Beware The Domain Phishers!
I have one domain and one domain only at Enom at the moment and even that is about to transferred to my usual registrar of choice, so it came as a surprise to me this morning, to have received a number of emails that appeared to be from Enom.com telling me that my whois information was inaccurate and that my domain could be deleted - though it didn't say which one.
The emails were sent on what's called a sequential autoresponder, that sends pre-compiled emails in a sequence set by the writer.
Had my email reader been set to read emails in HTML format (as most are by default), I might have clicked on the link. However, I only read emails in text format and saw that the url at the end of the mail was not enom.com. (Viewed in HTML, it just says enom.com of course).
Having just flown back home and feeling very tired, this one could have caught me out. Luckily, it didn't.
Just in case you get a similar email, here are all three of the emails I received. As you'll see, they don't mention a specific domain name, they are addressed to "Dear user" and the url is dodgy.
Email 1
Dear user,
On Wed, 29 Oct 2008 04:24:33 +0800 we received a third party complaint of invalid domain contact information in the Whois database for this domain Whenever we receive a complaint, we are required by ICANN regulations to initiate an investigation as to whether the contact data displaying in the Whois database is valid data or not. If we find that there is invalid or missing data, we contact both the registrant and the account holder and inform them to update the information.
The contact information for the domain which displayed in the Whois database was indeed invalid. On Wed, 29 Oct 2008 04:24:33 +0800 we sent a notice to you at the admin/tech contact email address and the account email address informing you of invalid data in breach of the domain registration agreement and advising you to update the information or risk cancellation of the domain. The contact information was not updated within the specified period of time and we canceled the domain. The domain has subsequently been purchased by another party. You will need to contact them for any further inquiries regarding the domain.
PLEASE VERIFY YOUR CONTACT INFORMATION - http://www.enom.com.com92.biz
If you find any invalid contact information for this domain, please respond to this email with evidence of the specific contact information you have found to be invalid on the Whois record for the domain name. Examples would be a bounced email or returned postal mail. If you have a bounced email, please attach or forward with your reply or in the case of returned postal mail, scan the returned letter and attach to your email reply or please send it to:
Attn: Domain Services14455 N Hayden RdSuite 219Scottsdale, AZ 85260
LINK TO CHANGE INFORMATION - http://www.enom.com.com72.biz
Thank you,Domain Services
[IncidentID:88900]
Email 2
Dear user,
On Sat, 1 Nov 2008 02:01:46 +0100 we received a third party complaint of invalid domain contact information in the Whois database for this domain. Whenever we receive a complaint, we are required by ICANN regulations to initiate an investigation as to whether the contact data displaying in the Whois database is valid data or not. If we find that there is invalid or missing data, we contact both the registrant and the account holder and inform them to update the information.
The contact information for the domain which displayed in the Whois database was indeed invalid. On Sat, 1 Nov 2008 02:01:46 +0100 we sent a notice to you at the admin/tech contact email address and the account email address informing you of invalid data in breach of the domain registration agreement and advising you to update the information or risk cancellation of the domain. The contact information was not updated within the specified period of time and we canceled the domain. The domain has subsequently been purchased by another party. You will need to contact them for any further inquiries regarding the domain.
PLEASE VERIFY YOUR CONTACT INFORMATION - http://www.enom.com.ssl45.mobi
If you find any invalid contact information for this domain, please respond to this email with evidence of the specific contact information you have found to be invalid on the Whois record for the domain name. Examples would be a bounced email or returned postal mail. If you have a bounced email, please attach or forward with your reply or in the case of returned postal mail, scan the returned letter and attach to your email reply or please send it to:
Attn: Domain Services14455 N Hayden RdSuite 219Scottsdale, AZ 85260
LINK TO CHANGE INFORMATION - http://www.enom.com.ssl45.mobi
Thank you,Domain Services
[IncidentID:06141]
Email 3
Dear user,
On Sat, 1 Nov 2008 17:09:05 +0100 we received a third party complaint of invalid domain contact information in the Whois database for this domain. Whenever we receive a complaint, we are required by ICANN regulations to initiate an investigation as to whether the contact data displaying in the Whois database is valid data or not. If we find that there is invalid or missing data, we contact both the registrant and the account holder and inform them to update the information.
The contact information for the domain which displayed in the Whois database was indeed invalid. On Sat, 1 Nov 2008 17:09:05 +0100 we sent a notice to you at the admin/tech contact email address and the account email address informing you of invalid data in breach of the domain registration agreement and advising you to update the information or risk cancellation of the domain. The contact information was not updated within the specified period of time and we canceled the domain. The domain has subsequently been purchased by another party. You will need to contact them for any further inquiries regarding the domain.
PLEASE VERIFY YOUR CONTACT INFORMATION - http://www.enom.com.sys53.ru
If you find any invalid contact information for this domain, please respond to this email with evidence of the specific contact information you have found to be invalid on the Whois record for the domain name. Examples would be a bounced email or returned postal mail. If you have a bounced email, please attach or forward with your reply or in the case of returned postal mail, scan the returned letter and attach to your email reply or please send it to:
Attn: Domain Services14455 N Hayden RdSuite 219Scottsdale, AZ 85260
LINK TO CHANGE INFORMATION - http://www.enom.com.sys63.ru
Thank you,Domain Services
[IncidentID:97426]
Labels: domain phishing scam, enom phishing scam

4 Comments:
yup, received it too, ive been also wondering, why there isnt specific domain name anywhere in the mail.
I got the same thing and I've never heard of enom.com before this. Fortunately, I too read everything in plain text and the .sys53.ru domain in the URL is a red flag.
I just received one November 2. I clicked on the link and then suddenly had an intuitive moment and stopped it from connecting. Is there anyone to "report" this to?
Fortunately, I have not received such emails for my domains. But reading this post somehow points out the importance of reading emails in text form instead of html which is my usual choice.v
Post a Comment
Links to this post:
Create a Link
<< Home