Home / Blogs

Phishing Registrar Accounts: eNom is First Target

Gadi Evron

Criminals are now looking to use established domain names, via phishing targeted at domain registrars. This is possibly related to ICANN finally moving to stop the black hat registrars of the world.

According to the first report on the matter sent yesterday to Registrar Operations (reg-ops) mailing list, the attacks seem to be run by gang of child pornography spammers. The domain names in the .biz TLD are all using fast flux technology to make the attack more difficult to mitigate.

Ironically, the email spam claims that the user's domain, according to the subject, has "Inaccurate Whois information".

Until eNom and other registrars get their anti-phishing services in place, I believe it is the job of the Internet security operations community to help them out by taking down these attacks.

The Registrar Operations group (reg-ops) will be watching for these and mitigating them as fast as possible, in close cooperation with the registrars and the security community.

By Gadi Evron, Security Strategist. Visit the blog maintained by Gadi Evron here.

Related topics: Domain Names, Email, ICANN, Security, Top-Level Domains

WEEKLY WRAP — Get CircleID's Weekly Summary Report by Email:

Comments

Network Solutions just got it. Working on Gadi Evron  –  Oct 29, 2008 2:42 PM PST

Network Solutions just got it. Working on it.

Moniker too. Anyone cares about black hat Gadi Evron  –  Oct 29, 2008 3:01 PM PST

Moniker too. Anyone cares about black hat registrars?

the phisher's goals and methods in these attacks Greg Aaron  –  Oct 30, 2008 6:47 AM PST

Registrars have been phishing targets since 2007, and so it is important for them to have plans to react when they become phishing targets.  Registrars have been phishing targets since 2007, and phishers usually do not use "black hat" registrars when registering domain names for their own use.  So it seems unlikely to me that this is related to ICANN's ongoing termination effort against EstDomains. 

In these attacks, the phishers' goal is to get access to a registrant's account via the registrar interface, and thereby gain the ability to purchase domains via the registrant account, control the DNS of the registrant's domains, etc.

Greg, my friend. Thank you for your Gadi Evron  –  Oct 30, 2008 7:01 AM PST

Greg, my friend. Thank you for your comment. to further clarify your point:

Malicious activity-wise, the criminals often test their attacks before they fully unleash them. I believe that is also what happened here. Only in this case they also used the date of the ICANN information confirmation messages for their phishing spam run.

As to the why, theoretically, if a criminal uses a real domain name which for our example's purpose, is used for an ecommerce website--suspending it due to abusive activity is going to be more problematic than normal, to say the least.

To post comments, please login or create an account.

Related Blogs

Related News

Topics

Industry Updates – Sponsored Posts

Top Level Domain Holdings Raises $14M for New gTLDs

.ORG COO Discusses Priorities With DailyVista, Pursuit of .NGO Domain

StarHub to Acquire '.starhub' New Top-Level Domain

ARI Registry Services Signs 21 Contracts in the First Week of New TLD Applications

MarkMonitor to Exhibit at Internet Tech Policy Exhibition and Reception to be Held on Capitol Hill

Sedari Signs With Dot Moscow Bidders

.ORG, The Public Interest Registry Welcomes Nancy Gofus As Chief Operating Officer

Minds+Machines Works with .bayern

The New Domain For Japan, JP.NET, Launches With Exclusive Invitation to Trademark Owners

Verisign to Award New Infrastructure Research Grants

Being a .PRO When Choosing a Registry Services Partner

Afilias Acquires Registry Services Corporation, .PRO

Thoughts on Applying for a Generic Top-Level Domain

Sedari Launches "Guess the Numbers Game" for New TLD Program

dot Brand Makes Its Debut: Afilias Advises Companies to Act Now for Successful TLD Applications

Facets of gTLD Registry Technical Operations - Registry Services

Technology and Finance Industries to Dominate New gTLD Applications

.CO Internet Selects Sedo to Broker Previously Unreleased .CO Domain Names

Sedari and NCC Launch Programme to Assist New Registry Operators

Nixu SNS 2.5 Series Gives Fresh Views on DNS

Hot Topics

Minds + Machines

Top-Level Domains

Sponsored by
Minds + Machines
Afilias

DNSSEC

Sponsored by
Afilias
dotMobi

Mobile

Sponsored by
dotMobi
Neustar UltraDNS

DNS

Sponsored by
Neustar UltraDNS
Verisign

Security

Sponsored by
Verisign