RSS RSS Subscribe

Posts tagged: spammer

Spam with a bonus — ‘Oops’

By , December 10, 2009 08:12
Hot:

I received a rather interesting spam the other day and it would seem to have included some well private details.  It looks like this email contains login information for various mail systems but I honestly did not follow up with it.  I figured it may be of interest to the owners of these sites so I’m posting it here rather than attempt to start tracking abuse emails for various domains.

Continue reading 'Spam with a bonus — ‘Oops’'»

Get you Anti Free Software Here!!!

comments Comments Off
By , October 20, 2008 16:17
Hot:

I was laughing so hard this morning. Who would have thought a review of the daily spam deluge could create such comedy. Don’t tell the spammers though, they’ll want more money. Headline in spam "Anti Free Protection Spyware". Get your’s here!! (link not included). I guess honesty in advertising is ok. So check your spam for your link to get ‘Anti Free’ Software :)

So does this mean I have to pay for it?

So many jokes, so little time to add them

Mr.Gay Spammer on site

comments Comments Off
By , October 23, 2007 12:09
Hot:

Well it appears that ‘supercatalogo.info’ is a HUGE source of spam and malware. I have identified the IP as

89.111.180.225

And the following whois details:

10/23/07 10:15:20 whois 89.111.180.225@whois.geektools.com

whois -h whois.geektools.com 89.111.180.225 …

GeekTools Whois Proxy v5.0.4 Ready.

Final results obtained from whois.ripe.net.

Results:

% This is the RIPE Whois query server #3.

% The objects are in RPSL format.

%

% Rights restricted by copyright.

% See http://www.ripe.net/db/copyright.html

% Note: This output has been filtered.

% To receive output for a database update, use the "-B" flag.

% Information related to ’89.111.176.0 – 89.111.191.255′

inetnum: 89.111.176.0 – 89.111.191.255

netname: CENTROHOST-NET

descr: JSC Centrohost

country: RU

org: ORG-JC13-RIPE

admin-c: IA327-RIPE

tech-c: IA327-RIPE

status: ASSIGNED PA

mnt-by: PAN1-RIPE-MNT

mnt-lower: PAN1-RIPE-MNT

mnt-routes: PAN1-RIPE-MNT

mnt-domains: IA327-RIPE-MNT

source: RIPE # Filtered

organisation: ORG-JC13-RIPE

org-name: JSC Centrohost

org-type: OTHER

descr: JSC Centrohost

address: 78, Profsojuznaya str.,

address: Moscow, Russia, 117393

phone: +7 495 3630309

phone: +7 495 3630318

admin-c: IA327-RIPE

tech-c: IA327-RIPE

mnt-ref: PAN1-RIPE-MNT

abuse-mailbox: abuse@hc.ru

mnt-by: PAN1-RIPE-MNT

source: RIPE # Filtered

person: Ivan Albetkov

address: Hosting-Center LTD

address: 22, Litovsky bulvar

address: Moscow, Russia, 117588

phone: +7 495 5445566

remarks: **************************************************

remarks: Please send abuse and spam reports to abuse@hc.ru

remarks: **************************************************

nic-hdl: IA327-RIPE

mnt-by: IA327-RIPE-MNT

source: RIPE # Filtered

% Information related to ’89.111.176.0/20AS41126′

route: 89.111.176.0/20

descr: JSC Centrohost route

origin: AS41126

mnt-by: PAN1-RIPE-MNT

source: RIPE # Filtered

So Mr. Gay can go find another rock to crawl under.

Oh, if your looking for details on supercatalogo.info Click the read more to view.

Domain ID:D15402764-LRMS

Domain Name:SUPERCATALOGO.INFO

Created On:22-Nov-2006 14:39:27 UTC

Last Updated On:21-Jan-2007 20:32:36 UTC

Expiration Date:22-Nov-2007 14:39:27 UTC

Sponsoring Registrar:EstDomains, Inc. (R295-LRMS)

Status:OK

Registrant ID:DI_4743150

Registrant Name:Isaias Stefanski

Registrant Organization:Isaias Stefanski

Registrant Street1:Devon Rd 67 26

Registrant Street2:

Registrant Street3:

Registrant City:BATON ROUGE

Registrant State/Province:Louisiana

Registrant Postal Code:70814

Registrant Country:US

Registrant Phone:+1.5043223563

Registrant Phone Ext.:

Registrant FAX:

Registrant FAX Ext.:

Registrant SuperCatalogo.info

Admin ID:DI_4743150

Admin Name:Isaias Stefanski

Admin Organization:Isaias Stefanski

Admin Street1:Devon Rd 67 26

Admin Street2:

Admin Street3:

Admin City:BATON ROUGE

Admin State/Province:Louisiana

Admin Postal Code:70814

Admin Country:US

Admin Phone:+1.5043223563

Admin Phone Ext.:

Admin FAX:

Admin FAX Ext.:

Admin SuperCatalogo.info

Billing ID:DI_4743150

Billing
Name:Isaias Stefanski

Billing Organization:Isaias Stefanski

Billing Street1:Devon Rd 67 26

Billing Street2:

Billing Street3:

Billing City:BATON ROUGE

Billing State/Province:Louisiana

Billing Postal Code:70814

Billing Country:US

Billing Phone:+1.5043223563

Billing Phone Ext.:

Billing FAX:

Billing FAX Ext.:

Billing SuperCatalogo.info

Tech ID:DI_4743150

Tech Name:Isaias Stefanski

Tech Organization:Isaias Stefanski

Tech Street1:Devon Rd 67 26

Tech Street2:

Tech Street3:

Tech City:BATON ROUGE

Tech State/Province:Louisiana

Tech Postal Code:70814

Tech Country:US

Tech Phone:+1.5043223563

Tech Phone Ext.:

Tech FAX:

Tech FAX Ext.:

Tech SuperCatalogo.info

Name Server:NS1.THEHOSTDIRECT.INFO

Name Server:NS2.THEHOSTDIRECT.INFO

Blog Spammers – NetCatHosting #1 Spammer Sept/07

comments Comments Off
By , October 17, 2007 13:40
Hot:

If you have a web site, chances are you deal with spam in some way. It’s become reality in the last couple years and dealing with it can be either finicky and time consuming or you spend very little time with it, thanks to effective solutions.

Here we get lots of spam even though the traffic here doesn’t warrant it. 90% of the visitors here are bots and only about 2% of those are spammers.

We have a great system for dealing with spam and so far we’ve had great success with it. No spam has been posted on this site that had to be manually removed. However we get an endless number of attempts.

One IP 195.225.177.190 has been particularly mindless in their attempt to spam our site got up to 10 to 15 attempts per day. During the latter part of September 2007, this ONE BOT generated over 100 attempts.

This is the detail of the identified spammer.

10/17/07 11:25:56 whois 195.225.177.190@whois.geektools.com

whois -h whois.geektools.com 195.225.177.190 …

GeekTools Whois Proxy v5.0.4 Ready.

Final results obtained from whois.ripe.net.

Results:

% This is the RIPE Whois query server #1.

% The objects are in RPSL format.

%

% Rights restricted by copyright.

%
See http://www.ripe.net/db/copyright.html

% Note: This output has been filtered.

% To receive output for a database update, use the "-B" flag.

% Information related to ’195.225.176.0 – 195.225.179.255′

inetnum: 195.225.176.0 – 195.225.179.255

netname: NETCATHOST

descr: NetcatHosting

country: PA

admin-c: VR1273-RIPE

tech-c: VR1273-RIPE

status: ASSIGNED PI

mnt-by: RIPE-NCC-HM-PI-MNT

mnt-lower: RIPE-NCC-HM-PI-MNT

mnt-by: NETCATHOST-MNT

mnt-routes: NETCATHOST-MNT

mnt-routes: WZNET-MNT

source: RIPE # Filtered

remarks: ***************************************

remarks: * Abuse contacts: abuse@netcathost.com *

remarks: ***************************************

person: Vladislav Radchek

address: IBC Tower Floor 9 PO Box 901-2389

address: Manuel Espinosa Batista Avenue

phone: +372 7121250

nic-hdl: VR1273-RIPE

source: RIPE # Filtered

% Information related to ’195.225.176.0/22AS31159′

route: 195.225.176.0/22

descr: NETCATHOST (full block)

mnt-routes: WZNET-MNT

mnt-routes: NETCATHOST-MNT

origin: AS31159

mnt-by: NETCATHOST-MNT

remarks: ****************************************

remarks: * Abuse contacts: abuse@netcathost.com *

remarks: ****************************************

source: RIPE # Filtered

% Information related to ’195.225.177.190/32AS31159′

route: 195.225.177.190/32

descr: Mark Stosberg

origin: AS31159

mnt-by: NETCATHOST-MNT

source: RIPE # Filtered

remarks: *******************************

* Mark Stosberg *

* +1 (202) 657-5440 *

* US, 47374, Indiana *

* Richmond, 914 E Main St *

****** Send abuse to: *********

* abuse@myfreepages.org *

*******************************

Results brought to you by the GeekTools WHOIS Proxy

Server results may be copyrighted and are used with permission.’,'This IP is part of the NETCATHOST.COM Domain and is a Web hosting provider. Two IP’s in this block were attributed in the spamming the one noted above and this one 195.225.176.177. This is a RIPE address space from the looks of it being used by an ISP in Europe and further used by this American either intentionally or otherwise. Given it’s a web hosting account I’d say the server has been compromised.

It was interesting that while these bots were spamming me, I received no other spam attempts. [well there were two] Once I blocked this IP block from accessing my site, the other bots started up again. Most curious.

I still average about 3 spam attempts per day and depending on the success of this article I may post further major spammers in the coming months.

Theme by Themocracy