Don't be spoofed by this Ryanair & Aer Lingus ad [2018]

Don't be spoofed by this Ryanair & Aer Lingus ad [2018]

I have seen this ad floating around on Facebook in the last few days and it is time to put a stop to it.

It is a phishing site. This is NOT a giveaway by Ryanair!!

 

The link in the preview should give it away “ryanair.com.first-ticket.win” – This ain’t a Ryanair domain! First-ticket.win is owned by a guy in Panama


Registry Registrant ID: C3D9BD253F34C40D096A2D756772EC247-NSR
Registrant Name: WhoisGuard Protected
Registrant Organization: WhoisGuard, Inc.
Registrant Street: P.O. Box 0823-03411
Registrant Street:
Registrant Street:
Registrant City: Panama
Registrant State/Province: Panama
Registrant Postal Code:
Registrant Country: PA
Registrant Phone: +507.8365503
Registrant Phone Ext:
Registrant Fax: +51.17057182
Registrant Fax Ext:
Registrant Email: 14b0888bcaee476b9452bb85e7c76d13.protect@whoisguard.com
Registry Admin ID: CBFAAF7AC1FDE4BD392B2E0CB853338C3-NSR

 

UPDATE: 14/01/2018 – It looks like there is a Aer Lingus version of this phising ad too:

The domain “com-promos-new.com” is registered to a “David Jordan” from San Franciso, CA, USA.


Domain Name: COM-PROMOS-NEW.COM
Registry Domain ID: 2211445712_DOMAIN_COM-VRSN
Registrar WHOIS Server: whois.enom.com
Registrar URL: www.enom.com
Updated Date: 2018-01-10T11:56:50.00Z
Creation Date: 2018-01-10T19:56:00.00Z
Registrar Registration Expiration Date: 2019-01-10T19:56:00.00Z
Registrar: ENOM, INC.
Registrar IANA ID: 48
Domain Status: clientTransferProhibited https://www.icann.org/epp#clientTransfer Prohibited
Registry Registrant ID:
Registrant Name: DAVID JORDAN
Registrant Organization:
Registrant Street: 2479 DIAMOND ST
Registrant City: SAN FRANCISCO
Registrant State/Province: CA
Registrant Postal Code: 94131
Registrant Country: US
Registrant Phone: +1.4152275901
Registrant Phone Ext:
Registrant Fax:
Registrant Fax Ext:
Registrant Email: JORDAN.DAVID1@BK.RU

The site goes to a VPS in America that belongs to “Impact VPS”…Ryanair wouldn’t cheap out on this……..

Please do not fall for this! IT CAN SCRAPE LOGIN DETAILS FOR FACEBOOK!