ALERT: Please treat all content from plexusmedia-adv.com and plexusmedia.net with extreme caution
As always, all domains listed here (except for plexusmedia.co.uk) should be treated with extreme caution.
Sources report that suspicious content using the domain plexusmedia-adv.com has been discovered. This domain redirects to plexusmedia.net.
Both domains should not be confused with the legitimate plexusmedia.co.uk.
What is interesting is that plexusmedia-adv.com AND plexusmedia.net are BOTH new domains. Historically the bad guys redirect visitors from their bad domain to a known good domain.
The tags using plexusmedia-adv.com exposed viewers to content from 206.217.206.145 and apt-adserver.net.
apt-adserver.net shares IP with mojoadserver.net. The domain mojoadserver.net has been seen to redirect visitors to mediaplex.com/mojo_adserver.shtml. mojoadserver.net has NO association with the legitimate company MediaPlex.
The agency that supplied the plexusmedia-adv.com tags pre-paid via Paypal (email address paypal@hotfile.com). The contact on file for the agency was "Natalie Portman" using the email address natalie.portman@in-one.eu. As so often happens in these cases, there was a sense of urgency from the agency in question, with the agency wanting the campaign to go live as soon as possible.
stopfraud.org reports that in-one.eu was claiming to represent a US cosmetics company, a claim that the US cosmetics company denied – the name Natalie Portman appears in that report also:
http://www.stopadfraud.org/2010/03/in-one-eu-fake-agency/
plexusmedia-adv.com
ICANN Registrar: EVOPLUS LTD
Created 18 March 2010
IP: 206.217.200.88 – Chicago, Illinois – Hosting Services Inc.
Shares IP with ns2.apt-adserver.net.
Registrant hidden behind a privacy protection service.
*****
plexusmedia.net
ICANN Registrar: EVOPLUS LTD
Created 15 March 2010
IP: 78.140.149.89 - Webazilla B.v
Shares IP with ad2deliver.com, in-one.eu and coin-media.com.
Registrant hidden behind a privacy protection service.
Plexusmedia.net gives its address as Rossello, 478, Barcelona, 08025,
Spain – which is an internet café:
*****
apt-adserver.net
ICANN Registrar: ENOM Inc
Created 10 March 2010
IP: 206.217.200.84 – Chicago, Illinois, Hosting Services Inc.
Shares IP with mojoadserver.net
Registrant: Stiven Mon (stive@catedral.es)
*****
mojoadserver.net
ICANN Registrar: ENOM Inc
Created 10 March 2010
IP: 206.217.200.84 – Chicago, Illinois, Hosting Services Inc.
Registrant: Stiven Mon (stive@catedral.es)
*****
ad2deliver.com
ICANN Registrar: EVOPLUS LTD
Created 8 February 2010
IP: 78.140.149.89 - Webazilla B.v
Registrant hidden behind a privacy protection service.
*****
in-one.eu
ICANN REGISTRAR: DIRECTI
Created 18 November 2009
IP: 78.140.149.89 - Webazilla B.v
Registrant: mika@in-one.eu
*****
coin-media.com
ICANN REGISTRAR: DIRECTI
Created 22 October 2009
IP: 78.140.149.89 – Webazilla B.v
Registrant hidden behind privacy protection service.
“ALERT: Please treat all content from plexusmedia-adv.com and plexusmedia.net with extreme caution”