<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Spyware Sucks : Malvertizing</title><link>http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx</link><description>Tags: Malvertizing</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>FTC versus Innovative Marketing et al - developments</title><link>http://msmvps.com/blogs/spywaresucks/archive/2009/11/18/1740364.aspx</link><pubDate>Tue, 17 Nov 2009 23:58:50 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1740364</guid><dc:creator>sandi</dc:creator><slash:comments>3</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1740364</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/11/18/1740364.aspx#comments</comments><description>&lt;p&gt;As we know, Jain&amp;#39;s legal counsel have applied for leave to withdraw as his attorneys of record.&amp;#160; They have not been given permission to withdraw yet, and the deadline for Jain to respond to the FTC&amp;#39;s renewed motion for sanctions was nigh, therefore Jain&amp;#39;s counsel has filed a document in opposition to the renewed motion. &lt;/p&gt;  &lt;p&gt;Jain&amp;#39;s counsel claims that: &lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&amp;quot;&lt;em&gt;Mr. Jain is not acting in bad faith, but on a well-justified fear that the FTC will attempt to circumvent and undermine his valid Fifth Amendment privilege against self-incrimination&lt;/em&gt;&amp;quot;. &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;and &lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&amp;quot;&lt;em&gt;Regarding deterrence, Mr. Jain is not guilty of a pattern of contumacious behavior; indeed, through counsel, he otherwise has actively participated in this case for almost one year&lt;/em&gt;.&amp;quot; &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;and &lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&amp;quot;&lt;em&gt;Finally, the FTC does not even address the possibility of lesser sanctions against Mr. Jain.&lt;/em&gt;&amp;quot; &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;My immediate reaction, on reading the motion, was “&lt;em&gt;come on, who are they trying to fool?&lt;/em&gt;”. Let&amp;#39;s not forget, when reading the above, that Jain&amp;#39;s legal counsel claim in their motion for leave to withdraw that they have NEVER had direct contact with Jain, and that they have had no indirect contact with him for more than 10 months, and that they have no idea where he is.&amp;#160; Such silence does not equate to &amp;#39;active&amp;#39; participation in my world. &lt;/p&gt;  &lt;p&gt;Not surprisingly, the FTC&amp;#39;s response has been swift and states, in part: &lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&amp;quot;&lt;em&gt;Counsel’s description of Jain’s conduct bears no resemblance to the facts of this case. Jain – a fugitive for nearly a year now – has been toying with this Court and the FTC from the outset of this case. Jain has ignored the Temporary Restraining Order and Preliminary Injunction entered by this Court, and completely disregarded this Court’s most recent command that he appear for deposition.&lt;/em&gt;&amp;quot; &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;and &lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&amp;quot;&lt;em&gt;Jain has also wasted this Court’s time with a barrage of frivolous motions, which were designed solely to bog down this litigation and delay the FTC’s efforts to obtain redress on behalf of the millions of consumers Jain and his co-defendants have defrauded. Having succeeded in delaying this case for as long as possible, Jain has now disappeared, and left his lawyers behind to craft excuses for his egregious conduct.&lt;/em&gt;&amp;quot; &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;It makes you wonder whether Jain&amp;#39;s lawyers have received, or are going to receive, payment for their hard work over the past year, doesn&amp;#39;t it.&amp;#160; Here&amp;#39;s hoping they received plenty of $$ in advance.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1740364" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Fraudware/default.aspx">Fraudware</category></item><item><title>FTC versus Innovative Marketing et al - Sam Jain's legal counsel request leave to withdraw as attorneys of record</title><link>http://msmvps.com/blogs/spywaresucks/archive/2009/11/16/1739915.aspx</link><pubDate>Mon, 16 Nov 2009 01:49:05 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1739915</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1739915</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/11/16/1739915.aspx#comments</comments><description>&lt;p&gt;In a not unsurprising development, legal counsel for Sam Jain have petitioned the Court for permission to withdraw as attorneys for Sam Jain.&amp;#160; The FTC does not oppose the request, but does object to any further extension of Mr Jain&amp;#39;s time to respond to the FTC&amp;#39;s pending Renewed Motion for Rule 37 Sanctions. &lt;/p&gt;  &lt;p&gt;The reasons Jain&amp;#39;s attorneys ask for permission to withdraw are: &lt;/p&gt;  &lt;ol&gt;   &lt;li&gt;They have NEVER communicated directly with Jain.&lt;/li&gt;    &lt;li&gt;Their last indirect communication with Jain was received on January 14, 2009.&lt;/li&gt;    &lt;li&gt;They have not communicated with Jain in more than 10 months, since before the bench warrant was issued for Jain&amp;#39;s arrest by the US District Court for the Northern District of California in an unrelated.&lt;/li&gt;    &lt;li&gt;They claim to have no knowledge of Jain&amp;#39;s whereabouts, and to have no ability to contact him directly. &lt;/li&gt; &lt;/ol&gt;  &lt;p&gt;Jain&amp;#39;s legal counsel state that &amp;quot;considering the bench warrant in the Northern District of California and the ongoing criminal investigation in the Northern District of Illinois, there is no indication Mr Jain will participate meaningfully in discovery, with or without counsel.&amp;quot;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1739915" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Fraudware/default.aspx">Fraudware</category></item><item><title>FTC versus Innovative Marketing et al - developments</title><link>http://msmvps.com/blogs/spywaresucks/archive/2009/11/11/1738897.aspx</link><pubDate>Wed, 11 Nov 2009 03:33:51 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1738897</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1738897</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/11/11/1738897.aspx#comments</comments><description>&lt;p&gt;Innovative Marketing and Daniel Sundin are still unrepresented.&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;09/16/2009      &lt;br /&gt;ORDER denying Motion of Marc D&amp;#39;Souza to Dismiss the Complaint. DIRECTING D&amp;#39;Souza to answer the complaint within 20 days. Signed by Judge Richard D Bennett on 9/16/09. &lt;/strong&gt;&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&amp;quot;&lt;em&gt;Viewing the totality of the allegations through the lens of judicial experience and common sense, this Court finds that the FTC has clearly “plea{d} factual content that allows the court to draw the reasonable inference that the defendant is liable for the misconduct alleged.” Iqbal, 129 S. Ct. at 1949 (citing Twombly, 550 U.S. at 50). Through its extensive factual pleadings, the FTC has positioned its claims against Marc D’Souza safely within the realm of plausibility.&lt;/em&gt;&amp;quot; &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;10/02/2009      &lt;br /&gt;MEMORANDUM ORDER granting Motion for Sanctions against Sam Jain insofar as certain conditions are imposed.&lt;/strong&gt; &lt;/p&gt;  &lt;p&gt;“The FTC’s Motion for Rule 37 Sanctions against Defendant Sam Jain (Paper No. 131) is GRANTED insofar as the following conditions are hereby imposed: &lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;em&gt;“1. the FTC is instructed to re-notice Jain’s deposition for an agreed upon time within the next thirty days of the date hereof;        &lt;br /&gt;2. Jain shall again be offered the opportunity to be deposed by video-conference from a location of his choosing;         &lt;br /&gt;3. Jain is hereby warned that if he fails to attend this upcoming deposition, this Court will consider imposing a default judgment against him pursuant to Federal Rule of Civil Procedure 37(d).”&lt;/em&gt; &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;10/06/2009      &lt;br /&gt;ANSWER to FTC Complaint (document 1), by Marc D&amp;#39;Souza&lt;/strong&gt; &lt;/p&gt;  &lt;p&gt;A few minor admissions, lots of denials, a claim that &amp;quot;the FTC has authority to seek restitution, consumer redress or disgorgement with respect to conduct that took place outside the United States and that does not affect domestic commerce&amp;quot;, lot of declining to answer under the Fifth Amendment (while at the same time requesting that said refusal be treated as a denial).&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;10/22/2009      &lt;br /&gt;Second MOTION for Sanctions Pursuant to Rule 37 Against Sam Jain by Federal Trade Commission. Responses due by 11/9/2009&lt;/strong&gt; &lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&amp;quot;&lt;em&gt;Sam Jain has made a mockery of this proceeding and has demonstrated nothing but contempt for this Court and the American judicial system as a whole. Together with his codefendants, Jain perpetrated one of the largest online frauds ever prosecuted by the FTC, with a total consumer injury figure that – as the Court will soon hear – exceeds $150 million. After being caught red-handed by the FTC, Jain promptly fled the United States, leaving his lawyers behind to delay the FTC’s efforts to redress the massive consumer injury Jain helped inflict. After nearly a year of delay, Jain has reached the end of the road. Unwilling to comply with this Court’s command that he participate in discovery, Jain has no further ability to stall this litigation. As a result, Jain has washed his hands of this matter, and simply disappeared. Given these facts, it is difficult to imagine a case that better supports the imposition of terminating sanctions, or an individual more deserving of such an outcome than Jain.&lt;/em&gt;&amp;quot; &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;11/02/2009      &lt;br /&gt;MOTION for Extension of Time to File Response/Reply as to Second MOTION for Sanctions Pursuant to Rule 37 Against Sam Jain by Sam Jain. Responses due by 11/19/2009 (unopposed)&lt;/strong&gt; &lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&amp;quot;&lt;em&gt;Mr. Jain respectfully submits that good cause for granting this Motion exists: (1) Mr. Jain has not requested or received from the Court an extension on any other response or reply filed in this case; (2) Logistical obstacles and the important factual and legal issues raised by the FTC’s Renewed Motion necessitate a brief extension of time to respond.&lt;/em&gt;&amp;quot; &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;11/03/2009      &lt;br /&gt;Paperless ORDER granting Defendant Jain&amp;#39;s unopposed Motion for Extension of Time. Response to Second Motion for Sanctions due 11/16/2009 &lt;/strong&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1738897" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Fraudware/default.aspx">Fraudware</category></item><item><title>Ponderings about the incident that hit Gizmodo (courtesy of Gawker)</title><link>http://msmvps.com/blogs/spywaresucks/archive/2009/11/09/1738591.aspx</link><pubDate>Mon, 09 Nov 2009 14:08:09 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1738591</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1738591</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/11/09/1738591.aspx#comments</comments><description>&lt;p&gt;While I was on holidays, a malvertizing incident hit Gizmodo (via advertising sold to Gawker).&amp;#160; The miscreants impersonated the legitimate advertising agency Spark Communications, registering the domain spark-smg.com (the real domain is sparksmg.com) to assist in the impersonation. &lt;/p&gt;  &lt;p&gt;Publicis have since taken over the fraudulent domain spark-smg.com but we still have access to historical information about the domain which is interesting. &lt;/p&gt;  &lt;p&gt;Before we get into the nitty gritty of the domain itself, I have a few observations to make.