How to verify whether a website is legitimate or not?:

sábado, 3 de febrero de 2018

How to uncover a massive campaign of counterfeit-related websites with just an e-mail address

Disclaimer: Thanks to my side project I reached out an agreement with DomainTools to use their commercial tools to research news ways about how to leverage them to gather additional intel around the online counterfeiting fraud. This is an example of a small research with the outcome of a massive campaign of counterfeit-related websites. A more formal article can be found on the DomainTools blog.

In the context of online counterfeiting, there are four classes of domain that warrant discussion:
  • Counterfeiters registered domains
  • Free hosting based
  • Legitimate but compromised
  • Expired domains
In order to know more about each type you can take a look to the SANS paper "Tracking online counterfeiters".  For the purpose of this article I will focus on the first type but just to find later a massive campaign of counterfeit websites of different types.

A counterfeit registered domain might be as in example: (active while writing this article)

Figure 1: Counterfeit-related website

This involves the online counterfeiters using any provider to register the domain in the conventional sense. Unfortunately Whois data can be spoofed yet. In fact, if the counterfeiter was never going to need to manage the domain again, he could use a false e-mail address. This scenario mostly works for the bad-guys registering C2 domains, but usually is not the case for counterfeit-related websites, as in the above case:

Figure 2: Legitimate mail address used to register the counterfeit-related website

Other considerations are that registration services often sell privacy/protected registration as a service. In those cases, only the privacy service and registrar have the information provided by the registrant that registers a domain on behalf of someone else and then transfers it to them shortly thereafter. In those cases (also mostly seen on C2 domain registrations) the initial registration would be the intermediary, and then registrant data may be updated later to reflect the actual domain owner. Something you can easily set up as an alert in Domaintools to keep track of, as in the example below of a counterfeit-related website handing over the domain´s ownership:

Figure 3: Registar domains extracted with

With the side project: I usually keep track how counterfeit-related websites are maturing. Inmersed in these tasks I was investigating the domain: cause despite of showing up all signs of a counterfeit-related one, the online tool was not able to analyze it due to some kind of block countermeasures on the counterfeit domain server side.

Figure 4: Register domains extracted with

The same behavior was showed by the domain: this case the domain was manifestly a copy-cat of Adidas but in Danish language.

Figure 5: Register domains extracted with

Based on the Whois public data observed I started to suspect; the name server of both domains is the same, they also have been recently created and the email registration seems random but under the same domain (a China based company).

Both pictures figure 3 and figure 4 were extracted with the free Domain tools whois lookup tool. In the other hand, Iris is a tool to give you additional insights while investigating any kind of online fraud. In this case, by using Iris in order to investigate further these 2 domains, I just found a massive and fresh campaign of around 50.000 counterfeit-related websites !! and all in less than 5 minutes.

Lets see the step by step process:

1. With valid DomainTools credentials we access to the Irish service:

Figure 6: Iris main website

2. We type the IOC we would like to investigate further, in this case:

  Figure 7: Web domain being investigated with the Iris tool

3. In the email section we see the same email addresses as devised in the public whois lookup tool plus two additional mail addresses. Right click in any of these fields and we can see the number of additional domains registered under them. When pivoting over the random mail address based on domain it show the text: "no other domains share this value" but when we pivot over the mail address [email protected] as seen in the figure 8:

  Figure 8: Pivoting over an Indicator ( web mail address )

4. We see 53.361 domains share this value. Lets check them out. In order to do it we click over "Narrow Search" and in the top menu we will see a new tag with this field as show below in the figure 9:

  Figure 9: Multitag search (web domain and web mail address)

5. Now we remove the domain tag in order to extract all the information related "only" to this email address and then we noticed the surprise:

  Figure 10: Iris search with a key indicator ( web mail address )

53.679 fresh counterfeit-related domains found !! a quick random verification show us that all are related to counterfeit-related websites targeting a huge amount of brands under domains which belong to many different TLDs specially: .com, .de and .top

Lets take a look to some of them as examples under the different TLDs.

