WhoIs – pegashosting.com – Money Mule Server [AS28753]


Reverse IP Lookup for 78.159.112.46
IP Address: 78.159.112.46
IP Location: Germany
Internet host name for this ip address: node1.webgater.com

Websites shared hosted on 78.159.112.46
Websafeclicks http://www.websafeclicks.com
Zetaclicks4 http://www.zetaclicks4.com
Searchclick2 http://www.searchclick2.com
Searchmeup4 http://www.searchmeup4.com

I cannot verify if the netblock WHOIS details are accurate:
inetnum: 178.162.135.0 – 178.162.135.255
netname: Maxim-Staricin-966729
descr: PegasHosting Network
country: UA
admin-c: MS20894-RIPE
tech-c: SR614-RIPE
status: ASSIGNED PA
mnt-by: NETDIRECT-MNT
mnt-lower: NETDIRECT-MNT
mnt-routes: NETDIRECT-MNT
source: RIPE # Filtered

person: Maxim Staricin
address: 6/40 Mira str.
address: Kiev 03134
address: Ukraine
phone: +380994005332
fax-no: +380994005332
abuse-mailbox: abuse@pegashosting.com
nic-hdl: MS20894-RIPE
mnt-by: NETDIRECT-MNT
source: RIPE # Filtered

pegashosting.com was only registered in February, so hardly an old company.

Service Provided By: Center of Ukrainian Internet Names
Website: http://www.ukrnames.com
Contact: +380.577626123

Domain Name: PEGASHOSTING.COM

Creation Date: 01-Feb-2010
Modification Date: 01-Feb-2010
Expiration Date: 01-Feb-2011

Domain servers in listed order:
ns1.pegashosting.com
ns2.pegashosting.com

Registrant:
Staricin Maxim
PegasHosting.com
6/40 Mira str.
Kiev, 03134
UKRAINE
+380.994005332

Billing Contact:
Staricin Maxim abuse@pegashosting.com
Private person
6/40 Mira str.
Kiev, 03134
UKRAINE
+380.994005332

Administrative Contact:
Staricin Maxim abuse@pegashosting.com
PegasHosting.com
6/40 Mira str.
Kiev, 03134
UKRAINE
+380.994005332

Technical Contact:
Staricin Maxim abuse@pegashosting.com
PegasHosting.com
6/40 Mira str.
Kiev, 03134
UKRAINE
+380.994005332


Address lookup

 

canonical name pegashosting.com
aliases
addresses 208.73.210.29
Domain Whois record

Queried whois.internic.net with “dom pegashosting.com”…

Domain Name: PEGASHOSTING.COM
Registrar: ! #1 HOST KOREA, INC.
Whois Server: whois.1hostkorea.com
Referral URL: http://www.1hostkorea.com
Name Server: NS1.DSREDIRECTION.COM
Name Server: NS2.DSREDIRECTION.COM
Status: clientDeleteProhibited
Status: clientTransferProhibited
Status: clientUpdateProhibited
Updated Date: 02-oct-2010
Creation Date: 02-oct-2010
Expiration Date: 02-oct-2011

Last update of whois database: Thu, 14 Oct 2010 04:46:25 UTC
Queried whois.1hostkorea.com with “pegashosting.com”…
Domain Name: PEGASHOSTING.COM
Registrar: 1HOSTKOREA

Registrant [1300164]:
Admin – admin@overseedomainmanagement.com
Oversee Domain Management, LLC
515 South Flower Street
Suite 4400
Los Angeles
CA
90071
US

Administrative Contact [1300164]:
Admin – admin@overseedomainmanagement.com
Oversee Domain Management, LLC
515 South Flower Street
Suite 4400
Los Angeles
CA
90071
US
Phone: +1.2132653191

Billing Contact [1300164]:
Admin – admin@overseedomainmanagement.com
Oversee Domain Management, LLC
515 South Flower Street
Suite 4400
Los Angeles
CA
90071
US
Phone: +1.2132653191

Technical Contact [1300164]:
Admin – admin@overseedomainmanagement.com
Oversee Domain Management, LLC
515 South Flower Street
Suite 4400
Los Angeles
CA
90071
US
Phone: +1.2132653191

Domain servers in listed order:

NS1.DSREDIRECTION.COM
NS2.DSREDIRECTION.COM

Record created on: 2010-10-02 14:29:19.0
Database last updated on: 2010-10-02 18:30:29.02
Domain Expires on: 2011-10-02 14:29:19.0

Network Whois record

Queried whois.arin.net with “n 208.73.210.29″…

NetRange: 208.73.208.0 – 208.73.215.255
CIDR: 208.73.208.0/21
OriginAS:
NetName: OVERSEE-NET-2
NetHandle: NET-208-73-208-0-1
Parent: NET-208-0-0-0-0
NetType: Direct Assignment
NameServer: NS2.OVERSEE.NET
NameServer: NS1.OVERSEE.NET
RegDate: 2006-12-28
Updated: 2006-12-28
Ref: http://whois.arin.net/rest/net/NET-208-73-208-0-1

OrgName: Oversee.net
OrgId: OVERS-1
Address: 515 S. Flower St
Address: Suite 4400
City: Los Angeles
StateProv: CA
PostalCode: 90071
Country: US
RegDate: 2003-08-01
Updated: 2008-11-10
Ref: http://whois.arin.net/rest/org/OVERS-1

OrgTechHandle: OVERS-ARIN
OrgTechName: Oversee NOC
OrgTechPhone: +1-213-408-0080
OrgTechEmail: ipadmin@oversee.net
OrgTechRef: http://whois.arin.net/rest/poc/OVERS-ARIN

OrgAbuseHandle: OVERS-ARIN
OrgAbuseName: Oversee NOC
OrgAbusePhone: +1-213-408-0080
OrgAbuseEmail: ipadmin@oversee.net
OrgAbuseRef: http://whois.arin.net/rest/poc/OVERS-ARIN
DNS records

DNS query for 29.210.73.208.in-addr.arpa returned an error from the server: NameError

name class type data time to live
pegashosting.com IN A 208.73.210.29 600s (00:10:00)
pegashosting.com IN NS ns2.dsredirection.com 3600s (01:00:00)
pegashosting.com IN NS ns1.dsredirection.com 3600s (01:00:00)
pegashosting.com IN MX
preference: 0
exchange: 127.0.0.1
7200s (02:00:00)
pegashosting.com IN SOA
server: ns1.dsredirection.com
email: hostmaster.oversee.net
serial: 2010100804
refresh: 16384
retry: 2048
expire: 1048576
minimum ttl: 25670
3600s (01:00:00)
pegashosting.com IN TXT v=spf1 -all 3600s (01:00:00)
— end —

  1. Escrow-ento.com
  2. Careers-kivox.com
  3. Careers-tekset.com
  4. Deutschenoote.com
  5. Es-trabajowug.com
  6. Gamestaff.org
  7. Hat.am
  8. Intelligentlogistics.biz
  9. Jobs-kivox.com
  10. Jobs-tekset.com
  11. Kivox-careers.com
  12. Kivox-company.com
  13. Kivox-consulting.com
  14. Kivox-jobs.com
  15. Kivox-today.com
  16. Mcashjdg.com
  17. Mejdskas.com
  18. Mhasdhfg.com
  19. Mksdjhfu.com
  20. Myasjhaa.com
  21. Pootervom.com
  22. Shop-n-ship.net
  23. Tekset-careers.com
  24. Tekset-consulting.com
  25. Tekset-jobs.com
  26. Tekset-news.com
  27. Trilane-careers.com
  28. Trilane-consulting.com
  29. Trilane-jobs.com
  30. Trilanecareers.com
  31. Trilaneconsulting.com
  32. Work-at-duolux.com
  33. Work-at-tekset.com
  34. Spicegrossisten.com
  35. Spicegrossisten.org
  36. Mlhsgdhh.com
  37. Jacksonstatue.com
  38. Gl-transport.com
  39. N-transport.com
  40. Hiring-westunion.com
  41. Ebaysquaretrade.com
  42. Bongblogs.net
  43. Bonglove.net
  44. Kydesniki.net
  45. Love4net.net
  46. Office-exchange.biz
  47. Office-exchange.info
  48. Avalonassistants.com
  49. Bettertasks.com
  50. Kptarnews.com
  51. Adjustedresults.com
  52. Resultscache.com
  53. Mailcenter-yahoo.com
  54. Allhdmovies.com
  55. X-torrents.info
  56. X-torrents.name
  57. X-torrents.net
  58. X-torrents.nu
  59. X-torrents.org
  60. X-torrents.ru
  61. Beachamateursite.info
  62. Hotlatinotube.info
  63. Hotnudistmix.info
  64. Partyhotpregnant.info
  65. Redheadvideovideos.info
  66. Siteblondhot.info
  67. Todaysnewest.com
  68. Tubegirlsexy.info
  69. Tuberedheadnudist.info
  70. Tuberedheadsexy.info
  71. Wetlesbianstube.info
  72. Big-stan.ru
  73. Careers-at-lexor.com
  74. Careers-stendal.com
  75. Europe-stendal.com
  76. Hallway-careers.com
  77. Hallway-group-careers.com
  78. Hallway-group-jobs.com
  79. Hallway-jobs.com
  80. Hallway-news.com
  81. Hallway-today.com
  82. Immobilie-vitrea.com
  83. Jobs-at-stendalgroup.com
  84. Jobs-stendal.com
  85. Kernet.name
  86. Lexor-careers.com
  87. Lexor-consulting.com
  88. Lexor-jobs.com
  89. Lexor-sl-careers.com
  90. Lexor-sl-consulting.com
  91. Lexor-sl.com
  92. Lexorsl.com
  93. Mybisiness.org
  94. News-stendal.com
  95. Onlinerentalparadise.com
  96. Silentspy.ru
  97. Stendal-applications.com
  98. Stendal-careers-now.com
  99. Stendal-careers-today.com
  100. Stendal-consulting-group.com
  101. Stendal-consulting.com
  102. Stendal-news.com
  103. Stendal-today.com
  104. Stendalcareers.com
  105. Stendaljobs.com
  106. Stendaltoday.com
  107. Vitrea-arbeit.com
  108. Vitrea-deutchland.eu
  109. Vitrea-estate-agents.com
  110. Vitrea-estate.eu
  111. Vitrea-immobilie-karrieren.com
  112. Vitrea-immobilie.com
  113. Vitrea-karrieren.com
  114. Vitrea-today.com
  115. Vitrea-uk.com
  116. Vitreaestate-europe.com
  117. Vitreaestatecareers.com
  118. Vitreajobs.com
  119. Vitreanews.com
  120. Wr-mail.ru
  121. Arbeit-vitrea.com
  122. Careers-at-stendal.com
  123. Careers-at-vitrea.com
  124. Jobs-at-hallway-group.com
  125. Jobs-at-lexor.com
  126. Jobs-at-stendal.com
  127. Jobs-lexor.com
  128. Karrieren-immobilie-vitrea.com
  129. Karrieren-vitrea.com
  130. Msk-guvd.org
  131. Westunionhiring.com
  132. Romlife.net
  133. Mypsp.my
  134. Qzzb.ru
  135. Softcracks.com
  136. Mayki.in
  137. Sms-partner.net
  138. Wmmailz.com
  139. Xandgo.net
  140. Dragporno.ru
  141. Megaru.com
  142. Nafani.net
  143. Pop-banner.ru
  144. Watchporno.ru
  145. Xlivetv.ru
  146. Alternativedabell.com
  147. Alternativedago.com
  148. Alternativedasound.com
  149. Alternativedassound.com
  150. Alternativedasting.com
  151. Best-freemovie.com
  152. Best-freemovies.com
  153. Dasoundservices.com
  154. Datingprivates.com
  155. Datingteen.net
  156. Datingteenonline.net
  157. Datingwork.com
  158. Free-moviebest.com
  159. Freemoviebest.com
  160. Fremoviesbest.com
  161. Moviebest-free.com
  162. Moviefree-best.com
  163. Moviesbest-free.com
  164. Moviesfree-best.com
  165. Myalternativedating.com
  166. Naebalova.net
  167. Releaseadultsex.com
  168. Releaseating.com
  169. Thefreedating.com
  170. Webalternativedating.com
  171. Webfreeadultsexnet.com
  172. Sportsbear.net
  173. Tdsse.net
  174. Qctsupport.com
  175. Neomaks.ru
  176. Videobum.net
  177. Pornogandon.ru
  178. Mp3gigant.net
  179. Gpssystemsused.com
  180. Mangomeds.net
  181. Mangomeds.org
  182. Medswhite.com
  183. Ourmeds.org
  184. 4aclepsa.com
  185. Medisupprt.com
  186. Cadipll.com
  187. Bonus-file.net
  188. Yastreb.biz

pcvirus-destroyer.com ns1.pcvirus-destroyer.com => 213.155.22.193
ns2.pcvirus-destroyer.com => 213.155.22.194
(AS28753) NETDIRECT
78.159.97.146 Directs to Trojan 2009-09-26
details
systemthreatkiller.com ns1.systemthreatkiller.com => 213.155.22.193
ns2.systemthreatkiller.com => 213.155.22.194
(AS28753) NETDIRECT
78.159.97.146 Directs to Trojan 2009-09-26
details
yoursystem-protector.com ns1.yoursystem-protector.com => 213.155.22.193
ns2.yoursystem-protector.com => 213.155.22.194
(AS28753) NETDIRECT
78.159.97.146 Directs to Trojan 2009-09-26
details
pcthreatremover.com ns1.pcthreatremover.com => 213.155.22.193
ns2.pcthreatremover.com => 213.155.22.194
(AS28753) NETDIRECT
78.159.97.147 Fake codec page / Directs to Trojan 2009-09-24
details
pctrouble-remover.com ns1.pctrouble-remover.com => 213.155.22.193
ns2.pctrouble-remover.com => 213.155.22.194
(AS28753) NETDIRECT
78.159.97.147 Directs to Trojan FakeSmoke 2009-09-22
details
malware-reaper.com ns1.malware-reaper.com => 213.155.22.193
ns2.malware-reaper.com => 213.155.22.194
(AS41665) HOSTING
213.155.22.193 Fake scanner page / Directs to TRojan FakeSmoke 2009-09-22
details
scareware-killer.com ns1.scareware-killer.com => 213.155.22.193
ns2.scareware-killer.com => 213.155.22.194
(AS28753) NETDIRECT
78.159.97.147 Fake scanner page / Directs to Trojan FakeSmoke (SaveDefender) 2009-09-20
details
scan-4-clean.com ns1.scan-4-clean.com => 213.155.22.193
ns2.scan-4-clean.com => 213.155.22.194
(AS28753) NETDIRECT
78.159.97.147 Fake scanner page / SoftSafeness 2009-09-16
details
topspyfreecheck.com ns1.topspyfreecheck.com => 213.155.22.193
ns2.topspyfreecheck.com => 213.155.22.194
(AS4645) HKNET
203.169.164.18 Fake scanner page / SoftSafeness 2009-09-16
details
checkerforfree.com ns1.checkerforfree.com => 213.155.22.193
ns2.checkerforfree.com => 213.155.22.194
(AS4645) HKNET
203.169.164.18 Fake scanner page / Directs to Trojan 2009-09-15
details

 

Stimul Media aka Rx Partners – stimul-cash.com

Buying Prescription Drugs Online Scam Alert 1
May Be Dangerous
Says Drug Enforcement Administration

DEA Logo - Buying Proscription Drugs

Click Here
National Association of Boards of Pharmacy (NABP)

Warning

“The Canadian Pharmacy, Canadian/European Pharmacy”, “Canadian Healthcare” and “US Drugstore” are brands of one of the most disgusting illegal online pharmacy group well organized CRIMINAL OPERATION of all times. “GREED” is the driving force behind this operation. Don’t let them fool you. They will never send you any genuine drugs. If they ever send anything at all, it may consist of literally anything from sugar to wall plaster, and they certainly don’t care that you will endanger your health by taking those dangerous counterfeit drugs.

Behind The Online Pharmacy

Today a shadowy, transnational network of illicit drug manufacturers, traders, doctors, Web site operators, spammers and criminals makes up the online pharmacy world.

Buying Medication Online Can Be Safe


salezhelp

October 22, 2007
Stimul Media and Rx Partners relation
Filed under: reviews — Crevete @ 6:51 am
Today I signed up for two pharmacy affiliate programs: Rx Partners and Stimul Cash (former known as Stimul Media). As you know, signing up for these two is quite hard these days and you are required to have invitation code plus webmaster approval to start making money with them. Here is a conversation with the approval guy (Mark from Rx-Partners):

14:58:58 Me: Hello! I want to sign-up with stimul-media but the signup form does not appear. https://www.stimul-media.com/signup.html Please leave offline message if it’s the case.
11:32:00 stimul-media: please register here http://www2.stimul-cash.com/signup.html
13:18:31 Me: Hello! How can I sign-up on stimul-cash.com and give credit to a friend that reffered me? Is http://www2.stimul-cash.com/?partner=2331 going to work?
13:19:22 stimul-media: yes, it will work.
13:19:34 : ok, thanks
13:22:22 stimul-media: are you signing up in Rx-parterns as well?
13:22:38 Me: yes
13:22:51 Me: how did you know?
13:23:20 430886685: we run both programs
13:23:34 Me: I understand
13:23:42 430886685: can yo uplease tellme how exactly are you planning to advertisie our sites?
I will advertise on http://www.bubub.org/, search engine traffic.
13:25:15 430886685: I have apporved your account
13:25:23 Me: ok
13:25:31 Me: thank you
That’s a lot of money these dudes are making. Two of the top affiliate programs. Hope this shit will work for me. If you want to sign up with Rx Partners and need an invitation code please leave a comment, I will respond in less than an hour. Also if you need affiliate coaching don’t hesitate to

bother me.
Later!

Address lookup
canonical name http://www.stimul-cash.com
aliases
addresses 72.52.4.173
Domain Whois record

Queried whois.internic.net with “dom stimul-cash.com”…

Domain Name: WWW.STIMUL-CASH.COM
Registrar: REALTIME REGISTER BV
Whois Server: whois.yoursrs.com
Referral URL: http://www.realtimeregister.com
Name Server: NS0.STIMULCASH.COM
Name Server: NS1.STIMULCASH.COM
Status: clientTransferProhibited
Updated Date: 24-sep-2010
Creation Date: 16-mar-2007
Expiration Date: 16-mar-2013

>>> Last update of whois database: Wed, 13 Oct 2010 20:26:41 UTC <<<
Queried whois.yoursrs.com with “stimul-cash.com”…

Domain Name:stimul-cash.com
Name Server:ns1.stimulcash.com
Name Server:ns0.stimulcash.com

Created On:2010-08-13
Last Updated On:2010-09-24
Expiration Date:2013-03-16
Dealer:stimul
Registrant ID:stimul
Registrant Name:Vitaly Petrov
Registrant Organization:STIMUL-MEDIA.COM
Registrant Street1:Petrozavodskaya st, 16
Registrant Street2:
Registrant Street3:
Registrant City:Moscow
Registrant State/Province:
Registrant Postal Code:125414
Registrant Country:RU
Registrant Phone:+7.9160248086
Registrant Fax:
Registrant Email:vitalypetrov76@yahoo.com

Admin ID:stimul
Admin Name:Vitaly Petrov
Admin Organization:STIMUL-MEDIA.COM
Admin Street1:Petrozavodskaya st, 16
Admin Street2:
Admin Street3:
Admin City:Moscow
Admin State/Province:
Admin Postal Code:125414
Admin Country:RU
Admin Phone:+7.9160248086
Admin Fax:
Admin Email:vitalypetrov76@yahoo.com

Billing ID:stimul
Billing Name:Vitaly Petrov
Billing Organization:STIMUL-MEDIA.COM
Billing Street1:Petrozavodskaya st, 16
Billing Street2:
Billing Street3:
Billing City:Moscow
Billing State/Province:
Billing Postal Code:125414
Billing Country:RU
Billing Phone:+7.9160248086
Billing Fax:
Billing Email:vitalypetrov76@yahoo.com

Tech ID:stimul
Tech Name:Vitaly Petrov
Tech Organization:STIMUL-MEDIA.COM
Tech Street1:Petrozavodskaya st, 16
Tech Street2:
Tech Street3:
Tech City:Moscow
Tech State/Province:
Tech Postal Code:125414
Tech Country:RU
Tech Phone:+7.9160248086
Tech Fax:
Tech Email:vitalypetrov76@yahoo.com

Network Whois record
Queried whois.arin.net with “n 72.52.4.173″…

NetRange: 72.52.0.0 – 72.52.63.255
CIDR: 72.52.0.0/18
OriginAS:
NetName: PROLEXIC
NetHandle: NET-72-52-0-0-1
Parent: NET-72-0-0-0-0
NetType: Direct Allocation
NameServer: NS2.PROLEXIC.NET
NameServer: NS1.PROLEXIC.NET
Comment: http://www.prolexic.com / NOC hours are 24/7
RegDate: 2005-07-11
Updated: 2007-06-27
Ref: http://whois.arin.net/rest/net/NET-72-52-0-0-1

OrgName: Prolexic Technologies, Inc.
OrgId: PROLE
Address: 1930 Harrison Street
City: Hollywood
StateProv: FL
PostalCode: 33020
Country: US
RegDate: 2004-07-15
Updated: 2009-10-16
Ref: http://whois.arin.net/rest/org/PROLE

OrgTechHandle: HOSTM528-ARIN
OrgTechName: Hostmaster
OrgTechPhone: +1-866-800-0366
OrgTechEmail: hostmaster@prolexic.com
OrgTechRef: http://whois.arin.net/rest/poc/HOSTM528-ARIN

RTechHandle: HOSTM528-ARIN
RTechName: Hostmaster
RTechPhone: +1-866-800-0366
RTechEmail: hostmaster@prolexic.com
RTechRef: http://whois.arin.net/rest/poc/HOSTM528-ARIN
DNS records

name class type data time to live
stimul-cash.com IN MX
preference: 10
exchange: mail.stimul-cash.com
600s (00:10:00)
stimul-cash.com IN A 72.52.4.173 600s (00:10:00)
stimul-cash.com IN SOA
server: ns0.stimulcash.com
email: root.stimulcash.com
serial: 2010824934
refresh: 3600
retry: 900
expire: 604800
minimum ttl: 1200
600s (00:10:00)
stimul-cash.com IN NS ns0.stimulcash.com 600s (00:10:00)
stimul-cash.com IN NS ns1.stimulcash.com 600s (00:10:00)
173.4.52.72.in-addr.arpa IN PTR unknown.prolexic.com 86400s (1.00:00:00)
— end —
IP address: 72.52.4.173
Host name: stimul-cash.com
Alias:
stimul-cash.com
72.52.4.173 is from United States(US) in region North America

TraceRoute to 72.52.4.173 [stimul-cash.com]
Hop (ms) (ms) (ms) IP Address Host name
1 53 41 30 72.249.128.5 –
2 23 14 8 8.9.232.73 xe-5-3-0.edge3.dallas1.level3.net
3 Timed out 41 Timed out 66.192.240.94 dal2-pr1-ge-5-0-0-0.us.twtelecom.net
4 26 37 23 157.238.224.193 xe-0-4-0-1.r07.dllstx09.us.bb.gin.ntt.net
5 24 46 11 129.250.3.66 ae-6.r20.dllstx09.us.bb.gin.ntt.net
6 63 41 42 129.250.6.87 as-0.r21.miamfl02.us.bb.gin.ntt.net
7 48 47 41 209.200.132.34 blackhole.prolexic.com
8 51 69 80 157.238.179.6 ge-4-12.r02.miamfl02.us.ce.gin.ntt.net
9 51 44 55 209.200.132.34 blackhole.prolexic.com
10 69 80 58 72.52.4.173 unknown.prolexic.com
Trace complete

Retrieving DNS records for stimul-cash.com…
DNS servers
ns0.stimulcash.com
ns1.stimulcash.com
Query for DNS records for stimul-cash.com failed: Timed out
Whois query for stimul-cash.com…
Query error: Timed out
Network IP address lookup:

Whois query for 72.52.4.173…

Results returned from whois.arin.net:
#
# The following results may also be obtained via:
# http://whois.arin.net/rest/nets;q=72.52.4.173?showDetails=true&showARIN=false
#

NetRange: 72.52.0.0 – 72.52.63.255
CIDR: 72.52.0.0/18
OriginAS:
NetName: PROLEXIC
NetHandle: NET-72-52-0-0-1
Parent: NET-72-0-0-0-0
NetType: Direct Allocation
NameServer: NS2.PROLEXIC.NET
NameServer: NS1.PROLEXIC.NET
Comment: http://www.prolexic.com / NOC hours are 24/7
RegDate: 2005-07-11
Updated: 2007-06-27
Ref: http://whois.arin.net/rest/net/NET-72-52-0-0-1

OrgName: Prolexic Technologies, Inc.
OrgId: PROLE
Address: 1930 Harrison Street
City: Hollywood
StateProv: FL
PostalCode: 33020
Country: US
RegDate: 2004-07-15
Updated: 2009-10-16
Ref: http://whois.arin.net/rest/org/PROLE

OrgTechHandle: HOSTM528-ARIN
OrgTechName: Hostmaster
OrgTechPhone: +1-866-800-0366
OrgTechEmail: hostmaster@prolexic.com
OrgTechRef: http://whois.arin.net/rest/poc/HOSTM528-ARIN

RTechHandle: HOSTM528-ARIN
RTechName: Hostmaster
RTechPhone: +1-866-800-0366
RTechEmail: hostmaster@prolexic.com
RTechRef: http://whois.arin.net/rest/poc/HOSTM528-ARIN

#
# ARIN WHOIS data and services are subject to the Terms of Use
# available at: https://www.arin.net/whois_tou.html

679-205-2937
1-679-205-2937
(679)205-2937

Billing LTD – VERITASGROUP-LLC.COM

The Purpose of This Post Is To ALERT You That The Job You Are About To APPLY For or May Have Applied For or is CONSIDERING APPLYING For Is Scam Alert 1Fraudulent. A LEGITIMATE COMPANY IDENTITY OR AN INDIVIDUAL IDENTITY HAS BEEN STOLEN OR A BOGUS ONE CREATED

These job postings are an attempt to lure you into cashing counterfeit checks and have you wire funds via Western Union or MoneyGram -Essentially You Become A Money or RePackage Mule

Understanding The Cyber Theft Ring
Money Mule Explained

Washingtonpost.com by Brian Kerbs

Interview With A Money Mule


Hi,

 

I just recevied this one yesterday from totaljobs.com (does it look familiar?). I think I will unsubscribe if they can’t filter this kind of rubbish out.

My name is Nastasha van der Berg and I represent Billing LTD.

We’ve reviewed your CV and I’m pleased to offer you a chance to fill a vacant Payment Processing Agent position which we currently have available in your area.

We are a large company founded and based in the UK. Billing LTD deals mainly with providing IT services to clients within the United Kingdom, while recruiting individuals and agencies from all around the world.

This is a part-time position with a flexible schedule. Working 2 to 3 hours a day from your home while staying in contact with our company via your supervisor and receiving all your tasks online.

During the training period you’ll be paid GBP 1,500 a month. In addition you’ll keep 8% from every money transfer processed. Total income, considering the current volume of clients, will be up to GBP 2,500 per month. After you successfully pass the training period, base salary will be increased up to GBP 1,800 per month. Furthermore, you may ask for an extra hours or even a full-time job.

My goal is to spark your interest. In the present economy our position offers training, support and a pay scale comparable to entry level position requiring 40 hours per week. I hope you will explore, compare, and then contact me with your questions.

Sincerely yours,

Nastasha van der Berg

Billing LTD.

Here are some more scam sites, registered on the 27th and 28th, and not live yet:

  1. US-BURGESSGROUP.NET
  2. US-CIELGROUP.NET
  3. US-LOGESTYGROUP.NET
  4. LLOYDGROUPLTD.NET

Here is another batch of sites, registered on the 6th, also not live yet:

  1. ATG-GROUPCOMP.COM
  2. DESERT-GOLDGROUP.COM
  3. EASYTRANSFERLLC.COM
  4. FINCONSULTUK-LTD.COM
  5. FIVECORNERSGROUPUK.COM
  6. FREE-LIVEGROUPUK.COM
  7. KRYPTON-GROUPINC.COM
  8. LLOYDGROUPLTDUK.COM
  9. MAJESTIC-GROUPSVC.COM
  10. STAFFORDSGROUPINC.COM
  11. US-LEAPROFGROUP.COM
  12. VERITASGROUP-LLC.COM
  13. VIRTUE-MAINGROUP.COM

Here are the new name servers registered on the 6th:

NS1.LIBUKERTY.CC (also NS1 and NS2)
NS1.NSDOOMED.CC (also NS1 and NS2)
NS1.SIPNSDOM2.CC (also NS1 and NS2)

Here are some new scam sites, registered on the 12th:

FOXLEY-GROUP.CC (Foxley Group LLC)
Tel 1-347-394-5001, Fax 1-800-803-5302
admin@foxley-group.cc,
support@foxley-group.cc,
job@foxley-group.cc,
webmaster@foxley-group.cc

INCO-GROUPNET.CC (INCO Group Inc)
Tel 1-315-254-2358
Fax 1-800-803-5302
admin@inco-groupnet.cc
support@inco-groupnet.cc
job@inco-groupnet.cc
webmaster@inco-groupnet.cc

POUND-GROUPLLC.CC (Pound Group LLC)
Tel 1-347-274-8182,
Fax 1-800-803-5302
admin@pound-groupllc.cc,
support@pound-groupllc.cc,
job@pound-groupllc.cc,
webmaster@pound-groupllc.cc

Here are the new name servers, registered on the 8th:

NS1.SURPLUSUSA.CC (also NS2 and NS3)
NS1.USABONDS.CC (also NS2 and NS3)
NS1.USAFUNDS.CC (also NS2 and NS3)

WhoIs – Paymentbit.net

Address lookup
canonical name paymentbit.net.
aliases
addresses 69.43.160.144
Domain Whois record

Queried whois.internic.net with “dom paymentbit.net”…

Domain Name: PAYMENTBIT.NET
Registrar: BIG HOUSE SERVICES INC.
Whois Server: whois.bighouseservices.com
Referral URL: http://www.bighouseservices.com
Name Server: NS1.ISAACHOST.COM
Name Server: NS2.ISAACHOST.COM
Status: clientTransferProhibited
Updated Date: 28-jul-2010
Creation Date: 27-jul-2010
Expiration Date: 27-jul-2011

Last update of whois database: Wed, 13 Oct 2010 18:01:19 UTC
Queried whois.bighouseservices.com with “paymentbit.net”.

Registration Service Provided By: eNom, Inc.
Contact: info2@eNom.com

Domain name: paymentbit.net
Administrative Contact:
Isaac Goldstein namejet@isaacgoldstein.com
+852.81757533
Fax: +852.1
Level 19 Two International Finance Centre
8 Finance Street, Central
Hong Kong, HK 0000
HK

Technical Contact:
Isaac Goldstein namejet@isaacgoldstein.com
+852.81757533
Fax: +852.1
Level 19 Two International Finance Centre
8 Finance Street, Central
Hong Kong, HK 0000
HK

Registrant Contact:
Isaac Goldstein
Fax:
Level 19 Two International Finance Centre
8 Finance Street, Central
Hong Kong, HK 0000
HK

Status: Locked

Name Servers:
NS1.ISAACHOST.COM
NS2.ISAACHOST.COM

Creation date: 27 Jul 2010 11:18:00
Expiration date: 27 Jul 2011 11:18:00

Version 6.3 4/3/2002
Network Whois record

Queried whois.arin.net with “n ! NET-69-43-160-0-1″…

NetRange: 69.43.160.0 – 69.43.160.255
CIDR: 69.43.160.0/24
OriginAS: AS22489
NetName: NET-69-43-160-0-1
NetHandle: NET-69-43-160-0-1
Parent: NET-69-43-128-0-1
NetType: Reassigned
NameServer: NS1.TRELLIAN.COM
NameServer: NS2.TRELLIAN.COM
RegDate: 2010-06-18
Updated: 2010-06-18
Ref: http://whois.arin.net/rest/net/NET-69-43-160-0-1

OrgName: Trellian Pty Ltd
OrgId: TRELL-4
Address: 8 East Concourse
City: Beaumaris
StateProv: VIC
PostalCode: 3193
Country: AU
RegDate: 2010-06-18
Updated: 2010-06-18
Ref: http://whois.arin.net/rest/org/TRELL-4

OrgTechHandle: HOSTM1579-ARIN
OrgTechName: Hostmaster
OrgTechPhone: +613 9589 7946
OrgTechEmail: hostmaster@trellian.com
OrgTechRef: http://whois.arin.net/rest/poc/HOSTM1579-ARIN

RTechHandle: HOSTM1579-ARIN
RTechName: Hostmaster
RTechPhone: +613 9589 7946
RTechEmail: hostmaster@trellian.com
RTechRef: http://whois.arin.net/rest/poc/HOSTM1579-ARIN
DNS records

DNS query for 144.160.43.69.in-addr.arpa returned an error from the server: NameError

name class type data time to live
paymentbit.net IN SOA
server: ns1.aphost.com
email: mx.aphost.com
serial: 2005021502
refresh: 1440
retry: 720
expire: 360000
minimum ttl: 8640
14400s (04:00:00)

paymentbit.net IN NS ns2.aphost.com 300s (00:05:00)
paymentbit.net IN NS ns1.aphost.com 300s (00:05:00)
paymentbit.net IN A 69.43.160.144 300s (00:05:00)


Sharing IP with 29 domains:

  1. 1softwarespot.com
  2. Adult-billing.com
  3. Bestsoftclub.com
  4. Billhlp.com
  5. Billingcenteronline.com
  6. Billinghost.net
  7. Billingintegrator.com
  8. Billingmill.com
  9. Billingserviceonline.com
  10. Billingsquad.net
  11. Billinternet.com
  12. Billsvc.com
  13. Customerhlp.com
  14. Dopaymentsonline.com
  15. Ebillingcenter.com
  16. Fantazybill.com
  17. Interbills.com
  18. Justnetbilling.net
  19. Legalbillingsystems.com
  20. Mainbillingcenter.com
  21. Megafixer.com
  22. Orderhlp.com
  23. Paymentbit.com
  24. Paymentbit.net
  25. Paymentforge.com
  26. Safepaymentsonline.com
  27. Softwbill.com
  28. Spankyhosting.com
  29. Support-wizard.com
  30. Truebillingservices.com
  • 09021030408721.cn
  • 1softwarespot.com
  • 8e9.net
  • 50nb.com
  • 78.108.183
  • 203.202.239
  • adnetserver.net
  • adult-billing.com
  • alex-first.com
  • allcooltubeshere.com
  • ameks.net
  • antispy2008.hk
  • antispywareguard.com
  • antispywerepro.com
  • antvirushelp.cm
  • av-pro-2009.com
  • avg-online-scanner.com
  • avira-online-scan.com
  • avpro2009.com
  • bestsoftclub.com
  • betterfasterpc.com
  • billhlp.com
  • billinghost.net
  • billingintegrator.com
  • billingmill.com
  • billingsquad.net
  • billinternet.com
  • billsvc.com
  • bizcn.com
  • bonus-protection.com
  • celebs4you-online2008.com
  • codecdownload.best-softwareportal.com
  • cool-porntube.com
  • crazy-party-pics.info
  • customerhlp.com
  • ddd.burimilol.com
  • defender-review.com
  • defender2009.com
  • dl.storage-proas2009.com
  • domain5123.net
  • dopaymentsonline.com
  • doublered.info
  • download-goodsoft.com
  • download-top-software.net
  • dream-ads.eu
  • easynetsearch.com
  • erabl-pict.com
  • erosets.net
  • fast-xxx-tube.net
  • feeds.videosz.com
  • ffseik.com
  • files.proas2009-dl.com
  • free-download-basez.com
  • fun4uuuu.com
  • galleries.videosz.com
  • get-files-4free.net
  • gfdsgf333.com
  • gknf21.net
  • greatporntubehere.com
  • helper-security.com
  • ho0k.com
  • homesiterenew.com
  • i-av-scanner2008.net
  • i-av-sscan2009.com
  • imp-porntube.net
  • interbills.com
  • internetcamz.com
  • ipowerwebz.mine.nu
  • juga-tube.com
  • justnetbilling.net
  • legalbillingsystems.com
  • life-download.net
  • livepc-update.com
  • lmt.www.conxion.com
  • localfun2.com
  • lsp-test-nax.ind.in
  • mac.sofotex.com
  • megafixer.com
  • megasexytube.com
  • megazmovie.com
  • mekiller.com
  • microsoft.protectionsoftwaredownload.com
  • mysecureexpertcleaner.com
  • mysy8.com
  • orderhlp.com
  • ox-tube.com
  • paymentbit.com
  • paymentbit.net
  • paymentforge.com
  • pewpewpew-hotcams.com
  • pillsexpert.com
  • pistvan.hu
  • pmsoftware.biz
  • powerfulvirusremover2008.com
  • prosecureexpertcleaner.com
  • prosecureexpertcleanerpro.com
  • registrydoctor2008-online.com
  • registrydoctor2008-pro.com
  • registrydoctor2008-scan.com
  • registrydoctorpro2008.com
  • remotespy.com
  • safepaymentsonline.com
  • sales.buy-antispyware-pro-xp.com
  • scan.proantispyware-scanner.com
  • scanner.extraantivir.com
  • secure.paymentbit.net
  • securefileshred.com
  • securefileshredder.com
  • securefileshredder2009.com
  • securefilesshred.com
  • securefilesshredder.com
  • smart-tube.net
  • sofotex.com
  • softwbill.com
  • ss1.videosz.com
  • strongvirusremover2008.com
  • super-av-scanner.com
  • supersecurefileshredder.com
  • support-wizard.com
  • switzerlandgirl.eu
  • switzerlandpussy.eu
  • systembooster2009.com
  • top-software-bazes.com
  • topregistrydoctor2008.com
  • truebillingservices.com
  • tube-ax.com
  • tube-chick.net
  • tube-dot.com
  • universel-software.com
  • upgrade-soft-ware-now.com
  • virusremover2008flash.com
  • virusremover2008plus.com
  • vvexe.com
  • webcam4uu.com
  • wieyou.com
  • winsecureexpertcleaner.com
  • winwebsecurity.com
  • http://www.09021030408721.cn
  • http://www.8e9.net
  • http://www.50nb.com
  • http://www.adnetserver.net
  • http://www.alex-first.com
  • http://www.ameks.net
  • http://www.antispy2008.hk
  • http://www.antispywerepro.com
  • http://www.antvirushelp.cm
  • http://www.betterfasterpc.com
  • http://www.bizcn.com
  • http://www.crazy-party-pics.info
  • http://www.doublered.info
  • http://www.download-top-software.net
  • http://www.dream-ads.eu
  • http://www.easynetsearch.com
  • http://www.erosets.net
  • http://www.fast-xxx-tube.net
  • http://www.ffseik.com
  • http://www.get-files-4free.net
  • http://www.gfdsgf333.com
  • http://www.gknf21.net
  • http://www.go-go-cash.com
  • http://www.greatporntubehere.com
  • http://www.helper-security.com
  • http://www.ho0k.com
  • http://www.homesiterenew.com
  • http://www.itcompany.com
  • http://www.life-download.net
  • http://www.lottoforever.com
  • http://www.marketbrowser.com
  • http://www.mekiller.com
  • http://www.mysy8.com
  • http://www.pcspeedscan.com
  • http://www.pewpewpew-hotcams.com
  • http://www.pmsoftware.biz
  • http://www.remotespy.com
  • http://www.sofotex.com
  • http://www.switzerlandgirl.eu
  • http://www.switzerlandpussy.eu
  • http://www.theshacker.com
  • http://www.tube-chick.net
  • http://www.tube-dot.com
  • http://www.virus-trigger.com
  • http://www.virusresponse2009.com
  • http://www.vvexe.com
  • http://www.youtube19.com
  • http://www.zlkon.lv
  • http://www.zloy.org
  • http://www.zoomovies.org
  • xmas-camss.com
  • xp-vista-scanner-pro.com
  • yoursecureexpertcleaner.com
  • youtube19.com
  • zlkon.lv
  • zloy.org
  • zoomovies.org
  • — end —

    WhoIs – internetserviceteam.com – internet-service-team.info

    84-16-252-115.internetserviceteam.com
    84-16-252-116.internetserviceteam.com
    84-16-252-117.internetserviceteam.com
    84-16-252-118.internetserviceteam.com
    89-149-194-210.internetserviceteam.com
    89-149-210-26.internetserviceteam.com
    internet-service-team.info
    internetserviceteam.info
    internet-service-team.org
    internetserviceteam.org
    jointoperationrecords.org
    internet-service-team.net
    internetserviceteam.net
    internet-service-team.com
    internetserviceteam.com
    internet-service-team.biz
    internetserviceteam.biz

    The home page for InternetServiceTeam.com is blank, so the I supect that this is not a good spider.

    Address lookup
    canonical name internetserviceteam.com
    aliases
    addresses 217.20.112.80
    Domain Whois record

    Queried whois.internic.net with “dom internetserviceteam.com”…

    Domain Name: INTERNETSERVICETEAM.COM
    Registrar: PSI-USA, INC. DBA DOMAIN ROBOT
    Whois Server: whois.psi-usa.info
    Referral URL: http://www.psi-usa.info
    Name Server: NS10.DNSPRO.DE
    Name Server: NS9.DNSPRO.DE
    Name Server: QUART.DNSPRO.DE
    Name Server: TERT.DNSPRO.DE
    Status: clientDeleteProhibited
    Status: clientTransferProhibited
    Status: clientUpdateProhibited
    Updated Date: 25-apr-2010
    Creation Date: 24-apr-2002
    Expiration Date: 24-apr-2011

    Last update of whois database: Wed, 13 Oct 2010 12:05:29 UTC
    Queried whois.psi-usa.info with “internetserviceteam.com”…
    =============
    PSI-USA, Inc.
    =============

    This is the PSI-USA, Inc. WHOIS server.

    All requests are logged.

    Requesting IP: 209.200.90.14
    Requesting URL: http://whois.psi-usa.info
    Requesting Object: domain internetserviceteam.com
    Timestamp: 2010-10-13 14:06:03

    You can see the policy that you agree by submitting a query to this server: whois -h whois.psi-usa.info POLICY
    domain: internetserviceteam.com
    status: LOCK
    owner-c: LULU-449414
    admin-c: LULU-449414
    tech-c: LULU-449414
    zone-c: LULU-449414
    nserver: ns9.dnspro.de
    nserver: ns10.dnspro.de
    nserver: tert.dnspro.de
    nserver: quart.dnspro.de
    created: 2002-04-24 19:04:23
    expire: 2011-04-24 19:04:23 (registry time)
    changed: 2010-04-26 10:35:57