&amp;#160; In short, the tricks used were not new.&lt;/p&gt;  &lt;p&gt;&amp;quot;Gawker Sales Guy&amp;quot; says on the &lt;a href="http://www.businessinsider.com/henry-blodget-gawker-scammed-by-malware-pretending-to-be-suzuki-2009-10#comment-4ae6400b00000000002367fd" target="_blank"&gt;businessinsider.com web site&lt;/a&gt; that&amp;quot; &lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&amp;quot;&lt;em&gt;The reason this is news (and the reason we sent it here in the first place) is because these guys were so thorough they managed to fool multiple levels of safeguards we have in place to keep this thing from happening. There was literally NO way for us to know, short of calling the agency and doing background checks on everyone we work with.&lt;/em&gt;&amp;quot; &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;Why did nobody notice that the domain spark-smg.com being was used, instead of sparksmg.com.&amp;#160; I concede that the difference between the domains is subtle, but even if&amp;#160; the &amp;quot;Gawker Sales Guy&amp;quot; who was corresponding with the miscreants did not notice the subtle difference in domains at first, I would have expected him to take a closer look when one of his emails bounced on Saturday 28 September. &lt;/p&gt;  &lt;p&gt;The realities of malvertizing *are* well known in the industry nowadays, thanks to all of the publicity that it has received over the past year or so.&amp;#160; Many warnings have been sent out by various parties and there have been many high profile incidents.&amp;#160; The new person approaching Gawker, the bounced email, and the wide variation in time of day when emails were received should have all given the Gawker Sales Guy reason to pause and take a closer look (despite the fraudster claiming, in one email, to be in London).&amp;#160; &amp;quot;Background checks&amp;quot; should be standard operating procedure, and &amp;quot;calling the agency&amp;quot; using their main telephone number (not a direct line) should also be standard operating procedure, even after background checks have been completed, whenever a new name appears. &lt;/p&gt;  &lt;p&gt;Gawker Sales Guy (&lt;a href="http://www.businessinsider.com/henry-blodget-gawker-scammed-by-malware-pretending-to-be-suzuki-2009-10#comment-4ae6561900000000008b1b70)" target="_blank"&gt;http://www.businessinsider.com/henry-blodget-gawker-scammed-by-malware-pretending-to-be-suzuki-2009-10#comment-4ae6561900000000008b1b70)&lt;/a&gt; then goes on to say: &lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&amp;quot;&lt;em&gt;This was truly damn near impossible to spot as a fake.&lt;/em&gt;&amp;quot; &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;This claim is impossible to judge without specific technical information.&amp;#160; That being said, the ads have to touch something bad as part of the malvertizement process, even if the malicious behaviour itself does not trigger. &lt;/p&gt;  &lt;p&gt;On the BBC web site (&lt;a href="http://news.bbc.co.uk/2/hi/technology/8328399.stm)" target="_blank"&gt;http://news.bbc.co.uk/2/hi/technology/8328399.stm)&lt;/a&gt; it states: &lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&amp;quot;&lt;em&gt;Blaming the fact that staff used Linux operating systems on their production machines for &amp;quot;not noticing sooner&amp;quot;, it advised concerned users to load some up-to-date antivirus software and &amp;quot;make sure your system is clean&lt;/em&gt;&amp;quot;.&amp;quot; &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;The fact that staff use Linux on their production machines is not why the staff did not see the malvertizements.&amp;#160; As regular readers of this blog know, the miscreants behind malvertizing actively manage their campaigns, deliberately doing all they can to avoid detection by victim web sites via geo-targeting, IP exclusions and whatnot.&amp;#160; I would be *extremely* surprised if the malicious behaviour would have been triggered if the malvertizement was displayed on a computer within an IP range associated with the victim web site, or the infrastructure used to serve the advertisement, even if it were running an old, vulnerable, version of Windows.&amp;#160; The bad guys are not fools – they are not going to allow malicious behaviour to trigger on a computer known to be owned by the very people they are trying to fool and defraud.&lt;/p&gt;  &lt;p&gt;Online Media Daily (&lt;a href="http://www.mediapost.com/publications/?fa=Articles.showArticle&amp;amp;art_aid=116269)" target="_blank"&gt;http://www.mediapost.com/publications/?fa=Articles.showArticle&amp;amp;art_aid=116269)&lt;/a&gt; states that it &amp;quot;&lt;em&gt;is believed to be the first to successfully mimic the identity of a major advertising agency&lt;/em&gt;&amp;quot;. &lt;/p&gt;  &lt;p&gt;Ok, I suppose we can argue about what a &amp;quot;major&amp;quot; advertising agency is, but it certainly is not the first time an advertising agency has been spoofed (or the first time that the bad guys have made preparations to do just that).&amp;#160; Some malicious domains that I have seen, and reported on in the past, that could be used to spoof legitimate ad networks include: &lt;/p&gt;  &lt;p&gt;byronadvertising.eu (used to impersonate the legitimate byronadvertising.com and byronadvertising.co.uk)    &lt;br /&gt;koeppelinteractive.co.uk (impersonating koeppelinteractive.com, redirecting visitors to that domain)     &lt;br /&gt;quigley-simpson.net (impersonating quigleysimpson.com, redirecting visitors to that domain)     &lt;br /&gt;mediavest-corp.com (WHOIS referred to support@us-resources.com, an email address also used with the legitimate mediavest.net)     &lt;br /&gt;posnerpromotion.com (impersonating posneradv.com, redirecting visitors to that domain)     &lt;br /&gt;adconion-inc.com (impersonating adconion.com, redirecting visitors to that domain)     &lt;br /&gt;carat-inc.com (impersonating carat.com, redirecting visitors to that domain)     &lt;br /&gt;pubmatic-inc.com (impersonating pubmatic.com, redirecting visitors to that domain)     &lt;br /&gt;doubleclick-ssl.com (impersonating Doubleclick) &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Then there are the fake sites pretending to sell advertising directly on behalf of large corporations: &lt;/p&gt; nokia-corp.com (shared IP with lacoste-ads for a while - can be assumed to impersonate Nokia)   &lt;br /&gt;foxinteractivemedia-inc.com (impersonating fox.com, redirecting visitors to that domain)   &lt;br /&gt;lacoste-ads.com (impersonating lacoste.com, redirecting visitors to that domain)   &lt;br /&gt;orangeadvertising-inc.com (impersonating orange.com, redirecting visitors to that domain)   &lt;br /&gt;hyundai-inc.com (impersonating hyundai-motor.com, redirecting visitors to that domain)   &lt;br /&gt;singlesnet-inc.com (impersonating singlesnet.com, redirecting visitors to that domain)   &lt;br /&gt;vonage-inc.com (used to impersonate the real Vonage)   &lt;p&gt;Tribalfusion has even been impersonated in a credit reference. &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Anyway, let&amp;#39;s take a look at spark-smg.com and see what danger signs we can find by examining historical data (taken from before Publicis Groupe S.A. took over the domain).&amp;#160; &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;spark-smg.com&lt;/strong&gt;     &lt;br /&gt;ICANN Registrar: BIZCN.COM (a known problem Registrar)     &lt;br /&gt;Created 4 September 2009 (a very new domain, another bad sign) &lt;/p&gt;  &lt;p&gt;IP address (up until on or about 3 October 2009): 212.117.175.6 &lt;/p&gt;  &lt;p&gt;212.117.175.6 = Luxembourg Root Esolutions (another problematic host, too often seen in association with malvertizing). &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Note:&amp;#160; A check of the IP range 212.117.175.% reveals a few domains associated with advertising that should be treated with caution: &lt;/p&gt;  &lt;p&gt;RevolteChMedia.com (claims to have been around since 2004, but the domain was only registered on 13 October 2009 - ICANN Registrar BIZCN.COM, INC)) &lt;/p&gt;  &lt;p&gt;BellWayInteractive.com (registered on 14 September 2009 - ICANN Registrar BIZCN.COM, INC) &lt;/p&gt;  &lt;p&gt;SmartMediaWay.com (registered 14 September 2009 - ICANN Registrar BIZCN.COM, INC) &lt;/p&gt;  &lt;p&gt;GoldBayMedia.com (registered 14 September 2009 - ICANN Registrar BIZCN.COM, INC)&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1738591" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category></item><item><title>I have received the Microsoft MVP Award – for the 11th time</title><link>http://msmvps.com/blogs/spywaresucks/archive/2009/10/02/1728978.aspx</link><pubDate>Fri, 02 Oct 2009 13:05:22 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1728978</guid><dc:creator>sandi</dc:creator><slash:comments>5</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1728978</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/10/02/1728978.aspx#comments</comments><description>&lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;margin:10px 20px 20px 0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" align="left" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/4721.image_5F00_7C595E5E.png" width="141" height="201" /&gt; &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;I received an email today advising me that I have been awarded Microsoft MVP status for the 11th time.&lt;/p&gt;  &lt;p&gt;Unlike my previous 10 awards, this time I have been awarded Microsoft MVP under the specialty “Consumer Security: Training” instead of as an Internet Explorer MVP.&amp;#160; I think that is perfectly appropriate; for years I have focused on Consumer Security from the perspective of an Internet Explorer user, but in recent years my focus has moved to studying malvertizing – what it is, how it works, and who is behind it – and, most importantly, sharing and passing on that knowledge and advising advertising networks and web site owners on how to best avoid the miscreants behind malicious advertising.&lt;/p&gt;  &lt;p&gt;Avoiding the bad guys is NOT easy, and is getting harder all the time.&amp;#160; As the Internet Community as a whole has become more aware, and as people as myself have put so much time and effort into educating the community, the bad guys have had to match our efforts and become sneakier.&amp;#160; The impersonation of legitimate companies has become more common; malicious SWF advertisements seem to be falling out of favor as we get better at detecting them, and the bad guys no longer dump all of their eggs in the one basket.&lt;/p&gt;  &lt;p&gt;The most important thing that any of us can do is complete comprehensive reputational research and background checks into any new advertiser/partner/client.&amp;#160; And, don’t take what is on those credit reference forms at face value.&amp;#160; Double check that the phone number supplied for the credit reference matches the company that he or she claims to work for.&amp;#160; If approached by a well known company, make sure that the domain being used actually belongs to that company.&lt;/p&gt;  &lt;p&gt;If you are approached by a well known company, put the attraction of money aside and ask yourself why they would want to advertise with you, and &lt;u&gt;be honest with yourself in your answers&lt;/u&gt;.&amp;#160; Do you attract enough traffic to make it worth their while? Are you well known enough? Is your target audience appropriate to what they are selling?&amp;#160; Is there a sense of urgency to the sale? Are they contacting you at unusual times of the day or night?&amp;#160; Are they reluctant to speak by telephone?&amp;#160; Does an answering machine pick up too often?&lt;/p&gt;  &lt;p&gt;A good reputation is hard won, and easily lost, and the negative press caused by a malvertizing incident does not go away.&amp;#160; Your web site may be blocked by the various web reputation services that are available nowadays.&amp;#160; Google may block access to your site via web searches.&amp;#160; Eventually there may be a noticeable reduction in advertising income if your visitors take it upon themselves to block all advertising for their own protection, or they may become angry or frustrated and stop visiting at all, especially if there is more than one malvertizing incident.&lt;/p&gt;  &lt;p&gt;Finally – &lt;u&gt;&lt;strong&gt;train your staff&lt;/strong&gt;&lt;/u&gt;. Make &lt;a href="http://www.anti-malvertising.com" target="_blank"&gt;www.anti-malvertising.com&lt;/a&gt; required reading and DO WHAT IS SUGGESTED.&amp;#160; If, despite your best efforts, you receive reports of problems from your visitors, DO NOT assume that your visitor is blaming you unfairly, or that there may be a problem with their computer.&amp;#160; Take *all* reports seriously, and ASK FOR HELP.&amp;#160; It is unlikely that your visitors will be sophisticated enough to be able to gather the evidence you need on their own, and the bad guys are very good at hiding their activities from you using various tricks.&lt;/p&gt;  &lt;p&gt;And keep reading this blog :)&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1728978" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/General+stuff/default.aspx">General stuff</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category></item><item><title>ALERT: Please treat content from extrabanner.com with extreme caution</title><link>http://msmvps.com/blogs/spywaresucks/archive/2009/09/20/1725131.aspx</link><pubDate>Sun, 20 Sep 2009 06:39:50 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1725131</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1725131</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/09/20/1725131.aspx#comments</comments><description>&lt;p&gt;&lt;img style="border-right-width:0px;display:inline;border-top-width:0px;border-bottom-width:0px;border-left-width:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/1323.image_5F00_5CCBA833.png" width="542" height="110" /&gt; &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Regular readers will recognize the domains t.banner09092.com and blackwater-cuprumworks.net – they were the domains used to attempt infection of computers via various security exploits:    &lt;br /&gt;&lt;a title="http://msmvps.com/blogs/spywaresucks/archive/2009/09/12/1722754.aspx" href="http://msmvps.com/blogs/spywaresucks/archive/2009/09/12/1722754.aspx" target="_blank"&gt;http://msmvps.com/blogs/spywaresucks/archive/2009/09/12/1722754.aspx&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Luckily, the domain blackwater-cuprumworks.net is not responding at the moment.&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;extrabanner.com&lt;/strong&gt;     &lt;br /&gt;ICANN Registrar: Godaddy.com, Inc     &lt;br /&gt;Created 30 July 2009     &lt;br /&gt;NS47.DOMAINCONTROL.COM     &lt;br /&gt;NS48.DOMAINCONTROL.COM &lt;/p&gt;  &lt;p&gt;IP: 68.178.232.100 - Arizona, Scottsdale, Godaddy.com, Inc (shares IP with 11,081,675 other sites) &lt;/p&gt;  &lt;p&gt;Registar:    &lt;br /&gt;Domain Owner (trafficbuyer@gmail.com - the same as pussbanner769.info)     &lt;br /&gt;15156 SW 5th     &lt;br /&gt;Scottsdale, Arizona 85260     &lt;br /&gt;US &lt;/p&gt;  &lt;p&gt;***** &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;dullnessfrequenting.info&lt;/strong&gt;     &lt;br /&gt;ICANN Registrar: Godaddy.com, Inc     &lt;br /&gt;Created 17 September 2009     &lt;br /&gt;NS57.DOMAINCONTROL.COM     &lt;br /&gt;NS58.DOMAINCONTROL.COM &lt;/p&gt;  &lt;p&gt;IP: 68.178.232.100 - same as extrabanner.com &lt;/p&gt;  &lt;p&gt;Registrant:    &lt;br /&gt;Domain Owner (trafficbuyer@gmail.com)     &lt;br /&gt;15156 SW 5th     &lt;br /&gt;Scottsdale, Arizona 85260     &lt;br /&gt;US &lt;/p&gt;  &lt;p&gt;***** &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;t.banner09092.com&lt;/strong&gt;     &lt;br /&gt;ICANN Registrar: Godaddy.com, Inc     &lt;br /&gt;Created 18 September 2009     &lt;br /&gt;NS57.DOMAINCONTROL.COM     &lt;br /&gt;NS58.DOMAINCONTROL.COM &lt;/p&gt;  &lt;p&gt;IP: 68.178.232.100 (again) &lt;/p&gt;  &lt;p&gt;Registrant:    &lt;br /&gt;Domain Owner (trafficbuyer@gmail.com)     &lt;br /&gt;15156 SW 5th     &lt;br /&gt;Scottsdale, Arizona 85260     &lt;br /&gt;US &lt;/p&gt;  &lt;p&gt;***** &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;blackwater-cuprumworks.net&lt;/strong&gt;     &lt;br /&gt;ICANN Registrar: DIRECTI (Registration service &amp;quot;Domain Names Registrar Reg.Ru Ltd&amp;quot;)     &lt;br /&gt;Created 7 September 2009     &lt;br /&gt;NS1.EVERYDNS.NET     &lt;br /&gt;NS2.EVERYDNS.NET &lt;/p&gt;  &lt;p&gt;IP: 213.155.2.112 - Namibia, Grinvich3, Vladimir Gubarenko &lt;/p&gt;  &lt;p&gt;Shares IP with the domains amateursex-hert.com, aw-work.net, awirons-work.com, blackwater-ironworks.com, blackwater-ironworks.net, blackwater-metalworks.net, blackwater-metalworks.net, sexamateur-hartcore.com and sleazy-dreamers.net &lt;/p&gt;  &lt;p&gt;Registrant:    &lt;br /&gt;Eduard Skobelev (eddiscobbi3@gmail.com)     &lt;br /&gt;ul. Starinskaya, d.1, kv. 92     &lt;br /&gt;g. Moskva     &lt;br /&gt;g. Moskva, 107009     &lt;br /&gt;RU     &lt;br /&gt;Tel: +7 4952243948 &lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1725131" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category></item><item><title>Ponderings about the New York Times malvertizing incident</title><link>http://msmvps.com/blogs/spywaresucks/archive/2009/09/15/1723398.aspx</link><pubDate>Tue, 15 Sep 2009 05:08:33 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1723398</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1723398</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/09/15/1723398.aspx#comments</comments><description>&lt;p&gt;It has been all over the popular press – the New York Times web site had been tricked into accepting a malvertizement that was hijacking some visitors to that site and dumping them at a web site touting fake security software.&amp;#160; And, in a move that is kind of unusual, the New York Times web site displayed a warning about the malvertizement.&lt;/p&gt;  &lt;p&gt;It just so happens that over on &lt;a href="http://troy.yort.com/anatomy-of-a-malware-ad-on-nytimes-com" target="_blank"&gt;yort.com&lt;/a&gt; (author: Troy Davis) there is a screenshot demonstrating how the hijack was triggered:&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;table border="5" cellspacing="2" cellpadding="5" width="924"&gt;&lt;tbody&gt;     &lt;tr&gt;       &lt;td valign="top" width="433"&gt;         &lt;p align="center"&gt;&lt;strong&gt;New York Times incident as &lt;/strong&gt;&lt;strong&gt;reported on yort.com&lt;/strong&gt;&lt;/p&gt;       &lt;/td&gt;        &lt;td valign="top" width="475"&gt;         &lt;p align="center"&gt;&lt;strong&gt;Similar incident as reported on Spyware Sucks&lt;/strong&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="433"&gt;&lt;img style="border-right-width:0px;display:block;float:none;border-top-width:0px;border-bottom-width:0px;margin-left:auto;border-left-width:0px;margin-right:auto;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/6763.image_5F00_76465918.png" width="447" height="460" /&gt; &lt;/td&gt;        &lt;td valign="top" width="475"&gt;&amp;#160;&lt;img style="border-right-width:0px;display:inline;border-top-width:0px;border-bottom-width:0px;border-left-width:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/4705.image_5F00_27FB9365.png" width="626" height="335" /&gt; &lt;/td&gt;     &lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;As you can see from the screenshots above, the two incidents are very similar, and the important stuff – the stuff that caused the hijack – is the code starting at “var a1” in both screenshots.&amp;#160; Depending on various conditions and controls (geolocation, IP address, time of day etc) some visitors would have received JUST the advertisement – others would have seen **the same advertisement** but would have also received the extra code (as pointed out above, starting at var a1).&lt;/p&gt;  &lt;p&gt;The IP address of the hijacking domain, tradenton.com, is:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;at a known bad IP (as reported on this blog on the 10th of September) &lt;/li&gt;    &lt;li&gt;other bad domains were discovered in the same IP range as far back as 4 September &lt;/li&gt;    &lt;li&gt;was very new (registered just this month) &lt;/li&gt;    &lt;li&gt;was registered using a known problematic Registrar &lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;I have said many times on this blog and elsewhere that reputational checks are of CRITICAL IMPORTANCE when accepting advertisements.&amp;#160; Information was available to warn those alert to potential danger that caution was needed as far back as the 4th of September (cite: &lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2009/09/04/1720609.aspx" target="_blank"&gt;my alert about vonage-inc.com on 4 September 2009&lt;/a&gt;).&lt;/p&gt;  &lt;p&gt;Please… take advantage of services such as &lt;a title="http://www.anti-malvertising.com/" href="http://www.anti-malvertising.com/" target="_blank"&gt;http://www.anti-malvertising.com/&lt;/a&gt; and start conducting indepth research when somebody tries to sell you advertising.&amp;#160; One day, your web site may not be hit by an advertisement that simply redirects your visitors to a fake security website.&amp;#160; Instead, your visitors may be redirected to:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;a p0rn0graphic web site, complete with streaming video and sound on the opening page:      &lt;br /&gt;&lt;a title="http://msmvps.com/blogs/spywaresucks/archive/2007/12/31/1428144.aspx" href="http://msmvps.com/blogs/spywaresucks/archive/2007/12/31/1428144.aspx" target="_blank"&gt;http://msmvps.com/blogs/spywaresucks/archive/2007/12/31/1428144.aspx&lt;/a&gt;       &lt;br /&gt;&lt;/li&gt;    &lt;li&gt;a web site that tries to infect your visitor’s computers using various security exploits:      &lt;br /&gt;      &lt;br /&gt;&lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2009/09/12/1722754.aspx" target="_blank"&gt;http://msmvps.com/blogs/spywaresucks/archive/2009/09/12/1722754.aspx&lt;/a&gt;       &lt;br /&gt;&lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2009/07/22/1704910.aspx" target="_blank"&gt;http://msmvps.com/blogs/spywaresucks/archive/2009/07/22/1704910.aspx&lt;/a&gt; &lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;&lt;img style="border-right-width:0px;margin:10px 0px 0px;display:inline;border-top-width:0px;border-bottom-width:0px;border-left-width:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/7345.image_5F00_7C96B0C3.png" width="532" height="140" /&gt;     &lt;br /&gt;&lt;strong&gt;The New York Times hijack in progress, as captured and reported by yort.com…&lt;/strong&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;em&gt;&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;em&gt;&lt;/em&gt;&lt;/strong&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;I have been reading the report at &lt;a href="http://www.wired.com/threatlevel/2009/09/nyt-revamps-online-ad-sales-after-malware-scam/" target="_blank"&gt;wired.com&lt;/a&gt; about this incident, and think it is worthwhile pondering some of the points made in the article.&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;em&gt;wired.com: “The move comes after a security loophole allowed scammers over the weekend to swap an innocuous advertisement for one serving a fake virus-warning, and hawking a deceptive scareware product intended to sell bogus security software.”&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;em&gt;wired.com: ““Over the weekend, the ad being served up was switched so that an intrusive message, claiming to be a virus warning from the reader’s computer, appeared.”&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;wired.com are correct when they say that the incident occurred because of a “security loophole” (that is, the New York Times allowed content to be displayed on its web site that was hosted remotely by a domain outside of their direct command and control – an extremely common behavior and certainly not unusual to the New York Times).&amp;#160; &lt;/p&gt;  &lt;p&gt;That being said, I find it interesting that an “innocuous advertisement” would be “swapped out” or “switched”.&amp;#160; Standard modus operandi for incidents such as the one caught by yort.com has always been to simply add additional malicious code when certain conditions were met – the advertisement itself has not changed in previous incidents (except for when there is an industry-standard rotation of advertisements, which is not the same as a deliberate swapping out).&amp;#160; &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;em&gt;&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;em&gt;wired.com: “Readers &lt;u&gt;who clicked on the ad&lt;/u&gt; found their browsers hijacked while a fake virus-scan was displayed. If they allowed the malicous (sic) website to serve its executable payload, they’d be stuck with a fake scareware program that badgers them into buying supposed anti-virus software.”&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;Wrong.&amp;#160; No user interaction is required for the hijack to occur.&amp;#160; Nobody needed to click on anything.&lt;/p&gt;  &lt;p&gt;Also, as evidenced by the yort.com report, if a person was not hijacked (and therefore had the opportunity to click on the advertisement), then they were redirected to a legitimate website (in the yort.com example, the BVLGARI advertisement was linked to the URL &lt;a title="http://www.bulgari.com/main.php?lang=6/ref=680" href="http://www.bulgari.com/main.php?lang=6/ref=680" target="_blank"&gt;http://www.bulgari.com/main.php?lang=6/ref=680&lt;/a&gt;).&lt;/p&gt;  &lt;p&gt;bulgari.com    &lt;br /&gt;ICANN Registrar: GROUP NBT PLC AKA NETNAMES     &lt;br /&gt;Created 17 February 1998     &lt;br /&gt;AUTH200.NS.UU.NET     &lt;br /&gt;AUTH210.NS.UU.NET     &lt;br /&gt;NS.BULGARI.COM &lt;/p&gt;  &lt;p&gt;Registrant:    &lt;br /&gt;Bulgari SpA     &lt;br /&gt;Lungotevere Marzio 11     &lt;br /&gt;Roma     &lt;br /&gt;00186     &lt;br /&gt;IT&lt;/p&gt;  &lt;p&gt;&lt;img style="border-right-width:0px;margin:10px 20px 20px 0px;display:inline;border-top-width:0px;border-bottom-width:0px;border-left-width:0px;" title="image" border="0" alt="image" align="left" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/7444.image_5F00_0926EE91.png" width="326" height="276" /&gt; &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;em&gt;wired.com: “The Times declined to identify the “national advertiser” the scammers originally impersonated.”&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;Again, let’s refer to yort.com.&amp;#160; From that article I can retrieve the URL of the advertisement used – you can see it to left of screen (I should warn you that there *may* have been more than one advertisement being supplied by the miscreants – we should not assume that this was the only advertisement that a victim may have seen).&lt;/p&gt;  &lt;p&gt;The author also writes:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;“A comment gave the campaign ID as Vonage01_1163613_nyt12, though it was obviously unrelated to Vonage.”&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;I wonder if the domain &lt;strong&gt;vonage-inc.com&lt;/strong&gt; was used by whoever it was that sold the malvertizing to the New York Times.&amp;#160; vonage-inc.com used to have the IP address 212.117.166.71, and known to be used by cybercriminals to impersonate the real Vonage.&amp;#160; Thankfully, vonage-inc.com seem to have been handed over to the *real* Vonage on or about 5 September.&lt;/p&gt;  &lt;p&gt;I wrote about vonage-inc.com back on &lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2009/09/04/1720609.aspx" target="_blank"&gt;4 September 2009&lt;/a&gt;.&lt;/p&gt;  &lt;p&gt;Edit: I see that the &lt;a href="http://www.nytimes.com/2009/09/15/technology/internet/15adco.html?_r=1" target="_blank"&gt;New York Times has admitted that Vonage was impersonated&lt;/a&gt;:&lt;/p&gt;  &lt;p&gt;&lt;em&gt;“The creator of the malicious ads posed as Vonage, the Internet telephone company, and persuaded NYTimes.com to run ads that initially appeared as real ads for Vonage. At some point, possibly late Friday, the campaign switched to displaying the virus warnings. &lt;/em&gt;&lt;/p&gt;  &lt;p&gt;&lt;em&gt;Because The Times thought the campaign came straight from Vonage, which has advertised on the site before, it allowed the advertiser to use an outside vendor that it had not vetted to actually deliver the ads, Ms. McNulty said. That allowed the switch to take place. “In the future, we will not allow any advertiser to use unfamiliar third-party vendors,” she said.”&lt;/em&gt;&lt;/p&gt;  &lt;p&gt;Just to repeat what I said above, information was available on the net, warning that Vonage was being impersonated, as far back as &lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2009/09/04/1720609.aspx" target="_blank"&gt;4 September&lt;/a&gt;. &lt;/p&gt;  &lt;p&gt;So, what do we know about the domains implicated in this latest incident? &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;tradenton.com&lt;/strong&gt;     &lt;br /&gt;ICANN Registrar: BIZCN.COM, INC     &lt;br /&gt;Created 2 September 2009     &lt;br /&gt;NS1.EVERYDNS.NET     &lt;br /&gt;NS2.EVERYDNS.NET &lt;/p&gt;  &lt;p&gt;IP: 212.117.166.69 - Luxembourg, Root Esolutions (a known bad IP address – also, note how close the IP address is to what used to be the IP address for vonage-inc.com)&lt;/p&gt;  &lt;p&gt;Currently shares IP with harlingens.com, kennedales.com, newadsresults.com, relunas.com and waveadvert.com &lt;/p&gt;  &lt;p&gt;Registrant:    &lt;br /&gt;Tradenton     &lt;br /&gt;Shawn Brownell (shawn@tradenton.com)     &lt;br /&gt;978-214-3972 fax: 978-214-3972     &lt;br /&gt;3051 Pearlman Avenue     &lt;br /&gt;Wilmington MA 01887     &lt;br /&gt;US &lt;/p&gt;  &lt;p&gt;***** &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;harlingens.com&lt;/strong&gt;     &lt;br /&gt;ICANN Registrar: BIZCN.COM, INC     &lt;br /&gt;Created 2 September 2009     &lt;br /&gt;NS1.EVERYDNS.NET     &lt;br /&gt;NS2.EVERYDNS.NET &lt;/p&gt;  &lt;p&gt;Registrant:    &lt;br /&gt;harlingens.com     &lt;br /&gt;Richard Andrew (admin@harlingens.com)     &lt;br /&gt;956-893-2463 fax: 956-893-2463     &lt;br /&gt;4859 Carolina Avenue     &lt;br /&gt;Harlingen TEX 78550 &lt;/p&gt;  &lt;p&gt;***** &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;sex-and-the-city.cn&lt;/strong&gt;     &lt;br /&gt;ICANN Registrar: Chinese     &lt;br /&gt;Created 3 September 2009     &lt;br /&gt;NS1.EVERYDNS.NET     &lt;br /&gt;NS2.EVERYDNS.NET &lt;/p&gt;  &lt;p&gt;IP: 94.102.48.209 - Noord-holland, Amsterdam, As29073 Ecatel Ltd &lt;/p&gt;  &lt;p&gt;Registrant: oregon.artscomm@state.or.us &lt;/p&gt;  &lt;p&gt;*****&lt;/p&gt;  &lt;p&gt;Finally, yort.com mentions adxbigad - I have found several references to adxbigad in scripts designed to remove advertising from the New York Times web site (cite: &lt;a href="http://userscripts.org/scripts/review/56684)" target="_blank"&gt;http://userscripts.org/scripts/review/56684)&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1723398" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Fraudware/default.aspx">Fraudware</category></item><item><title>ALERT: Please treat content from trendbanner.com with extreme caution</title><link>http://msmvps.com/blogs/spywaresucks/archive/2009/09/12/1722754.aspx</link><pubDate>Sat, 12 Sep 2009 09:16:19 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1722754</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1722754</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/09/12/1722754.aspx#comments</comments><description>&lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;margin:10px 20px 20px 0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" align="left" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/5488.image_5F00_67DFCC06.png" width="550" height="261" /&gt; &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;It has been implicated in the facilitation of malvertizing that attempts to infect computers via PDF exploit&lt;/p&gt;  &lt;p&gt;The way it works is as follows:&lt;/p&gt;  &lt;p&gt;ad.trendbanner.com uses document.write to load the JS content at banner.pushbanner769.info&lt;/p&gt;  &lt;p&gt;banner.pushbanner769.info displays an advertisement, but also loads content from content from t.banner08092.com.&lt;/p&gt;  &lt;p&gt;t.banner08092.com simply redirects to blackwater-cuprumworks.net&lt;/p&gt;  &lt;p&gt;blackwater-cuprumworks.net includes a javascript (valla.js) which loads content from bintus-bahi.cn in a 0x0 iframe&lt;/p&gt;  &lt;p&gt;bintus-bahi.cn uses CVE-2009-0927 (Stack-based buffer overflow in Adobe Reader and Acrobat via the getIcon method of a Collab object) to infect vulnerable computers, as well as downloading other malware.&lt;/p&gt;  &lt;p&gt;The SWF (oneComesEthics.swf) is suspected to be malicious.&lt;/p&gt;  &lt;p&gt;Virustotal analysis of some content received via bintus-bahi.cn:&lt;/p&gt;  &lt;p&gt;&lt;a title="http://www.virustotal.com/analisis/fbf39bcd9dea6e1233895e391c2d4bab22096cf7b76b8a6b760203f3d0efa76d-1252662476" href="http://www.virustotal.com/analisis/fbf39bcd9dea6e1233895e391c2d4bab22096cf7b76b8a6b760203f3d0efa76d-1252662476" target="_blank"&gt;http://www.virustotal.com/analisis/fbf39bcd9dea6e1233895e391c2d4bab22096cf7b76b8a6b760203f3d0efa76d-1252662476&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Domain information&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;ad.trendbanner.com&lt;/strong&gt;    &lt;br /&gt;ICANN REGISTRAR: GODADDY.COM, INC    &lt;br /&gt;Created 30 July 2009    &lt;br /&gt;NS47.DOMAINCONTROL.COM    &lt;br /&gt;NS48.DOMAINCONTROL.COM &lt;/p&gt;  &lt;p&gt;IP: 161.58.56.25 and 207.57.97.233 &lt;/p&gt;  &lt;p&gt;Shares IP with &lt;strong&gt;doityourselfbuilder.com&lt;/strong&gt; and &lt;strong&gt;banner.islandbanner.com&lt;/strong&gt; &lt;/p&gt;  &lt;p&gt;Registrant:   &lt;br /&gt;&lt;strong&gt;Modena Inc&lt;/strong&gt; (domains@modenainc.com) (associated with 102 domains)    &lt;br /&gt;921 SW Washington ST    &lt;br /&gt;Suite 228    &lt;br /&gt;Portland, Oregon 97205    &lt;br /&gt;United States &lt;/p&gt;  &lt;p&gt;Modena Inc have a dubious history, with complaints as far back to 2005 about &amp;quot;spyware infested filesharing programs&amp;quot;, site scraping and 302 domain poisoning: &lt;/p&gt;  &lt;p&gt;&lt;a href="http://www.freedomcrowsnest.org/forum/viewtopic.php?t=1416" target="_blank"&gt;http://www.freedomcrowsnest.org/forum/viewtopic.php?t=1416&lt;/a&gt;    &lt;br /&gt;&lt;a href="http://forum.abestweb.com/showthread.php?p=456066&amp;amp;mode=threaded#post456066" target="_blank"&gt;http://forum.abestweb.com/showthread.php?p=456066&amp;amp;mode=threaded#post456066&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Modena Inc domains were also part of the malvertizing incident that his digitalspy.co.uk:   &lt;br /&gt;&lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2009/07/22/1704910.aspx" target="_blank"&gt;http://msmvps.com/blogs/spywaresucks/archive/2009/07/22/1704910.aspx&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;There is also a dishonorable mention at bluetack.co.uk (**10** different security exploits were used in that incident) - domains used were banners.exitexchange.com and count.exit1208.com:   &lt;br /&gt;&lt;a href="http://www.bluetack.co.uk/forums/index.php?showtopic=18064&amp;amp;st=210&amp;amp;p=90509&amp;amp;" target="_blank"&gt;http://www.bluetack.co.uk/forums/index.php?showtopic=18064&amp;amp;st=210&amp;amp;p=90509&amp;amp;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;It is interesting that ashoping.com was part of the incident recorded at bluetack.co.uk. The registrant, helen.nikolson@gmail.com, has been seen myriad times, in association with traffichunters.net (which we can tie to Innovative Marketing in the Ukraine):   &lt;br /&gt;&lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2009/03/27/1682054.aspx" target="_blank"&gt;http://msmvps.com/blogs/spywaresucks/archive/2009/03/27/1682054.aspx&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;***** &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;doityourselfbuilder.com&lt;/strong&gt;    &lt;br /&gt;ICANN Registrar: MELBOURNE IT, LTD D/B/A INTERNET