CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 934
Comments: 25
block bottom
spacer spacer

Add / Change Registrar
Goto page Previous  1, 2, 3, 4, 5 ... 7, 8, 9, 11, 12, 13  Next
 
Post new topic   Reply to topic       All -> FavForums -> Complainterator [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
ahoier

SIRT Handler


Joined: Jan 14, 2006
Posts: 1020
Location: USA

PostPosted: Thu Jun 12, 2008 1:21 am    Post subject:
Reply with quote

I've seen mixed responses from Tucows and well, DNS.COM.CN - largely because DNS.COM.CN has URIBL filtering on their mailbox.

***PASTE_INTO_http://reports.internic.net/cgi/registrars/problem-report.cgi could be included alongside those registrars.

Perhaps the InterNIC notice would land in their inbox, paste their filtering.

Back to top
View users profile Send private message Visit posters website AIM Address Yahoo Messenger MSN Messenger
Krivoi

Sergeant
Sergeant


Joined: Mar 03, 2008
Posts: 83
Location: Uk

PostPosted: Thu Jun 12, 2008 10:10 pm    Post subject:
Reply with quote

Hi everyone

Assistance required! Could someone please run Complainterator on this one and send the report(s) and add any new registrars in this thread as appropriate. I realise the domain is the bit after the first dot, ie the "f-word" Very Happy , but it's throwing up two new registrars and one looks like it's their own name servers. I'm a bit out of my depth & I don't want to get it wrong so any comments welcome. Remove any spaces and replace DOT with a "." character:

h tt p : // evaluation DOT fmcaction DOT org/r DOT html

Thanks

K

Back to top
View users profile Send private message
AlphaCentauri

SIRT Handler
Premium Member

Joined: Nov 20, 2003
Posts: 2617

Premium

PostPosted: Thu Jun 12, 2008 10:47 pm    Post subject:
Reply with quote

Good call -- hostingfrance.com doesn't look like a spammer domain! You can see from the whois that it was registered 5 years ago, so although occasionally a spammer gets a name that sounds pretty official, it usually won't be around that long.

GandiSAS isn't new, they just act on spam so fast that any spammer with the sense he was born with will avoid them. It's already in the Complainterator contacts.txt file, so I don't know why the program prompts you for another address. You can just copy it out of the contacts file and paste it in when prompted. If you get any registrars that aren't in that file, you can find accredited registrars at www.icann.org/registrars/accreditation-qualified-list.html . For unaccredited registrars, you have to go to each registrar's website and poke around to find a contact address.

In this case, fmcaction.org appears to be a legit site that got hacked. The file "r.html" has already been removed. evaluation.fmcaction.org is still there and is a login page, but I'm guessing that since the owner took down "r.html," he's removed the unauthorized user, too. So unless you find any other files on that domain that look squirrelly, the site owner has already taken care of the problem.

Back to top
View users profile Send private message
Krivoi

Sergeant
Sergeant


Joined: Mar 03, 2008
Posts: 83
Location: Uk

PostPosted: Fri Jun 13, 2008 7:40 pm    Post subject:
Reply with quote

Thanks, AlphaCentauri - very helpful. Yes, I could see it looked different from the usual Xin Net style emails I see so glad I asked.

Back to top
View users profile Send private message
efa

Sergeant
Sergeant


Joined: Aug 31, 2007
Posts: 111
Location: Italy

PostPosted: Fri Jun 13, 2008 10:22 pm    Post subject:
Reply with quote

EURODNS S.A ~ icann@eurodns.com
VITALWERKS INTERNET SOLUTIONS LLC DBA NO-IP ~ domains@no-ip.com
Vitalwerks Internet Solutions, LLC DBA No-IP ~ domains@no-ip.com
NAME.COM LLC ~ support@name.com
Network Solutions LLC (R63-LROR) ~ abuse@networksolutions.com
XIAMEN CHINASOURCE INTERNET SERVICE CO., LTD. ~ jeff@114.com.cn
LiveDns Ltd ~ support@livedns.co.il
NWEB s.r.l. ~ info@nweb.it
INIT s.r.l. ~ info@init.it

Back to top
View users profile Send private message
tembow

Blue Angel
Premium Member

Joined: Oct 10, 2005
Posts: 2881

Blue Security Premium

PostPosted: Sat Jun 14, 2008 8:21 am    Post subject:
Reply with quote

efa
If you find a registrar who is not in the existing list, please add it in this forum topic.

