The silent threat: Black Hat SEO and Rogue Antivirus
AntivirusPlus ZlKon Malware drop - liveinternetmarketingltd.com
In addition to fake scanner domain, recent research also reveal that several sites are registered through "EVOPLUS LTD" with the information as follow:
Registrant: Live Internet Marketing Limited ****@liveinternetmarketingltd.com attn: Private Registrations 5285 Decarie Boulevard #100 Montreal, QC H3W3C2 Canada +1-514-371-5650
Domain Name: LIVEINTERNETMARKETINGLTD.COM Registrar: EVOPLUS LTD Whois Server: whois.evonames.com Referral URL: http://www.evonames.com Name Server: NS1.LIVEINTERNETMARKETINGLTD.COM Name Server: NS2.LIVEINTERNETMARKETINGLTD.COM Status: clientDeleteProhibited Status: clientTransferProhibited Status: clientUpdateProhibited Updated Date: 27-mar-2009 Creation Date: 20-feb-2009 Expiration Date: 20-feb-2010
Registered Through: AdvancedHosters.com (http://www.AdvancedHosters.com)
******************************
Looking on google show absolutely no web presence apart from malware and pornography websites:
For "liveinternetmarketingltd": Malware domain drop and pornography websites For "Live Internet Marketing Limited": Pornography websites For "liveinternetmarketingltd.com": Pornography websites and malware domain found by Malware Domain List.
Looking on malwaredomainlist show 23 sites with the registrant information "liveinternetmarketingltd.com".
Some domain have been added to the list below:
antivirus-plus-new.com antivirusplussite.com bestinternetexamine.com bestnetcheckonline.com bestwebexamine.com downloadantivirusplus.com easynetcheckonline.com easywebchecklive.com easywebexamine.com easywebscanlive.com internethomecheck.com linkcanlive.com linkcanonline.com linkcanpro.com myantivirusplus.com myinternetexamine.com onlinescanweb.com rapldhsare.com safeyouthnet.com security-check-center.com securesoftinternet.com theantivirusplus.com websecurecheck.com websmartcheck.com websportscheck.com yourinternetexamine.com yournetascertain.com yournetcheckonline.com yournetcheckonline.com yourwebexamine.com yourwebscanlive.com yourwebscanpro.com
**********************
SUSPENDED domain
Registrar: DIRECTI INTERNET SOLUTIONS PVT. LTD. D/B/A PUBLICDOMAINREGISTRY.COM
antivirusplus.biz *** antivirusplus2009.net Symantec Result Registration Service Provided By: HIGH QUALITY HOST COMPANY *** avplus2009.com Symantec Result PrivacyProtect - Registration Service Provided By: ERDOMAIN.COM *** internet-check.net PrivacyProtect - Registration Service Provided By: ERDOMAIN.COM *** traffchecking.com Registration Service Provided By: ERDOMAIN.COM Registrant: uebochek - Luhansk Oblast,01001 - UA - uebochek@gmail.com
********************** ACTIVE domain
*** av-plus-support.com PrivacyProtect - Registration Service Provided By: ERDOMAIN.COM ***
antivirusplussite.com has a fake error page which redirect to downloadantivirusplus.com/buy.php?id=
downloadantivirusplus.com is also hosted on the same IP at ZlKon, also registered by "Live Internet Marketing Limited" and the fraudulent payment page is on the domain below:
https://secure-plus-payments.com/cgi-bin/nph-pr/pandora/softcore/buy_soft.php?productid=avplus3&advert=
209.8.25.204 - ns1.secure-plus-payments.com
Registration Service Provided By: RESELLERCLUB Registrant: Globo inc John Sparck (sparck000@mail.com) South reg, 14 st, 3 Atoll ,3290867 BB Tel. +27.221994 "Globo inc" include: antivirus--plus.com, plus-antivirus.com (Already suspended) ********************** Looking on spamhaus also reveal
newp-digital.com webspywareremover2009.com cure-soft.com [63.219.177.210] innovagest2000s.com secure-softwaretools.com [207.226.175.124] **********************
Host on 94.247.2.215 [hs.2-215.zlkon.lv] AS12553
AS12553 PCEXPRESS-AS "DATORU EXPRESS SERVISS" Ltd.
Some screenshot
|