Web Images Videos Maps News Shopping Gmail more »
Recently Visited Groups | Help | Sign in
Google Groups Home
Mortgage phisher and fake diploma spammer
There are currently too many topics in this group that display first. To make this topic appear first, remove this option from another topic.
There was an error processing your request. Please try again.
flag
  Messages 151 - 175 of 409 - Expand all  -  Translate all to Translated (View all originals) < Older  Newer >
The group you are posting to is a Usenet group. Messages posted to this group will make your email address visible to anyone on the Internet.
Your reply message has not been sent.
Your post was successful
 
From:
To:
Cc:
Followup To:
Add Cc | Add Followup-to | Edit Subject
Subject:
Validation:
For verification purposes please type the characters you see in the picture below or the numbers you hear by clicking the accessibility icon. Listen and type the numbers you hear
 
Quaestor  
View profile  
 More options Dec 30 2005, 5:18 am
Newsgroups: news.admin.net-abuse.email
From: Quaestor <no-s...@my.place>
Date: Fri, 30 Dec 2005 02:18:38 -0800
Local: Fri, Dec 30 2005 5:18 am
Subject: Re: Mortgage phisher and fake diploma spammer

Spam Reporting wrote:
> "glgxg" <gl...@mfire.com.invalid> wrote in message
> news:11r8umagjprh589@corp.supernews.com...

>> Thanks. BTW, the phone number being used:
>> http://www.google.com/search?hl=en&lr=&q=303-831-0661&btnG=Search

>> is probably also bogus... either that or someone has paid Ms. Kokins to
>> answer the phone.

> Easy enough to determine that... call the number, posing as the
> Registrar. If she seems to know what you're talking about, then she's
> in on it. If not, then she's an innocent victim.

If she seems gullible enough, make a date with her.

--
Godwin is a net-nazi


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Rev. Beergoggles  
View profile  
 More options Dec 30 2005, 7:26 am
Newsgroups: news.admin.net-abuse.email
From: "Rev. Beergoggles" <post.repl...@invalid.address>
Date: Fri, 30 Dec 2005 06:26:01 -0600
Local: Fri, Dec 30 2005 7:26 am
Subject: Re: Mortgage phisher and fake diploma spammer
Spam Reporting did pass the time by typing:

> "Rev. Beergoggles" <post.replies [at] invalid.address> wrote in message
> news:u%2tf.20083$Ou3.12412@dukeread09...
>> (got to love a slow day at work) and will consider hacking a dnsbot
>> although that's a lot of domain names to examine without being abusive.

> Well, if you're looking to do batch DNS lookups, and you're running
> Windows, you can use NS-Batch 32.
> http://jimprice.com/jim-soft.htm

Oh.. nice toy.  I will put that to "good use".

--
rbg


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Discussion subject changed to "Mortgage phisher and fake diploma spammer [LONG POST]" by Rev. Beergoggles
Rev. Beergoggles  
View profile  
 More options Dec 30 2005, 7:43 am
Newsgroups: news.admin.net-abuse.email
From: "Rev. Beergoggles" <post.repl...@invalid.address>
Date: Fri, 30 Dec 2005 06:43:43 -0600
Local: Fri, Dec 30 2005 7:43 am
Subject: Re: Mortgage phisher and fake diploma spammer [LONG POST]
Spam Reporting did pass the time by typing:

> They really ramped up the number of domains they registered today, and the
> amount of spam they're sending... looks like we've stirred up a hornet's
> nest. They accounted for ~17% of spam reported today. Of course, I'll not
> reveal the sources I'm checking, so they can't list-wash.

Fresh from the siphon.  All larted to yesnic.

[202.65.99.20] p8123.net
[202.65.99.20] n03921.net
[202.65.99.20] p63721.com
[202.65.99.20] pa812.com
[202.65.99.20] pa812.net
[202.65.99.20] p8123.com
[202.65.99.20] k9381.net

hmm: eggs, basket, one each.

> Now that we've got them all agitated, let's break their ability to make
> money by draining their websites and filling in their website feedback
> forms with bogus data (check my sig).

I've got my own special methods to keep spammy busy. :)

--
rbg
Help stamp out stupidity, donate:
http://www.ahbl.org/legalfund


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
glgxg  
View profile  
 More options Dec 30 2005, 3:50 pm
Newsgroups: news.admin.net-abuse.email
From: glgxg <gl...@mfire.com.invalid>
Date: Fri, 30 Dec 2005 12:50:42 -0800
Local: Fri, Dec 30 2005 3:50 pm
Subject: Re: Mortgage phisher and fake diploma spammer [LONG POST]

Rev. Beergoggles wrote:

> I've got my own special methods to keep spammy busy. :)

Why not just nail hkabc.net who seem more than happy to continue to host
this spammer?

[IPv4 whois information for 202.65.99.20 ]
inetnum:      202.65.99.20 - 202.65.99.20 <== Note the IP range
netname:      BB099020
descr:        BB099020
country:      HK
admin-c:      MM211-AP
tech-c:       MM211-AP
status:       ASSIGNED NON-PORTABLE
mnt-by:       MAINT-ABCNET
changed:      abuse[]hkabc.net 20050420
source:       APNIC
person:       Ma wai ming Ma wai ming
nic-hdl:      MM211-AP
e-mail:       wmma[]hkabc.net
address:      HK
phone:        +852 2710 0275
fax-no:       +852 2384 5872
country:      HK
changed:      wmma[]hkabc.net 20050530
mnt-by:       MAINT-ABCNET
source:       APNIC

[DOMAIN whois information for HKABC.NET ]
   Domain Name: HKABC.NET
   Namespace: ICANN Unsponsored Generic TLD - http://www.icann.org
   TLD Info: See IANA Whois - http://www.iana.org/root-whois/net.htm
   Registry: VeriSign, Inc. - http://www.verisign-grs.com
   Registrar: GO DADDY SOFTWARE, INC. - http://registrar.godaddy.com
   Whois Server: whois.godaddy.com
   Name Server[whois+dns with ip] GOLD.HKABC.NET 202.73.252.67
   Name Server[whois+dns with ip] SILVER.HKABC.NET 202.73.252.65
   Status: REGISTRAR-LOCK
   Updated Date: 08-dec-2005
   Creation Date: 05-oct-1995
   Expiration Date: 04-oct-2006
[whois.godaddy.com]
Registrant:
   ABC Net Limited
   2F Jade Mansion
   40 Waterloo Road
   YauMaTei, 852 852
   Hong Kong
   Registered through: GoDaddy.com
   Domain Name: HKABC.NET
      Created on: 04-Oct-95
      Expires on: 03-Oct-06
      Last Updated on: 09-Aug-05
   Administrative Contact:
      Tung, Chung Wai  domainadmin[]hkabc.net
      ABC Net Limited
      2F Jade Mansion
      40 Waterloo Road
      YauMaTei, 852 852
      Hong Kong
      27100363      Fax -- 27100365
   Technical Contact:
      Tung, Chung Wai  domainadmin[]hkabc.net
      ABC Net Limited
      2F Jade Mansion
      40 Waterloo Road
      YauMaTei, 852 852
      Hong Kong
      27100363      Fax -- 27100365
   Domain servers in listed order:
      GOLD.HKABC.NET
      SILVER.HKABC.NET

route:      202.65.96.0/20
descr:      Pacific Internet (Hong Kong) Limited
            Unit 573, HITEC
            1 Trademart Drive
            Kowloon Bay
            HONG KONG
origin:     AS2706
mnt-by:     MAINT-AS2706
changed:    n...@pacific.net.hk 20050124
source:     RADB

route:              202.65.96.0/20
descr:              Proxy Announcement
origin:             AS17444
remarks:            16 Class C from ABC Net
remarks:            Transit via AS17444
notify:             radb_ad...@newworldtel.com
mnt-by:             MAINT-AS17444
changed:            anthony.li...@newworldtel.com 20011204
source:             RADB

route:      202.65.96.0/20
descr:      ABC NET
origin:     AS17989
notify:     yong-chuan....@ap.equinix.com
notify:     jonathan....@ap.equinix.com
mnt-by:     MAINT-EQUINIXPAC
changed:    yong-chuan....@ap.equinix.com 20050718
source:     VERIO

http://www.cidr-report.org/cgi-bin/as-report?as=AS17989
17989 ABCNET-2001-AP ABC NET LTD.  Adjacency:     2  Upstream:     2
Downstream:     0
  Upstream Adjacent AS list
    AS17444   NWT-AS-AP AS number for New World Telephone Ltd.
    AS17819   ASN-EQUINIX-AP Equinix Asia Pacific

http://www.ordb.org/lookup/rbls/?host=202.65.99.20
http://www.spamhaus.org/SBL/sbl.lasso?query=SBL36175
[interesting that there doesn't seem to be an SBL that is specific to
this spammer/group]
http://www.spamhaus.org/SBL/listings.lasso?isp=hkabc.net
http://groups.google.com/groups?q=202.65.99.20&start=0&scoring=d
http://groups.google.com/groups?q=ssmort.net&start=0&scoring=d

202.65.99.20:
DNS1.SSMORT.NET
DNS2.SSMORT.NET
DNS3.SSMORT.NET


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Rev. Beergoggles  
View profile  
 More options Dec 30 2005, 4:38 pm
Newsgroups: news.admin.net-abuse.email
From: "Rev. Beergoggles" <post.repl...@invalid.address>
Date: Fri, 30 Dec 2005 15:38:10 -0600
Local: Fri, Dec 30 2005 4:38 pm
Subject: Re: Mortgage phisher and fake diploma spammer [LONG POST]
glgxg did pass the time by typing:

> Rev. Beergoggles wrote:

>> I've got my own special methods to keep spammy busy. :)

> Why not just nail hkabc.net who seem more than happy to continue to host
> this spammer?

