今天看到F-secure博客上的一篇文章,文中有如下文字:
When we look at the whois information of these domains, we see that not only these domains have similar sounding names but we can also categorize them to just three different groups: domains registered to "Wang Pang", "Dima Li" or "Bai Ming".
电脑侠客翻译:当我们在WHOIS中查找这些站点信息时,我们看到不但这些域名有类似的夸大的名字,
而且我们还可以把这些域名归为3类:注册者为Wang Pang", "Dima Li" 或 "Bai Ming".
含图.
When we look at the whois information of these domains, we see that not only these domains have similar sounding names but we can also categorize them to just three different groups: domains registered to "Wang Pang", "Dima Li" or "Bai Ming".
电脑侠客翻译:当我们在WHOIS中查找这些站点信息时,我们看到不但这些域名有类似的夸大的名字,
而且我们还可以把这些域名归为3类:注册者为Wang Pang", "Dima Li" 或 "Bai Ming".
含图.


And when comparing the domain names used in the virus to domains shown in the spam messages, we can see that they overlap, proving that these are all part of single operation:
电脑侠客翻译:而且当我们在这些在用于传播病毒站点和制造垃圾邮件的站点之间比较时,可以看到它们是重复的,证明这些都是单一来源.spam warezov


电脑侠客翻译投递
They link to fake viagra sites like these:
