ALERT: malvertizement featuring Best Western
Detectable by adopstools:
http://www.adopstools.net/index.asp?page=quicklink&id=OTfPElP8UO2czuD9
The malvertizement hits the following domains:
profitabill.com
ab-outstat.net
I also see hits on:
onlinestatsmanager.com
protected-web-space.com
scan.freeantispyware-scanner.com
system-scanner.org
| profitabill.com | ----- ICANN Registrar: ENOM, Inc Created 25 March 2008 NS1,2,3,4.PROFITABILL.COM IP: 213.189.9.228- Noord-holland, Amsterdam, Trancepitt Services Registrant: "noo", Serg Moon, moon.serg@gmail.com (associated with 104 domains) ----- |
| ab-outstat.net | ----- ICANN Registrar: ENOM, Inc Created 10 October 2008 NS1,2.AB-OUTSTAT.NET IP: 79.135.187.70 - Turkey, Sistemnet Registrant: ITmeter Inc, Sergey Belonozhko, sergbelo@gmail.com (associated with 40 domains) Shares IP range with many domains associated with the facilitation of malvertizing and fraudware. ----- |
| onlinestatsmanager.com | ----- ICANN Registrar: ENOM, Inc Created 3 July 2008 NS1,2,3,4.ONLINEPROMOSTATS.COM IP: 76.74.249.9 - Virgin Islands, Soft-sol.inc Registrant: Generic namecheap.com details - historical WHOIS hidden behind privacy service. ----- |
| protected-web-space.com | ----- ICANN Registrar: BIZCN.COM Created 3 December 2008 NS1,2,3.FREEYOURDNS.COM IP: 69.10.44.198 - United Kingdom - Innovative Solutions Registrant: Vladimir Nevskiy (onicdomains@yahoo.com) ----- |
| scan.freeantispyware-scanner.com | ----- ICANN Registrar: REGTIME LTD Created 1 December 2008 NS1,2.NAMESELF.COM (195.161.133.218 & 204 - RTComm, Russia) IP: 78.26.179.233 - Ukraine, Renome-Service Registrant: Jamil Mcfatridge, jamil.mcfatridge@gmail.com (owns 4 domains) ----- |
| system-scanner.org | ----- ICANN Registrar: BIZCN COM Created 20 November 2008 NS1,2.SPY-PROTECTOR.NET IP: 115.126.5.92 - Bangladesh Telegraph and Telephone Board Registrant: Oleg Bajenov, oleg.bajenov@gmail.com ----- |