Archive for August, 2010

Aug 11 2010

CDT: ISP Level Gmail Phishing

Published by under Censorship,China internet

Via @torproject comes a link to a China Digital TImes (a site run at Berkeley) that gives just a brief notice that some users behind the GFW are having their gmail login attempts redirected to hxxp://124.117.227.201/web/gmail/ where they are asked to enter their password. Chinese users reporting this redirect believe that the redirects are being performed by the ISP. Interestingly, 124.117.227.201 is a CNC host in Xinjiang.

At the time of this post the hxxp://124.117.227.201/web/gmail/ site is not operating (from the US or the PRC according to webpulse).

The original info apparently came from ntdtv:
中国ISP騙取gmail密码 被現場抓獲

https://www.ntdtv.com/xtr/b5/2010/08/11/a417907_p.html

https://www.ntdtv.com/xtr/b5/2010/08/11/a417907_p.html

UPDATE: I was looking closely at the screen cap that shows the source and it appears that part of the phishing app is hosted on ndns01.com, which doesn’t presently have an IP address assigned although the DNS record was updated on August 10.

Comments Off