CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

[SIRT#187182] Canadian Pharmacy on joyhappen.com

 
Post new topic   Reply to topic       All -> FavForums -> SIRT Reports [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
ahoier

SIRT Handler


Joined: Jan 14, 2006
Posts: 1118
Location: USA

PostPosted: Wed Jun 11, 2008 7:18 pm    Post subject: [SIRT#187182] Canadian Pharmacy on joyhappen.com
Reply with quote

Spam Alert
 
 Full Report: CastleCops Link/Canadian_Pharmacy_spam187182.html
 
 Consumed following related reports:

[184499] http://joyhappen.com
[184765] http://joyhappen.com/
Changed status to confirmed spam.IP Converted: 116.123.47.80

dword = 1954230096
hex1 = 0x747b2f50
hex2 = 0x74.0x7b.0x2f.0x50
oct = 0164.0173.057.0120
View CIDR AS9318 Report: http://www.cidr-report.org/cgi-bin/as-report?as=9318

"9318 | KR | apnic | 1998-06-03 | HANARO-AS Hanaro Telecom Inc."<br />
Extended information for AS9318:
State/Province:
Country: kr
Responsible Domain: hananet.net
Abuse Email: abuse@hananet.net
IP Converted: 222.186.13.84

dword = 3736735060
hex1 = 0xdeba0d54
hex2 = 0xde.0xba.0xd.0x54
oct = 0336.0272.015.0124
View CIDR AS4134 Report: http://www.cidr-report.org/cgi-bin/as-report?as=4134

"4134 | CN | apnic | 2002-08-01 | CHINANET-BACKBONE No.31,Jin-rong Street"<br />
Extended information for AS4134:
State/Province:
Country: cn
Responsible Domain: chinanet.cn.net
Abuse Email: cncert@cert.org.cn
IP Converted: 59.63.157.72

dword = 994024776
hex1 = 0x3b3f9d48
hex2 = 0x3b.0x3f.0x9d.0x48
oct = 073.077.0235.0110
View CIDR AS4134 Report: http://www.cidr-report.org/cgi-bin/as-report?as=4134

"4134 | CN | apnic | 2002-08-01 | CHINANET-BACKBONE No.31,Jin-rong Street"<br />
Extended information for AS4134:
State/Province:
Country: cn
Responsible Domain: chinanet.cn.net
Abuse Email: cncert@cert.org.cn
IP Converted: 218.61.18.139

dword = 3661435531
hex1 = 0xda3d128b
hex2 = 0xda.0x3d.0x12.0x8b
oct = 0332.075.022.0213
View CIDR AS4837 Report: http://www.cidr-report.org/cgi-bin/as-report?as=4837

"4837 | CN | apnic | 2001-09-17 | CHINA169-BACKBONE CNCGROUP China169 Backbone"<br />
Extended information for AS4837:
State/Province:
Country: cn
Responsible Domain: cnc-noc.net
Abuse Email: abuse@cnc-noc.net
IP Converted: 221.122.64.14

dword = 3715776526
hex1 = 0xdd7a400e
hex2 = 0xdd.0x7a.0x40.0xe
oct = 0335.0172.0100.016
View CIDR AS17772 Report: http://www.cidr-report.org/cgi-bin/as-report?as=17772

"17772 | CN | apnic | 2001-06-01 | CHINACOM CHINA COMMUNICATIONS SYSTEM Co.,Ltd."<br />
Extended information for AS17772:
State/Province:
Country: cn
Responsible Domain: cetc-chinacomm.com.cn
Abuse Email: postmaster@cetc-chinacomm.com.cn
View CIDR AS4808 Report: http://www.cidr-report.org/cgi-bin/as-report?as=4808

"4808 | CN | apnic | 1996-01-09 | CHINA169-BJ CNCGROUP IP network China169 Beijing Province Network"<br />
Extended information for AS4808:
State/Province:
Country: cn
Responsible Domain: cnc-noc.net
Abuse Email: abuse@cnc-noc.net


Criminal Evidence

See the Spam Wiki entry at http://www.spamtrackers.eu/wiki/index.php?title=Canadian_Pharmacy
or from China: http://www.spamtrackers.hk/wiki/index.php?title=Canadian_Pharmacy
See the McAfee Site Advisor information at http://siteadvisor.com/sites/joyhappen.com


