<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>InfoSec on Micah Bird's Site</title><link>https://www.micahbird.com/categories/infosec/</link><description>Recent content in InfoSec on Micah Bird's Site</description><generator>Hugo -- gohugo.io</generator><language>en</language><lastBuildDate>Thu, 09 Apr 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://www.micahbird.com/categories/infosec/index.xml" rel="self" type="application/rss+xml"/><item><title>A Novel Kind of Domain Scam</title><link>https://www.micahbird.com/p/a-novel-kind-of-domain-scam/</link><pubDate>Thu, 09 Apr 2026 00:00:00 +0000</pubDate><guid>https://www.micahbird.com/p/a-novel-kind-of-domain-scam/</guid><description>&lt;img src="https://www.micahbird.com/p/a-novel-kind-of-domain-scam/cover.jpg" alt="Featured image of post A Novel Kind of Domain Scam" />&lt;h2 id="the-scam">The Scam
&lt;/h2>&lt;p>Today out of the blue I was contacted by a business that I made a website for ages ago. They simply sent a picture of the following letter they received in the mail and asked if they should do anything about it. Here is that picture:&lt;/p>
&lt;p>&lt;img src="https://www.micahbird.com/p/a-novel-kind-of-domain-scam/scam-letter.jpg"
width="1200"
height="1328"
srcset="https://www.micahbird.com/p/a-novel-kind-of-domain-scam/scam-letter_hufe00fafe528ed67412b6dda8beacbd46_221606_480x0_resize_q75_box.jpg 480w, https://www.micahbird.com/p/a-novel-kind-of-domain-scam/scam-letter_hufe00fafe528ed67412b6dda8beacbd46_221606_1024x0_resize_q75_box.jpg 1024w"
loading="lazy"
alt="The Letter"
class="gallery-image"
data-flex-grow="90"
data-flex-basis="216px"
>&lt;/p>
&lt;p>It looks like some &amp;ldquo;professional&amp;rdquo; bill, but something is off. What the heck is the domain &lt;code>marston-holdings.com&lt;/code> and why would they want $288 for it?! Well, when going to that site, it displays the homepage for the business who received this letter. Also, the letter is from &amp;ldquo;Domain Listings&amp;rdquo; how could it not be legit??&lt;/p>
&lt;p>&lt;img src="https://www.micahbird.com/p/a-novel-kind-of-domain-scam/urlbar.png"
width="1176"
height="146"
srcset="https://www.micahbird.com/p/a-novel-kind-of-domain-scam/urlbar_huc97f349067df35a1a6ea91065d5ad381_49085_480x0_resize_box_3.png 480w, https://www.micahbird.com/p/a-novel-kind-of-domain-scam/urlbar_huc97f349067df35a1a6ea91065d5ad381_49085_1024x0_resize_box_3.png 1024w"
loading="lazy"
alt="The Scam Site"
class="gallery-image"
data-flex-grow="805"
data-flex-basis="1933px"
>&lt;/p>
&lt;p>Well, this is going to come as a real shocker, but this is a phishing scam. This business has nothing to do with that domain, let alone hosting a clone of their homepage!&lt;/p>
&lt;p>From the outside, this is how I believe the scam works:&lt;/p>
&lt;ol>
&lt;li>Get a cheap domain.&lt;/li>
&lt;li>Host a mirror of a website through that domain.&lt;/li>
&lt;li>Send out scary letters that could be plausible that you need to pay for it.&lt;/li>
&lt;/ol>
&lt;p>It is a clever scam I must admit, but incredibly poor execution. No doubt it would have tricked the employees in this business as admittedly they are the older, and in non-technical crowd. I am incredibly thankful that they reached out to me before doing anything about it. Now, it&amp;rsquo;s my turn.&lt;/p>
&lt;h2 id="lets-get-it">Let&amp;rsquo;s Get It
&lt;/h2>&lt;p>First, I started with an obligatory whois lookup:&lt;/p>
&lt;p>&lt;img src="https://www.micahbird.com/p/a-novel-kind-of-domain-scam/whois-lookup.png"
width="1598"
height="1370"
srcset="https://www.micahbird.com/p/a-novel-kind-of-domain-scam/whois-lookup_hu411f48d09314bab0f6df2617ebf33f91_326147_480x0_resize_box_3.png 480w, https://www.micahbird.com/p/a-novel-kind-of-domain-scam/whois-lookup_hu411f48d09314bab0f6df2617ebf33f91_326147_1024x0_resize_box_3.png 1024w"
loading="lazy"
alt="Whois Lookup"
class="gallery-image"
data-flex-grow="116"
data-flex-basis="279px"
>&lt;/p>
&lt;p>Which, unfortunately, does not tell much, besides it being registered through GoDaddy&amp;hellip; More on them later.&lt;/p>
&lt;p>Onto a &lt;code>dig&lt;/code> to see what&amp;rsquo;s under the hood.&lt;/p>
&lt;div class="highlight">&lt;div class="chroma">
&lt;table class="lntable">&lt;tr>&lt;td class="lntd">
&lt;pre tabindex="0" class="chroma">&lt;code>&lt;span class="lnt"> 1
&lt;/span>&lt;span class="lnt"> 2
&lt;/span>&lt;span class="lnt"> 3
&lt;/span>&lt;span class="lnt"> 4
&lt;/span>&lt;span class="lnt"> 5
&lt;/span>&lt;span class="lnt"> 6
&lt;/span>&lt;span class="lnt"> 7
&lt;/span>&lt;span class="lnt"> 8
&lt;/span>&lt;span class="lnt"> 9
&lt;/span>&lt;span class="lnt">10
&lt;/span>&lt;span class="lnt">11
&lt;/span>&lt;span class="lnt">12
&lt;/span>&lt;span class="lnt">13
&lt;/span>&lt;span class="lnt">14
&lt;/span>&lt;span class="lnt">15
&lt;/span>&lt;span class="lnt">16
&lt;/span>&lt;span class="lnt">17
&lt;/span>&lt;span class="lnt">18
&lt;/span>&lt;span class="lnt">19
&lt;/span>&lt;span class="lnt">20
&lt;/span>&lt;/code>&lt;/pre>&lt;/td>
&lt;td class="lntd">
&lt;pre tabindex="0" class="chroma">&lt;code class="language-fallback" data-lang="fallback">&lt;span class="line">&lt;span class="cl">$ dig marston-holdings.com
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">; &amp;lt;&amp;lt;&amp;gt;&amp;gt; DiG 9.10.6 &amp;lt;&amp;lt;&amp;gt;&amp;gt; marston-holdings.com
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">;; global options: +cmd
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">;; Got answer:
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">;; -&amp;gt;&amp;gt;HEADER&amp;lt;&amp;lt;- opcode: QUERY, status: NOERROR, id: 18973
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">;; OPT PSEUDOSECTION:
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">; EDNS: version: 0, flags:; udp: 1220
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">;; QUESTION SECTION:
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">;marston-holdings.com. IN A
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">;; ANSWER SECTION:
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">marston-holdings.com. 600 IN A 160.153.78.39
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">;; Query time: 55 msec
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">;; SERVER: 172.16.0.1#53(172.16.0.1)
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">;; WHEN: Thu Apr 09 17:56:58 MDT 2026
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">;; MSG SIZE rcvd: 65
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/td>&lt;/tr>&lt;/table>
&lt;/div>
&lt;/div>&lt;p>Wow, a single IP? How brave.&lt;/p>
&lt;p>Taking that IP to good ol&amp;rsquo; &lt;a class="link" href="https://www.shodan.io" target="_blank" rel="noopener"
>shodan&lt;/a> is pretty revealing.&lt;/p>
&lt;p>&lt;img src="https://www.micahbird.com/p/a-novel-kind-of-domain-scam/shodan-lookup.png"
width="1259"
height="1262"
srcset="https://www.micahbird.com/p/a-novel-kind-of-domain-scam/shodan-lookup_huc147646ddc2119c2a5345158861f3101_494122_480x0_resize_box_3.png 480w, https://www.micahbird.com/p/a-novel-kind-of-domain-scam/shodan-lookup_huc147646ddc2119c2a5345158861f3101_494122_1024x0_resize_box_3.png 1024w"
loading="lazy"
alt="Shodan Results"
class="gallery-image"
data-flex-grow="99"
data-flex-basis="239px"
>&lt;/p>
&lt;p>Quite a few vulnerabilities, and a fair amount of open ports too. Seems to be associated with a few other suspect domains, such as &lt;code>forthedocs.com&lt;/code>. Which reminds me, the scam site did not even have HTTPs certs! &lt;em>For shame&amp;hellip;&lt;/em> But that got me wondering, how long has this site been cloned?&lt;/p>
&lt;p>&lt;img src="https://www.micahbird.com/p/a-novel-kind-of-domain-scam/internet-archive-lookup.png"
width="2986"
height="132"
srcset="https://www.micahbird.com/p/a-novel-kind-of-domain-scam/internet-archive-lookup_hud2e19c035e6689c78bdda612eaae1ee9_155771_480x0_resize_box_3.png 480w, https://www.micahbird.com/p/a-novel-kind-of-domain-scam/internet-archive-lookup_hud2e19c035e6689c78bdda612eaae1ee9_155771_1024x0_resize_box_3.png 1024w"
loading="lazy"
alt="Internet Archive Lookup"
class="gallery-image"
data-flex-grow="2262"
data-flex-basis="5429px"
>&lt;/p>
&lt;p>Huh, that&amp;rsquo;s odd. The website was at least cloned starting in July 2025, and the business who is being impersonated did not receive a letter until today. Not sure if this was premeditated or if the scammers are just lazy.&lt;/p>
&lt;h2 id="the-end">The End..?
&lt;/h2>&lt;p>For now, I have contacted GoDaddy support to get the impostor site taken down, but I have yet to hear back. I will update this post with new developments as they happen.&lt;/p></description></item></channel></rss>