Symantec Blogs: Security ResponseSyndicate content

Peter Coogan | October 14th, 2009
0 comments

Yesterday a friend of mine sent me a copy of an email he received regarding the renewal of a domain name he owned, which was due to expire. Since the information in the email was correct, he clicked on the renewal link provided. At this point he became dubious of the email—and for good reason. As in most cases like this, at first glance you would find it difficult to spot anything out of the ordinary with this type of email and would simply presume that it was a friendly reminder from your ISP to re-register your domain name.  

ISPemailEdit.jpg

When the link provided in the email is clicked (in order to supposedly renew the domain) it brings you to a site where you are presented with a page like the one shown below. Again, there is nothing really out of the ordinary and all appears nice and professional:
 
...