Counterfeit-related website targeting to the New Balance brand:

  Figure 11: Counterfeit related website

Multibrand counterfeit-related website: 

                                                                    Figure 12: Counterfeit related website

Multibrand Counterfeit-related website:

                                                                    Figure 13: Counterfeit related website

Counterfeit-related website targeting to the Reebok brand:

                                                                    Figure 14: Counterfeit related website

Multibrand Counterfeit-related website (car parts, toys, electronics...):

                                                                    Figure 15: Counterfeit related website

Multibrand counterfeit-related website:

                                                                    Figure 16: Counterfeit related website

Multibrand counterfeit-related website:

                                                                    Figure 17: Counterfeit related website

"All the information collected here as been sent along to the Europol as part of the IOS program to fight the trade of counterfeit products online."

Update: After some days, the Indicator [email protected] keeps registering new counterfeit-related domains as while I am writing this update (some days later after writing the original article) the number of domains related to this counterfeit actor is: 55.048. That is 1369 new counterfeit-related domains registered within a few days by the same actor.

4 comentarios:

  1. Пользователь имеет возможность приобрести товар, нажав на поле. Закажите вантуслим В гамбурге для участия в акции со скидкой! До и в конце приема onetwoslim в гамбурге Включая обсуждения с отзовикой и irecommend: Аня, работник сельского хозяйства, 38 лет вантуслим, кажется, самое оптимальное лекарство для похудения, которое можно приобрести в нашей стране! Я говорю по опыту, я пробовал то-то и то-то, а также только сейчас получил эффект. Мой муж в шоке! Лично я боялась того, что значит развод, но в конце концов похудела на 6 килограммов. Если бы вы не были onetwoslim в гамбурге, а бетон обладает магическим действием, лишние килограммы мучили бы меня всю оставшуюся жизнь. Галина, турагент, 27 лет я сбросила десять килограммов лишних килограммов с помощью вантуслима. Том целый месяц пил капли перед тем, как лечь спать. Таисия, диджей, 28 лет пережила такой ужас, которого вы никогда не пожелаете. Оставаясь в той позе, которая мне нравилась, я растолстел на 19 килограммов жира. Сбить их с толку так и не получилось. Конец страданиям пришел, когда моя сестра посоветовала мне купить onetwoslim в гамбурге. Десять дней, и стрелка весов показала результат. Теперь я чувствую себя комфортно и стройной, а капли van tu slim - мой главный помощник.

  2. Please , enter your search term. Man pleads guilty to posting child pornography Author: anna peters Published: 16 may 2023 / 11:36 cdt Updated: may 16, 2023 / 12:03 cdt Sioux falls, s.D. (Kelo) - man from mitchell admits to having child pornography. Justin brende appeared in federal court this morning and pleaded guilty. He is due to be sentenced several weeks and he will have at least several years of imprisonment in federal prison. Legal rights reserved. This material may not be published, broadcast, rewritten or distributed. How to select and acquire budget ideas and make air travel affordable despite… Scatter Best long lasting makeup for a spring/summer wedding… If you pick the right cosmetics, you have a great chance to expect the fact that the provided makeup will stay at home for the full event . Is there any hype around the new hoka sneakers? Hoka is back with its own ultra-soft sneakers. Learn more about his 2023 releases. And why everyone talks about them so much. If there are various concerns in the apartment about where and whether it is possible to use ai porn reviews - - , you can contact us on our internal web page.