Oh, that's in the works.  I just need an abundance of information.
Next up is putting abuse at godaddy on all larts to hkabc.

>   Registrar: GO DADDY SOFTWARE, INC. - http://registrar.godaddy.com

--
rbg

    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Andreas Kohlbach  
View profile  
 More options Dec 30 2005, 6:03 pm
Newsgroups: news.admin.net-abuse.email
From: "Andreas Kohlbach" <ank...@email.com>
Date: 30 Dec 2005 15:03:12 -0800
Local: Fri, Dec 30 2005 6:03 pm
Subject: Re: Mortgage phisher and fake diploma spammer [LONG POST]

Spam Reporting wrote:

[...]

> We've got one of the world's largest spammers reeling right now... let's
> double the pressure we're putting on them, and watch them fall. The death
> threats show that we're hurting them... now let's drive the stake through
> their hearts.

> We need 5000 people filling in their feedback forms at least once a day
> each with bogus (but believable) data, and running the SpamVampire in
> low-bandwidth-draining mode. We've already got quite a few people doing
> it, but not nearly enough to completely poison their leads database to
> such an extent that it's unusable, nor to run up their hosting costs
> enough to bankrupt them. So, tell everyone you know... slashdot it if you
> want to... publicity will put this spammer out of business.

Unfortunately I use the account of a friend right now and promised not
to "fill out" those forms. I hope to soon have my own account and can
continue.

Umm, anybody has a Linux/Unix account and would let me do it from there
until then? *g*

The script I have somewhere just aspects the URL of this loan spammer
he sent in the spam, since the rest stays the same.

> If you check the link in my sig, you'll find a spreadsheet I compiled that
> makes it really easy to create fake personas for poisoning spammer's
> feedback forms.

I read through it, interesting.

> No more having to look up the ZIP code or area code for
> the fake person you're entering into their database. Every town and city
> in the US is in that spreadsheet, with the corresponding ZIP Code and
> telephone area code.

Not sure what this spammer tests on, but last timeI also had problems
to fill it out more than once.

Another promissing thing is the spamform.pl which you can find at
<http://7eggert.dyndns.org/l/spam+mail/> (along with other nice things
you want to have a look at).Didn't get it running as the perl on my
machine is broken, but people reported to the author it works nicely.
You also just feed it with an URL and, no matter what kind of spam it
is, it's smart enough to generate content (also has a database with
first and last names, street addresses and stuff) and bomb the spammer
with it.

> Just choose a random state for your fake person, pick a random city within
> that state from the spreadsheet, choose a fake name, and fill in the data.
> It's as easy as that.

In this case. But some spammers test that they match.

Some spammers also only let fill out the form once from each IP. For
that you need an anon proxy (or a list with working proxies), like
<http://tor.eff.org/>. A local proxy (Privoxy for example) helps to
integrate this.

> Have you kicked a spammer in the nuts today?
> http://www.thescambaiter.com/forum/showthread.php?t=5653

Hope I can do soon. :-)
--
Andreas

    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Andreas Kohlbach  
View profile  
 More options Dec 30 2005, 6:09 pm
Newsgroups: news.admin.net-abuse.email
From: "Andreas Kohlbach" <ank...@email.com>
Date: 30 Dec 2005 15:09:36 -0800
Local: Fri, Dec 30 2005 6:09 pm
Subject: Re: Mortgage phisher and fake diploma spammer [LONG POST]

Andreas Kohlbach wrote:

I forgot to mention that, for other spam where you can "order" OEM
crap, pen1s enlargement or whatever you need a credit card number which
at least makes it through the test the spammer does. The page at
<http://www.darkcoding.net/index.php/credit-card-numbers/> generates
random credit card numbers (they don't really work so you cannot harm
innocent people) each time you refresh it.

There is also a python script (gencc.py) you can use locally. For
example if you need a new credit card number for your bombing script.
You can grep one from the script every time you fill out a form and
have a new number every time.

This works nicely for mentioned kind of pam, and of course for
Ebay/Paypal/bank phishers to bomb them with fake data.

Happy nuts kicking.
--
Andreas


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Discussion subject changed to "Mortgage phisher and fake diploma spammer" by Rev. Beergoggles
Rev. Beergoggles  
View profile  
 More options Dec 30 2005, 8:48 pm
Newsgroups: news.admin.net-abuse.email
From: "Rev. Beergoggles" <post.repl...@invalid.address>
Date: Fri, 30 Dec 2005 19:48:54 -0600
Local: Fri, Dec 30 2005 8:48 pm
Subject: Re: Mortgage phisher and fake diploma spammer
Spam Reporting did pass the time by typing:

> Keep those domains coming, Rev.

Fresh batch and some analysis.
Seems spammy is trying (poorly) to shuttle name, address, and phone.
Even the country code to hide.  A n00b could do better.

Wow.. the UK and IS country codes rilly lost me for a few hours there.
When spammy ups the volume I code a quicker larting tools. :)

Common IP [202.65.99.20]

d19821.com  Drew Baker   567 SAN NICOLAS  Newport Beach  926266  CA  US  +1.9096365001389
                                      b3b15eb83130939d531660a33d972-954585[]owner.gandi.net
e27831.net  Jim Reda     184 Glen Ellyn Way 14618 UK 303 831-0661   ju217[]kj.net
h73128.net  Jim Reda     184 Glen Ellyn Way 14618 US 303 831-0662   heqwehwq[]ya.net
k03921.com  Jimer Redar  144 Glen Ellyn Way 14616 US 303-831-0661   ju217[]kj.net
k03921.net  Jim Reda     144 Glen Ellyn Way 14618 US 74-81-928-3212 ju2217[]3kj.net
k3820.com   Jim Reda     184 Glen Ellyn Way 14618 UK 303 831-0661   ju217[]kj.net
k812733.net Jim Reda     184 Glen Ellyn Way 14618 US 303 831-0662   heqwehwq[]ya.net
k8192.net   Jim Reda     184 Glen Ellyn Way 14618 UK 303 831-0661   ju217[]kj.net
k9048.com   Jim Reda     144 Glen Ellyn Way 14618 US 74-81-928-3212 ju2217[]3kj.net
k9381.com   Jim Reda     144 Glen Ellyn Way 14618 US 303-831-0669   ju217[]kj.net
k9381.net   Jim Reda     144 Glen Ellyn Way 14618 US 303-831-0669   ju217[]kj.net
m9838.com   Jim Reda     184 Glen Ellyn Way 14618 UK 303 831-0661   ju217[]kj.net
m9838.net   Jim Reda     184 Glen Ellyn Way 14618 UK 303 831-0661   ju217[]kj.net
n03921.com  Jimer Redar  184 Glen Ellyn Way 14618 US 303-831-0669   ju2217[]3kj.net
n03921.net  Jimer Redar  184 Glen Ellyn Way 14618 US 303-831-0669   ju2217[]3kj.net
o94182.com  Jimer Redar  184 Glen Ellyn Way 14618 US 303-831-0669   ju2217[]3kj.net
o94182.net  Jimer Redar  184 Glen Ellyn Way 14618 US 303-831-0669   ju2217[]3kj.net
p4812.com   Jimer Redar  184 Glen Ellyn Way 14618 US 303-831-0661   ju2217[]3kj.net
p4812.net   Jimer Redar  184 Glen Ellyn Way 14618 US 303-831-0661   ju2217[]3kj.net
p63721.com  Jimer Redar  184 Glen Ellyn Way 14618 US 303-831-0661   ju2217[]3kj.net
p63721.net  Jim Reda     144 Glen Ellyn Way 14618 US 303-831-0661   ju2217[]3kj.net
p8123.com   Jim Reda     184 Glen Ellyn Way 14618 IS 303-831-0661   ju2217[]3kj.net
p8123.net   Jim Reda     184 Glen Ellyn Way 14618 IS 303-831-0661   ju2217[]3kj.net
pa812.com   Jimer Redar  184 Glen Ellyn Way 14618 US 303-831-0661   ju2217[]3kj.net
pa812.net   Jimer Redar  184 Glen Ellyn Way 14618 US 303-831-0661   ju2217[]3kj.net
s0192.net   Jim Reda     184 Glen Ellyn Way 14618 UK 303 831-0661   ju217[]kj.net

--
rbg
Support "free speach", donate:
http://www.ahbl.org/legalfund


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
glgxg  
View profile  
 More options Dec 30 2005, 9:56 pm
Newsgroups: news.admin.net-abuse.email
From: glgxg <gl...@mfire.com.invalid>
Date: Fri, 30 Dec 2005 18:56:50 -0800
Local: Fri, Dec 30 2005 9:56 pm
Subject: Re: Mortgage phisher and fake diploma spammer

I've not received a reply back from Mr. Reda... perhaps he's away for
the holidays or my msg was filtered as a spam. Who knows?

Given all of the new domains, I'm willing to bet that spammy has his CC
info and is using that for the signups.


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Rev. Beergoggles  
View profile  
 More options Dec 30 2005, 10:24 pm
Newsgroups: news.admin.net-abuse.email
From: "Rev. Beergoggles" <post.repl...@invalid.address>
Date: Fri, 30 Dec 2005 21:24:27 -0600
Local: Fri, Dec 30 2005 10:24 pm
Subject: Re: Mortgage phisher and fake diploma spammer
glgxg did pass the time by typing:

> I've not received a reply back from Mr. Reda... perhaps he's away for
> the holidays or my msg was filtered as a spam. Who knows?

That's possible.

> Given all of the new domains, I'm willing to bet that spammy has his CC
> info and is using that for the signups.

Yesnic has been alerted about this possiblity in a seperate email.

I have also started collecting and sending evidence of the hkabc.net
spam support to abuse[]godaddy.com via my godaddy hosted domains abuse
address.

--
rbg
Free speach should be free, donate:
http://www.ahbl.org/legalfund


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Discussion subject changed to "Mortgage phisher and fake diploma spammer [LONG POST]" by Spam Reporting
Spam Reporting  
View profile  
 More options Dec 31 2005, 4:52 am
Newsgroups: news.admin.net-abuse.email
From: "Spam Reporting" <FROM:@hillscapital.com>
Date: Sat, 31 Dec 2005 09:52:07 GMT
Local: Sat, Dec 31 2005 4:52 am
Subject: Re: Mortgage phisher and fake diploma spammer [LONG POST]
"Spam Reporting" <FROM:@hillscapital.com> wrote in message

news:Ju7tf.3626$UF3.144@newssvr25.news.prodigy.net...

> They really ramped up the number of domains they registered today, and
> the amount of spam they're sending... looks like we've stirred up a
> hornet's nest. They accounted for ~17% of spam reported today. Of
> course, I'll not reveal the sources I'm checking, so they can't
> list-wash.

They've gone over 1600 total domains, and 1300 dead domains.

Again, we need ~5000 people all running SpamVampire at a very low drain
rate, and filling in their feedback forms with bogus submissions.

You only need to do one form submission per day, so choose a domain from
those currently listed under 202.65.99.20, fill in the bogus data, and
watch as the spammer's leads database becomes so polluted that the leads
become worthless. It takes almost no time for you, but it will cause an
immense amount of damage to the spammers once their leads become so
polluted that the majority of them are bogus.

It also would be an immense help if someone could start canary-trapping
the leads brokers, so we can determine once and for all the lead sellers
who are acting as fronts for this spammer.

The list of domains (alive and dead) for this spammer and scammer:

==============================

11.221.133.100 ns2.jad3.com

24.126.58.51 dns10.o84mort.net

24.127.0.35 ns2.nb2372.com

58.177.252.85:
ns7.1234-9876.com   ns7.donfiyaymay.com   ns7.host4allhere.com

59.107.72.195:
ns2.c01l.com   ns2.grumbl3.com

60.28.29.170:
ns1.mpixet.com   ns1.wepori.com

60.28.29.227 ns2.wepori.com

61.31.214.173:
ns05.1234-9876.com   ns05.host4allhere.com

61.183.60.16:
ns1.4n0w.net   ns2.4n0w.net

61.234.235.13 ns3.l76288.net

62.205.194.73 ns1.cz-trans.com

63.245.201.3 mail.thebesthgh.com

64.20.43.107 kemort.com

64.69.68.143 hgrefi.net

64.94.29.14 bxmort.net

64.202.189.170:
jungleventures.biz   jungleventures.info   jungleventures.net

65.182.132.3 ns3.host4allhere.com

66.118.136.67:
breathe-123.com   bxmort.com   ds838.com   join-123.com   ns1.join-123.com
ns2.join-123.com

66.98.186.167 iehdg.info

68.88.219.218 re-finance.com

68.160.116.241 ns1.8sek.com

69.25.142.3:
hello-123.net   kw839.net

69.55.109.39 thebesthgh.com

72.232.37.132 solidinvestment.com

200.200.200.220 ns1.hostfor-web.com

200.200.200.222:
f1.whataf.com   f2.whataf.com   ns1.37-37.com   ns1.37-37-37.com
ns1.agnitech-service.com   ns1.alwaysbestpornsites.com   ns1.archaist.net
ns1.daniil-help.com   ns1.fengar.com   ns1.fleeing.net   ns1.foejesbd.com
ns1.hostinhost.com   ns1.megaoemsoftware.com   ns1.oemtime1.com
ns1.posthosting-area.com   ns1.presumer.net   ns1.realysitesdaily.com
ns1.segmental.net   ns1.ship-pay.com   ns1.tyrmu.com
ns1.vps-master-host.com   ns1.xhostback.com   ns1.yourdomainshere.com
ns2.37-37.com   ns2.37-37-37.com   ns2.agnitech-service.com
ns2.alwaysbestpornsites.com   ns2.archaist.net   ns2.daniil-help.com
ns2.fengar.com   ns2.fleeing.net   ns2.foejesbd.com   ns2.hostfor-web.com
ns2.hostinhost.com   ns2.megaoemsoftware.com   ns2.neosoftwareshop.com
ns2.oemtime1.com   ns2.posthosting-area.com   ns2.presumer.net
ns2.realysitesdaily.com   ns2.segmental.net   ns2.ship-pay.com
ns2.spx2006.com   ns2.transporteza.com   ns2.tyrmu.com   ns2.xhostback.com
ns2.yourdomainshere.com   ns3.37-37-37.com   ns3.pulle.net
ww.w-e-gold.com   www.aucgs.net   www1.aucgs.net   y1.bostonoem.com
y1.hundredoem.com   y1.novemberoemtime.com   y1.oemforyoutobuy.com
y1.onlythisoem.com   y2.blacksundownload.com   y2.bostonoem.com
y2.hundredoem.com   y2.losangelesoem.com   y2.novemberoemtime.com
y2.onlythisoem.com

202.65.99.20:
1728j.net   813248a.net   a2732.net   b8182.net   dns1.ssmort.net
dns2.ssmort.net   dns3.ssmort.net   e27831.com   e27831.net   f19391.net
h7236.com   h7236.net   h73128.net   j2371.com   j2371.net   j8219.net
k03921.com   k03921.net   k092812.com   k092812.net   k18271.net
k3820.com   k3820.net   k4783.net   k48122.net   k483821.net   k812733.net
k8192.com   k8192.net   k82391.net   k9048.com   k9048.net   k9381.com
k9381.net   k9812.net   l1921.net   l2981.net   la192.net   lp2912.com
lp2912.net   m28172.net   m2871.net   m812371.net   m82912.com
m82912.net   m9281.com   m9281.net   m9838.com   m9838.net   n0293.com
n0293.net   n03921.com   n03921.net   ns01.ssmort.net   o12933.com
o12933.net   o94182.com   o94182.net   p04831.com   p04831.net   p4812.com
p4812.net   p63721.com   p63721.net   p8123.com   p8123.net   pa812.com
pa812.net   q2737.net   s0192.com   s0192.net   ssmort.net   w12838.net
y32171.com   y32171.net   y8491.com   y8491.net

202.103.56.86 ns2.fe11we11.com

202.157.177.77 ns1.piratesplayground.com

202.157.177.85:
ns1.999-999.biz   ns2.999-999.biz   ns2.piratesplayground.com

202.181.210.215:
ns01.host4allhere.com   ns01.loanszx.com

204.251.15.171:
freestyleaffiliates.com   ns0.freestyleaffiliates.com
ns1.freestyleaffiliates.com

204.251.15.194 m-tg-today.com

205.209.184.110:
ns1.hosting-for-jungle-ventures.com   ns2.hosting-for-jungle-ventures.com

211.144.147.126:
ns1.fastturning.com   ns1.funniestime.com   ns1.funnyisntit.com
ns1.hitherehomie.com   ns1.l76288.net   ns1.simplyonce.com
ns1.simplyonce.net   ns1.whoarey0u.com   ns1.whoarey0u.net
ns2.boringisntit.com   ns2.boringisntit.net   ns2.chancewasonce.com
ns2.chancewasonce.net   ns2.easymista.com   ns2.easymista.net
ns2.fastturning.com   ns2.fastturning.net   ns2.funniestime.com
ns2.funniestime.net   ns2.funnyisntit.net   ns2.gofor1t.net
ns2.interstingplace.com   ns2.interstingplace.net   ns2.simplyonce.com
ns2.simplyonce.net   ns2.whoarey0u.com   ns2.whoarey0u.net
ns3.funniestime.com   simplyonce.com   simplyonce.net   whoarey0u.com
whoarey0u.net211.144.147.134 ns1.hihellothere.com

211.144.147.134 ns2.h0lier.net

211.147.228.104 ns3.nscomur.com

211.147.228.105 ns2.6555.biz

216.52.184.240 kw839.com

217.126.254.239 din3.com

218.201.43.139 ns1.hurry-4.com

218.201.43.147:
funnyprice.net   hitherehomie.com   l5875.com   l76288.net
ns1.funnyprice.net   ns1.peopleschoiceismort.net   ns1.sh0ots.net
ns1.timet0save.net   ns2.feeltherhythm.net   ns2.funnyprice.net
ns2.hitherehomie.com   ns2.l76288.net   ns2.peopleschoiceismort.net
ns2.timet0save.net   peopleschoiceismort.net   sh0ots.net   timet0save.net

218.201.43.230:
ns2.funnyisntit.com   ns2.gofor1t.com   ns2.heyabrp.com

218.244.189.22:
ns3.1234-9876.com   ns3.donfiyaymay.com

219.138.7.185 ns2.guimar287.com

219.138.7.186 ns1.guimar287.com

219.254.32.117:
ns03.donfiyaymay.com   ns03.host4allhere.com   ns04.host4allhere.com
ns04.nowhostthis.com

220.248.157.27 ns1.jad3.com

221.5.2.44:
bbb.pajamakama.com   la.acrazebicm.com   teok.boultergdgc.com

221.5.2.130 ns1.helago.com

221.5.250.87:
ns1.4n0w.com   ns1.br1b3ry.com   ns1.brid3.com   ns1.brid3.net
ns1.help-is-near.com   ns1.pay-m3.com   ns2.4n0w.com   ns2.br1b3ry.com
ns2.brid3.com   ns2.brid3.net   ns2.help-is-near.com   ns2.pay-m3.com

221.7.209.67:
bluangle.com   blutriongle.com   ceeptowe.com   floatwyck.com
fortishfee.com   happyjuke.com   hydebig.com   kampup.com   kedhouse.com
ns1.bluangle.com   ns2.bluangle.com   nytehappy.com   unsork.com
washyde.com   wyckbig.com

221.7.209.85 ns3.pointerns.com

221.7.209.93 ns1.curt-1.net

221.10.201.157:
ns1.1-2-3-mtg.net   ns1.j0in.com   ns1.pla1n.com   ns1.pr1c3.net
ns1.stra1n.net   ns2.1-2-3-mtg.net   ns2.j0in.com   ns2.pla1n.com
ns2.pr1c3.net   ns2.stra1n.net

221.11.133.60:
ns1.246-135.com   ns5.1234-9876.com   ns5.host4allhere.com
ns5.showmethehosting.com

221.11.134.11 ns1.6555.biz

221.11.134.34:
ns1.c01l.com   ns1.grumbl3.com   ns1.grumbl3.net   ns1.hello-123.net
ns1.join-123.net   ns1.tistart.com   ns2.cost-123.com   ns2.grumbl3.net
ns2.hello-123.net   ns2.join-123.net   ns2.tistart.com

221.12.161.103 ns5.pointerns.com

221.12.161.104:
ns1.hurry-3.com   ns2.curt-1.net

221.143.42.59 ns3.mort-xyz.com

222.39.47.94 ns5.tekheadisadickhead.com

222.47.78.228 ns1.g00d-things.com

222.47.94.31 ns2.g00d-things.com

222.47.183.202:
ns1.cost-123.com   ns4.tekheadisadickhead.com

222.51.53.147:
ns1.alongfry.net   ns1.byefour.net   ns1.cryforsmall.net   ns1.gofor1t.com
ns1.h0lier.net   ns1.heyabrp.net   ns1.hiago.net   ns1.lokkoa.net
ns1.prettyhit.net   ns2.alongfry.net   ns2.byefour.net
ns2.cryforsmall.net   ns2.hiago.net   ns2.hihellothere.com
ns2.lokkoa.net   ns2.prettyhit.net

222.168.100.181 ns1.fe11we11.com

0.0.0.0:
123456-123.biz   1234-9876.com   1-2-3-mtg.com   1-2-3-mtg.net
1-2-mtg.com   1-2-mtg.net   1ncr3dible.com   1ncr3dible.net   246-135.com
37-37.com   37-37-37.com   3asler.com   3l33t187.net   3-mn.com
43v3r.com   43v3r.net   4n0w.com   4n0w.net   4orty4.com   4rate.net
6555.biz   987-654.biz   999-999.biz   abanid.com   a-b-c-finance.com
abnegated.net   adsmort.net   agnitech-service.com   agoodfeel.com
agoodfeel.net   ah37.com   ah37.net   akekicb.com   al1v3.com
all-cds.org   alldisks.net   alongfar.com   alongfar.net   alongfry.com
alongfry.net   alwaysbestpornsites.com   antitankal.com   appl3s.com
archaist.net   archnesses.com   areyouaok.com   areyouaok.net   argime.com
asofttube.com   asofttube.net   ast0unds.com   ast0unds.net   aucgs.net
b0ngs.com   b0ngs.net   b3mort.com   b3mort.net   babiismcb.com
baj28.com   baj28.net   beebreads.net   beersoena.com   befileml.com
bestplacetoshowatches.com   bgrefi.net   bilstedaa.com   biolyticim.com
blacksundownload.com   bleeryde.com   bluerate.com   boringisntit.com
boringisntit.net   bostonoem.com   br00ding.com   br00ding.net   br01l.com
br01l.net   br0w.net   br0wnies.com   br0wnies.net   br1b3ry.com
br1ght.com   br1ght.net   br1lliant.com   br1lliant.net   br33ding.com
br33ze.com   br33ze.net   br3ath.com   br3ath.net   bra1d.com   bra1d.net
bra1ds.com   bra1ds.net   bra1ns.com   bra1ns.net   brambl3.com
brav3.com   brav3.net   brave-123.com   brave-123.net   brbrbr3.com
brid3.com   brid3.net   bright-3.com   bright-3.net   bro1l.com
browntables.com  
...

read more »


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Spam Reporting  
View profile  
 More options Dec 31 2005, 3:50 pm
Newsgroups: news.admin.net-abuse.email
From: "Spam Reporting" <FROM:@hillscapital.com>
Date: Sat, 31 Dec 2005 20:50:55 GMT
Local: Sat, Dec 31 2005 3:50 pm
Subject: Re: Mortgage phisher and fake diploma spammer [LONG POST]
"Spam Reporting" <FROM:@hillscapital.com> wrote in message

news:bxstf.39874$dO2.35115@newssvr29.news.prodigy.net...

> They've gone over 1600 total domains, and 1300 dead domains.

So, is eNom actively helping this spammer with hosting and redirects?

Check out:
y37212.com
y37212.net
n3824.com
n3824.com

----------

dns y37212.com
Mail for y37212.com is handled by eforward3.name-services.com
eforwardct.name-services.com
Canonical name: y37212.com
Addresses:
  64.74.96.243

----------

whois -h whois.completewhois.com 64.74.96.243 ...
[IPv4 whois information for 64.74.96.243 ]
[whois.arin.net]
Internap Network Services PNAP-SEA-BLOCK4 (NET-64-74-0-0-1)
                                  64.74.0.0 - 64.74.255.255
eNom PNAP-CHG-ENOM-RM-01 (NET-64-74-96-224-1)
                                  64.74.96.224 - 64.74.96.255

----------

All the newly registered domains for this spammer do a 302 redirect to
p04831.net, which is still on the old IP address of 202.65.99.20.

If you check out the DNS setup they've got for the newly registered
domains:

  Name Server[whois+dns with ip] DNS1.NAME-SERVICES.COM 69.25.142.1
  Name Server[whois+dns with ip] DNS2.NAME-SERVICES.COM 216.52.184.230
  Name Server[whois+dns with ip] DNS3.NAME-SERVICES.COM 63.251.92.193
  Name Server[whois+dns with ip] DNS4.NAME-SERVICES.COM 64.74.96.242
  Name Server[whois+dns with ip] DNS5.NAME-SERVICES.COM 212.118.243.118

----------

And that is:
Domain name: name-services.com
Administrative Contact:
   eNom, Inc.
   DNS Manager (paul.stah...@enom.com)
   +1.4258838860
   Fax: +1.4258833553
   P.O. Box 7449
   2002 156th Avenue NE, Ste. 300
   Bellevue, WA 98007
   US

----------

Notice also that the domains list two Registrars:
  Registrar: ENOM, INC. - http://www.enom.com
  Registration Service Provided By: NameCheap.com

So, apparently NAMECHEAP.COM is ENOM.COM.

----------

All signs point back to eNom.com, and it looks like eNom.com is actively
helping this spammer and scammer to commit criminal offenses via the
internet.

--
Have you kicked a spammer in the nuts today?
http://www.thescambaiter.com/forum/showthread.php?t=5653


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Karl-Josef Ziegler  
View profile  
 More options Dec 31 2005, 4:12 pm
Newsgroups: news.admin.net-abuse.email
From: Karl-Josef Ziegler <k...@despammed.com>
Date: Sat, 31 Dec 2005 22:12:19 +0100
Local: Sat, Dec 31 2005 4:12 pm
Subject: Re: Mortgage phisher and fake diploma spammer [LONG POST]

Spam Reporting wrote:
> So, is eNom actively helping this spammer with hosting and redirects?

For me since a long time eNom/Internap simply is 'black hat'. Period.
Why should anything have changed?

- kjz


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Marcus Aurelius  
View profile  
 More options Dec 31 2005, 7:12 pm
Newsgroups: news.admin.net-abuse.email
From: Marcus Aurelius <aur.mar...@gmail.com>
Date: Sun, 1 Jan 2006 01:12:54 +0100
Local: Sat, Dec 31 2005 7:12 pm
Subject: Re: Mortgage phisher and fake diploma spammer [LONG POST]
Scripsit Spam Reporting:

> So, is eNom actively helping this spammer with hosting and redirects?

AFAICS, eNom is a registrar set up (by spammers?) specifically to
register spammers' domains.

--
MA


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Spam Reporting  
View profile  
 More options Jan 1 2006, 10:18 am
Newsgroups: news.admin.net-abuse.email
From: "Spam Reporting" <FROM:@hillscapital.com>
Date: Sun, 01 Jan 2006 15:18:25 GMT
Local: Sun, Jan 1 2006 10:18 am
Subject: Re: Mortgage phisher and fake diploma spammer [LONG POST]
"Spam Reporting" <FROM:@hillscapital.com> wrote in message

news:PaCtf.40728$BZ5.28796@newssvr13.news.prodigy.com...

> "Spam Reporting" <FROM:@hillscapital.com> wrote in message
> news:bxstf.39874$dO2.35115@newssvr29.news.prodigy.net...
>> They've gone over 1600 total domains, and 1300 dead domains.

Ok, I finally found a connection between Alex Polyakov and the new botnet
that's developing... perusing the spam source code sometimes pays off.

As a hint, take a look at the source code of the spam reported for:
g10928.org/1093

Notice that they're using the same exact wording (including some
mis-spellings) as the spam already attributed to Polyakov. This also ties
USA Lenders Network to Polyakov, since the site says:
"Submitting personal information constitutes a request to generate a
mortgage quote and authorize USA Lenders Network to send your loan request
to multiple qualified lenders and brokers, who will be calling you with no
obligation mortgage quotes. The information will be used and disclosed to
effect only such transaction."

So, we can start adding the botnet domains to the list of known domains
belonging to Alex Polyakov... the bigger he tries to get, the more illegal
he's got to do things, and the quicker he'll be brought down.

They've gone over 1800 domains.

And with the information I've provided to LE, both he and Kuvayev should
feel very uncomfortable venturing out in public from now on. Forces have
been set in motion that will eventually net them both... or has Kuvayev
forgotten that getting forces set in motion is what I excel at? That's why
he's so mad at me, rather than anybody else.

As an aside, there is another botnet out there... not sure if it belongs
to Polyakov et. al. Check out greatgauge.com for an example of that
botnet. If that's Polyakov's, as well, then all the mortgage spam is
coming from just one source. And that means that ~17% of spam worldwide is
coming from just one source. And THAT means that there is even more
incentive for LE to take them down.

The list of domains (alive and dead) attributed to this spammer / scammer
/ botnet operator:

==============================

11.221.133.100 ns2.jad3.com

24.95.57.200 ns2.smiley-fam.com

24.126.58.51 dns10.o84mort.net

24.127.0.35 ns2.nb2372.com

58.177.252.85:
ns7.1234-9876.com   ns7.donfiyaymay.com   ns7.host4allhere.com

59.107.72.195:
ns2.c01l.com   ns2.grumbl3.com

60.28.29.170:
ns1.mpixet.com   ns1.wepori.com

60.28.29.227 ns2.wepori.com

61.31.214.173:
ns05.1234-9876.com   ns05.host4allhere.com

61.183.60.16:
ns1.4n0w.net   ns2.4n0w.net

61.234.235.13 ns3.l76288.net

62.195.153.86 robinsml.com

62.205.194.73 ns1.cz-trans.com

63.245.201.3 mail.thebesthgh.com

63.251.92.195 k10293.com

64.20.43.107 kemort.com

64.69.68.143 hgrefi.net

64.74.134.64 bxmort.net

64.202.189.170:
jungleventures.biz   jungleventures.info   jungleventures.net

65.25.255.105 z984132.net

65.43.180.39 ns3.robinsml.com

65.182.132.3 ns3.host4allhere.com

66.90.142.48 ns3.smiley-fam.com

66.98.186.167 iehdg.info

66.118.136.67:
breathe-123.com   bxmort.com   ds838.com   join-123.com   ns1.join-123.com
ns2.join-123.com

67.186.166.108:
ns2.robinsml.com   ns5.smiley-fam.com

68.61.57.106:
ns4.robinsml.com   ns5.robinsml.com

68.88.219.218 re-finance.com

68.127.160.45 ns1.smiley-fam.com

68.160.116.241 ns1.8sek.com

68.248.229.66 smiley-fam.com

69.25.142.3:
hello-123.net   k10293.net   kw839.net   l0294.net   m1023.com   m1023.net
n0392.net   n3824.com   n3824.net   n84712.net   y37212.net

69.55.109.39 thebesthgh.com

69.142.79.147 d19821.com

69.142.81.10 ns4.smiley-fam.com

69.225.17.67 ns1.robinsml.com

69.252.163.134 g10928.org

72.232.37.132 solidinvestment.com

200.200.200.220 ns1.hostfor-web.com

200.200.200.222:
f1.whataf.com   f2.whataf.com   ns1.37-37.com   ns1.37-37-37.com
ns1.agnitech-service.com   ns1.alwaysbestpornsites.com   ns1.archaist.net
ns1.daniil-help.com   ns1.fengar.com   ns1.fleeing.net   ns1.foejesbd.com
ns1.hostinhost.com   ns1.megaoemsoftware.com   ns1.oemtime1.com
ns1.posthosting-area.com   ns1.presumer.net   ns1.realysitesdaily.com
ns1.segmental.net   ns1.ship-pay.com   ns1.tyrmu.com
ns1.vps-master-host.com   ns1.xhostback.com   ns1.yourdomainshere.com
ns2.37-37.com   ns2.37-37-37.com   ns2.agnitech-service.com
ns2.alwaysbestpornsites.com   ns2.archaist.net   ns2.daniil-help.com
ns2.fengar.com   ns2.fleeing.net   ns2.foejesbd.com   ns2.hostfor-web.com
ns2.hostinhost.com   ns2.megaoemsoftware.com   ns2.neosoftwareshop.com
ns2.oemtime1.com   ns2.posthosting-area.com   ns2.presumer.net
ns2.realysitesdaily.com   ns2.segmental.net   ns2.ship-pay.com
ns2.spx2006.com   ns2.transporteza.com   ns2.tyrmu.com   ns2.xhostback.com
ns2.yourdomainshere.com   ns3.37-37-37.com   ns3.pulle.net
ww.w-e-gold.com   www.aucgs.net   www1.aucgs.net   y1.bostonoem.com
y1.hundredoem.com   y1.novemberoemtime.com   y1.oemforyoutobuy.com
y1.onlythisoem.com   y2.blacksundownload.com   y2.bostonoem.com
y2.hundredoem.com   y2.losangelesoem.com   y2.novemberoemtime.com
y2.onlythisoem.com

202.65.99.20:
1728j.net   813248a.net   a167.net   a172.net   a182.net   a2732.net
a8122.net   b121.net   b261.net   b271.net   b281.net   b3272.net
b372.net   b8182.net   c176.net   c9012.net   d291.com   d291.net
dns1.ssmort.net   dns2.ssmort.net   dns3.ssmort.net   e162.net
e27831.com   e27831.net   e718.net   f12373.net   f19391.net   f721.net
g261.net   g271.net   g728.net   g732.net   g73232.net   h271.net
h2712.net   h272.net   h273.net   h2738.com   h2738.net   h278.net
h3712.net   h3721.net   h7236.com   h7236.net   h73128.net   h7323.net
ha172.net   ha712.net   i817.net   i8322.net   j1611.net   j2371.com
j2371.net   j271.net   j2712.com   j2712.net   j2812.net   j2871.net
j3182.net   j8212.net   j8219.net   ju372.net   k0293.com   k0293.net
k03921.com   k03921.net   k09218.net   k092812.com   k092812.net
k18271.net   k192.net   k1921.net   k1922.net   k218.net   k2819.net
k283.com   k283.net   k2832.net   k2893.net   k321912.net   k382.net
k3820.com   k3820.net   k3821.net   k38291.net   k3891.net   k39281.com
k39281.net   k4783.net   k48122.net   k483821.net   k812733.net
k8192.com   k8192.net   k82391.net   k82712.com   k82712.net   k9048.com
k9048.net   k9180.com   k9180.net   k91832.net   k9281.net   k92812.net
k9381.com   k9381.net   k9812.net   l1921.net   l281.net   l282.net
l2833.com   l2910.com   l2910.net   l2981.net   l3921.net   l7281.com
l7281.net   l9382.net   la192.net   lp2912.com   lp2912.net   m1821.net
m273.net   m2781.net   m281.net   m28172.net   m287.net   m2871.net
m291.net   m3128.net   m3218.net   m812371.net   m82912.com   m82912.net
m83721.com   m83721.net   m912.net   m9281.com   m9281.net   m9838.com
m9838.net   n0293.com   n0293.net   n03921.com   n03921.net   n1272.net
n1281.com   n1281.net   n271.net   n2718.net   n281.net   n289.net
n712.net   n721.net   ns01.ssmort.net   o12933.com   o12933.net   o291.net
o9012.com   o9012.net   o9233.net   o94182.com   o94182.net   p04831.com
p04831.net   p09281.com   p09281.net   p093821.com   p093821.net
p192.net   p28312.com   p28312.net   p291.net   p298.net   p32892.net
p472.com   p472.net   p4812.com   p4812.net   p63721.com   p63721.net
p7462.net   p8123.com   p8123.net   p9012.com   p9012.net   p9281.net
pa812.com   pa812.net   q2737.net   r261.net   r262.net   r3626.net
r3722.net   s0192.com   s0192.net   s281.net   ssmort.net   t172.net
t23718.net   t263.net   t272.net   t2761.net   t7212.net   u161.net
u8312.net   v121.net   v261.net   v271.net   v837.com   v837.net
w12838.net   w721.net   x172.net   x817.net   y271.net   y32171.com
y32171.net   y621.net   y712.net   y721.net   y7281.com   y7281.net
y732.net   y8491.com   y8491.net   ye3h.net   z1721.com   z1721.net
z812.net   z9102.com   z9102.net

202.157.177.77 ns1.piratesplayground.com

202.157.177.85:
ns1.999-999.biz   ns2.999-999.biz   ns2.piratesplayground.com

202.181.210.215:
ns01.host4allhere.com   ns01.loanszx.com

204.251.15.171:
freestyleaffiliates.com   ns0.freestyleaffiliates.com
ns1.freestyleaffiliates.com

204.251.15.194 m-tg-today.com

205.209.184.110:
ns1.hosting-for-jungle-ventures.com   ns2.hosting-for-jungle-ventures.com

211.144.147.126:
boringisntit.com   boringisntit.net   chancewasonce.com
chancewasonce.net   easymista.com   easymista.net   fastturning.com
fastturning.net   funniestime.com   funniestime.net   funnyisntit.com
funnyisntit.net   gofor1t.com   gofor1t.net   interstingplace.com
interstingplace.net   ns1.boringisntit.com   ns1.boringisntit.net
ns1.chancewasonce.com   ns1.chancewasonce.net   ns1.easymista.com
ns1.easymista.net   ns1.fastturning.com   ns1.fastturning.net
ns1.funniestime.com   ns1.funniestime.net   ns1.funnyisntit.net
ns1.gofor1t.net   ns1.hitherehomie.com   ns1.interstingplace.com
ns1.interstingplace.net   ns1.l76288.net   ns1.simplyonce.com
ns1.simplyonce.net   ns1.whoarey0u.com   ns1.whoarey0u.net
ns2.boringisntit.com   ns2.boringisntit.net   ns2.chancewasonce.com
ns2.chancewasonce.net   ns2.easymista.com   ns2.easymista.net
ns2.fastturning.com   ns2.fastturning.net   ns2.funniestime.com
ns2.funniestime.net   ns2.funnyisntit.net   ns2.gofor1t.net
ns2.interstingplace.com   ns2.interstingplace.net   ns2.simplyonce.com
ns2.simplyonce.net   ns2.whoarey0u.com   ns2.whoarey0u.net
ns3.funniestime.com   simplyonce.com   simplyonce.net   whoarey0u.com
whoarey0u.net

211.144.147.128:
bluangle.com   blutriongle.com   ceeptowe.com   floatwyck.com
fortishfee.com   happyjuke.com   hydebig.com   kampup.com   kedhouse.com
lykewas.com   ns1.bluangle.com   ns2.bluangle.com   nytehappy.com
unsork.com   washyde.com   wyckbig.com

211.144.147.134:
ns1.hihellothere.com   ns2.h0lier.net

211.147.228.104 ns3.nscomur.com

211.147.228.105 ns2.6555.biz

212.118.243.115:
l0294.com   n0392.com   y37212.com

216.52.184.240 kw839.com

217.126.254.239 din3.com

218.201.43.139 ns1.hurry-4.com
...

read more »


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Rev. Beergoggles  
View profile  
 More options Jan 1 2006, 1:57 pm
Newsgroups: news.admin.net-abuse.email
From: "Rev. Beergoggles" <post.repl...@invalid.address>
Date: Sun, 1 Jan 2006 12:57:38 -0600
Local: Sun, Jan 1 2006 1:57 pm
Subject: Re: Mortgage phisher and fake diploma spammer [LONG POST]
Spam Reporting did pass the time by typing:

> As a hint, take a look at the source code of the spam reported for:
> g10928.org/1093

I found this interesting

x82387.com = [ 221.7.209.67 ]
             [61.234.235.12]
  PacNames Whois Server Version 1.1.0
     Domain name: X82387.COM
     Registrar: PacNames        <-- more on this, note 2
     Referral URL: http://www.pacnames.com/
     Domain Registrant: TOTALNIC-127686 KINGGOOGLE[]FUSEMAIL.COM
        Matthew Peirson         <-- odd spelling, Pierson more common
        2160 E FRY BLVD         <-- Strip mall, note 1
        Sierra Vista AZ 85635
        Telephone: 1.6238498388 <-- Phoenix Arizona
        Fax: 1.6238498389

(note 1)
The UPS Store #0516
  2160 E Fry Blvd, Sierra Vista AZ 85635, 520-459-6996
Resort hotel booking
  http://www.sancarlosmexico.com/
  2160 E. Fry Blvd., 433, Sierra Vista, AZ 85635
  Tel: (520) 678-7765 (800) 308-8478  Fax: (520) 378-3521

(note 2)
www.pacnames.com main page is very amateurish in nature.
if you go to pacnames.com they don't even know how to alias
back to www.

pacnames.com = [ 209.245.20.98 ]
     Domain Registrant: TOTALNIC-73552 SUPPORT[]PACNAMES.COM
        Technical Manager
        PacDomains  Ltd. dba PacNames
        42 Montgomeray Avenue
        Murrays Bay
        North Shore City nil nil
        NZ                          <--- exsqeeze me? (note 3)
        Telephone: 1.3033021400     <--- exsqeeze me? (note 3)
        Fax:

(note 3)
303-302-1 is Denver Colorado.
Even stretching it
(30) is Greece, not NZ which is (64)

]http://www.totalnic.net/
]
]PACNAMES is pleased to announce it recently
]acquired the TotalNIC gTLD registrar. PACNAMES
]has now implemented a new registration interface
]at www.PACNAMES.com.
]
]PACNAMES thanks you for your business and apologizes
]for any inconvience this transition may entail. Support
]officers are available on +1-303 302 1400 (or info[]pacnames.com)
]to assist with any queries you may have in relation to
]the new registration website.

How nice.  Now even registrars use false registration data.

--
rbg


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Karl-Josef Ziegler  
View profile  
 More options Jan 1 2006, 4:07 pm
Newsgroups: news.admin.net-abuse.email
From: Karl-Josef Ziegler <k...@despammed.com>
Date: Sun, 01 Jan 2006 22:07:28 +0100
Local: Sun, Jan 1 2006 4:07 pm
Subject: Re: Mortgage phisher and fake diploma spammer [LONG POST]

Rev. Beergoggles wrote:
> How nice.  Now even registrars use false registration data.

and:

http://www.rfc-ignorant.org/tools/lookup.php?domain=pacnames.com

have no working postmaster, abuse and whois address....

PacNames = darkest black....

- kjz


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Discussion subject changed to "Mortgage phisher and fake diploma spammer" by Spam Reporting
Spam Reporting  
View profile  
 More options Jan 1 2006, 11:24 pm
Newsgroups: news.admin.net-abuse.email
From: "Spam Reporting" <FROM:@hillscapital.com>
Date: Mon, 02 Jan 2006 04:24:06 GMT
Local: Sun, Jan 1 2006 11:24 pm
Subject: Re: Mortgage phisher and fake diploma spammer
"Spam Reporting" <FROM:@hillscapital.com> wrote in message

news:5pStf.40114$dO2.13105@newssvr29.news.prodigy.net...

> Ok, I finally found a connection between Alex Polyakov and the new
> botnet that's developing... perusing the spam source code sometimes pays
> off.

Bwahahahaha!

Hey, Polyakov! If what you are and what you do are considered 'swear
words' then why do you do it?

http://shaver.nytehappy.com/zee2/default.asp?affiliateid=11103
var swear_words_arr=new
Array("fuck","cunt","shit","dickless","cocksucker","bitch","whore","fag","s pammer","pussy","dick","spam","cock");

Thanks, stupid... I'll be sure to change the SpamVampire URL appendage
wording to avoid those words... do you mind if I use something like
'mouth-breathing troglodyte' instead?

--
Have you kicked a spammer in the nuts today?
http://www.thescambaiter.com/forum/showthread.php?t=5653
http://www.hillscapital.com/antispam/


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Discussion subject changed to "Mortgage phisher and fake diploma spammer [LONG POST]" by fhh
fhh  
View profile  
 More options Jan 2 2006, 7:08 pm
Newsgroups: news.admin.net-abuse.email
From: fhh <f...@nospam.demon.invalid>
Date: Tue, 03 Jan 2006 01:08:54 +0100
Local: Mon, Jan 2 2006 7:08 pm
Subject: Re: Mortgage phisher and fake diploma spammer [LONG POST]

Spam Reporting wrote:
>> They've gone over 1600 total domains, and 1300 dead domains.
> So, is eNom actively helping this spammer with hosting and redirects?

That I do not know. However I do know that services of eNom are being abused
by some spammers in much the same way as geocities.com directories are
abused to fool spamfilters. The difference is that the services of eNom are
not free of charge.

Some outfit advertising eplanteurope.com is using about 400 *.info domains
(all hosted and registered through eNom) in well defined spamruns. That is:
all those 400 *.info domains point to eplanteurope.com through 2 redirects
(I just put my finger in the giant spam flow of a certain spam botnetwork
for a few hours to get these domains) .

Examples:

http://groups.google.com/group/nl.internet.misbruik/msg/0e213e63dc43bbf9
http://groups.google.com/group/news.admin.net-abuse.email/msg/a67dee6...

--
feike


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Discussion subject changed to "Mortgage and fake diploma spammer / investment scammer / money launderer / credit card thief [LONG POST]" by Spam Reporting
Spam Reporting  
View profile  
 More options Jan 3 2006, 10:48 am
Newsgroups: news.admin.net-abuse.email
From: "Spam Reporting" <FROM:@hillscapital.com>
Date: Tue, 03 Jan 2006 15:48:27 GMT
Local: Tues, Jan 3 2006 10:48 am
Subject: Re: Mortgage and fake diploma spammer / investment scammer / money launderer / credit card thief [LONG POST]
"Spam Reporting" <FROM:@hillscapital.com> wrote in message

news:GV1uf.42739$7h7.26219@newssvr21.news.prodigy.com...

> Hey, Polyakov! If what you are and what you do are considered 'swear
> words' then why do you do it?

They continue to register domains at a high rate, and spam at an extremely
high rate... the sources I'm checking show them accounting for ~17% of all
reported spam. With as large a user base as these reporting entities have,
that should mean that Polyakov is now accounting for ~17% of all spam
worldwide. He's obviously trying to listwash people reporting to NANAS...
he's not showing up there much at all.

Keep in mind that all the domains currently being registered (hosted on
202.65.99.20) are paid for with stolen credit cards, obtained via
Polyakov's large money laundering and credit card theft ring that he
operates here in the US.

The list of domains (alive and dead) that are attributed to this spammer /
scammer:

==============================

11.221.133.100 ns2.jad3.com

12.218.132.207:
ns1.robinsml.com   ns1.smiley-fam.com

24.16.110.136 ns3.smiley-fam.com

24.19.170.53 d19821.com

24.126.58.51 dns10.o84mort.net

24.127.0.35 ns2.nb2372.com

24.222.67.114 g10928.org

58.177.252.85:
ns7.1234-9876.com   ns7.donfiyaymay.com   ns7.host4allhere.com

59.107.72.195:
ns2.c01l.com   ns2.grumbl3.com

59.188.1.173 ns4.freeformsx.com

60.28.29.170:
ns1.mpixet.com   ns1.wepori.com

60.28.29.227 ns2.wepori.com

61.31.214.74 ns5.freeformsx.com

61.31.214.173:
ns05.1234-9876.com   ns05.host4allhere.com   ns3.freeformsx.com

61.183.60.16:
ns1.4n0w.net   ns2.4n0w.net

61.234.235.12 ns1.freeformsx.com

61.234.235.13:
ns1.l76288.net   ns3.l76288.net

62.205.194.73 ns1.cz-trans.com

63.245.201.3 mail.thebesthgh.com

63.251.92.195 kw839.com

64.94.29.64 bxmort.net

64.202.189.170:
jungleventures.biz   jungleventures.info   jungleventures.net

65.43.180.39 ns2.robinsml.com

65.182.132.3 ns3.host4allhere.com

66.98.186.167 iehdg.info

66.118.136.67:
breathe-123.com   bxmort.com   ds838.com   join-123.com   ns1.join-123.com
ns2.join-123.com

66.168.163.247 ns5.smiley-fam.com

67.167.36.157 robinsml.com

67.186.166.108 ns2.smiley-fam.com

68.35.110.254 ns3.robinsml.com

68.88.219.218 re-finance.com

68.112.254.217:
smiley-fam.com   z984132.net

68.160.116.241 ns1.8sek.com

69.25.142.3:
kw839.net   l9482.com   l9482.net

69.55.109.39 thebesthgh.com

69.73.63.113 ns4.robinsml.com

69.203.113.220 ns4.smiley-fam.com

72.232.37.132 solidinvestment.com

82.36.169.14 ns5.robinsml.com

200.200.200.220 ns1.hostfor-web.com

200.200.200.222:
f1.whataf.com   f2.whataf.com   ns1.37-37.com   ns1.37-37-37.com
ns1.agnitech-service.com   ns1.alwaysbestpornsites.com   ns1.archaist.net
ns1.daniil-help.com   ns1.fengar.com   ns1.fleeing.net   ns1.foejesbd.com
ns1.hostinhost.com   ns1.megaoemsoftware.com   ns1.oemtime1.com
ns1.posthosting-area.com   ns1.presumer.net   ns1.realysitesdaily.com
ns1.segmental.net   ns1.ship-pay.com   ns1.tyrmu.com
ns1.vps-master-host.com   ns1.xhostback.com   ns1.yourdomainshere.com
ns2.37-37.com   ns2.37-37-37.com   ns2.agnitech-service.com
ns2.alwaysbestpornsites.com   ns2.archaist.net   ns2.daniil-help.com
ns2.fengar.com   ns2.fleeing.net   ns2.foejesbd.com   ns2.hostfor-web.com
ns2.hostinhost.com   ns2.megaoemsoftware.com   ns2.neosoftwareshop.com
ns2.oemtime1.com   ns2.posthosting-area.com   ns2.presumer.net
ns2.realysitesdaily.com   ns2.segmental.net   ns2.ship-pay.com
ns2.spx2006.com   ns2.transporteza.com   ns2.tyrmu.com   ns2.xhostback.com
ns2.yourdomainshere.com   ns3.37-37-37.com   ns3.pulle.net
ww.w-e-gold.com   www.aucgs.net   www1.aucgs.net   y1.bostonoem.com
y1.hundredoem.com   y1.novemberoemtime.com   y1.oemforyoutobuy.com
y1.onlythisoem.com   y2.blacksundownload.com   y2.bostonoem.com
y2.hundredoem.com   y2.losangelesoem.com   y2.novemberoemtime.com
y2.onlythisoem.com

202.65.99.20:
1728j.net   813248a.net   a167.net   a172.net   a182.net   a2732.net
a8122.net   b121.net   b261.net   b271.net   b281.net   b3272.net
b372.net   b8182.net   b9382.com   b9382.net   c176.net   c9012.net
d291.com   d291.net   dns1.ssmort.net   dns2.ssmort.net   dns3.ssmort.net
e162.net   e27831.com   e27831.net   e718.net   f12373.net   f19391.net
f721.net   g261.net   g271.net   g728.net   g732.net   g73232.net
h271.net   h2712.net   h272.net   h273.net   h2738.com   h2738.net
h278.net   h3712.net   h3721.net   h7236.com   h7236.net   h73128.net
h7323.net   ha172.net   ha712.net   i817.net   i8322.net   j1611.net
j2371.com   j2371.net   j271.net   j2712.com   j2712.net   j2812.net
j2871.net   j3182.net   j8212.net   j8219.net   ju372.net   k0293.com
k0293.net   k03921.com   k03921.net   k03928.com   k03928.net   k09218.net
k092812.com   k092812.net   k18271.net   k192.net   k1921.net   k1922.net
k218.net   k2819.net   k283.com   k283.net   k2832.net   k2893.net
k321912.net   k382.net   k3820.com   k3820.net   k3821.net   k38291.net
k3891.net   k39281.com   k39281.net   k4783.net   k48122.net   k483821.net
k812733.net   k8192.com   k8192.net   k82391.net   k82712.com   k82712.net
k9048.com   k9048.net   k9180.com   k9180.net   k91832.net   k9281.net
k92812.net   k9381.com   k9381.net   k9812.net   l1921.net   l281.net
l282.net   l2833.com   l2910.com   l2910.net   l2981.net   l3921.net
l7281.com   l7281.net   l9382.net   la192.net   lp2912.com   lp2912.net
m1821.net   m273.net   m2781.net   m281.net   m28172.net   m287.net
m2871.net   m291.net   m3128.net   m3218.net   m812371.net   m82912.com
m82912.net   m83721.com   m83721.net   m912.net   m9281.com   m9281.net
m9838.com   m9838.net   n0293.com   n0293.net   n03921.com   n03921.net
n1272.net   n1281.com   n1281.net   n271.net   n2718.net   n281.net
n289.net   n712.net   n721.net   ns01.ssmort.net   o12933.com   o12933.net
o291.net   o9012.com   o9012.net   o9233.net   o94182.com   o94182.net
p04831.com   p04831.net   p09281.com   p09281.net   p093821.com
p093821.net   p192.net   p28312.com   p28312.net   p291.net   p298.net
p32892.net   p472.com   p472.net   p4812.com   p4812.net   p63721.com
p63721.net   p7462.net   p8123.com   p8123.net   p9012.com   p9012.net
p9281.net   pa812.com   pa812.net   q2737.net   r261.net   r262.net
r3626.net   r3722.net   s0192.com   s0192.net   s281.net   ssmort.net
t172.net   t23718.net   t263.net   t272.net   t2761.net   t7212.net
u161.net   u8312.net   v121.net   v261.net   v271.net   v837.com
v837.net   w12838.net   w3627.net   w721.net   x172.net   x372.com
x372.net   x817.net   y271.net   y32171.com   y32171.net   y621.net
y712.net   y721.net   y7281.com   y7281.net   y732.net   y781.com
y781.net   y8271.com   y8271.net   y8491.com   y8491.net   ye3h.net
z1721.com   z1721.net   z812.net   z9102.com   z9102.net

202.157.177.77 ns1.piratesplayground.com

202.157.177.85:
ns1.999-999.biz   ns2.999-999.biz   ns2.piratesplayground.com

202.181.210.215:
ns01.host4allhere.com   ns01.loanszx.com

204.251.15.171:
freestyleaffiliates.com   ns0.freestyleaffiliates.com
ns1.freestyleaffiliates.com

204.251.15.194 m-tg-today.com

205.209.184.110:
ns1.hosting-for-jungle-ventures.com   ns2.hosting-for-jungle-ventures.com

210.51.170.66 ns.xinnetdns.com

210.51.170.67:
ns2.xinnet.cn   ns2.xinnetdns.com

210.51.171.209 ns.xinnet.cn

211.144.147.126:
ns1.fastturning.com   ns1.headin3ss.com   ns1.hitherehomie.com
ns1.whoarey0u.com   ns2.fastturning.com   ns2.whoarey0u.com
ns3.funniestime.com

211.144.147.128:
fortishfee.com   hydebig.com   kampup.com   kedhouse.com
ns1.ophorentsed.com   ns2.freeformsx.com   ns2.ophorentsed.com
ophorentsed.com   washyde.com   wyckbig.com   x82387.com

211.144.147.134:
ns1.hihellothere.com   ns2.h0lier.net

211.147.228.104 ns3.nscomur.com

211.147.228.105 ns2.6555.biz

216.52.184.240 hello-123.net

217.126.254.239 din3.com

218.201.43.139 ns1.hurry-4.com

218.201.43.147:
boringisntit.com   boringisntit.net   chancewasonce.com
chancewasonce.net   easymista.com   easymista.net   feeltherhythm.net
funniestime.com   funniestime.net   funnyhow.net   funnyisntit.com
funnyisntit.net   funnyprice.net   gofor1t.com   gofor1t.net   h7566.com
happyn3wy3ar.net   headin3ss.com   headin3ss.net   hitherehomie.com
interstingplace.com   interstingplace.net   l5875.com   l76288.net
ns1.boringisntit.com   ns1.boringisntit.net   ns1.chancewasonce.com
ns1.chancewasonce.net   ns1.easymista.com   ns1.easymista.net
ns1.feeltherhythm.net   ns1.funniestime.net   ns1.funnyisntit.net
ns1.funnyprice.net   ns1.gofor1t.net   ns1.headin3ss.net
ns1.interstingplace.com   ns1.interstingplace.net
ns1.peopleschoiceismort.net   ns1.sh0ots.net   ns1.simplyonce.com
ns1.simplyonce.net   ns1.timet0save.net   ns1.whoarey0u.net
ns2.boringisntit.com   ns2.boringisntit.net   ns2.chancewasonce.com
ns2.chancewasonce.net   ns2.easymista.com   ns2.easymista.net
ns2.feeltherhythm.net   ns2.funniestime.com   ns2.funniestime.net
ns2.funnyisntit.net   ns2.funnyprice.net   ns2.gofor1t.net
ns2.headin3ss.com   ns2.headin3ss.net   ns2.hitherehomie.com
ns2.interstingplace.com   ns2.interstingplace.net   ns2.l76288.net
ns2.peopleschoiceismort.net   ns2.simplyonce.com   ns2.simplyonce.net
ns2.timet0save.net   ns2.whoarey0u.net   ns3.headin3ss.net
peopleschoiceismort.net   sh0ots.net   simplyonce.com   simplyonce.net
timet0save.net   whoarey0u.com   whoarey0u.net

218.201.43.230:
ns2.funnyisntit.com   ns2.gofor1t.com   ns2.heyabrp.com

218.244.189.22:
ns3.1234-9876.com   ns3.donfiyaymay.com

219.138.7.185 ns2.guimar287.com

219.138.7.186 ns1.guimar287.com

219.254.32.117:
ns03.donfiyaymay.com   ns03.host4allhere.com   ns04.host4allhere.com
ns04.nowhostthis.com

220.248.157.27 ns1.jad3.com

221.4.152.203 ns2.fe11we11.com

221.5.2.44:
bbb.pajamakama.com   la.acrazebicm.com   teok.boultergdgc.com

221.5.2.130 ns1.helago.com

221.5.250.87:
ns1.4n0w.com   ns1.br1b3ry.com   ns1.brid3.com   ns1.brid3.net
ns1.help-is-near.com   ns1.pay-m3.com   ns2.4n0w.com   ns2.br1b3ry.com
...

read more »


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
SneakyP  
View profile  
 More options Jan 3 2006, 11:00 am
Newsgroups: news.admin.net-abuse.email
From: SneakyP <48umof...@sneakemail.com>
Date: Tue, 03 Jan 2006 16:00:29 -0000
Local: Tues, Jan 3 2006 11:00 am
Subject: Re: Mortgage and fake diploma spammer / investment scammer / money launderer / credit card thief [LONG POST]
"Spam Reporting" <FROM:@hillscapital.com> wrote in
news:f1xuf.61039$tV6.34779@newssvr27.news.prodigy.net:

> They continue to register domains at a high rate, and spam at an
> extremely high rate... the sources I'm checking show them accounting
> for ~17% of all reported spam. With as large a user base as these
> reporting entities have, that should mean that Polyakov is now
> accounting for ~17% of all spam worldwide. He's obviously trying to
> listwash people reporting to NANAS... he's not showing up there much
> at all.

I suspect that's because it is so voluminous and easy to block that it is
too boring to show.   I get it all the time.  Since it doesn't get back
to any US based spamhaus, I dont bother with it.

--
---
SneakyP
 not an admin, security, programmer,, etc... just one of a million
complainants.  I guess I'm one in a million! ;)


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Vernon Schryver  
View profile  
 More options Jan 3 2006, 11:47 am
Newsgroups: news.admin.net-abuse.email
From: v...@calcite.rhyolite.com (Vernon Schryver)
Date: Tue, 3 Jan 2006 09:47:33 -0700 (MST)
Local: Tues, Jan 3 2006 11:47 am
Subject: Re: Mortgage and fake diploma spammer / investment scammer / money launderer / credit card thief [LONG POST]
In article <Xns974065C69ADD948umofa02sneakema...@127.0.0.1>,

SneakyP  <48umof...@sneakemail.com> wrote:
>> accounting for ~17% of all spam worldwide. He's obviously trying to
>> listwash people reporting to NANAS... he's not showing up there much
>> at all.

>I suspect that's because it is so voluminous and easy to block that it is
>too boring to show.   I get it all the time.  Since it doesn't get back
>to any US based spamhaus, I dont bother with it.

It's a sad commentary on too many NANAE contributors that they do not
apply similar adult and rational reasoning to the spam and other games
of some (other) NANAE trolls.   For example, why do a few missives per
month directed at WHOIS contact addresses merit comment?

Vernon Schryver    v...@rhyolite.com


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Discussion subject changed to "Mortgage phisher and fake diploma spammer [LONG POST]" by Andreas Kohlbach
Andreas Kohlbach  
View profile  
 More options Jan 3 2006, 4:35 pm
Newsgroups: news.admin.net-abuse.email
From: "Andreas Kohlbach" <ank...@email.com>
Date: 3 Jan 2006 13:35:29 -0800
Local: Tues, Jan 3 2006 4:35 pm
Subject: Re: Mortgage phisher and fake diploma spammer [LONG POST]
It seems the spammer's tool is broken or exoired as I often get spam
with "URLs" like http://harvest<excommunicate>implicit.p8123.com.

Though invalid I remove the brackets stuff and report on Spamcop and
also bomb them with fake data.

It seems that hkabc.net is often involved. He offers a kind or
dedicated server, so the spammer might have tons of domains there.

He runs an "Apache Apache/2.0.55 (Unix) PHP/4.4.1". In case anybody
knows of vulns there, feel free.

You can see at <http://www.hkabc.net/eng/main_datahouse.htm> what it
costs the spammer, but I cannot see any traffic limit.

I guess if there is a traffic limit it will sum up from all domains he
uses.

If you want to run a "performance test" on that server you might want
to get the tool "siege". Just in case...


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Rev. Beergoggles  
View profile  
 More options Jan 3 2006, 6:08 pm
Newsgroups: news.admin.net-abuse.email
From: "Rev. Beergoggles" <post.repl...@invalid.address>
Date: Tue, 3 Jan 2006 17:08:55 -0600
Local: Tues, Jan 3 2006 6:08 pm
Subject: Re: Mortgage phisher and fake diploma spammer [LONG POST]
Andreas Kohlbach did pass the time by typing:

> It seems the spammer's tool is broken or exoired as I often get spam
> with "URLs" like http://harvest<excommunicate>implicit.p8123.com.

"semi broken"  IE will still use them but Firefox does the correct
thing.  SC knows about the situation and I hoped it would have been
fixed by now.

> You can see at <http://www.hkabc.net/eng/main_datahouse.htm> what it
> costs the spammer, but I cannot see any traffic limit.

The limit is when spammys stolen credit card numbers run out. :/

> If you want to run a "performance test" on that server you might want
> to get the tool "siege". Just in case...

wget is also a good tool for archiving the spammers sites.

FYI:

k9048.com
p8123.com
p63721.net
p8123.net
n03921.com
pa812.com
k4821.net

--
rbg


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Andreas Kohlbach  
View profile  
 More options Jan 4 2006, 9:59 am
Newsgroups: news.admin.net-abuse.email
From: "Andreas Kohlbach" <ank...@email.com>
Date: 4 Jan 2006 06:59:00 -0800
Subject: Re: Mortgage phisher and fake diploma spammer [LONG POST]

Rev. Beergoggles wrote:
> Andreas Kohlbach did pass the time by typing:
> > It seems the spammer's tool is broken or exoired as I often get spam
> > with "URLs" like http://harvest<excommunicate>implicit.p8123.com.

> "semi broken"  IE will still use them but Firefox does the correct
> thing.  SC knows about the situation and I hoped it would have been
> fixed by now.

Then it could be done by purpose. May be (and they are probably right)
they think users with other mailreaders and so browsers would complain
more than IE/OE users.

I remember spam which did a JScript in the spam. Only IE would decode
this and display the spam, other browsers would just show an empty
page.

> > You can see at <http://www.hkabc.net/eng/main_datahouse.htm> what it
> > costs the spammer, but I cannot see any traffic limit.

> The limit is when spammys stolen credit card numbers run out. :/

Hopefully the people who realise their card data were stolen withdraw
the amount the provider would charge them.

> > If you want to run a "performance test" on that server you might want
> > to get the tool "siege". Just in case...

> wget is also a good tool for archiving the spammers sites.

> FYI:

> k9048.com
> p8123.com
> p63721.net
> p8123.net
> n03921.com
> pa812.com
> k4821.net

Yeah, you (probably know :-) can put all URLs in a text file and tell
wget to download them again and again without locally saving the
content.

Also Windows user can help. There exists a wget.exe which works withou
the "Linux environment" cygwin. <http://users.ugent.be/~bpuype/wget/>

After you put all URLs you can get your hand on (see other articles) to
a text file (say "loan.txt") you do (using the CMD)

wget -i loan.exe -O /dev/null

Well not /dev/null on Windows. No idea where this has its bit bucket.
May be you can also put it in a loop there to restart downloading after
all URLs are processed with CMD.

For Linux users it's

while (true);do wget -i loan.txt -O /dev/null;done

Then go on vacation for some weeks. :-)

Though I think in addition to that filling out the form has even more
impact of the spammer.

Some more URLs (at telemar.br) from today

mysx.cscourier.be:3595
alzt.ctive.be:3636
sfm.ct-reserch.be:3639

--
Andreas


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Messages 151 - 175 of 409 < Older  Newer >
« Back to Discussions « Newer topic     Older topic »

Create a group - Google Groups - Google Home - Terms of Service - Privacy Policy
©2009 Google