NAMES WORLDWIDE    &lt;br /&gt;Created 10 June 2006    &lt;br /&gt;NS1.SECURE.NET    &lt;br /&gt;NS2.SECURE.NET &lt;/p&gt;  &lt;p&gt;Registrant:   &lt;br /&gt;Music Unlimited Inc    &lt;br /&gt;PO Box 1200    &lt;br /&gt;Jacksonville 97530 &lt;/p&gt;  &lt;p&gt;Admin Name:   &lt;br /&gt;David Sprunger (pptorders@playpianotoday.com) &lt;/p&gt;  &lt;p&gt;***** &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;banner.islandbanner.com&lt;/strong&gt;    &lt;br /&gt;ICANN Registrar: GODADDY.COM, INC    &lt;br /&gt;Created 24 July 2009    &lt;br /&gt;NS45.DOMAINCONTROL.COM    &lt;br /&gt;NS46.DOMAINCONTROL.COM &lt;/p&gt;  &lt;p&gt;IP: 68.178.232.100 (shares IP with 11,039,738 other sites) &lt;/p&gt;  &lt;p&gt;Registrant:   &lt;br /&gt;&lt;strong&gt;Modena Inc&lt;/strong&gt; (domains@modenainc.com) (associated with 102 domains)    &lt;br /&gt;921 SW Washington Street    &lt;br /&gt;Suite 228    &lt;br /&gt;Portland, Oregon 97205 &lt;/p&gt;  &lt;p&gt;***** &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;pussbanner769.info&lt;/strong&gt;    &lt;br /&gt;ICANN Registrar: GODADDY.COM, INC    &lt;br /&gt;Created 7 August 2009    &lt;br /&gt;NS47.DOMAINCONTROL.COM    &lt;br /&gt;NS48.DOMAINCONTROL.COM &lt;/p&gt;  &lt;p&gt;IP: 68.178.232.100 (shares IP with 11,039,738 other sites) &lt;/p&gt;  &lt;p&gt;Registrant:   &lt;br /&gt;Domain Owner (trafficbuyer@gmail.com)    &lt;br /&gt;15156 SW 5th    &lt;br /&gt;Scottsdale    &lt;br /&gt;Arizona 85260    &lt;br /&gt;Tel: +1 8005551212 &lt;/p&gt;  &lt;p&gt;***** &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;blackwater-cuprumworks.net&lt;/strong&gt;    &lt;br /&gt;ICANN Registrar: DIRECTI    &lt;br /&gt;Created 7 September 2009    &lt;br /&gt;NS1.EVERYDNS.NET    &lt;br /&gt;NS2.EVERYDNS.NET &lt;/p&gt;  &lt;p&gt;IP: 213.155.2.112 - Namibia, Grinvich3, Vladimir Gubarenko &lt;/p&gt;  &lt;p&gt;Shares IP with the domains aw-work.net, awirons-work.com, sexamateur-hartcore.com and sleazy-dreamers.net &lt;/p&gt;  &lt;p&gt;Registrant:   &lt;br /&gt;Eduard Skobelev (eddiscobbi3@gmail.com)    &lt;br /&gt;ul. Starinskaya, d.1, kv. 92    &lt;br /&gt;g. Moskva    &lt;br /&gt;g. Moskva, 107009    &lt;br /&gt;RU    &lt;br /&gt;Tel: +7 4952243948 &lt;/p&gt;  &lt;p&gt;***** &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;masterwood-works.com&lt;/strong&gt;    &lt;br /&gt;ICANN Registrar: NETWORK SOLUTIONS, LLC.    &lt;br /&gt;Created 19 February 1999    &lt;br /&gt;NS.WVT.NET    &lt;br /&gt;NS2.WVT.NET &lt;/p&gt;  &lt;p&gt;IP: 65.36.167.73 - Delaware, Newark, Hostmysite &lt;/p&gt;  &lt;p&gt;Shares IP with 395 other sites &lt;/p&gt;  &lt;p&gt;Registrant:   &lt;br /&gt;Master Wood-Works    &lt;br /&gt;4526 Olentangy River Road    &lt;br /&gt;Delaware, OH 43015    &lt;br /&gt;US &lt;/p&gt;  &lt;p&gt;Admin:   &lt;br /&gt;Steve Krengel (hostmaster@wvt.net) &lt;/p&gt;  &lt;p&gt;***** &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;bintus-bahi.cn&lt;/strong&gt;    &lt;br /&gt;ICANN Registrar: Chinese    &lt;br /&gt;Created 15 August 2009    &lt;br /&gt;NS1.EVERYDNS.NET    &lt;br /&gt;NS2.EVERYDNS.NET    &lt;br /&gt;NS3.EVERYDNS.NET    &lt;br /&gt;NS4.EVERYDNS.NET &lt;/p&gt;  &lt;p&gt;IP: 61.235.117.72 - Guangdong, Shenzen, China Railcom Guangdong Shenzhen Subbranch &lt;/p&gt;  &lt;p&gt;Registrant:   &lt;br /&gt;Cehhost, inc (owns about 84 other domains)    &lt;br /&gt;Lucas Steven (steven_lucas_2000@yahoo.com)&lt;/p&gt;  &lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;margin:10px 20px 20px 0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/1565.image_5F00_0E68EB58.png" width="1012" height="462" /&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1722754" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Vulnerabilities_2C00_+viruses+and+exploits/default.aspx">Vulnerabilities, viruses and exploits</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category></item><item><title>Alert: please treat content from kennedales.com with extreme caution</title><link>http://msmvps.com/blogs/spywaresucks/archive/2009/09/11/1722477.aspx</link><pubDate>Fri, 11 Sep 2009 01:43:01 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1722477</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1722477</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/09/11/1722477.aspx#comments</comments><description>&lt;p&gt;   &lt;br /&gt;I have received information that kennedales.com has been implicated in a malvertizing incident.&amp;#160; &lt;/p&gt;  &lt;p&gt;I noted in &lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2009/09/10/1722200.aspx" target="_blank"&gt;my last blog post&lt;/a&gt; that kennedales.com shares IP address with two other domains that have already been caught facilitating malvertizing but at that time had not received intelligence indicating that kennedales.com was also involved.&lt;/p&gt;  &lt;p&gt;   &lt;br /&gt;Now we know that it is.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1722477" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category></item><item><title>Another two bad domains: newadsresults.com and waveadvert.com</title><link>http://msmvps.com/blogs/spywaresucks/archive/2009/09/10/1722200.aspx</link><pubDate>Thu, 10 Sep 2009 01:30:20 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1722200</guid><dc:creator>sandi</dc:creator><slash:comments>2</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1722200</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/09/10/1722200.aspx#comments</comments><description>&lt;p&gt;Seen distributing malvertizing at starnewsonline.com:    &lt;br /&gt;&lt;a title="http://forums.starnewsonline.com/eve/forums/a/tpc/f/6431032365/m/7121097019/r/9841029019" href="http://forums.starnewsonline.com/eve/forums/a/tpc/f/6431032365/m/7121097019/r/9841029019" target="_blank"&gt;http://forums.starnewsonline.com/eve/forums/a/tpc/f/6431032365/m/7121097019/r/9841029019&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;And collegehumor.com:    &lt;br /&gt;&lt;a title="http://www.facebook.co.za/CollegeHumor" href="http://www.facebook.co.za/CollegeHumor" target="_blank"&gt;http://www.facebook.co.za/CollegeHumor&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;And tigerdroppings.com:    &lt;br /&gt;&lt;a href="http://www.tigerdroppings.com/rant/messagetopic.asp?p=14780012&amp;amp;pg=1" target="_blank"&gt;http://www.tigerdroppings.com/rant/messagetopic.asp?p=14780012&amp;amp;pg=1&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;And basilmarket.com (page doesn&amp;#39;t load, but you can find it in Google cache):    &lt;br /&gt;&lt;a href="http://www.basilmarket.com/forum/1184277/2" target="_blank"&gt;http://www.basilmarket.com/forum/1184277/2&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;newadsresults.com&lt;/strong&gt;     &lt;br /&gt;ICANN Registrar: BIZCN.COM, INC.     &lt;br /&gt;Created 21 July 2009     &lt;br /&gt;NS1.EVERYDNS.NET     &lt;br /&gt;NS2.EVERYDNS.NET &lt;/p&gt;  &lt;p&gt;IP: 212.117.166.69 (Luxembourg, Root Esolutions) &lt;/p&gt;  &lt;p&gt;Shares IP with two other domains, kennedales.com and waveadvert.com &lt;/p&gt;  &lt;p&gt;Registrant:    &lt;br /&gt;RJ     &lt;br /&gt;Rita Johnson (ritaj@gmail.com)     &lt;br /&gt;4122082301 fax: 4122082301     &lt;br /&gt;101 Bellevue Road     &lt;br /&gt;Pittsburgh PA 15229     &lt;br /&gt;US &lt;/p&gt;  &lt;p&gt;***** &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;kennedales.com&lt;/strong&gt;     &lt;br /&gt;ICANN Registrar: BIZCN.COM, INC     &lt;br /&gt;Created 14 August 2009     &lt;br /&gt;NS1.EVERYDNS.NET     &lt;br /&gt;NS2.EVERYDNS.NET &lt;/p&gt;  &lt;p&gt;IP: 212.117.166.69 (Luxembourg, Root Esolutions) &lt;/p&gt;  &lt;p&gt;Registrant:    &lt;br /&gt;kennedales.com     &lt;br /&gt;Jonathan Nelson (admin@kennedales.com)     &lt;br /&gt;812-750-2673 fax: 812-750-2673     &lt;br /&gt;1370 Heliport Loop     &lt;br /&gt;Bloomington IN 47404     &lt;br /&gt;US &lt;/p&gt;  &lt;p&gt;***** &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;waveadvert.com      &lt;br /&gt;&lt;/strong&gt;ICANN Registrar: BIZCN.COM, INC.     &lt;br /&gt;Created 4 August 2009     &lt;br /&gt;NS1.EVERYDNS.NET     &lt;br /&gt;NS2.EVERYDNS.NET &lt;/p&gt;  &lt;p&gt;IP: 212.117.166.69 (Luxembourg, Root Esolutions) &lt;/p&gt;  &lt;p&gt;Registrant:    &lt;br /&gt;Premier ANC     &lt;br /&gt;Linda Hogan (lindahg@yahoo.com)     &lt;br /&gt;6788081308 fax: 6788081308     &lt;br /&gt;4495 Atlanta Hwy     &lt;br /&gt;Atlanta GA 30052     &lt;br /&gt;US &lt;/p&gt;  &lt;p&gt;Note waveadvert.com’s involvement in malvertizing incidents at blogspot.com:    &lt;br /&gt;&lt;a title="http://google.com/safebrowsing/diagnostic?site=waveadvert.com/&amp;amp;hl=en-gb" href="http://google.com/safebrowsing/diagnostic?site=waveadvert.com/&amp;amp;hl=en-gb" target="_blank"&gt;http://google.com/safebrowsing/diagnostic?site=waveadvert.com/&amp;amp;hl=en-gb&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;And a problem at mangafox:    &lt;br /&gt;&lt;a title="http://forums.mangafox.com/showthread.php?p=2507674" href="http://forums.mangafox.com/showthread.php?p=2507674" target="_blank"&gt;http://forums.mangafox.com/showthread.php?p=2507674&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1722200" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category></item><item><title>ALERT: The gogomediacenter.com incidents continue</title><link>http://msmvps.com/blogs/spywaresucks/archive/2009/09/06/1721130.aspx</link><pubDate>Sun, 06 Sep 2009 09:53:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1721130</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1721130</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/09/06/1721130.aspx#comments</comments><description>&lt;p&gt;&lt;img height="128" width="585" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/7433.image_5F00_22B071D5.png" alt="image" border="0" title="image" style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" /&gt;&lt;img height="508" width="500" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/3704.image_5F00_31E96B53.png" align="left" alt="image" border="0" title="image" style="border-bottom:0px;border-left:0px;margin:10px 15px 15px 0px;display:inline;border-top:0px;border-right:0px;" /&gt;&amp;nbsp; &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;I have a few more domains for you&amp;hellip;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;mediadison.com &lt;br /&gt;&lt;/strong&gt;ICANN Registrar: BIZCN.COM, INC &lt;br /&gt;Created 6 July 2009 &lt;/p&gt;
&lt;p&gt;IP: 212.117.166.77, Luxembourg, Root Esolutions &lt;/p&gt;
&lt;p&gt;Sharing IP with the following domains, all of which should be treated with extreme caution: &lt;/p&gt;
&lt;p&gt;2ez4clicks.com, denrifiox.com, monsteradhost.com, newage-advertising.com, profitgainerz.com, ranparetc.com, s7atwola.com, scheuvronts.com, smartadvertisment.net, westernadrix.com &lt;/p&gt;
&lt;p&gt;Registrant: &lt;br /&gt;Solaris Co &lt;br /&gt;Jack Thompson (jthompson@yahoo.com) &lt;br /&gt;4049422100 fax: 4049422100 &lt;br /&gt;1921 Monroe Drive &lt;br /&gt;Atlanta GA 30324 &lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;stopdrugstoday.cn&lt;/strong&gt; &lt;br /&gt;ICANN Registrar (Chinese) &lt;br /&gt;Created 1 September 2009 &lt;/p&gt;
&lt;p&gt;IP: 83.133.126.155 - Germany, Lncde-greatnet-newmedia &lt;/p&gt;
&lt;p&gt;Registrant administrative email: webmaster@tangodance.cn &lt;/p&gt;
&lt;p&gt;By the way, we should revisit gogomediacenter.com - there have been some changes since I last posted with some new domains appearing at its IP address: &lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;gogomediacenter.com&lt;/strong&gt; &lt;br /&gt;ICANN Registrar: BIZCN.COM, INC &lt;br /&gt;Created 26 August 2008 &lt;/p&gt;
&lt;p&gt;IP: 212.117.166.75 - Luxembourg, Root Esolutions &lt;/p&gt;
&lt;p&gt;Shares IP with the domains bestmediamind.com, fastdns-ms7.com, jetfastads.com, pro-drugstore.com, query2feed.com, tdshosterserv8.com and yakaboopromo.com (all domains should be treated with extreme caution). &lt;/p&gt;
