>...
>> All DNS provided by:
>>
>> nserver: ns1.dnsm.net 218.7.120.70
>> nserver: ns2.dnsm.net 218.7.120.70
>>
>> And all domains registered to:
>>
>> owner: Roelf Van der Brug
>> email: admin(a)taiwanmedialtd.com
>> address: Singel 2
>> address: Jordaan
>> city: Amsterdam
>> state: --
>> postal-code: 1015JT
>> country: NL
>> phone: +31 84 220 2586
>
>We have seen fake registrations before, and this also fits there.
>Amsterdam is 020. not 084. The PO code fits Amsterdam however.
>
>domain: taiwanmedialtd.com
>status: lock
>owner: Mohammad Khan
>email: admin(a)taiwanmedialtd.com
>address: Kizilelma Caddesi No
>address: Findikzade
>city: Istanbul
>
>Funny, we have seen that also before.
>
>Bye,
>Raymond.
>_______________________________________________
>Discuss mailing list
>Discuss(a)lists.surbl.org
>http://lists.surbl.org/mailman/listinfo/discuss
>
The postal code would be correct, if it was on land, but for the on
the docks (and this is a boat slip), the proper postal code is 1013JT.
Also, there are two variants of the Istanbul address, one has just
"No" at the end, the other is "No. 62" - It is actually a rug shop in the
bazaar. The "really" old registrations used taiwantelco. com as the email
domain and dnst. net for name service. (I have found over a hundred, before
I started using other people's data - from Joe Wein's, Bill Stearns' and a
few other peoples collected and published lists I've found a few hundred
more.) My favorite's are still the ones which use the address from the
Beverley Hills 90210 TV show (mostly a couple of months ago).
The most recent Turkish address, Pakistani telephone number, and email
they are using is (Note: there is a bazaar at Oguzhan Caddesi No. 1 that fills
the entire block - this address does not exist, but the telephone is a valid
mobile phone registered in Pakistan and the email is functional):
Gulhan Ozgur
Oguzhan Caddesi No:2 Kat: 2
Denizli
TR-20100
TR
+9.2582411726
magicgoodman(a)yahoo.com
Paul Shupak
track(a)plectere.com
>-----Original Message-----
>From: Steven Champeon [mailto:schampeo@hesketh.com]
>Sent: Monday, May 16, 2005 11:32 AM
>To: discuss(a)lists.surbl.org
>Subject: [SURBL-Discuss] yet another joe job
>
>
>
>Please list the following domains:
>
>dnbfbsqs.com SPAMMER
>ghtnsecn.com SPAMMER
>rumbumbale.com SPAMMER
>tnashbsv.com SPAMMER
>turuntale.com SPAMMER
All but one were already in uribl.com. I added the other ;)
Keep up the good fight Steven!
--Chris
Excellent thank you. I wasn't sure if the actual sites they were linking
were involved.
/E.
-----Original Message-----
From: discuss-bounces(a)lists.surbl.org
[mailto:discuss-bounces@lists.surbl.org] On Behalf Of Raymond Dijkxhoorn
Sent: Monday, May 16, 2005 11:25 AM
To: SURBL Discussion list
Subject: RE: [SURBL-Discuss] German spam crap
Hi!
> So I saw the rule, but will any of the links in most of the messages be
> added to SURBL? It's my understanding this is virus related coming
> sometimes from internal hosts infected with a new class of virus that will
> turn the infected PC into a spam host. We do filter internal mail for
spam
> also so I thought I would check if the links in these messages will
> eventually make it to SURBL.
No, since the sites itself didnt do the spamrums, but were just abused
also. And no, thats not SURBL material...
>> http://mailscanner.prolocation.net/german.cf
>>
>> Ruleset to stop the Sober crap thats been going around like crazy
>> currently. The political spams written in german language...
>>
>> Hopefully it will help some people to stop this crap.
So get the ruleset if you wanna filter those.
Bye,
Raymond.
_______________________________________________
Discuss mailing list
Discuss(a)lists.surbl.org
http://lists.surbl.org/mailman/listinfo/discuss
Hi!
Its mentioned on the SA list also, but since we got some questions about
it from other people who didnt read it there:
http://mailscanner.prolocation.net/german.cf
Ruleset to stop the Sober crap thats been going around like crazy
currently. The political spams written in german language...
Hopefully it will help some people to stop this crap.
Bye,
Raymond.
>>
>>
>> >-----Original Message-----
>> >From: Steven Champeon [mailto:schampeo@hesketh.com]
>> >Sent: Monday, May 16, 2005 11:32 AM
>> >To: discuss(a)lists.surbl.org
>> >Subject: [SURBL-Discuss] yet another joe job
>> >
>> >
>> >
>> >Please list the following domains:
>> >
>> >dnbfbsqs.com SPAMMER
>> >ghtnsecn.com SPAMMER
>> >rumbumbale.com SPAMMER
>> >tnashbsv.com SPAMMER
>> >turuntale.com SPAMMER
>>
>> All but one were already in uribl.com. I added the other ;)
>>
>> Keep up the good fight Steven!
>
>Can't really help not ;)
>
>More domains just came in today:
>
>aupd.com
>bnik.com
>c5t.net
>d3w.net
>da9.net
>ei7.net
>el9.net
>f5s.net
>g3r.net
>h64.net
>l73.net
>lzac.com
>mq5.net
>myyv.com
>nf0.net
>nlav.com
>pi11.com
>pq4.net
>pqer.com
>przc.com
>rgry.com
>t6i.net
>uosb.com
>vf9.net
>viags.com
>wlue.com
>xi4.net
>yi4.net
>ymil.com
>
>Looks like a completely different spammer. :(
>
>All DNS provided by:
>
>nserver: ns1.dnsm.net 218.7.120.70
>nserver: ns2.dnsm.net 218.7.120.70
>
>And all domains registered to:
>
>owner: Roelf Van der Brug
>email: admin(a)taiwanmedialtd.com
>address: Singel 2
>address: Jordaan
>city: Amsterdam
>state: --
>postal-code: 1015JT
>country: NL
>phone: +31 84 220 2586
>admin-c: admin(a)taiwanmedialtd.com#0
>tech-c: admin(a)taiwanmedialtd.com#0
>billing-c: admin(a)taiwanmedialtd.com#0
>nserver: ns1.dnsm.net 218.7.120.70
>nserver: ns2.dnsm.net 218.7.120.70
>created: 2005-04-21 14:11:39 UTC
>modified: 2005-05-09 10:20:38 UTC
>expires: 2006-04-21 10:11:39 UTC
>
>--
>hesketh.com/inc. v: +1(919)834-2552 f: +1(919)834-2554 w: http://hesketh.com
>join us! http://hesketh.com/about/careers/account_manager.html join us!
>_______________________________________________
>Discuss mailing list
>Discuss(a)lists.surbl.org
>http://lists.surbl.org/mailman/listinfo/discuss
>
All taiwantelco/taiwanmedialtd - also uses addresses in Turkey and
telephone numbers in Pakistan. Look at the domain dnst. net for some
historic data. Many new domains are registered on a "Bay Drive" in
Beverley Hills - zipcodes 90210 and 90211 (no such street exists, except
on the TV show, it did) and some in New York and a few other places.
There is some relationship, maybe shared customers. Some of their
sites are hosted on the same machines as the multitrade group machines (see
the spamhaus records on both).
BTW. The 2 Singel address is a boat slip with no tenant (also the proper
postal code for the boat docks is 1013, not 1015). They just switched
registrars after Joker marked almost all of their domains as "invalid address".
See 900mg. com, aekb. com, b7x. com, cpko. com, dgko. com, and about a hundred
more.
Paul Shupak
track(a)plectere.com
So I saw the rule, but will any of the links in most of the messages be
added to SURBL? It's my understanding this is virus related coming
sometimes from internal hosts infected with a new class of virus that will
turn the infected PC into a spam host. We do filter internal mail for spam
also so I thought I would check if the links in these messages will
eventually make it to SURBL.
/E.
-----Original Message-----
From: discuss-bounces(a)lists.surbl.org
[mailto:discuss-bounces@lists.surbl.org] On Behalf Of Kevin A. McGrail
Sent: Sunday, May 15, 2005 1:06 PM
To: SURBL Discussion list
Subject: Re: [SURBL-Discuss] German spam crap
Thanks Raymond. I was wondering about that. It's been hammering a ton of
my mailing list subscriptions including sourceforge!
> Its mentioned on the SA list also, but since we got some questions about
> it from other people who didnt read it there:
>
> http://mailscanner.prolocation.net/german.cf
>
> Ruleset to stop the Sober crap thats been going around like crazy
> currently. The political spams written in german language...
>
> Hopefully it will help some people to stop this crap.
_______________________________________________
Discuss mailing list
Discuss(a)lists.surbl.org
http://lists.surbl.org/mailman/listinfo/discuss
>...
>
>when browsing unsubscribe links like http://www.signoffcorp.biz/uns.htm to
>enter a spamtrap address I just noticed that quite a few of the pages look
>extremely similar, DNS lookups show:
>
>$ host www.signoffcorp.biz
>www.signoffcorp.biz has address 217.107.217.8
>$ host www.bestcds.biz
>www.bestcds.biz has address 217.107.217.8
>$ host www.wonder-pills.com
>www.wonder-pills.com has address 217.107.217.8
>$ host www.multimed.ws
>www.multimed.ws has address 217.107.217.8
>
>$ host 217.107.217.8
>8.217.107.217.in-addr.arpa is an alias for 8.0/27.217.107.217.in-addr.arpa.
>8.0/27.217.107.217.in-addr.arpa domain name pointer webrider.ru.
>$ host webrider.ru
>webrider.ru has address 217.107.216.26
>
>so i wonder if it is possible (or already done) to also list (and save) the
>IPs of URIBL listed domains and check newly queried, yet unlisted domains
>against those IPs.
>
>any comments?
>
>regards,
>
>wolfgang
>_______________________________________________
>Discuss mailing list
>Discuss(a)lists.surbl.org
>http://lists.surbl.org/mailman/listinfo/discuss
>
All multitrade group - look at multitrade-corp. {biz,com}. Also,
you can lookup all those domains at rfc-ignorant.org for more comments.
BTW. You suggestion is the fundamental difference between IP based
BLs and RHS BLs - That is why there is a place in the world for both.
Paul Shupak
track(a)plectere.com
P.S. There are a least a few hundred domains at those IPs - I think there's
a partial list on one Spamhaus page (don't have the SBL at hand).