> DIRECTI INTERNET SOLUTIONS PVT. LTD. D/B/A PUBLICDOMAINREGISTRY.COM
REGISTRATION OF THE WEB SITE: joyhappen.com
ACTION: To suspend this criminal site which breaks your terms of service, set the domain status to clientHold


> XIN NET TECHNOLOGY CORPORATION (globohosts.com,globonss.com)
> BEIJING INNOVATIVE LINKAGE TECHNOLOGY LTD. DBA DNS.COM.CN (likenewdesign.com,yourpleasant.com)
REGISTRATION OF THE NAME SERVERS
These name servers are registered by criminals to resolve only illegal web sites. This breaks your terms of service. You can safely suspend them:
ns0.globohosts.com | 222.186.13.84 | N/A | Blacklisted | China | http://www.spamhaus.org/SBL/sbl.lasso?query=SBL64784
ns0.globonss.com | 59.63.157.72 | N/A | Blacklisted | China | http://www.spamhaus.org/SBL/sbl.lasso?query=SBL65031
ns0.likenewdesign.com | 218.61.18.139 | N/A | Blacklisted | China | http://www.spamhaus.org/SBL/sbl.lasso?query=SBL65030
ns0.yourpleasant.com | 221.122.64.14 | N/A | Blacklisted | China | http://www.spamhaus.org/SBL/sbl.lasso?query=SBL62867

ACTION: To suspend these name servers successfully, follow these steps.
1. set the ns Address records to a non-routable address, such as 127.0.0.1 or 61.61.61.61.
2. Set the domain status to clientUpdateProhibited, clientTransferProhibited, clientDeleteProhibited, and clientHold


> HANARO-AS Hanaro Telecom Inc. (incl. abuse@hanaro.com,spamrelay@certcc.or.kr,spamcop@kisa.or.kr)
IP ADDRESS OF HOST: 116.123.47.80
The IP address of this criminal site is within your allocated address space.
Furthermore, you will find this IP address is within the Spamhaus Blocklists due to its use in unsolicited spam e-mail
* http://www.spamhaus.org/SBL/sbl.lasso?query=SBL64370

