Google Groups Home
Help | Sign in
SUCCESS!
There are currently too many topics in this group that display first. To make this topic appear first, remove this option from another topic.
There was an error processing your request. Please try again.
flag
  Messages 1 - 25 of 207 - Collapse all   Newer >
The group you are posting to is a Usenet group. Messages posted to this group will make your email address visible to anyone on the Internet.
Your reply message has not been sent.
Your post was successful
Anonymous  
View profile
 More options Aug 4 2004, 2:46 pm
Newsgroups: news.admin.net-abuse.email
From: "Anonymous" <Anonym...@domain.invalid>
Date: Wed, 04 Aug 2004 18:46:41 GMT
Local: Wed, Aug 4 2004 2:46 pm
Subject: SUCCESS!
Boo-yah! Down another one goes... I found a registrar who's actually taking
action against one of our spammers.

Here's the message from InterCosmos.com:
Thanks for the information. We have put the domain tecmnsd.info on
registrar-hold. So the domain will stop resolving.
Donny

I sent them back a message, telling them about the spammer having other
URLs registered through them, 5 of them, so I may just get this spammer
shut down wholesale.

Here's hoping, anyway.


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
brad.madison  
View profile
 More options Aug 4 2004, 3:30 pm
Newsgroups: news.admin.net-abuse.email
From: "brad.madison" <brad.madi...@mail.tds.net>
Date: Wed, 04 Aug 2004 14:30:57 -0500
Local: Wed, Aug 4 2004 3:30 pm
Subject: Re: SUCCESS!

Anonymous wrote:
> Boo-yah! Down another one goes... I found a registrar who's actually taking
> action against one of our spammers.

Thank you.  Registrar action can be another effective way to pressure
the spammers.

    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Anonymous  
View profile
 More options Aug 4 2004, 3:30 pm
Newsgroups: news.admin.net-abuse.email
From: "Anonymous" <Anonym...@domain.invalid>
Date: Wed, 04 Aug 2004 19:30:25 GMT
Local: Wed, Aug 4 2004 3:30 pm
Subject: Re: SUCCESS!
"Anonymous" <Anonym...@domain.invalid> wrote in message

news:laaQc.459$of6.157@newssvr29.news.prodigy.com...

> I sent them back a message, telling them about the spammer having other
> URLs registered through them, 5 of them, so I may just get this spammer
> shut down wholesale.

My mistake, only two of the spammer's 5 domains were registered with
InterCosmos.com, but they're gone now... all Registrars should be as
responsive as InterCosmos.com. That's damned impressive. Now we wait for
the DNS changes to propagate, and they'll be off the air.

So, we should see:
http://www.tecmnsd.info/ES001/

http://www.mdnfdkk.info/OE017/

going away.

What's funny is that even though the domains are on Registrar hold, meaning
that DNS won't resolve for them anymore, my DNS server's still got the
required information to hit them with SpamVampire. So, nobody can visit,
except for me. And I'm visiting a lot. And I'm not allowing my DNS server
to update that DNS record, so I'll be able to continue hitting them for as
long as that server is serving those websites, even if DNS won't point
anyone else to them.

I've got to be hell on the poor spammers... nobody can visit their websites
except the one they don't want to have visit under any circumstances... too
much fun. But, it's all part of striking fear into the hearts of spammers
everywhere. If I can become world-famous in spammer circles as someone to
avoid, I'll have accomplished my goal.


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Alexis  
View profile
 More options Aug 4 2004, 4:25 pm
Newsgroups: news.admin.net-abuse.email
From: "Alexis" <Ale...@invalid.domain>
Date: Wed, 4 Aug 2004 16:25:53 -0400
Local: Wed, Aug 4 2004 4:25 pm
Subject: Re: SUCCESS!
"Anonymous" <Anonym...@domain.invalid> wrote in message

news:lPaQc.471$sx6.383@newssvr29.news.prodigy.com...

That's the Russian Spam Gang.

Intercosmos is DirectNIC. How did you contact them? What did you tell them?

How about going after the nameserver for lots of them- LIONSTAM.BIZ?


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Anonymous  
View profile
 More options Aug 4 2004, 5:06 pm
Newsgroups: news.admin.net-abuse.email
From: "Anonymous" <Anonym...@domain.invalid>
Date: Wed, 04 Aug 2004 21:06:46 GMT
Local: Wed, Aug 4 2004 5:06 pm
Subject: Re: SUCCESS!
"Alexis" <Ale...@invalid.domain> wrote in message

news:mDbQc.4499$Mg1.2542@bignews4.bellsouth.net...

> That's the Russian Spam Gang.

Yep, that's the Russian Spam Gang... I've been hammering the living hell
out of their websites with my SpamVampire
(http://www.hillscapital.com/antispam/index.htm feel free to grab the
source code and set up your own).

> Intercosmos is DirectNIC. How did you contact them? What did you tell

them?

I sent the LART to ab...@intercosmos.com, with a note at the top that they
were the registrar, and that they should check the registration information
for the site, and terminate it if it was found that the registration
information was invalid.

> How about going after the nameserver for lots of them- LIONSTAM.BIZ?

Tried that... the email address obtained by doing a dig on Lionstam.biz
bounces.

    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Anonymous  
View profile
 More options Aug 4 2004, 5:29 pm
Newsgroups: news.admin.net-abuse.email
From: "Anonymous" <Anonym...@domain.invalid>
Date: Wed, 04 Aug 2004 21:29:52 GMT
Local: Wed, Aug 4 2004 5:29 pm
Subject: Re: SUCCESS!
"Anonymous" <Anonym...@domain.invalid> wrote in message

news:GdcQc.494$g57.177@newssvr29.news.prodigy.com...

> Yep, that's the Russian Spam Gang... I've been hammering the living hell
> out of their websites with my SpamVampire
> (http://www.hillscapital.com/antispam/index.htm feel free to grab the
> source code and set up your own).

Hooo-BOY, we're going after these scumbags in a big way! I just got another
spam from them on a new domain they'd registered with InterCosmos. It's
already down...

http://ndffzzy.hksdhdj.info/ES001/?affiliate_id=234170&campaign_id=404

Man, when Donny at InterCosmos decides to bork a site, he doesn't mess
around.


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Dolphin  
View profile
 More options Aug 4 2004, 6:00 pm
Newsgroups: news.admin.net-abuse.email
From: Dolphin <usenet-Aug+na...@2004.dolphinwave.org>
Date: 4 Aug 2004 22:00:32 GMT
Local: Wed, Aug 4 2004 6:00 pm
Subject: Re: SUCCESS!
#begin  Ale...@invalid.domain.exe (or was it Alexis.com)
 message <mDbQc.4499$Mg1.2...@bignews4.bellsouth.net> reply:

<SNIP>

> Intercosmos is DirectNIC. How did you contact them? What did you tell them?

I have several such replies from Intercosmos, when CC:ing DirectNIC on spams.
But in all other cases I get their standard "we are just a Registrar, contact
ISPs" answer. No idea what triggers that "lucky" reply.

Dolphin.

--
 URL: http://www.DolphinWave.org
Mail: on the web page (no spam)
 ICQ: 6615461


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Jeff Higgins  
View profile
 More options Aug 4 2004, 6:46 pm
Newsgroups: news.admin.net-abuse.email
From: Jeff Higgins <JHigg...@Polarbay.com>
Date: Wed, 04 Aug 2004 18:46:44 -0400
Local: Wed, Aug 4 2004 6:46 pm
Subject: Re: SUCCESS!

>Man, when Donny at InterCosmos decides to bork a site, he doesn't mess
>around.

He didn't happen to give you his last name did he?

Jeff


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
glgxg  
View profile
 More options Aug 4 2004, 7:03 pm
Newsgroups: news.admin.net-abuse.email
From: glgxg <gl...@mfire.invalid.com>
Date: Wed, 04 Aug 2004 16:03:00 -0700
Subject: Re: SUCCESS!

Have Donny take a look at:

http://groups.google.com/groups?&scoring=d&q=%22%2FOE017%2F%22
http://groups.google.com/groups?&scoring=d&q=%22%2FES001%2F%22

He'll find plenty more...

Sample:

KLCBHGF.BIZ

klcbhgf.biz
IP Addresses:   61.128.198.12
IP Country:     CHINA
Reverse IP Lookup:      IP hosts 25 domains

Hosting Company Name:  
ICANN Registrar:        INTERCOSMOS MEDIA GROUP, INC. D/B/A DIRECTNIC.COM
Creation Date:  Jul 7 2004
Expiry Date:    Jul 6 2005

61.128.198.12 - IP hosts 25 Total Domains ...
Showing 1 - 25 out of 25

        Domain Name
1       AEAMDGI.INFO.
2       BDEAHCHA.INFO.
3       BHGNCGE.INFO.
4       BJCKKBFF.INFO.
5       CAIBGJC.BIZ.
6       CBIDABJ.INFO.
7       CKLIBCDN.INFO.
8       ENLDLID.INFO.
9       FDGFDBI.BIZ.
10      FKMJECB.INFO.
11      FMLAECCJ.BIZ.
12      GHCCLCCC.BIZ.
13      IHJJFJDF.INFO.
14      INCBGGC.INFO.
15      JJGLCLLJ.INFO.
16      KFJLFJKA.BIZ.
17      KIHGGCF.INFO.
18      KJFDMJE.INFO.
19      KLCBHGF.BIZ.
20      LDDEKFAN.INFO.
21      MFCALEL.BIZ.
22      MHCNJCNN.INFO.
23      MKJFKBE.INFO.
24      MMHLIFID.BIZ.
25      NFKIIJL.INFO.


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Jeff Higgins  
View profile
 More options Aug 4 2004, 7:32 pm
Newsgroups: news.admin.net-abuse.email
From: Jeff Higgins <JHigg...@Polarbay.com>
Date: Wed, 04 Aug 2004 19:32:11 -0400
Local: Wed, Aug 4 2004 7:32 pm
Subject: Re: SUCCESS!
    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
glgxg  
View profile
 More options Aug 4 2004, 8:12 pm
Newsgroups: news.admin.net-abuse.email
From: glgxg <gl...@mfire.invalid.com>
Date: Wed, 04 Aug 2004 17:12:55 -0700
Local: Wed, Aug 4 2004 8:12 pm
Subject: Re: SUCCESS!

Thanks, I forgot they are back up.

Many of those on that list that I gave for IP 61.128.198.12 are
registered at namebay.com.  It appears that BUENOCARTO.INFO has 27
domain names registered, all associated with this spam group.

BUENOCARTO.INFO doesn't appear on Polarbeach because it doesn't resolve
and they apparently only used it to sign up the other spam domains.
Here is the info:

[Note: using the whois.namebay.com server reveals the actual registrar
while whois.afilias.info does not]

contacting server whois.namebay.com

Domain Name : BUENOCARTO.INFO
Created On : 2004-07-01
Expiration Date : 2005-07-01
Status : ACTIVE
Registrant Name : Valery Binanaka
Registrant Street1 : Bolshoy Kamenniy Most 21, 14
Registrant City : Moscow
Registrant State/Province  : RU
Registrant Postal Code : 132423
Registrant Country : RU
Admin Handle : VB38284
Admin Name : Valery Binanaka
Admin Street1 : Bolshoy Kamenniy Most 21, 14
Admin City : Moscow
Admin State/Province : RU
Admin Postal Code : 132423
Admin Country : RU
Admin Phone : +7.6490189
Admin Email : valerybinan...@mail.ru
Tech Handle : VB38284
Tech Name : Valery Binanaka
Tech Street1 : Bolshoy Kamenniy Most 21, 14
Tech City : Moscow
Tech State/Province : RU
Tech Postal Code : 132423
Tech Country : RU
Tech Phone : +7.6490189
Tech Email : valerybinan...@mail.ru
Billing Handle : VB38284
Billing Name : Valery Binanaka
Billing Street1 : Bolshoy Kamenniy Most 21, 14
Billing City : Moscow
Billing State/Province : RU
Billing Postal Code : 132423
Billing Country : RU
Billing Phone : +7.6490189
Billing Email : valerybinan...@mail.ru
Name Server : FIRST.BUENOCARTO.INFO
Name Server : SECOND.BUENOCARTO.INFO
Name Server : THIRD.BUENOCARTO.INFO
Name Server : ADDON.BUENOCARTO.INFO
Registrar Name : NAMEBAY
Registrar WebSite : http://www.namebay.com

FIRST.BUENOCARTO.INFO = 221.143.42.209 / HANARO
SECOND.BUENOCARTO.INFO = 221.139.2.84 / HANARO
THIRD.BUENOCARTO.INFO = 61.128.198.10 / CHINANET-CQ
ADDON.BUENOCARTO.INFO = 219.146.151.49 / CHINATELECOM-sd

Total Domains Trend - BUENOCARTO.INFO

Weeks      Total Domains        
08/02/04        27      
07/26/04        27      
07/19/04        27      
07/12/04        19      


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.