Domain Name: VENDASOINVESTAS.COM
Registrar: ESTDOMAINS, INC.
Whois Server: whois.estdomains.com
Referral URL: http://www.estdomains.com
Name Server: NS1.GRISHEK.RU
Name Server: NS2.GRISHEK.RU
Updated Date: 26-mar-2008
Creation Date: 26-mar-2008
Expiration Date: 26-mar-2009
The website at this domain currently serves a script which redirects to http://www.v-i-b.biz/index-4.html. That page has the title, "Vendas o Investas de Brazil", which is presumably what V.I.B. is supposed to stand for. This page also confirms that the scam is a money mule job: "During all working process you will operate with money transfers, so you have to provide us with valid bank account which you will be using especially for our company needs and transfers you process and forward."
Domain Name: V-I-B.BIZ
Domain ID: D22972891-BIZ
Sponsoring Registrar: ESTDOMAINS INC
Sponsoring Registrar IANA ID: 832
Domain Status: clientTransferProhibited
Registrant ID: DI_6758232
Registrant Name: Voland
Registrant Email: v@volandzerocker.info
Name Server: NS1.VOLAND-DNS.ORG
Name Server: NS2.VOLAND-DNS.ORG
Created by Registrar: ESTDOMAINS INC
Last Updated by Registrar: ESTDOMAINS INC
Domain Registration Date: Thu Jan 31 18:33:14 GMT 2008
Domain Expiration Date: Fri Jan 30 23:59:59 GMT 2009
Domain Last Updated Date: Tue Mar 25 12:21:38 GMT 2008
Curious -- who is volandzerocker.info? And who is voland-dns.org?
Domain ID:D23068396-LRMS
Domain Name:VOLANDZEROCKER.INFO
Created On:30-Dec-2007 11:10:15 UTC
Last Updated On:29-Feb-2008 03:00:39 UTC
Expiration Date:30-Dec-2008 11:10:15 UTC
Sponsoring Registrar:Blog.com Digital Communications Inc. (R315-LRMS)
Registrant ID:DI_4356825
Registrant Name:Veev
Registrant Email:admin@veev.ru
Name Server:NS1.3MA.RU
Name Server:NS2.3MA.RU
Domain ID:D152132088-LROR
Domain Name:VOLAND-DNS.ORG
Created On:25-Mar-2008 11:48:04 UTC
Last Updated On:25-Mar-2008 11:55:28 UTC
Expiration Date:25-Mar-2009 11:48:04 UTC
Sponsoring Registrar:EstDomains, Inc. (R1345-LROR)
Registrant ID:DI_3079491
Registrant Name:Pit Gate
Registrant Email:pitgate@bigmam.org
Name Server:MANAGEDNS1.ESTBOXES.COM
Name Server:MANAGEDNS2.ESTBOXES.COM
Quite a twisty little maze of recent registrations, this. The domain "bigmam.org" currently advertises "localhost" for its MX host (mail), so that's pretty much a dead end. On the other hand, "veev.ru" has no MX record, but does have an address record, so it could theoretically receive mail. The record has a "time to live" of ten minutes, however, which potentially makes it a fast-flux target.
---------- Forwarded message ----------
From: [redacted (random)]
Date: 26 Mar 2008 XX:XX UTC
Subject: PART-TIME
To: ideceive@gmail.com
[CareerBuilder graphic redacted] | |||
WE HAVE A JOB FOR YOU.
|