{"id":2353,"date":"2015-03-17T14:44:53","date_gmt":"2015-03-17T05:44:53","guid":{"rendered":"http:\/\/www.joewein.net\/blog\/?p=2353"},"modified":"2015-03-17T14:44:53","modified_gmt":"2015-03-17T05:44:53","slug":"domains-hijacked-by-fake-brand-spammers","status":"publish","type":"post","link":"https:\/\/joewein.net\/blog\/2015\/03\/17\/domains-hijacked-by-fake-brand-spammers\/","title":{"rendered":"Domains hijacked by fake brand spammers"},"content":{"rendered":"<p>Spammer who set up fake websites offering brand name products to sell counterfeit merchandise or to steal credit card details of would-be buyers often hack third party websites to host ads and shopping websites on them. <\/p>\n<p>On top of that we&#8217;ve also come across many cases of them taking over control of existing domains, whose names then don&#8217;t make any mention of the brands being offered. <\/p>\n<p>For example the domain &#8220;itelekom.net&#8221;, which currently hosts a site selling Nike shoes, has been around since 2004 and apparently was previously owned by a telecommunications company in Nigeria. Looking up its current ownership using WHOIS, it still has a 2004 creation date but appears to be owned by someone in China:<\/p>\n<p>[CODE]Domain Name: ITELEKOM.NET<br \/>\nRegistry Domain ID: 119763324_DOMAIN_NET-VRSN<br \/>\nRegistrar WHOIS Server: whois.godaddy.com<br \/>\nRegistrar URL: http:\/\/www.godaddy.com<br \/>\nUpdate Date: 2014-06-22T11:19:59Z<br \/>\nCreation Date: 2004-05-11T08:50:26Z<br \/>\nRegistrar Registration Expiration Date: 2015-05-11T08:50:26Z<br \/>\nRegistrar: GoDaddy.com, LLC<br \/>\nRegistrar IANA ID: 146<br \/>\nRegistrar Abuse Contact Email: abuse@godaddy.com<br \/>\nRegistrar Abuse Contact Phone: +1.480-624-2505<br \/>\nDomain Status: clientTransferProhibited http:\/\/www.icann.org\/epp#clientTransferProhibited<br \/>\nDomain Status: clientUpdateProhibited http:\/\/www.icann.org\/epp#clientUpdateProhibited<br \/>\nDomain Status: clientRenewProhibited http:\/\/www.icann.org\/epp#clientRenewProhibited<br \/>\nDomain Status: clientDeleteProhibited http:\/\/www.icann.org\/epp#clientDeleteProhibited<br \/>\nRegistry Registrant ID:<br \/>\nRegistrant Name: gina zipperian<br \/>\nRegistrant Organization:<br \/>\nRegistrant Street: pu tian<br \/>\nRegistrant Street: fu jian<br \/>\nRegistrant City: fujian<br \/>\nRegistrant State\/Province: jiao wei<br \/>\nRegistrant Postal Code: 351253<br \/>\nRegistrant Country: China<br \/>\nRegistrant Phone: +86.15860339007<br \/>\nRegistrant Phone Ext:<br \/>\nRegistrant Fax:<br \/>\nRegistrant Fax Ext:<br \/>\nRegistrant Email: 157505829@qq.com<br \/>\nRegistry Admin ID:<br \/>\nAdmin Name: gina zipperian<br \/>\nAdmin Organization:<br \/>\nAdmin Street: pu tian<br \/>\nAdmin Street: fu jian<br \/>\nAdmin City: fujian<br \/>\nAdmin State\/Province: jiao wei<br \/>\nAdmin Postal Code: 351253<br \/>\nAdmin Country: China<br \/>\nAdmin Phone: +86.15860339007<br \/>\nAdmin Phone Ext:<br \/>\nAdmin Fax:<br \/>\nAdmin Fax Ext:<br \/>\nAdmin Email: 157505829@qq.com<br \/>\nRegistry Tech ID:<br \/>\nTech Name: gina zipperian<br \/>\nTech Organization:<br \/>\nTech Street: pu tian<br \/>\nTech Street: fu jian<br \/>\nTech City: fujian<br \/>\nTech State\/Province: jiao wei<br \/>\nTech Postal Code: 351253<br \/>\nTech Country: China<br \/>\nTech Phone: +86.15860339007<br \/>\nTech Phone Ext:<br \/>\nTech Fax:<br \/>\nTech Fax Ext:<br \/>\nTech Email: 157505829@qq.com<br \/>\nName Server: NS47.DOMAINCONTROL.COM<br \/>\nName Server: NS48.DOMAINCONTROL.COM<br \/>\nDNSSEC: unsigned<br \/>\nURL of the ICANN WHOIS Data Problem Reporting System: http:\/\/wdprs.internic.net\/[\/CODE]<\/p>\n<p>We suspect that that phishing and malware were used to enable a domain transfer away from the legitimate owners to the scammers. Having to reinstall your PC to get rid of a malware infestation is one thing. Losing an established domain that you spent years promoting on the web is another.<\/p>\n<p>Protecting yourself from phishing and malware is more important than ever.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Spammer who set up fake websites offering brand name products to sell counterfeit merchandise or to steal credit card details of would-be buyers often hack third party websites to host ads and shopping websites on them. On top of that &hellip; <a href=\"https:\/\/joewein.net\/blog\/2015\/03\/17\/domains-hijacked-by-fake-brand-spammers\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6,2],"tags":[],"class_list":["post-2353","post","type-post","status-publish","format-standard","hentry","category-fraud","category-spam"],"_links":{"self":[{"href":"https:\/\/joewein.net\/blog\/wp-json\/wp\/v2\/posts\/2353","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/joewein.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/joewein.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/joewein.net\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/joewein.net\/blog\/wp-json\/wp\/v2\/comments?post=2353"}],"version-history":[{"count":2,"href":"https:\/\/joewein.net\/blog\/wp-json\/wp\/v2\/posts\/2353\/revisions"}],"predecessor-version":[{"id":2355,"href":"https:\/\/joewein.net\/blog\/wp-json\/wp\/v2\/posts\/2353\/revisions\/2355"}],"wp:attachment":[{"href":"https:\/\/joewein.net\/blog\/wp-json\/wp\/v2\/media?parent=2353"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/joewein.net\/blog\/wp-json\/wp\/v2\/categories?post=2353"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/joewein.net\/blog\/wp-json\/wp\/v2\/tags?post=2353"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}