Twitter Phishing Site

The newest phishing scam showed up today – maybe it’s been around a while?

First you get the Direct Message – this one forwarded to my email:

20091128_twitter_phish_email

The link in the DM/email takes you to a  site that is a perfect replica of the (old) Twitter logon screen.

But wait.

ALWAYS check the URL before you type in your username/password.

20091128_twitter_phish_webscreen

They even bothered to include the Twitter favicon, but the url is…

20091128_url_favicon

And here’s who owns THAT URL, via a public Whois search…

Registrant Contact:
   jiang wen bin
   jiang wen bin jiang wen bin lixing688@gmail.com
   +86.0517757813719 fax: +86.0517757813719
   jin hua chang jiang lu 125 hao5zhuang 603
   jin hua ZJ 345634
   CN

Administrative Contact:
   jiang jiang lixing688@gmail.com
   +86.02163883527 fax: +86.02163883527
   jinghua Changjiang east street 1255603
   jing hua SH 345634
   CN

Technical Contact:
   jiang wen bin jiang wen bin lixing688@gmail.com
   +86.0517757813719 fax: +86.0517757813719
   jin hua chang jiang lu 125 hao5zhuang 603
   jin hua ZJ 345634
   CN

Billing Contact:
   jiang wen bin jiang wen bin lixing688@gmail.com
   +86.0517757813719 fax: +86.0517757813719
   jin hua chang jiang lu 125 hao5zhuang 603
   jin hua ZJ 345634
   CN

DNS:
ns1.4everdns.com
ns2.4everdns.com