Put in the web site name that used the registrar, and optionally the registrar and contact address.

For updates to the Complainterator contact list:

Spammed domain = ____________________
Registrar = ____________________________
Contact = _________[at]______._____

Of these 3 items, the first is mandatory, the 2nd and 3rd are optional.

E-mail via the complainterator.com contacts page, or append to this forum

If you find that a complaint is rejected because an existing email address is no longer valid, please provide the mail bounce message here, too.

Back to top
View users profile Send private message Visit posters website AIM Address
efa

Sergeant
Sergeant


Joined: Aug 31, 2007
Posts: 111
Location: Italy

PostPosted: Sun Jun 15, 2008 1:19 am    Post subject:
Reply with quote

Apart the capital version of existing registrar, I dont remember what are the domain implicated.... but I can search in the sended complaint.
Tomorrow

Back to top
View users profile Send private message
ahoier

SIRT Handler


Joined: Jan 14, 2006
Posts: 1020
Location: USA

PostPosted: Sun Jun 22, 2008 2:36 am    Post subject:
Reply with quote

Is this the right thread to report name servers that shouldn't be requested to be shut-down (I.e.: the old GANDI incident lol)?

Code:
Subject: Removal request: nease.net
NETWORK SOLUTIONS, LLC.

This is a request for you to remove the domain nease.net
and to remove its name server Address record ns.nease.net [202.106.185.75], and ns3.nease.net [220.181.28.3]


Psst, I didn't send it Smile

Updated in next release

Back to top
View users profile Send private message Visit posters website AIM Address Yahoo Messenger MSN Messenger
trobbins

SIRT Handler
Premium Member

Joined: Feb 19, 2007
Posts: 1166
Location: USA
Premium

PostPosted: Mon Jun 23, 2008 6:36 pm    Post subject:
Reply with quote

Dynamic Dolphin
Failure:
was not delivered to: <info@dynamicdolphin.com>
because: Error transferring to 3744772.mx.DYNAMICDOLPHIN.COM; SMTP Protocol Returned a Permanent Error 550 5.1.1 <info@dynamicdolphin.com>: Recipient address rejected: User unknown in relay recipient table

Back to top
View users profile Send private message
jimVO

Sergeant
Sergeant
Premium Member

Joined: Mar 17, 2008
Posts: 139
Location: USA
Premium

PostPosted: Tue Jun 24, 2008 3:55 am    Post subject:
Reply with quote

I think Dynamic Dolphin has been "tweaking" their mail servers all day today. They are using surbl filtering and have been rejecting more and more reports all day. I even obfuscated all references to offending sites and got rejected. I have taken to posting spam complaints to their web form at:

http://dynamicdolphin.com/reports.php?action=report_spam

Don't know if that will do any good either.

Also all my complaints to cnadm@hichina.com have been getting rejected in the same way and I don't have an alternative means of filing complaints for them.

Back to top
View users profile Send private message
tembow

Blue Angel
Premium Member

Joined: Oct 10, 2005
Posts: 2881

Blue Security Premium

PostPosted: Tue Jun 24, 2008 5:21 am    Post subject:
Reply with quote

ICANN has:
Dynamic Dolphin, Inc. (United States)
http://www.dynamicdolphin.com
Tel: 1-720-872-3477
Email: info ~at~ dynamicdolphin.com


MX record has
dynamicdolphin.com. 38400 IN MX 100 3744772.mx.dynamicdolphin.com.

Address of mail servers shows as
3744772.mx.dynamicdolphin.com. 14400 IN A 209.62.87.245
3744772.mx.dynamicdolphin.com. 14400 IN A 67.15.238.68


Web site contact us page has
Name: Dynamic Dolphin
Company: Dynamic Dolphin, Inc
Address: 5023 W 120th Ave #233, ,
City: Broomfield
State: Colorado
Country: US
Zip: 80020
Telephone Number : 1-7208723477
Fax Number : 1-3034961710
Email Address : admin ~at~ dynamicdolphin.com

Technical Support Telephone Number : 1-7208723477
Email Address : techsupport ~at~ dynamicdolphin.com

Back to top
View users profile Send private message Visit posters website AIM Address
ahoier

SIRT Handler


Joined: Jan 14, 2006
Posts: 1020
Location: USA

PostPosted: Tue Jun 24, 2008 1:54 pm    Post subject:
Reply with quote

sounds good Smile Let's roll them all into our little party ^^

Back to top
View users profile Send private message Visit posters website AIM Address Yahoo Messenger MSN Messenger
Jim_P

Sergeant
Sergeant
Premium Member

Joined: Apr 19, 2004
Posts: 128

Premium

PostPosted: Tue Jun 24, 2008 3:16 pm    Post subject:
Reply with quote

ahoier wrote:
sounds good Smile Let's roll them all into our little party ^^


A bit of digging into Dynamic Dolphin revealed that it is owned by a company called CPA Empire, which in turn is owned by Media Breakaway LLC. Its CEO is Scott Richter, a notorious, self-avowed spammer who claims to have quit the business.

The above from a Knujon memo.

With this connection I say we have our work cut out for us.

Back to top
View users profile Send private message
ahoier

SIRT Handler


Joined: Jan 14, 2006
Posts: 1020
Location: USA

PostPosted: Tue Jun 24, 2008 4:05 pm    Post subject:
Reply with quote

_that's_ where I read it - the KnujOn memo....lately, all my sources kinda slide and combine into each other, forgetting where I read what.

Seems Dynamic Dolphin is appears a lot in my sister's mailbox.....she's one to "punch the monkey" and fall for other such banner ads...and submit her address to slews of "opt-in" services.

A lot of the spam domain she receives for free handbags, samples, magazines, surveys, etc. "give aways" (if it can be considered that, since she likely gave them her address...somewhere along the line) is registered by Dynamic Dolphin.

As if they are trying to run a valid business, but I wouldn't doubt it if they sell their lists to Herbal King/VPXL/Canadian Pharmacy and other associated bad-apples.

Back to top
View users profile Send private message Visit posters website AIM Address Yahoo Messenger MSN Messenger
AlphaCentauri

SIRT Handler
Premium Member

Joined: Nov 20, 2003
Posts: 2617

Premium

PostPosted: Tue Jun 24, 2008 5:03 pm    Post subject:
Reply with quote

Jim_P wrote:
Its CEO is Scott Richter, a notorious, self-avowed spammer who claims to have quit the business.


That explains why I had never heard of this "top ten" spammer Dolphin.

I have a filter in complainterator that looks for Scott Richter's IP in the headers. It hadn't registered anything in a very long time. But I was checking someone else's email from my computer, and that filter got some hits. While I haven't unsubscribed from anything, I do send all the semi-compliant looking spam to spamcop. So apparently they did get the message and took me off their list.

As far as selling their lists, as far as I know that's legal, even though it isn't legal to harvest them. I can't imagine spammers giving up a source of income. Nor can I imagine them scrubbing their lists first, since they are sold on the basis of the number of addresses on the list, not the number who aren't anti's.

Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Complainterator All times are GMT
Goto page Previous  1, 2, 3, 4, 5 ... 7, 8, 9, 11, 12, 13  Next
Page 8 of 13

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer