CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 949
Comments: 28
block bottom
spacer spacer

forum spambots

 
Post new topic   Reply to topic       All -> FavForums -> Phishing, Fraud and Dastardly Deeds [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
logicman_alf

Corporal
Corporal


Joined: Aug 18, 2006
Posts: 72
Location: UK

PostPosted: Sat Jun 28, 2008 7:00 am    Post subject: forum spambots
Reply with quote

Forum operators should be on their guard against a new generation of forum spambots.

These use a very primitive AI algorithm, a bit like the ALICE and ELIZA programs, snagging up a phrase and firing it back.

Typically, the bot will plant a 'thnx for that' message as an excuse to plant a 'sig' with hyperlinks.

The purpose there is to boost sites in google ratings.
A classic example of this would be bablorub's posts - just google it.

There have been recent posts by spambot
username boebtpstaacl

boebtpstaacl@8nfoblog.cn
ICQ 15663615

The following URLs are posted by this bot:

clicking on a credit card image shows url:
hxxp://seobox.net/in.cgi?16&group=forumbt
seobox is in some blacklists.
note the 'forumbt' - cute!

ordinary hypertext urls:

transfer-balance-offer-visa.prmotions-card-now.cn
creditcards-rewaeds-now.cn
transfer-balances-chase.amazing-carrds-now.cn
transfers-saving-limit-to.bonouscreditcard-now.cn
creditcards-incenctives-now.cn
transfer-balance-2000.cardsbenefits-now.cn
transfer-balance-search.creditpromotions-now.cn
0balance-transfer-transfer-balance.goodies-creditcards-now.cn
freebies-credit-now.cn
transfer-balance-offers-free.instantresultscardact-now.cn
transfur-airline-miles-to.cardbenefits-now.cn
banlance-transfer.card-advantages-now.cn
cardsbenefits-now.cn
transfer-balance-checks-amex.creditcard-flexiblerewards-now.cn
transfer-balance-credit-cards.prmotionscredit-now.cn
loyaltyprogramscreditcards-now.cn
transfer-balance-amount-until.bestdards-now.cn
creditspecialpromos-now.cn
transfer-account-balance.prizescreditcard-now.cn
insentivescreditcard-now.cn

I have tagged all these in WOT and SA as a fraud alert.
They can only have one purpose: a criminal purpose.

Any help with checking these further will be greatly appreciated.

Back to top
View users profile Send private message
logicman_alf

Corporal
Corporal


Joined: Aug 18, 2006
Posts: 72
Location: UK

PostPosted: Sun Jun 29, 2008 3:24 am    Post subject: more spambot posts/links
Reply with quote

A new batch of credit-card fraud sites.

looks like seobox is the control HQ for a lot of spambots!

botname: boebtpstaabh

links:
hxxp://seobox.net/in.cgi?16&group=forumbt. hxxp://seobox.net/in.cgi?16&group=forumbt.hxxp://seobox.net/in.cgi?16&group=forumbt.hxxp://seobox.net/in.cgi?16&group=fbtlapr

hxxp://seobox.net/in.cgi?16&group=forumbt. hxxp://seobox.net/in.cgi?16&group=fbtlapr.hxxp://seobox.net/in.cgi?16&group=fbtlapr.hxxp://seobox.net/in.cgi?16&group=fbtexe

domains:
amazingcardit-now.cn
approval-transfer-balances-instant.credit-rewarding-now.cn
beneiftscredit-now.cn
carddinstan-now.cn
craditeexcellant-now.cn
freeholderscard-now.cn
redemptioncreditcard-now.cn
rrewardscreditcards-now.cn
transaction-transfer-balance-with.boness-cards-now.cn
transfer-balance-chase.dobblemoney-creditcard-now.cn
transfer-balance-compare-deals.creditcardscrisereward-now.cn
transfer-balance-fees-apr.besr-dredit-now.cn
transfer-balance-offer-visa.prmotions-card-now.cn
transfer-balance-with-cap.amazing-crdeitcards-now.cn
transfer-balence-offers.incenctives-card-now.cn
transfer-credit-cards-best6362491.crdditcard-goodcredit-now.cn
transfer-interest-rate-past.cardite-instantdecition-now.cn
transfers-approval-balance-instant.cardrewards-credit-now.cn
transfers-balance-balance-life6267840.credit-rewardpoints-now.cn
washington-balance-tranfer-mutual.bestdealscardss-now.cn

and no doubt thousands more to come?

Please note that all domains in 2 posts are verbatim,
spelling errors are spammer's errors.

Back to top
View users profile Send private message
AlphaCentauri

SIRT Handler
Premium Member

Joined: Nov 20, 2003
Posts: 2763

Premium

PostPosted: Sun Jun 29, 2008 3:29 am    Post subject:
Reply with quote

In an interesting twist, I have also seen this type of forum post that appeared to be trying to get higher search engine ranking than a page exposing a group of websites as scams.

During that time period, the sites themselves were unavailable, but multiple forums had users register with the site URLs as unames (eg, a new user named "scamsite.com" or whatever) and including that URL and perhaps one or two others of the group in his sig. The posts themselves were lame but innocuous and relatively on-topic, not typical spam that would be easily recognized as such.

Googling any of the domain names would produce pages and pages of these forum posts, with the page describing them as a scam pushed down in the ranking.

Back to top
View users profile Send private message
logicman_alf

Corporal
Corporal


Joined: Aug 18, 2006
Posts: 72
Location: UK

PostPosted: Sun Jun 29, 2008 4:34 am    Post subject:
Reply with quote

That's an interesting idea. Wink

It's a bit like when someone accused of being a spammer gets an injunction, as here:
http://courtnic.nic.in/dhcorder/dhcqrydisp_o.asp?pn=20089&yr=2008

Not much to say about that except to quote the official, public court document, where it was said in the bloggers defence
that he never claimed: "Tulip Lab is directly behind the spamming ".

Wink

Moderators: if there are, or may be, any legal issues here,
please feel free to delete my reference to what the court's official document says.

Back to top
View users profile Send private message
logicman_alf

Corporal
Corporal


Joined: Aug 18, 2006
Posts: 72
Location: UK

PostPosted: Sun Jun 29, 2008 6:00 am    Post subject:
Reply with quote

Domains list updated.

I have copied the list to:
http://www.mvps.org/winhelp2002/hosts.htm

If I find more, I'll post a fresh link to latest SA here.

http://www.siteadvisor.com/sites/excellent-credit-rates.cn/

Back to top
View users profile Send private message
logicman_alf

Corporal
Corporal


Joined: Aug 18, 2006
Posts: 72
Location: UK

PostPosted: Tue Jul 01, 2008 10:51 am    Post subject:
Reply with quote

This single domain was added to hosts file at winhelp2002 (see above)
track dot acclaimnetwork dot com

It's an affiliate site used by all above domains, and probably more.

Nicely spotted by these folks. Smile

Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Phishing, Fraud and Dastardly Deeds All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer