Confusing .au.com domain threatens Aussie users

A US-based anti-spyware company has registered the ".com.au.com" domain name, which experts fear could be used by cybercriminals to create more convincing phishing attacks.

The download page resembles an Internet Explorer error, and claims "Your computer system may have been compromised by dangerous spyware and/or adware infections.

For example, typing www.google.com.au.com or www.commbank.com.au.com, will redirect to an anti-spyware download page -- as will all other URLs that finish ".com.au.com" or ".org.au.com".

Users who accidentally add .com at the end of an Australian domain will also be redirected to the fake anti-spyware site.

Bradley Anstis, vice president of security firm Marshal, was concerned about the development.

"This one is pretty worrying really; I think it sends a very strong message to domain registrars, how they can allow a top level domain to be registered as a secondary level domain is clearly beyond me."

Currently, it seems the owner of the domain is redirecting all traffic to the fake spyware page but Anstis claims that more specific attacks are possible.

"If you're getting people to fall for this, and I suspect people will, the world is your oyster really," Anstis said.

Anstis warned that the domain could be particularly dangerous if used to mimic financial Web sites: "You could easily put an [fake] ANZ Web site that looks exactly like the original one. I think the big concern with this is it is quite difficult to spot."

The au.com domain is owned by Australian domain name reseller and hosting provider NetRegistry. In an interview with ITRadio's Risky Business podcast, the CEO of NetRegistry, Larry Bloch, argued that registrants should be able to use domains as they liked unless they were breaking the law.

"In the absence of any overriding concern, for example illegal activity or activity that's clearly not satisfying community norms -- and this may be an example of that -- we'll literally let registrants carry on as they see fit," said Bloch.

However, Chris Disspain, CEO of the Australian Domain Name Administrator (auDA), said in this case there may be a legal precedent for taking action.

"I am investigating this, whether this is either a breach of either, the register agreement or the code of practice. The fact that it is not in .au does not necessarily mean that it is outside the register agreement or the code of practice," he said.

Disspain referred to an Australian Federal Court case from June 2004, which put such sites within the auDA's reach. He said, "We could have a go at sites outside [.au domain] if they, to use a football phase, 'brought the game into disrepute'."

Security firm F-Secure analysed the "anti-spyware" program found at the site and confirmed it to be fake. F-Secure's Patrik Runald said, "when you scan your PC it will always find something to complain about ... to clean anything you need to register your e-mail address and then it asks you for your credit card," he said.

A screenshot of the downloaded program courtesy of F-Secure.

Chris Gatford, from penetration testing firm Pure Hacking, said even if people do not fall for the fake anti-spyware application, the misleading domain name is likely to be generating revenue for its owner through a pay-per-click scheme.

Gatford explains that although the site downloads via the domain anti-spyware.com, " before that, it goes through three or four redirections, and some of these are using what is called 'click bank', which is basically counting the clicks that adware-free.com is sending through to anti-spyware.com".

Talkback

Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

Terms of Service - As a ZDNet registrant, and by using this service, you indicate that you agree to our Terms and Conditions and have read and understand our Privacy Policy.

ZDNet Australia Live

Global mobile phone sales take a hit; Nokia yields to Apple, Samsung http://t.co/95pDxClp

29 minutes ago by Fedaupdat on Reservoir blogs: Fan fakes Tarantino diary

Global mobile phone sales take a hit; Nokia yields to Apple, Samsung - ZDNet (blog): Global mobile phone sales t... http://t.co/GtLqWFz1

ABC's Bitcoin miner tackled in minutes: The Australian Broadcasting Corporation (ABC) looked set to become a hav... http://t.co/qq5oPZ15

ABC's Bitcoin miner tackled in minutes: The Australian Broadcasting Corporation (ABC) looked set to become a hav... http://t.co/7v06Ygfl

ABC's Bitcoin miner tackled in minutes: The Australian Broadcasting Corporation (ABC) looked set to become a hav... http://t.co/z7ngF4XL

Admits? Don't fall for their marketing. Vista was beautiful. Microsoft has a history of trashing their older OSes.

1 hour ago by anonymuos on Microsoft admits Vista was 'cheesy'

Oracle v. Google loses another juror: By Rachel King, ZDNet US on May 21st, 2012 (7 hours ago) Rather than 12 An... http://t.co/nflnWgb9

RT @MSDynamicsCRM: Great article on ZDNet - Microsoft #Dynamics #CRM saves email-drowned Australian Power and Gas http://t.co/LKjZzQcR #msdyncrm #crm2011 ^pb

Gotta agree. For our Burnie, Tas. internet, we have a 1.5MB download speed adls connection through exetel using testra copper line. ADS...

1 hour ago by brozza on Broadband Speedtest

Vic councils tender for VMware partner http://t.co/diHsmLt6

Govt set for electorate office IT refresh: The Department of Parliamentary Services (DPS) is waiting for existin... http://t.co/FYaojbCN

RT @zdnetaustralia: In this week's Patch Monday we look at the themes of last week's AusCERT security conference. http://t.co/XMRm8n9k ^ST

Facebook tracking you after you logout, isn't that against the law? To stop this, go to the settings / options /... http://t.co/6Gzl4Eht

Vic councils tender for VMware partner - ZDNet Australia http://t.co/3XreTY9E

RT @zdnetaustralia: In this week's Patch Monday we look at the themes of last week's AusCERT security conference. http://t.co/XMRm8n9k ^ST

RT @zdnetaustralia: In this week's Patch Monday we look at the themes of last week's AusCERT security conference. http://t.co/XMRm8n9k ^ST

RT @zdnetaustralia: In this week's Patch Monday we look at the themes of last week's AusCERT security conference. http://t.co/XMRm8n9k ^ST

