Directi Internet Solutions strikes again
I ask you – just how obvious does the impersonation of a legitimate company have to be before Directi notices and stops a site from going live *before* it can do harm???
quigley-simpson.net
Registrar: DIRECTI INTERNET SOLUTIONS
Created 17 December 2008
NS1.EVERYDNS.NET
NS2.EVERYDNS.NET
NS3.EVERYDNS.NET
NS4.EVERYDNS.NET
IP: 94.247.3.17 - Latvia, Zlkon
Website redirects visitors to the legitimate website, quigleysimpson.com
Domain discovered after it was used to fraudulently sell malvertizing, purportedly on behalf of the legitimate Quigley Simpson company:
(http://www.bluetack.co.uk/forums/index.php?s=9fa704b47f52bec51accb4cb17439f29&showtopic=18064&st=210&p=90729&#)
The fraudulent domain shares IP address with several domains that are also a cause for concern, being:
hyundai-inc.com
Registrar: DIRECTI INTERNET SOLUTIONS
Created 17 December 2008
NS1.EVERYDNS.NET
NS2.EVERYDNS.NET
NS3.EVERYDNS.NET
NS4.EVERYDNS.NET
IP: 94.247.3.17 - Latvia, Zlkon
Website redirects visitors to the legitimate website, hyundai-motor.com
*****
mediavest-corp.com
Registrar: DIRECTI INTERNET SOLUTIONS
Created 17 December 2008
NS1.EVERYDNS.NET
NS2.EVERYDNS.NET
NS3.EVERYDNS.NET
NS4.EVERYDNS.NET
IP: 94.247.3.17 - Latvia, Zlkon
Website not yet live, but WHOIS refers to support@us-resources.com, which is the same email address as is registered for "mediavest.net".
*****
posnerpromotion.com
Registrar: DIRECTI INTERNET SOLUTIONS
Created 17 December 2008
NS1.EVERYDNS.NET
NS2.EVERYDNS.NET
NS3.EVERYDNS.NET
NS4.EVERYDNS.NET
IP: 94.247.3.17 - Latvia, Zlkon
Website redirects visitors to the legitimate website, posneradv.com
*****
singlesnet-inc.com
Registrar: DIRECTI INTERNET SOLUTIONS
Created 17 December 2008
NS1.EVERYDNS.NET
NS2.EVERYDNS.NET
NS3.EVERYDNS.NET
NS4.EVERYDNS.NET
IP: 94.247.3.17 - Latvia, Zlkon
Website redirects visitors to the legitimate website, singlesnet.com
*****
I, for one, am sick to death of Directi letting this stuff through. Do they *really* believe that a high profile company like Hyundai is going to register a domain through them, and then host the domain in Latvia? Come on!!
I don't care that Directi are suspending domains **after the fact**. The bad guys can do a lot of damage with domains such as those above, even in the space of a few days.
Impersonation of legitimate domains is not the only behavior which leads us to Directi. Reseller Club (aka Directi) and Directi continue to be involved in the registration of domains used to facilitate the distribution of fraudware - Kimberley has details of a recent incident:
http://www.bluetack.co.uk/forums/index.php?s=9fa704b47f52bec51accb4cb17439f29&showtopic=18064&st=210&p=90729&#