0

Abuse Report: Malicious DNS Profile used for MitM and Data Interception (ID: 13b27e)

Hello NextDNS Team,

 

I am writing to report a serious violation of the Terms of Service. A user is misusing your platform by setting up a malicious DNS configuration profile (ID: 13b27e) to conduct a Man-in-the-Middle (MitM) attack and DNS spoofing against mobile game players.

 

This profile redirects official game server requests (game-server-01.prod.ava.101xp.com) to an unauthorized proxy server (173.0.146.114) to intercept traffic and harvest session tokens without authorization.

 

Details:

- Malicious Profile ID: 13b27e

- Profile / Setup URLs used: 

- https://apple.nextdns.io

- http://13b27e.dns.nextdns.io/

- Target Domain: game-server-01.prod.ava.101xp.com

- Attacker's Proxy IP: 173.0.146.114

 

Please investigate and disable this configuration profile as soon as possible.

 

---

Note: English is not my native language and I have poor proficiency in it, so I used an AI assistant to help me translate and structure this message. Thank you for your understanding and help.

1 reply

null
    • NextDNs
    • 2 days ago
    • Reported - view

    How does the attacker convince victims to install their DNS profile?

Content aside

  • 2 days agoLast active
  • 1Replies
  • 38Views
  • 2 Following