ALERT: Please treat content from these domains with caution…
cdn-adrotation.com
cdn-businessweek.com
cdn-gamingahead.com
cdn-justin.tv
cdn-ovguide.com
cdn-thestreet.com
cdn-transworld.net
cdn-veoh.com
pdnads.com
The Registrants are all hidden behind Domains By Proxy, Inc, all domains are hosted at IP 74.81.169.61 (carohosting.net), all were registered using Godaddy, and all were created on 14 July 2009.
All are using name servers at softdreams.eu
softdreams.eu was registered on 6 February 2009 to a Ionut Bogdan Dumitru, Str.Zambielor nr. 6, bl. 60, ap.5, sector 2, 032801 Bucuresti, Romania.
You’ll see that there was a complaint about cdn-adrotation.com content back in September of this year at gaiaonline.com (a web site that has had more than its fair share of malvertizing):
and the Kaspersky forums:
http://forum.kaspersky.com/lofiversion/index.php/t138891.html
As well as a smattering of other places.
It is concerning that names such as businessweek and veoh are there. In fact, take away "cdn-" and every single URL leads to legitimate domain (except for adrotation.com).
It makes you wonder if the domains are intended for use to impersonate legitimate websites such as businessweek.com and veoh.com…