[HN Gopher] Ask HN: How to get a phishing website that steals cr...
       ___________________________________________________________________
        
       Ask HN: How to get a phishing website that steals credentials taken
       down?
        
       Every few weeks I receive one of those scam SMS messages that are
       along the lines of "You have not paid for shipping for your parcel,
       please go to scam-domain-123.xyz to pay" which then has a php form
       to steal unsuspecting people's credit card details.  Sometimes I
       look for these on popular social media posts as well where people
       repost SMS scams, and every time I do a WHOIS check, contact the
       registrar's abuse email, send them the details, and get them taken
       down so they don't scam more people.  I know the scammers will just
       register another domain, but it does slow them down and in my mind
       if I save just one person from getting scammed by doing that, it's
       worth it. It's like a hobby in my free time.  My success rate has
       been pretty much 100%, some registrars like Porkbun get the domains
       delisted within minutes, I am very impressed. Others take their
       time but it always works in the end.  I have recently ran into one
       instance where my reports do nothing, the registrar is ignoring it
       and I'm not sure how I can get it taken down. These domains have
       been active for more than a month.  WARNING! DANGEROUS SCAM
       websites ahead, do visit if you don't know what you're doing and DO
       NOT put any details into the forms!  I have encoded them in base64
       just in case: aHR0cHM6Ly9hcHBsZS13YWxsZXQtaWQ0Ny5jb20v (WARNING
       SCAM WEBSITE!)  The first website attempts to steal all your
       payment details, and after entering them (I tried with fake ones
       obviously), then redirects to the second website attempting to
       steal your iCloud credentials:
       aHR0cHM6Ly9hcHBsZXBheS5hdXRoLWljbG91ZC5jb20v (WARNING SCAM
       WEBSITE!)  They are both very well made and cloned in the style of
       official Apple websites.  The registrar seems to be ALIBABA.COM
       SINGAPORE E-COMMERCE PRIVATE LIMITED.  When I contacted their abuse
       email, I get an automated message saying my message is ignored
       because they get a lot of false reports (how convenient!), and
       redirecting me to another website[0] to report it which requires
       tons of your personal details, photographic evidence, and all sorts
       of nonsense. I filled out these forms but they seem to just ignore
       the report anyway.  For some reason these websites are still not
       flagged by Chrome's Safe Browsing despite me making reports[1] and
       the website running for at least a month, having been registered on
       2022-08-03. Google are normally pretty good in flagging these kind
       of websites but in this instance it seems futile.  Any ideas?  [0]
       1. https://report.aliyun.com (for users within China) 2.
       https://intl.aliyun.com/report#abuse (for users outside of China)
       [1] https://safebrowsing.google.com/safebrowsing/report_phish/
        
       Author : temp_account_32
       Score  : 8 points
       Date   : 2022-08-29 21:06 UTC (1 hours ago)
        
       | mtmail wrote:
       | You did an impressive number of steps and follow-ups already.
       | 
       | If it's faking a Apple website it might help to report it to
       | Apple, too. I reported fake bank websites to the (real) banks and
       | they were responsive because it's in their best interest as their
       | customers are likely the targeted audience. That would hopefully
       | get their security team (or a project manager) on the case. I
       | didn't follow up though how long deletion took.
        
         | 0x0000000 wrote:
         | Agree with this, if the malicious site is phishing by
         | purporting to be a corporate entity, report it to them if you
         | can. Most of them have Brand Protection(tm) services on
         | retainer which will have their own relationships with
         | registrars and know the ICANN dispute/seizure process very
         | well.
        
         | temp_account_32 wrote:
         | Thanks to you and the other poster on this suggestion, it
         | hadn't occurred to me that Apple will have such a reporting
         | channel as well.
        
       | connordoner wrote:
       | Safari on macOS shows a Deceptive Website Warning for the first
       | but not the second. The second now seems to redirect (unless it
       | discriminates based on User Agent, country or similar) to
       | apple.com/pay.
       | 
       | That said, it might be worth reporting both to Apple at
       | reportphishing@apple.com.
        
         | temp_account_32 wrote:
         | Thanks for the idea, will try this.
         | 
         | RE: Discrimination, yes it is very possible, I have ran into
         | all sorts of server configurations, discriminating based on
         | User Agents, Geolocation, etc. and usually they redirect you
         | away to the real websites if you're not the "target". The
         | second website can spawn a fake iCloud login screen.
        
       | altilunium wrote:
       | > When I contacted their abuse email, I get an automated message
       | saying my message is ignored because they get a lot of false
       | reports (how convenient!), and redirecting me to another
       | website[0] to report it which requires tons of your personal
       | details, photographic evidence, and all sorts of nonsense. I
       | filled out these forms but they seem to just ignore the report
       | anyway.
       | 
       | I also experienced this multiple times when trying to report scam
       | and phishing sites. Some registrars/hosting services wont respond
       | positively to abuse report ever, then what's the point of abuse
       | email?
       | 
       | I wonder if we could report them to their higher authority
       | (IANA?).
        
       ___________________________________________________________________
       (page generated 2022-08-29 23:02 UTC)