The earth4energy scam

In recent months I have come across many ads for a website called earth4energy.com. If you haven’t seen the ads, it makes implausible claims of anyone being able to become energy independent for a only small investment. Make no mistake, it’s a scam, designed to sell worthless “e-books”. See this site for a thorough debunking of their claims.

The fact is, the electricity usage of average households can not be met easily or on the cheap from renewable sources using some DIY design. Any photovoltaic panels or wind turbines that are powerful enough to make a significant contribution will cost you a lot of money, typically at least several years worth of your normal electricity bill. These people would have you believe that for a few hundred dollars you could become independent of the utility companies. They do so because their business is selling e-books and videos to people. The exaggerated claims are how they get people to send them money. They are using an elaborate affiliate scheme and paid online ads to fish wide and far for people who might fall for their promises.

What I find particularly interesting about earth4energy.com is how similar it looks to the earlier “Run your car on water” scam I reported about a little over 4 years ago that made similarly outrageous claims. Then they promised cutting your fuel bill by wiring a “hydrogen generator” to your car alternator. Of course it didn’t work.

Both scams made money by selling worthless e-books. Both used affiliate schemes. On either set of sites when you try to navigate away from it, a dialog box will pop up to ask you if you really want to leave, trying to keep you there. If both schemes were not run by the same person, I’d guess they either used the same web designer or one guy closely copied the other. Typical for the hype used to sell on both sites is a “limited time offer” on earth4energy.com. When I checked it, it said the special offer expired on November 22 at midnight, which is today:

To secure your purchase and get the bonus products for free please order now. (This offer expires Thursday November 22 at midnight)

When I checked the source code of the earth4energy.com website, I found this piece of Javascript code that always outputs the current date:

To secure your purchase and get the bonus products for free please <a href=”ordercd.php”>order now</a>. (This offer expires
<script type=”text/javascript”>
var d=new Date()
var weekday=new Array(“Sunday”,”Monday”,”Tuesday”,”Wednesday”,
“Thursday”,”Friday”,”Saturday”)
var monthname=new Array(“January”,”February”,”March”,”April”,”May”,
“June”,”July”,”August”,”September”,”October”,”November”,”December”)
document.write(weekday[d.getDay()] + ” “)
document.write(monthname[d.getMonth()] + ” “)
document.write(d.getDate() + ” “)
</script>
at midnight)</p>

It will tell you the offer expires on today’s weekday and today’s exact date at midnight. It will do so today, tomorrow or a year from now. The offer is not meant to ever expire, the fake deadline is only claimed to rush you into buying. That is just one example of deception on their site.

The identity of the registrant of domain “earth4energy.com” is hidden behind a WHOIS proxy, so we don’t know who it is. What’s interesting though is that the site was registered in June of 2008, around when I wrote about the earlier scam. Back then there was a site called water4gas.com (notice the similar naming scheme!) run by a guy calling himself “Ozzie Freedom”, whose original name was Eyal Siman-Tov. He is from Israel and appeared to be a member of the Scientology cult. In 2008 he got sued by the state of Texas for deceptive business practises. You can read about the court case here.

I find it interesting how many web pages out there promote both water4gas by Ozzie Freedom and earth4energy.com. Here are a few of them. Is that by coincidence or are they connected?

Brand merchandise blog spam from China

Spammers in China are trying to promote websites selling counterfeit brand merchandise by posting numerous blog and guestbook spam comments with links to their sites. For example, the following domains were recently advertised by a spammer using IP address 117.28.249.102 in China:

  • 2012michaelkorsoutlet.com
  • coachfactoryonlinesoutlet.com
  • discount-christianlouboutinoutlet.com
  • longchampsaleoutlet2012.com
  • michaelkors-outletonline.com

Don’t buy from such sites. You’re handing your credit card details to criminals and spammers. Even if the sellers were to send out merchandise (which they may not bother with, as they can always claim it was impounded by customs), it tends to be of low quality. It may indeed get confiscated by customs and you could be fined.

Here are many more domains like that:

  • 2011coachbags2010.com
  • 2012coachonlineoutlet.com
  • 2012coachoutletonline.info
  • 2012michaelkorsoutlet.com
  • authenticcoach-ebags.com
  • chaussurellouboutinpascher.com
  • chaussurevslouboutinpascher.com
  • cheap-christianlouboutinoutlet.net
  • cheapchristianlouboutinoutlet.com
  • cheapcoachhandbag.net
  • cheaplouboutinsonsale.org
  • cheapuggbootsoutlet111.info
  • christian-louboutin-outlets.org
  • christian-louboutin-shoes-ireland.com
  • christian-louboutin-shoesstore.com
  • christian-louboutin.cc
  • christianalouboutinpascher.com
  • christianlouboutin-shoes-uk.net
  • christianlouboutinak.com
  • christianlouboutinbrownthomas.com
  • christianlouboutinck.com
  • christianlouboutindiscount-outlet.com
  • christianlouboutinfemmes.com
  • christianlouboutinidanmark.com
  • christianlouboutinkaufendeutschland.com
  • christianlouboutinmode.com
  • christianlouboutinoutletboots.com
  • christianlouboutinoutletnorge.com
  • christianlouboutinoutletschweiz.com
  • christianlouboutinsaleclearance.com
  • christianlouboutinsaleoutletonline.com
  • christianlouboutinsaleus.info
  • christianlouboutinshoesinfo.com
  • christianlouboutinskorsverige.com
  • christianlouboutinssaleuk1.net
  • christianlouboutinssko.com
  • christianlouboutinuk-sales.com
  • christianlouboutinuk2012.org
  • christianlouboutinvk.com
  • christianolouboutinpascher.com
  • christianslouboutincheap.com
  • christianzlouboutinpascher.com
  • coach-factoryoutletonlines.com
  • coach-factoryoutlets.org
  • coach-factoryoutletstores.com
  • coach-outlet-store-factory.com
  • coach-outletstore-factory.com
  • coach-purseoutlet.com
  • coach-store-outletonline.com
  • coachbagclearancesite.com
  • coachbagscheapjp.com
  • coachbagsfactoryjp.com
  • coachbagshandbags2012.info
  • coachbagsonsalejp.com
  • coachbagsoutletsg.net
  • coachbagsstorejp.com
  • coachbagsvsale.com
  • coachcoachfactoryoutlet.com
  • coachcoachoutlet.org
  • coachcoachoutletbags.com
  • coachfactoryonlinesoutlet.com
  • coachfactoryoutletoutlet.com
  • coachfactoryoutlets-online.net
  • coachfactoryoutletsonlines.us
  • coachhandbagsale.org
  • coachhandbagsforcheap.net
  • coachhandbagsrjp.com
  • coachjpbags.com
  • coachjphandbags.com
  • coachoutletclearance.com
  • coachoutletfactory.org
  • coachoutletfactoryus.com
  • coachoutlethandbags-store.com
  • coachoutletonline.net
  • coachoutletonline111.info
  • coachoutletonline2.info
  • coachoutletonline2012.com
  • coachoutletonline2012.info
  • coachoutletonlinecoo.com
  • coachoutletonliner.net
  • coachoutletonlinestore2012.info
  • coachoutletstoreonlinev.com
  • coachoutletv.net
  • coachpursesoutletsale.com
  • coachs-outlets-online.us
  • coachsfactoryoutletstore.com
  • coachsfactoryoutletstore.us
  • coachsoutlet-online.us
  • coachsoutlet-storeonline.com
  • coachsoutletstore.com
  • coachstore-online-outlet.com
  • coachstore-onlineoutlet.com
  • coachstoreoutletv.com
  • discount-christianlouboutinoutlet.com
  • discountuggs-outlet.com
  • louboutinireland.com
  • louboutinprix-fr.com
  • louboutinshoesstoresjp.com
  • lrechristianlouboutin.com
  • michaelkors-handbagsoutlet.com
  • michaelkors-outletonline.com
  • michaelkorsoutlet-online.com
  • michaelkorsoutlet-sale.com
  • michaelkorsoutletcheap.com
  • michaelkorsoutletjp.com
  • olcoachbagsoutlet.com
  • online-coach-handbags.com
  • outletchristianlouboutinsales.com
  • outletcoachhandbag.net
  • salechristianlouboutinoutletonline.com
  • salemichaelkorsroutlet.com
  • saleschristianlouboutinoutlet.com
  • store-uggoutlet.com
  • ugg-bootsoutletclearance.com
  • ugg-bootsoutletclearance.info
  • ugg-saleoutlet.com
  • uggfactoryoutletonline.com
  • uggoutletface.com
  • uggoutletonline.info
  • uggoutletonline111.info
  • uggoutletonline2012.info
  • uggoutletonlines.info
  • uggoutletonlinesale.info
  • uggoutletstore20.info
  • uggpascherdutout.com
  • uggs-outlet-stores-online.net
  • uggs-outletstores.info
  • uggsonsaleoutlet.info
  • uggsoutlet-online.info
  • uggsoutletdeutschland.com
  • uggsoutletface.com
  • uggsoutletinrotterdam.com
  • uggsoutletonlinestore11.info
  • ukchristianlouboutin4sale.com

Summit spam from Atlanta, Georgia

Recently I got a couple of spams sent to non-existent email addresses at a domain that I host. These spams were very similar, even though they use a variety of domain names and diferent postal address.

Here are some of the domains:

  • hr-summit.net
  • cfo-summit.net
  • cmo-summit.net
  • cmosummits.org
  • cmo-summit.org
  • bizsummits.org
  • thetrainingsummit.net
  • thecorporatecounselsummit.org
  • theengineeringsummit.com
  • theproductdevsummit.org
  • thepublicrelationssummit.net

Here are spam samples:

From: “J.R. Williams” <jason@hr-summit.net>
To: “XXXXXXXXXXXXXXX” <YYYYY@YYYYYYYYYYYYY>
Subject: Geoffrey, interesting speaker
Date: Tue, 4 Oct 2011 09:30:32 -0400

Hi Geoffrey, hope you are well. On Oct 12 at 12 pm ET I thought you would
enjoy dialing in to hear Welch’s VP of Human Resources speaking on
“Creative Ways of Developing Individuals in Smaller Organizations.” Just
go to our site to become part of our group (takes just a minute), thanks!

Truly yours,
J.R. Williams
HR-Summit
hr-summit.net

This message is confidential and intended only for the original recipient.
If you have received this message in error, please delete it or mail us
back if you no longer wish to receive further email. If any follow-up is
needed I show your contact information as XXXXXXXXXXXXXXX,
YYYYY@YYYYYYYYYYYYY ZZZZZZZZZZZZZZZZZ and you may also reach us
at 12OO Abernathy Road #1700, Atlanta Georgia 30328 or through the
contact information on our site.

Domain cfo-summit.net:

From: “Patrick Hansen” <patrick@cfo-summit.net>
To: “XXXXXXXXXXXXXXX” <YYYYY@YYYYYYYYYYYYY>
Subject: Karen, interesting speaker
Date: Thu, 13 Oct 2011 09:43:43 -0400

Hi Karen, hope you are well. On Nov 3 at 12 pm ET I thought you would
enjoy dialing in to hear Banner Health’s CFO speaking on “The Financial
Implications of the New Era of Healthcare.” Just go to our site to become
part of our group (takes just a minute), thanks!

Truly yours,
Patrick Hansen
CFO Summits
cfo-summit.net

This message is confidential and intended only for the original recipient.
If you have received this message in error, please delete it or mail us
back if you no longer wish to receive further email. If any follow-up is
needed I show your contact information as XXXXXXXXXXXXXXX,
YYYYY@YYYYYYYYYYYYY ZZZZZZZZZZZZZZZZZ and you may also reach us at
201 17th St, Ste 1200, Atlanta GA 30363 or through the contact
information on our site.

Domain thehrsummits.org:

From: “J.R. Williams” <jason@thehrsummits.org>
To: “XXXXXXXXXXXXXXX” <YYYYY@YYYYYYYYYYYYY>
Subject: Jack, interesting speaker
Date: Tue, 15 Nov 2011 12:25:12 -0500

Hi Jack, hope you are well. On Dec 7th at 12 pm ET I thought you would
enjoy dialing in to hear Four Seasons Hotel’s Director of Human Resources,
speaking on “Finding the Right People for the Right Job.” Just go to our
site to become part of our group (takes just a minute), thanks!

Yours Truly,
J.R. Williams
HRSummit
thehrsummits.org

This message is confidential and intended only for the original recipient.
If you have received this message in error, please delete it or mail us
back if you no longer wish to receive further email. If any follow-up is
needed I show your contact information as XXXXXXXXXXXXXXX,
YYYYY@YYYYYYYYYYYYY ZZZZZZZZZZZZZZZZZ and you may also reach us
at 201 17th St, Ste 1200, Atlanta GA 30363 or through the contact
information on our site.

Domain cmosummits.org:

From: “Matthew T. Keener” <matthew@cmosummits.org>
To: “XXXXXXXXXXXXXXX” <YYYYY@YYYYYYYYYYYYY>
Subject: Leo, interesting speaker
Date: Thu, 17 Nov 2011 10:55:06 -0500

Hi Leo, hope you are well. On Dec 5th at 12 pm ET I thought you would
enjoy dialing in to hear Aramark’s Associate Vice President of Marketing,
speaking on “Global Marketing.” Just go to our site to become part of our
group (takes just a minute), thanks!

Truly,
Matthew T. Keener
CMO-Summit
cmosummits.org

This message is confidential and intended only for the original recipient.
If you have received this message in error, please delete it or mail us
back if you no longer wish to receive further email. If any follow-up is
needed I show your contact information as XXXXXXXXXXXXXXX,
YYYYY@YYYYYYYYYYYYY ZZZZZZZZZZZZZZZZZ and you may also reach us
at 1200 Abernathy Rd, Atlanta Georgia 30328 or through the contact
information on our site.

