Another redirection scam is based on the abuse of registrars EvoPlus / EvoNames in Canada, and PSI-USA / InterNetX in Germany.
The name serversare often suspended, but the miscreants move on to others. In December 2013, the current name servers were on
NVIKO87.com (PSI-USA / InterNetX). In January 2014,
nsvilero.com sponsored by InterNetX in Germany
Examples of the redirector domains registered on
EvoPlus Ltd. (R589-LRMS) subsequently suspended, were
amicroshetochkaprokrashi.com
auholopovshatntreshat.com
avoobshemndedofonaryaskoka.com
dapribudetsilakvakisnami.com
gonitkolegatebesdolikedfop.com
These in turn perform a redirection, thus:
> Location:
http://ddw.bigrxdiscountmedstore.comThis is another Canadian Health&Care Mall fraud out of Russia, registered with sponsor PSI-USA / InterNetX in Germany
Location:
http://ddw.bigrxdiscountmedstore.com (subsequently suspended)
In January the Name server was on
nglns12.com (PSI-USA / InterNetX) with redirectors sponsored by
EvoPlus and
Domain Context registrars. Sample redirectors:
bandakolpikedasoi.com . . . DOMAINCONTEXT, INC.
bobbarbikoled.com . . . DOMAINCONTEXT, INC.
densvobodiisobornosti.com . . . EVOPLUS LTD
dilizansprohoditmimo.com . . . DOMAINCONTEXT, INC.
etapievrochempionafu.com . . . EVOPLUS LTD
etootlichniyvariantikolep.com . . . DOMAINCONTEXT, INC.
etovesmastarayainformaciu.com . . . EVOPLUS LTD
glazaotkrilspacibonoci.com . . . EVOPLUS LTD