Panama?!? This stinks ... and the trace continues:
Registrant:
Laissez Faire City Lomas de Ayarco Sur
Curridabat, San Jose 00000
CR
Domain name: MAILVAULT.COM
Administrative Contact:
Hostmaster, LFC domains at lfcfa.org
Lomas de Ayarco Sur
Curridabat, San Jose 00000
CR
506-272-0000
Technical Contact:
Hostmaster, LFC domains at lfcfa.org
Lomas de Ayarco Sur
Curridabat, San Jose 00000
CR
506-272-0000
Registrar of Record: TUCOWS, INC.
Record last updated on 22-Apr-2003.
Record expires on 10-Dec-2004.
Record Created on 11-Dec-1997.
Domain servers in listed order:
DNS1.VGUILD.COM 64.69.65.222
NS1.THIRDHOST.COM 65.113.114.194
Registration info for VGUILD.COM is stinking, too.
On of their DNS servers are in the PHANTOMSERVER.COM domain.
THIRDHOST.COM stinks, too, and is registrered through
dotster.com, all the others were through Tucows/OpenSRS.
Contact email address is at MAILVAULT.COM. IPs are 65.113.114.194+195 at
ProHosting.
PHANTOMSERVER.COM smells not much better and is registered
through directnic.com. Email is again at MAILVAULT.COM.
Back to LFCFA.ORG, mail contact for MAILVAULT.COM:
Registrant:
Johann Gevers 1017 Second St Apt 101
Santa Monica, CA 90403-3620
US
Domain name: LFCFA.ORG
Administrative Contact:
Gevers, Johann johann at gevers.net
1017 Second St Apt 101
Santa Monica, CA 90403-3620
US
(209) 254-9856
Technical Contact:
Gevers, Johann johann at gevers.net
1017 Second St Apt 101
Santa Monica, CA 90403-3620
US
(209) 254-9856
Registrar of Record: TUCOWS, INC.
Record last updated on 18-Jun-2003.
Record expires on 31-Jul-2004.
Record Created on 31-Jul-2002.
Domain servers in listed order:
NS19.ZONEEDIT.COM
NS18.ZONEEDIT.COM
GEVERS.NET seems to have the same data and is registered
through godaddy.com (and jomax.net is godaddy). Can someone
verify the data for this domain? Or does it ring a bell?
IIRC I've already seen it somewhere here around :-/.
www.LFCFA.ORG redirects to
www.LFCFA.COM (same WHOIS,
except for DNS by METROPIPE.NET), which gives an
interesting reading, introducing LFCGATE.COM and HUSH.COM.
METROPIPE.NET is bogus, *.METROPIPE.NET resolves to 213.84.134.134,
which is hosted at XS4ALL.
LFCGATE.COM bogus in CR, registered through dotster.com,
DNS by THIRDHOST.COM, contact email at MAILVAULT.COM.
audit at hush.com: HUSH.COM itself looks halfway acceptable,
except for being offshore and a similar, but bogus DNS
of
HUSHMAIL.COM and IPs 65.39.178.0 - 65.39.178.255.
I don't know what's being conveyed about hushmail.com, but we know who its founder is.