Domains bizsummits.org / thetrainingsummit.net:

Reply-To: ryan@bizsummits.org
Date: Wed, 23 Nov 2011 00:35:37 +0000
Subject: John, follow up
From: Ryan English <trainingsummits1@gmail.com>

Hi John,

You recently expressed an interest regarding joining our Training Summit and on behalf of our Administration and Membership; it is my pleasure to extend an invitation to participate in upcoming events and to join our organization. The Training Summit is an invitation only group that is comprised of innovative leaders and visionaries in the Training and Learning & Development field. We discuss best practices and find ways to help one another. Here are some details on upcoming meetings along with the featured speaker that month:

12/01/11 Rob Patterson, CiTi, Senior Vice President, Learning Technology and Architecture-Topic: Utilizing Share points to support a learning organization

We meet once a month via teleconference. In between these monthly calls we have an online forum where our more than 200 members network and collaborate. The membership dues are $1,250 per year, there is a 30 day evaluation period, if you do not feel like the group is advantageous to you or a fit; you can request a full refund. A list of topics and upcoming speakers can be found at www.thetrainingsummit.net. Please contact me ASAP for registration as it is filling up quickly, as well as to confirm networking information. Thank you very much for your time and consideration, if you have any further questions please do not hesitate to call me at (330)-769-7628. I look forward to working with you, have a great day!

Regards,

Ryan English
Training Summit
Direct: 330-769-7628

This message is confidential and intended only for the original recipient. If you have received this message in error, please delete it or mail us back if you no longer wish to receive further email. You may also reach us at 1200 Abernathy Rd, Atlanta Georgia 30328 or through the contact information on our site.

Here are some more spam samples published on other websites, as I’m not the only one being spammed:

This company seems to have been at it for a couple of years already. They will probably keep going as long as some companies fall for their unsolicited emails and sign up.

Report sub4sub.com spam

After uploading a video clip of mine to YouTube for public viewing, I received the following message via YouTube:

Gracehapp has sent you a message:

whats going on? great video
To:[my YouTube ID and 19 others]

howdy,

wow i like ur channel im gonna sub to ya..if you want more subs i used a website

called sub4sub.com you can enter everyday im after getting 300 subs since yesterday.

keep the vids coming

If you receive a message like that (even with other domains in place of ‘sub4sub.com’), report it to YouTube as spam. To the right of the YouTube logo at the top of the message you will see:

help center | e-mail options | report spam

click on that “report spam” link.

It looks like the same spammers previously used the domain earnsubscribers.com, which was advertised using identically worded messages.

Yahoo: “The CAPTCHA you entered did not match please try again”

Today I tried to report an advance fee scammer in Senegal, West Africa who had sent me a scam email using a Yahoo Mail account. I went to the Yahoo Spam Report form and submitted the mail headers and message text, only to get this error message:

The CAPTCHA you entered did not match please try again

Yes, that was the exact punctuation. The form I had submitted did not have any CAPTCHA test to pass. A quick Google search found others reporting the same problem. It looks like Yahoo broke its abuse report handling, which if they don’t fix it soon will both save them staff costs and make them more popular with scammers.

The “Find your stalkers” Facebook scam

Today I received a strange Facebook message. Supposedly one of my friends (an old classmate of mine in Germany) had posted on my wall, but the posting was in English. Now this German friend, unless he happens to forward me an English joke, always writes to me in German. There were several of these wall posts (please DO NOT CLICK on those links!):

23 February at 17:35:
According to http://goo.gl/6hr4J you’re my top stalker. Creep.

23 February at 17:35:
Secret tool shows who stalks your pics http://tinyurl.com/procreeper

23 February at 17:35:
Hey! This is awesome
Insane! Awesome tool to see who looks at your pics >> http://goo.gl/XsUqi

23 February at 17:35:
Hey! This is awesome
New FB tool shows who stalks your profile– http://goo.gl/FTx5T

23 February at 17:43:
Hey, whats happening?
Secret tool shows who stalks your pics http://goo.gl/DxvMD

So I contacted my friend and asked him if it was really him who’d written that or if his facebook account had been hacked. He replied that he wasn’t him.

I investigated the links, which use the Google URL shortening service to hide the
target URL:

tinyurl.com/procreeper => procreeper.info
goo.gl/6hr4J => theprochecker.info/?h
goo.gl/DxvMD => myprochecker.info/?i
goo.gl/FTx5T => procheckers.info/?e
goo.gl/XsUqi => theprochecker.info/?b

Domains procreeper.info, myprochecker.info, procheckers.info and theprochecker.info are all hosted at the same IP address (98.126.9.210, Krypt Technologies) and use the same name servers (ns1.imgurnot.com, ns2.imgurnot.com). The registrant is hidden behind a WHOIS proxy. The reverse DNS name of the host is “wowchatroulette.info“.

Here are other domains that appear connected to these domains (this is probably just the tip of the iceberg):

  • fb-creeper.info
  • fb-creeper.info
  • fbcheckers.info
  • fbcheckersnow.info
  • fbcreeper.info
  • fbcreeper.info
  • fbcreeperonline.info
  • fbcreeperonline.info
  • fbcreepers.info
  • fbcreepers.info
  • fbisfun.info
  • fbpromo.info
  • myfbcheckers.info
  • myprocreeper.info
  • newfbcheckers.info
  • omgfbisfun.info
  • procreep.info
  • procreeper.info
  • procreeperonline.info
  • procreepers.info
  • profilechecker.info
  • profileseek.info
  • profilespy.info
  • profileview.info
  • profileviewers.info
  • thefbcheckers.info
  • thefbcreeper.info
  • thefbcreeper.info

These sites have messages such as:

Find YOUR Stalkers

Find out who spends excessive time with your photos, reading your old wall posts, and looking at your friends list.

This is a scam designed to trick people into running a script on Facebook that will have a message sent to all their Facebook friends and to get them to also visit such websites. Anti-malware site TrendMicro warns:

Malware type : Spyware
Destructive : No
Platform : Windows 2000, XP, Server 2003
Encrypted : Yes
In the wild : Yes

This malware uses social engineering methods to lure users into performing certain actions that may, directly or indirectly, cause malicious routines to be performed. Specifically, it poses as a Facebook stalker finder to be able to infect Facebook user accounts

(…)

This malware may be hosted on websites that run a malicious script when accessed by unsuspecting users.

It poses as a legitimate Facebook application. It propagates by sending IMs and status messages with links to websites where it can be downloaded.

This spyware executes when a user accesses certain websites where it is hosted.

See also this TrendMicro blog post on the subject.

If you have received wall posts like that in the name of a friend, click on the X to the right of the posts to delete them and alert your friend! Do not click on any of the links in the malicious posts.

Fake news / “work at home mom” job scams

During the last couple of weeks I have listed hundreds of domains that are part of an ongoing spam campaign advertising bogus “Work at home jobs”. The websites advertised by these spams were designed to look like they belong to commercial TV channels, sometimes illegally including the CNBC logo and many of the domain names contain terms like “cnbc”, “nbc”, “abc” or “news”.

Here is a sample screen shot:


One of the scam sites: cnbcwebsource20.com

The fact that these people illegally use trademarks of major corporations should already be a major red flag. This is not just some dubious get-rich-quick scheme, is is the work of a criminal operation. The sites are hosted in different countries, including the US, Russia, China and Romania. The registrant details that can be looked up via WHOIS often only list a proxy service.

Here is text from a typical site used in this scam:

news8reports.com | Work At Home Mom Makes $6,498/Month Part-Time

Can $97 Really Turn Into $6795? We Investigated…
News 8 Reports Investigates Online Work at Home Programs…

Are There Any Legit Work At Home Programs?

With unemployment numbers extremely high, everybody is looking to make a few extra bucks these days. Many people are turning to work at home programs… But, which ones are REAL and which ones are SCAMS?

We just had to find out… So we set out to do some research ourselves. We came across a blog by Jessica Holmes of Tokyo, 40.

Oh, Tokyo? By sheer coincidence that’s where I live. But looking at the source of the website, I could see that the HTML code simply looks up the IP address from which the site is accessed and outputs the city associated with it. If you were reading the same article from an IP address in Baltimore it would say that “Jessica Holmes” lived in Baltimore!

That little bit of cheating and the attempt to be mistaken for commercial TV channel websites are just the tip of the iceberg of this criminal scam. In an attempt to avoid being caught by spam filters, many of the spams abuse URL shortening services such as bit.ly or redi.ec to hide the domain names of the fake news sites that are getting blacklisted by us. Many of the spams appear to have been sent from hacked Hotmail, Gmail and AOL mail accounts. The spam appears designed to get unemployed people to pay $97 dollars upfront (“Can $97 Really Turn Into $6795?” headline on the fake site) in the hope of being able to support their families with whatever is offered, when they’re really only going to support the criminals who run this scam.

Here are the WHOIS details of the above mentioned site:

Registrant:
Domains by Proxy, Inc.
DomainsByProxy.com
15111 N. Hayden Rd., Ste 160, PMB 353
Scottsdale, Arizona 85260
United States

Registered through: GoDaddy.com, Inc. (http://www.godaddy.com)
Domain Name: NEWS8REPORTS.COM
Created on: 30-Jan-10
Expires on: 30-Jan-11
Last Updated on: 28-Sep-10

Administrative Contact:
Private, Registration NEWS8REPORTS.COM@domainsbyproxy.com
Domains by Proxy, Inc.
DomainsByProxy.com
15111 N. Hayden Rd., Ste 160, PMB 353
Scottsdale, Arizona 85260
United States
(480) 624-2599 Fax — (480) 624-2598

Technical Contact:
Private, Registration NEWS8REPORTS.COM@domainsbyproxy.com
Domains by Proxy, Inc.
DomainsByProxy.com
15111 N. Hayden Rd., Ste 160, PMB 353
Scottsdale, Arizona 85260
United States
(480) 624-2599 Fax — (480) 624-2598

Domain servers in listed order:
NS1.WIREDTREE.COM
NS2.WIREDTREE.COM

Be extremely skeptical of any job offers that involve any of the following:

  1. Anything sent as spam (unsolicited bulk email)
  2. Work at home jobs that supposedly pay thousands of dollars a month that anybody can do
  3. Upfront payments or purchases in order to get a job (in any real job the employer pays you, not vice versa!)
  4. Hard sales tactics, such as web sites that pop up a dialog when you’re trying to close them
  5. Signs of deception or hidden identities.

URL shortening abuse examples:

cnbcfinancenow21.tk = bit.ly/cYANOE
cnbc2.com = bit.ly/cVE04V
cnbc2.com = bit.ly/9am423
cnbc2.com = bit.ly/9yLTQz
cnbc2.com = bit.ly/ajmIpO
cnbc2.com = bit.ly/dehCDk
nbcnow28.tk = is.gd/h1cqG
cnbc2.com = bit.ly/a7azZN
nbcnow28.tk = is.gd/h1cbJ
cnbc2.com = bit.ly/a81vu0
cnbc2.com = bit.ly/9fe1sd
cnbc2.com = bit.ly/aROkLP
cnbc2.com = bit.ly/aZSKYx
cnbc2.com = bit.ly/9DCGzQ
cnbc2.com = bit.ly/9avkAn
cnbc2.com = bit.ly/dcEmpU
cnbc2.com = bit.ly/9lXpMJ
nbc40news.net = bit.ly/bjI19K
nbc39news.net = bit.ly/alVIfU
nbc40news.net = bit.ly/cTHQ2Y
nbc40news.net = bit.ly/aYrKCa
nbc40news.net = bit.ly/dieJ5R
nbc39news.net = bit.ly/dbkWxV
nbc40news.net = bit.ly/9uOD6H
nbc41news.net = bit.ly/c7gCyu
nbc41news.net = bit.ly/gqRtBZ
nbc41news.net = bit.ly/f5VsQz
cnbc14news.net = bit.ly/fot9an
nbc41news.net = bit.ly/i0jOK2
nbc41news.net = bit.ly/gFJe8e
nbc41news.net = bit.ly/fgpSVG
nbc7newsmedia.net = bit.ly/9lBObh
cnbc3news.net = bit.ly/eGEYhq
cnbc3news.net = bit.ly/g2u93V
msnbcnews4.net = bit.ly/fGupR0
msnbcnews4.net = bit.ly/hq2gX3
msnbcnews4.net = bit.ly/i8iYaK
nbcnews7.net = bit.ly/h0Kw5O
cnbc3news8.com = bit.ly/hnQyy7
cnbc3.com = bit.ly/hIxAuy
msnbcnews11.net = bit.ly/i6CZN3
msnbcnews11.net = bit.ly/fmRgsD
nbcnews12.net = bit.ly/gANdZw
msnbcnews11.net = bit.ly/gadsv7
msnbcnews11.net = bit.ly/hBXuRH
cnbc7.com = bit.ly/eUPW7N
cnbc7.com = bit.ly/edNttc
cnbc7.com = bit.ly/elDyof
cnbc7.com = bit.ly/fAe9oj
cnbc7.com = bit.ly/hg6Kvi
cnbc7.org = bit.ly/h6bTfo
cnbc7.org = bit.ly/gpuFHr
cnbc7.org = bit.ly/idIJoX
cnbc7.org = bit.ly/hOBmjw
cnbc7.org = bit.ly/gLbsrp
cnbc7.org = bit.ly/eq12aU
cnbc7.com = bit.ly/e43Iib
cnbc7.org = bit.ly/dPKBna
cnbc7.org = bit.ly/e10nTV
cnbc7.com = bit.ly/f5Z7rq
cnbc7.org = bit.ly/guMMYG
cnbc7.com = bit.ly/ez7AJF
cnbc7.com = bit.ly/grGu4j
cnbc7.com = bit.ly/gNwG4N
cnbc7.com = bit.ly/hdv9Xr
cnbc7.com = bit.ly/eMp8ce
cnbc7.org = bit.ly/hLrMSK
cnbc7.org = bit.ly/dKWCHA
cnbc7.com = bit.ly/eDe0ud
cnbc7.com = bit.ly/ft1H3q
cnbc7.org = bit.ly/fGPn0R
cnbc7.org = idek.net/3dtS
nbcbeforehotmail.info = bit.ly/gmv7PJ
nbcbeforehotmail.info = bit.ly/i5dFZm
nbcbeforehotmail.info = bit.ly/eQLUik
nbcbeforehotmail.info = bit.ly/hJnzSD
nbcbeforehotmail.info = bit.ly/fpBgps
nbcbeforehotmail.info = bit.ly/hYbl1G
nbcbeforehotmail.info = bit.ly/f75etY
nbcbeforehotmail.info = bit.ly/i0DGVt
nbcbeforehotmail.info = bit.ly/h1rrCw
nbcbeforehotmail.info = bit.ly/gEdAoY
nbcbeforehotmail.info = bit.ly/gm3Ti8
nbcbeforehotmail.info = bit.ly/ihbu2g
nbcbeforehotmail.info = bit.ly/hj7GKp
nbcbeforehotmail.info = bit.ly/gkbCcG
nbcbeforehotmail.info = bit.ly/e8RuVs
nbcbeforehotmail.info = bit.ly/hoVraB
nbcbeforehotmail.info = bit.ly/hFLA4Q
nbcbeforehotmail.info = bit.ly/h9lmA3
nbcbeforehotmail.info = bit.ly/f082ws
nbcbeforehotmail.info = bit.ly/gfhNP6
nbcbeforehotmail.info = bit.ly/emkJsL
nbcbeforehotmail.info = bit.ly/hoVraB
nbcbeforehotmail.info = bit.ly/hFLA4Q
nbcbeforehotmail.info = bit.ly/gfhNP6
nbcbeforehotmail.info = bit.ly/hoVraB
nbcbeforehotmail.info = bit.ly/gfhNP6
bannewsnbc.info = bit.ly/gysB7G
nbcbeforehotmail.info = bit.ly/hoVraB
nbcbeforehotmail.info = bit.ly/gfhNP6
bannewsnbc.info = bit.ly/gysB7G
cnbc20medianet.com = bit.ly/gfgAUo
bannewsnbc.info = bit.ly/g2xI9o
bannewsnbc.info = bit.ly/eL2oQx
bannewsnbc.info = bit.ly/hTX1Tr
msn7nbc.info = bit.ly/eBVtbo
polonbcnews.info = bit.ly/fkXMia
msn7nbc.info = bit.ly/hQDC2d
polonbcnews.info = bit.ly/fC0Gvj
msn7nbc.info = bit.ly/fGAVTr
polonbcnews.info = bit.ly/fBGs29
msn7nbc.info = bit.ly/eIgvhO
msn7nbc.info = bit.ly/dFjrGX
msn7nbc.info = bit.ly/dYIcw5
msn7nbc.info = bit.ly/gn896l
msn7nbc.info = bit.ly/er1dSj
msn7nbc.info = bit.ly/g61R4u
news42local.info = is.gd/gMaJL
ultranews23.com = tiny.cc/UltraYjlSnews23
ultranews23.com = tiny.cc/Ultra0Delnews23
newsfamily7.com = a.nf/2tmNJV
ultranews23.com = tiny.cc/Ultra6sPYnews23
newsfamily7.com = a.nf/2tmNJV
news42local.net = is.gd/gMtdl
ultranews23.com = tiny.cc/UltradmSJnews23
ultranews23.com = tiny.cc/UltraMfIanews23
ultranews23.com = tiny.cc/UltrameYanews23
news42local.net = bit.ly/ctBb1V
news42local.info = bit.ly/d1MSVM
news42local.co.uk = is.gd/gNatd
ultranews23.com = tiny.cc/UltratIfOnews23
ultranews23.com = tiny.cc/UltrabS2znews23
news42local.co.uk = is.gd/gNiZ6
news42local.co.uk = is.gd/gNrYT
news42local.co.uk = bit.ly/bw7lIF
news42local.co.uk = is.gd/gNuTt
news42local.net = bit.ly/a7lyX5
ultranews23.com = tiny.cc/UltraOqI9news23
ultranews23.com = tiny.cc/UltraJ5s7news23
ultranews23.com = tiny.cc/UltrameYanews23
ultranews23.com = tiny.cc/UltrakP48news23
news42local.biz = bit.ly/9CZnHc
news42local.net = bit.ly/9o9F07
news42local.net = bit.ly/b4VA1w
news42local.co.uk = is.gd/gNF4a
news42local.co.uk = bit.ly/aqgrW8
news42local.net = bit.ly/cvFRT2
ultranews23.com = tiny.cc/UltraMfIanews23
ultranews23.com = tiny.cc/UltraCWiRnews23
ultranews23.com = tiny.cc/Ultrap5RVnews23
ultranews23.com = tiny.cc/UltratbGGnews23
ultranews23.com = tiny.cc/Ultran79Unews23
news42local.co.uk = is.gd/gNMW5
newsfornow1.net = is.gd/gMuAg
news42local.co.uk = is.gd/gNPVV
news42local.biz = bit.ly/bfcDWc
ultranews23.com = tiny.cc/UltrajUqYnews23
ultranews23.com = tiny.cc/UltrahiT7news23
ultranews23.com = tiny.cc/UltraJFv2news23
ultranews23.com = tiny.cc/UltrafG3rnews23
ultranews23.com = tiny.cc/Ultra0TQWnews23
ultranews23.com = tiny.cc/UltraaRW8news23
ultranews23.com = tiny.cc/Ultra5xnEnews23
ultranews23.com = tiny.cc/UltraXt90news23
ultranews23.com = tiny.cc/UltrafKw7news23
ultranews23.com = tiny.cc/UltrabJQbnews23
ultranews23.com = tiny.cc/UltraSsFOnews23
news88local.com = is.gd/gPDsy
news88local.biz = is.gd/gOPq1
news88local.org = is.gd/gOPUX
news88local.com = is.gd/gOQI1
ultranews23.com = tiny.cc/UltraffIjnews23
news88local.com = is.gd/gOXqs
news88local.com = is.gd/gOXXx
news88local.org = is.gd/gP4Aj
news88local.org = is.gd/gP6yN
ultranews23.com = tiny.cc/UltraGUWenews23
news88local.net = is.gd/gPQ1S
ultranews23.com = tiny.cc/Ultrabjwynews23
ultranews23.com = tiny.cc/Ultragxl9news23
news88local.net = is.gd/gPftN
news88local.org = is.gd/gPgb1
news88local.org = is.gd/gPlkm
ultranews23.com = tiny.cc/UltragLHCnews23
news88local.biz = is.gd/gPoBK
news88local.com = is.gd/gPqMb
news88local.biz = is.gd/gPwP4
news88local.org = bit.ly/bttwD6
ultranews23.com = tiny.cc/UltrazuZWnews23
ultranews23.com = tiny.cc/Ultrax70Dnews23
news88local.biz = bit.ly/dCR623
news88local.biz = bit.ly/ajGmui
newsfamily7.com = a.nf/2tmNJV
news88local.com = bit.ly/aOBoYO
newsfamily7.com = a.nf/2tmNJV
news88local.net = bit.ly/9C49kE
news88local.biz = bit.ly/cJqASy
news88local.biz = bit.ly/9EXjGv
news88local.net = bit.ly/9AbRRU
news88local.com = bit.ly/bMxJFA
news88local.biz = bit.ly/9TPphi
news88local.com = bit.ly/c2aoIR
news88local.com = bit.ly/cwUiTp
news88local.org = bit.ly/ceXIWe
news88local.org = bit.ly/ayN7mB
news88local.org = bit.ly/dwGy6e
news88local.net = bit.ly/blEQQW
newsfamily7.com = a.nf/2tmNJV
newschan42.com = a.nf/kBJUtc
newsfamily7.com = a.nf/2tmNJV
newsfornow1.net = bit.ly/9r6UkK
thenews4later.net = bit.ly/9C9ZPP
local50news.com = bit.ly/aH9MEQ
local50news.com = bit.ly/czTx2t
thenews4later.net = bit.ly/9C9ZPP
local50news.com = bit.ly/cWQ62S
local50news.com = bit.ly/9mUM9t
local50news.com = bit.ly/dwFAzE
ultranews23.com = a.nf/kV7WWd
thenews4later.net = bit.ly/bOdJk8
businessnews10.tk = is.gd/hleaz
ultranews23.com = korta.nu/f84ji
newscenter10.co.cc = is.gd/hmLhQ
businessnews21.tk = bit.ly/9o2AvQ
cnn65news.com = bit.ly/ciDaWR
cnn65news.com = bit.ly/9ieRys
ultranews23.com = retwt.me/1PKxk
local87news.com = bit.ly/cdyzi5
local87news.com = bit.ly/9Y5OEA
local87news.com = bit.ly/cdyzi5
local87news.com = bit.ly/9Y5OEA
local87news.com = bit.ly/cdyzi5
local87news.com = bit.ly/9WlaQT
local87news.com = bit.ly/cdyzi5
ultranews23.com = retwt.me/1PKxk
nbc40news.net = bit.ly/bjI19K
nbc39news.net = bit.ly/alVIfU
nbc40news.net = bit.ly/cTHQ2Y
nbc40news.net = bit.ly/aYrKCa
nbc40news.net = bit.ly/dieJ5R
nbc39news.net = bit.ly/dbkWxV
local99news.net = bit.ly/ac1Nt7
ultranews23.com = retwt.me/1PKxk
nbc40news.net = bit.ly/9uOD6H
ultranews23.com = bacn.me/jrbj
local99news.org = bit.ly/bm8NPu
local99news.org = bit.ly/bFi8J6
local99news.com = bit.ly/bCzIrN
local99news.com = bit.ly/ae3EY2
nbc41news.net = bit.ly/c7gCyu
local99news.net = bit.ly/9PCUP4
local99news.com = bit.ly/dgeAan
local99news.org = bit.ly/9wqppM
local99news.net = bit.ly/aTLwlD
ultranews23.com = bacn.me/jrbl
local99news.com = bit.ly/dBacHx
local99news.org = bit.ly/chHCja
nbc41news.net = bit.ly/c7gCyu
local99news.org = bit.ly/bCB5uB
local99news.com = bit.ly/9IBs4W
local99news.org = bit.ly/dsl0Om
ultranews23.com = bacn.me/jrbj
nbc41news.net = bit.ly/gqRtBZ
nbc41news.net = bit.ly/f5VsQz
local90news.net = bit.ly/gKy1NM
cnbc14news.net = bit.ly/fot9an
nbc41news.net = bit.ly/i0jOK2
ultranews23.com = bacn.me/jrbp
nbc41news.net = bit.ly/gFJe8e
nbc41news.net = bit.ly/fgpSVG
nbc7newsmedia.net = bit.ly/9lBObh
ultranews23.com = bacn.me/jrbn
local46news.org = bit.ly/fcPLLc
local46news.org = bit.ly/hGN6E0
cnbc3news.net = bit.ly/eGEYhq
cnbc3news.net = bit.ly/g2u93V
ultranews23.com = retwt.me/1PKxk
ultranews23.com = bacn.me/jrbk
ultranews23.com = retwt.me/1PKxk
msnbcnews4.net = bit.ly/fGupR0
msnbcnews4.net = bit.ly/hq2gX3
ultranews23.com = retwt.me/1PKxk
ultranews23.com = bacn.me/jrbj
ultranews23.com = bacn.me/jrbp
ultranews23.com = bacn.me/jrbk
ultranews23.com = bacn.me/jrbl
ultranews23.com = bacn.me/jrbm
msnbcnews4.net = bit.ly/i8iYaK
ultranews23.com = bacn.me/jrbl
nbcnews7.net = bit.ly/h0Kw5O
cnbc3news8.com = bit.ly/hnQyy7
abcnews12.net = bit.ly/gnP0r0
abcnews12.net = bit.ly/fr2era
abcnews12.net = bit.ly/eLpV1n
abcnews12.net = bit.ly/gT7zEx
abcnews12.net = bit.ly/evDdv9
abcnews11.net = bit.ly/i0AdRc
abcnews11.net = bit.ly/hB00NV
abcnews11.net = bit.ly/haD230
abcnews12.net = bit.ly/eC6Nib
abcnews11.net = bit.ly/eH1AEF
abcnews12.net = bit.ly/gdA3tj
abcnews12.net = bit.ly/hTHdgL
abcnews11.net = bit.ly/ggMB1g
abcnews12.net = bit.ly/dVHHsG
abcnews11.net = bit.ly/f34jVH
abcnews12.net = bit.ly/hMf52P
abcnews11.net = bit.ly/fycYPy
msnbcnews11.net = bit.ly/i6CZN3
msnbcnews11.net = bit.ly/fmRgsD
nbcnews12.net = bit.ly/gANdZw
msnbcnews11.net = bit.ly/gadsv7
cbsnews12.net = bit.ly/hurzVY
msnbcnews11.net = bit.ly/hBXuRH
cbsnews12.net = bit.ly/hjGq7d
cbsnews12.net = bit.ly/gWwBD8
cbsnews12.net = bit.ly/fj1m2B
here4newslocal.net = bit.ly/hQ68Yq
nb18newstoday.info = i5.be/SY6
usnews3.com = a.nf/K3gdA1
newswebguide.com = tinyurl.com/6x2b4qf
cnn65news.net = bacn.me/k55j
cnn65news.net = bacn.me/k59p
global81news.net = bacn.me/k6mp
newschan42.com = a.nf/lrW38G
usnews3.com = a.nf/K3gdA1
newschan42.com = a.nf/lrW38G
walletnews1.info = bit.ly/eRuN9c
newschan42.com = a.nf/lrW38G
local22news.biz = bacn.me/kbzd
newschan42.com = a.nf/lrW38G
usnews3.com = a.nf/K3gdA1
newschan42.com = a.nf/lrW38G
local22news.biz = bit.ly/dGHb1x
usnews3.com = a.nf/K3gdA1
ultranews23.com = a.nf/GleoGo
usnews3.com = a.nf/K3gdA1
ultranews23.com = a.nf/GleoGo
usnews3.com = a.nf/K3gdA1
ultranews23.com = a.nf/GleoGo
usnews3.com = a.nf/K3gdA1
ultranews23.com = a.nf/GleoGo
usnews3.com = a.nf/K3gdA1
ultranews23.com = a.nf/GleoGo
usnews3.com = a.nf/K3gdA1
ultranews23.com = a.nf/GleoGo
usnews3.com = a.nf/K3gdA1
ultranews23.com = a.nf/GleoGo
bannewsnbc.info = bit.ly/gysB7G
ultranews23.com = a.nf/GleoGo
bannewsnbc.info = bit.ly/gysB7G
bannewsnbc.info = bit.ly/g2xI9o
bannewsnbc.info = bit.ly/eL2oQx
bannewsnbc.info = bit.ly/hTX1Tr
polonbcnews.info = bit.ly/fkXMia
polonbcnews.info = bit.ly/fC0Gvj
polonbcnews.info = bit.ly/fBGs29
usnews3.com = a.nf/K3gdA1

Hosted in Russia:

news7bfge.com
news7ffvg.com
news7ghuf.com
news7hdtr.com
news7hhgs.com
news7hjkl.com
news7kjih.com
news7mnvb.com
news7oksi.com
news7oplk.com
news7riue.com
news7ttdd.com
news7tuij.com
news7uuij.com
news7vfys.com
news7connect.com
news7link.com
news7sync.com
news7technology.com
news7udomain.com
news7uinternet.com
news7usource.com
news7utechnology.com
accessnews11.com
b2news11.com
buynews11.com
bytenews11.com
compunews11.com
connectnews11.com
cybernews11.com
directnews11.com
domainnews11.com
e-news11.com
enews11.com
eznews11.com
i-news11.com
inews11oi.com
infounews11a.com
internetnews11.com
internews11.com
news11asuy.com
news11hjgf.com
news11iuyr.com
news11kdjc.com
news11qoiu.com
news11quyw.com
news11qwuo.com
news11vyru.com

Hosted in Hong Kong:

buycnbc1aok.com
internetcnbc1wo.com
procnbc1wo.com
sellcnbc1wo.com

Hosted in the USA:

cnbc20market.com
cnbcjobs20.com
cnbc20early.com

Fake diploma spam (1-954-537-3038, 1-801-461-5023)

Here are some examples of diploma spam that we are seeing in our spam traps recently. I wrote about this type of spam four years ago.

Get a Degree in 4 to 6 Weeks with our program!

~We offer a program that will help ANYoNE with professional experience
get a 100% verified Degree:
Doctorate (PHD), Bachelors, Masters
– Think about it…
Within a few weeks, you can become a college graduate!- Follow YoUR Dreams- Live a better life by earning or upgrading your degree

This is a rare chance to make a right move and receive your due
benefits… if you are qualified but are lacking that piece of paper,
Get one from us in a fraction of the time.

~CALL FoR A FREE CoNSULTATIoN~

1-801-461-5023

It is your move…
Make the right decision.

Due to time zone variations across the country, a representative may not be in the office at the time of your call.
If that is the case please leave us a message with your name and phone number and we will get back to you as soon as possible.

Do Not Reply to this Email.
We do not reply to text inquiries, and our server will reject all response traffic.
We apologize for any inconvenience this may have caused you.

and

Get a Degree in 4 to 6 Weeks with our program!

~We offer a program that will help ANYoNE with professional experience
get a 100% verified Degree:
Doctorate (PHD), Bachelors, Masters
– Think about it…
Within a few weeks, you can become a college graduate!- Follow YoUR Dreams- Live a better life by earning or upgrading your degree

This is a rare chance to make a right move and receive your due
benefits… if you are qualified but are lacking that piece of paper,
Get one from us in a fraction of the time.

~CALL FoR A FREE CoNSULTATIoN~

1-801-461-5023

It is your move…
Make the right decision.

Due to time zone variations across the country, a representative may not be in the office at the time of your call.
If that is the case please leave us a message with your name and phone number and we will get back to you as soon as possible.

Do Not Reply to this Email.
We do not reply to text inquiries, and our server will reject all response traffic.
We apologize for any inconvenience this may have caused you.

University diplomas advertised in spam, usually only mentioning a contact phone number which takes a voice mail, are not worth the paper they are printed on. People get such diplomas from unaccredited “universities” by paying thousands of dollars, regardless of their academic record. If an employer you’re trying to impress this way is not familiar with the institution and bothers to do a little bit of research they will consider you a highly unethical person they would never want to do business with.

Don’t pay for a fake diploma. You’d get better value for money buying toilet paper (cheaper, softer, does not damage your career).

USDomainlicensing.com spam

When I received the following email, I was scared for a moment that I might not have taken care of renewing one of my domains, but I think panic is exactly what the senders had intended to provoke:

US Domain Licensing
130 Church St Suite 280 New York, NY 10007
Web: www.USDomainlicensing.com
Email: support@usdomainlicensing.com
Phone: 1 800 690 1269

————————————————————–
Final Notice Of Domain Extension
————————————————————–

ATT:

ADMINISTRATIVE CONTACT
joewein
jwspamspy@pobox.com
Address:
Phone:
Fax:
www.jwspamspy.us Notice Tracking Number: EXE2799704

Please be advised that the above noted domain name has now become available for registration. Consequently the possibility of a conflicting domain registration may occur. As the registrant of the commerce extension, you have been granted the first right to use preference in securing the intellectual property for the United States country code. If you choose to waive this right, the name will be available for public registration.

————————————————————–

Please note that businesses and consumers are increasingly losing the rights to their domain names caused by Domain Hijacking, Registrant/Registrar mistake, inadvertence, or Blocked Emails.
————————————————————–

This is an urgent domain notice to verify the rights to your name to prevent 3rd party infringement and unintentional name loss. Our organization is responsible for verifying the public and private Intellectual Property rights of domain holders, and to carry out UDRP Disputes according to the guidelines:

Protecting a domain name registrant or trademark owner from confusing and/or conflicting domain name registrations is not the responsibility of the domain and trademark registration processes. In the event of a registration of the above noted domain by a third party, the UDRP may be applied under the following conditions.

You may loose your domain if a complainant/competitor proves that each of these three elements are present with your domain registration. – For the purposes of Paragraph 4(a)(iii), the following circumstances, in particular but without limitation, if found by the Panel to be present, shall be evidence of the registration and use of a domain name in bad faith:

(i) your domain name is identical or confusingly similar to a trademark or service mark in which the complainant has rights; and
(ii) you have no rights or legitimate interests in respect of the domain name; and
(iii) your domain name has been registered and is being used in bad faith.

b. Evidence of Registration and Use in Bad Faith.

.(i) You acquired the domain primarily for the purpose of selling, renting, or otherwise transferring the domain name registration to the complainant/ trademark or service mark owner, or to their competitor, or (ii) you have registered the domain name in order to prevent the owner of the trademark or service mark from reflecting the mark in a corresponding domain name, therefore revealing a pattern of such conduct, or (iii) you have registered the domain name primarily for the purpose of disrupting the business of a competitor, or (iv) by using the domain name, to create confusion with the complainant’s mark.

Note: You may disregard this notice. If you disregard this notice or fail to reply:
(a) The licensing rights of this domain name may be assigned to any other applicant, (b) UDL and or any ICANN accredited registrar will not be liable for loss of domain name license, identical or confusingly similar use of your company’s domain name; or interruption of business activity or business losses.

————————————————————–

PLEASE READ CAREFULLY:
If you fail to reply to UDL this domain may be registered by any third party without further notice. To protect the intellectual property rights to this name, you are required to advise us of your intent to (a) secure this domain name or (b) to leave this domain name for Public Registration.

————————————————————–
Call 1 800 690 1269
Notice Tracking Number: EXE2799704

Sounds terribly official and scary, but I’ve never owned any “.us” domains, so there is no domain registration to extend. Not being based in the United States, I have no plans to register any .us domains. I do own the .com and .net variants of the domain in question though and they are far more useful for commercial purposes.

These people seem to try to frighten recipients of their spam into signing up for a .us domain. They are not cheap: From the FAQ on their website it looks like they charge US$70 for two years.

Reputable registrars offer .us domains for around $20 for 2 years, so it’s unlikely anyone would pay $70 to register one through these people unless prompted to do so by deceptive advertising, even if they had a need for a .us domain in the first place.

By the way, domains USDomainlicensing.us and USDomainlicensing.net were still available when I checked, so they themselves don’t practice what they preach. The same people own domainregistryrights.com, which was registered about two years earlier (May 2008) than usdomainlicensing.com (February 2010).

See also:

Vir7remover_2009_b2.exe / defend6-pc.com scareware

While researching some information, I came across a Google hit that looked like what I was looking for, but when I opened the page, none of the text in the preview paragraph was there. Somebody must have fed bogus contents to GoogleBot to attract searches.

Instead of the expected information I found myself on a scareware site called defend6-pc.com that was then trying to coerce me into downloading and installing their fake security software. A pop-up dialog asked me whether I wanted to scan my computer with their software. It didn’t matter if I clicked OK or Cancel, a download would always start. Only by closing the browser Window could I get rid of their nasty popup dialogs.

I’m using Mozilla FireFox, which does not offer to run downloaded EXEs directly. I did not click on the downloaded “Vir7remover_2009_b2.exe”, instead I ran it through the VirusTotal.com online malware scanner (highly recommended!) and products by four companies diagnosed it as malicious or suspicious:

  • Microsoft (1.5605) says it’s a “Trojan:Win32/FakeXPA”
  • Sophos (4.52.0) says it’s “Mal/FakeAV-CX”
  • VBA32 (3.12.12.4) says it’s “BScope.Trojan.MTA.0157”
  • Panda (10.0.2.2) calls it a “”Suspicious file”

“Mal/FakeAV-CX” indicates “scareware“, software that pretends to be an anti-virus / malware scanner that scares you with bogus alerts of malware on your harddisk into installing and or purchasing the software. Such software can include Trojans (as you would suspect from “Trojan:Win32/FakeXPA” and “BScope.Trojan.MTA.0157”) that take over your machine and can give someone else full control over your machine for malicious activities.

The following domains are all hosted on the same server as defend6-pc.com (IP address 93.174.95.154) and this list probably is not complete. I definitely would not recommend installing any software from any of these sites:

  • 10scanantispyware.com
  • 20scanantispyware.com
  • 2scanantispyware.com
  • 30scanantispyware.com
  • 3scanantispyware.com
  • 50virus-scanner.com
  • 5scanantispyware.com
  • 60scanantispyware.com
  • 7scanantispyware.com
  • 80scanantispyware.com
  • 8scanantispyware.com
  • 90virus-scanner.com
  • antispy-scan200.com
  • antispy-scan400.com
  • antispy-scan600.com
  • antispy-scan700.com
  • antispy-scan800.com
  • antispywarehelp002.com
  • antispywarehelp004.com
  • antispywarehelp008.com
  • antispywarehelp010.com
  • antispywarehelp022.com
  • antispywarehelpk0.com
  • antispywarehelpk2.com
  • antispywarehelpk4.com
  • antispywarehelpk6.com
  • antispywarehelpk8.com
  • antivirus-inet01.com
  • antivirus-inet31.com
  • antivirus-inet41.com
  • antivirus-inet51.com
  • antivirus-scan200.com
  • antivirus-scan400.com
  • antivirus-scan600.com
  • antivirus-scan700.com
  • antivirus-scan900.com
  • antivirus-test88.com
  • antivirus10scanner.com
  • antivirus900scanner.com
  • av-scanner200.com
  • av-scanner300.com
  • av-scanner400.com
  • av-scanner500.com
  • av-scanner700.com
  • defend-computer10.com
  • defend-computer30.com
  • defend-computer50.com
  • defend-computer70.com
  • defend-computer82.com
  • defend-computer83.com
  • defend-computer84.com
  • defend-computer85.com
  • defend-computer86.com
  • defend-computer88.com
  • defend-computer90.com
  • defend-pc100.com
  • defend-pc130.com
  • defend-pc150.com
  • defend-pc170.com
  • defend2-pc.com
  • defend5-pc.com
  • defend6-pc.com
  • inetproscan001.com
  • inetproscan031.com
  • inetproscan061.com
  • inetproscan081.com
  • inetproscan091.com
  • insight-scan20.com
  • insight-scan40.com
  • insight-scan60.com
  • insight-scan80.com
  • insight-scan90.com
  • insight-scanner2.com
  • insight-scanner5.com
  • insight-scanner7.com
  • insight-scanner8.com
  • insight-scanner9.com
  • internet-scan020.com
  • internet-scan040.com
  • internet-scan050.com
  • internet-scan070.com
  • internet-scan090.com
  • internet-scanner020.com
  • internet-scanner030.com
  • internet-scanner050.com
  • internet-scanner070.com
  • internet-scanner090.com
  • net-02antivirus.com
  • net-04antivirus.com
  • net-05antivirus.com
  • net-07antivirus.com
  • net001antivirus.com
  • net011antivirus.com
  • net021antivirus.com
  • net111antivirus.com
  • net222antivirus.com
  • novirus-scan00.com
  • novirus-scan01.com
  • novirus-scan22.com
  • novirus-scan31.com
  • novirus-scan33.com
  • novirus-scan41.com
  • novirus-scan55.com
  • novirus-scan61.com
  • novirus-scan81.com
  • novirus-scan88.com
  • spyware-stop01.com
  • spyware-stopb1.com
  • spyware-stopm1.com
  • spyware-stopn1.com
  • spyware-stopz1.com
  • spyware200scan.com
  • spyware500scan.com
  • spyware800scan.com
  • spyware880scan.com
  • spywarescan010.com
  • spywarescan013.com
  • spywarescan015.com
  • spywarescan017.com
  • spywarescan018.com
  • stop-all-virus1.com
  • stop-all-virus3.com
  • stop-all-virus6.com
  • stop-all-virus9.com
  • stop-virus-01a.com
  • stop-virus-01b.com
  • stop-virus-01d.com
  • stop-virus-01e.com
  • stop-virus-01f.com
  • stop-virus-03b.com
  • stop-virus-03u.com
  • stop-virus-03y.com
  • stop-virus-03z.com
  • stop-virus-040.com
  • stop-virus-070.com
  • stop-virus-090.com
  • stop-virus-091.com
  • stop-virus-099.com
  • stopvirus-scan11.com
  • stopvirus-scan13.com
  • stopvirus-scan16.com
  • stopvirus-scan18.com
  • stopvirus-scan33.com
  • stopvirus-scan66.com
  • stopvirus-scan88.com
  • stopvirus-scan99.com
  • virus77scanner.com
  • virus88scanner.com