Erik van Straten<p><span class="h-card" translate="no"><a href="https://infosec.exchange/@spamvictim" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>spamvictim</span></a></span> and <span class="h-card" translate="no"><a href="https://infosec.exchange/@briankrebs" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>briankrebs</span></a></span> : it's big tech that makes money out of this - by facilitating cybercrime.</p><p>Last week <a href="https://www.bleepingcomputer.com/news/security/fraud-network-uses-4-700-fake-shopping-sites-to-steal-credit-cards/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">bleepingcomputer.com/news/secu</span><span class="invisible">rity/fraud-network-uses-4-700-fake-shopping-sites-to-steal-credit-cards/</span></a> referred to <a href="https://blog.eclecticiq.com/inside-intelligence-center-financially-motivated-chinese-threat-actor-silkspecter-targeting-black-friday-shoppers" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">blog.eclecticiq.com/inside-int</span><span class="invisible">elligence-center-financially-motivated-chinese-threat-actor-silkspecter-targeting-black-friday-shoppers</span></a>.</p><p>After a bit of research I found that Cloudflare proxies more than 1,000 fake webshops at one IPv4 address alone, all created over the last few days (source: <a href="https://www.virustotal.com/gui/ip-address/104.18.73.116/relations" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">virustotal.com/gui/ip-address/</span><span class="invisible">104.18.73.116/relations</span></a> and <a href="https://crt.sh" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">crt.sh</span><span class="invisible"></span></a>). In this case it's Cloudflare and Shopify who make money to begin with.</p><p>Just to name a few, abusing brands and logos:</p><p>hxxps://playmobil-sale[.]shop<br>hxxps://zarahome-eu[.]com<br>hxxps://amazstore-us[.]online<br>hxxps://www.asicsshoes-eu[.]top<br>hxxps://shopping-matel[.]com<br>hxxps://snowboots-ugg[.]com<br>hxxps://ugg-usaoutlets[.]com<br>hxxps://zalandostorevip[.]shop<br>hxxps://www.oralb-eushop[.]top<br>hxxps://gaborshoes-eu[.]shop<br>hxxps://costairlines[.]com ($500 gift cards for $199)<br>hxxps://wayfairblackfriday[.]com<br>(EclecticIQ mentioned<br>wayfareblackfriday[.]com in their list of IOC's)<br>etc.</p><p>Note that there were also approx. 6 fake Lego sites, apparently they *were* taken down by Cloudflare.</p><p>The actual websites may be hosted at Google (e.g. <a href="https://www.virustotal.com/gui/ip-address/35.244.245.121/relations" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">virustotal.com/gui/ip-address/</span><span class="invisible">35.244.245.121/relations</span></a>, example: hxxps://wayshunz[.]shop - also a Waifair imitation) or Amazon. If the real sites are taken down, the crims just let Cloudflare point to another server.</p><p>Adding more TLDs indeed means that it's harder for internet users to distinguish between fake and authentic websites.</p><p>A domain name is hardly meaningful nowadays. Initially its purpose was to replace hard to remember IP-addresses, but by now many of them have become as hard to remember as strong passwords. Worse, phishing works because even if people look at domain names, more TLD's means that there are more ways to create lookalikes.</p><p>This is exactly what leads big tech to make more money. I would be surprised if it's not THEM pushing ICANN to add more TLD's.</p><p><a href="https://infosec.exchange/tags/TLDs" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>TLDs</span></a> <a href="https://infosec.exchange/tags/BigTech" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>BigTech</span></a> <a href="https://infosec.exchange/tags/CyberCrime" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CyberCrime</span></a> <a href="https://infosec.exchange/tags/InfoSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>InfoSec</span></a></p>