Friday, October 5, 2007

Wall-E (Pixars new film) domain hijacked for drive-by attack!! Or is it viral marketing?

While looking around for some more information about Pixars new film Wall-e, I tried heading over to http://wall-e.net (Do not go here until someone can confirm if this is a actually safe)

It loaded what appeared to be Google home page, but some things were not right..

<HTML><HEAD><title>Movies Coming Soon - New Releases!</title>
<style>
table { border: 0px outset; }
td { border: 0px; }
</style>
</HEAD>
<!-- BODY background="../images/movie2.gif"><center -->
<frameset border=0 rows=100%,*>
<frame name=frame src="http://www.drivingwhileinfatuated.com">
</frameset>
</html>

There are a few interesting things here. Firstly, the title of the 'google' page has been changed to "Movies Coming Soon - New Releases!". Which would at least indicate the domain has been registered to be associated with the upcoming movie.

Secondly, the domain in the frameset http://www.drivingwhileinfatuated.com. When going to this domain directly, it seems to redirect straight to YouTube.com. I tried disabling Javascript to see if I could catch what happens on that page, but it appears to be a straight redirect (can anyone provide more info on this?).

I deciced to find some more info about the domains. Firstly as who is lookup on the first domain wall-e.net came back with an actual person (all details here):

Whois Record

Contact: +626.5551212

Domain Name: WALL-E.NET

Registrant:
R
Pete Gilchrist (Whois Privacy and Spam Prevention by DomainTools.com)
4401 Fourth Ave.
Brooklyn
NY,11220
US
Tel. +718.777777777

Creation Date: 21-Nov-2006
Expiration Date: 21-Nov-2007

Looks like a real person/address (although I am not in the US, am guessing here) but with an obvisouly faked telephone contact.

Now for the oddly named "DrivingWhileInfatuated" domain. You can see the whois results here

There are a couple of strange things about these results. The Page Title is Google, yet the thumbnail preview for the domain is a screener of youtube?

The detailed whois info is below, although I cannot see anything of great interest other than it seems to be anonymously registered (let me know if there is anything of interest in here)

Registrant:
Domains by Proxy, Inc.
DomainsByProxy.com
15111 N. Hayden Rd., Ste 160, PMB 353
Scottsdale, Arizona 85260
United States

Registered through: GoDaddy.com, Inc. (http://www.godaddy.com)
Domain Name: DRIVINGWHILEINFATUATED.COM
Created on: 26-Sep-04
Expires on: 26-Sep-08
Last Updated on: 31-Aug-07

Administrative Contact:
Private, Registration Whois Privacy and Spam Prevention by DomainTools.com
Domains by Proxy, Inc.
DomainsByProxy.com
15111 N. Hayden Rd., Ste 160, PMB 353
Scottsdale, Arizona 85260
United States
(480) 624-2599 Fax -- (480) 624-2599


Please post in the comments your thoughts on what is going on. Is google parking the domain, is it a new viral marketing campaign planned by Pixar? Are google and Pixar working together on this one? Is it a drive-by scammer?

** UPDATE : I have emailed Pixar about this, and will let you know of any responses.

No comments: