A fake AquaVPN website has been used to distribute malware

Jan 17, 2014 12:09 GMT  ·  By
AquaVPN domain not suspended by Namecheap despite being involved in malware distribution
   AquaVPN domain not suspended by Namecheap despite being involved in malware distribution

The security researcher known as Trojan7Sec accuses domain name registrar Namecheap of refusing to suspend domains involved in malicious activities.

The expert says that he has filed numerous reports regarding a domain called aquavpn(dot)com, which has been registered with Namecheap. Malwarebytes has also analyzed the domain in question and found it to be serving keylogging malware.

“This company is completely corrupt and is perfectly happy to be the registrar behind a huge malware campaign. I've contacted them at least 30 times by now and they've made absolutely no effort to even consider elevating this to management never mind suspend the domain,” Trojan7Sec said.

He claims that the AquaVPN website is involved in a malware distribution campaign in which between 4,000 and 10,000 devices are infected each day.

Over 24 hours have passed since I sent a request for comment to Namecheap regarding these accusations. So far, I haven’t received a response to my inquiry.

Update. Namecheap's Legal & Abuse Department has provided the following statement:
“While the AQUAVPN.COM domain name does have Namecheap.com as the registrar, we do not have the ability to oversee what data are being transmitted through its site. We do not own the domain name mentioned in your complaint, we are simply the registrar that the registrant purchased the domain name from.

The issue would need to be addressed through the hosting provider to see if their terms of service have been violated, and would need to be addressed through the domain registrant as they should be the individual that would control what particular content is being exchanged. We have no way to police these issues as we do not control the hosting company in this instance.

Here are contact details of the company that owns IP address assigned to the domain: http://whois.domaintools.com/108.162.199.100

While I understand your issue, we are not in a position where we can make determination of validity of your statements.

If you believe you are the victim of an internet crime, or if you are aware of an attempted crime, you can file a complaint through Internet Crime Complaint Center at https://complaint.ic3.gov. You also may contact either your lawyer(s) or the local authorities in order get the issue resolved. We will assist them any way we can.”