&lt;p&gt;Registrant: &lt;br /&gt;Mediaswan &lt;br /&gt;Frank Roberts (frank@mailqueen.com) &lt;br /&gt;2128054649 fax: 2128054649 &lt;br /&gt;2130 Small Street &lt;br /&gt;New York, NY 10007 &lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1721130" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category></item><item><title>ALERT: Please treat the domains gogomediacenter.com, sys17media.com and praharesorts.cn with extreme caution</title><link>http://msmvps.com/blogs/spywaresucks/archive/2009/09/04/1720667.aspx</link><pubDate>Fri, 04 Sep 2009 09:15:39 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1720667</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1720667</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/09/04/1720667.aspx#comments</comments><description>&lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" title="Sketchers malvertizement" border="0" alt="Sketchers malvertizement" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/8037.image_5F00_6931FA63.png" width="749" height="112" /&gt;     &lt;br /&gt;&lt;/p&gt;  &lt;p&gt;It is very interesting to watch the modus operandi that the bad guys are using change.&lt;/p&gt;  &lt;p&gt;This malvertizement was NOT seen on a web page; rather it was being displayed by an advertising supported freeware application.&lt;/p&gt;  &lt;p&gt;The trouble starts when an ad.yieldmanager.com GET retrieves content, in an iframe, from the domain &amp;quot;gogomediacenter.com&amp;quot;.&amp;#160; The content served up by gogomediacenter.com is an innocent &amp;quot;skechers” JPG (which is the advertisement itself), but it also serves up a little something extra...&lt;/p&gt;  &lt;p&gt;&lt;img style="display:inline;" title="image" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/2677.image_5F00_160B7160.png" width="861" height="445" /&gt; &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Note the two areas of code highlighted by the arrows.&amp;#160; I find it interesting that the miscreants are going to the trouble of using some (basic) encoding.&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;If we decode the script at the end, we get this:&lt;/p&gt;  &lt;p&gt;&lt;img style="display:inline;" title="image" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/6787.image_5F00_667504E6.png" width="242" height="62" /&gt; &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Again, there is a little bit of (basic) encoding to get rid of, which leaves us with this:&lt;/p&gt;  &lt;p&gt;&lt;img style="display:inline;" title="image" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/0523.image_5F00_7134ECEC.png" width="896" height="18" /&gt; &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Another interesting thing to note about this particular incident is that the malicious code only seems to appear &lt;strong&gt;&lt;em&gt;once per IP address&lt;/em&gt;&lt;/strong&gt;.&amp;#160; If I nuke the sandbox I am using, the redirect does not recur, but if I change my IP address, then I can reproduce the redirect as often as I wish.&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Ok, so let’s take a look at these new domains, gogomediacenter.com, sys17med.com and praharesorts.cn.&amp;#160; I think we can say that Root Esolutions, Luxembourg is turning into a bit of a cesspool, and yes, it is the same IP range as the domains revealed in &lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2009/09/04/1720609.aspx" target="_blank"&gt;my earlier blog post&lt;/a&gt; :(&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;gogomediacenter.com&lt;/strong&gt;    &lt;br /&gt;ICANN Registrar: BIZCN.COM, INC    &lt;br /&gt;Created 26 August 2008 &lt;/p&gt;  &lt;p&gt;IP: 212.117.166.75 - Luxembourg, Root Esolutions &lt;/p&gt;  &lt;p&gt;Shares IP with the domains bestmediamind.com, pro-drugstore.com and yakaboopromo.com (all domains should be treated with extreme caution). &lt;/p&gt;  &lt;p&gt;Registrant:   &lt;br /&gt;Mediaswan    &lt;br /&gt;Frank Roberts (frank@mailqueen.com)    &lt;br /&gt;2128054649 fax: 2128054649    &lt;br /&gt;2130 Small Street    &lt;br /&gt;New York, NY 10007 &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;sys17media.com&lt;/strong&gt;    &lt;br /&gt;ICANN Registrar: BIZCN.COM, INC    &lt;br /&gt;Created 2 September 2009 &lt;/p&gt;  &lt;p&gt;IP: 212.117.166.70 - Luxembourg, Root Esolutions &lt;/p&gt;  &lt;p&gt;Shares IP with the domains doubleclick-ssl.com and verilline.com (both domains should be treated with extreme caution). &lt;/p&gt;  &lt;p&gt;Registrant:   &lt;br /&gt;DNS Admin (d71245@registar.com)    &lt;br /&gt;580-433-9026 fax: 580-433-9026    &lt;br /&gt;2654 Cody Ridge Rd    &lt;br /&gt;Clinton OK 73601 &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;praharesorts.cn&lt;/strong&gt;    &lt;br /&gt;ICANN Registrar (Chinese)    &lt;br /&gt;Created 28 August 2009 &lt;/p&gt;  &lt;p&gt;IP: 83.133.126.155 - Lncde-greatnet-newmedia, Germany &lt;/p&gt;  &lt;p&gt;Administrative email: webmaster@seniorstuds.com.ar (no such domain) &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;bestmediamind.com&lt;/strong&gt;    &lt;br /&gt;ICANN Registrar: BIZCN.COM, INC    &lt;br /&gt;Created 26 June 2009 &lt;/p&gt;  &lt;p&gt;IP: 212.117.166.75 - Luxembourg, Root Esolutions &lt;/p&gt;  &lt;p&gt;Registrant:   &lt;br /&gt;Bob Robertson (bobrobertsonscmpbst@gmail.com)    &lt;br /&gt;6172679396    &lt;br /&gt;159 Newbury Street    &lt;br /&gt;Boston, MA 02116 &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;yakaboopromo.com     &lt;br /&gt;&lt;/strong&gt;ICANN Registrar: BIZCN.COM, INC    &lt;br /&gt;Created 26 June 2009 &lt;/p&gt;  &lt;p&gt;IP: 212.117.166.75 - Luxembourg, Root Esolutions &lt;/p&gt;  &lt;p&gt;Registrant:   &lt;br /&gt;John Robertson (johnrobertsoncmpbst@gmail.com)    &lt;br /&gt;6172679396    &lt;br /&gt;159 Newbury Street    &lt;br /&gt;Boston MA 02116 &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;pro-drugstore.com     &lt;br /&gt;&lt;/strong&gt;ICANN Registrar: ENOM, INC    &lt;br /&gt;Created 29 January 2009 &lt;/p&gt;  &lt;p&gt;IP: 212.117.166.75 - Luxembourg, Root Esolutions &lt;/p&gt;  &lt;p&gt;Registration service contact director@climbing-games.com (regular readers of this blog will recognise that email address) &lt;/p&gt;  &lt;p&gt;Registrant:   &lt;br /&gt;Jack Hum (no email)    &lt;br /&gt;208 W. 1st St. CA 90012    &lt;br /&gt;Los Angeles 90012    &lt;br /&gt;Tel: +1 2338824832 &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;doubleclick-ssl.com&lt;/strong&gt;    &lt;br /&gt;ICANN Registrar: BIZCN.COM, INC    &lt;br /&gt;Created 20 August 2009 &lt;/p&gt;  &lt;p&gt;IP: 212.117.166.70 - Luxembourg, Root Esolutions &lt;/p&gt;  &lt;p&gt;Registrant:   &lt;br /&gt;doubleclick-ssl.com    &lt;br /&gt;Carolyn Hooley (carolyn@doubleclick-ssl.com)    &lt;br /&gt;845-223-3913 fax: 845-223-3913    &lt;br /&gt;4619 Camdem Place    &lt;br /&gt;Lagrangeville NY 12540 &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;verilline.com&lt;/strong&gt;    &lt;br /&gt;ICANN Registrar: BIZCN.COM, INC    &lt;br /&gt;Created 29 July 2009 &lt;/p&gt;  &lt;p&gt;IP: 212.117.166.70 - Luxembourg, Root Esolutions &lt;/p&gt;  &lt;p&gt;Registrant:   &lt;br /&gt;Lithpro Co    &lt;br /&gt;Linda Thompson (info@lithpro.com)    &lt;br /&gt;3037989467 fax: 3037989467    &lt;br /&gt;2600 W 104th Ave    &lt;br /&gt;Boston CO 80234 &lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1720667" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category></item><item><title>ALERT: Impersonation of legitimate advertising networks and companies</title><link>http://msmvps.com/blogs/spywaresucks/archive/2009/09/04/1720609.aspx</link><pubDate>Fri, 04 Sep 2009 03:18:25 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1720609</guid><dc:creator>sandi</dc:creator><slash:comments>3</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1720609</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/09/04/1720609.aspx#comments</comments><description>&lt;p&gt;This investigation began after I was alerted to the fact that somebody has been posing as a Vonage representative, and using the domain &lt;strong&gt;vonage-inc.com&lt;/strong&gt; while doing so.&lt;/p&gt;  &lt;p&gt;The domain vonage-inc.com was created on 5 August 2009, and the ICANN Registrar is BIZCN.COM, Inc.&amp;#160; It is hosted by Root Esolutions, Luxembourg (IP address 212.117.166.71). &lt;/p&gt;  &lt;p&gt;Registrant details: &lt;/p&gt;  &lt;p&gt;Vonage-Inc    &lt;br /&gt;Domain Administrator (itadmin@vonage-inc.com)     &lt;br /&gt;7322643911 fax 7322643911     &lt;br /&gt;4 South Holmdel Road     &lt;br /&gt;Holmdel NJ 07733&lt;/p&gt;  &lt;p&gt;Interestingly, it looks like Vonage may have already taken control of vonage-inc.com.&amp;#160; This is because domaintools.com reports that vonage-inc.com has an IP address of 212.117.166.71, and that it is using the name servers NS1.EVERYDNS.NET and NS2.EVERYDNS.NET but Robtex, on the other hand, reports that vonage-inc.com no longer has an IP address, and that it is using the name servers dns-auth-00.kewr0.s.vonagenetworks.net. dns-auth-00.kiad0.s.vonagenetworks.net. dns-auth-00.klax1.s.vonagenetworks.net and dns-auth-00.klga1.s.vonagenetworks.net.&lt;/p&gt;  &lt;p&gt;My grateful thanks go to the gentleman who alerted me to the goings-on involving vonage-inc.com.&amp;#160; His alert has led to the exposure of several other domains are could also be used to impersonate legitimate companies.&lt;/p&gt;  &lt;p&gt;Several other domains can be found at same IP address that vonage-inc.com was using (212.117.166.71).&amp;#160; All of the domains should be treated with extreme caution.&amp;#160; When we bear in mind the warning that somebody has been posing as a Vonage representative while using the domain vonage-inc.com, I think it is safe to assume that somebody is planning to pose as (or is already posing as) a representative of Adconion, Carat, Fox Media, Lacoste, Orange or Pubmatic.&lt;/p&gt;  &lt;p&gt;Here are details of other domains at IP 212.117.166.71 as at time of writing.&amp;#160; All but one are redirecting visitors to other, legitimate, domains.&amp;#160; &lt;/p&gt;  &lt;p&gt;You will note that all of the domains, bar one, have the same ICANN Registrar, being BIZCN.COM, INC.&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;adconion-inc.com      &lt;br /&gt;&lt;/strong&gt;ICANN Registrar: BIZCN.COM, Inc     &lt;br /&gt;Created 10 Aug 2009     &lt;br /&gt;Registrant:     &lt;br /&gt;adconion-inc.com     &lt;br /&gt;IT Admin (admin@adconion-inc.com)     &lt;br /&gt;498951490701 fax: 498951490701     &lt;br /&gt;Bayerstrasse 41     &lt;br /&gt;Muenchen Bavaria 80335 &lt;/p&gt;  &lt;p&gt;adconion-inc.com is currently redirecting visitors to the legitimate domain adconion.com (IP 89.110.133.18, ICANN Registrar Ascio Technologies, Inc, Registrant address Lindwurmstr.114, Muenchen, Bavaria 80337) &lt;/p&gt;  &lt;p&gt;***** &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;adjimbo.com&lt;/strong&gt;     &lt;br /&gt;ICANN Registrar: BIZCN.COM, Inc.     &lt;br /&gt;Created 9 June 2009 &lt;/p&gt;  &lt;p&gt;Registrant:    &lt;br /&gt;Registar services Co     &lt;br /&gt;Jack Omands (jacksosomands@gmail.com)     &lt;br /&gt;352691787     &lt;br /&gt;10 rue Large     &lt;br /&gt;Luxembourg Luxembourg 1918 &lt;/p&gt;  &lt;p&gt;Address as per web site: 260 Peachtree street, Suite 2200, Atlanta, Georgia 30303, US &lt;/p&gt;  &lt;p&gt;Note: 260 Peachtree Street, Suite 2200, is a Regus property.&amp;#160; Regus operates business centres, virtual offices, virtual PA&amp;#39;s etc. &lt;/p&gt;  &lt;p&gt;***** &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;carat-inc.com&lt;/strong&gt;     &lt;br /&gt;ICANN Registrar: BIZCN.COM, INC     &lt;br /&gt;Created 10 August 2009 &lt;/p&gt;  &lt;p&gt;Registrant:    &lt;br /&gt;Carat-inc.com     &lt;br /&gt;IT Administrator (admin@carat-inc.com)     &lt;br /&gt;441179045055 fax: 441179045055     &lt;br /&gt;90 Great Portland Street     &lt;br /&gt;London London W1W 5QZ &lt;/p&gt;  &lt;p&gt;carat-inc.com is currently redirecting visitors to the legitimate domain carat.com (IP 91.206.177.56, Aegis Group Plc, UK - ICANN Registrar GROUP NBT PLC AKA NETNAMES, Registrant: Aegis Group plc, 180 Great Portland Street, London W1W 5QZ) &lt;/p&gt;  &lt;p&gt;***** &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;foxinteractivemedia-inc.com      &lt;br /&gt;&lt;/strong&gt;ICANN Registrar: BIZCN.COM, INC     &lt;br /&gt;Created 10 August 2009 &lt;/p&gt;  &lt;p&gt;Registrant:    &lt;br /&gt;domain admin (admin@foxinteractivemedia-inc.com)     &lt;br /&gt;3102750087 fax: 3102750087     &lt;br /&gt;424 N. Beverly Dr     &lt;br /&gt;Beverly Hills CA 90210 &lt;/p&gt;  &lt;p&gt;foxinteractivemedia-inc.com is currently redirecting visitors to the legitimate domain fox.com (IP 80.67.66.57, Akamai Technologies, ICANN Registrar MARKMONITOR, INC, Registrant address: Intellectual Property Department, Twentieth Century Fox Film Corporation, PO Box 900, Beverley Hills CA 90213-0900) &lt;/p&gt;  &lt;p&gt;***** &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;lacoste-ads.com&lt;/strong&gt; (note, we have encountered lacoste-ads.com before, as discussed here:     &lt;br /&gt;&lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2009/04/23/1690197.aspx)" target="_blank"&gt;http://msmvps.com/blogs/spywaresucks/archive/2009/04/23/1690197.aspx)&lt;/a&gt;     &lt;br /&gt;ICANN Registrar: NETFIRMS, INC     &lt;br /&gt;Created 2 March 2009     &lt;br /&gt;Registrant details hidden behind a WHOIS privacy protection service (Domain Privacy Group) &lt;/p&gt;  &lt;p&gt;lacoste-ads.com is currently redirecting visitors to the legitimate domain lacoste.com (IP 199.93.55.126, ICANN Registrar Core Internet Council of Registrars, Registrant VIAL TRIBOULET catherine, Lacoste S.A., 8 rue de Castiglione, Paris) &lt;/p&gt;  &lt;p&gt;***** &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;orangeadvertising-inc.com&lt;/strong&gt;     &lt;br /&gt;ICANN Registrar: BIZCN.COM, INC     &lt;br /&gt;Created 10 August 2009 &lt;/p&gt;  &lt;p&gt;Registrant:    &lt;br /&gt;Orangeadvertising     &lt;br /&gt;Network Administrator: admin@orangeadvertising.us     &lt;br /&gt;441179045053 fax: 441179045053     &lt;br /&gt;6400 North Radcliffe St     &lt;br /&gt;Bristol Bristol BS9 4AU     &lt;br /&gt;GB &lt;/p&gt;  &lt;p&gt;orangeadvertising-inc.com is currently redirecting visitors to the legitimate domain orange.com (IP 194.2.208.16, Telecom France, Registrant: Orange Personal Communications Services Limited, St James Court, Great Park Road, Almondbury Park, Bradley Stoke, Bristol, UK, Tel: ) &lt;/p&gt;  &lt;p&gt;Note: the domain orangeadvertising.us (used for the Network Administrator&amp;#39;s contact email address) has never been registered. &lt;/p&gt;  &lt;p&gt;***** &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;pubmatic-inc.com&lt;/strong&gt;     &lt;br /&gt;ICANN Registrar: BIZCN.COM, INC     &lt;br /&gt;Created 10 August 2009 &lt;/p&gt;  &lt;p&gt;Registrant:    &lt;br /&gt;IT Admin (itadmin@pubmatic-inc.com)     &lt;br /&gt;6508562386 fax: 6508562386     &lt;br /&gt;675 El Camino Real     &lt;br /&gt;Palo Alto CA 94301 &lt;/p&gt;  &lt;p&gt;pubmatic-inc.com is currently redirecting visitors to the legitimate pubmatic.com (IP 69.163.146.58, New Dream Network Llc, California, Registrant: Pubmatic, Inc, PO Box 975, Palo Alto, CA 94302)&lt;/p&gt;  &lt;p&gt;*******************************&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Other domains in the same IP range:&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;IP: 212.117.166.74&lt;/strong&gt; &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;brightadsnetwork.com&lt;/strong&gt; (visually almost identical to adjimbo.com – see above)     &lt;br /&gt;Address as per web site: 2115 North Charles Street, North Baltimore     &lt;br /&gt;ICANN Registrar: BIZCN.COM, INC     &lt;br /&gt;Created 14 June 2009 &lt;/p&gt;  &lt;p&gt;Registrant:    &lt;br /&gt;RegServ Co     &lt;br /&gt;Norman Jason (normanjason01223@gmail.com)     &lt;br /&gt;2127340192     &lt;br /&gt;20 Washington Street     &lt;br /&gt;New York New York 10006 &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;topleanpro.com&lt;/strong&gt;     &lt;br /&gt;ICANN Registrar: BIZCN.COM, INC     &lt;br /&gt;Created 18 June 2009 &lt;/p&gt;  &lt;p&gt;Registrant:    &lt;br /&gt;Domains Inform Inc     &lt;br /&gt;Thomas Kleineberg (thomaskleinebergdomains@gmail.com)     &lt;br /&gt;498999216255     &lt;br /&gt;Maximillianstrasse 18     &lt;br /&gt;Munich Munich 80539 &lt;/p&gt;  &lt;p&gt;*****&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;IP: 212.117.166.73&lt;/strong&gt; &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;ad-advanced.com&lt;/strong&gt; (address as per web site is Suite 300, 8875 Hidden River Parkway, Tampa which is a Regus asset) &lt;/p&gt;  &lt;p&gt;ICANN Registrar: BIZCN.COM, INC    &lt;br /&gt;Created 1 July 2009 &lt;/p&gt;  &lt;p&gt;Registrant:    &lt;br /&gt;Norman Sebring (nsebring@rit-consulting.com)     &lt;br /&gt;5116 New Centre Drive     &lt;br /&gt;WILMINGTON NC 28403 &lt;/p&gt;  &lt;p&gt;***** &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;dnzmg.com&lt;/strong&gt; (web site address Suite 410, 6802 Paragon Place, Richmond, Virginia - another Regus asset) &lt;/p&gt;  &lt;p&gt;ICANN Registrar: BIZCN.COM, INC    &lt;br /&gt;Created 1 July 2009 &lt;/p&gt;  &lt;p&gt;Registrant:    &lt;br /&gt;Magnetic Wave     &lt;br /&gt;Daryl Lewis (markstein@mwa.com)     &lt;br /&gt;3035568550 fax: 3035568550     &lt;br /&gt;235 Columbine Street     &lt;br /&gt;Denver CO 80206 &lt;/p&gt;  &lt;p&gt;***** &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;vertixgroup.com&lt;/strong&gt; (web site address 3525 Piedmont Road, 7 Piedmont Center, Atlanta - this address is for the HP Business Centre, a member of the Regus Group Network) &lt;/p&gt;  &lt;p&gt;ICANN Registrar: BIZCN.COM, INC    &lt;br /&gt;Created 1 July 2009 &lt;/p&gt;  &lt;p&gt;Registrant:    &lt;br /&gt;Mark Stein (pholexkapsilow@gmail.com) (Mark Stein again? See Daryl Lewis email above)     &lt;br /&gt;2158554688 fax: 2158554688     &lt;br /&gt;1202 Market Street     &lt;br /&gt;Philadelphia PA 19107 &lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1720609" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category></item><item><title>ALERT: More malvertizing via Facebook applications?</title><link>http://msmvps.com/blogs/spywaresucks/archive/2009/08/25/1718057.aspx</link><pubDate>Tue, 25 Aug 2009 07:37:20 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1718057</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1718057</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/08/25/1718057.aspx#comments</comments><description>&lt;p&gt;Last time it was “Human Gifts” (aka Owned) that I wrote about on August 3:   &lt;br /&gt;&lt;a title="ALERT- Malvertizing on Facebook and gaiaonline.com" href="http://msmvps.com/blogs/spywaresucks/archive/2009/08/03/1712174.aspx" target="_blank"&gt;ALERT- Malvertizing on Facebook and gaiaonline.com&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;This time it is the “We’re Related” application – an incident reported on August 18   &lt;br /&gt;&lt;a href="http://community.tigranetworks.co.uk/blogs/tim_long/archive/2009/08/18/drive-by-downloads-from-facebook.aspx" target="_blank"&gt;http://community.tigranetworks.co.uk/blogs/tim_long/archive/2009/08/18/drive-by-downloads-from-facebook.aspx&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;And, according to a family member, her web browser’s security filter blocked her web browser from accessing something when playing Bubbletown (I quote: “a big red page came up”).&amp;#160; Something was going on there too.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1718057" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category></item><item><title>Malvertizement featuring careerbuilder.com</title><link>http://msmvps.com/blogs/spywaresucks/archive/2009/08/20/1716839.aspx</link><pubDate>Thu, 20 Aug 2009 12:12:47 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1716839</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1716839</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/08/20/1716839.aspx#comments</comments><description>&lt;p&gt;Thankfully it tries to load content from a known bad domain that is not responding.&lt;/p&gt;  &lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/0412.image_5F00_21E55324.png" width="329" height="272" /&gt;&amp;#160;&amp;#160; &lt;img style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/1007.image_5F00_606D317B.png" width="327" height="273" /&gt; &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/2577.image_5F00_3B7201B3.png" width="327" height="274" /&gt;&amp;#160;&amp;#160; &lt;img style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/4212.image_5F00_7A6612FF.png" width="328" height="234" /&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1716839" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category></item><item><title>FTC versus Innovative Marketing et al – developments: Innovative Marketing and Daniel Sundin</title><link>http://msmvps.com/blogs/spywaresucks/archive/2009/08/12/1714996.aspx</link><pubDate>Wed, 12 Aug 2009 03:37:43 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1714996</guid><dc:creator>sandi</dc:creator><slash:comments>1</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1714996</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/08/12/1714996.aspx#comments</comments><description>&lt;p&gt;An Order of Default was entered against Innovative Marketing and Daniel Sundin on 6 August 2009 “&lt;em&gt;&lt;strong&gt;for want of answer or other defense&lt;/strong&gt;”&lt;/em&gt;.&lt;/p&gt;  &lt;p&gt;Regular readers will know that Innovative Marketing and Daniel Sundin have ignored the FTC action right from the start, and are unrepresented.&amp;#160; Innovative Marketing is meant to be paying a fine to the Court of $8,000 per day.&amp;#160; I have found nothing to indicate that they have paid anything at all.&lt;/p&gt;  &lt;p&gt;Maurice D’Souza has finally entered a defense (which follows pretty much the same theme as those lodged by other defendants).&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1714996" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Fraudware/default.aspx">Fraudware</category></item><item><title>Malvertizement featuring TravelRes</title><link>http://msmvps.com/blogs/spywaresucks/archive/2009/08/11/1714840.aspx</link><pubDate>Tue, 11 Aug 2009 02:00:54 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1714840</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1714840</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/08/11/1714840.aspx#comments</comments><description>&lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/3716.image_5F00_185D7B1E.png" width="751" height="113" /&gt; &lt;/p&gt;  &lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/6355.image_5F00_5E70C8E2.png" width="751" height="114" /&gt; &lt;/p&gt;  &lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/2543.image_5F00_28FD281F.png" width="751" height="114" /&gt; &lt;/p&gt;  &lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/6763.image_5F00_258127E6.png" width="751" height="113" /&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;The malvertizement attempted to load a &lt;strong&gt;clickrevenue.info&lt;/strong&gt; URL, and features the now familiar ‘dynamic text’:&lt;/p&gt;  &lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;margin:10px 20px 20px 0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" align="left" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/4705.image_5F00_6CF8987C.png" width="470" height="241" /&gt; &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;clickrevenue.info&lt;/strong&gt;    &lt;br /&gt;ICANN Registrar: REGTIME LTD    &lt;br /&gt;Created 21 July 2009    &lt;br /&gt;NS1.NAMESELF.COM (89.108.122.149 - Agava) (195.161.113.218 - RTCOMM, Russia)    &lt;br /&gt;NS2.NAMESELF.COM (89.108.122.120.153 - Agava) (217.16.27.38 - MASTERHOST, Russia) &lt;/p&gt;  &lt;p&gt;IP:&amp;#160; 89.149.243.28 - Berlin, Netdirekt E.k &lt;/p&gt;  &lt;p&gt;Registrant:   &lt;br /&gt;Paul McShane (paulmcshane@&lt;strong&gt;pisem.net&lt;/strong&gt;)    &lt;br /&gt;St Mainlow 212    &lt;br /&gt;San Jose CA 96014    &lt;br /&gt;Tel: +1 212 265 4785 &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;pisem.net&lt;/strong&gt; (Registrant email address)     &lt;br /&gt;ICANN Registrar: NETWORK SOLUTIONS, LLC.    &lt;br /&gt;Created 19 November 1999    &lt;br /&gt;NS1.POCHTA.RU    &lt;br /&gt;NS2.POCHTA.RU    &lt;br /&gt;NS3.POCUTA.RU &lt;/p&gt;  &lt;p&gt;IP: 82.204.219.251 - Moscow City, Pochta.ru Network &lt;/p&gt;  &lt;p&gt;Shares IP with chat-open.biz, chat-open.info, chat-open.net, chatopen.ru, fromru.com, fromru.su, front.ru, hotbox.ru, kaka.net.ru, krovatka.su, land.ru, lflirt.com, mail15.com, mail15.su, mail333.com, mail333.su, newmail.ru, nightmail.ru, nm.ru, pisem.su, pochta.com, pochta.ru, pochtamt.ru, pop3.ru, rbcmail.ru, smtp.ru, tosno-online.ru &lt;/p&gt;  &lt;p&gt;Registrant:   &lt;br /&gt;Ltd. Halverston Holdings Limited (hosting@hc.ru)    &lt;br /&gt;Drake Chambers, Tortola    &lt;br /&gt;Tortola 18502    &lt;br /&gt;VG    &lt;br /&gt;Tel: +7495 363 1111    &lt;br /&gt;Fax: +7495 363 1125&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1714840" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category></item><item><title>ALERT: Malvertizing on Facebook and gaiaonline.com</title><link>http://msmvps.com/blogs/spywaresucks/archive/2009/08/03/1712174.aspx</link><pubDate>Sun, 02 Aug 2009 15:28:18 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1712174</guid><dc:creator>sandi</dc:creator><slash:comments>4</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1712174</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/08/03/1712174.aspx#comments</comments><description>&lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/4657.image_5F00_5C6A4AB1.png" width="721" height="128" /&gt; &lt;/p&gt;  &lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/3681.image_5F00_6EDA4D79.png" width="721" height="128" /&gt; &lt;/p&gt;  &lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/6712.image_5F00_1468EC3D.png" width="721" height="128" /&gt; &lt;/p&gt;  &lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/0447.image_5F00_60596E4B.png" width="721" height="128" /&gt; &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;This investigation started after I read a report by a fellow member of the security community that his mother had called him downstairs &amp;quot;&lt;em&gt;because her screen had been filled with warnings and download boxes whilst she was on Facebook&amp;#39;s &amp;#39;Owned&amp;quot; site&amp;#39;&lt;/em&gt;&amp;quot;, and he asked for help to find the malvert.&amp;#160; I also saw on the GAIA site that lots of people were having problems with browser hijackings on that site, and that a poster&amp;#39;s &amp;quot;&lt;em&gt;mother just got the exact same redirection from Facebook&lt;/em&gt;&amp;quot;: &lt;/p&gt;  &lt;p&gt;&lt;a href="http://www.gaiaonline.com/forum/bug-reports-technical-support/help-redirected-slightly-different-than-the-scan-problem/t.52761261_31/" target="_blank"&gt;http://www.gaiaonline.com/forum/bug-reports-technical-support/help-redirected-slightly-different-than-the-scan-problem/t.52761261_31/&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Facebook incident: &lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;The malvertizement that I caught on Facebook was displayed with a Facebook application - apps.new.facebook.com/humangifts/.&lt;/p&gt;  &lt;p&gt;The domains involved in the hijack were &lt;strong&gt;apps3.coolapps.com, social.bidsystem.com, icon.cubics.com, ads.cubics.com, zamnadserver.com, internetnetworkads.com&lt;/strong&gt; and &lt;strong&gt;jessicasimpsonblog.cn&lt;/strong&gt; before the victim finally ends up at a fraudware site (screenshot of network sessions below). &lt;/p&gt;  &lt;p&gt;Facebook said on their blog on &lt;a href="http://blog.facebook.com/blog.php?post=110636457130" target="_blank"&gt;25 July 2009&lt;/a&gt; that advertising displayed by Facebook applications is &amp;quot;&lt;em&gt;not from Facebook but placed within applications by third parties&lt;/em&gt;&amp;quot;.&amp;#160; I suspect that Facebook will face an ongoing problem if they are going to allow “third parties” to independently source and manage advertising to display in conjunction with Facebook Applications. &lt;/p&gt;  &lt;p&gt;Malvertizement - ads.cubics.com/CubicsGraphicAd.axd?adid=101153&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;gaiaonline.com incident: &lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;The malvertizement that I saw on gaiaonline.com is visually identical, but some domains are different.&amp;#160; You will see that the bad SWF is coming from openx.org instead of cubics.com (screenshot of network sessions below). &lt;/p&gt;  &lt;p&gt;Malvertizement URL: c3.openx.org/416f7968fd52ccbf9686b55a6a85915c.swf&lt;/p&gt;  &lt;p&gt;Both malvertizements have been reported to the appropriate parties.&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;icons.cubics.com     &lt;br /&gt;ads.cubics.com      &lt;br /&gt;&lt;/strong&gt;ICANN Registrar: Network Solutions, LLC    &lt;br /&gt;Created 28 August 2004    &lt;br /&gt;NS: UDNS1.ULTRADNS.NET    &lt;br /&gt;NS: NDNS2.ULTRADNS.NET &lt;/p&gt;  &lt;p&gt;IP: 204.137.31.12 - Missouri, Kansas City, Adknowledge Inc &lt;/p&gt;  &lt;p&gt;Registrant:   &lt;br /&gt;Adknowledge    &lt;br /&gt;4600 Madison    &lt;br /&gt;Suite 1000    &lt;br /&gt;Kansas City, MO 64112    &lt;br /&gt;US &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;zamnadserver.com     &lt;br /&gt;&lt;/strong&gt;ICANN Registrar: HOOYOO (US) INC.    &lt;br /&gt;Created 6 May 2009    &lt;br /&gt;NS1.EVERYDNS.NET    &lt;br /&gt;NS2.EVERYDNS.NET    &lt;br /&gt;NS3.EVERYDNS.NET    &lt;br /&gt;NS4.EVERYDNS.NET &lt;/p&gt;  &lt;p&gt;IP: 94.76.213.227 - United Kingdom, Canonical Range for Hp3-right (Blueconnex Ltd) &lt;/p&gt;  &lt;p&gt;Registrant:   &lt;br /&gt;Giovanni Cattini (cattini@freebbmail.com    &lt;br /&gt;543 Ty Mair    &lt;br /&gt;Pembrokeshire Caldey Island SA70 7UJ    &lt;br /&gt;GB    &lt;br /&gt;44 183 484 4453 &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;internetnetworkads.com     &lt;br /&gt;&lt;/strong&gt;ICANN Registrar: DIRECTI    &lt;br /&gt;Created: 16 April 2009    &lt;br /&gt;NS1.REG.RU    &lt;br /&gt;NS2.REG.RU &lt;/p&gt;  &lt;p&gt;IP: 94.76.213.227 - United Kingdom, Canonical Range for Hp3-right (Blueconnex Ltd) &lt;/p&gt;  &lt;p&gt;Registrant:   &lt;br /&gt;Olivier Le Pord (shreeadarsha@gmail.com)    &lt;br /&gt;Unit No 6B, 6th Floor of M-6    &lt;br /&gt;New Delhi 11001    &lt;br /&gt;India    &lt;br /&gt;91 223 0611 555 &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;jessicasimpsonblog.cn     &lt;br /&gt;&lt;/strong&gt;ICANN Registrar: 广东时代互联科技有限公司    &lt;br /&gt;Created: 14 July 2009 &lt;/p&gt;  &lt;p&gt;IP: 78.47.91.155 - Berlin, Siarhei Shandrokha &lt;/p&gt;  &lt;p&gt;Sharing IP with bbcnewstyleguide.com, securingyourwebbrowser.com, brooklyn-bounty.com &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;antispywareliveproscannerv4.com     &lt;br /&gt;&lt;/strong&gt;ICANN Registrar: TODAYNIC.COM, INC    &lt;br /&gt;Created: 28 July 2009    &lt;br /&gt;NS1.EVERYDNS.NET    &lt;br /&gt;NS2.EVERYDNS.NET    &lt;br /&gt;NS3.EVERYDNS.NET    &lt;br /&gt;NS4.EVERYDNS.NET &lt;/p&gt;  &lt;p&gt;IP: No IP &lt;/p&gt;  &lt;p&gt;Registrant:   &lt;br /&gt;Wright S Diana (diana1982@yahoo.com)    &lt;br /&gt;2433 Lacy Lane    &lt;br /&gt;Carrollton    &lt;br /&gt;Texas, US, 75006&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;onlineproscanner.com     &lt;br /&gt;&lt;/strong&gt;ICANN Registrar: BIZCN.COM, INC    &lt;br /&gt;Created: 3 January 2009    &lt;br /&gt;NS1.EVERYDNS.NET    &lt;br /&gt;NS2.EVERYDNS.NET    &lt;br /&gt;NS3.EVERYDNS.NET    &lt;br /&gt;NS4.EVERYDNS.NET &lt;/p&gt;  &lt;p&gt;IP: 209.44.126.52 - Quebec, Laval, Netelligent Hosting Services Inc &lt;/p&gt;  &lt;p&gt;Shares IP address with mx052.belmony.com&lt;/p&gt;  &lt;p&gt;Registrant:   &lt;br /&gt;Igor Voloshin (addworld@freebbmail.com    &lt;br /&gt;ul. Vilkova 31-54    &lt;br /&gt;Moskva Moskovskay oblast 126108    &lt;br /&gt;+74952783443&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;img style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/0066.image_5F00_2E1A4621.png" width="775" height="470" /&gt; &lt;/p&gt;  &lt;p&gt;&amp;#160; &lt;img style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/8473.image_5F00_171607A9.png" width="777" height="673" /&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1712174" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Fraudware/default.aspx">Fraudware</category></item><item><title>FTC versus Innovative Marketing et al - developments re Sam Jain</title><link>http://msmvps.com/blogs/spywaresucks/archive/2009/07/30/1710850.aspx</link><pubDate>Thu, 30 Jul 2009 06:11:05 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1710850</guid><dc:creator>sandi</dc:creator><slash:comments>3</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1710850</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/07/30/1710850.aspx#comments</comments><description>&lt;p&gt;Regular readers of this blog will know that Sam Jain filed a motion for protective order requiring deposition to proceed by written questions, a motion which was DENIED on 22 July 2009. &lt;/p&gt;  &lt;p&gt;Sam Jain has now refused to be deposed, even refusing an offer from the FTC to be deposed by video-conference from a location of his choosing (an offer that was made by the FTC to allay any fears held by Jain that a deposition would lead to his arrest). &lt;/p&gt;  &lt;p&gt;Jain has a history in the courts that is less than complimentary.&amp;#160; As has been mentioned on this blog (and elsewhere) before, Jain was sued by Symantec in 2004 for pirating Symantec’s computer security software. He evaded service during those proceedings, and basically ignored the whole thing until judgment was entered in default. Then he tried to have the default judgment overturned. As noted by the FTC in its latest motion, the Court at that time described Jain&amp;#39;s action as a “&lt;em&gt;cynical and intentional manipulation of the[] proceedings&lt;/em&gt;”, and rejected the application.&amp;#160; I have tried to find out if Jain ever paid the default judgment in the Symantec case but have been unable to find out for sure, one way or the other. &lt;/p&gt;  &lt;p&gt;Also, let&amp;#39;s not forget that Jain is a fugitive.&amp;#160; He had a bench warrant issued against him in the United States District Court for the Central District of California early this year - a warrant that remains in effect. &lt;/p&gt;  &lt;p&gt;The FTC now seeks sanctions against Jain (that sanction being default judgment), and has filed a MOTION for Sanctions Pursuant to Rule 37(d).&amp;#160; Any responses must be filed by 17 August 2009.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1710850" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Fraudware/default.aspx">Fraudware</category></item><item><title>FTC versus Innovative Marketing et al - developments</title><link>http://msmvps.com/blogs/spywaresucks/archive/2009/07/28/1710428.aspx</link><pubDate>Tue, 28 Jul 2009 03:17:49 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1710428</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1710428</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/07/28/1710428.aspx#comments</comments><description>&lt;p&gt;&lt;strong&gt;A win for Marc D&amp;#39;Souza. &lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;The preliminary injunction is to be modified as followed (the FTC indicated that it had no objections to the language of the amendments): &lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&amp;quot;F. The Assets affected by this Paragraph shall include existing Assets of any Corporate Defendant, Individual Defendant (with the exception of Assets referenced in paragraph G), or Relief Defendant and Assets acquired after the effective date of this Order that are derived from conduct prohibited in Paragraphs I and II. &lt;/p&gt;    &lt;p&gt;G. With respect to Defendant Marc D’Souza, the Assets affected by this Paragraph do not include Assets acquired after December 31, 2006 that were generated independently of the IMI Defendants (other than Marc D’Souza) and are not derived from any conduct prohibited in Paragraphs I and II.&amp;quot; &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;Kristy Ross may move for a similar amendment. &lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1710428" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Fraudware/default.aspx">Fraudware</category></item></channel></rss>