This IP address is currently linked with the following fraudulent, criminal-operated domains:
shapesea.com A 116.123.47.80
clearbasic.com A 116.123.47.80
egghad.com A 116.123.47.80
certainglad.com A 116.123.47.80
ns1.certainglad.com A 116.123.47.80
ns2.certainglad.com A 116.123.47.80
ns3.certainglad.com A 116.123.47.80
ns4.certainglad.com A 116.123.47.80
ns4.dependadd.com A 116.123.47.80
lengthadd.com A 116.123.47.80
teethdid.com A 116.123.47.80
viewcold.com A 116.123.47.80
wroteland.com A 116.123.47.80
startstand.com A 116.123.47.80
clocksend.com A 116.123.47.80
ns1.sectionfind.com A 116.123.47.80
ns2.sectionfind.com A 116.123.47.80
ns4.sectionfind.com A 116.123.47.80
eachperiod.com A 116.123.47.80
ns1.eachperiod.com A 116.123.47.80
ns1.sheetstood.com A 116.123.47.80
ns2.sheetstood.com A 116.123.47.80
ns3.sheetstood.com A 116.123.47.80
ns4.sheetstood.com A 116.123.47.80
rightheard.com A 116.123.47.80
multiplytoward.com A 116.123.47.80
edkn.makechord.com A 116.123.47.80
pleasetube.com A 116.123.47.80
www.differrace.com A 116.123.47.80
housepractice.com A 116.123.47.80
butdance.com A 116.123.47.80
teachchance.com A 116.123.47.80
ns1.teachchance.com A 116.123.47.80
ns2.teachchance.com A 116.123.47.80
ns3.teachchance.com A 116.123.47.80
ns4.teachchance.com A 116.123.47.80
willexperience.com A 116.123.47.80
rollexperience.com A 116.123.47.80
ns1.rollexperience.com A 116.123.47.80
ns2.rollexperience.com A 116.123.47.80
ns3.rollexperience.com A 116.123.47.80
ns4.rollexperience.com A 116.123.47.80
headinclude.com A 116.123.47.80
ns1.headinclude.com A 116.123.47.80
ns2.headinclude.com A 116.123.47.80
ns3.headinclude.com A 116.123.47.80
ns4.headinclude.com A 116.123.47.80
shellwife.com A 116.123.47.80
companywife.com A 116.123.47.80
ns1.motherchange.com A 116.123.47.80
ns2.motherchange.com A 116.123.47.80
ns3.motherchange.com A 116.123.47.80
ns4.motherchange.com A 116.123.47.80
differarrange.com A 116.123.47.80
www.guidehuge.com A 116.123.47.80
signscale.com A 116.123.47.80
includeable.com A 116.123.47.80
unxtrc.appearable.com A 116.123.47.80
rbk.appearable.com A 116.123.47.80
melodydouble.com A 116.123.47.80
ladymile.com A 116.123.47.80
smellexample.com A 116.123.47.80
ledsettle.com A 116.123.47.80
ns1.ledsettle.com A 116.123.47.80
gasmolecule.com A 116.123.47.80
ns1.gasmolecule.com A 116.123.47.80
ns2.gasmolecule.com A 116.123.47.80
ns3.gasmolecule.com A 116.123.47.80
ns4.gasmolecule.com A 116.123.47.80
substancename.com A 116.123.47.80
posename.com A 116.123.47.80
ns1.lengthsame.com A 116.123.47.80
ns2.lengthsame.com A 116.123.47.80
ns4.lengthsame.com A 116.123.47.80
especiallytime.com A 116.123.47.80
ns1.especiallytime.com A 116.123.47.80
ns2.especiallytime.com A 116.123.47.80
ns3.especiallytime.com A 116.123.47.80
ns4.especiallytime.com A 116.123.47.80
couldengine.com A 116.123.47.80
repeatengine.com A 116.123.47.80
ns1.repeatengine.com A 116.123.47.80
ns2.repeatengine.com A 116.123.47.80
ns3.repeatengine.com A 116.123.47.80
ns4.repeatengine.com A 116.123.47.80
tiredetermine.com A 116.123.47.80
ns1.tiredetermine.com A 116.123.47.80
ns2.tiredetermine.com A 116.123.47.80
ns3.tiredetermine.com A 116.123.47.80
ns4.tiredetermine.com A 116.123.47.80
ridesquare.com A 116.123.47.80
personthere.com A 116.123.47.80
originalshore.com A 116.123.47.80
ns1.moleculethese.com A 116.123.47.80
ns2.moleculethese.com A 116.123.47.80
ns3.moleculethese.com A 116.123.47.80
ns4.moleculethese.com A 116.123.47.80
ringpose.com A 116.123.47.80
silverindicate.com A 116.123.47.80
ns1.plantcreate.com A 116.123.47.80
ns2.plantcreate.com A 116.123.47.80
ns3.plantcreate.com A 116.123.47.80
ns4.plantcreate.com A 116.123.47.80
www.plantcreate.com A 116.123.47.80
ns1.answerseparate.com A 116.123.47.80
ns3.answerseparate.com A 116.123.47.80
ns4.answerseparate.com A 116.123.47.80
rowexcite.com A 116.123.47.80
highminute.com A 116.123.47.80
www.costcontinue.com A 116.123.47.80
areleave.com A 116.123.47.80
secondsolve.com A 116.123.47.80
planeprove.com A 116.123.47.80
dictionaryobserve.com A 116.123.47.80
caresize.com A 116.123.47.80
ns1.chartleg.com A 116.123.47.80
ns3.chartleg.com A 116.123.47.80
ns4.chartleg.com A 116.123.47.80
dealfig.com A 116.123.47.80
rockwing.com A 116.123.47.80
mainlong.com A 116.123.47.80
ns1.mainlong.com A 116.123.47.80
ns2.mainlong.com A 116.123.47.80
ns3.mainlong.com A 116.123.47.80
ns4.mainlong.com A 116.123.47.80
motionteach.com A 116.123.47.80
hoperich.com A 116.123.47.80
ns1.hoperich.com A 116.123.47.80
ns2.hoperich.com A 116.123.47.80
ns3.hoperich.com A 116.123.47.80
ns4.hoperich.com A 116.123.47.80
specialrich.com A 116.123.47.80
ns1.specialrich.com A 116.123.47.80
ns2.specialrich.com A 116.123.47.80
ns3.specialrich.com A 116.123.47.80
ns4.specialrich.com A 116.123.47.80
www.madebranch.com A 116.123.47.80
rightmuch.com A 116.123.47.80
www.rightmuch.com A 116.123.47.80
www.successlaugh.com A 116.123.47.80
everylaugh.com A 116.123.47.80
pageoh.com A 116.123.47.80
rainparagraph.com A 116.123.47.80
ns2.guidefresh.com A 116.123.47.80
organfish.com A 116.123.47.80
ns1.organfish.com A 116.123.47.80
ns2.organfish.com A 116.123.47.80
ns3.organfish.com A 116.123.47.80
ACTION: Black-hole the route to this address to prevent further criminal activity


