NameSilo

WARNING NEW GODADDY PHISHING EMAIL !!!

Spaceship Spaceship
Watch
Impact
6,395
I have just received this NEW AND VERY WELL DONE phishing email.

Please be very careful and always double check the source and redirection links/button.

The following email comes from master @ godaddy .com

SO WHY IS IT FAKE?

  • GD always places customer names and account ID in their emails
  • when hovering on the orange and green buttons the hidden link is godadbby .com
  • there are some other dodgy aspects
Even though it's not a perfect carbon copy of a real GD email it is the very best attempt I have seen so far and it could easily fool many of us who are not familiar with GD emails or are simply in a hurry. Luckily enough this email was put directly in my spam folder.


@Joe Styler please take notice.

GD phishing 1.jpg
GD phishing 2.jpg







 
Last edited:
16
•••
The views expressed on this page by users and staff are their own, not those of NamePros.
I received this as well.
And I knew immediately that it's fake because GD will never reward existing customers with 50% off :rolleyes:
 
6
•••
What is the domain name being used for links and email?

Would like to know the registrar that the domain is reg'd at.
 
0
•••
What is the domain name being used for links and email?

Would like to know the registrar that the domain is reg'd at.

I wrote it up there godadbby .com

Domain Name: GODADBBY.COM
Registrar: BEIJING INNOVATIVE LINKAGE TECHNOLOGY LTD. DBA DNS.COM.CN
Sponsoring Registrar IANA ID: 633
Whois Server: whois.dns.com.cn
Referral URL: http://www.dns.com.cn
Name Server: F1G1NS1.DNSPOD.NET
Name Server: F1G1NS2.DNSPOD.NET
Status: clientTransferProhibited http://www.icann.org/epp#clientTransferProhibited
Updated Date: 23-oct-2015
Creation Date: 23-oct-2015
Expiration Date: 23-oct-2016
godadbby.com registrar whois
Updated 1 second ago
Domain name: godadbby.com
Registry Domain ID: 1971126768_DOMAIN_COM-VRSN
Registrar WHOIS Server: whois.dns.com.cn
Registrar URL: http://www.dns.com.cn
Updated Date: 2015-10-23T15:02:37Z
Creation Date: 2015-10-23T15:02:37Z
Registrar Registration Expiration Date: 2016-10-23T15:02:37Z
Registrar: Beijing Innovative Linkage Technology Ltd.
Registrar IANA ID: 633
Registrar Abuse Contact Email:
f27330124ea50a1a7ed40205dac7ab29f6f4b68d.png
@dns.com.cn
Registrar Abuse Contact Phone: +86.1082151122
Reseller:
Domain Status: clientTransferProhibited
Registry Registrant ID:
Registrant Name: Protection Privacy
Registrant Organization:
Registrant Street: 12 Xueyuannan Rd
Registrant City: Beijing
Registrant State/Province: BJ
Registrant Postal Code: 100089
Registrant Country: CN
Registrant Phone: +86.1059928888
Registrant Phone Ext:
Registrant Fax: +86.1059928888
Registrant Fax Ext:
Registrant Email:
b854e3e1ad0a62945669750c1ff6819c19b28a78.png
@rashost.cn
Registry Admin ID:
Admin Name: Protection Privacy
Admin Organization:
Admin Street: 12 Xueyuannan Rd
Admin City: Beijing
Admin State/Province: BJ
Admin Postal Code: 100089
Admin Country: CN
Admin Phone: +86.1059928888
Admin Phone Ext:
Admin Fax: +86.1059928888
Admin Fax Ext:
Admin Email:
b854e3e1ad0a62945669750c1ff6819c19b28a78.png
@rashost.cn
Registry Tech ID:
Tech Name: Protection Privacy
Tech Organization:
Tech Street: 12 Xueyuannan Rd
Tech City: Beijing
Tech State/Province: BJ
Tech Postal Code: 100089
Tech Country: CN
Tech Phone: +86.1059928888
Tech Phone Ext:
Tech Fax: +86.1059928888
Tech Fax Ext:
Tech Email:
b854e3e1ad0a62945669750c1ff6819c19b28a78.png
@rashost.cn
Name Server: f1g1ns2.dnspod.net
Name Server: f1g1ns1.dnspod.net
DNSSEC: unsigned
URL of the ICANN WHOIS Data Problem Reporting System: http://wdprs.internic.net/
>>> Last update of WHOIS database: Fri Nov 20 04:33:50 2015 +0800

The data in this whois database is provided to you for information
purposes only, that is, to assist you in obtaining information about or
related to a domain name registration record. We make this information
available "as is," and do not guarantee its accuracy. By submitting a
whois query, you agree that you will use this data only for lawful
purposes and that, under no circumstances will you use this data to: (1)
enable high volume, automated, electronic processes that stress or load
this whois database system providing you this information; or (2) allow,
enable, or otherwise support the transmission of mass unsolicited,
commercial advertising or solicitations via direct mail, electronic
mail, or by telephone. The compilation, repackaging, dissemination or
other use of this data is expressly prohibited without prior written
consent from us. We reserve the right to modify these terms at any time.
By submitting this query, you agree to abide by these terms.
 
0
•••
0
•••
0
•••
You've edited your post I see...

No I have just underlined it as apparently it wasn't visible enough. It has been there since the beginning ask the mods, they have all the logs. You haven't read the post thoroughly I see...
Now please move on. Thanks.
 
0
•••
0
•••
Your first post actually doesn't have the domain. :)
Chinese registrar this time... the last one I reported directly to GD was reg'd at Namesilo.

I think I understand the confusion here, and this is an important distinction. The email comes from godaddy com, if I understand correctly. The links go to godadbby com. Right? Go Daddy could easily prevent fake emails appearing to be from godaddy com if they bothered to properly configure DMARC.
 
6
•••
I think I understand the confusion here, and this is an important distinction. The email comes from godaddy com, if I understand correctly. The links go to godadbby com. Right? Go Daddy could easily prevent fake emails appearing to be from godaddy com if they bothered to properly configure DMARC.

It's hard to know when the headers are not pasted.

I would ask for the full headers...but yeah.. :D

However, Godaddy does have DKIM setup, which is how I usually know it is them.
 
0
•••
I received this as well.
And I knew immediately that it's fake because GD will never reward existing customers with 50% off :rolleyes:

off topic flashback! I seem to remember G doing a 50% off anything special a couple years ago. wish that was done once a year. maybe on the anniversary of the day godaddy.com was registered? YES !!!!!!!!!!! :)
 
2
•••
Godaddy are stupid adding links in emails. You can't call that a safe registrar..
 
1
•••
I too received this email and was quick to notice that it came from godadbby.com
 
1
•••
Me too I've received two emails today for the same domain ... I just ignore those emails as I have been getting them every few days and they love numerics...

226860.JPG
 
1
•••
So frustrating, I'm getting these emails a good few times daily now.

My domains what cause this:

277290.com
277260.com

Just wondering as it says it's from "[email protected]" but obviously it's from "godadbby.com".

How I add this to my blocked spam email list as I don't want to block the real GD?
 
Last edited:
1
•••
That is why it is good to check such emails on pc system and not on phone, as no one could hover mouse on links if it is on phones, but it is easy to hover mouse on systems.

Cheers.
 
1
•••
Woooah, thanks for letting us know!

These Phishing bandits are getting more and more creative these days.
 
1
•••
How I add this to my blocked spam email list as I don't want to block the real GD?

Mine was automatically blocked. As I mentioned in the opening post I found it in my spam folder
 
0
•••
  • The sidebar remains visible by scrolling at a speed relative to the page’s height.
Back