Opened 7 years ago

Closed 7 years ago

#10529 closed defect (fixed)

shutdown torzip.com

Reported by: phobos Owned by: phobos
Priority: Medium Milestone:
Component: Webpages/Website Version:
Severity: Keywords: malware trademark
Cc: Actual Points:
Parent ID: Points:
Reviewer: Sponsor:

Description

torzip.com is violating our trademark and copyrights. users are downloading it, thinking it's from Tor Project, and finding themselves infected with malware. They are calling us angry.

Child Tickets

Attachments (1)

2014-01-03-torzip-website.pdf (134.1 KB) - added by phobos 7 years ago.
pdf screenshot of website

Download all attachments as: .zip

Change History (14)

comment:1 Changed 7 years ago by phobos

email to abuse at godaddy sent.

comment:3 Changed 7 years ago by phobos

The Registry database contains ONLY .COM, .NET, .EDU domains and
Registrars.
Domain Name: TORZIP.COM
Registry Domain ID: 1834279535_DOMAIN_COM-VRSN
Registrar WHOIS Server: whois.godaddy.com
Registrar URL: http://www.godaddy.com
Update Date: 2013-11-05 12:53:11
Creation Date: 2013-11-05 12:53:11
Registrar Registration Expiration Date: 2014-11-05 12:53:11
Registrar: GoDaddy.com, LLC
Registrar IANA ID: 146
Registrar Abuse Contact Email: abuse@godaddy.com
Registrar Abuse Contact Phone: +1.480-624-2505
Domain Status: clientTransferProhibited
Domain Status: clientUpdateProhibited
Domain Status: clientRenewProhibited
Domain Status: clientDeleteProhibited
Registry Registrant ID: 
Registrant Name: Michael Lalisan
Registrant Organization: 
Registrant Street: 7085 Fairmeadow Cresent
Registrant City: Toronto
Registrant State/Province: Ontario
Registrant Postal Code: L5N 8R6
Registrant Country: Canada
Registrant Phone: 647-289-8855
Registrant Phone Ext: 
Registrant Fax: 
Registrant Fax Ext: 
Registrant Email: zetustiger@gmail.com
Registry Admin ID: 
Admin Name: Michael Lalisan
Admin Organization: 
Admin Street: 7085 Fairmeadow Cresent
Admin City: Toronto
Admin State/Province: Ontario
Admin Postal Code: L5N 8R6
Admin Country: Canada
Admin Phone: 647-289-8855
Admin Phone Ext: 
Admin Fax: 
Admin Fax Ext: 
Admin Email: zetustiger@gmail.com
Registry Tech ID: 
Tech Name: Michael Lalisan
Tech Organization: 
Tech Street: 7085 Fairmeadow Cresent
Tech City: Toronto
Tech State/Province: Ontario
Tech Postal Code: L5N 8R6
Tech Country: Canada
Tech Phone: 647-289-8855
Tech Phone Ext: 
Tech Fax: 
Tech Fax Ext: 
Tech Email: zetustiger@gmail.com
Name Server: NS73.DOMAINCONTROL.COM
Name Server: NS74.DOMAINCONTROL.COM
DNSSEC: unsigned
URL of the ICANN WHOIS Data Problem Reporting System: http://wdprs.internic.net/
Last update of WHOIS database: 2013-12-31T00:00:00Z

comment:4 Changed 7 years ago by phobos

The reporting company said they are also seeing "ad auctions" for the site for the keywords "tor, privacy, and anonymity" beating out legitimate ads.

comment:5 Changed 7 years ago by phobos

godaddy responds:

Thank you for your email.  Unfortunately, the email did not
contain all of the information necessary for us to review your claim. As per
Go Daddy’s Trademark Infringement Policy, available here http://
www.godaddy.com/agreements/ShowDoc.aspx?pageid=TRADMARK_COPY, a notification
of a claimed trademark violation must include all of the following
information: •    The trademark, service mark, trade dress, name, or other
indicia of origin ("mark") that is claimed to be infringed, including
registration number. •    The jurisdiction or geographical area to which the
mark applies. •    The name, post office address and telephone number of the
owner of the mark identified above. •    The goods and/or services covered
by or offered under the mark identified above. •    The date of first use of
the mark identified above. •    The date of first use in interstate commerce
of the mark identified above. •    A description of the manner in which the
Complaining Party believes its mark is being infringed upon. •    Sufficient
evidence that the owner of the website that is claimed to be infringing is a
Go Daddy customer. •    The precise location of the infringing material. •
 A good faith certification, signed under penalty of perjury, stating: 1.
 The content of the website [identify website] infringes the rights of
another party, 2.    The name of such said party, 3.    The mark [identify
mark] being infringed, and 4.    That use of the content of the website
claimed to be infringing at issue is not defensible. When you send us all of
the required information to substantiate your claim, we will initiate an
investigation. Thank you, Chris Trademark Claims GoDaddy.com, LLC

Changed 7 years ago by phobos

pdf screenshot of website

comment:6 Changed 7 years ago by phobos

asked our lawyers to take a look at it and help figure out next steps.

comment:7 Changed 7 years ago by runa

The malware tries to connect back to faw323.zapto.org on port 1010. This domain has resolved to at least 198.13.231.249 and 198.13.132.61. I'm fairly certain NoIP would be willing to help with this.

