[HN Gopher] Ask HN: How to get a phishing website that steals cr...
___________________________________________________________________
Ask HN: How to get a phishing website that steals credentials taken
down?
Every few weeks I receive one of those scam SMS messages that are
along the lines of "You have not paid for shipping for your parcel,
please go to scam-domain-123.xyz to pay" which then has a php form
to steal unsuspecting people's credit card details. Sometimes I
look for these on popular social media posts as well where people
repost SMS scams, and every time I do a WHOIS check, contact the
registrar's abuse email, send them the details, and get them taken
down so they don't scam more people. I know the scammers will just
register another domain, but it does slow them down and in my mind
if I save just one person from getting scammed by doing that, it's
worth it. It's like a hobby in my free time. My success rate has
been pretty much 100%, some registrars like Porkbun get the domains
delisted within minutes, I am very impressed. Others take their
time but it always works in the end. I have recently ran into one
instance where my reports do nothing, the registrar is ignoring it
and I'm not sure how I can get it taken down. These domains have
been active for more than a month. WARNING! DANGEROUS SCAM
websites ahead, do visit if you don't know what you're doing and DO
NOT put any details into the forms! I have encoded them in base64
just in case: aHR0cHM6Ly9hcHBsZS13YWxsZXQtaWQ0Ny5jb20v (WARNING
SCAM WEBSITE!) The first website attempts to steal all your
payment details, and after entering them (I tried with fake ones
obviously), then redirects to the second website attempting to
steal your iCloud credentials:
aHR0cHM6Ly9hcHBsZXBheS5hdXRoLWljbG91ZC5jb20v (WARNING SCAM
WEBSITE!) They are both very well made and cloned in the style of
official Apple websites. The registrar seems to be ALIBABA.COM
SINGAPORE E-COMMERCE PRIVATE LIMITED. When I contacted their abuse
email, I get an automated message saying my message is ignored
because they get a lot of false reports (how convenient!), and
redirecting me to another website[0] to report it which requires
tons of your personal details, photographic evidence, and all sorts
of nonsense. I filled out these forms but they seem to just ignore
the report anyway. For some reason these websites are still not
flagged by Chrome's Safe Browsing despite me making reports[1] and
the website running for at least a month, having been registered on
2022-08-03. Google are normally pretty good in flagging these kind
of websites but in this instance it seems futile. Any ideas? [0]
1. https://report.aliyun.com (for users within China) 2.
https://intl.aliyun.com/report#abuse (for users outside of China)
[1] https://safebrowsing.google.com/safebrowsing/report_phish/
Author : temp_account_32
Score : 8 points
Date : 2022-08-29 21:06 UTC (1 hours ago)
| mtmail wrote:
| You did an impressive number of steps and follow-ups already.
|
| If it's faking a Apple website it might help to report it to
| Apple, too. I reported fake bank websites to the (real) banks and
| they were responsive because it's in their best interest as their
| customers are likely the targeted audience. That would hopefully
| get their security team (or a project manager) on the case. I
| didn't follow up though how long deletion took.
| 0x0000000 wrote:
| Agree with this, if the malicious site is phishing by
| purporting to be a corporate entity, report it to them if you
| can. Most of them have Brand Protection(tm) services on
| retainer which will have their own relationships with
| registrars and know the ICANN dispute/seizure process very
| well.
| temp_account_32 wrote:
| Thanks to you and the other poster on this suggestion, it
| hadn't occurred to me that Apple will have such a reporting
| channel as well.
| connordoner wrote:
| Safari on macOS shows a Deceptive Website Warning for the first
| but not the second. The second now seems to redirect (unless it
| discriminates based on User Agent, country or similar) to
| apple.com/pay.
|
| That said, it might be worth reporting both to Apple at
| reportphishing@apple.com.
| temp_account_32 wrote:
| Thanks for the idea, will try this.
|
| RE: Discrimination, yes it is very possible, I have ran into
| all sorts of server configurations, discriminating based on
| User Agents, Geolocation, etc. and usually they redirect you
| away to the real websites if you're not the "target". The
| second website can spawn a fake iCloud login screen.
| altilunium wrote:
| > When I contacted their abuse email, I get an automated message
| saying my message is ignored because they get a lot of false
| reports (how convenient!), and redirecting me to another
| website[0] to report it which requires tons of your personal
| details, photographic evidence, and all sorts of nonsense. I
| filled out these forms but they seem to just ignore the report
| anyway.
|
| I also experienced this multiple times when trying to report scam
| and phishing sites. Some registrars/hosting services wont respond
| positively to abuse report ever, then what's the point of abuse
| email?
|
| I wonder if we could report them to their higher authority
| (IANA?).
___________________________________________________________________
(page generated 2022-08-29 23:02 UTC)