Barnu Rapatska / TotalPharmacy / WELCOME! Cheating House Wife Services / Date Lonely Wives
discountRxweb.com - Order Cialis Online and Save! lt;Secured Billing - Discreetly Shipped / How To Be A Red Hot Persuasion Wizard... In 20 Days Or Less!
DRUGS DIRECT: CHEAPEST DRUGS ON THE NET
Score = 87
This spammer uses web bugs and tagged URLs. Opening his spam with HTML & images enabled lets him know that your email address is valid. Following the links does too. Controls his own name servers. Sends from open proxies on trojaned computers. Changes domain name for redirecting pathes at least once a day. Fake whois data. Uses throwaway URLs that redirect to a URL tht tracks your email address and the affiliate ID then redircts to the pay off URL.
Fake names: Mush hashor, Radbergas, Olegas, Helmut Fischer, CHAS BUSHNELL, Bob Cooper, Barnu Rapatska, zopa cathlina, Stacey Gerstien, WebLove, Vadim Gablian, HomeViz, mathew barberstantonly, base advertising jump inc, lifetime, James Sweet, vashumat, James corona, mike mC Garythomason, bishopletsy trierson
Fake emails: olegas2003@spam.lv, helfischer1975@yahoo.com, chas@blazemail.com, bcooper@allsaintsfan.com, barnu@barnurapatska.com, support@emarketingdeals.com, admin@chillblow.com, infohelpteam@yahoo.com, admin@wifesmile.com, abbie@fusemail.com, joker2newdomains@yahoo.com, nameserver2004@yahoo.com
======================
Affiliate IDs:
Badboy
got
okok
ronn
====================
Samples of how redirect works:
----
http://hulbertwe.com/Ap6G9jCsQaWeokpJBXVfDrdni/
IP: 221.11.133.51
Reporting addresses:
abuse@cnc-noc.net
- Redirects to
http://dns-html2.com/hulbertwe.com/Ap6G9jCsQaWeokpJBXVfDrdni/
Rotating IPs
IP: 221.7.209.86 (chinanet)
IP: 221.11.133.51 (cnc-noc.net)
- Redirects to
Tadalafil_Home
http://partied.net/cs/?Badboy
IP: 211.147.228.102
Reporting addresses:
ct-abuse@abuse.sprint.net, abuse@gzidc.com, xuxinyu@gzidc.com
==================
http://meckbachgf.com/kepFbBOc17qdmUcl9kY7sPQTI/
Rotating IPs
IP: 219.254.32.74 (hanaro.com)
IP: 222.122.65.3 (kornet.net)
- Redirects to
http://dns-html2.com/meckbachgf.com/kepFbBOc17qdmUcl9kY7sPQTI/
IP: 219.254.32.74
Reporting addresses:
abuse@hanaro.com
- Redirects to
Tadalafil_Home
http://genuinely.net/cs/
?Badboy
IP: 63.105.204.170 (mci.com)
==========
http://opikdf.com/OwvWzzMxjHbuETFKn1zc2slNB/
UoO7KGtPNk.html
IP: 221.11.133.51 (chinanet)
- Redirects to:
http://dns-html2.com/opikdf.com/OwvWzzMxjHbuETFKn1zc2slNB/
IP: 219.254.32.74
Reporting addresses:
abuse@hanaro.com
Tadalafil_Home
IP: 219.254.32.74
http://dusked.biz/cs/?Badboy
219.254.32.74
Reporting addresses:
abuse@hanaro.com
======
DRUGS DIRECT: CHEAPEST DRUGS ON THE NET
http://hladiukds.net/IDSMmqTSngdX30JO7b6iXOxV7/
Rotating IPs:
IP: 211.143.29.222
IP: 219.254.32.74 (hanaro)
IP: 221.11.133.51 (chinanet)
