishing Site<\/em><\/p>\n<p>&nbsp;<\/p>\n<p>This redirected website asks the victim to fill in some basic information like Domain name, Email address, Phone Number, and Digital signature, as shown below.<\/p>\n<p>&nbsp;<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-90089 aligncenter\" src=\"https:\/\/blogs.quickheal.com\/wp-content\/uploads\/2021\/06\/Picture4-300x195.png\" alt=\"\" width=\"490\" height=\"319\" srcset=\"https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2021\/06\/Picture4-300x195.png 300w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2021\/06\/Picture4-600x390.png 600w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2021\/06\/Picture4.png 742w\" sizes=\"(max-width: 490px) 100vw, 490px\" \/><\/p>\n<p style=\"text-align: center;\">\u00a0<em>\u00a0\u00a0Fig.4 User Info page<\/em><\/p>\n<p>&nbsp;<\/p>\n<p>After submitting details in the given form and clicking on submit button, it redirects to a page that will show some plans for domain renewal.<\/p>\n<p>&nbsp;<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-90090 aligncenter\" src=\"https:\/\/blogs.quickheal.com\/wp-content\/uploads\/2021\/06\/Picture5-300x165.png\" alt=\"\" width=\"500\" height=\"275\" srcset=\"https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2021\/06\/Picture5-300x165.png 300w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2021\/06\/Picture5-650x358.png 650w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2021\/06\/Picture5-768x422.png 768w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2021\/06\/Picture5-789x434.png 789w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2021\/06\/Picture5.png 858w\" sizes=\"(max-width: 500px) 100vw, 500px\" \/><\/p>\n<p style=\"text-align: center;\">\u00a0<em>\u00a0Fig.5: \u00a0Domain renewal plans<\/em><\/p>\n<p>&nbsp;<\/p>\n<p>After clicking on <strong><b>PAY NOW<\/b><\/strong>\u00a0on any of the plans this page redirects the user to the payment page (PayPal).<\/p>\n<p>&nbsp;<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-90091 aligncenter\" src=\"https:\/\/blogs.quickheal.com\/wp-content\/uploads\/2021\/06\/Picture6-300x158.png\" alt=\"\" width=\"497\" height=\"262\" srcset=\"https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2021\/06\/Picture6-300x158.png 300w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2021\/06\/Picture6.png 605w\" sizes=\"(max-width: 497px) 100vw, 497px\" \/><\/p>\n<p style=\"text-align: center;\">\u00a0\u00a0<em>\u00a0\u00a0Fig.6: \u00a0Payment page<\/em><\/p>\n<p>&nbsp;<\/p>\n<p><strong><b>VT Graph<\/b><\/strong><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-90092 aligncenter\" src=\"https:\/\/blogs.quickheal.com\/wp-content\/uploads\/2021\/06\/Picture7-300x169.png\" alt=\"\" width=\"500\" height=\"281\" srcset=\"https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2021\/06\/Picture7-300x169.png 300w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2021\/06\/Picture7.png 614w\" sizes=\"(max-width: 500px) 100vw, 500px\" \/><\/p>\n<p style=\"text-align: center;\"><em>Fig.7 VT Graph<\/em><\/p>\n<p>&nbsp;<\/p>\n<p>Here, we can see the <strong><b>Root node<\/b><\/strong>\u00a0https[:]\/\/bit.ly\/3l2vkND is communicating with the malicious files.<\/p>\n<p>&nbsp;<\/p>\n<h2 style=\"font-size: 27px;\"><strong><b>How Can We Catch and Avoid Falling for these types of Phishing Scams?<\/b><\/strong><\/h2>\n<ul>\n<li><b><\/b><strong><b>Validate Links and Attachment: <\/b><\/strong>Don&#8217;t click and open any Link and attachments attached in Mail validate it, then open it.<\/li>\n<li><b><\/b><strong><b>Set up Auto-renewal: <\/b><\/strong>Use domain name auto-renewal services. So, you can ignore all renewal mails, which might be Phishing mail.<\/li>\n<li><b><\/b><strong><b>Use Registrar\u2019s website: <\/b><\/strong>Renew your domain name through the official registrar\u2019s website only.<\/li>\n<li><b><\/b><strong><b>Registration information: <\/b><\/strong>Use Domain privacy protection. It\u2019s worth it.<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><strong><b>IOCs:<\/b><\/strong><\/p>\n<p><strong><b>Short URLs: <\/b><\/strong>These Shorten <strong><b>bit.ly<\/b><\/strong>\u00a0URLs redirect to the below given malicious URLs.<\/p>\n<ul>\n<li>https[:]\/\/bit.ly\/3l2vkND<\/li>\n<li>https[:]\/\/bit.ly\/38sIQVM<\/li>\n<li>https[:]\/\/bit.ly\/2PSyhVH<\/li>\n<li>https[:]\/\/bit.ly\/3raUDj5<\/li>\n<li>https[:]\/\/bit.ly\/3qDXcc6<\/li>\n<li>https[:]\/\/bit.ly\/38tbshO<\/li>\n<li>https[:]\/\/bit.ly\/3pNezHb<\/li>\n<\/ul>\n<p><strong><b>\u00a0<\/b><\/strong><\/p>\n<p><strong><b>Malicious URLs:<\/b><\/strong><\/p>\n<ul>\n<li>http[:]\/\/domainsrvcsexpiry.com\/<\/li>\n<li>https[:]\/\/domainsrvcsexpiry.com\/03\/09\/2021be<\/li>\n<li>http[:]\/\/domainsrvcsexpiry.com\/03\/09\/2021bj\/<\/li>\n<li>https[:]\/\/domainsrvcsexpiry.com\/03\/09\/2021ae<\/li>\n<li>http[:]\/\/domainsrvcsexpiry.com\/03\/09\/2021ab<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Have you received an email notification that your domain is about to expire? Most website owners have. But do you pay close attention to who it is from and the renewal fee? If not, you may be throwing money away to a scammer. Quick Heal Security Labs has recently come across a phishing scam related [&hellip;]<\/p>\n","protected":false},"author":90,"featured_media":90126,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1739,24],"tags":[1838,1837,1839,49,25],"class_list":["post-90084","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","category-malware","tag-domain","tag-domainname","tag-expiration","tag-malware","tag-phishing"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/posts\/90084"}],"collection":[{"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/users\/90"}],"replies":[{"embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/comments?post=90084"}],"version-history":[{"count":19,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/posts\/90084\/revisions"}],"predecessor-version":[{"id":91459,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/posts\/90084\/revisions\/91459"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/media\/90126"}],"wp:attachment":[{"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/media?parent=90084"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/categories?post=90084"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/tags?post=90084"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}