> HANARO-AS Hanaro Telecom Inc.
> CHINANET-BACKBONE No.31,Jin-rong Street (incl. abuse@jsinfo.net,abuse@jlonline.com,abuse@public1.ptt.js.cn,spam@jsinfo.net,anti-spam@ns.chinanet.cn.net)
IP ADDRESS OF NAMESERVER (ns0.globohosts.com): 222.186.13.84
The IP address of this criminal nameserver is within your allocated address space. This nameserver is solely being used for malicious and criminal intent.

This IP address is currently linked with the following fraudulent, criminal-operated domains:
ns4.goo33.com A 222.186.13.84
ns2.ns444.com A 222.186.13.84
ns3.gtd44.com A 222.186.13.84
ns4.gtd44.com A 222.186.13.84
www.biverga.com A 222.186.13.84
ns1.fellspeed.com A 222.186.13.84
ns2.fellspeed.com A 222.186.13.84
ns3.fellspeed.com A 222.186.13.84
ns4.fellspeed.com A 222.186.13.84
clocksend.com A 222.186.13.84
ns2.agreeage.com A 222.186.13.84
ns3.agreeage.com A 222.186.13.84
ns4.agreeage.com A 222.186.13.84
ns1.tufille.com A 222.186.13.84
ns2.tufille.com A 222.186.13.84
ns3.tufille.com A 222.186.13.84
ns4.tufille.com A 222.186.13.84
www.tufille.com A 222.186.13.84
ns2.ledsettle.com A 222.186.13.84
ns3.ledsettle.com A 222.186.13.84
ns4.ledsettle.com A 222.186.13.84
ns2.dryduring.com A 222.186.13.84
ns4.dryduring.com A 222.186.13.84
everylaugh.com A 222.186.13.84
ns4.bervk.com A 222.186.13.84
ns4.takelearn.com A 222.186.13.84
ns1.mecasinofun.com A 222.186.13.84
ns2.mecasinofun.com A 222.186.13.84
ns3.mecasinofun.com A 222.186.13.84
ns4.mecasinofun.com A 222.186.13.84
ns1.vedismo.com A 222.186.13.84
ns4.vedismo.com A 222.186.13.84
www.vedismo.com A 222.186.13.84
your-gold-casino.com A 222.186.13.84
colonytop.com A 222.186.13.84
teacheither.com A 222.186.13.84
figcenter.com A 222.186.13.84
ns4.hopens.com A 222.186.13.84
forcepass.com A 222.186.13.84
ns2.forcepass.com A 222.186.13.84
ns3.forcepass.com A 222.186.13.84
ns1.middlesuccess.com A 222.186.13.84
ns2.middlesuccess.com A 222.186.13.84
ns3.middlesuccess.com A 222.186.13.84
ns3.rundnss.com A 222.186.13.84
ns0.globohosts.com A 222.186.13.84
severalsheet.com A 222.186.13.84
legsent.com A 222.186.13.84
ns1.thankfoot.com A 222.186.13.84
ns2.thankfoot.com A 222.186.13.84
ns3.thankfoot.com A 222.186.13.84
ns4.thankfoot.com A 222.186.13.84
www.thankfoot.com A 222.186.13.84
shallstart.com A 222.186.13.84
ns1.shallstart.com A 222.186.13.84
ns2.shallstart.com A 222.186.13.84
ns3.shallstart.com A 222.186.13.84
ns4.shallstart.com A 222.186.13.84
fullrow.com A 222.186.13.84
ns1.napemix.com A 222.186.13.84
ns2.napemix.com A 222.186.13.84
ns3.napemix.com A 222.186.13.84
ns1.wereboy.com A 222.186.13.84
ns2.wereboy.com A 222.186.13.84
ns3.wereboy.com A 222.186.13.84
ns4.wereboy.com A 222.186.13.84
www.wereboy.com A 222.186.13.84
ns1.asrtalb.com.cn A 222.186.13.84
ns2.asrtalb.com.cn A 222.186.13.84
ns3.asrtalb.com.cn A 222.186.13.84
ns4.asrtalb.com.cn A 222.186.13.84
www.asrtalb.com.cn A 222.186.13.84
ns1.belisd.com.cn A 222.186.13.84
www.belisd.com.cn A 222.186.13.84
ns1.vigvame.com.cn A 222.186.13.84
ns2.vigvame.com.cn A 222.186.13.84
ns3.vigvame.com.cn A 222.186.13.84
ns4.vigvame.com.cn A 222.186.13.84
www.vigvame.com.cn A 222.186.13.84
ns1.nagavag.com.cn A 222.186.13.84
ns2.nagavag.com.cn A 222.186.13.84
ns3.nagavag.com.cn A 222.186.13.84
ns4.nagavag.com.cn A 222.186.13.84
www.nagavag.com.cn A 222.186.13.84
ns1.asrtaloi.com.cn A 222.186.13.84
ns2.asrtaloi.com.cn A 222.186.13.84
ns3.asrtaloi.com.cn A 222.186.13.84
ns4.asrtaloi.com.cn A 222.186.13.84
www.asrtaloi.com.cn A 222.186.13.84
ns1.figvan.com.cn A 222.186.13.84
ns2.figvan.com.cn A 222.186.13.84
ns3.figvan.com.cn A 222.186.13.84
ns4.figvan.com.cn A 222.186.13.84
www.figvan.com.cn A 222.186.13.84
ns1.trutlen.com.cn A 222.186.13.84
ns2.trutlen.com.cn A 222.186.13.84
ns3.trutlen.com.cn A 222.186.13.84
ns4.trutlen.com.cn A 222.186.13.84
ns1.tvaer.com.cn A 222.186.13.84
ns2.tvaer.com.cn A 222.186.13.84
ns3.tvaer.com.cn A 222.186.13.84
ns4.tvaer.com.cn A 222.186.13.84
www.tvaer.com.cn A 222.186.13.84
ns1.shimeter.com.cn A 222.186.13.84
ns2.shimeter.com.cn A 222.186.13.84
ns3.shimeter.com.cn A 222.186.13.84
ns4.shimeter.com.cn A 222.186.13.84
www.shimeter.com.cn A 222.186.13.84
ns1.mochasr.com.cn A 222.186.13.84
ns2.mochasr.com.cn A 222.186.13.84
ns3.mochasr.com.cn A 222.186.13.84
ns4.mochasr.com.cn A 222.186.13.84
ns2.mozeds.com.cn A 222.186.13.84
ns3.mozeds.com.cn A 222.186.13.84
ns4.mozeds.com.cn A 222.186.13.84
ns1.schmiky.com.cn A 222.186.13.84
ns2.schmiky.com.cn A 222.186.13.84
ns3.schmiky.com.cn A 222.186.13.84
ns4.schmiky.com.cn A 222.186.13.84
www.schmiky.com.cn A 222.186.13.84
ns1.vedismo.net A 222.186.13.84
ns2.vedismo.net A 222.186.13.84
ns3.vedismo.net A 222.186.13.84
ns4.vedismo.net A 222.186.13.84
ACTION: Black-hole the route to this address to prevent further criminal activity


> CHINANET-BACKBONE No.31,Jin-rong Street (incl. postmaster@public1.nc.jx.cn,anti-spam@ns.chinanet.cn.net)
IP ADDRESS OF NAMESERVER (ns0.globonss.com): 59.63.157.72
The IP address of this criminal nameserver is within your allocated address space. This nameserver is solely being used for malicious and criminal intent.