Last edited 7 years ago by runa (previous) (diff)

comment:8 Changed 7 years ago by runa

NoIP looked into the issue and said it has been disabled: https://twitter.com/NoIPcom/status/419262427482439681

comment:9 Changed 7 years ago by torusr115

talked to godaddy today and thy said that torzip.com is not hosted by them and so they cant do anything about it but torzip.com resolves to there ip address block this smells like collusion with the government

50.62.246.1

NetRange: 50.62.0.0 - 50.63.255.255
CIDR: 50.62.0.0/15
OriginAS: AS26496
NetName: GO-DADDY-COM-LLC
NetHandle: NET-50-62-0-0-1
Parent: NET-50-0-0-0-0
NetType: Direct Allocation
Comment: Please send abuse complaints to abuse@…
RegDate: 2011-02-02
Updated: 2012-02-24
Ref: http://whois.arin.net/rest/net/NET-50-62-0-0-1

OrgName: GoDaddy.com, LLC
OrgId: GODAD
Address: 14455 N Hayden Road
Address: Suite 226
City: Scottsdale
StateProv: AZ
PostalCode: 85260
Country: US
RegDate: 2007-06-01
Updated: 2012-03-15
Comment: Please send abuse complaints to abuse@…
Ref: http://whois.arin.net/rest/org/GODAD

OrgNOCHandle: NOC124-ARIN
OrgNOCName: Network Operations Center
OrgNOCPhone: +1-480-505-8809
OrgNOCEmail: noc@…
OrgNOCRef: http://whois.arin.net/rest/poc/NOC124-ARIN

OrgTechHandle: NOC124-ARIN
OrgTechName: Network Operations Center
OrgTechPhone: +1-480-505-8809
OrgTechEmail: noc@…
OrgTechRef: http://whois.arin.net/rest/poc/NOC124-ARIN

OrgAbuseHandle: ABUSE51-ARIN
OrgAbuseName: Abuse Department
OrgAbusePhone: +1-480-624-2505
OrgAbuseEmail: abuse@…
OrgAbuseRef: http://whois.arin.net/rest/poc/ABUSE51-ARIN

comment:10 Changed 7 years ago by runa

I sent abuse@… another email.

comment:11 Changed 7 years ago by phobos

Thanks, but we already sent the follow-up via the lawyers.

comment:12 Changed 7 years ago by phobos

Response from godaddy:

Discussion Notes                                                                                                                                                               
                                                                                                                                                                               
Support Staff Response                                                                                                                                                         
                                                                                                                                                                               
Dear Andrew, We are in receipt of your email regarding the website located                                                                                                     
at TORZIP.COM. .  We have redirected the site to a parked web page and have                                                                                                    
notified the customer of this action.  In addition, we have provided the                                                                                                       
customer with your claim and contact information. Please note that per our                                                                                                     
Trademark Policy (http://www.godaddy.com/gdshop/legal_agreements/                                                                                                              
show_doc.asp?pageid=TRADMARK%5FCOPY), the customer has the ability to submit                                                                                                   
a Counter Notification.  If we receive a valid Counter Notification, we will                                                                                                   
replace the removed material and cease disabling access to it in not less                                                                                                      
than ten nor more than fourteen business days, unless you provide us a                                                                                                         
notice that you have filed an action seeking a court order to restrain the                                                                                                     
customer from engaging in infringing activity. Please feel free to contact                                                                                                     
us if we can provide further assistance. Thank you, Chris Trademark Claims                                                                                                     
GoDaddy.com, LLC                                                                                                                                                               
                                                                                                                                                                               
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━                                                                                                   
                                                                                                                                                                               
                                                                                                                                                                               
If you need further assistance with this matter, please reply to this email                                                                                                    
and reference [Incident ID: 21559858].                                                                                                                                         
                                                                                                                                                                               
Regards,                                                                                                                                                                       
Trademark Claims                                                                                                                                                               
                   Copyright © 2014. All rights reserved.

comment:13 Changed 7 years ago by phobos

Resolution: fixed
Status: newclosed

torzip has stayed down for 3 weeks.

Note: See TracTickets for help on using tickets.