    [owner-c] handle: 449414
    [owner-c] type: ORG
    [owner-c] title:
    [owner-c] fname: Wiethold
    [owner-c] lname: Wagner
    [owner-c] org: netdirekt e.K.
    [owner-c] address: Kleyerstrasse 79 / Tor 13
    [owner-c] city: Frankfurt
    [owner-c] pcode: 60326
    [owner-c] country: DE
    [owner-c] state: Frankfurt
    [owner-c] phone: +49-69-9055688-0
    [owner-c] fax: +49-69-9055688-22
    [owner-c] email: info@netdirekt.de
    [owner-c] protection: B
    [owner-c] remarks: Please send abuse Complaints to abuse@internetserviceteam.com
    [owner-c] remarks: >
    [owner-c] updated: 2009-07-13 14:07:46

    [admin-c] handle: 449414
    [admin-c] type: ORG
    [admin-c] title:
    [admin-c] fname: Wiethold
    [admin-c] lname: Wagner
    [admin-c] org: netdirekt e.K.
    [admin-c] address: Kleyerstrasse 79 / Tor 13
    [admin-c] city: Frankfurt
    [admin-c] pcode: 60326
    [admin-c] country: DE
    [admin-c] state: Frankfurt
    [admin-c] phone: +49-69-9055688-0
    [admin-c] fax: +49-69-9055688-22
    [admin-c] email: info@netdirekt.de
    [admin-c] protection: B
    [admin-c] remarks: Please send abuse Complaints to abuse@internetserviceteam.com
    [admin-c] remarks: >
    [admin-c] updated: 2009-07-13 14:07:46

    [tech-c] handle: 449414
    [tech-c] type: ORG
    [tech-c] title:
    [tech-c] fname: Wiethold
    [tech-c] lname: Wagner
    [tech-c] org: netdirekt e.K.
    [tech-c] address: Kleyerstrasse 79 / Tor 13
    [tech-c] city: Frankfurt
    [tech-c] pcode: 60326
    [tech-c] country: DE
    [tech-c] state: Frankfurt
    [tech-c] phone: +49-69-9055688-0
    [tech-c] fax: +49-69-9055688-22
    [tech-c] email: info@netdirekt.de
    [tech-c] protection: B
    [tech-c] remarks: Please send abuse Complaints to abuse@internetserviceteam.com
    [tech-c] remarks: >
    [tech-c] updated: 2009-07-13 14:07:46

    [zone-c] handle: 449414
    [zone-c] type: ORG
    [zone-c] title:
    [zone-c] fname: Wiethold
    [zone-c] lname: Wagner
    [zone-c] org: netdirekt e.K.
    [zone-c] address: Kleyerstrasse 79 / Tor 13
    [zone-c] city: Frankfurt
    [zone-c] pcode: 60326
    [zone-c] country: DE
    [zone-c] state: Frankfurt
    [zone-c] phone: +49-69-9055688-0
    [zone-c] fax: +49-69-9055688-22
    [zone-c] email: info@netdirekt.de
    [zone-c] protection: B
    [zone-c] remarks: Please send abuse Complaints to abuse@internetserviceteam.com
    [zone-c] remarks: >
    [zone-c] updated: 2009-07-13 14:07:46

    Network Whois record

    Queried whois.ripe.net with “-B 217.20.112.80″…

    % Information related to ‘217.20.112.0 – 217.20.112.255’

    inetnum: 217.20.112.0 – 217.20.112.255
    netname: NETDIRECT-NET
    descr: netdirekt e. K.
    country: DE
    admin-c: WW200-RIPE
    tech-c: SR614-RIPE
    status: ASSIGNED PA
    mnt-by: NETDIRECT-MNT
    mnt-lower: NETDIRECT-MNT
    mnt-routes: NETDIRECT-MNT
    mnt-domains: NETDIRECT-MNT
    changed: technik@netdirekt.de 20040224
    source: RIPE

    person: Wiethold Wagner
    address: netdirekt e. K.
    address: Kleyer Strasse 79 / Tor 14
    address: 60326 Frankfurt
    address: DE
    phone: +49 69 90556880
    fax-no: +49 69 905568822
    e-mail: info@netdirekt.de
    abuse-mailbox: abuse@netdirekt.de
    nic-hdl: WW200-RIPE
    mnt-by: NETDIRECT-MNT
    changed: technik@netdirekt.de 20040224
    changed: technik@netdirekt.de 20100617
    source: RIPE

    person: Simon Roehl
    address: netdirekt e. K.
    address: Kleyer Strasse 79 /Tor 14
    address: 60326 Frankfurt
    address: DE
    phone: +49 69 90556880
    fax-no: +49 69 905568822
    e-mail: technik@netdirekt.de
    abuse-mailbox: abuse@netdirekt.de
    nic-hdl: SR614-RIPE
    mnt-by: NETDIRECT-MNT
    changed: technik@netdirekt.de 20040224
    changed: technik@netdirekt.de 20100617
    source: RIPE

    Information related to ‘217.20.112.0/20AS28753’

    route: 217.20.112.0/20
    descr: netdirect Frankfurt, DE
    origin: AS28753
    mnt-by: NETDIRECT-MNT
    changed: technik@netdirekt.de 20030220
    source: RIPE
    DNS records

    name class type data time to live
    internetserviceteam.com IN NS ns10.dnspro.de 50000s (13:53:20)
    internetserviceteam.com IN NS ns9.dnspro.de 50000s (13:53:20)
    internetserviceteam.com IN A 217.20.112.80 50000s (13:53:20)
    internetserviceteam.com IN SOA
    server: ns9.dnspro.de
    email: ns.netdirekt.de
    serial: 7012701
    refresh: 10800
    retry: 3600
    expire: 605000
    minimum ttl: 50000
    50000s (13:53:20)
    80.112.20.217.in-addr.arpa IN SOA
    server: ns9.dnspro.de
    email: ns.netdirekt.de
    serial: 4062002
    refresh: 10800
    retry: 3600
    expire: 1209700
    minimum ttl: 100000
    100000s (1.03:46:40)
    80.112.20.217.in-addr.arpa IN NS tert.dnspro.de 100000s (1.03:46:40)
    80.112.20.217.in-addr.arpa IN NS ns9.dnspro.de 100000s (1.03:46:40)
    80.112.20.217.in-addr.arpa IN NS ns10.dnspro.de 100000s (1.03:46:40)
    80.112.20.217.in-addr.arpa IN NS quart.dnspro.de 100000s (1.03:46:40)
    80.112.20.217.in-addr.arpa IN PTR ad150.unix-server.com 100000s (1.03:46:40)
    — end —