פישינג או סקאם בנוגע לחידוש דומיין

דומיינים: domainvlx[.]cc, premiumdomainregistry[.]com
ארץ מקור למתקפה: רוסיה (ככל הנראה).

אימייל שהתקבל כולל האדרים (מצונזר)
Return-Path: <info@premiumdomainregistry.com>
Delivered-To: REDACTED
Received: from REDACTED ([REDACTED])
	by REDACTED with LMTP
	id REDACTED
	(envelope-from <info@premiumdomainregistry.com>)
	for <REDACTED>; Sun, 30 Jan 2022 12:28:06 +0000
Received: from srv.premiumdomainregistry.com (srv.premiumdomainregistry.com [91.217.77.52])
	(using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits))
	(No client certificate requested)
	by REDACTED (Postcow) with ESMTPS id REDACTED
	for <REDACTED>; Sun, 30 Jan 2022 12:28:05 +0000 (UTC)
Received: from [REDACTED]
DKIM-Filter: OpenDKIM Filter v2.11.0 srv.premiumdomainregistry.com REDACTED
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
	d=premiumdomainregistry.com; s=default; t=1643545680;
	bh=IA1COZr8y2SP1jIL/9f9pf2I5w0udOmzWermjiHSLRw=;
	h=Date:Subject:From:Reply-To:To:List-Id:From;
	b=oe1DVgAvj2tKzZLrj+Sh+pFcxsTS+Hg8yClF+XX5T8YRkgRE58h2eF2LEAeymsaQH
	 AXNezIr9iFHPJ1kbSxRaoIYG/1FUiRhU3EsjDYjwnHCDcMJdhXawuZbnwGcia4eemW
	 FayPozwnNbcAXFNy30a4hkeKOypePUWysTyhYYBc=
Message-ID: <6dfb8b25a99505aaa37cc549128c93fd6d228eb6@premiumdomainregistry.com>
Date: Sun, 30 Jan 2022 12:27:59 +0000
Subject: THISISNOTBANKOFAMERICA.COM TERMINATION Notice
From: "THISISNOTBANKOFAMERICA.COM Domain" <info@premiumdomainregistry.com>
Reply-To: "THISISNOTBANKOFAMERICA.COM Domain" <info@premiumdomainregistry.com>
To: "REDACTED" <REDACTED>
MIME-Version: 1.0
Content-Type: multipart/alternative;
 boundary="_=_swift_1643545679_4f477ce554df5134b852ffd641a08a84_=_"
List-Id: gy69061kznaa8 <GIC 12>
Feedback-ID: rh690t82488a6:pa1243ahjo30d:gy69061kznaa8:ml2487mm8xbc5
ARC-Seal: i=1; s=dkim; d=REDACTED; t=1643545685; a=rsa-sha256; cv=none;
	b=oWWA9HLcwzVwWIvRhb+ZlKnLLqx1xQLFtrE34I63XfVLBDrJhrTrjq1IIwvhP0sxcXa+fS
	Gw3bH7DRbdcOEkfsdw4j/SYTSXV01Tpf3nE3Ljl3P+ImjFyYJxx5ZDbrWi33RsHAo31aif
	6D7hknc/jd5haT3B+6GGg7vvaMkB06Bu1+N7HsKIqmb2KZI6kdqSZw2w8Z/X41OEw7Al1Y
	4/9bE8WyMHi+qDkdkK/tZ6tV8MxXvmWSm0W9HbjoGKH9UGdj1YinZf6VCrVZ/AXGfS4ftc
	0ERb2LZJPhN7rQTI5cyJ/IQN41oicxf3L/ON/Kje5ROdLuYT4B4aBUNanTg1eA==
ARC-Authentication-Results: i=1;
	REDACTED;
	dkim=pass header.d=premiumdomainregistry.com header.s=default header.b=oe1DVgAv;
	dmarc=permerror reason="Multiple policies defined in DNS" header.from=premiumdomainregistry.com (policy=permerror);
	spf=pass (REDACTED: domain of info@premiumdomainregistry.com designates 91.217.77.52 as permitted sender) smtp.mailfrom=info@premiumdomainregistry.com
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=REDACTED;
	s=dkim; t=1643545685; h=from:from:reply-to:reply-to:subject:subject:date:date:
	 message-id:message-id:to:to:cc:mime-version:mime-version:
	 content-type:content-type:list-id:dkim-signature;
	bh=IA1COZr8y2SP1jIL/9f9pf2I5w0udOmzWermjiHSLRw=;
	b=ot/5LzYX+zLBj1Ph35dvOm0yBbnqOAAzv+nUOQPAS0uq5tvD+Z5YHspnAj8fxNamAB8Kvy
	g2lyiylWYf0lvpYXZo3D3I33qUTZ6XBCnbAiuImHDtPSFQu8p6qfo4Pyd07xJJS5W1DD6f
	SVf9c+MYqDKvdLMIihx4zj4tLhu5gu1I6YljaqJ+vRaQH9XfbtC22rIKbb9QMG/8MuLZDd
	pCNVAggcd+FYkAMhW94fuOJ1lxMfstFu9gWfJQSmbGapxWAv5PSezqMesfRIS8qqCeRgvg
	c2JnAWOe43BEoj6XksXMAOL9aBAaQhlO9JX4l/CMXHz8phxWJKi/1FE0ctPBsA==
X-Last-TLS-Session-Version: TLSv1.2
Authentication-Results: REDACTED;
	dkim=pass header.d=premiumdomainregistry.com header.s=default header.b=oe1DVgAv;
	dmarc=permerror reason="Multiple policies defined in DNS" header.from=premiumdomainregistry.com (policy=permerror);
	spf=pass (REDACTED: domain of info@premiumdomainregistry.com designates 91.217.77.52 as permitted sender) smtp.mailfrom=info@premiumdomainregistry.com
X-Spamd-Result: REDACTED
X-Rspamd-Queue-Id: REDACTED


--_=_swift_1643545679_4f477ce554df5134b852ffd641a08a84_=_
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: quoted-printable

This notice is to inform you that your outstanding invoice number
81680e8=
7662540928e7c667eeb63f5e7 is OVERDUE.
THISISNOTBANKOFAMERICA.COM.COM expi=
red on 01/30/2022 is SUSPENDED.
Please make payment ASAP to avoid any TER=
MINATION of service to
THISISNOTBANKOFAMERICA.COM
Do take note that if =
no payment is made in the next 3 business days,
your data will be purged =
and deleted.
TO RENEW THISISNOTBANKOFAMERICA.COM (Expires on 01/30/2022):=

https://domainvlx.cc/?xid=3D81680e87662540928e7c667eeb63f5e7
The conta=
ct currently listed is Itzhak Daniel.
Disclaimer notice: We can not be he=
ld legally liable for any claims,
damage or loss that you may incur becau=
se of the cancellation of
THISISNOTBANKOFAMERICA.COM. Any such damages ma=
y potentially include
but are not solely limited to: monetary losses, del=
eted data without
backup copies, loss of position in search rankings, mis=
sed
appointments, undeliverable email and any other technical, business o=
r
service damage that you may suffer. For more information please refer=

section 22.d.1.c of our Terms of Service.
This is the final message th=
at we are legally required to send out
with regards to the expiration of =
THISISNOTBANKOFAMERICA.COM.
SECURE ONLINE RENEWAL:
=3D=3D> https://doma=
invlx.cc/?xid=3D81680e87662540928e7c667eeb63f5e7

--_=_swift_1643545679_4f477ce554df5134b852ffd641a08a84_=_
Content-Type: text/html; charset=utf-8
Content-Transfer-Encoding: quoted-printable

<!DOCTYPE html>
<html>
<head><meta charset=3D"utf-8"/>
=09<title>THISISNOTBANKOFAMERICA.COM TERMINATION Notice</title>
</head>
<body>This notice is to inform you that your outstanding invoice number 816=
80e87662540928e7c667eeb63f5e7 is OVERDUE. THISISNOTBANKOFAMERICA.COM.COM ex=
pired on 01/30/2022 is SUSPENDED. Please make payment ASAP to avoid any TER=
MINATION of service to THISISNOTBANKOFAMERICA.COM<br />
<br />
Do take note that if no payment is made in the next 3 business days, your d=
ata will be purged and deleted.<br />
<br />
TO RENEW THISISNOTBANKOFAMERICA.COM (Expires on 01/30/2022):<br />
<br />
https://domainvlx.cc/?xid=3D81680e87662540928e7c667eeb63f5e7<br />
<br />
The contact currently listed is Itzhak Daniel.<br />
<br />
Disclaimer notice: We can not be held legally liable for any claims, damage=
 or loss that you may incur because of the cancellation of THISISNOTBANKOFA=
MERICA.COM. Any such damages may potentially include but are not solely lim=
ited to: monetary losses, deleted data without backup copies, loss of posit=
ion in search rankings, missed appointments, undeliverable email and any ot=
her technical, business or service damage that you may suffer. For more inf=
ormation please refer section 22.d.1.c of our Terms of Service.<br />
<br />
This is the final message that we are legally required to send out with reg=
ards to the expiration of THISISNOTBANKOFAMERICA.COM.<br />
<br />
SECURE ONLINE RENEWAL:<br />
=3D=3D> https://domainvlx.cc/?xid=3D81680e87662540928e7c667eeb63f5e7 <=3D=
=3D<br />
<br />
Expiry: January-2022<br />
<br />
All web services will be restored automatically on THISISNOTBANKOFAMERICA.C=
OM upon receipt of payment. We thank you for your cooperation and continued=
 business.<br />
<br />
Alert sent on 01/30/2022</body>
</html>

--_=_swift_1643545679_4f477ce554df5134b852ffd641a08a84_=_--

הדומיין הראשון, domainvlx[.]cc נרשם בדצמבר 26, 2021, הוא משתמש ב-Cloudflare.

