Page 1 of 1

Weird duplicate/phising domains?

Posted: Tue Jun 25, 2013 5:14 am
by Sirioh
What's up with the strange domains that mirror te4.org, but are clearly not legitimate? For example: sports3.blog.forums.te4.org.com; forus.te4.org; ww.w.te4.org, among many others. I presume these are some kind of phishing attempt, but I can't really fathom why. I've most often seen these sorts of permutations with things like phishing scams for MMOs (e.g. WoW, Diablo 3, GW2, among others), but I can't imagine why anyone would try to target TOME. Does accessing someone's account gain access to financial information, as it does with those more popular scams? Or perhaps I'm being too specific; instead, such sites may attempt to simply install keyloggers or other trojans rather than specifically access the account's financial information.

Just figured I'd give a heads up if this wasn't already known. You can see a few more of the "bogus" domains with a google search. I don't suggest actually visiting any of them; between adblock and noscript I felt safe enough to at least look, they appear visually to be complete copies of the pages of the real website. I didn't poke around any farther than just looking, though.

Re: Weird duplicate/phising domains?

Posted: Tue Jun 25, 2013 2:07 pm
by greycat
Anything that ends with .te4.org is under DarkGod's control, at least in theory. He's the registrant for te4.org (confirmed with whois).

I tried http://forus.te4.org/ and it merely redirected me to http://te4.org/ . In fact it's a simple CNAME (or DNS alias):
imadev:~$ host forus.te4.org
forus.te4.org is a nickname for te4.org
te4.org has address 176.31.252.67
te4.org mail is handled (pri=10) by mail.te4.org
Presumably DarkGod set that up for some reason (testing?) and then left it in place. I see nothing malicious there.

Now, something like te4.org.com is another matter entirely. You'd be right to exercise caution there.