Fraudulent redirects via spacing in address so unable to resolve the Host

See: htxp://www.re place.com/id/lmcdonald cannot be resolved ( as wXw.replace.com/id/lmcdonald will)
Giving this redirection: htxp://replace.com/?page=3&kop=Cyprus%20zorgt%20voor%20paniek&mainSection=dft&sectie=dft&artikelURL=http%3A%2F%2Fwww.telegraaf.nl%2Fdft%2F21394298%2F__Reddingsdeal_Cyprus_veroorzaakt_paniek__.html&hashCheck=6f0869094c771a06d484bb9551975c8a&id=21394298&showReactionForm=true
as the site should go here htxp://www.telegraaf.nl/dft/21394298/Reddingsdeal_Cyprus_veroorzaakt_paniek.html?page=4
as you give this into the browser address bar, it will resolve where it should direct…
Where is the hack being placed and how was the hijack being performed?

polonus

This similar redirect has been closed, see: http://jsunpack.jeek.org/dec/go/?report=342d52cef8bc7d0e3ceff9f20811c1eddc7e0f79
See: http://support.clean-mx.de/clean-mx/viruses.php?ip=216.21.146.161&sort=first%20desc
The other one I reported above apparently has not…

polonus