CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 937
Comments: 25
block bottom
spacer spacer
image I got mortgage spam from Purdue University! image
CastleCops
Who would have thought it? Purdue University allowed a spammer to get thru their email system. Wow...

Return-Path: <ILyles_cEd@purdue.edu>
Received: from computercops.biz (pvil-a-178.resnet.purdue.edu [128.211.252.178])
by bugsbunny.castlecops.com (8.13.4/8.13.4) with SMTP id jBSLCvJJ023405
for <paul@computercops.biz>; Wed, 28 Dec 2005 16:12:58 -0500
Received: from pax.seed.org.au (localhost [sinew.net])
by pax.betony.org.au (8.12.8/8.12.5) with ESMTP id h4GBtot3031884
for <hereunder@mincemeat.psychometry.org.au>; Wed, 28 Dec 2005 21:12:51 +0300
Message-ID: <20791210624117.GA13691ILyles_cEd@purdue.edu>
User-Agent: Mutt/1.5.3i
Date: Wed, 28 Dec 2005 21:08:06 +0000
From: "Ed Lyles" <ILyles_cEd@purdue.edu>
To: paul@computercops.biz
Subject: Hey
X-Mailer: MIME-tools 5.41 (Entity 5.404)

A lookup on IP 128.211.252.178 shows the ownership information back to Purdue:


OrgName: Purdue University
OrgID: PURDUE
Address: Information Technology
Address: 501 Harrison Street
City: West Lafayette
StateProv: IN
PostalCode: 47907-2025
Country: US

NetRange: 128.211.0.0 - 128.211.255.255
CIDR: 128.211.0.0/16
NetName: PURDUE-CS-CYP
NetHandle: NET-128-211-0-0-1
Parent: NET-128-0-0-0-0
NetType: Direct Assignment
NameServer: PENDRAGON.CS.PURDUE.EDU
NameServer: MOE.RICE.EDU
NameServer: NS.PURDUE.EDU
NameServer: HARBOR.ECN.PURDUE.EDU
Comment: All SPAM and Abuse complaints should be sent to abuse@purdue.edu
RegDate:
Updated: 2003-01-15

Initial shock aside, the email follows below:


Dear Home Owner,

Your credit doesn't matter to us! If you OWN real estate
and want IMMEDIATE cash to spend ANY way you like, or simply wish
to LOWER your monthly payments by a third or more, here are the deals
we have TODAY (hurry, these offers will expire TONIGHT) :

$4890,000.00 at a 3.797,% fixed-rate
$3096,000.00 at a 3.25,% variable-rate
$425,000.00 at a 3.84,% interest-only
$254,000.00 at a 3.18,% fixed-rate
$1955,000.00 at a 3.931,% variable-rate

Hurry, when these deals are gone, they are gone!
Simply fill out this one-minute form...

Don't worry about approval, your credit will not disqualify you!

http://www.l2910.net

Sincerely,
Maureen Muniz
Approval Manager




time In the meanwhileyou must try to look at it from a new point of view and not as a schoolboy
Ed I tell you what my floppy said my aunt one morning in the
devoted For a year or more I had immunoelectrophoresis to find a satisfactory answer to her often
Its a mercy that poor baptist baby of a mother of yours didnt live said my aunt
himself to looking watchfully at her for her suggestions and rattling his money
looking at me approvingly or shed have been so vain of her boy by this time that her soft
not make a mistake in our decision if we can help it I think we had better take a little breathing
as he can look at me out of his two eyes Is he indeed said Mr Lyles
If you follow the link to http://www.l2910.net you'll be asked all sorts of personal questions. The domain itself has a reverse pointer to: 099020.static.hhkabc.net. And the l2910.net domain (IP 202.65.99.20) is email blacklisted under SBL:

http://www.spamhaus.org/SBL/sbl.lasso?query=SBL36175

The SBL advisory displays:

Ref: SBL36175

202.65.99.20/32 is listed on the Spamhaus Block List (SBL)

23-Dec-2005 02:30 GMT | SR09

q2737.net

x.q2737.net. IN A 202.65.99.20
q2737.net. IN NS ns2.xinnet.cn.
q2737.net. IN NS ns2.xinnetdns.com.
ns2.xinnet.cn. IN A 210.51.170.67
ns2.xinnetdns.com. IN A 202.106.124.194

...

[whois.paycenter.com.cn]
Domain Name:q2737.net

Registrant:
hezitong
No: 2 TaiYuan
200233

Administrative Contact:
Guang Zhou
Guang Zhou
No: 2 TaiYuan
Tai Yuan Shanghai 200233
China
tel: 86 021 55534555
fax: 86 021 55534555
test@55534555.net

Technical Contact:
Guang Zhou
Guang Zhou
No: 2 TaiYuan
Tai Yuan Shanghai 200233
China
tel: 86 021 55534555
fax: 86 021 55534555
test@55534555.net

Billing Contact:
Guang Zhou
Guang Zhou
No: 2 TaiYuan
Tai Yuan Shanghai 200233
China
tel: 86 021 55534555
fax: 86 021 55534555
test@55534555.net

Registration Date: 2005-12-11
Update Date: 2005-12-11
Expiration Date: 2006-12-11

Primary DNS: ns2.xinnetdns.com 202.106.124.194
Secondary DNS: ns2.xinnet.cn 210.51.170.67
Posted on Wednesday, 28 December 2005 @ 16:42:33 UTC by Paul (1281 reads)
[ Trackback ]
image

"I got mortgage spam from Purdue University!" | Login/Create an Account | 0 comments
Threshold
The comments are owned by the poster. We aren't responsible for their content.

No Comments Allowed for Anonymous, please register
 
Login
spacer
Nickname

Password

Security Code: Type Security Code: Usage signifies AUP acceptance
· New User? · Click here to create a registered account.
block bottom
Related Links
spacer
· del.icio.us!
· digg it!
· reddit!
· TrackBack (0)
· HotScripts
· W3 Consortium
· Spam Cop
· CastleCops
· More about CastleCops
· News by Paul


Most read story about CastleCops:
Join Computer Cops Club to Find A Cure!

block bottom
Article Rating
spacer
Average Score: 0
Votes: 0

Please take a second and vote for this article:

Bad
Regular
Good
Very Good
Excellent


block bottom
Options
spacer

Printer Friendly Page  Printer Friendly Page

block bottom
spacer spacer