CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 940
Comments: 25
block bottom
spacer spacer

Add / Change Registrar
Goto page Previous  1, 2, 3, 4, 5 ... 8, 9, 10, 11, 12, 13  Next
 
Post new topic   Reply to topic       All -> FavForums -> Complainterator [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
Jim_P

Sergeant
Sergeant
Premium Member

Joined: Apr 19, 2004
Posts: 128

Premium

PostPosted: Tue Jun 24, 2008 10:33 pm    Post subject:
Reply with quote

I just heard something from DynamicDolphin.
I have not check this out.

Jim, we are currently processing several complaints on one of our domain owners. We have already disabled this domain and the name server info you see below has been used to disable it.


Regards,

Dynamic Dolphin Admin

From: Jim [mailto:j.chelmsford@gmail.com]
Sent: Tuesday, June 24, 2008 2:14 PM
To: Jenny Frederick; techsupport@dynamicdolphin.com; abuse@opticaljungle.com
Subject: Removal request: dynamicdeleted.info



Dynamic Dolphin Inc (R334-LRMS)
Dear Registrar

This is a request for you to remove the domain dynamicdeleted.info
and to remove its name server Address record ns2.dynamicdeleted.info [69.6.21.21], and ns1.dynamicdeleted.info [69.6.21.21]

EVIDENCE

>From this link, you can see that it is used as a name server for a spammed site
> http://www.dnsstuff.com/tools/traversal.ch?domain=tatinasur.com&type=a&token=complainterator&src=complainterator

>From this link, you can see that your company is the name server's registrar
> http://www.dnsstuff.com/tools/whois.ch?ip=dynamicdeleted.info&src=complainterator&token=complainterator



ACTION

Setting the status to client hold is not enough to suspend it.
Use the removal instructions for name servers in this link
> http://www.spamtrackers.eu/wiki/index.php?title=Registrar_Advice
> http://www.spamtrackers.hk/wiki/index.php?title=Registrar_Advice (for China)

Once removed in that manner, this Complaint Generator tool will generate no more requests on this domain.

Thank you for your efforts to reduce spam and to keep criminals from abusing your terms of service.

-----
This message was generated by the Complainterator - www.complainterator.com
Wrong address? Send address changes to info@complainterator.com
-----

Back to top
View users profile Send private message
Jim_P

Sergeant
Sergeant
Premium Member

Joined: Apr 19, 2004
Posts: 128

Premium

PostPosted: Tue Jun 24, 2008 11:58 pm    Post subject:
Reply with quote

I checked it out and it looks like only the NS was changed.

Back to top
View users profile Send private message
pwillener

SRT Trainee
SRT Trainee
Premium Member

Joined: Apr 17, 2006
Posts: 1725
Location: Japan
Premium

PostPosted: Wed Jun 25, 2008 2:48 am    Post subject:
Reply with quote

I've had just a few reports to this registrar over the past few days (tinalyme.com, hitoferaf.com, mububesas.com, bosanite.com, tidide.com, ganisape.com, sidotapy.com), but so far none of them has been touched in any way. P.S. all using new XIN NET domain servers, registered on 2008-06-06.

Back to top
View users profile Send private message Visit posters website
pwillener

SRT Trainee
SRT Trainee
Premium Member

Joined: Apr 17, 2006
Posts: 1725
Location: Japan
Premium

PostPosted: Wed Jun 25, 2008 4:45 am    Post subject:
Reply with quote

SPOT DOMAIN LLC DBA DOMAINSITE.COM

Quote:
Your message did not reach some or all of the intended recipients.

 Subject: Removal request: oletdaptment.com
 Sent: 2008-06-25 13:27

The following recipient(s) could not be reached:

 support[@]domainsite.com on 2008-06-25 13:28
  There was a SMTP communication problem with the recipient's email server. Please contact your system administrator.
  <em03.cincom.com #5.5.0 smtp;554 mail server permanently rejected message (#5.3.0)>

Back to top
View users profile Send private message Visit posters website
pwillener

SRT Trainee
SRT Trainee
Premium Member

Joined: Apr 17, 2006
Posts: 1725
Location: Japan
Premium

PostPosted: Wed Jun 25, 2008 5:14 am    Post subject:
Reply with quote

SPOT DOMAIN LLC DBA DOMAINSITE.COM

Resent with munged domain name; no bounce so far.

Back to top
View users profile Send private message Visit posters website
tembow

Blue Angel
Premium Member

Joined: Oct 10, 2005
Posts: 2884

Blue Security Premium

PostPosted: Wed Jun 25, 2008 9:12 am    Post subject:
Reply with quote

Jim_P wrote:
I just heard something from DynamicDolphin.
I have not check this out.

Jim, we are currently processing several complaints on one of our domain owners. We have already disabled this domain and the name server info you see below has been used to disable it.


Regards,

Dynamic Dolphin Admin

From: Jim [mailto:j.chelmsford@gmail.com]
Sent: Tuesday, June 24, 2008 2:14 PM
To: Jenny Frederick; techsupport@dynamicdolphin.com; abuse@opticaljungle.com
Subject: Removal request: dynamicdeleted.info



Dynamic Dolphin Inc (R334-LRMS)
Dear Registrar

This is a request for you to remove the domain dynamicdeleted.info
and to remove its name server Address record ns2.dynamicdeleted.info [69.6.21.21], and ns1.dynamicdeleted.info [69.6.21.21]

EVIDENCE

>From this link, you can see that it is used as a name server for a spammed site
> http://www.dnsstuff.com/tools/traversal.ch?domain=tatinasur.com&type=a&token=complainterator&src=complainterator
-----


One WHOIS has
Code:
   Domain Name: TATINASUR.COM
   Registrar: DYNAMIC DOLPHIN, INC.
   Whois Server: whois.dynamicdolphin.com
   Referral URL: http://www.dynamicdolphin.com
   Name Server: NS1.COASTERLE.COM
   Name Server: NS2.COASTERLE.COM
   Status: clientTransferProhibited
   Updated Date: 22-jun-2008  <==
   Creation Date: 20-jun-2008
   Expiration Date: 20-jun-2009

Another more recent WHOIS has
Code:
 Domain Name: TATINASUR.COM
 Registrar: MONIKER ONLINE SERVICES, INC.
 Whois Server: whois.moniker.com
 Referral URL: http://www.moniker.com/whois.html
 Name Server: NS1.STANDBYCOINS.COM
 Name Server: NS2.STANDBYCOINS.COM
 Status: clientDeleteProhibited
 Status: clientTransferProhibited
 Status: clientUpdateProhibited
 Updated Date: 25-jun-2008 <==
 Creation Date: 25-jun-2008
 Expiration Date: 25-jun-2009

The one that got away!

Back to top
View users profile Send private message Visit posters website AIM Address
jimVO

Sergeant
Sergeant
Premium Member

Joined: Mar 17, 2008
Posts: 143
Location: USA
Premium

PostPosted: Thu Jun 26, 2008 4:35 am    Post subject:
Reply with quote

Found a registrar today that isn't on the ICANN list.

Spammed domain: leria.pl
Registrar: REGISTRAR: Hanival Internet Services GMBH
Contact office [at] hanival.net

Seems sort of odd to me. Got this on the traversal:

"ns2.hanival.com [193.19.93.18] [BOGUS ANSWER: This server is not authoritative for leria.pl: it refers back to the root servers]"

The domain hanival.com is registered with Directi Internet Solutions.

Back to top
View users profile Send private message
ahoier

SIRT Handler


Joined: Jan 14, 2006
Posts: 1029
Location: USA

PostPosted: Thu Jun 26, 2008 7:21 pm    Post subject:
Reply with quote

Spammed domain = buyxpsoft.com
Registrar = MOUZZ INTERACTIVE INC.
Contact = admin@mouzz.com

admin@ is another I found...

But they also have webforms available for pasting in spam/support (spam is a big support issue, ofc ^^)

***PASTE_INTO_http://www.mouzz.com/reports.php?action=report_spam
***PASTE_INTO_http://support.linklabs.com/

I sent in one request just now, using all 3 methods (2 forms, 1 e-mail)

We'll see what comes of it....

Though, I don't have the "original" spam containing buyxpsoft.com - so I linked to a mailing list that the mailer spammed....hopefully that works.

Back to top
View users profile Send private message Visit posters website AIM Address Yahoo Messenger MSN Messenger
tembow

Blue Angel
Premium Member

Joined: Oct 10, 2005
Posts: 2884

Blue Security Premium

PostPosted: Fri Jun 27, 2008 12:12 am    Post subject:
Reply with quote

The overriding philosophy of Complainterator is to not behave like a spammer. If we can find the ONE email address that the registrar prefers all complaints to go to, and it is effective, then tht is the one that goes into the contact list.

The latest versions have a trailer line inviting the recipient to feed back changes if the contact address is wrong.

Please do not break this method. It is likely to result in either
(a) your email address going onto an ignore list
(b) Complainterator mail going on an ignore list

Your aim should be to behave in such a way as to do on to the priority or trusted list, and that is something you have to earn.

Back to top
View users profile Send private message Visit posters website AIM Address
pwillener

SRT Trainee
SRT Trainee
Premium Member

Joined: Apr 17, 2006
Posts: 1725
Location: Japan
Premium

PostPosted: Fri Jun 27, 2008 2:05 am    Post subject:
Reply with quote

tembow wrote:
If we can find the ONE email address that the registrar prefers all complaints to go to ...

I just had an email conversation with Chris Cheng at Todaynic.com - I asked him what the best address is to report Todaynic issues (Complainterator by default currently reports to abuse ~AT~ now.net.cn, sanry ~AT~ now.net.cn, info ~AT~ todaynic.com).

He asked me to definitely remove the sanry address, and if possible only to report to service ~AT~ todaynic.com, or his own address, which is chris at the same domain.

I have just changed my complainterator.contacts file to reflect that (5 instances).

> Master copy updated

Back to top
View users profile Send private message Visit posters website
tembow

Blue Angel
Premium Member

Joined: Oct 10, 2005
Posts: 2884

Blue Security Premium

PostPosted: Fri Jun 27, 2008 4:34 am    Post subject:
Reply with quote

Latest contacts file is updated at
http://www.spamtrackers.eu/downloads/Complainterator/complainterator.contacts.txt

Back to top
View users profile Send private message Visit posters website AIM Address
tembow

Blue Angel
Premium Member

Joined: Oct 10, 2005
Posts: 2884

Blue Security Premium

PostPosted: Fri Jun 27, 2008 4:43 am    Post subject:
Reply with quote

ahoier wrote:
Spammed domain = buyxpsoft.com
Registrar = MOUZZ INTERACTIVE INC.
Contact = admin@mouzz.com
Alex Rodrigez (domains@suremoon.com)
Lappeenranta
Lappeenranta
NA,12700
FI
Tel. +358.305563

That's Leo Kuvayev's pseudonym

Back to top
View users profile Send private message Visit posters website AIM Address
pwillener

SRT Trainee
SRT Trainee
Premium Member

Joined: Apr 17, 2006
Posts: 1725
Location: Japan
Premium

PostPosted: Fri Jun 27, 2008 6:14 am    Post subject:
Reply with quote

Spammed domain: vakgosoft.com
Registrar: 0101 INTERNET, INC.
Contact: info[@]0101domain.com

Spammed domain: adwordsglogin.com
Registrar: ARSYS INTERNET, S.L. D/B/A NICLINE.COM
Contact: icann[@]arsys.es

Spammed domain: jrladdha.in
Registrar: Net4India (R7-AFIN)
Contact: abuse[@]net4india.net

Spammed domain: magic-help-russia.org
Registrar: Regtime Ltd (R1602-LROR)
Contact: support[@]regtime.net

Master copy updated

Back to top
View users profile Send private message Visit posters website
efa

Sergeant
Sergeant


Joined: Aug 31, 2007
Posts: 118
Location: Italy

PostPosted: Sun Jun 29, 2008 8:48 am    Post subject:
Reply with quote

Spammed Domain: ieateacc.com
Registrar: BASIC FUSION, INC.
Contact: info@basicfusion.com


Spammed Name Server: dnsnameserver.org
Registrar: Basic Fusion Inc (R1329-LROR)
Contact: info@basicfusion.com

dnsnameserver.org should be exempted from removal requests
master copy updated

Back to top
View users profile Send private message
Nolimit

Trooper
Trooper


Joined: Jun 13, 2007
Posts: 12
Location: Netherlands

PostPosted: Mon Jun 30, 2008 7:22 am    Post subject:
Reply with quote

alenfot.net
Dynamic Network Services, Inc. (United States)
http://www.dyndns.com
icann@dyndns.com
abuse@dyndns.com

LOCAWEB SERVICOS DE INTERNET S/A DBA LOCAWEB
In the contacts file: joaquim.torres@locaweb.com.br
On their wesite: abuse@locaweb.com.br

Nl.

Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Complainterator All times are GMT
Goto page Previous  1, 2, 3, 4, 5 ... 8, 9, 10, 11, 12, 13  Next
Page 9 of 13

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer