March 2009 - Posts

Online advertising and impression fraud

I admit, I have seen this carry-on before, and it seems to be more common nowadays (or maybe we’re just keeping a closer eye-out for it) but I had not seen as extreme an example as that demonstrated by Mike Nolet on his blog.

You can see a video of the fraud, as it happens, here:
http://www.mikeonads.com/2009/03/25/using-ads-for-impression-fraud/

BTW, Wayne Porter has the same video:
http://www.wayneporter.com/2009/03/26/fraud/

BTW, did you spot the Norton alert that warned that an “a recent attempt to attack your computer was blocked”?  It makes me wonder what else was going on in that capture…

Posted by sandi with 1 comment(s)
Filed under:

Have we found a connection between Traffichunters.net and Innovative Marketing?

image

Every so often, an absolute gem crosses my desk.  This is one of those occasions.

The screenshot to left of screen is of the message headers of an email from “traffichunters.net”.  traffichunters.net were trying to sell advertisements for display on a web site.  Please accept my apologies for the redacted areas – they are necessary to protect the anonymity of the information source.

You will see that the “return path”, “x-envelope-from”, “authenticated sender”, and “from” indicate that the message was from somebody using an @traffichunters.net email address.  Another @traffichunters.net email address was cc’d.  You will also see the highlighted IP address in the screenshot (194.140.237.225).  Let’s see who that IP address belongs to…

inetnum:        194.140.237.0 - 194.140.237.255
netname:        IMU-NET
descr:          04073, Ukraine, Kyiv
descr:          160 Frunze st.
country:        UA
org:            ORG-IMU1-RIPE
admin-c:        IMU-RIPE
tech-c:         IMU-RIPE
status:         ASSIGNED PI
mnt-by:         RIPE-NCC-HM-PI-MNT
mnt-by:         IMU-MNT
mnt-lower:      RIPE-NCC-HM-PI-MNT
mnt-routes:     IMU-MNT
mnt-domains:    IMU-MNT
source:         RIPE # Filtered

organisation:   ORG-IMU1-RIPE
org-name:       Innovative Marketing Ukraine <---
org-type:       OTHER
address:        04136, Ukraine, Kyiv
address:        Severo-Syretskaya st, 160
e-mail:        
mnt-ref:        IMU-MNT
mnt-by:         IMU-MNT
source:         RIPE # Filtered

role:           Innovative Marketing Ukraine NOC <----
address:        04136, Ukraine, Kyiv <----
address:        Severo-Syretskaya st, 3 <----
e-mail:         noc@imu.kiev.ua
admin-c:        OLAR-RIPE
tech-c:         OLAR-RIPE
nic-hdl:        IMU-RIPE
mnt-by:         IMU-MNT
source:         RIPE # Filtered

route:          194.140.237.0/24
descr:          Innovative Marketing Ukraine <---
origin:         AS41146
mnt-by:         IMU-MNT
source:         RIPE # Filtered

 

traffichunters.net has been mentioned several times on this blog – it has also been mentioned that there are a lot of similarities between traffichunters.net and Olympic Media:
http://msmvps.com/blogs/spywaresucks/archive/2009/01/05/1658482.aspx

WHOIS information about traffichunters.net is currently hidden behind Moniker Privacy Services but that was not always so.  Historical WHOIS information (and this very blog) reveal that the Registrant of traffichunters.net used to be listed as:

Helen Nikolson (helen.nikolson@gmail.com)
PO Box 441
Road town
null
0000
VG

As a matter of interest, the email address helen.nikolson@gmail.com is or has been associated with the following domains, all of which should be treated with extreme caution:

adminkas.com | alodila.com | ashoping.com | ausgebl.com | automobilewdew.com | balluvi.com | begried.com | bescoro.com | bestdatinforu.com | bigmp3online.com | bombitti.com | childhe.com | chroned.com | cowresti.com | cussermono.com | deniti.com | derousti.com | digitalmedia-supply.net | digitalmedia-supply.org | eidingsl.com | elneua.com | entders.com | fecati.com | fimmida.com | financemagpro.biz | financestoc.com | geleisch.com | gifrup.com | greatlakemusic.com | griehe.com | gudmun.com | jealalts.com | kantende.com | mediadvision.biz | mediadvision.info | mediatraff.com | mehrsei.com | meogrep.com | mobileprotx.net | mobiletechserv.com | mp3cdt.com | nachgeb.com | newrevenuestore.net | noniumbe.com | notdom.com | obiebe.com | oldmusicbox.com | pornosbest.com | prackyph.com | purchaselive.net | sagipsul.com | scutheti.com | shopingprojet.com | smartmedia24.com | softsecuritysite.net | stroxylo.com | tatmun.com | thepurchase.net | tolerli.com | traffichunters.net | ungeb.com | unvern.com | upednene.com | vollende.com | xxxlifesite.net | zustaus.com

 

We can draw even further associations by examining traffichunter.net (as distinct to traffichunters.net) and olympicmedia.net – I always did find it interesting that two domains, sharing the same IP address, and with only one letter difference in the name, would have such different Registrant details ;o)

traffichunter.net
ICANN Registrar: NAME.COM LLC
Created: 25 September 2008
NS1.TRAFFICHUNTER.COM
NS2.TRAFFICHUNTER.COM

IP: 72.232.107.19 - New York, Layered Technologies Inc

Registrant: Jeann Covergale Petroleum (jeann.petroleum@yahoo.com)
339 St Paul Street, Kamloops, Vancouver BC
Note: It is worth noting that the Coast Canadian Inn is located at the address claimed by the traffichunter.net Registrant (http://www.coasthotels.com/hotels/canada/bc/kamloops/coast_canadian/overview)

olympicmedia.net is currently not resolving but its WHOIS details reveal the following Registrant:

Jane Ross  (soft.sol.inc@gmail.com) - email address associated with 34 domains
16 Main str 
Tortola, NONE  BVI
VG
14193017014

One last point of interest - another IP associated with Innovative Marketing (194.140.237.200) has been caught distributing comment spam and traditional spam in the past - cite: http://www.projecthoneypot.org/ip_194.140.237.200

Posted by sandi with no comments
Filed under: ,

Developments in the FTC versus Innovative Marketing et al lawsuit

Joint MOTION to Stay Further Proceedings as to James M. Reno and Bytehosting Internet Services, LLC Pending Approval of Settlement by Federal Trade Commission.  Responses due by 4/3/2009 (Robbins, Colleen)

The FTC, James Reno and Bytehosting Internet Services have requested the Court stay further proceedings as to James Reno and Bytehosting for a period of 90 days.

The stay is requested so that the Commission's attorneys can seek approval of a "Stipulated Final Order for Permanent Injunction and Monetary Judgment As To Defendants James M. Reno and Bytehosting Internet Services, LLC".  Reno and Bytehosting executed a proposed stipulated final order on 11 March 2009, but this proposed stipulated final order must firstly be approved by the Director of the Bureau of Consumer Protection and then considered, voted on and approved by the full Commission; a procedure that can take up to 90 days.

We will not know the details of the proposed stipulated final order until it it is approved, and then lodged with the Court for its approval.

Posted by sandi with 1 comment(s)
Filed under: ,

Alert: please treat all content from hitoptimist.com with extreme caution

Seen in association with malvertizing incidents - measurehits.com used in same malvertizing campaigns.

hitoptimist.com
ICANN Registrar: Communigal Communications Ltd
Created 10 March 2009

DNS1.COMMUNIGAL.NET
DNS2.COMMUNIGAL.NET

IP: 88.198.8.15 - Bayern - Gunzenhausen - Hetzner-rz-nbg-net

Contact Information :
Domain Contact is Private
Address is private
Private
00000
972 9999999
972 9999999

hostnames sharing ip with a-records:

cosmotraf.net
download.pcprivacycleaner.com
download.powerfulvirusremover2008.com
static.88-198-8-15.clients.your-server.de
sw.effectiveload.com
ydmstats.com

Posted by sandi with no comments
Filed under: ,

ALERT: please treat the domains hit-detect.com and statsnclick.com with extreme caution

Both are new domains associated with the Registrant "Gabriel Jenks".  Regular readers of my blog will know that "Gabriel Jenks" is a name associated with several malvertizement related domains in recent times, including measurehits.com and statisticsishere.com.

hit-detect.com
ICANN Registrar: YESNIC CO. LTD
Created 10 March 2009

NS1.HIT-DETECT.COM - 116.50.15.1 - HostFresh
NS2.HIT-DETECT.COM - 116.50.15.1 - HostFresh
NS3.HIT-DETECT.COM - 89.149.226.121 - Netdirekt

NS4.HIT-DETECT.COM (only in zone) - 212.117.162.90) - Luxembourg Root Esolutions

IP: 195.62.37.14 - Sardegna - Olbia - Geonic.net Ltd

Web sites in the same IP range: addded.com, banner-count.com, lineacount.com, lineweather.com, mypersonalhttp.com, tangoing.info, tinnily.info, unmarine.info, warwork.info, wovens.info.

Registrant::
Name      : Gabriel Jenks
Email     : gabrielcjenks17@mail.com
Address   : 3515 Cooks Mine Road, NM
Zipcode   : 88101
Nation    : US
Tel       : 1-505-763-5453
Fax       :

IMPORTANT: Let's not forget that the postcode (88101) and phone number (505-763-5453) map to Clovis, New Mexico.  I cannot find a "Cooks Mine Road" in Clovis.  Not only that, the phone number listed in the WHOIS is apparently owned by a Brian A Jones and Delinda K Jones, not a Gabriel Jenks.

NS1.HIT-DETECT.COM and NS2.HIT-DETECT.COM:  hostnames sharing ip with a-records - mail.xxx-online.in | ns1.statisticsishere.com | ns2.02sta.com | ns2.admediastats.com | ns2.onlinestatsmanager.com | s2.promorotation.com | ns2.securityclick.net | ns2.st-athome.net | ns2.st-aticglobalsources.com | ns2.themonitoring.net
domains using this as nameserver under another name - o2sta.com | measurehits.com | promorotation.com | st-athome.net | st-aticglobalsources.com | statisticishere.com | themonitoring.net | traffic-analytics.com | waytotheprofit.com

NS3.HIT-DETECT.COM: hostnames sharing ip with a-records - 89-149-226-121.internetserviceteam.com - ns2.measurehits.com - ns3.02sta.com - ns3.admediastats.com - ns3.promorotation.com - ns3.securityclick.net - ns3.st-athome.net - ns3.st-aticglobalsources.com - ns3.statisticsishere.com - ns3.themonitoring.net

nameservers missing in parent delegation - ns4.hit-detect.com (212.117.162.90): hostnames sharing ip with a-records - ns3.measurehits.com - ns4.02sta.com - ns4.admediastats.com - ns4.onlinestatsmanager.com - ns4.promorotation.com - ns4.securityclick.net - ns4.st-athome.net - ns4.st-aticglobalsources.com - ns4.themonitoring.net - ns4.traffic-analytics.com

 

statsnclick.com
ICANN Registrar: YESNIC CO. LTD
Created 10 March 2009

NS1.STATSNCLICK.COM - 116.50.15.1
NS2.STATSNCLICK.COM - 116.50.15.1
NS3.STATSNCLICK.COM - 89.149.226.121

NS4.STATSNCLICK.COM (only in zone) - 212.117.162.90)

IP: 212.117.165.128 - Luxembourg - Root Esolutions

Shares IP with measurehits.com and waytotheprofit.com

Registrant::
Name      : Gabriel Jenks
Email     : gabrielcjenks17@mail.com
Address   : 3515 Cooks Mine Road, NM
Zipcode   : 88101
Nation    : US
Tel       : 1-505-763-5453
Fax       :

Posted by sandi with no comments
Filed under: ,

News: lovesick hacker cripples Northern Territory Health Department, hospital, prison and Supreme Court servers?

For heavens sake … according to the news report at the URL below it took “130 experts” to “find the problem and fix it” – the “problem” was, apparently, the fact that the “hacker” (and I use that term very loosely) “deleted 10,475 user accounts”.

The incident is explained as:

In submissions from his lawyer Tom Berkley and prosecutor Paul Usher yesterday, the court heard that McIntosh hacked into the system on his workmate's computer, using her password.

He was living with her in May, 2008, when he logged into government servers and deleted 10,475 user accounts from the Health Department, hospital, prison and Supreme Court servers.

Who was this “workmate”?  And how the heck did he know her password? Especially a password for a user account that I can only assume had high level administrative credentials?  And how can such an unsubtle slash-and-burn attack need “130 experts” and a bill of $1,253,750 to fix?

Cite: http://www.ntnews.com.au/article/2009/03/13/38995_ntnews.html

Posted by sandi with no comments
Filed under:

ALERT: New malvertizement featuring Bausch & Lomb Softlens contact lenses

image

 

I have seen multiple, visually identical, versions of the malvertizement shown above, one of which has revealed a new name and domains.  Please be on the look-out.

 

One sample that I received today is effectively neutralized because the malvertizement hits the domains of-ficialstat.com and securityclick.net, both of which are not resolving.

securityclick.net is a "Serg Moons" domain, which is currently "on hold" (aka locked) :o)  The domain is no longer resolving, but its last IP address was 212.117.165.128. 

212.117.165.128 currently hosts two well known domains, measurehits.com and waytotheprofit.com.  waytotheprofit.com has been mentioned more times on this blog than I care to remember.  measurehits.com (listed as owned by a Gabriel Jenks) was mentioned on this blog just the other day, here:
http://msmvps.com/blogs/spywaresucks/archive/2009/03/09/1676761.aspx

of-ficialstat.com is also "on hold", and is listed as owned by a "Sergey Belonozhko (sergbelo@gmail.com).  The domain is no longer resolving, but its last IP was 79.135.187.73

*********************************************************************************************

 

The next sample I examined hits the following domains - cosmotraf.net and pleaselinkmeto.com - two domains that I have not encountered before.   This campaign is live.

Once the redirect is triggered we hit a URL at traff-direct.com.  We are then redirected to go-uniq.com before we hit the fraudware domains removespywarethreats.com or desktoprepairpage.com or pcantimalwaresolution.com.

cosmotraf.net
ICANN Registrar: Communigal Communications Ltd
Created 5 March 2009
IP: 88.198.8.15 - Bayern - Gunzenhausen - Hetzner-rz-nbg-net

Hostnames sharing IP with A Records:

download.pcprivacycleaner.com
download.powerfulvirusremover2008.com
static.88-198-8-15.clients.your-server.de
sw.effectiveload.com
ydmstats.com

WHOIS information - how unhelpful of Communigal:

Domain Contact is Private
Address is private
Private
00000
972 9999999
972 9999999

pleaselinkmeto.com
ICANN Registrar: Communigal Communications Ltd
Created 5 March 2009
IP: 58.65.237.43 - Hong Kong (sar) - Hostfresh

WHOIS information - how unhelpful of Communigal:

Domain Contact is Private
Address is private
Private
00000
972 9999999
972 9999999

 

traff-direct.com
ICANN Registrar: YESNIC CO. LTD.
Created 16 February 2009

NS1.TRAFF-DIRECT.COM
NS2.TRAFF-DIRECT.COM
NS3.COMONDNS.COM
NS4.COMONDNS.COM

IP: 78.129.158.69 - United Kingdom - Eukhost Ltd

Registrant:
Preston Wasson
wassonpreston@email.com
4532 Dancing Dove Lane
10011
US
347 526 4950

Note: "Preston Wasson" is also the Registrant of comondns.com above.  "Preston Wasson" owns about 19 domains.

The address apparently does not exist, and the phone number is associated with an address in White Plains, NY.


Just out of interest, let's take a look at the NS*.COMONDNS.COM - all discovered domains should, of course, be treated with extreme caution.

NS1.COMONDNS.COM - hostnames sharing IP with A records:

a.dnstut.com
ns1.go-uniq.com
ns1.removespywarethreats.com
ns1.thesurfdigest.com
ns2.comondns.com
ns2.dnstut.com
ns2.go-uniq.com
ns2.removespywarethreats.com

 

Domains using this name server under another name:

comondns.com
desktoprepairpackage.com
dnserror.org
fuckteencunt.com
go-uniq.com
mainfeedhere.com
pcantimalwaresolution.com
removespywarethreats.com
search-lasslorn.com
search-unassuetude.com

 

NS1.COMONDNS.COM - hostnames sharing IP with A records:

a.dnstut.com
ns1.comondns.com
ns1.go-uniq.com
ns1.removespywarethreats.com
ns1.thesurfdigest.com
ns2.dnstut.com
ns2.go-uniq.com
ns2.removespywarethreats.com

Domains using this nameserver under another name:

comondns.com
desktoprepairpackage.com
dnserror.org
find-allnot.com
fuckteencunt.com
mainfeedhere.com
pcantimalwaresolution.com
removespywarethreats.com
search-lasslorn.com
search-unassuetude.com

 

NS3.COMONDNS.COM - domains using this as a name server:

comondns.com
desktoprepairpackage.com
go-uniq.com
pcantimalwaresolution.com
comondns.com
desktoprepairpackage.com
go-uniq.com
pcantimalwaresolution.com
comondns.com
desktoprepairpackage.com
go-uniq.com
pcantimalwaresolution.com

 

NS4.COMONDNS.COM - domains using this as name server:

comondns.com
desktoprepairpackage.com
go-uniq.com
pcantimalwaresolution.com

 

go-uniq.com
ICANN Registrar: YESNIC CO. LTD.
Created 16 February 2009

NS1.GO-UNIQ.COM
NS2.GO-UNIQ.COM
NS3.COMONDNS.COM
NS4.COMONDNS.COM

IP: 72.55.153.155 - Quebec - Iweb Dedicated Cl

Registrant:
Preston Wasson
wassonpreston@email.com
4532 Dancing Dove Lane
10011
US
347 526 4950

 

removespywarethreats.com
ICANN Registrar: YESNIC CO. LTD
Created 24 February 2009

NS1.COMONDNS.COM
NS2.COMONDNS.COM
NS3.COMONDNS.C0M
NS4.COMONDNS.COM

IP: 78.46.90.230 - Bayern - Gunzenhausen - Hetzner

Shares IP with billgroups.com, cleanerpcsolution.com, desktoprepairpackage.com pcantimalwaresolution.com, pcsolutionshelp.com and removespywarethreats.com

Registrant:
Preston Wasson
wassonpreston@email.com
4532 Dancing Dove Lane
10011
US
347 526 4950

 

desktoprepairpage.com
ICANN Registrar: YESNIC CO. LTD.
Created 24 February 2009

NS1.COMONDNS.COM
NS2.COMONDNS.COM
NS3.COMONDNS.C0M
NS4.COMONDNS.COM

IP: 78.46.90.230 - Bayern - Gunzenhausen - Hetzner

Registrant:
Preston Wasson
wassonpreston@email.com
4532 Dancing Dove Lane
10011
US
347 526 4950

 

pcantimalwaresolution.com
ICANN Registrar: YESNIC CO. LTD.
Created 24 February 2009

NS1.COMONDNS.COM
NS2.COMONDNS.COM
NS3.COMONDNS.C0M
NS4.COMONDNS.COM

IP: 78.46.90.230 - Bayern - Gunzenhausen - Hetzner

Registrant:
Preston Wasson
wassonpreston@email.com
4532 Dancing Dove Lane
10011
US
347 526 4950

*********************************************************************************************

 

A third sample hits the following domains - googlesearchingweb.net and clickanalytic.com.

googlesearchingweb.net
ICANN Registrar: DIRECTI
Created 6 February 2009

IP: Suspended domain

Historical IP: 79.135.187.62 - Turkey Sistemnet Telekomunikasyon Ve Bilgi Tek. Tic. Ltd. Sti

Other suspicious sites in the same IP range include officialstat.net, statgroup.net, st-atetstr.com, staticglobalsources.net, station-appraisals.com, st-athisranch.net, s-tatetstr.com and of-ficialstat.net

WHOIS: Hidden behind privacyprotect.org (as far as I am concerned, once a domain has been suspended it should lose the protection of privacyprotect.org)

 

clickanalytic.com
ICANN Registrar: DIRECTI
Created 6 February 2009

IP: Suspended domain

Historical IP: 79.135.187.83 (Turkey Sistemnet Telekomunikasyon Ve Bilgi Tek. Tic. Ltd. Sti) then 212.117.165.128 (Luxembourg Root Esolutions)

As noted earlier, 212.117.165.128 is the IP of measurehits.com and waytotheprofit.com.

WHOIS: Hidden behind privacyprotect.org (again, as far as I am concerned, once a domain has been suspended it should lose the protection of privacyprotect.org)

Posted by sandi with no comments
Filed under: ,

Developments in the FTC versus Innovative Marketing et al lawsuit

Here is the latest in the FTC v IMI et al lawsuit.  Since my last post the following activity has occurred:

26 February 2009 - REPLY to Response to Motion re MOTION to Stay filed by Sam Jain (Wood, Benjamin)

26 February 2009 - REPLY to Response to Motion re MOTION to Stay (Temporary) filed by Kristy Ross (Bertram, Connie)

3 March 2009 - REPLY to Response to Motion re MOTION for Other Relief Order Holding Sam Jain and Kristy Ross In Contempt Of Court And Requiring The Repatriation Of Their Assets filed by Federal Trade Commission (Arenson, Ethan)

4 March 2009 - MOTION to Dismiss Complaint by Marc D'Souza. Responses due by 23 March 2009 (Duncan, Russell)

4 March 2009 - MOTION to Stay Temporary by Marc D'Souza. Responses due by 23 March 2009 (Duncan, Russell)

5 March 2009 - REPLY to Response to Motion re MOTION to Dismiss Complaint and MOTION to Dismiss COMPLAINT JOINT REPLY MEMORANDUM filed by Sam Jain (Wood, Benjamin)

5 March 2009 - MOTION to Appear Pro Hac Vice for Garret Rasmussen on behalf of Marc D'Souza.

5 March 2009 - MOTION to Appear Pro Hac Vice for Michael Madigan on behalf of Marc D'Souza.

5 March 2009 - RESPONSE in Opposition re MOTION to Modify Preliminary Injunction, re Preliminary Injunction filed by Federal Trade Commission. Replies due by 19 March 2009 (Arenson, Ethan)

6 March 2009 - NOTICE to Substitute Attorney representing Defendant Kristy Ross (Del Negro, Michael)

6 March 2009 - PAPERLESS ORDER granting Motion to Appear Pro Hac Vice for attorney Garret G Rasmussen on behalf of Marc D'Souza.

6 March 2009 - PAPERLESS ORDER granting Motion to Appear Pro Hac Vice for attorney Michael J Madigan on behalf of Marc D'Souza.

*****

Defendant Marc D’Souza joins Defendants Sam Jain’s and Kristy Ross’s Motions to Dismiss and requests that the Court dismiss the FTC complaint for failure to join Innovative Marketing, Inc., "a necessary and indispensable party".  D’Souza adopts and incorporates the supporting arguments and authorities provided in Mr. Jain’s memorandum in support of his motion to dismiss (arguments and authorities that the FTC have already responded to).

D'Souza also requests a stay of all proceedings against him all proceedings against him in the this case until a parallel criminal proceeding is resolved.  Not only that, he asks the Court to to modify Section IV of the Preliminary Injunction to allow him to access assets either obtained (i) after December 2006, the date the Federal Trade Commission (“FTC”) acknowledges that Mr. D’Souza terminated his involvement with Innovative Marketing’s business; or (ii) resulted from foreign conduct involving foreign consumers for which he claims the FTC has no authority to seek consumer redress (Sandi note: the FTC argues that it does have the right to seek consumer redress for "foreign consumers").

D'Souza claims a Fifth Amendment privilege against self-incrimination.

*****

Jain and Ross claim that IMI has not been properly served because the FTC has not filed with the Court proof of service "by a receipt signed by the addressee, or by other evidence satisfying the court that the summons and complaint were delivered to the addressee" (basically, they are saying that because the return of service is only supplied as an "exhibit to its Opposition" as distinct to being filed separately with the Court, the FTC has not properly filed proof of service).

Jain and Ross also claim that the service of IMI in Belize is ineffective because Belize "specifically directs international plaintiffs to send "requests for service" only to the designated central authority, The General Registry in the Supreme Court Building in Belize City" (Process Servers were used to serve IMI in Belize).  There is a footnote that says "Retaining this control by insisting on service through the central authority, Belize could refuse to serve a domestic corporation with foreign process from the U.S. Federal Trade Commission. ... (noting that "the Central Authority of the Russian Federation denies all requests for service of process originating from the United States.").  For this reason, Defendants Jain and Ross have suggested joinder of IMI may never be feasible under Rule 19(b), justifying dismissal under Rule 12(b)(7)."

Jain and Ross also complain that the return of service identifies "Ramona Lewis" as "the person with whom the summons and complaint were left", but that the return of service "does not bear her signature or include any information establishing her connection to IMI or even to Apex Trust."

*****

Quotes taken from "Plaintiff's consolidated reply to Sam Jain and Kristy Ross's opposition to the FTC's motion for an order holding Sam Jain and Kristy Ross in contempt of court and requiring repatriation of their assets":

"In their Opposition, defendants Sam Jain and Kristy Ross fail to provide this Court with any justification for the contumacious conduct that has become their hallmark.  Instead, Jain and Ross seek to downplay their wilful noncompliance with this Court's preliminary injunction ("PI") by pointing out that the FTC has only accused them of violating some, but not all, of the PI's provisions, and dismissing these provisions as unimportant.

Jain and Ross devote much of the rest of their Opposition to a half-baked impossibility defense, arguing that they cannot be held in contempt for failing to effectuate Innovative Marketing, Inc.'s ("IMI") compliance with the PI because the FTC has not proven they currently control IMI.  In making this argument, defendants attempt to distance themselves from their own sworn affidavits, in which they proudly claim IMI as their own.  Unfortunately for the defendants, the burden of proving an impossibility defense rests firmly with them.  Having failed to offer any evidence that they no longer control IMI, Ross and Jain's impossibility defense fails."

and

"...defendant Jain wrongly accuses the FTC of "consistently misrepresent{ing} the contents" of the affidavit he signed admitting that he is the CEO of IMI.  Opposition at 4.  Jain argues that his affidavit merely states that he "performed the general functions of a Chief Executive Officer" not that he actually served as the CEO of IMI.  This argument gets Jain nowhere.  As Jain concedes in his own affidavit, the defendants operated IMI in an informal fashion, often without written contracts.  See FTC's Ex Parte Motion For Temporary Restraining Order and Order To Show Cause ("TRO Motion") (D.E. 3) Ex 17, Att. F at 93.  See also Aff. of Marc D'Souza at 6, attached as Ex. 17, Att. D at 31 to the TRO Motion ("These ventures relied on convoluted, complex and opaque business structures designed to confuse consumers and regulators as to the identity of the true owners ... the partners had no formal, written partnership agreement and deliberately did not keep formal records ...".)  Given the loose structure of the defendants' fraudulent enterprise, it is hardly surprising that Jain did not have a name plate outside a corner office identifying him as CEO of IMI.  Nonetheless, Jain admittedly controls IMI and "functions" as its CEO.  Any doubt as to this point is resolved later in the same Jain affidavit, in which Jain acknowledges that he and defendant Sundin are the only two persons within IMI with the authority to "approve or reject any request for expenditures of {IMI's} resources."  Id. at Att. F at 106."

and

"In their Opposition, Jain and Ross do not actually deny that they are corporate officers of IMI, nor do they deny the authenticity of their own sworn affidavits establishing their roles as IMI officers.  Rather, Jain and Ross allege that the FTC has not proven that they are corporate officers IMI as of today, and as a result the FTC has failed to prove the defendants are in contempt of the PI for failing to effectuate IMI's compliance.

The defendants' argument fails to two independent reasons.  First, it is not the FTC's burden to prove that the defendants have the capacity to comply with the PI.  Rather, it is the defendants' burden to prove that compliance is impossible.  Second, even if the FTC were obligated to provide evidence of the defendants' control of IMI, it has already done so via the defendants' own sworn affidavits.  Moreover, the FTC possess a wealth of additional information establishing Jain and Ross's control of IMI, which is discussed in depth below."

and

"In their Opposition, defendants introduce no evidence of any kind establishing that they no longer control IMI.  Instead, defendants merely assert that the FTC has not proven that they currently control IMI, and therefore they cannot be held in contempt.  This is not enough."

and

"... it appears clear that the defendants are still crafting their story, which will undoubtedly have them relinquishing control of IMI shortly after the last date the Commission's evidence ties them to the company."

and

"Jain and Ross's control of IMI continued throughout 2007 and 2008.  Pursuant to the PI issued by the Court, defendant James Reno recently turned over to the FTC thousands of pages of "instant message" logs, including instant message "chats" between both Reno and Jain as well as Reno and Ross.  See Decl. of James Reno at 5, attached hereto as Exhibit 3.  While the FTC's review of these logs is ongoing, the Commission has already uncovered plentiful evidence of Ross and Jain's continuing control of IMI.  The Commission also has obtained the lease agreement for the luxury condominium occupied by Sam Jain prior to his decision to flee prosecution in California.  This agreement further connects Jain and IMI."

and

"The instant message chat logs turned over to the FTC by James Reno contain a wealth of recent information about Jain's control of IMI."

and

"...the FTC obtained the "Residential Lease Agreement and Deposit Receipt" ("Lease") for the luxury San Francisco condominium in which Jain resided before absconding from the criminal case pending against him and fleeing California. ... The Lease, which is dated May 22, 2008, and runs through May 21, 2009, lists the tenant of the condominium as "IMI, Inc.," and includes a signature block for "Sam Jain for the benefit of IMI, Inc." ... The Lease also provides that only Sam Jain may occupy the unit." (Footnote: As the Court will recall, Jain attempted to evade service of the Complaint by describing this condominium as a "satellite office" for Jack Palladino's investigative firm, a description Palladino included in the sworn declaration submitted to this Court. ... This description appears irreconcilable with the Lease.)"

Note by Sandi: to be precise, the Residential Lease Agreement and Deposit Receipt records that "ONLY the following listed individuals, AND NO OTHERS shall occupy the subject property for no more than 21 days unless the {illegible} written consent of OWNERS is obtained in advance and in writing: Sam Jain" - I agree that this makes it difficult to believe that the condo was Palladino's satellite office ;o)

"The Reno instant message logs also contain evidence establishing Ross's continued control of IMI.  In a May 5, 2008 discussion, Ross discusses "Winifixer", a clone of IMI's notorious "WinFixer" scareware product that was created by a competitor. ... Ross complains in the discussion about how "basically everyone on the planet copied our stuff" and indicates that she asked another IMI employee to ask the competitor to change the name of their product."

and

"...the defendants have already incriminated themselves by voluntarily airing the financial details of their fraudulent enterprise in open court filings."

*****

Quotes taken from plaintiff's opposition to defendant Sam Jain's motion to modify the preliminary injunction:

"Jain's argument that he has an absolute right to use an unlimited amount of frozen funds for his "criminal defense" is ironic, given that Jain is not presenting a defense in the unrelated criminal case pending against him in California.  Instead, Jain has elected to flee prosecution and is now on the run from the United States Marshals' Service.  Clearly, Jain should not be allowed to deplete the still unknown amount of frozen funds for a case in which he has affirmatively decided to abscond."

and

"To suggest that Jain has not received the proceeds of this fraud is absurd, and belied by the fact that Jain was the driving force behind the IMI lawsuit filed in Canada against Marc D'Souza to recover IMI's ill-gotten proceeds."

and

"Through their deceptive marketing, the defendants made more than $74 million through the sale of their computer security software products through 2006 alone.  So far, the FTC has frozen a mere $174,000 in the United States, and because of the defendants' refusal to complete the court-ordered financial disclosures, the FTC has no way of knowing the full extent of their assets.  It would unfairly prejudice the FTC to require it to trace assets at this stage in the litigation, especially since - in disregard of this Court's PI - the defendants are refusing to turn over IMI records to the FTC; the very records that would allow the FTC to accomplish the tracing defendants' demand.  Defendants should not benefit from their own contumacious conduct, and therefore the defendants' argument on tracing should be rejected."

and

"Jain has not submitted any evidence of any kind that he lacks access to non-frozen funds. Indeed, it appears clear Jain has such access.  Jain's lawyers have been extraordinarily aggressive in this litigation, filing motion after motion to delay this proceeding and undoubtedly ringing up a huge legal bill.  Presumably Jain's lawyers have been compensated for these efforts, and Jain does not suggest otherwise.  Moreover, Jain has yet to petition this court for any living expenses, despite the fact that the asset freeze has been in place for more than three months.  Jain offers no explanation as to how he has been able to fund his exploits as a fugitive from justice during these several months.  Jain also offers no evidence as to whether he is currently holding a job, and if so, what compensation he is receiving.  Any such funds would be wholly exempt from the asset freeze, and should be used to pay Jain's legal expenses."

*****

Quotes taken from Declaration of James Reno pursuant to 28 U.S.C. 1746:

"ByteHosting has performed a variety of work for Innovative Marketing, Inc. ("IMI"), including the operation of an IMI call center.  ByteHosting also provided Network Infrastructure Management services to IMI, including technical support, and configured and tuned IMI servers.  This work ceased on or about October 24, 2008."

and

"During the period ByteHosting performed work for IMI, I was in routine contact with representatives of IMI, including defendant Kristy Ross.  These communications occurred primarily during "chats" conducted over the Internet via instant message."

*****

Let’s turn our mind away from the legal maneuverings that are currently occurring in this case.  There is going to be lots of back and forth until the Judge finally rules on the motions.  As noted above, the FTC has “thousands of pages” of chat transcript as supplied by James Reno but so far only a few pages have been attached to publicly accessible court documents. 

The FTC, in the court documents, has focused on the evidence supplied by the recorded messages of who has/had ongoing control of IMI.  I looked at the chats from a different perspective.

I share with you some choice quotes:

As written by Mr James "I only provided the infrastructure, I'm a victim" Reno – it looks to me like he was well aware of exactly what was going on, and more than that, was quite a supporter/fan – and familiar enough with the behavior of the malware that he felt it necessary to reassure his correspondent that “garunteed {sic} no worms spreading to that box”:

James: http: // 63.210.246.34/users/jreno/ksx12f2f-MalwareWarrior.png
James: :)
James: Right click -> exit on taskbar
James: brings up the window that wont disappear ;)
James: and i love the FALSE alerts, its lovely
James: thats on a VMWAre workstation running inside our LAN, behind a firewall, with nothing but other unix boxes ;) .. garunteed {sic} no worms spreading to that box.
James: interesting software ;)

And elsewhere:

James: the only entries in my passport
James: "ukraine"
James: :) about once a year
James: heh
James: maybe i need to go to some other nations, just to get their stamps
James: lol

Conversation attributed to the fugitive Sam Jain:

Sam: well thats why we have the slush fund
Sam: of extra $ from globaldat
Sam: just figure ot how much :)
Sam: no worries

And later, the two of them being sneaky:

Sam: ya, i just put b.s. names
Sam: and address on the customs form
Sam: no 1 looks
James: im not worried about entry to ukraine
James: just re-entry to the us
James: dont feel like being hassled by customs again
James: stupid govt :(
James: us is so screwed anymore
James: if you miss me, its good actully :)
James: cuz then they cant say, i came to "meet with you"
James: even if they found out you were there
James: heh
James: but id love to meet sometime, just sucks
Sam: ya, if u get stopped coming back and after basic questions
Sam: u'd have to sayi {sic} want my lawyer
Sam: heh
James: i dont know if your using 'your' passport or not {Sandi comment: if not ‘his’ passport, then whose? Note Reno’s emphasis on ‘your’}
James: but afaik, interpool {sic} is watching yours
James: but if they seen you leave
Sam: yep i use mine
Sam: freely heh
Sam: screw them
James: im just saying
James you 100% are not there :)
Sam: its cuz of that swiss *** {Sandi comment: now that's interesting...}
James: so how was i meeting you :)
Sam: ya, so i guess from that standpoint
Sam: works out well

Posted by sandi with 2 comment(s)
Filed under: ,

ALERT: Please treat the domain statisticsishere.com and measurehits.com with extreme caution

I received this email a short while ago:

We have been getting a lot of ads accessing scripts from this domain statisticsishere.com. So far there is no malware redirect or download but this domain looks suspicious having been created less than a week.

I have to agree that the domain is suspicious. 

Before we get started, it is important that I remind you that the fact that there is no suspicious behavior *at the moment* is of no comfort.  The crooks behind malvertizing have been known to establish a relationship with potential victims by running one or more “clean” campaigns, thereby building a level of trust between them and their victims, before hitting their victims with malvertizing.

 

Let’s look at the WHOIS information for statisticsishere.com:

ICANN Registrar: YESNIC CO. LTD.
Created: 5 March 2009
NS1.STATISTICSISHERE.COM - IP 116.50.15.1 (HostFresh)
NS2.STATISTICSISHERE.COM - IP 116.50.15.1 (HostFresh)
NS3.STATISTICSISHERE.COM - IP 89.149.226.121 (Netdirekt)

IP: 195.62.37.14 - Sardegna, Olbia, Geonic.net Ltd

Registrant:
Gabriel Jenks (gabrielcjenks17@mail.com)
3515 Cooks Mine Road
88101
US
Tel: 1 505-763-5453

First of all, HostFresh and Netdirekt have both been problematic in the past but, more importantly, the postcode (88101) and phone number (505-763-5453) map to Clovis, New Mexico.  I cannot find a "Cooks Mine Road" in Clovis.  Not only that, the phone number listed in the WHOIS is apparently owned by a Brian A Jones and Delinda K Jones, not a Gabriel Jenks.

image

 

Now, let’s look at the NS for the domain statisticsishere.com:

IP of NS1.STATISTICSISHERE.COM - 116.50.15.1
IP of NS2.STATISTICSISHERE.COM - 116.50.15.1

Hostnames sharing IP with A Records - you will see some very familiar domains....

mail.xxx-online.in
ns2.02sta.com
ns2.admediastats.com
ns2.onlinestatsmanager.com
ns2.promorotation.com
ns2.securityclick.net
ns2.st-athome.net
ns2.st-aticglobalsources.com
ns2.statisticsishere.com
ns2.themonitoring.net
ns2.traffic-analytics.com
ns2.waytotheprofit.com
www.xxx-online.in

Domains using NS1.STATISTICSISHERE.COM as nameserver: statisticsishere.com

Domains using NS1.STATISTICSISHERE.COM as nameserver under another name (again, you're going to see some familiar names):

02sta.com
promorotation.com
st-athome.net
st-aticglobalsources.com
statisticsishere.com
themonitoring.net
traffic-analytics.com
waytotheprofit.com

Nameservers missing in zone:

ns1.statisticsishere.com
ns2.statisticsishere.com
ns3.statisticsishere.com

Used as nameserver but missing in zone: statisticsishere.com

*****

IP of NS3.STATISTICSISHERE.COM - 89.149.226.121

PTRS of IP numbers: 89-149-226-121.internetserviceteam.com

Hostnames sharing IP with A Records (again, lots of familiar names):

89-149-226-121.internetserviceteam.com
ns3.02sta.com
ns3.admediastats.com
ns3.promorotation.com
ns3.securityclick.net
ns3.st-athome.net
ns3.st-aticglobalsources.com
ns3.themonitoring.net
ns3.traffic-analytics.com
ns3.waytotheprofit.com

Domains using this as nameserver:  statisticsishere.com

Domains using this as nameserver under another name:

02sta.com
promorotation.com
st-athome.net
st-aticglobalsources.com
themonitoring.net
traffic-analytics.com
waytotheprofit.com

Nameservers missing in zone:

ns1.statisticsishere.com
ns2.statisticsishere.com
ns3.statisticsishere.com

Used as nameserver but missing in zone: statisticsishere.com

*****

According to a Registrant search, “Gabriel Jenks” owns another domain, being measurehits.com, which should also be treated with extreme caution.

ICANN Registrar: YESNIC CO. LTD.
Created: 26 February 2009

NS1.MEASUREHITS.COM (116.50.15.1)
NS2.MEASUREHITS.COM (89.149.226.121

IP: 212.117.165.128 - Luxembourg, Root Esolutions

Registrant:
Gabriel Jenks (gabrielcjenks17@mail.com)
3515 Cooks Mine Road
88101
US
Tel: 1 505-763-5453

Shares IP address with the following domains, all of which should be treated with extreme caution.

advertpanda.com, clickanalytic.com, extrabigad.com, greatad.net, securityclick.net, waytotheprofit.com, whoisadvert.com

 

NS1.MEASUREHITS.COM

Hostnames sharing IP with A-Records:

mail.xxx-online.in
ns1.statisticsishere.com
ns2.02sta.com
ns2.admediastats.com
ns2.onlinestatsmanager.com
ns2.promorotation.com
ns2.securityclick.net
ns2.st-athome.net
ns2.st-aticglobalsources.com
ns2.statisticsishere.com
ns2.themonitoring.net
ns2.traffic-analytics.com
ns2.waytotheprofit.com
www.xxx-online.in

Domains using this as nameserver under another name:

02sta.com
promorotation.com
st-athome.net
st-aticglobalsources.com
statisticsishere.com
themonitoring.net
traffic-analytics.com
waytotheprofit.com

 

NS2.MEASUREHITS.COM

PTRS of IP numbers - 89-149-226-121.internetserviceteam.com

Hostnames sharing IP with A-Records:

89-149-226-121.internetserviceteam.com
ns3.02sta.com
ns3.admediastats.com
ns3.promorotation.com
ns3.securityclick.net
ns3.st-athome.net
ns3.st-aticglobalsources.com
ns3.statisticsishere.com
ns3.themonitoring.net
ns3.traffic-analytics.com
ns3.waytotheprofit.com

Domains using this as nameserver under another name:

02sta.com
promorotation.com
st-athome.net
st-aticglobalsources.com
statisticsishere.com
themonitoring.net
traffic-analytics.com
waytotheprofit.com

When voice recognition goes bad…

image

One day the voice recognition software, feeling unloved and unappreciated, decided to show the world just how much power it had…

Posted by sandi with 5 comment(s)
Filed under:

Now this is scary…. :(

image We can only hope that the following was a joke – if not, the implications are very worrying…

Our computers at the hospital are crashing all the time now. There are so many extra programs, virus and outdated programs running that the operating system is unable to handle them. Their power supplies can not handle all the extra hardware that is plugged in to them. Being a surgeon, I wanted to to fix them by operating on them. I wanted to debride all the devitalized and parasitic stuff like viruses and spyware; delete all the outdated programs that suck up memory and cpu; amputate all the un-needed hardware and then cleanse the operating systems by refreshing them to the earliest point at which they seemed to work.

I was out voted, We are going to use Obama tech support. We are going to tell the computer that it has more vitual {sic} memory than it really has, add hundreds of new programs to further tie up the cpu, ignore all the viruses and spyware that clog up the whole system and lastly we will get rid of any backups.

Seen at Throckmorton’s other signs.