CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

[SIRT#197226] King Replica on mosttall.com / broyaoise.com

 
Post new topic   Reply to topic       All -> FavForums -> SIRT Reports [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
jimVO

Lieutenant
Lieutenant
Premium Member

Joined: Mar 17, 2008
Posts: 152
Location: USA
Premium

PostPosted: Mon Jul 07, 2008 3:53 pm    Post subject: [SIRT#197226] King Replica on mosttall.com / broyaoise.com
Reply with quote

Spam Alert
 
 Full Report: CastleCops Link/King_Replica_spam197226.html
 
 Changed status to confirmed spam.IP Converted: 218.106.90.235

dword = 3664403179
hex1 = 0xda6a5aeb
hex2 = 0xda.0x6a.0x5a.0xeb
oct = 0332.0152.0132.0353
View CIDR AS4837 Report: http://www.cidr-report.org/cgi-bin/as-report?as=4837

"4837 | CN | apnic | 2001-09-17 | CHINA169-BACKBONE CNCGROUP China169 Backbone"<br />
Extended information for AS4837:
State/Province:
Country: cn
Responsible Domain: cnc-noc.net
Abuse Email: abuse@cnc-noc.net
Criminal Evidence

See the Spam Wiki entry at http://www.spamtrackers.eu/wiki/index.php?title=King_Replicas
or from China: http://www.spamtrackers.hk/wiki/index.php?title=King_Replicas
See the McAfee Site Advisor information at http://siteadvisor.com/sites/mosttall.com


> 35 TECHNOLOGY CO
REGISTRATION OF THE WEB SITE: mosttall.com
ACTION: To suspend this criminal site which breaks your terms of service, set the domain status to clientHold


> HICHINA
REGISTRATION OF THE NAME SERVERS
These name servers are registered by criminals to resolve only illegal web sites. This breaks your terms of service. You can safely suspend them:
ns4.broyaoise.com 60.172.219.14 60.172.219.14 Blacklisted China URIBL SBL65572 | ip=60.172.219.14 |
ns3.broyaoise.com 218.106.90.235 218.106.90.235 Blacklisted China URIBL SBL63494 | SBL65358 |

ACTION: To suspend these name servers successfully, follow these steps.
1. set the ns Address records to a non-routable address, such as 127.0.0.1 or 61.61.61.61.
2. Set the domain status to clientUpdateProhibited, clientTransferProhibited, clientDeleteProhibited, and clientHold


> CNCGROUP
IP ADDRESS OF HOST: 218.106.90.235
The IP address of this criminal site is within your allocated address space.
ACTION: Black-hole the route to this address to prevent further criminal activity

Quote:
http://mosttall.com

Back to top
View users profile Send private message
tembow

Blue Angel
Premium Member

Joined: Oct 10, 2005
Posts: 2931

Blue Security Premium

PostPosted: Tue Jul 08, 2008 9:46 pm    Post subject:
Reply with quote

Arrival-Date: Mon, 7 Jul 2008 15:53:34 +0000 (UTC)

Final-Recipient: rfc822; liveperson@35.cn
Action: failed
Status: 5.0.0
Remote-MTA: dns; mx.35.cn
Diagnostic-Code: smtp; 553 Email was rejected by 35 AntiSpam System,
id=mx.35.cn.23856.1215445634

Back to top
View users profile Send private message Visit posters website AIM Address
tembow

Blue Angel
Premium Member

Joined: Oct 10, 2005
Posts: 2931

Blue Security Premium

PostPosted: Tue Jul 08, 2008 9:53 pm    Post subject:
Reply with quote

Arrival-Date: Mon, 7 Jul 2008 15:53:34 +0000 (UTC)

Final-Recipient: rfc822; english@hichina.com
Action: failed
Status: 5.0.0
Remote-MTA: dns; mxrelay.hichina.com
Diagnostic-Code: smtp; 553 This target address is not our MX service client.

Final-Recipient: rfc822; mamj@hichina.com
Action: failed
Status: 5.0.0
Remote-MTA: dns; mxrelay.hichina.com
Diagnostic-Code: smtp; 553 This target address is not our MX service client.

Back to top
View users profile Send private message Visit posters website AIM Address
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> SIRT Reports All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You cannot post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer