[WHOIS-WG] who needs proxies?

Derek Smythe derek at aa419.org
Mon Jul 23 19:11:03 UTC 2012


While digging into a phishing website hosted on an equally fake HyIp
website, I uncovered a nest of fake Forex/HyIP websites.

However these caught my attention based upon their whois details,
violating the registrant agreement:

fastlibertyreserve.com
star-pays.com
fxcmoney.com
makecurrencyonline.com
safetyinvestment.net
unitedcashbank.com
redtieforex.com
(follow up on the DNS servers - neverddos.net, anonymous domain
registrations - from company in themselves with a private registration)
shortterminvestment.biz - email domain teleworm expired/non-existent.
investinghyip.com
libertyreserve-income.com
libertyreserveforex.net
libertyreserveinvestmenthyip.com
giant-investment.com
investorsbankowned.com
worldtrustbank.net (their Mr Bejnamin Forster looks exactly like
someone else:
http://www.chicagofinancialtimes.com/cdxc/index.html )
hyipfunding.com
etc etc

Not pretty at all!

A domain that used the same fake certificates etc was payingclub.com.
Losses to it mentioned are deep in the thousands of dollars. Not bad
for a $10 domain investment. Consider that very few of these are
reported by victims, nobody knows what the real losses are or where
the proceeds go to.

Most recently there has been a huge uproar about HSBC and deficient
AML controls and how it benefits the terrorism and drug trade:
http://www.hsgac.senate.gov/download/?id=DF587F5F-DB15-4804-9F90-AAD2CACE9631

Who needs worry about AML controls at American banks and the effect of
those, while an American registrar gladly accepts the above type of
registrations with clearly deficient registration details?


-- 

Derek


More information about the WHOIS-WG mailing list