פרטי רישום domainvlx. cc
[Querying ccwhois.verisign-grs.com]
[Redirected to whois.nicenic.net]
[Querying whois.nicenic.net]
[whois.nicenic.net]
Domain Name: domainvlx.cc
Registry Domain ID: D202112261409605-COM
Registrar WHOIS Server: whois.nicenic.net
Registrar URL: http://www.nicenic.net
Updated Date: 2021-12-26T15:48:46Z
Creation Date: 2021-12-26T15:48:46Z
Registrar Registration Expiration Date: 2022-12-26T15:47:50Z
Registrar: NICENIC INTERNATIONAL GROUP CO., LIMITED
Registrar IANA ID: 3765
Registrar Abuse Contact Email: support@nicenic.net
Registrar Abuse Contact Phone: +86.07563366365
Reseller: 
Domain Status: clientDeleteProhibited <a href="https://icann.org/epp#clientDeleteProhibited" target="_blank">https://icann.org/epp#clientDeleteProhibited</a>
Domain Status: clientTransferProhibited <a href="https://icann.org/epp#clientTransferProhibited" target="_blank">https://icann.org/epp#clientTransferProhibited</a>
Registry Registrant ID: Not Available From Registry
Registrant Organization: N/A
Registrant State/Province: California
Registrant Country: US
Registrant Email: http://whois.nicenic.net/?page=whoisform
Admin Email: http://whois.nicenic.net/?page=whoisform&emailtype=admin
Tech Email: http://whois.nicenic.net/?page=whoisform&emailtype=tech
Name Server: JOURNEY.NS.CLOUDFLARE.COM
Name Server: OLOF.NS.CLOUDFLARE.COM
DNSSEC: unsigned
URL of the ICANN WHOIS Data Problem Reporting System: http://wdprs.internic.net/
>>> Last update of WHOIS database: 2021-12-26T15:48:46Z <<<

הדומיין השני, premiumdomainregistry[.]com, שממנו הגיע המייל, נרשם בינואר 17, 2022.

פרטי רישום premiumdomainregistry. com
[Querying whois.verisign-grs.com]
[Redirected to whois.nicenic.net]
[Querying whois.nicenic.net]
[whois.nicenic.net]
Domain Name: premiumdomainregistry.com
Registry Domain ID: D202201171411025-COM
Registrar WHOIS Server: whois.nicenic.net
Registrar URL: http://www.nicenic.net
Updated Date: 2022-01-17T15:10:58Z
Creation Date: 2022-01-17T15:10:58Z
Registrar Registration Expiration Date: 2023-01-17T15:09:57Z
Registrar: NICENIC INTERNATIONAL GROUP CO., LIMITED
Registrar IANA ID: 3765
Registrar Abuse Contact Email: support@nicenic.net
Registrar Abuse Contact Phone: +86.07563366365
Reseller: 
Domain Status: clientDeleteProhibited <a href="https://icann.org/epp#clientDeleteProhibited" target="_blank">https://icann.org/epp#clientDeleteProhibited</a>
Domain Status: clientTransferProhibited <a href="https://icann.org/epp#clientTransferProhibited" target="_blank">https://icann.org/epp#clientTransferProhibited</a>
Registry Registrant ID: Not Available From Registry
Registrant Organization: Victoria Tattam
Registrant State/Province: Texas
Registrant Country: AC
Registrant Email: http://whois.nicenic.net/?page=whoisform
Admin Email: http://whois.nicenic.net/?page=whoisform&emailtype=admin
Tech Email: http://whois.nicenic.net/?page=whoisform&emailtype=tech
Name Server: NS1.PREMIUMDOMAINREGISTRY.COM
Name Server: NS2.PREMIUMDOMAINREGISTRY.COM
DNSSEC: unsigned
URL of the ICANN WHOIS Data Problem Reporting System: http://wdprs.internic.net/
>>> Last update of WHOIS database: 2022-01-17T15:10:58Z <<<

שני הדומיין נרשמו דרך רשם סיני (הונג קונג), nicenic[.]net.
המייל שנשלח הגיע מכתובת האי פי 91.217.77.52, ששייכת לספק אינטרנט רוסי.

בכדי לגשת לעמוד הסקאם\פישינג, חייבים את xid, אך הערך שלו יכול להיות כל ערך ויוצג עמוד חלקי. בכדי שיוצג העמוד עם הפרטים של המותקף, צריך גיבוב תקף, לא הצלחתי להבין איך הם מייצרים את הגיבוב, אבל נראה שמדובר ב-md5. הדומיין באמת היה שייך לי בעבר (שימש להסבר על פישינג ו-https), היה רשום ללא privacy, והפרטים שמופיעים נראה שנלקחו מה-whois. הדומיין הזה לא בשימוש כבר כמה שנים ומעניין שהם בחרו להשתמש בדומיין שלא בתוקף מאשר דומיין שכן, שאולי היה מצליח להלחיץ אותי יותר.