NameSilo

ALERT: Phishing Scam - GoDaddy Targetted

Spaceship Spaceship
Watch

RicoShay

Experience & Service StrategistVIP Member
Impact
270
PHISHING ALERT: DOMAINERS BEWARE

I just received an email appearing to be from GoDaddy.com - alerting me to multiple invalid login attempts on my account. It gave a link asking me to proceed to setup extra security.

The email looks exactly like most legit emails I get from GoDaddy. But it just didn't sound right. I hovered over the link and immediately noticed it to be a hoax. It starts of like
Code:
http://godaddy.com.48673468909234902340X9238.search799.com

I clicked on it to take a closer look. I was presented with a page that looked identical to the GD login pages. Even the certificate at the bottom is faked almost to perfection. However, the domain where this page is hosted is "search799.com" (admin please remove if you find it inappropriate).

Amongst other things I found a fake Barclays Bank site also on the same domain.


WARNING: We all need to be extra vigilant, especially when clicking through links either via email or otherwise. As a rule, I always type in my registrars url manually - I never click through on a link without inspecting it first. Everyone needs to be aware of these scams. Your domains are at risk, so pay that little extra bit of attention.


Pay attention to the links, the most important part is the just before the first forward slash - right after the extension.

eg.

Code:
http://namepros.com.7897983-04.security.fakedom.com/example

in that example "fakedom.com" is the domain and not namepros.com as it might appear at first glance. Scam links generally use subdomains with names of popular sites to make it appear like its the real deal.


Btw. I'm not sure who, how or where to report this issue. Please feel free to take some action and give advice on what to do with such cases.
 
0
•••
The views expressed on this page by users and staff are their own, not those of NamePros.
Unstoppable Domains โ€” AI StorefrontUnstoppable Domains โ€” AI Storefront
Thanks for alert. I just received the same scam emails.
The whois for search799 shows:

Registrant:
Jackie Robinson
140 Marlborough Street
Henley Beach
Adelaide, South Australia 5022
Australia

Domain Name: SEARCH799.COM
Created on: 25-Nov-07
Expires on: 25-Nov-09
Last Updated on: 16-Jun-09

Administrative Contact:
Robinson, Jackie
140 Marlborough Street
Henley Beach
Adelaide, South Australia 5022
Australia
(088) 356-6285 Fax --

email [email protected]
 
0
•••
I just received about 10 of the exact same emails. The first giveaway was that the email came to my whois email, which is different than my account email. The link pointed to cyber-edge.com, which is registered on GoDaddy using Domains By Proxy, pretty ironic.

I would like to report this but have no idea who to report it to.

Brad
 
0
•••
I just received about 10 of the exact same emails. The first giveaway was that the email came to my whois email, which is different than my account email. The link pointed to cyber-edge.com, which is registered on GoDaddy using Domains By Proxy, pretty ironic.

I would like to report this but have no idea who to report it to.

Brad

So, its quite common then. Just as I feared.

I've no clue how to go about reporting it either. I'm surprised there's not been much response here.

ddchan, nice work with the whois info lol.

Would be nice to get more input here.
This is quite a serious issue.

8-X%%-
 
0
•••
I would send godaddy a mail.They should be made aware.
 
0
•••
i think the websites are removed now...
ny wasy thanks for updating us regarding the issue
 
0
•••
thanks for the alert
 
0
•••
Dynadot โ€” .com TransferDynadot โ€” .com Transfer
Appraise.net
Domain Recover
NameMaxi - Your Domain Has Buyers
  • The sidebar remains visible by scrolling at a speed relative to the pageโ€™s height.
Back