- Redirects to
http://dns-html2.com/hladiukds.net/IDSMmqTSngdX30JO7b6iXOxV7/
IP: 219.254.32.74 (hanaro)
- Redirects to
http://dusked.biz/
IP: 61.232.205.187 (chinatietong)
Click to see a scam site
=================
http://venkatramanfg.com/D3P9pFi3uxt4rXn1vpaf6PM2l/
Rotating IPs:
219.254.32.74 (hanaro)
221.11.133.11 (chinanet)
- Redirects to:
http://dns-html2.com/venkatramanfg.com/D3P9pFi3uxt4rXn1vpaf6PM2l/
Rotating IPs:
219.254.32.74 (hanaro)
221.11.133.11 (chinanet)
IP: 221.11.133.11
- Redirects to:
Tadalafil_Home
http://www.hurtfully.com/rm/
http://hybridisms.com/cs/
http://hybridisms.com/extender/
http://visagraph.net/cs/
IP: 222.47.183.98, 222.47.183.126
Reporting addresses:
postmaster@chinatietong.com,
crnet_mgr@chinatietong.com,
crnet_tec@chinatietong.com
========
http://robinhoodty.com/SXKXOjQHeNYEUhUEEwWyeC0er/
Rotating IPs
IP: 211.143.29.222
Report to: 13908491010@hnmcc.com
IP: 219.254.32.74 (hanaro)
- Redirects to
http://dns-html2.com/robinhoodty.com/SXKXOjQHeNYEUhUEEwWyeC0er/
- Redirects to
Tadalafil_Home
http://gossipy.net/cs/
?Badboy
IP: 210.21.117.104
Reporting addresses:
abuse@chinanet.cn.net
==================
http://timhunterbv.com/TsRHFEnzxsGTlTyZAjWP1Fy9t/
- Redirects to
http://dns-html2.com/timhunterbv.com/TsRHFEnzxsGTlTyZAjWP1Fy9t/
- Redirects to
Tadalafil_Home
http://gossipy.net/cs/
?Badboy
IP: 210.21.117.104
Reporting addresses:
abuse@chinanet.cn.net
=======================
http://furbelows.net/cs/?got
http://howsoever.net/specials.php?okok
http://unpardoned.net/rm.php?got
IP: 211.147.228.102
Reporting addresses:
ct-abuse@abuse.sprint.net
Third parties interested in reports:
abuse@gzidc.com
=============
http://confuting.com/cs/?got
http://confuting.com/spur/?ronn
IP: 211.147.228.102
Reporting addresses:
ct-abuse@abuse.sprint.net
Third parties interested in reports:
abuse@gzidc.com
Alias:
Jeffrey Metzinger
leimomi01@tom.com
Name Servers:
ns1.unheeded.net
ns2.unheeded.net
========
http://genuinely.net/extender/
http://revetments.net/cs/
IP: 210.21.117.112
Reporting addresses:
abuse@chinanet.cn.net
========
http://huichimingfd.net/vnZW...
http://dns-html2.com/huichimingfd.net/vnZW...
Rotating IPs
IP: 220.202.248.55 (cnuninet.com)
IP: 221.11.133.11 (cnc-noc.net)
=======
http://arthurpetrfdon.net/VSTT...
IP: 221.10.201.174 (chinanet)
=======
http://friggings.net/cs/
?got
http://gravesides.com/spur/
?ronn
http://provencaux.net/cs/
?got
IP: 63.105.204.170
Reporting addresses:
abuse@mci.com
============
http://renisd.com/ZdTy...
IP: 210.22.50.103
=======
http://raywilsoncv.net/o2t8...
IP: 221.10.201.174
========
http://arianeyuui.com/5Cw...
http://artmanesd.com/Mf8...
IP: 221.11.134.15 (cnc-noc.net)
======
http://kamelwe.com/zgkrYEoWHlBKiCuxgwCTCCLyi/
IP: 221.11.133.51 (cnc-noc.net)
========
http://brunierfd.net/utLq...
IP: 222.122.65.3 (kornet)
================
http://katchemack.net/cs/
?ronn
IP: 210.21.117.113 (chinanet.cn.net)
=============
http://bulwarking.com/cs/?ronn
http://depletive.com/cs/?got
http://endosonic.com/spur/?got
http://impactions.net/cs/?ronn
http://impactions.net/rm.php?got
http://impactions.net/spur/?got
http://snorter.net/cs/?ronn
http://katchemack.net/cs/?ronn
http://zigzagging.net/cs/?okok
IP: 210.21.117.104 (chinanet)
===============
Dead on arrival
http://nanyourtds.com/this...
http://scottyoungwq.net/ALzf...
http://yarigatakeer.net/4ZSo...
=================
http://borrellyqw.net/eXxSawzbSncapRa7azUphiN4l/
IP: 221.11.133.51 (chinanet)
=========================
http://soddenness.net/cs/?got
IP: 222.47.183.99 (chinatietong)
================
http://edisonacv.net/fPQHVnUHdA7cAShpwMyknStfg/
IP: 220.202.248.55 (chinanet)
============
http://dusked.biz/cs/
http://dusked.biz/extender/
http://dusked.biz/spur/
IP: 61.232.205.187 (chinatietong)
=============
http://katchemack.net/spur/
IP: 61.232.205.186 (chinatietong)
==================
Score = 25
No URL. Pump and dump stock scam sent via open proxies on hijacked computers. Started with plain text email but now sends base 64 encoded with microscopic text that I can't read.
============
Related scams:
Eldorado Exploration
CD TRADING CARDS (CDTD)
Nomad International Inc.
Gulf Biomedical Corp
Crystal Graphite Corporation
Martin Nutraceuticals, Inc.
Northeast Development Corporation (NSC)
Eldorado Exploration Inc. (Pink Sheets: EDEX)
EXPLOSIVE PICK FOR OUR MEMBERS
The Daily Stock Barometer
Emerging Growth 0pportunity
Investor Alert Newsletter
Rx Processing Corp.
China World Trade Corporation
6/24/05
This scam spewing asshole moved to 200.108.172.10. The listed reporting address for 200.108.172.10 is pdlweb@yahoo.com. A yahoo address is most likely the scammer himself. Traceroute shows the upstream provider to be
IP: 64.116.36.77
Reporting addresses:
abuse@mci.com
On 5/05, MCI finally booted this scammer and he moved to xo.com using 69.67.72.10 & 69.67.72.20
Emailed reports to whoa007@pacbell.net & abuse@xo.com are ignored
Contact XOSales
Call toll-free 1.877.932.2629
Support
Call toll-free 1.888.575.6398
XO quickly proved to be even worse than MCI. When phoned, they denied having any connection to this scammer even when confronted with traceroutes proving that the provide connectivity.
Score = 7
==============
http://servingmail.com/life.html
IP: 69.67.72.10
Reporting addresses:
abuse@xo.com
- Redirects to:
http://aftrk.com/c/c?b=20865&h=19541&sh=316862&bt=html
http://aftrk.com/c/c?b=20865
IP: 216.23.173.249
Reporting addresses:
abuse@intelenet.net
Whois blocked
Name servers:
NS3.INTELENET.NET
NS4.INTELENET.NET
http://aftrk.com/c/c?b=20865
- Redirects to
ETerm; life insurance: term life insurance, life insurance quote, life insurance company, term life insurance quote
http://www.eterm.com/VM/newquote.asp?publisher=Afffuel&campaign=EmailM&bannercode=316862
============
http://goldenfury.com
Reporting addresses:
abuse@mci.com
Registrant:
Software Factory Solutions
contact@thehottestthingaround.com
Domain servers in listed order:
NS1.THEHOTTESTTHINGAROUND.COM 63.82.96.35
Host: 63.82.96.35
Reporting addresses:
abuse@xo.com
abuse@mci.com
================
Other domains
0NTHEBA11S0FTWARE.COM
18ANDOLDEROFFERS.COM
1UXYS01UT10NS.COM
A11THES0FTWAREY0UNEED.COM
ADULTONLYOFFERS.COM
ADULTSUBSCRIPTIONOFFERS.COM
ALLAROUNDTHINGS.COM
ALLTHEMEDSYOUNEED.COM
ALWAYSIMPORTANT.COM
AMAZINGPHARMACYSAVINGS.COM
B1C0RP1US.COM
BACKPOST.BIZ
BEHINDITALLEXCHANGE.COM
BIGBUCKS4DRIVING.COM
BIGCAPABILITIES.COM
BIGCASH4DRIVING.COM
BLANKTRADE.COM
blastoffcom.com
BLAZEBOUNCE.COM
BREAKTHROUGHVISIONARIES.COM
BUCKS4DRIVING.COM
BUYANDSAVEONMEDS.COM
BUYMEDSONLINEANDSAVE.COM
C0MP1ETE1S01UT10NS.COM
C0MP1ETETARGET1NG.COM
CHEAPDRUGS4U.NET
CLICKANDSAVEONMEDS.COM
CREATIONPLACED.COM
CREATIVECRAFTANDMORE.COM
CREATIVEFACESMORE.COM
CROSSINTEREST.COM
CRUISECARS4CASH.COM
DATALINKEXCHANGE.COM
DEALSFOR18ANDUP.COM
DIGITALPROPOGANDA.COM
DISCOUNTEDDRUGSONLINE.NET
DISCOUNTEDMEDSONLINE.COM
DREAMCONTROLLER.COM
DREAMWAKING.COM
DRIVE4BIGBUCKS.COM
DRIVE4INCOME.COM
DRIVE4PAYCHECKS.COM
DRIVEMAKINGMONEY.COM
E11TEPR0DUCTSSPEC1A11YF0RY0U.COM
EARNMONEYWHILEDRIVING.COM
EASTCOASTLIQUIDATIONCENTER.COM
EASYMONEYDRIVING.COM
EMA11SPYPR0GRAM.COM
FASTCASH4DRIVING.COM
fastserving.com
FREESERVING.COM
GETPRESCRITIONMEDSONSALE.COM
GETRICHDRIVING.COM
GETTH1SS0FTWAREN0W.COM
GETYOURMEDSONLINEHERE.COM
GETYOURPRESCRIPTIONSONLINE.COM
GOLDENEXPERT.COM
GOLDENFURY.COM
IP: 63.82.96.35
GOLDENVIRTUAL.COM
GONEPOINTONE.COM
GREATDEALSONADULTSITES.COM
GREATPRICES4PILLS.COM
GROUPDRUGSONLINE.COM
H0TAMAZ1NGPR0GRAMS.COM
H0TANDNEWPR0GRAMS.COM
HOTADULTDEALS.COM
HOTMATURESITES.COM
IMPROMPT.COM
INCOME4DRIVING.COM
INSTALLEREXCHANGE.COM
INTERESTOR.COM
INTERESTSAVVY.COM
KICKHOSTING.COM
LARIMORECREATIVE.COM
lifemakings.com
LOCKINGPOINTONE.COM
M0N1T0RWHATTHEYD0.COM
MAK1NGTH1GSHAPPENF0RY0U.COM
MAKEMONEY4DRIVING.COM
MAKEREALCASHDRIVING.COM
MAKESERIOUSMONEYDRIVING.COM
MAKINGMORECREATIVES.COM
MALLPACKS.COM
MANDARINEFFECTS.COM
MATUREWEBSITEDEALS.COM
MIDWESTPROPOGANDA.COM
MIDWESTPROPOGANDALAND.COM
MONEYSAVINGDRUGSITE.COM
NAMEBRANDPILLSDISCOUNTED.COM
NETMANDARIN.COM
NETWORKVISIONARIES.COM
NEWEASTCOAST.COM
NEWEDGECORP.COM
NEWEDGEZONE.COM
NEWMEDIAEDGE.COM
ONLINEPHARMACYSUPERSTORE.COM
OPENCONTROLLER.COM
OPENFACES.COM
PAB10S0FT.NET
PAYCHECKFORDRIVING.COM
PHARMACYSAVINGS4U.COM
PINPOINTMONEY.COM
PROCONTROLLERS.COM
PROFITWHENDRIVING.COM
PROMPTHANDLINGTIPS.COM
PROMPTPLUS.COM
PROPOGANDALAB.COM
PURCHASEYOURPILLSONLINE.COM
QUICKPACED.COM
R1GHTMAPS.COM
RAPIDPROMPT.COM
REWARDS4DRIVING.COM
S0FTWAREC0MPET1T10N.COM
SATISFYINGFORPROFITS.COM
SATISFYINGRAPHICS.COM
SAVEONYOURPRESCRIPTIONSONLINE.COM
SECRET1YKN0WEVERYTH1NG.COM
SEEMORECREATIVE.COM
SERIOUSMONEYPAID2DRIVE.COM
SERVINGMAIL.COM
SERVINGONES.COM
SITEFARMS.COM
STUFFYOUACTUALLYCAREABOUT.COM
SUPPLYPALACE.COM
THEBESTS0FTWAREY0UCANBUY.COM
THEHOTTESTTHINGAROUND.COM
THENEWINNOVATIVEEDGE.COM
THESTOPPOINT.COM
THINGSAROUND.COM
topserving.com
TRADEPOINTONE.COM
ULTIMATEADULTOFFERS.COM
UN1QUE0FFERS0N11NE.COM
VERYSATISFYING.COM
VISIONARIESLEADERSHIP.COM
WAKINGENDS.COM
WAKINGS.COM
WESTCOASTDESICIONMAKING.COM
XRTHOSTING.COM
Y0UCANW1NW1THTH1S.COM
YESITALLCANBEDONE.COM
YOURPILLFACTORYOUTLET.COM
ZSXCONTROLLER.COM
ZXRMAIL.COM
The above domain names are just redirects for various "affiliate programs" such as WebRewardsCentral.com, Addrive and ProductTestPanel.comWebRewardsCentral.com
http://www2.webrewardscentral.com
RegistrantContact:
MarketLabs.net Inc
admin@marketlabs.net
Domain servers in listed order:
NS2.MARKETLABS.NET 66.33.254.12
NS1.MARKETLABS.NET 66.33.254.11
Addrive
http://www.addrive.com
http://jp1.sb01.com/index.php
IP: 208.38.131.24
Report to: abuse@esnet.com
Whois:
Yacoubian, Dikran
subscriberbaseholdings@yahoo.com
3830 Forest Drive
Suite 207
Columbia, SC 29204
US
803-790-8381
Domain servers in listed order:
DNS101.SB01.COM 204.74.66.252
DNS102.SB01.COM 204.74.67.252
From web page:
Nancy Margaret Jones
nancymargaret@addrive.com
ProductTestPanel.com
http://producttestpanel.com
IP: 208.38.131.22
Report to: abuse@esnet.com
Whois:
Dikran Yacoubian: subscriberbaseholdings@yahoo.com
SubscriberBASE Holdings, Inc
3830 Forest Drive
Columbia, South Caro 29204
US
Phone- 803-790-8381
Domain servers in listed order:
DNS101.SB01.COM 204.74.66.252
DNS102.SB01.COM 204.74.67.252
IPs this scammer uses to send from
69.67.72.10, 69.67.72.20
Reporting addresses: abuse@xo.com
This info from a IP whois looks like it is real. If you are looking to sue this spammer, start with this asshole. Even if he is not the one sending the spam, he is well aware that his network is being used by the spammer because he is profitting from it ad ignoring all complaints.
CustName: Roger Graves
Address: 301 W. Capital Exp.
City: San Jose
StateProv: CA
PostalCode: 95136
Country: US
NetRange: 69.67.72.0 - 69.67.72.255
NetName: DATAMONITOR-BUSSINESS-INFORMATION
OrgTechHandle: NOC1264-ARIN
OrgTechName: Network Operations Center
OrgTechPhone: +1-408-268-4526
OrgTechEmail: whoa007@pacbell.net
Malena Management spam gang
Fake Names: Alejandro Quesada, EDWIN VILLAPANDO
Fake Emails: Alex913@indiatimes.com, malena525@indiatimes.com
Score = 6
===================
Free Foreign Currency Exchange Information Request
http://akeeuncle.info/astral/lord/
http://bulgursquid.net/astral/cooright/
200.108.172.5 (No valid reporting address)
Upstream provider: 64.116.160.18
Reporting addresses:
abuse@mci.com
==========
Get a FREE Mortgage Quote TODAY!
http://otisactive.info/astral/cooright/
IP: 200.108.172.5
Report to: fwdctrl@yahoo.com
fwdctrl@yahoo.com bounces
fwdctrl@yahoo.com known spammer
Upstream provider: 64.116.160.18
Reporting addresses:
abuse@mci.com
===========
Get a FREE Mortgage Quote TODAY!
http://lipariscurry.biz/astral/accescom/
IP: 69.67.72.118 (xo)
Malena Spam Gang
Alias:
Alejandro Quesada
Alex913@indiatimes.com
Name Servers:
NS1.DMITRIQUICK.BIZ
NS2.DMITRIQUICK.BIZ
========
crapbroth.com
hyaenastir.com
psophiastable.net
steeringgiblet.com
tongancrunchies.info
tortricidpeel.net
The Mortgage Source
Sent via open proxy on a trojaned computer. Web site hosted on criminal tolerant ISP in China. Just the kind of people you want to give your money to.
Score = 4
===================
The Mortgage Source
http://ahnhgh.com/
IP: 211.144.147.131
Report to:
llz@srit.com.cn, abuse@srit.com.cn, shenzhi@cnnic.cn
===============
The Mortgage Source
http://ez-rate.info
IP: 221.209.18.3
IP: 219.147.197.196
Whois blocked by ProtectFly.com
Tech Email:15663638.fly@spamfly.com
Name Servers:
NS1.ANZWERSNET.BIZ
NS2.ANZWERSNET.BIZ
Contact in spam:
(800) 513-3855
Laura Wayne
domele@glasgow.cx
==========
Other domains:
ez-rate.info
Score = 2
http://healup.info
http://medkit.info
213.135.64.93
Reporting addresses:
abuse@telecore.net.ru
Internet Laboratories Corp.
Success! / Bodycare
They're baaack! I had hoped this one got busted after he disappeared from my mailbox months ago. Fake whois. Illegal drugs (if there are real). Hosted by rogue ISPs in China. Domain name morpher. This asshole does it all.
Score = 3
http://freenewiteminfo.com/mp/
http://freenewiteminfo.com/lj/
http://prideknowledgeline.com/lj/
http://prideknowledgeline.com/mp/
http://realpowersecret.com/mp/
http://realpowersecret.com/lj/
IP: 61.234.143.139, 61.234.143.140 (chinatetong)
Alias:
Haiyi Ling Haiyi Ling
dlanor_yong_buga@yahoo.com
Nameserver Information:
ns3.todayisp.com
ns4.todayisp.com
http://angeletcb.com
http://visional72d3.com/
Score = 2
Dead on arrival
Alias:
Zhamelgo, Alexandr
aazhago@yahoo.com
Domain servers:
DOG.CCPATONCEJK.BIZ 202.99.172.145
TSURT.CCPATONCEJK.BIZ 200.149.11.62
Penis Growth Patch Rx...
Score = 1
http://www.jnaz.net/
IP: 217.20.209.147
Reporting addresses:
s_mal@informtelecom.ru