This IP address is currently linked with the following fraudulent, criminal-operated domains:
royal-euro-club.org A 59.63.157.72
ns1.fort23.com A 59.63.157.72
ns3.goo33.com A 59.63.157.72
ns1.mop33.com A 59.63.157.72
ns3.mop33.com A 59.63.157.72
ns1.m44444.com A 59.63.157.72
ns1.x44444.com A 59.63.157.72
ns3.ns444.com A 59.63.157.72
ns1.row744.com A 59.63.157.72
ns2.row744.com A 59.63.157.72
ns3.gtd44.com A 59.63.157.72
ns3.man454.com A 59.63.157.72
ns3.cas454.com A 59.63.157.72
ns3.ter345.com A 59.63.157.72
ns1.rush88.com A 59.63.157.72
kingscasinoworld.com A 59.63.157.72
adultcasinotime.com A 59.63.157.72
ns1.adultcasinotime.com A 59.63.157.72
ns2.hetme.com A 59.63.157.72
yourthe-king.com A 59.63.157.72
ns1.yourthe-king.com A 59.63.157.72
ns2.yourthe-king.com A 59.63.157.72
ns3.yourthe-king.com A 59.63.157.72
ns4.yourthe-king.com A 59.63.157.72
joinluxgambling.com A 59.63.157.72
ns1.joinluxgambling.com A 59.63.157.72
ns2.joinluxgambling.com A 59.63.157.72
ns3.joinluxgambling.com A 59.63.157.72
ns4.joinluxgambling.com A 59.63.157.72
goldfirstplaying.com A 59.63.157.72
ns3.bervk.com A 59.63.157.72
dumbcasinowomen.com A 59.63.157.72
ns1.mecasinofun.com A 59.63.157.72
ns2.mecasinofun.com A 59.63.157.72
ns3.mecasinofun.com A 59.63.157.72
ns4.mecasinofun.com A 59.63.157.72
your-gold-casino.com A 59.63.157.72
worldultimatecasino.com A 59.63.157.72
goldpaycasino.com A 59.63.157.72
worldcasinovip.com A 59.63.157.72
ns2.hopens.com A 59.63.157.72
ns2.rundnss.com A 59.63.157.72
ns4.rundnss.com A 59.63.157.72
ns0.globonss.com A 59.63.157.72
ns1.jokecasinomoney.com A 59.63.157.72
ns2.jokecasinomoney.com A 59.63.157.72
ns3.jokecasinomoney.com A 59.63.157.72
ns4.jokecasinomoney.com A 59.63.157.72
www.jokecasinomoney.com A 59.63.157.72
bestgamingmagic.net A 59.63.157.72
bestnewgambling.net A 59.63.157.72
luxhitgaming.net A 59.63.157.72
magichotgaming.net A 59.63.157.72
webnewplaying.net A 59.63.157.72
ns1.gtgvip.net A 59.63.157.72
ns2.gtgvip.net A 59.63.157.72
ns3.gtgvip.net A 59.63.157.72
ns4.gtgvip.net A 59.63.157.72
ACTION: Black-hole the route to this address to prevent further criminal activity


> CHINA169-BACKBONE CNCGROUP China169 Backbone (incl. abuse@cnc-noc.net)
IP ADDRESS OF NAMESERVER (ns0.likenewdesign.com): 218.61.18.139
The IP address of this criminal nameserver is within your allocated address space. This nameserver is solely being used for malicious and criminal intent.

This IP address is currently linked with the following fraudulent, criminal-operated domains:
ns2.fort23.com A 218.61.18.139
ns2.goo33.com A 218.61.18.139
ns2.m44444.com A 218.61.18.139
ns2.x44444.com A 218.61.18.139
ns2.row744.com A 218.61.18.139
ns2.gtd44.com A 218.61.18.139
ns2.rush88.com A 218.61.18.139
ns2.bervk.com A 218.61.18.139
ns0.likenewdesign.com A 218.61.18.139
ns2.rundnss.com A 218.61.18.139
ns4.rundnss.com A 218.61.18.139
ACTION: Black-hole the route to this address to prevent further criminal activity


> CHINACOM CHINA COMMUNICATIONS SYSTEM Co.,Ltd. (incl. anti-spam@ns.chinanet.cn.net)
> CHINA169-BJ CNCGROUP IP network China169 Beijing Province Network
IP ADDRESS OF NAMESERVER (ns0.yourpleasant.com): 221.122.64.14
The IP address of this criminal nameserver is within your allocated address space. This nameserver is solely being used for malicious and criminal intent.

This IP address is currently linked with the following fraudulent, criminal-operated domains:
ns1.goo33.com A 221.122.64.14
ns1.gtd44.com A 221.122.64.14
ns4.gtd44.com A 221.122.64.14
ns4.canadianmedsworld.com A 221.122.64.14
multiplytoward.com A 221.122.64.14
ns3.hetme.com A 221.122.64.14
ns1.bervk.com A 221.122.64.14
ns1.kindns.com A 221.122.64.14
ns3.hopens.com A 221.122.64.14
ns1.rundnss.com A 221.122.64.14
ns0.yourpleasant.com A 221.122.64.14
ACTION: Black-hole the route to this address to prevent further criminal activity


The criminality of these domain names can be verified using the following SiteAdvisor link format, http://www.siteadvisor.com/lookup/?q=domainname.tld


> Stacy.Barnett@icann.org
You will notice from the WHOIS results displayed for this spamvertised domain that this registrant has falsified the contact details. Furthermore, the registrar, DIRECTI INTERNET SOLUTIONS PVT. LTD. D/B/A PUBLICDOMAINREGISTRY.COM has honored these forged/munged contact details, and allowed them to be posted to the public whois database. This is a violation of requirements set by ICANN accredited registrars.
ACTION: Please discuss with this registrar that allowing this fudged data is a violation of ICANN standards and practices.


CRIMINAL EVIDENCE: VIOLATION OF CAN-SPAM LAWS

Delivered-To: xxx
Received: by 10.150.156.15 with SMTP id d15cs111768ybe;
Sun, 8 Jun 2008 07:50:39 -0700 (PDT)
Received: by 10.210.102.12 with SMTP id z12mr2054289ebb.52.1212936638299;
Sun, 08 Jun 2008 07:50:38 -0700 (PDT)
Return-Path: <sammy@pervalidus.net>
Received: from ctv-86-100-217-55.ip.rygveda.lt (ctv-86-100-217-55.ip.rygveda.lt [86.100.217.55])
by mx.google.com with ESMTP id i7si45410823nfh.8.2008.06.08.07.50.34;
Sun, 08 Jun 2008 07:50:38 -0700 (PDT)
Received-SPF: neutral (google.com: 86.100.217.55 is neither permitted nor denied by domain of sammy@pervalidus.net) client-ip=86.100.217.55;
Authentication-Results: mx.google.com; spf=neutral (google.com: 86.100.217.55 is neither permitted nor denied by domain of sammy@pervalidus.net) smtp.mail=sammy@pervalidus.net
Date: Sun, 08 Jun 2008 23:03:07 +0000
Message-ID: <42684.jackson@mtichell>
From: "dimitrou sidarta" <sammy@pervalidus.net>
To: <xxx>
Subject: 80% prices
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary="=_q8lx4lMXSglVbn"

This is a multi-part message in MIME format.

--=_q8lx4lMXSglVbn
Content-Type: text/plain;
charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

My dear xxx, be smart, buy your pharmaceuticals from the best shop.

--=_q8lx4lMXSglVbn
Content-Type: text/html;
charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML>
<HEAD>
<META http-equiv=3DContent-Type content=3D"text/html; =
charset=3Diso-8859-1">
</HEAD>
<BODY bgColor=3D#66FF99>
<P>My dear xxx, be smart, buy your pharmaceuticals from the <A =
HREF=3D"http://joyhappen.com">
best shop.</A></P>



</BODY>
</HTML>
--=_q8lx4lMXSglVbn--


This spam e-mail was not requested. Further more, this spam e-mail violates many rulings set forth by the CAN-SPAM Laws which can be viewed at the following link:
* http://www.ftc.gov/bcp/conline/pubs/buspubs/canspam.shtm

Quote:
http://joyhappen.com/counter.php?account_id=joyhappen.com&aid=&said=&js=1&nocache=0.524283617361051&referrer=&cookies=1&java=1&style_sheets=1&system_lang=undefined&browser_lang=undefined&user_lang=undefined&color_depth=32&resolution=1280x800&avail_window_size=1280x772&cpu_class=undefined&platform=Win32&sub

Back to top
View users profile Send private message Visit posters website AIM Address Yahoo Messenger MSN Messenger
tembow

Blue Angel
Premium Member

Joined: Oct 10, 2005
Posts: 2945

Blue Security Premium

PostPosted: Thu Jun 12, 2008 12:23 am    Post subject:
Reply with quote

Delivery errors

Arrival-Date: Wed, 11 Jun 2008 19:18:47 +0000 (UTC)

Final-Recipient: rfc822; abuse@DNS.COM.CN
Action: failed
Status: 5.0.0
Remote-MTA: dns; mail.DNS.COM.CN
Diagnostic-Code: smtp; 550 Does not like recipient,your mail is rejected!

Final-Recipient: rfc822; cnreg@dns.com.cn
Action: failed
Status: 5.0.0
Remote-MTA: dns; mail.DNS.COM.CN
Diagnostic-Code: smtp; 550 Does not like recipient,your mail is rejected!

Final-Recipient: rfc822; huyan@dns.com.cn
Action: failed
Status: 5.0.0
Remote-MTA: dns; mail.DNS.COM.CN
Diagnostic-Code: smtp; 550 Does not like recipient,your mail is rejected!

Final-Recipient: rfc822; postmaster@public1.nc.jx.cn
Action: failed
Status: 5.7.1
Remote-MTA: dns; public1.nc.jx.cn
Diagnostic-Code: smtp; 550 5.7.1 <postmaster@public1.nc.jx.cn>... Rejected:
149.20.54.190 listed at blackholes.mail-abuse.org

Back to top
View users profile Send private message Visit posters website AIM Address
tembow

Blue Angel
Premium Member

Joined: Oct 10, 2005
Posts: 2945

Blue Security Premium

PostPosted: Thu Jun 12, 2008 12:25 am    Post subject:
Reply with quote

X-AIMC-MAILFROM: postmaster@ptt.js.cn
X-Auto-Forward: abuse@jlonline.com
fuwuban@supernj.com
X-AIMC-Msg-ID: RmtR6GUB

--aimc
Content-type: text/plain

ÒÔϵÄÓʼþ:

> ÈÕÆÚ: Wed, 11 Jun 2008 19:18:47 +0000 (UTC)
> Ö÷Ìâ: [SIRT#187182] Canadian Pharmacy Spam on your network (AS9318,AS4134,AS4837,AS17772,AS4808) {154120}
> ´óС: 29384 bytes ×Ö½Ú
> ¶¯×÷: ʧ°Ü

ûÓÐÄܹ»·¢Ë͵½ÒÔϵÄÊÕ¼þÈË:

fuwuban.supernj_com "(54), ErrMsg=Mailbox space not enough (space limit is 102400KB). Size of arriving mail (1KB) exceeds free space (0KB)."
abuse:jl "(59), ErrMsg=Mailbox space not enough (space limit is 102400KB). Size of arriving mail (1KB) exceeds free space (0KB)."


²»»áÔÙÓÐÈκζ¯×÷À´³¢ÊÔ·¢ËÍÄãµÄÓʼþÁË¡£ ÇëÁªÏµÄãµÄϵͳ¹ÜÀíÔ±»òÏÈͨ¹ýÆäËü·Çµç×ÓÓʼþµÄ·½Ê½ÏòÄãµÄÅóÓÑ·¢ËÍÐÅÏ¢ÒÔÃâµ¢Îó¡£
--aimc

Back to top
View users profile Send private message Visit posters website AIM Address
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> SIRT Reports All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You cannot post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer