Home Internet Security EstDomains Inc Harboring Malicious Websites

EstDomains Inc Harboring Malicious Websites

Posted: September 15, 2008

Is EstDomains Inc the choice registrar scams and spam? While EstDomains is the 49th largest domain according to RegistarStats.com, it is believed that a percentage of the domains consist of scamming sites and spam sources. Security Fix, a security vendor, is working on cataloging all of the domains within EstDomains and will examine about 10,000 of them to make proof of the idea of EstDomains consisting of a good amount of spam or scam related domains. The study, based off of spam terms, is where they find many sites registered at EstDomains while using their name servers.

One ISP, Atrivo (aka Intercage), online connectivity was ended by several large data carries due to them being home to many spam and scamming sources. Now EstDomains is being examined by Security experts such as Brian Krebs at Security Fix.

SURBL.org tracks website names that are advertised in various junk emails. Brian found that one-third of the 10,000 domains examined are blacklisted by SURBL.org. That just goes to show that many of the domains are scams or come from spammers.

Example of a malicious domain with EstDomains, Inc. listed as the registrar

Domain Name: WINDOWS-PRIVACY-PROTECTION.COM
Registrar: ESTDOMAINS, INC.
Whois Server: whois.estdomains.com
Referral URL: http://www.estdomains.com
Name Server: NS1.WINDOWS-PRIVACY-PROTECTION.COM
Name Server: NS2.WINDOWS-PRIVACY-PROTECTION.COM
Status: clientHold
Status: clientUpdateProhibited
Updated Date: 11-sep-2008
Creation Date: 29-apr-2008
Expiration Date: 29-apr-2009

Many security vendors and security sites offer additional information for well known rogue anti-spyware programs. Some of them have their own website and the web page domain usually has EstDomains as the registrar. IT is almost an epidemic when you do research on some of the dangerous spyware infections that run amuck over the internet. We conduct research on many rogue applications and find that most of them have Estdomains listed as the registrar. It can be said that EstDomains listed as the registrar is a common sign that you must further check the credentials of that particular site because it has a high chance of being malicious.

An ongoing examination of EstDomains is now happening due to the vast amount of sites that are malicious in content found to have EstDomains as a listed registrar. Have you ever checked the WHOIS on a website and found that it has EstDomains as it's registrar? Was it a legitimate site or a site that was questionable. Remember, many of the websites that contain malware look like a 'normal' web page but it usually solicits malware or secretly infects your system with a Trojan. It can be said to use caution in any situation whither the domain registrar is EstDomains or anything else.

One Comment

Loading...