Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Spam, Scam and Phishbusters » [Phish] Google adwords phish "please udpate your billing info"
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
[Scam] Scam email not suree what to do with.... »
« [Credit Card Fraud] PW EAUCTION, aka Pacific Webworks  
AuthorAll Replies


Dennis
Premium,Mod
join:2001-01-26
Algonquin, IL
reply to MGD
Re: [Phish] Google adwords phish "please udpate your billing inf

yeah, after my post I tried to reach it from a "test" computer and couldn't get to it.

odd....


SnowyOne
Premium
join:2003-04-05
Kailua, HI
·RoadRunner Cable
·Clearwire Wireless

said by Dennis See Profile :

yeah, after my post I tried to reach it from a "test" computer and couldn't get to it.
It's reachable. Maybe not touchable, but reachable.
»www.fr4ck.cn/icons/


SnowyOne
Premium
join:2003-04-05
Kailua, HI
·RoadRunner Cable
·Clearwire Wireless

Where would a logical traceroute of »r4oik.cn end at?
China
Brazil
France
Zululand
Romania
Memphis TN

Here's a hint: It's a phish site
»89.41.180.87/icons/

MGD
Premium,MVM
join:2002-07-31
Fort Lauderdale, FL


edit:
March 23rd, @02:31AM

said by SnowyOne See Profile :

Where would a logical traceroute of »r4oik.cn end at? ...
Appears to be roving bot type hosting. A 30 minute TTL on the phisher contolled DNS rotates a pool of hosts.

A list of 10 hosts cached on a non authorative DNS:


; > DiG 9.2.4 > @algw1.att.com -t A adwords.google.com.r4oik.cn
;; global options: printcmd
;; Got answer:
;; ->>HEADER->> opcode: QUERY, status: NOERROR, id: 22389
;; flags: qr rd ra; QUERY: 1, ANSWER: 10, AUTHORITY: 2, ADDITIONAL: 2

;; QUESTION SECTION:
;adwords.google.com.r4oik.cn. IN A

;; ANSWER SECTION:

adwords.google.com.r4oik.cn. 1800 IN A 84.108.239.70
[reverse DNS - bzq-84-108-239-70.cablep.bezeqint.net]
.
adwords.google.com.r4oik.cn. 1800 IN A 85.130.35.217
[reverse DNS - 85-130-35-217.1712826.ddns.cablebg.net]
.
adwords.google.com.r4oik.cn. 1800 IN A 86.122.171.209
[reverse DNS - 86-122-171-209.rdsnet.ro]
.
adwords.google.com.r4oik.cn. 1800 IN A 87.68.1.132
[reverse DNS - 87.68.1.132.cable.012.net.il]
.
adwords.google.com.r4oik.cn. 1800 IN A 87.68.28.118
[reverse DNS - 87.68.28.118.cable.012.net.il]
.
adwords.google.com.r4oik.cn. 1800 IN A 222.235.171.188
[no reverse DNS set]
.
adwords.google.com.r4oik.cn. 1800 IN A 59.187.199.82
[no reverse DNS set]
.
adwords.google.com.r4oik.cn. 1800 IN A 79.116.242.190
[reverse DNS - 79-116-242-190.rdsnet.ro]
.
adwords.google.com.r4oik.cn. 1800 IN A 80.97.170.165
[no reverse DNS set]
.
adwords.google.com.r4oik.cn. 1800 IN A 81.25.43.13
[reverse DNS - port-13-adslby-pool43.infonet.by]
.



A get request of the root IP on several, if not all, of the above will generate a redirect to:
>http://www.microsoft.com/


Also, the actual phish page contains a 1x1 iframe for:
>http://58.65.239.3/cgi-bin/mail.cgi?p=tor

which is the subject of:

FORM id=wzMainForm name=wzMainForm

action=submit.php

method=post
and relevant to:


After the submit to 58.65.239.3/cgi-bin/mail.cgi you are then redirected to >http://www.google.com:


IP 58.65.239.3 appears to have FTP running and hosts two domains: Escortinukraine.com and Kumau.info. They may not be relevant if that IP is hijacked.

MGD


SnowyOne
Premium
join:2003-04-05
Kailua, HI
·RoadRunner Cable
·Clearwire Wireless

said by MGD See Profile :

IP 58.65.239.3 appears to have FTP running and hosts two domains: Escortinukraine.com and Kumau.info.
OK,OK, but just in the defense of Truth, Justice & The GoogleWay!

MGD
Premium,MVM
join:2002-07-31
Fort Lauderdale, FL


edit:
March 23rd, @02:54AM

LOL !!

....
..
For reference, in case it disappears, here is the source code for the entire phish page. For some reason it causes an immediate GPF on my web brwowser. I am not sure why.


