Confusing .au.com domain threatens Aussie users

A US-based anti-spyware company has registered the ".com.au.com" domain name, which experts fear could be used by cybercriminals to create more convincing phishing attacks.

The download page resembles an Internet Explorer error, and claims "Your computer system may have been compromised by dangerous spyware and/or adware infections.

For example, typing www.google.com.au.com or www.commbank.com.au.com, will redirect to an anti-spyware download page -- as will all other URLs that finish ".com.au.com" or ".org.au.com".

Users who accidentally add .com at the end of an Australian domain will also be redirected to the fake anti-spyware site.

Bradley Anstis, vice president of security firm Marshal, was concerned about the development.

"This one is pretty worrying really; I think it sends a very strong message to domain registrars, how they can allow a top level domain to be registered as a secondary level domain is clearly beyond me."

Currently, it seems the owner of the domain is redirecting all traffic to the fake spyware page but Anstis claims that more specific attacks are possible.

"If you're getting people to fall for this, and I suspect people will, the world is your oyster really," Anstis said.

Anstis warned that the domain could be particularly dangerous if used to mimic financial Web sites: "You could easily put an [fake] ANZ Web site that looks exactly like the original one. I think the big concern with this is it is quite difficult to spot."

The au.com domain is owned by Australian domain name reseller and hosting provider NetRegistry. In an interview with ITRadio's Risky Business podcast, the CEO of NetRegistry, Larry Bloch, argued that registrants should be able to use domains as they liked unless they were breaking the law.

"In the absence of any overriding concern, for example illegal activity or activity that's clearly not satisfying community norms -- and this may be an example of that -- we'll literally let registrants carry on as they see fit," said Bloch.

However, Chris Disspain, CEO of the Australian Domain Name Administrator (auDA), said in this case there may be a legal precedent for taking action.

"I am investigating this, whether this is either a breach of either, the register agreement or the code of practice. The fact that it is not in .au does not necessarily mean that it is outside the register agreement or the code of practice," he said.

Disspain referred to an Australian Federal Court case from June 2004, which put such sites within the auDA's reach. He said, "We could have a go at sites outside [.au domain] if they, to use a football phase, 'brought the game into disrepute'."

Security firm F-Secure analysed the "anti-spyware" program found at the site and confirmed it to be fake. F-Secure's Patrik Runald said, "when you scan your PC it will always find something to complain about ... to clean anything you need to register your e-mail address and then it asks you for your credit card," he said.

A screenshot of the downloaded program courtesy of F-Secure.

Chris Gatford, from penetration testing firm Pure Hacking, said even if people do not fall for the fake anti-spyware application, the misleading domain name is likely to be generating revenue for its owner through a pay-per-click scheme.

Gatford explains that although the site downloads via the domain anti-spyware.com, " before that, it goes through three or four redirections, and some of these are using what is called 'click bank', which is basically counting the clicks that adware-free.com is sending through to anti-spyware.com".

Talkback

Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

Terms of Service - As a ZDNet registrant, and by using this service, you indicate that you agree to our Terms and Conditions and have read and understand our Privacy Policy.

ZDNet Australia Live

Yes "without secure internet identification methods" I cannot see a future for online voting be it a referendum or selecting a Gov (at ...

20 minutes ago by Taskmanager on A farewell to democracy: Kaspersky

Oh of course you would would want something in return. hmmm I see, well maybe my best wishes for and your family. btw, Western Union is ...

25 minutes ago by Doubt on NBN users opt for 100Mbps

Well Willunga looks like a nice place to live, close to wine growing areas, a golf club. Houses are probably reasonably priced. Very nice...

27 minutes ago by Doubt on NBN users opt for 100Mbps

Listening to @stilgherrian cover AusCERT and cyberwar, http://t.co/6lGUEz8H

http://edfarmaciaes.com/#0500 generico viagra barcelona EdFarmaciaEs sildenafil y sulfatos

41 minutes ago by buy priligy cheap on Top alternatives to Microsoft Outlook

Travel Tech Q and A: Skyscanner's Ewan Gray http://t.co/VN5tGJzC

#Westpac Board goes paperless with #Ipads with #Tabula #App http://t.co/duxuj2fd #Cybersecurity #Bank

Microsoft is serious about open source??? http://t.co/mqQGgta7

If I give you money what do I get in return? Do you know how commerce works or are you just a filthy poor that wants my monies for nothin...

1 hour ago by Hubert Cumberdale on NBN users opt for 100Mbps

@joedamato just try varying caps randomly. Maybe they do this http://t.co/1FN5FwYv

NSW outlines datacentre migration plans - Hardware - News - ZDNet Australia http://t.co/OQfUl0D1

MikeSkoey - thanks for your comments. Rather than hang my head in shame, I am proud of my achievements, particularly of being able to ru...

1 hour ago by Paul_Berryman on 30 servers to 7: BUPA redoes virtualisation

The Liberals have no idea what to do and would just go back to the "do nothing" policy we had under Howard, Alston and Coonan.

1 hour ago by Magnus on NBN cost-benefit analyses are so 2011

"Why is that if someone who expresses a view different from the sheep, are immediately bandied a troll?" Nope. I prefer to call you some...

1 hour ago by Hubert Cumberdale on NBN users opt for 100Mbps

"on the new fast Internets everyone wants the fast plan" #orly #nareally #yarly http://t.co/kvfCa84A

This article needs a conclusion or recommendation advising Android users what to do about this. For example, are there reliable security...

1 hour ago by Magnus on Android's biggest security flaws

Kaspersky is right. Even though voting is compulsory here, Australia needs to start work on this now. Once such a secure online credent...

2 hours ago by Magnus on A farewell to democracy: Kaspersky

Chrome overtakes IE: does it matter? http://t.co/e4SILk8a

A ZDNet study showed that British Facebook users are drunk in 76 percent of their photos.

The HDMI cable ripoff and why retail is really dying http://t.co/eFT7zEW7

Travel Tech Q and A: Skyscanner's Ewan Gray http://t.co/IUysbyKf

Travel Tech Q and A: Skyscanner's Ewan Gray http://t.co/V7vL5QB9

Dazza - lets make a deal. I won't call you a troll if you don't call me a sheep. Anyway let's get some perspective on this. You cannot ...

3 hours ago by dickster on NBN users opt for 100Mbps

Further to the comments from James, I can add that most botnets will test the bandwidth of the end host before they take control of that ...

3 hours ago by patrickbutler on National Botnet Network coming: Earthwave

ZDNet reports Microsoft launches its own social service http://t.co/VJS5BkwF

by http://t.co/vmlLt4bh: Travel Tech Q and A: Skyscanner's Ewan Gray: Ewan Gray, Skyscanner's director for Asia P... http://t.co/4bfDRXo4

Travel Tech Q and A: Skyscanner's Ewan Gray http://t.co/CtNlVWN7

Travel Tech Q and A: Skyscanner's Ewan Gray: Ewan Gray, Skyscanner's director for Asia Pacific, shares some of h... http://t.co/ZxjpmqiM

Seriously, every business is slow to start off, that's common sense. But the NBN is attempting to replace an incumbent monopoly. So wait ...

3 hours ago by Beta on NBN users opt for 100Mbps

Microsoft is serious about open source: 10 proof points http://t.co/iv2ji74q

Ok, for all of those that are complaining about price lets look at it this way, Australia started using copper wiring back in the late 18...

3 hours ago by Kalthae on NBN users opt for 100Mbps

Ah so you have an anti-NBN website then...ok!

4 hours ago by Beta on NBN users opt for 100Mbps

@ Doubt, I think you should be a policy advisor to Tony Abbott. I can see it now pre-election 2013, Press Club - Journo: Mr Abbott, yo...

4 hours ago by Beta on NBN users opt for 100Mbps

@beachking, that's why the first N in NBN is of importance, because while this may come as a shock, the universe does not revolve around ...

4 hours ago by Beta on NBN users opt for 100Mbps

Err the words give it away "world class"... it's not Huawei class, China class or India class, it's world class! World Class from Farlex...

4 hours ago by Beta on NBN users opt for 100Mbps

How many billions of dollars have they spent for these 3500 connections? Whats the return in profit? How long are they going to keep subs...

4 hours ago by Dazza152 on NBN users opt for 100Mbps

Accelerator targets 'clean-tech' start-ups http://t.co/p9VPCzCa

RT @vexnews: NBN users opt for highest speed plan http://t.co/8eUvvVvQ

OutsourcingLive: #Outsourcing is still on the rise http://t.co/5U6R431A ^NK http://t.co/B8HtVvAD

In Facebook IPO fiasco the 'smart money' got burnt - ZDNet (blog): TIMEIn Facebook IPO fiasco the 'smart money' ... http://t.co/3iD1g6lG

So thats $2000 per premise just to replace the NTU...wow. Somebody is making a fortune on that work

4 hours ago by Coops1 on NBN's Tassie upgrade to cost $1.3 million

But will we actually get 100mps Internet speeds often overstated RT@vexnews: NBN users opt for highest speed plan http://t.co/1uTiHXrd

RT @JamesVickery: NBN users opt for 100Mbps http://t.co/atP8fi1L

more cloud TV recording services tumble in wake of court victory for copyright monopolies - http://t.co/FEWm6Z7Y

Mike Quigley | Only 3500 NBN customers with active fibre services to date http://t.co/6eB525Ur via #auspol NBN very expensive failure

NBN users opt for highest speed plan http://t.co/8eUvvVvQ

http://t.co/ZWOl5p8F

http://t.co/JWINuozI

Remember, these are the high speeds that Mr Abbott believes you guys don't want.... http://t.co/Jtqnwb2M

Three tips for businesses to support connected customers http://t.co/to8fCl1N via @zite

Which Windows will make for a better tablet? http://t.co/wxr95itf via @zite

Cloud based TV recording services in Australia shutdown after negative ruling. http://t.co/9zlnSVJd

AD on azure, is all about APPS .. http://t.co/EMdsrHZF

#Biometric bugs too dangerous for public? http://t.co/IdIBiRUJ (via @zdnetau by @mukimu)

#Outsourcing is still on the rise http://t.co/ANaHIofI ^NK

This story has been voted 12000 times in the last 24 hours!

1 day ago, Is Bill Gates a great leader?

This story has been voted 10 times in the last 24 hours!

3 days ago, CeBIT 2012 opens: photos

This story has been voted 15 times in the last 24 hours!

3 days ago, Lenovo ThinkPad 3G tablet (32GB)

Facebook Activity

Keep up with ZDNet Australia

ZDNet Events Calendar

ZDNet Events Calendar