Categorized | Antivirus

Persistent Domain-Renewal Scam Alive and Kicking

A friend of mine forwarded a suspicious email message recently. I’ve replaced the domain, order number, etc. below:

—————————-

From: Customer Support <support@droa.com>
Subject: Order Confirmation for <domain>, Order ######

To <registered domain holder>,

Thank you for registering/renewing the following domains with the Domain Registry of America, America’s fastest growing Domain Registrar.
We take pride in offering you superior customer service and competitive pricing.

*******************************************************
Order Information
*******************************************************
<domain> renewal/transfering
The order number for <domain> is #####.

*******************************************************
Payment Information
*******************************************************
Your check ##### for $30.00 has been received.

Domain Registry of America
support@droa.com

—————————-

I validated for my friend that the email was bogus. The domain was not held by Domain Registry of America (DROA), and never had been. The domain was not expiring in the next 90 days.

Later he received a follow-up email:

—————————-

From: “Transfer Department” <transfers@namejuice.com>
Subject: RE: <domain>; Order #####
Reply-To: <support@namejuice.com>

To <domain holder>,

Thank you for choosing to transfer and renew <domain> with the Domain Registry of America.

Your transfer and renewal of <domain> is not yet complete.

Due to the changes in the .org renewal process, you will need to obtain an EPP key code from your current registrar.

This authorization key removes the need for the user to send in a fax or reply to an email to verify their transfer request. This is because these names are assigned a unique authorization key at the time of their registration. The key is created and held with your current registrar. You should be able to obtain your authorization key by contacting your current registrar.

Please contact your current registrar using the information below and request your EPP Key code.

Domain: <domain>
Current Registrar: <registrar>
Registrar Phone Number: Please visit their site to contact them

When you call provide them with your domain name (<domain>), and ask for your EPP key.

Once obtained, please click the link below to input your EPP key code and confirm your email address.

http://confirm.droa.com/getepp.asp?e=1&o=####&p=####

You must click on the link above in order to continue the transfer and renewal process.

Yours truly
Domain Registry of America
Toll free 1-866-434-0212 or for International Callers, dial +1(905)479-2533

—————————-

The scam attempts to get domain holders to transfer service and pay accordingly. It seems this scam has been around for at least eight years, though it has morphed over time. Apparently the DROA has chosen to test the 2003 judgment by the Federal Trade Commission (http://www.ftc.gov/opa/2003/12/domainreg.shtm).

One thing of interest here is the two-staged approach: The first message requires no action by the recipient, but the second message tells the user to obtain and hand over the keys to the castle.

View full post on McAfee Avert Labs

Related Posts
  • Persistent Tax Refund Scam
    A month ago, the New Zealand Department of Inland Revenue (IRD) issued a warning advising people not to respond to scam emails claiming to offer tax refunds. We have observed these types of scams bef...
  • 2 FREE Southwest Airline Tickets!
    Scam Signature Message: 2 FREE Southwest Airline Tickets!Scam Type: Click-Jacking, Bogus OfferTrending: May 2011Why it's a Scam:Clicking the wall post link takes you to the  f...
  • Father walks in on his Daughter… EMBARRASIN!
    Scam Signature Message: Father walks in on his Daughter... EMBARRASIN!Scam Type: Survey Scam, Click-JackingTrending: May 2011Why it's a Scam:Clicking the wall post link takes you t...
  • Royal Wedding or Royal hunt
    Instantly this news became? very fruitful? for all kinds of cybercriminals. Here is? some of the proof we found:1) SEO optimized Google image searches leading to a malicious site with the exploit for ...
  • The Ultimate Profile Viewer is now being released! Shocking for real! See who visits your profile real time!
    Scam Signature Message: The Ultimate Profile Viewer is now being released! Shocking for real! See who visits your profile real time! See who invisible you on their friend list chat! Check it now ...
  • The BLOODIEST Fight EVER – BANNED FROM TV!
    Scam Signature Message: The BLOODIEST Fight EVER - BANNED FROM TV!Scam Type: Survey Scam Trending: April 2011Why it's a Scam:Clicking the wall post link takes you to the ...
  • Malware spammed out as “FaceFacebook Support”.
    Another Facebook spam mail pretending that your password is not safe, currently circulating on Internet. The subject is: FaceFacebook Support. Personal data has been changed!ID55733. The email comes w...
  • 500 free credits from Facebook – malware
    There's no such thing as a free lunch - or free Facebook credits.  As proof consider the attack described below which has several stages:1)      Users get messages with o...
  • 419 Scammers Still Open to ‘Traditional Postal Services’ Option
    Communication in the today's world is dominated by email, instant messaging, and social networking. However, for making any formal statement or announcement, hard-copy letters are still sent using pos...
  • ygnetwork-ltd.com domain scam
    This scam has been around for years - basically, you get an unsolicited email from a company claiming to be a domain registrar in China (it is usually China) that says that someone is trying to regist...

One Response to “Persistent Domain-Renewal Scam Alive and Kicking”

  1. name says:

    Huh, I have actually received this as snail mail from the same company. Sure it’s a scam, but it feels like 50% of everything is. I even get mail from a very well known auto insurance company, with PAYMENT NOTICE ENCLOSED printed on the envelope, even though I’m not insured by them. It’s the company with the gecko mascot

Trackbacks/Pingbacks


Security Status

Beware Facebook "Timeline" scams http://t.co/W5EW0cVv
5 months ago
Nigerian government (unknowingly) hosts phishing website http://t.co/uQd42ENw
5 months ago
PCMag Awards McAfee All Access its Editors’ Choice: SANTA CLARA, Calif.--(BUSINESS WIRE)--McAfee today announced... http://t.co/FakV7Vd8
5 months ago
RT @mikko: I hadn't noticed Google Maps has added 3D models of buildings. Here's a (very accurate) view of F-Secure HQ in Helsinki http://t.co/IKfAZlak
5 months ago
North Koreans aren't known for their online presence. But others may be lured into clicking Kim Jong-Il 'videos' too http://t.co/yQOon6YT
5 months ago
How to Protect Your Professional Reputation on Facebook Timeline http://t.co/I4bcR2VN
5 months ago
This is pretty impressive from @Softpedia: Facebook scans 2 trillion link clicks and blocks 220 million posts each day http://t.co/vKsn9gNl
5 months ago
Need for integrated approach to security in industrial control systems - http://t.co/tPBCNOow with @PikeResearch
5 months ago
Some free-based music we play at work http://t.co/xu5agZfc
5 months ago
Japan’s cyber defense weapon: a virus. It includes quotes by @Luis_Corrons via @InfosecurityMag
5 months ago