I dug a bit deeper...and found that the phone number listed in the WhoIs for privatedns.com happened to match the phone number for a web hosting service by the name of iWeb.com (have Apple sued them yet?) - who appear to be quite legitimate - and no Russians in sight. They've been around for over ten years and get very good reviews. One of the owners has a blog here:
http://www.martinleclair.comThey really
don't look like the sort to knowingly host a Mac Trojan
That phone numbr doesn't actually belong to imunizator.com; the whois for imunizator.com is cloaked by PrivacyProtect.org and the domain is registered through estdomains.com. The registrar estdomains.com is the preferred domain registrar for Russian organized crome; every Russian Business Network site I've seen so far, without exception, is registered through them.
tacits-computer-2:~ tacit$ whois
www.imunizator.com Whois Server Version 2.0
Domain names in the .com and .net domains can now be registered
with many different competing registrars. Go to
http://www.internic.netfor detailed information.
No match for "
WWW.IMUNIZATOR.COM".
>>> Last update of whois database: Fri, 04 Apr 2008 18:16:34 UTC <<<
NOTICE: The expiration date displayed in this record is the date the
registrar's sponsorship of the domain name registration in the registry is
currently set to expire. This date does not necessarily reflect the expiration
date of the domain name registrant's agreement with the sponsoring
registrar. Users may consult the sponsoring registrar's Whois database to
view the registrar's reported date of expiration for this registration.
TERMS OF USE: You are not authorized to access or query our Whois
database through the use of electronic processes that are high-volume and
automated except as reasonably necessary to register domain names or
modify existing registrations; the Data in VeriSign Global Registry
Services' ("VeriSign") Whois database is provided by VeriSign for
information purposes only, and to assist persons in obtaining information
about or related to a domain name registration record. VeriSign does not
guarantee its accuracy. By submitting a Whois query, you agree to abide
by the following terms of use: You agree that you may use this Data only
for lawful purposes and that under no circumstances will you use this Data
to: (1) allow, enable, or otherwise support the transmission of mass
unsolicited, commercial advertising or solicitations via e-mail, telephone,
or facsimile; or (2) enable high volume, automated, electronic processes
that apply to VeriSign (or its computer systems). The compilation,
repackaging, dissemination or other use of this Data is expressly
prohibited without the prior written consent of VeriSign. You agree not to
use electronic processes that are automated and high-volume to access or
query the Whois database except as reasonably necessary to register
domain names or modify existing registrations. VeriSign reserves the right
to restrict your access to the Whois database in its sole discretion to ensure
operational stability. VeriSign may restrict or terminate your access to the
Whois database for failure to abide by these terms of use. VeriSign
reserves the right to modify these terms at any time.
The Registry database contains ONLY .COM, .NET, .EDU domains and
Registrars.
tacits-computer-2:~ tacit$ whois imunizator.com
Whois Server Version 2.0
Domain names in the .com and .net domains can now be registered
with many different competing registrars. Go to
http://www.internic.netfor detailed information.
Domain Name: IMUNIZATOR.COM
Registrar: ESTDOMAINS, INC.
Whois Server: whois.estdomains.com
Referral URL:
http://www.estdomains.com Name Server: NS.IMUNIZATOR.COM
Name Server: NS1.TWISTED4LIFE.COM
Status: clientTransferProhibited
Updated Date: 09-mar-2008
Creation Date: 09-mar-2008
Expiration Date: 09-mar-2009
>>> Last update of whois database: Fri, 04 Apr 2008 13:16:49 EST <<<
The Registry database contains ONLY .COM, .NET, .EDU domains and
Registrars.
Registration Service Provided By: ESTDOMAINS INC
Contact: +1.3027224217
Website:
http://www.estdomains.comDomain Name: IMUNIZATOR.COM
Registrant:
PrivacyProtect.org
Domain Admin (contact@privacyprotect.org)
P.O. Box 97
All Postal Mails Rejected, visit Privacyprotect.org
Moergestel
null,5066 ZH
NL
Tel. +45.36946676
Creation Date: 09-Mar-2008
Expiration Date: 09-Mar-2009
Domain servers in listed order:
ns1.twisted4life.com
ns.imunizator.com
Administrative Contact:
PrivacyProtect.org
Domain Admin (contact@privacyprotect.org)
P.O. Box 97
All Postal Mails Rejected, visit Privacyprotect.org
Moergestel
null,5066 ZH
NL
Tel. +45.36946676
Technical Contact:
PrivacyProtect.org
Domain Admin (contact@privacyprotect.org)
P.O. Box 97
All Postal Mails Rejected, visit Privacyprotect.org
Moergestel
null,5066 ZH
NL
Tel. +45.36946676
Billing Contact:
PrivacyProtect.org
Domain Admin (contact@privacyprotect.org)
P.O. Box 97
All Postal Mails Rejected, visit Privacyprotect.org
Moergestel
null,5066 ZH
NL
Tel. +45.36946676
Status:ACTIVE
The phone number probably belongs to their Web host. Right now, imunizator.com is hosted by iWeb (which has been around for longer than Apple's iWeb, and is located in Canada):
Parsing input: imunizator.com
Tracking details
$ whois 67.205.75.10@whois.arin.net
[whois.arin.net]
Groupe iWeb Technologies inc. IWEB-BLK-04 (NET-67-205-64-0-1)
67.205.64.0 - 67.205.95.255
Individual IWEB-CL-T062-361CL-188 (NET-67-205-75-8-1)
67.205.75.8 - 67.205.75.15
"whois 67.205.75.10@whois.arin.net" (Getting contact from whois.arin.net )
checking NET-67-205-75-8-1
$ whois NET-67-205-75-8-1@whois.arin.net
[whois.arin.net]
CustName: Individual
Address: Olevska 3
City: Kiev
StateProv:
PostalCode: 03164
Country: UA
RegDate: 2008-04-03
Updated: 2008-04-03
NetRange: 67.205.75.8 - 67.205.75.15
CIDR: 67.205.75.8/29
OriginAS: AS32613
NetName: IWEB-CL-T062-361CL-188
NetHandle: NET-67-205-75-8-1
Parent: NET-67-205-64-0-1
NetType: Reassigned
Comment:
RegDate: 2008-04-03
Updated: 2008-04-03
OrgAbuseHandle: ABUSE1906-ARIN
OrgAbuseName: Abuse Coordinator
OrgAbusePhone: +1-514-286-4242
OrgAbuseEmail: abuse@noc.privatedns.com
OrgNOCHandle: NETWO2356-ARIN
OrgNOCName: Network Admministrator
OrgNOCPhone: +1-514-286-4242
OrgNOCEmail: net-admin@noc.privatedns.com
OrgTechHandle: NETWO2356-ARIN
OrgTechName: Network Admministrator
OrgTechPhone: +1-514-286-4242
OrgTechEmail: net-admin@noc.privatedns.com
"whois NET-67-205-75-8-1@whois.arin.net" (Getting contact from whois.arin.net )
Found AbuseEmail in whois abuse@noc.privatedns.com
Ignoring small (7 IP) network
checking NET-67-205-64-0-1
Display data:
"whois NET-67-205-64-0-1@whois.arin.net" (Getting contact from whois.arin.net )
Found AbuseEmail in whois abuse@noc.privatedns.com
67.205.64.0 - 67.205.95.255:abuse@noc.privatedns.com
Routing details for 67.205.75.10
Using abuse net on abuse@noc.privatedns.com
abuse net noc.privatedns.com = abuse@privatedns.com, support@privatedns.com, abuse-report@iweb.ca, abuse@iweb.ca
So they're registered through estdomains.com, cloaked by provacyprotect.org, and hosted on iweb.ca. The odds that iWeb will take action against them are, unfortunately, quite small.