Hat tip to phishlabs (www.phishlabs.com) for the heads up :)
There have been reports of potential malvertizing activity in association with dowsonandco.com and vertfi.com.
dowsonandco.com
Created 8 November 2009
Registrar: BIZCN.COM, INC (notoriously problematic)
IP: 217.23.7.177 (Faro - Worldstream)
Server is running nginx (Software preferred by the miscreants)
Registrant: Timothy Davis (davist@yahoo.com) of 4786 Nutters Barn Lane, Des Moines IA 50317 (I can’t find evidence that this address exists)
Business address is listed as 1221 Brickell Ave Miami, FL, which is the address of some executive offices. Note that you won’t find Dowson and Co at that address according to this web site:
http://www.corporationwiki.com/Florida/Miami/1221-Brickell-Ave-Miami-FL-33131-a4202.aspx
Shares IP with advert-ex.com, bradeymedia.com and lemanmarketing.com as well as mail.parsok.com.
*****
advert-ex.com
Created 8 November 2009
Registrar: BIZCN.COM. INC
Registrant: Johnny Johnson (johnj@dnsconsulting.com), 4765 Horner Street, Montgomery AL 36107
*****
bradeymedia.com
Created 8 November 2009
Registrar: BIZCN.COM, INC
Registrant: Travis Davis (davis@vipdomains.com), 1728 Rafe Lane, Memphis MS 38118
*****
lemanmarketing.com
Created 8 November 2009
Registrar: BIZCN.COM, INC
Registrant: Curtis Bridges (curtisdomains@yahoo.com), 2674 Ryder Avenue, Seattle WA 98101
******************************************************************************
vertfi.com
Created 20 December 2009
Registrar: BIZCN.COM, INC
IP: 217.23.7.83 (Faro, Worldstream) Note that there is also a vertfi.info registered.
Shares IP with febring.com, indrine.com and schnine.com
Registrant: Kenneth Mcdonald (dns@vertfi.com), 33 Tibbs Ave, Superior MT 59872
*****************************************************************************
Other stuff:
A search of IP 217.23.7.% reveals some worrying web sites, eg:
- abercrombielife.com (which displays a series of fake security seals purporting to be issued by BBB, Verisign, McAfee and Security Metrics).
- googie-anaitlcs.ws, googie-analytics.ws
- A series of 'advertising' type domains such as 4livemarket.com, bellwayinteractive.com, goldbaymedia.com, revoltechmedia.com, smartmediaway.com (several of which have been seen before in association with IP addresses of domains used to facilitate the distribution of malvertizing).
I find it interesting that some domains (bellwayinteractive.com, goldbaymedia.com, revoltechmedia.com and smartmediaway.com) used to be within IP range 212.117.175.% – they were IP stablemates with spark-smg.com which was the domain used to trick Gawker Media into accepting malvertizing.
I have also spotted the domain vigana-media.com and yewomedia.com (IP: 217.23.7.175)
vigana-media.com is sharing IP address with yewomedia.com. yewomedia.com's web site is visually identical to vigana-media except for a few minor textual changes to make the blurbs suit the different domains.
Vigana-media.com claims to have been around since 1997 and yewomedia.com claims to have been around since 2002, which is quite interesting, considering both domains were not registered until late 2009. Both sites also claim to have been "ranked by AdvertisingAge as a "Top 100 Interactive Agency Nationwide". Despite the extensive similarities between the web sites, there is no similarity when it comes to the Registrants.
vigana-media.com
ICANN Registrar: BIZCN.COM, INC
Created 15 October 2009
Registrant:
Gene West (genetwest@gmail.com)
510-696-1538
4014 Clifford Street
San Leandro CA 74578
yewomedia.com
ICANN Registrar: BIZCN.COM, INC
Created 30 November 2009
Registrant:
FreeBiofuel
Christopher Penaflor (christopherpenaflor@gmail.com)
503-361-4762
988 Mattson Street
Salem OR 97301