  3. 51 hot pics of camren bicondova that will make you sweat The american actress who is mostly known for her role as young kyle/catwoman in the fox television series, gotham and prissy in the dance movie battleground america is none other than camren bicondova. She was born on may 22, 1999 in san diego, california, usa. Her parents are jessie bikondova and joshua bokondova. At the age of six, she took dance lessons. Moved to hawaii. 1xbet also took jazz-funk and hip-hop dance classes at a local studio. By the age of eleven, she has become a member of the elite portage dance convention pulse on tour. 1. She started her acting career 7 years ago with the television series shake it up as a little highlighter. In the future seeding season, she accepted the appearance in the seventh season of america's best dance crew with her own female dance group called 8 flavahz and took the 2nd podium. 2. She became famous for her role as selina kyle in the tv series gotham, to which she was attached from 2014 to 2019. She made her big screen and surround sound debut in the twelfth g dance film battlefield america as prissy. In 2014, she got the role of girl 1 on the screen "house for girls". 1xbet has also starred in a number of music videos including underneath, got me good, use the ride, etc. 3. It also supports several non-commercial organizations. And charitable causes including global citizen festival, uso, north shore animal league america, noh8 campaign and others. Although she is far from having any awards, she was nominated for a saturn award three years ago. 4. Now that we have given enough information about kamren bikondova, it's time to move on to the next virtual segment, which you have been waiting so patiently for so far! Yes! It's time to dive in and become a witness to the youth and behavior of this elegant glamorous babe in her many positions and positions in this carefully curated collection of camren bicondova's plethora of hot photographs, purposefully for her own clients - and people. 5. We hope that fans will be delighted to see and admire these sexy pictures of camren bicondova, which they will definitely love and enjoy! Each of her shots is a dedication to her undeniably unsurpassed beauty and one can be found in camren bicondova's insurance priceless collection of boobs images. 6. appreciate the type of this diva, after as you admire her lusciously smooth and stunning ass pictures of camren bicondova and pictures of camren bicondova's ass. Most of these photos include images of camren bikondova in a bikini from camren bikondova's sexiest instagram photos, showing her wild direction and superb curves! Without further ado, let's get started! If you have all sorts of thoughts about where and how to use hairy pussy polaroids - - , you will get a great chance to chat with our company on this own webpage.

  4. Artificial intelligence porn? We have been talking about this for some time and energy, but no one expected that the current ai technologies would grow too easily in this short time of the year we carried out this operation, because we are fans of the film "the matrix". In spite of everything, artificial intelligence has rapidly appeared in its sector and building materials find areas of operation in absolutely every conceivable industry ... Including porn. Through these resources that our confectioners have chosen, you get the right to use this new technology for free or in a deluxe version. These artificial intelligences allow the player to virtually generate every body part of a life purpose model by providing the ai with simple porn tags, stripping a character in a photo, creating simple fake porn videos with artificial intelligence, or putting whatever face you want into the picture, for example. An already existing video. In our opinion, it is one of the recommended artificial intelligence pornographic image generators currently available. With pornpen, you can finally build the woman of your dreams. Thanks to deep swap and its sophisticated ai face swap tool, you can organize your own memes, pictures, content and gif videos instantly and easily. Looking for a good man-made intelligence pornographic image generator? You are at the address you need! Visit soulgen.Net, take their free trial and check out hot cartoon movies and realistic looking babes for your personal fap folder. With artificial intelligence. Its sophisticated tool allows you to create amateur stories with artificial intelligence, so all your dreams will come true! Picso is a great ai text generator. Its main function is to help visitors to create the woman they dreamed of, in any construction, an anime babe or a girl from reality. Comes with a ton of options. With his secrets, you can finally see the baby of long-term perspective. Do you want to see your hot secretary naked? Or maybe your dear neighbor? Now you will finally be able to watch series and movies from not too much help deep nude now! Deepnude is a state of the art artificial intelligence image generator that will enable you to see every girl naked. With this app, you don't have to rely on your imagination anymore. Visit a hot virtual girl in the 21st century and start a conversation with sammy, a seductive and horny ai bot that can't wait to chat with chat visitors about current passions and sex desires. Pornjourney.Ai is an advanced pornographic image generator that you can use for free or resort to its premium version that can provide you access to some auxiliary functions. Join pornjoy.Ai and start creating your new lady friends and animated babe movies. By carefully examining him, we are able to conclude that he is one of the best ai porn generators. If you are ready to order to create fake nudes from various films and pictures that you need, recommended dreamtime, a sophisticated application that allows you to create deep fakes for free. If you are more comfortable using an uncomplicated and intelligible artificial intelligence pornographic image generator, consider looking at sexy.Ai. With the zodiac easy-to-use tool, you have the ability to provide a lot of hot ai chicks. Nolo is one of the rudimentary and proven virtual ai porno image generators. With the zodiac modern tool, you get the opportunity to easily create the woman you dreamed of or the young lady from the anime.


Trata a los demás como te gustaría ser tratado.