CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

[SIRT#187353] dating site on on qop17.com /volbon.com voldon

 
Post new topic   Reply to topic       All -> FavForums -> SIRT Reports [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
ahoier

SIRT Handler


Joined: Jan 14, 2006
Posts: 1118
Location: USA

PostPosted: Thu Jun 12, 2008 3:07 am    Post subject: [SIRT#187353] dating site on on qop17.com /volbon.com voldon
Reply with quote

Spam Alert
 
 Full Report: CastleCops Link/dating_site_spam187353.html
 
 Changed status to confirmed spam.Consumed following related reports:

[187354] http://qop17.com/u04/?me=lH8jeH7H9LMD88888a6PVcHBp8G2FHdCN2BL5NH5L4WyH88
[187355] http://qop17.com/u04/?me=XHB8f9H9W6Z4H94H4Hs8I87yH5SM9LqfawN7kH9H8JH6i75W83
IP Converted: 220.214.94.104

dword = 3705036392
hex1 = 0xdcd65e68
hex2 = 0xdc.0xd6.0x5e.0x68
oct = 0334.0326.0136.0150
View CIDR AS4732 Report: http://www.cidr-report.org/cgi-bin/as-report?as=4732

"4732 | JP | apnic | 1995-08-30 | DION KDDI CORPORATION"<br />
Extended information for AS4732:
State/Province:
Country: jp
Responsible Domain: kddi.com
Abuse Email: abuse@dion.ne.jp
View CIDR AS2516 Report: http://www.cidr-report.org/cgi-bin/as-report?as=2516

"2516 | JP | apnic | 2002-04-05 | KDDI KDDI CORPORATION"<br />
Extended information for AS2516:
State/Province:
Country: jp
Responsible Domain: kddi.com
Abuse Email: abuse@dion.ne.jp
IP Converted: 210.157.193.151

dword = 3533554071
hex1 = 0xd29dc197
hex2 = 0xd2.0x9d.0xc1.0x97
oct = 0322.0235.0301.0227
View CIDR AS4704 Report: http://www.cidr-report.org/cgi-bin/as-report?as=4704

"4704 | JP | apnic | 1995-08-30 | SANNET NTT DATA SANYO SYSTEM"<br />
Extended information for AS4704:
State/Province:
Country: jp
Responsible Domain: sannet.ne.jp
Abuse Email: admin@sannet.ne.jp
View CIDR AS2516 Report: http://www.cidr-report.org/cgi-bin/as-report?as=2516

"2516 | JP | apnic | 2002-04-05 | KDDI KDDI CORPORATION"<br />
Extended information for AS2516:
State/Province:
Country: jp
Responsible Domain: kddi.com
Abuse Email: abuse@dion.ne.jp
IP Converted: 121.1.252.81

dword = 2030173265
hex1 = 0x7901fc51
hex2 = 0x79.0x1.0xfc.0x51
oct = 0171.01.0374.0121
View CIDR AS4685 Report: http://www.cidr-report.org/cgi-bin/as-report?as=4685

"4685 | JP | apnic | 1995-08-30 | ASAHI-NET Asahi Net"<br />
Extended information for AS4685:
State/Province:
Country: jp
Responsible Domain: asahi-net.or.jp
Abuse Email: postmaster@asahi-net.or.jp


Criminal Evidence

See the McAfee Site Advisor information at http://siteadvisor.com/sites/qop17.com


> ENOM, INC.
REGISTRATION OF THE WEB SITE: qop17.com
ACTION: To suspend this criminal site which breaks your terms of service, set the domain status to clientHold


> TUCOWS INC. (voldon.com)
> YESNIC CO. LTD. (volbon.net)
REGISTRATION OF THE NAME SERVERS
These name servers are registered by criminals to resolve only illegal web sites. This breaks your terms of service. You can safely suspend them:
ddns.volbon.com (210.157.193.151)
ddns.voldon.com (121.1.252.81)

ACTION: To suspend these name servers successfully, follow these steps.
1. set the ns Address records to a non-routable address, such as 127.0.0.1 or 61.61.61.61.
2. Set the domain status to clientUpdateProhibited, clientTransferProhibited, clientDeleteProhibited, and clientHold


> DION KDDI CORPORATION
> KDDI KDDI CORPORATION
IP ADDRESS OF HOST: 220.214.94.104
The IP address of this criminal site is within your allocated address space.

ACTION: Black-hole the route to this address to prevent further criminal activity


> SANNET NTT DATA SANYO SYSTEM
> KDDI KDDI CORPORATION (incl. taya@sannet.ad.jp,mmatsu@sannet.ad.jp)
IP ADDRESS OF NAMESERVER (ddns.volbon.com): 210.157.193.151
The IP address of this criminal nameserver is within your allocated address space.

ACTION: Black-hole the route to this address to prevent further criminal activity


> ASAHI-NET Asahi Net
> KDDI KDDI CORPORATION
IP ADDRESS OF NAMESERVER (ddns.voldon.com): 121.1.252.81
The IP address of this criminal nameserver is within your allocated address space.

This IP address is currently linked with the following fraudulent, criminal-operated domains:
ns.ia66.com A 121.1.252.81
ACTION: Black-hole the route to this address to prevent further criminal activity


The criminality of these domain names can be verified using the following SiteAdvisor link format, http://www.siteadvisor.com/lookup/?q=domainname.tld

> Janan CERT
These hosts, ISPs, and IP addresses are within your jurisdiction. Please work with these hosts, individuals, and companies allocated to these IP addresses to ensure that all systems are updated, patched of all vulnerabilties, and all passwords are strengthened.


CRIMINAL EVIDENCE: VIOLATION OF CAN-SPAM LAW

Delivered-To: xxx
Received: by 10.151.45.9 with SMTP id x9cs166735ybj;
Sun, 11 May 2008 13:07:50 -0700 (PDT)
Received: by 10.70.118.12 with SMTP id q12mr9536214wxc.40.1210536469462;
Sun, 11 May 2008 13:07:49 -0700 (PDT)
Return-Path: <o0jecbkt@yahoo.com>
Received: from gmail.com ([60.20.7.64])
by mx.google.com with ESMTP id h15si8767202wxd.38.2008.05.11.13.07.45;
Sun, 11 May 2008 13:07:49 -0700 (PDT)
Received-SPF: neutral (google.com: 60.20.7.64 is neither permitted nor denied by domain of o0jecbkt@yahoo.com) client-ip=60.20.7.64;
Authentication-Results: mx.google.com; spf=neutral (google.com: 60.20.7.64 is neither permitted nor denied by domain of o0jecbkt@yahoo.com) smtp.mail=o0jecbkt@yahoo.com
Message-Id: <48275215.0f86460a.0c2c.ffff81feSMTPIN_ADDED@mx.google.com>
Reply-To: =?ISO-2022-JP?B?GyRCOTZOLDcvGyhC?= <o0jecbkt@yahoo.com>
From: =?ISO-2022-JP?B?GyRCOTZOLDcvGyhC?= <o0jecbkt@yahoo.com>
To: <xxx>
Subject: =?ISO-2022-JP?B?GyRCJSolOSU5JWEhQRsoQlZvbC4y?=
Date: Mon, 12 May 2008 05:07:09 +09:00
MIME-Version: 1.0
Content-Type: text/plain;
charset="iso-2022-jp"
Content-Transfer-Encoding: base64
X-Priority: 3
X-MSMail-Priority: Nomal
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.3138

GyRCOiMycyROJE4lKiU5JTklYSRPJTolUCVqJDMkTkp9ISobKEINCg0KaHR0cDovL3FvcDE3LmNvbS91MDQvP21lPWxIN2luSDdIOUxNRDg4ODg4YTZQVmNIQnA4RzJGSGRKSDg1QjdmSDZYTDRidEg4OA0KDQobJEIkSiQrJEokK0I+P00kSyRPOEAkKCRKJCRIYD13JE5Ia0wpJHJKOSQtPVAkOyEqGyhCDQoNCg0KDQobJEJHWz8uNXFIXSRPJDMkQSRpJF4kRxsoQg0Kbm9uZWVkQHJlamVjdC5xb3AxNy5jb20NCg==


Second count:
Delivered-To: xxx
Received: by 10.151.45.9 with SMTP id x9cs335116ybj;
Mon, 19 May 2008 08:34:31 -0700 (PDT)
Received: by 10.141.151.20 with SMTP id d20mr3749097rvo.108.1211211270539;
Mon, 19 May 2008 08:34:30 -0700 (PDT)
Return-Path: <f3hj4a99b6k@yahoo.com>
Received: from gmail.com ([221.201.65.142])
by mx.google.com with ESMTP id g31si13355928rvb.2.2008.05.19.08.34.28;
Mon, 19 May 2008 08:34:30 -0700 (PDT)
Received-SPF: neutral (google.com: 221.201.65.142 is neither permitted nor denied by domain of f3hj4a99b6k@yahoo.com) client-ip=221.201.65.142;
Authentication-Results: mx.google.com; spf=neutral (google.com: 221.201.65.142 is neither permitted nor denied by domain of f3hj4a99b6k@yahoo.com) smtp.mail=f3hj4a99b6k@yahoo.com
Message-Id: <48319e06.1f538c0a.5fa6.ffff9854SMTPIN_ADDED@mx.google.com>
Reply-To: =?ISO-2022-JP?B?GyRCOTZOLDcvGyhC?= <f3hj4a99b6k@yahoo.com>
From: =?ISO-2022-JP?B?GyRCOTZOLDcvGyhC?= <f3hj4a99b6k@yahoo.com>
To: <xxx>
Subject: =?ISO-2022-JP?B?GyRCJSolOSU5JWEhQRsoQlZvbC4y?=
Date: Tue, 20 May 2008 00:33:36 +09:00
MIME-Version: 1.0
Content-Type: text/plain;
charset="iso-2022-jp"
Content-Transfer-Encoding: base64
X-Priority: 3
X-MSMail-Priority: Nomal
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.3138

GyRCOiMycyROJE4lKiU5JTklYSRPJTolUCVqJDMkTkp9ISobKEINCg0KaHR0cDovL3FvcDE3LmNvbS91MDQvP21lPWxIOGplSDdIOUxNRDg4ODg4YTZQVmNIQnA4RzJGSGRDTjJCTDVOSDVMNFd5SDg4DQoNChskQiRKJCskSiQrQj4/TSRLJE84QCQoJEokJEhgPXckTkhrTCkkcko5JC09UCQ7ISobKEINCg0KDQoNChskQkdbPy41cUhdJE8kMyRBJGkkXiRHGyhCDQpub25lZWRAcmVqZWN0LnFvcDE3LmNvbQ0K


Third count:
Delivered-To: xxx
Received: by 10.150.11.15 with SMTP id 15cs10303ybk;
Thu, 29 May 2008 07:37:15 -0700 (PDT)
Received: by 10.114.36.1 with SMTP id j1mr4420886waj.7.1212071833913;
Thu, 29 May 2008 07:37:13 -0700 (PDT)
Return-Path: <mhm4vhckhbmy3b2@yahoo.com>
Received: from gmail.com ([221.201.64.44])
by mx.google.com with ESMTP id n20si1573324pof.0.2008.05.29.07.37.09;
Thu, 29 May 2008 07:37:13 -0700 (PDT)
Received-SPF: neutral (google.com: 221.201.64.44 is neither permitted nor denied by domain of mhm4vhckhbmy3b2@yahoo.com) client-ip=221.201.64.44;
Authentication-Results: mx.google.com; spf=neutral (google.com: 221.201.64.44 is neither permitted nor denied by domain of mhm4vhckhbmy3b2@yahoo.com) smtp.mail=mhm4vhckhbmy3b2@yahoo.com
Message-Id: <483ebf99.14be600a.51e6.2462SMTPIN_ADDED@mx.google.com>
Reply-To: =?ISO-2022-JP?B?GyRCOTZOLDcvGyhC?= <mhm4vhckhbmy3b2@yahoo.com>
From: =?ISO-2022-JP?B?GyRCOTZOLDcvGyhC?= <mhm4vhckhbmy3b2@yahoo.com>
To: <xxx>
Subject: =?ISO-2022-JP?B?GyRCJSolOSU5JWEhQRsoQlZvbC4y?=
Date: Thu, 29 May 2008 23:37:01 +09:00
MIME-Version: 1.0
Content-Type: text/plain;
charset="iso-2022-jp"
Content-Transfer-Encoding: base64
X-Priority: 3
X-MSMail-Priority: Nomal
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.3138

GyRCOiMycyROJE4lKiU5JTklYSRPJTolUCVqJDMkTkp9ISobKEINCg0KaHR0cDovL3FvcDE3LmNvbS91MDQvP21lPVhIQjhmOUg5VzZaNEg5NEg0SHM4STg3eUg1U005THFmYXdON2tIOUg4Skg2aTc1VzgzDQoNChskQiRKJCskSiQrQj4/TSRLJE84QCQoJEokJEhgPXckTkhrTCkkcko5JC09UCQ7ISobKEINCg0KDQoNChskQkdbPy41cUhdJE8kMyRBJGkkXiRHGyhCDQpub25lZWRAcmVqZWN0LnFvcDE3LmNvbQ0K


These e-mails violates many requirements and restrictions set forth by the CAN-SPAM Law which can be found at the following link:
http://www.ftc.gov/bcp/conline/pubs/buspubs/canspam.shtm

Quote:
http://qop17.com/u04/?me=lH7inH7H9LMD88888a6PVcHBp8G2FHdJH85B7fH6XL4btH88

Back to top
View users profile Send private message Visit posters website AIM Address Yahoo Messenger MSN Messenger
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> SIRT Reports All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You cannot post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer