Wednesday, January 16, 2013

Twitter Phishing from China 2

This morning, I received a message on Twitter :

Did you see this pic of you? lol bit.ly/V66IFi ... :rajesh

Fetching links :

=======================================================
bit.ly/V66IFi >>>> http://t.co/fO2zHet
http://t.co/fO2zHet >>>> http://itwtier.com/16/verify/?&account_secure_login
=======================================================

Extracting datas :

itwtier.com is hosted on 220.164.140.246 by :
=======================================================
aut-num: AS4134
as-name: CHINA-TELECOM
descr: China Telecom
=======================================================
import: from AS6993 action pref=10; accept ANY NOT {0.0.0.0/0}
import: from AS14923 action pref=10; accept ANY NOT {0.0.0.0/0}
import: from AS3561 action pref=10; accept ANY NOT {0.0.0.0/0}
import: from AS1239 action pref=10; accept ANY NOT {0.0.0.0/0}
import: from AS2914 action pref=10; accept ANY NOT {0.0.0.0/0}
import: from AS5727 action pref=10; accept ANY NOT {0.0.0.0/0}
import: from AS6453 action pref=10; accept ANY NOT {0.0.0.0/0}
import: from AS701 action pref=10; accept ANY NOT {0.0.0.0/0}
=======================================================
export: to AS6993 announce AS-CN
export: to AS14923 announce AS-CN
export: to AS3561 announce AS-CN
export: to AS1239 announce AS-CN
export: to AS2914 announce AS-CN
export: to AS5727 announce AS-CN
export: to AS6453 announce AS-CN
export: to AS701 announce AS-CN
=======================================================
admin-c: ZX2-SAVVIS
tech-c: WW7-SAVVIS
notify: staff(at)ns.bta.net.cn
mnt-by: MAINT-AS4134
changed: wwei(at)cndata.com 20001219
source: SAVVIS
=======================================================
aut-num: AS4134
as-name: CHINANET-BACKBONE
descr: No.31,Jin-rong Street
descr: Beijing
descr: 100032
country: CN
remarks: for backbone of chinanet
admin-c: CH93-AP
tech-c: CH93-AP
mnt-by: MAINT-CHINANET
mnt-routes: MAINT-CHINANET
=======================================================
changed: shenjun(at)cndata.com 20030113
changed: hm-changed(at)apnic.net 20041221
changed: hm-changed(at)apnic.net 20060601
=======================================================
source: APNIC
=======================================================
itwtier.com whois :
=======================================================
Domain Name.......... itwtier.com
=======================================================
Creation Date........ 2013-01-08 20:58:44
Registration Date.... 2013-01-08 20:58:44
Expiry Date.......... 2014-01-08 20:58:44
=======================================================
Organisation Name.... fang yun
Organisation Address. Shang hai City
Organisation Address. Shang Hai
Organisation Address. 200000
Organisation Address. SH
Organisation Address. CN
=======================================================
Admin Name........... fang yun
Admin Address........ Shang hai City
Admin Address........ Shang Hai
Admin Address........ 200000
Admin Address........ SH
Admin Address........ CN
Admin Email.......... liangyan997@hotmail.com
Admin Phone.......... +86.2187751100
Admin Fax............ +86.2187751100
=======================================================
Tech Name............ tao li
Tech Address......... Zhengzhou
Tech Address......... Zhengzhou
Tech Address......... 450008
Tech Address......... HA
Tech Address......... CN
Tech Email........... ym@enkj.com
Tech Phone........... +86.37160135955
Tech Fax............. +86.37160123888
=======================================================
Bill Name............ tao li
Bill Address......... Zhengzhou
Bill Address......... Zhengzhou
Bill Address......... 450008
Bill Address......... HA
Bill Address......... CN
Bill Email........... ym@enkj.com
Bill Phone........... +86.37160135955
Bill Fax............. +86.37160123888
=======================================================
Name Server.......... ns13.dns.com.cn
Name Server.......... ns14.dns.com.cn
=======================================================

Social engineering is a long path...

No comments:

Post a Comment