MGD


SnowyOne
Premium
join:2003-04-05
Kailua, HI
·RoadRunner Cable
·Clearwire Wireless

said by MGD See Profile :

For reference, in case it disappears, here is the source code for the entire phish page. For some reason it causes an immediate GPF on my web brwowser. I am not sure why.

Uhm, excuse me, but that's why you're supposed to put crap like this on other peoples servers.


Dennis
Premium,Mod
join:2001-01-26
Algonquin, IL
oh man here we go again



Dennis
Premium,Mod
join:2001-01-26
Algonquin, IL
·AT&T Yahoo

Host:
Chicago
Users find Hot Deals
Users find Hot Dea..
Requests for Hot D..
Home Repair & Impr..

edit:
April 7th, @09:49AM

two more this morning...

It just occurred to me now that this is way too focused of an attack to be random or luck. Plus I'm getting them to two very specific email addresses...so after a little digging I've found only one place that they could have been pulled from.

Google Analytics
»https://www.google.com/analytics

It's the only place that both email addresses were in (I get daily reports on different sub domains, one to each) so I have to assume at this point that somebody gained access to the list of emails and assumed that a majority of people using Google Analytics were also using Google Adwords (not to be confused with Adsense).

Now the only question is...does google know???

--
My Blog. Because I desperately need the acknowledgement of others.

Meet my son, Connor.


Dennis
Premium,Mod
join:2001-01-26
Algonquin, IL
and again:

No response from google about this at all yet...


Dennis
Premium,Mod
join:2001-01-26
Algonquin, IL
·AT&T Yahoo

Host:
Chicago
Users find Hot Deals
Users find Hot Dea..
Requests for Hot D..
Home Repair & Impr..

You know the frequency of these is what scares me the most...

--
My Blog. Because I desperately need the acknowledgement of others.

Meet my son, Connor.


Dennis
Premium,Mod
join:2001-01-26
Algonquin, IL
·AT&T Yahoo

Host:
Chicago
Users find Hot Deals
Users find Hot Dea..
Requests for Hot D..
Home Repair & Impr..

edit:
April 8th, @08:23AM

lord...why did I even try. All they did was send me a explanation of what "spoofing" is.

Good to see that Google has joined the ranks of the large company that hires people dumb enough to not understand the emails they get.

On second thought...it was probably just a small perl script that responded to me.

--
My Blog. Because I desperately need the acknowledgement of others.

Meet my son, Connor.


VisualdreamZ

@cox.net

Gotta point out one other thing about this that is a little scarier than your average phishing scheme. It follows the logical procession of what it claims to be. In order, and on a reasonable time frame.

I unfortunately did not keep most of these, but I received the first I think sometime in late February. Received a couple more in March and earlier April. And now I just received one yesterday (as I scrolled through my spam box) that claimed "Your adwords account has now been 'stoped'." (Thank god for illiterate phisphers!)

But the fact that it well mimics the general progress of a real account shut down indicates a somewhat higher level of intelligence here. And - that scares me. LOL

Just thought I'd share my observation, and thanks for allowing a body to post without creating yet another account =)

V--Z

PS - I tried telling google, too, and also got the standard scripted response. Thank god for form letter writers, too, keeping otherwise perfectly good telemarketers from calling me!
Forums » Up and Running » Security » Spam, Scam and Phishbusters[Scam] Scam email not suree what to do with.... »
« [Credit Card Fraud] PW EAUCTION, aka Pacific Webworks  


Tuesday, 02-Dec 14:43:39 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 9 years online! © 1999-2008 dslreports.com.
page compression OFF
Most commented news this week
· [106] AT&T Metered Billing Trial Hits Second Market
· [82] UDP BitTorrent Will Destroy The Interwebs!
· [59] Comcast Tries To Slow Verizon's Philly Entry
· [56] EFF Challenges Telecom Immunity
· [25] Cablevision Bumps HD Count To 68
· [22] Mega-ISPs, Consumer Advocates Demand Broadband Plan
· [17] FCC To Vote On Free National Wireless Broadband
· [15] Clearwire May Slow WiMax Build
· [14] Hawaii Telecom Files For Bankruptcy
· [8] Embarq Rejected Higher Offer
Most people now reading
· [Rant] Bestbuy receipt checker [Rants, Raves, & Praise]
· Is this a good thing for the net? [news,99366]
· Coalition Government Possible? [TekSavvy]
· Routing problem? [OptimumOnline]
· Java SE Runtime Environment (JRE) 6 Update 11 [Security]
· Comcast has horribly hobbled Houston! [Comcast HSI]
· Basic 500 Price Increase! [Vonage]
· Ted Rogers passed away [Rogers]
· [WotLK] New Hunter Macros [World of Warcraft]
· Level 80 PVP gear info? [World of Warcraft]