Vic councils tender for VMware partner: in brief A 58-strong consortium of Victorian regional coun... http://t.co/nEA6Gs8G #VMware #News

RT: New "Patch Monday" podcast: "War talk dominates #AusCERT 2012" http://t.co/utUIf5Mw

RT @zdnetaustralia: 58 Victorian councils looking for new VMware partner: http://t.co/HqOuEOK9 ^LH

RT @JamesVickery: Microsoft launches its own social service http://t.co/xthGjXI5

ZDNet App Wrap: 21 May 2012 http://t.co/rQ6ZoKAc

ABC's Bitcoin miner tackled in minutes http://t.co/Ue6A5qnp

by http://t.co/vmlQ0Ecb: Govt set for electorate office IT refresh: The Department of Parliamentary Services (DPS... http://t.co/25budC2T

RT @zdnetaustralia: In this week's Patch Monday we look at the themes of last week's AusCERT security conference. http://t.co/XMRm8n9k ^ST

National Botnet Network coming: Earthwave http://t.co/ChqUVcgs #ddos

ABC's Bitcoin miner tackled in minutes http://t.co/hF0MzDsE

Govt set for electorate office IT refresh: The Department of Parliamentary Services (DPS) is waiting for existin... http://t.co/AOzluavp

MPs won't get Wi-Fi in their electorate offices paid by Parliamentary Services until the current contracts run out. http://t.co/EcoNgTnR

ABC's Bitcoin miner tackled in minutes - ZDNet Australia: Sydney Morning HeraldABC's Bitcoin miner tackled in mi... http://t.co/tKnRlZdW

58 Victorian councils looking for new VMware partner: http://t.co/HqOuEOK9 ^LH

ABC's Bitcoin miner tackled in minutes - ZDNet Australia http://t.co/aGMcf6W0

ABC's Bitcoin miner tackled in minutes - ZDNet Australia http://t.co/7vC8E0b9

RT @Daily_Donkey: National Botnet Network coming: Earthwave - ZDNet Australia http://t.co/keLouVk8 #cyberwar

ABC's Bitcoin miner tackled in minutes - ZDNet Australia http://t.co/Zi6QUkuQ #australia #technews

ABC's Bitcoin miner tackled in minutes http://t.co/AsQxlLV0

RT @joshgnosis: The ABC caught the employee who was trying to mine Bitcoins last year in a matter of minutes. http://t.co/uEl4Y1YW

Well the message certainly is clear. Never do anything because something might happen. Seriously it seems to me "Earthwave" just want to...

3 hours ago by Hubert Cumberdale on National Botnet Network coming: Earthwave

you really think it's going to be such a grim future? looking at South Korea, Japan, even Czech Republic - I haven't seen either emit mo...

5 hours ago by romant on National Botnet Network coming: Earthwave

No... they'll just blame the NBN for that too ;-)

5 hours ago by Beta on National Botnet Network coming: Earthwave

It seems that some of the people who set up ACCAN (not staff members) took the view that it would somehow be against their view of 'consu...

6 hours ago by socrates on ACCAN gets govt tick amid industry criticism

Don't laugh, Mr Turnbull is dumb enough to try and use this against the NBN. I'm sure the noallitions magical FTTN will be impervious to ...

6 hours ago by Jingles on National Botnet Network coming: Earthwave

OMG, the sky will fall if we get NBN - it must be cancelled immediately! Sorry; was just channelling Malcolm Turnbull there for a moment...

6 hours ago by socrates on National Botnet Network coming: Earthwave

Thats just stupid.. what else is the NBN going to get blamed for? People die crossing the road, are you going to ban cars or police it b...

7 hours ago by fibretech on National Botnet Network coming: Earthwave

And again - missed this bit did you? "... Telstra is responsible for estates where development approval was granted before 1 January 201...

7 hours ago by Beta on Copper greenfield dominance irrelevant: Conroy

I think the idea of dropping aero glass bit of a mistake. At least have some colour. Thats something i liked (especially after working on...

7 hours ago by JCOZ on Microsoft admits Vista was 'cheesy'

Yes, most people hate the processes put in place to ensure purchasing is fair, transparent and above board. Having been a purchasing off...

8 hours ago by ozguy2000 on Woolies case poses procurement questions

God,..why spend another $6.7M on a system that's never going to be any good & never work in all probability!.. \ Government bureaucrats ...

9 hours ago by Keith Styles on Vic scraps HealthSMART system

The gorilla in the room is Information Privacy Principles. I'm not so sure that providing arbitrarily developed acceptable usage policie...

10 hours ago by Rowan Williams on How government does BYOD

NBNCo requires ALL greenfield areas must be connected to the NBN but they are only company in Australia allowed to install the fibre yet ...

22 hours ago by zag on Copper greenfield dominance irrelevant: Conroy

The funny thing is the NBNCo demands that ALL greenfield areas must be connected to the NBN, but due to conroy always demanding for no ot...

22 hours ago by zag on Copper greenfield dominance irrelevant: Conroy

Looks like The GPT Group are having similar woes, I'm off to see their CIO speak at AIPM this week, and the topic is .... You guessed a f...

1 day ago by SarahMc on NSW govt in SAP project blowout

I think, therefore I am. I am what? A machine. Damn!!

1 day ago by Patanjali on AusCERT 2012 pics: Vaders and Terminators

As a contractor, I have generally not been entitled to the smaller portable devices, like a phone, though I have had client laptops at ti...

1 day ago by Patanjali on How government does BYOD

Facebook Activity

Keep up with ZDNet Australia

ZDNet Events Calendar

ZDNet Events Calendar