US RUNNING SHOES FAKE SITE NO 2 IN GOOGLE SEARCH


12/2/2024


This site was reported to Brooks EU as fake on 17 Jan 2024. It is still active today (12/2/2024).

Background

When searching for Brooks running shoes (search term “brooks nl”), the second entry on the google page is a fake phishing site.

This site is extremely well done to look like it mimics the real brooks site (real site is https://www.brooksrunning.com/en_nl). Fake site is www.brooks-netherland.com.

This site is unique in that it extends normal phishing schemes by:

Analysis

Recommendations

Appendix - Research

www.brooks-netherland.com

NameALIBABA.COM SINGAPORE E-COMMERCE PRIVATE LIMITED

Whois Servergrs-whois.aliyun.com

Referral URLhttp://www.alibabacloud.com

Statusok https://icann.org/epp#ok

Important Dates

Expires On 2024-11-06

Registered On 2023-11-06

Updated On 2023-11-06

Name Servers

NS1.ECPAGE.COM47.75.3.214

NS2.ECPAGE.COM54.193.69.207


Email is unhealthy

ISP that is hosting the site is Fibergrid


ISP Location

N°5 Sturdee Avenue, Suite 3012196, Rosebank, Johannesburg, South Africa


Support mail from

Goodserviceforcustomer.com (non-existant domain)

Actually from

online@goodserviceforcustomer.com

Users AmazonSES For mail

Fake delivery email


The site most likely originates in China (Comments in code in chinese and DNS registration done through Baidu)


Site is still active

Verification posted to 

https://topstorefsale.com/godpay/confirm/en-us/731707685004890675

This leads to another fake site

https://www.topstorefsale.com/