Another Directi registered fraudware domain
It seems to me that Directi is not even close to cleaning up its act, and they certainly don’t seem to be keeping away from domains that are used to facilitate the distribution of fraudware. Just over the past few days I have encountered quicktds.com (which had been registered since 16 Sept), pcvirusbuster.com (registered 7 October), vsemutorba.com (registered on 2 April 2008), quicktds.name (registered 16 September), trap17.com (registered 9 May 2004), orderbox-dns.com (registered 2 July 2004), computinghost.com, trusted-scanner.com (registered 30 September), antivirus-fullscan.com (registered 7 October), and now royalproscan.com.
Here’s the problem – this domain was created on 13 October 2008. It is now 16 October 2008. The bad guys have had 3 days to make good use of their latest domain.
royalproscan.com (216.240.134.211 – California – Irvine – Go2online Corp)
ICANN Registrar: Directi Internet Solutions
Created: 13 October 2008
NS: DOMISHKO.EARTH.ORDERBOX-DNS.COM (has 37,446 domains)
NS: DOMISHKO.MARS.ORDERBOX-DNS.COM
NS: DOMISHKO.MERCURY.ORDERBOX-DNS.COM
NS: DOMISHKO.VENUS.ORDERBOX-DNS.COM
WHOIS: Hidden behind privacyprotect.org
Fraudware URL:
royalproscan.com/2009/1/freescan.php?id=<<snipped>>
“Another Directi registered fraudware domain”