CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

[SIRT#187337] dating site on ha-u-a-u.com / volbon / voldon

 
Post new topic   Reply to topic       All -> FavForums -> SIRT Reports [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
ahoier

SIRT Handler


Joined: Jan 14, 2006
Posts: 1118
Location: USA

PostPosted: Thu Jun 12, 2008 2:10 am    Post subject: [SIRT#187337] dating site on ha-u-a-u.com / volbon / voldon
Reply with quote

Spam Alert
 
 Full Report: CastleCops Link/dating_site_spam187337.html
 
 Consumed following related reports:

[75798] http://ha-u-a-u.com/?bc=mark&me=6bEB6W9H9W6Z4H94H4Hs8I87yH5SM9Lqfa4H8iikH8A4N68z784
[79290] http://ha-u-a-u.com/?bc=mark&me=75HD3GhH2Hg7jdH5M9691HB8zP3HgH3Fp5k9H9HwN84NN3G4HHH85
[80052] http://ha-u-a-u.com/?bc=mark&me=8aN3IiHSq8kHS5H5H8H2BSQQ4F6MH7zqH8eRhkH85L4H8Y2J6
[89847] http://ha-u-a-u.com/?bc=kep
[111431] http://ha-u-a-u.com/?bc=mark&me=81H7s4DbsHeDHsBBk7QfdBPlH8L6F3H4LNH4H6VPa4a9fu
[144219] http://ha-u-a-u.com/?bc=mark&me=76H4OPH1Hk77DBR7QLHb4HF889HV6H5H9R68IjkHUB7eG4H9hI7
[187338] http://ha-u-a-u.com/?bc=mark&me=6k3ORjC8z9HDJ6P2H93HTHjR4Pkb86767HN6jj5DLL9H9k8R6
Changed status to confirmed spam.IP Converted: 220.214.94.104

dword = 3705036392
hex1 = 0xdcd65e68
hex2 = 0xdc.0xd6.0x5e.0x68
oct = 0334.0326.0136.0150
View CIDR AS4732 Report: http://www.cidr-report.org/cgi-bin/as-report?as=4732

"4732 | JP | apnic | 1995-08-30 | DION KDDI CORPORATION"<br />
Extended information for AS4732:
State/Province:
Country: jp
Responsible Domain: kddi.com
Abuse Email: abuse@dion.ne.jp
View CIDR AS2516 Report: http://www.cidr-report.org/cgi-bin/as-report?as=2516

"2516 | JP | apnic | 2002-04-05 | KDDI KDDI CORPORATION"<br />
Extended information for AS2516:
State/Province:
Country: jp
Responsible Domain: kddi.com
Abuse Email: abuse@dion.ne.jp
IP Converted: 210.249.60.67

dword = 3539549251
hex1 = 0xd2f93c43
hex2 = 0xd2.0xf9.0x3c.0x43
oct = 0322.0371.074.0103
IP Converted: 121.1.252.81

dword = 2030173265
hex1 = 0x7901fc51
hex2 = 0x79.0x1.0xfc.0x51
oct = 0171.01.0374.0121
View CIDR AS4685 Report: http://www.cidr-report.org/cgi-bin/as-report?as=4685

"4685 | JP | apnic | 1995-08-30 | ASAHI-NET Asahi Net"<br />
Extended information for AS4685:
State/Province:
Country: jp
Responsible Domain: asahi-net.or.jp
Abuse Email: postmaster@asahi-net.or.jp
IP Converted: 210.249.60.67

dword = 3539549251
hex1 = 0xd2f93c43
hex2 = 0xd2.0xf9.0x3c.0x43
oct = 0322.0371.074.0103


Criminal Evidence

See the McAfee Site Advisor information at http://siteadvisor.com/sites/ha-u-a-u.com


> FIRSTSERVER, INC.
REGISTRATION OF THE WEB SITE: ha-u-a-u.com
ACTION: To suspend this criminal site which breaks your terms of service, set the domain status to clientHold


> YESNIC CO. LTD. (volbon.net)
> TUCOWS INC. (voldon.com)
REGISTRATION OF THE NAME SERVERS
These name servers are registered by criminals to resolve only illegal web sites. This breaks your terms of service. You can safely suspend them:
ddns.volbon.net | 210.249.60.67 | Japan
ddns.voldon.com | 121.1.252.81 | Japan

ACTION: To suspend these name servers successfully, follow these steps.
1. set the ns Address records to a non-routable address, such as 127.0.0.1 or 61.61.61.61.
2. Set the domain status to clientUpdateProhibited, clientTransferProhibited, clientDeleteProhibited, and clientHold


> DION KDDI CORPORATION
> KDDI KDDI CORPORATION
IP ADDRESS OF HOST: 220.214.94.104
The IP address of this criminal site is within your allocated address space.

ACTION: Black-hole the route to this address to prevent further criminal activity


> DION KDDI CORPORATION (incl. kddi-ipnw@ip.kddi.com)
IP ADDRESS OF NAMESERVER (ddns.volbon.net): 210.249.60.67
The IP address of this criminal nameserver is within your allocated address space.

This IP address is currently linked with the following fraudulent, criminal-operated domains:
ns.wi84.com A 210.249.60.67
ACTION: Black-hole the route to this address to prevent further criminal activity


> ASAHI-NET Asahi Net (incl. postmaster@asahi-net.or.jp)
IP ADDRESS OF NAMESERVER (ddns.voldon.com): 121.1.252.81
The IP address of this criminal nameserver is within your allocated address space.

This IP address is currently linked with the following fraudulent, criminal-operated domains:
ns.ia66.com A 121.1.252.81
ACTION: Black-hole the route to this address to prevent further criminal activity


The criminality of these domain names can be verified using the following SiteAdvisor link format, http://www.siteadvisor.com/lookup/?q=domainname.tld


> JAPAN CERT:
Notification has been sent to the host of the related japenese IP addresses reflected within this report. Please ensure that the machines behind these addresses are cleaned up, secured, and updated so that furhter malicious actions do not occur from these addresses.


CRIMINAL EVIDENCE: VIOLATION OF CAN-SPAM LAW

First count:
Delivered-To: xxx
Received: by 10.151.45.9 with SMTP id x9cs152374ybj;
Sun, 11 May 2008 06:54:38 -0700 (PDT)
Received: by 10.90.29.13 with SMTP id c13mr1131439agc.121.1210514077508;
Sun, 11 May 2008 06:54:37 -0700 (PDT)
Return-Path: <c3q0dbj7ldb2euz@yahoo.com>
Received: from gmail.com ([218.211.145.129])
by mx.google.com with ESMTP id 1si6638669agb.30.2008.05.11.06.54.33;
Sun, 11 May 2008 06:54:37 -0700 (PDT)
Received-SPF: neutral (google.com: 218.211.145.129 is neither permitted nor denied by domain of c3q0dbj7ldb2euz@yahoo.com) client-ip=218.211.145.129;
Authentication-Results: mx.google.com; spf=neutral (google.com: 218.211.145.129 is neither permitted nor denied by domain of c3q0dbj7ldb2euz@yahoo.com) smtp.mail=c3q0dbj7ldb2euz@yahoo.com
Message-Id: <4826fa9d.01025a0a.0e35.0321SMTPIN_ADDED@mx.google.com>
Reply-To: =?ISO-2022-JP?B?GyRCQG5FZz8/SH4bKEI=?= <c3q0dbj7ldb2euz@yahoo.com>
From: =?ISO-2022-JP?B?GyRCQG5FZz8/SH4bKEI=?= <c3q0dbj7ldb2euz@yahoo.com>
To: <xxx>
Subject: =?ISO-2022-JP?B?GyRCOGUyeRsoQg==?=
Date: Sun, 11 May 2008 22:54:10 +09:00
MIME-Version: 1.0
Content-Type: text/plain;
charset="iso-2022-jp"
Content-Transfer-Encoding: base64
X-Priority: 3
X-MSMail-Priority: Nomal
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.3138

GyRCM1hAODt+QmUkKyRpRDkkJCQzJEhJVSQtOWckQyRGJCQkP0hgJEgbKEIyNBskQjpQJEc3azonJDckXiQ3JD8hIxsoQg0KGyRCTWJHLyRLPVA7OiEjGyhCDQobJEIkPSRsJCskaSQqJGgkPRsoQjEwGyRCRy8hIxsoQg0KGyRCJGgkJiRkJC87UjYhJCw8aiQrJGlOJSRsISI7ZCQsIVY9dyRIJDckRiRkJGo7RCQ3JD8kMyRIIVckcjlNJCgkayRoJCYkSyRKJGokXiQ3JD8hIxsoQg0KDQoNCg0KGyRCO2QhIkE0QTNNNyRzJEckSiQrJEMkPyRKJCEhRCRDJEYhIxsoQg0KDQoNCg0KGyRCPGc/TTBKMzAkTkNLQC0kTyRbJEgkcyRJQ04kaiReJDskcyEjGyhCDQoNChskQjojJCskaSRHJGJOeDAmJDckPyQkISMbKEINChskQkNZJC8kTyRKJCQkRyQ5JGgkTSEpGyhCDQoNCg0KGyRCTTckcyRHJC8kQCQ1JCQhIxsoQg0KDQoNCmh0dHA6Ly9oYS11LWEtdS5jb20vP2JjPW1hcmsmbWU9ODFIN3NjSGJzSGVESHNCQms3UWZkQlBsSDhMNkYzSDZnTkg1T1BZVk02NzhoMQ0KDQoNCg0KDQoNChskQkdbPy41cUhdJE8kMyRBJGkkXiRHGyhCDQpjYW5jZWxAci5oYS11LWEtdS5jb20NCg==


Second count:
Delivered-To: xxx
Received: by 10.151.7.21 with SMTP id k21cs163944ybi;
Sat, 31 May 2008 16:57:13 -0700 (PDT)
Received: by 10.210.72.14 with SMTP id u14mr3284259eba.18.1212278225921;
Sat, 31 May 2008 16:57:05 -0700 (PDT)
Return-Path: <x5j0kks0ue4@yahoo.com>
Received: from gmail.com ([122.146.33.6])
by mx.google.com with ESMTP id k5si15306773nfh.39.2008.05.31.16.57.04;
Sat, 31 May 2008 16:57:05 -0700 (PDT)
Received-SPF: neutral (google.com: 122.146.33.6 is neither permitted nor denied by domain of x5j0kks0ue4@yahoo.com) client-ip=122.146.33.6;
Authentication-Results: mx.google.com; spf=neutral (google.com: 122.146.33.6 is neither permitted nor denied by domain of x5j0kks0ue4@yahoo.com) smtp.mail=x5j0kks0ue4@yahoo.com
Message-Id: <4841e5d1.05ed300a.6a9c.ffffddc3SMTPIN_ADDED@mx.google.com>
Reply-To: =?ISO-2022-JP?B?GyRCTTM5YRsoQg==?= <x5j0kks0ue4@yahoo.com>
From: =?ISO-2022-JP?B?GyRCTTM5YRsoQg==?= <x5j0kks0ue4@yahoo.com>
To: <xxx>
Subject: =?ISO-2022-JP?B?GyRCP006SiU1ITwlLyVrGyhC?=
Date: Sun, 01 Jun 2008 08:58:10 +09:00
MIME-Version: 1.0
Content-Type: text/plain;
charset="iso-2022-jp"
Content-Transfer-Encoding: base64
X-Priority: 3
X-MSMail-Priority: Nomal
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.3138

GyRCJDMkTiU1JSQlSCROMT8xRDxUJE80ezonPFQhIiREJF4kaj9NOkokRyQ5ISMbKEINChskQkM2RmEkS0lUS34kLCQiJGs/TSEjSVRLfiRPJEokLyRGJGJKTCROQ0tALSRITngwJiRyJDckPyQkJEgkJCQmSiM/dCROP006SiQsPTgkXiRqISIxPzFEJDckRiQkJF4kOSEjGyhCDQoNCmh0dHA6Ly9oYS11LWEtdS5jb20vP2JjPW1hcmsmbWU9NmszT1JqQzh6OUhESjZQMkg5M0hUSGpSNFBrYjg2NzY3SE42amo1RExMOUg5azhSNg0KGyRCIiY5LUpzQzRFdiROTTM5YSRHJDkhIyQzJE4lNSUkJUgkTzg1ITkhVjdrOickNyRGJEYkYk54MCYkYiQ3JD8kJCFXJEgkJCQmPXdALSQsPTgkXiRDJD8hViU1ITwlLyVrIVckXyQ/JCQkSiRiJE4kRyQ3JD8hIxsoQg0KGyRCPi8kNyQ6JERDSz13MnEwdyQsPTgkXiRqISIkKiQrJDIkNSReJEckMyROJGgkJiRLPVAycSQkJTUlJCVIJEgkSCQ3JEZOKSRBPmUkMiRrJDMkSCRLJEokaiReJDckPyEjGyhCDQobJEI4NSE5JCwlNSE8JS8layRKJE4kRz13QC0ycTB3P3QkSyRPPCs/LiQsJCIkaiReJDkhIzJxMHc9d0AtJE48QSRLJGI8Kz8uJHI7fSRDJEYkJCReJDkhIyFWPEEhVyRIJCQkJiROJE8hIjgrJD9MXCROO3YkRyRPJCIkaiReJDskcyEjOCskP0xcJE45JSRfJE8/TSQ9JGwkPiRsMGMkJiRiJE4kRyQ5JCskaSEjGyhCDQoNChskQjNkJGpAWiRDJEY/Pzd1JEs9UDJxJCQkcks+JGA9d0AtJD8kQSRQJCskaiRHJDkkTiRHISIkPCRSJDMkMyRHJTklRiUtJEolUSE8JUglSiE8JHI4KyREJDEkRiQvJEAkNSQkISMbKEINChskQkQ+QFxFRU9DJGQlYSE8JWskR08iTW0kciRIJGwkXiQ5JCwhIkFqPGokTj13QC0kTzR7Oic8VCRHJDkhIyVrITwlayRyPGkkaiEiJVclaSUkJVkhPCVIJE5BJzp3JEokSSRPJDckSiQkJGgkJiRLJCo0aiQkJDckXiQ5ISMbKEINCg0KaHR0cDovL2hhLXUtYS11LmNvbS8/YmM9bWFyayZtZT02azNPUmpDOHo5SERKNlAySDkzSFRIalI0UGtiODY3NjdITjZqajVETEw5SDlrOFI2DQoNCg0KDQoNCg0KDQoNCg0KDQoNCg0KGyRCR1s/LjVxSF0kTyQzJEEkaSReJEcbKEINCmNhbmNlbEByLmhhLXUtYS11LmNvbQ0K


This e-mail violates many requirements and restrictions set forth by the CAN-SPAM Law which can be found at the following link:
http://www.ftc.gov/bcp/conline/pubs/buspubs/canspam.shtm

Quote:
http://ha-u-a-u.com/?bc=mark&me=81H7scHbsHeDHsBBk7QfdBPlH8L6F3H6gNH5OPYVM678h1

Back to top
View users profile Send private message Visit posters website AIM Address Yahoo Messenger MSN Messenger
tembow

Blue Angel
Premium Member

Joined: Oct 10, 2005
Posts: 2945

Blue Security Premium

PostPosted: Thu Jun 12, 2008 2:40 am    Post subject:
Reply with quote

Delivery failure:
Arrival-Date: Thu, 12 Jun 2008 02:14:13 +0000 (UTC)

Final-Recipient: rfc822; cfc@cyberpolice.jp
Action: failed
Status: 5.4.4
Diagnostic-Code: X-Postfix; Host or domain name not found. Name service error
for name=cyberpolice.jp type=A: Host found but no data record of requested
type

Back to top
View users profile Send private message Visit posters website AIM Address
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> SIRT Reports All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You cannot post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer