Thursday, November 20, 2008

SanCash and AffKing are Back To Spamming Everyone On The Planet

Well look who's back. It's SanCash / AffKing again!

With this incredible scientific breakthrough formula, massive gains can be achieved is just a few short weeks.

As advertised on TV and FHM. Rediscover your male verve and virility, with the same product as seen on TV and FHm. Results indicate 97% of men report rapid growth within weeks.

http://xnmatuj.com/


Link is promoting "PowerGain+", the latest iteration of VPXL / Express Herbal / PowerEnlarge / Elite Herbal / MaxGain+ / Manster / ManXL / etc. etc. etc.

And also look at this:

Impress your business colleagues and stun the ladies at the club today with that incredibly expensive timepiece today!

The ultimate in making a fashion and wealth statement: a branded timepiece on your wrist. Nothing says success more than a $50,000 bling watch strapped around your wrist, to go along with your party clothes or your power business suit.

http://mntocef.com/


Prestige Replicas, back from the grave. Yet another SanCash property. I've also seen spam for King Replica, another of their multiple replica watch sites.

To whoever is sending this spam: Are you utterly without a single brain cell? Do you really think this is a wise idea?

There are numerous standing court orders and injunctions from several countries specifically demanding that this activity stop. You haven't stopped. You're operating in violation of the law. If you really want to go to jail that much quicker, or at least have all of your ill-gotten profits removed more rapidly, then perhaps I understand why you'd suddenly begin sending this crap again.

Especially in light of this past year's events regarding the shutdown of illegal spammers: whoever you are, you're exhibiting an astonishing lack of intelligence (and greed) by continuing to send unwanted, illegal spam promoting these "products."

Every single one of these messages are being backed up and sent to numerous law enforcement agencies (and the FTC), who I assure you will have no difficulty in finding you, shutting you down, and seizing all of your income from this activity.

SanCash spammers are among the stupidest people on this planet, and they have just proven it again.

SiL / IKS / concerned citizen

Monday, November 17, 2008

CONGRATULATION! / Winning Notification!!! / Payment Notification / Re: STATUTORY ANOMALIES ON YOUR FUND TRANSFER

To anyone who's been investigating spam, or even vaguely following the transformation of illegal spam over the years, the concept of the Nigerian scam seems ludicrous and pathetic. It seems impossible that anybody would NOT know about this scam in this day and age. (They've been received by millions starting in around 2002. How people could not be aware of this scam is beyond me.)

I'm not going to describe what this scam is because there are already thousands of places which do so very effectively. Google the term "Nigerian scam" or "419 scam" and read any of the results you get back.

Numerous websites engage in the "baiting" of the criminals behind these scam messages, often keeping them on the hook for months at a time, wasting considerable time and energy. I highly recommend reading any of the baits going on as we speak on TheScamBaiter.com. If you don't know what a Nigerian scam is, read the "recommended reading" in the postscript. (And tell your friends. More people need to be made aware of how this scam works.)

Since the freezing of SanCash a month ago (which appears to have not slowed them down any, more on that in a subsequent post) my spam intake initially slowed to a crawl across numerous accounts I monitor. Then suddenly all I was seeing was one or another variety of lottery, inheritance or other money exchange scams. They've been abusing every free mail system on the Internet, and I and several colleagues have had numerous successes in getting their email addresses shut down quite rapidly.

However it isn't stopping the influx of spam, and it's now to the point where I am seeing several dozen such emails every single day, often with four to six of them received within the same hour.

Ignoring for the moment the utter stupidity of whoever is mailing this (how could you possibly think anyone would be fooled when they're told they've simultaneously "won" 12 "lotteries" within the same day?), or the effectiveness of these scams, this type of influx in illegal cheque fraud attempts raises numerous questions about how to report this spam, not all of which is very straightforward at all.

Of course, there is no "lottery". I have not "won". There is no "inheritance". It's a scam to get me to send money for any number of "fees" which must be paid first to ensure the money makes its way to my account. It's illegal, and it's most commonly known as check fraud.

Prior to October 2008, reporting abuse of any freemail system was a straightforward affair. Each company has their own contact addresses or abuse processing forms. But you would be surprised at just how ineffective each of these can be when trying to report these abuses, something that takes a bit of extra effort to do in the first place.

I'll itemize the current state of abuse reporting and my experiences with each. I would also like to put out an open call to the abuse teams of Yahoo, Hotmail and Gmail with regards to how to make this abuse reporting process more seamless and effortless for the average user, most of whom have absolutely no idea how to report this abuse to your teams. Further: Hotmail - seriously - wtf? Your abuse team is now among the absolute worst I have ever dealt with. We'll see why in a second.

Gmail



Gmail has arguably the very best method of reporting, and given that they're very much aware of what this scam entails, they are really, really fast at investigating and shutting down offending accounts.

Where to report it: Their abuse reporting form is located here. Make a point of outlining what kind of scam this is. If it's one of those "you have won" messages, that's cheque fraud (aka: Nigerian fraud, "419" fraud.) If it's a "work from home" message, that's money laundering. Make a point of outlining that this is illegal, and abuses their terms of service.

Expected response: Automated single email with a ticket ID. States they are looking into it. Often this is the only response you'll get from Gmail, but guaranteed you'll never see another spam using that Gmail account as the response address.

Yahoo



Yahoo also has an abuse form, but their responses lately lead me to believe that, honestly, that entire abuse team is asleep at the wheel.

After months of successful reports throughout 2008, I suddenly noticed that whoever it is that responds to these abuse reports doesn't really read the reports at all.

Anyone reporting any kind of spam knows that the headers are usually 99% forged. Yahoo apparently focuses solely on the headers, and if they determine that the message wasn't sent using Yahoo mail, they'll conclude that there's nothing wrong with the account, even if the message body says "I want to steal your money and kill your family, so email me at myillegalaccount@yahoo.com". They will, almost to a person, completely ignore the message body and the complaint. This HAS to change. This is not 1999 anymore. This scam should be extremely well-known to every free-mail provider on the planet. I spend more time explaining this scam to abuse handlers than should ever be necessary.

Where to report it: The Yahoo abuse form is located here. As mentioned above, you really have to spell out not only that this is illegal, you have to try to get their attention that the headers are not necessarily how to tell that Yahoo's mail service is being abused.

Expected response: Automated single email with a ticket ID, followed anywhere from 2 to 6 days later with a followup as to what their conclusion was. If that conclusion is "we saw that Yahoo was not used to send this message", you have to reply to that message and clarify that 1) they need to learn how to handle a nigerian fraud message and 2) They need to look beyond the headers.

Why this is the case now is baffling. Yahoo: clean up your act!

AOL



AOL is quite long-in-the-tooth at handling abuse requests - which isn't surprising, since they originated a lot of the filtering and other abuse processes we now all take for granted. They appear to have a decent, if slightly slow, abuse team. In light of recent successes in shutting down Gmail and Yahoo addresses, AOL is fast becoming the free-mail provider of choice for Nigerian scammers.

Where to report it: Send the entire message, including full headers, to: TOSEmail1@aol.com.

Expected response: Automated single email. I often don't hear anything else after that, but I also don't appear to receive any further messages sporting the offending address.

Sify.com Email



I know what you're thinking: Sify.com??

Sify is the Indian equivalent of Hotmail or Yahoo mail. It's an independent portal located in Mumbai. Over the past year I have seen a shift from Gmail and Yahoo to Sify, which indicates there have been enough successful shutdowns that now they're really looking for any free-mail port in a storm. Sify has an abuse reporting address, but, as far as I can tell, no defined abuse process.

Where to report it: Send the entire message, including full headers, to: customercare@sify.com.

Expected response: [crickets...] I've never received any response from Sify mail. It's really sporadic when I do see an inbound scam message featuring a sify.com address.

Hotmail



Here's where I begin to lose my mind, and I'd have to say at this point that Hotmail effectively has no abuse reporting process for this type of scam, or indeed for any abuse of Hotmail involved with spam.

For years I was reporting these scams to abuse@hotmail.com, but then last year they introduced report_spam@hotmail.com. Reports sent to that address went unanswered, but then in June would send an automated message claiming that I should instead report the abuse to abuse@hotmail.com. (Huh?)

I later discovered that MSN also has the same two addresses, so I began reporting every such abused address to all four:

abuse@hotmail.com
report_spam@hotmail.com
abuse@msn.com
report_spam@msn.com

That resulted in four of the same automated messages, but it did finally also result in a followup message stating that the account had been terminated.

Starting in October 2008, however, all messages reporting abuse sent to those four addresses were all bounced. The reason?

They contained content which appeared to be spam.

Honestly: Hotmail abuse team - HOW do we report this abuse to you? If anyone at Hotmail abuse is reading this, I would very much appreciate you responding by posting a comment here (I won't publish it if you want to just reach me directly.) This has GOT to change.

Hotmail and MSN Live Spaces are, as we speak, essentially owned by criminals. The only sites I am ever referred to on MSN live spaces featured content which has been automatically generated for use in spam campaigns, by "users" who have clearly also been created via some automated means.

If anyone at Hotmail / MSN abuse is reading this: we as angry recipients of illegal spam would like an explanation. You're clearly falling way, way behind in handling this type of abuse, and it's leading to many people being scammed out of their life savings. What gives?

In closing, here's the recent tally of my "lottery winnings" from just this past Friday (Nov. 15, 2008) and today (Nov. 17, 2008)


  • $1.500,000.00 in cash [Apparently waiting for me in a package being held at the FEDEX DELIVERY COURIER COMPANY.]

  • Six million US Dollars [Waiting to be invested "into profitable areas of business in your country"]

  • US$2,500, 000.00 [My prize from the SOUTH AFRICA WORLD CUP LOTTERY 2010 Sweepstake Award Promo]

  • 5,000,000.00 GBP [MICROSOFT MEGA JACKPOT LOTTERY]

  • a cash prize of One Million British Pounds [£1, 000,000.00] [from the South Africa FIFA 2010 World Cup Organizing Lottery Promotion - I won twice?!?! In one day?!?!]

  • $4.2Million USD [from the nondesript CONTRACT AWARD COMMITTEE]

  • USD18M {EIGHTEEN MILLION UNITED STATES DOLLARS} [an inheritance from the death of one "MR.TONY.RAYMOND"]

  • £3,000,000.00 (THREE MILLION POUNDS STERLING) [won from the COCA-COLA LOTTERY PROMOTION.]

  • £850,000,00 POUNDS (Eight Hundred And Fifty Thousand Pounds Sterling) [THE CASINO-WEB LOTTERY PROMO]

  • US$ 2Million (TWO MILLION UNITED STATES DOLLARS) [International Human Rights Organization (IHRO) in Nigeria, West Africa]

  • US$3,600,000.00 [UN Fund recovery Committee]

  • £1.500,000 GBP (One million five hundred thousand) Pound Sterling [Online Sweepstakes® I.P Award Department.]

  • US$3,600,000.00 [CCH & Securities (Advancing Payment Solution WorldWide)]

  • $5,000,000.00 USD [DIPLOMAT HIETER HAENSGEN / RESERVE BANK OF AUSTRALIA, European Terminal]


Grand total as of this writing (in USD): $55,925,912.79

If I wait two more hours I guarantee I will win at the bare minimum another million dollars USD. The best part is: it looks like everyone's a winner (they are always sent to "multiple recipients", never just to me.) Let's buy each other a drink shall we?

I'll see about including a tally widget on the sideline of this blog. Any wagers that I "win" a billion dollars by Xmas?

Don't believe these stupid, pathetic and desperate messages.

SiL / IKS / concerned citizen

P.S. Recommended reading:

Nigeria cracks down on e-mail scams
The 'yahoo-yahoo boys' who are behind the country's infamous export have few job prospects.

Wikipedia: Advance-Fee Fraud

FOXNews.com: Oregon Woman Loses $400,000 to Nigerian E-Mail Scam

Wednesday, October 29, 2008

eNom Phishing, Child Porn and Avalonpay.com

Lots of spam suddenly showing up claiming to be on behalf of eNom.com, a well-known domain registrar.

Investigating these phishing attempts leads down a very dark hole indeed.

The eNom phishing sites are attempting to gather up domain information. For what purposes exactly is unsure, but I'm sure you could imagine: theft of a large number of domains, redirection of previously "good" domains to harmful content.

The contact information on these sites is all identical, and should be familiar to anyone who investigates this crap. Let's take one example domain, sys82.net:

Whois sys82.net

Domain Name: SYS82.NET
Registrar: ONLINENIC, INC.
Whois Server: whois.onlinenic.com
Referral URL: http://www.OnlineNIC.com
Name Server: NS1.KOLBERACN.COM
Name Server: NS2.KOLBERACN.COM
Name Server: NS3.KOLBERACN.COM
Name Server: NS4.KOLBERACN.COM
Name Server: NS5.KOLBERACN.COM
Status: ok
Updated Date: 25-oct-2008
Creation Date: 25-oct-2008
Expiration Date: 25-oct-2009

...

Domain servers in listed order:
ns1.kolberacn.com ns2.kolberacn.com

Administrator:
Name-- Shestakov Yuriy
EMail-: (alexeyvas@safe-mail.net)
tel --: +7.9218839910
org: Shestakov Yuriy
Lenina 21 16
Mirniy,MSK,RU 102422

Technical Contactor:
Name-- Shestakov Yuriy
EMail-: (alexeyvas@safe-mail.net)
tel --: +7.9218839910
org: Shestakov Yuriy
Lenina 21 16
Mirniy,MSK,RU 102422

Billing Contactor:
Name-- Shestakov Yuriy
EMail-: (alexeyvas@safe-mail.net)
tel --: +7.9218839910
org: Shestakov Yuriy
Lenina 21 16
Mirniy,MSK,RU 102422


Registration Service Provider:
name: Shestakov Yuriy
tel: +7.9218839910
fax: +7.9218839910
web:


Let's examine what else those dns servers are supporting:

ns1.kolberacn.com

lolita-bbs.name NS ns1.kolberacn.com
ns1.kolberacn.com A 68.48.197.101
ns1.kolberacn.com A 68.80.158.76
ns1.kolberacn.com A 72.2.13.24
ns1.kolberacn.com A 75.60.192.242
ns1.kolberacn.com A 75.187.202.144
ns1.kolberacn.com A 97.82.229.170
ns1.kolberacn.com A 98.229.69.62
ns1.kolberacn.com A 99.245.182.179
xlpreview.com NS ns1.kolberacn.com
sys82.net NS ns1.kolberacn.com
com94.net NS ns1.kolberacn.com
weblola.net NS ns1.kolberacn.com
littlelolita.net NS ns1.kolberacn.com
nude-kids.net NS ns1.kolberacn.com
xlsites.net NS ns1.kolberacn.com

The server state is: 201 Okay


ns2.kolberacn.com

lolita-bbs.name NS ns2.kolberacn.com
ns2.kolberacn.com A 65.182.248.145
ns2.kolberacn.com A 66.30.49.194
ns2.kolberacn.com A 68.48.197.101
ns2.kolberacn.com A 68.80.158.76
ns2.kolberacn.com A 69.208.85.23
ns2.kolberacn.com A 72.2.13.24
ns2.kolberacn.com A 75.60.192.242
ns2.kolberacn.com A 76.112.161.176
ns2.kolberacn.com A 99.245.182.179
ns2.kolberacn.com A 209.60.226.164
ns2.kolberacn.com A 209.252.169.130
xlpreview.com NS ns2.kolberacn.com
sys82.net NS ns2.kolberacn.com
com94.net NS ns2.kolberacn.com
weblola.net NS ns2.kolberacn.com
littlelolita.net NS ns2.kolberacn.com
nude-kids.net NS ns2.kolberacn.com
xlsites.net NS ns2.kolberacn.com

The server state is: 201 Okay


And the rest are supporting several other domains featuring the enom phishing setup.

Note the diversity of the ip addresses associated with those domains: every single one of these is being hosted via a botnet, assumedly home computers infected with the Asprox infection. I had been reading up on several investigations into that exploit, and now it appears it's directly a part of my own spam investigations.

Many of the domains supported by those name servers are, of course, sites which promote, sell, and distribute child pornography. Fortunately, as I write this, all of these sites are not responding. (Good work on getting those shut down, whoever you are.)

A quick investigation of one of those sites leads to a payment processing site known as Avalonpay.com. A quick search on that domain turns up an interesting blog entry on matchent.com concerning a similar investigation. The registrant contact data for that domain includes the company name "Absolutee Corp. Ltd.", allegedly based in Hong Kong:

Note the company name used, ABSOLUTEE CORP. LTD.
Compare with an article in Wired News, http://www.wired.com/politics/security/news/2007/10/russian_network , about the Russian Business Network from October 2007, quote:

"Jaret [note: speaking on behalf of RBN] also says there's no mystery about the company's ownership. According to Jaret, an offshore company called First Connect Telecom Limited Inc. owns RBN, though the company's principals remain anonymous. The registration information for the company's website lists a company called Absolutee Corp. LTD as the owner of the domain name. "

The article also mentioned that the whois info for RBN was changed later. And it has now expired.


So:

- eNom Phishing sites (all featuring alexeyvas@safe-mail.net contact email in whois.)
- Rogue DNS servers (All featuring fake Chinese registrant information in whois.)
- Child porn sites (All featuring absolutee.com registrant information in whois.)
- Avalonpay.com (Payment processor for child porn sites, also featuring absolutee.com registrant information in whois.)

ALL hosted using botnet-supported fast-flux servers.

You would think that this guy's days in this industry were numbered, but sadly you'd be wrong, at least to gauge it from how long he's maintained these operations.

I would love it if anyone from Russian law enforcement would investigate this scumbag. I guess I would first have to figure out how much they charge to do that. (Pardon my cynicism.)

Stay far, far away from any email related to these eNom "securiy bulletin" emails.

SiL / IKS / concerned citizen

Thursday, October 23, 2008

Is UADreams the new VPXL?

UADreams (Formerly UALadys) is back to spamming everybody whether they want it or not with 100% bogus "Russian dating" messages. Here's a sampling from mere moments ago:

Subject: RE: Message 00

Im a charming blue-eyed blonde, who looks for a male pen friend, or just a man to talk with on Skype or in real life!

Don't loose time and come get registered FREE at: http://el1te-russ1an-g1rls.com/?idAff=5


Subject: RE: Message 61

I'm a beautiful girl, who looks for a male pen friend, or just a man to talk with on Skype or in real life!

I have registered my profile at: http://el1te-russ1an-g1rls.com/?idAff=5


Subject: RE: Message 11

I'm a beautiful girl, who looks for a male pen friend, or just a man to talk with on Skype or in real life!

My home page: http://el1te-russ1an-g1rls.com/?idAff=5


Subject: RE: Message 54

I'm a hot brunette girl, who looks for a male pen friend, or just a man to talk with on Skype or in real life!

My home page: http://el1te-russ1an-g1rls.com/?idAff=5


Subject: RE: Message 30

I am an atractive blonde, and I'm searching for a man to chat with by email or by Skype, or even meet in reality!

My home page: http://el1te-russ1an-g1rls.com/?idAff=5


Of course I never initiated any communication with anyone in Russia (thus: why would there be a "Re:" in the subject in the first place?) This same affiliate (idAff=5) is sending me, on average, five to ten of these per hour, and the wording makes it clear he has utterly no idea what he's doing. Nobody should be dumb enough to click on any of these messages, especially since they all arrived virtually simultaneously.

Ignoring all of that: who describes themselves this way? There's just no basis of reality in any of these messages. Also: nobody is dumb enough to assume they are the sole object of this "woman's" affection. Literally everyone I discuss spam with has received these messages, and continue to do so.

This affiliate was previously sending me non-stop VPXL spam (prior to the shutdown of SanCash / AffKing, of course.) I can tell simply because he's applying the same template and frequency to this "UADreams" spam run. He also mails on behalf of GlavMed / Spamit and is among the mailers sending four times as much "Canadian Pharmacy" spam to everyone on the planet.

I've blogged about UALadys in the past. They clearly have no problem paying mailers to send millions of messages illegally to anybody. This idiot has no idea who's in his lists, and he doesn't care. I could be a 98 year old woman or a five year old boy. He will still assume I am interested in meeting a Russian woman to date and / or marry. This is the typical intellect of the average mailer. Not only do they not segment their lists or clean them, they just flat-out have no idea whatsoever of who is in their lists. Yet they believe it's up to us to take care of that by "just deleting" the millions -- or billions, as we've seen recently -- of messages they clog the Internet with on a daily basis.

Needless to say: you should never join ANY dating site which uses unsolicited email to promote itself.

SiL / IKS / concerned citizen

Tuesday, October 14, 2008

GenBucks + SanCash + AffKing + Tulip Lab + Shane and Lance Atkinson: BUH BYE!

A quick note today about some recent news which I think we've all been expecting for some time now.

Shane Atkinson, his brother Lance, and several others are currently the subject of intense legal action against the by-know well known spam operation SanCash, aka GenBucks.

If you caught any of the news last year regarding this setup, you might remember the BBC4 report which connected several dots between Atkinson, GenBucks, a product called "Manster" and a company called Tulip Lab.

Well two very big announcements today confirm, and place in the public record, that this investigative work was definitely on the right track.

This story, posted mere minutes ago, outlines pending fines of $200,000 per person against each of Shane and Lance Atkinson (together the foundation of SanCash), Roland Smits, and also confirms that they ran both GenBucks and SanCash, to promote what are now confirmed to be bogus and / or dangerous products which were manufactured and distributed by Tulip Lab, most notably Express Herbal (called approximately a dozen names over the past two years.)

It gets better: The US Federal Trade Commission also has taken action against the abovementioned operators of GenBucks / SanCash, as well as Jody Smith, a resident of Texas, and four companies they operate. They further make mention of the widespread illegality of how they sent their messages (using an internationally-seeded botnet), and also mention AffKing, which is what SanCash used to be called.

Assets for all of the above entities have been frozen, effectively cutting off the profit source for any mailers who still insist on promoting these bogus, dangerous products.

The FTC press release puts a very fine point on the rampant falsehoods perpetrated on a daily (hell: hourly) basis by these criminals:

One product called "VPXL" was touted as an herbal male-enhancement pill. Advertised as "100% herbal and safe," it supposedly caused a permanent increase in the size of a user's penis. The agency alleged that not only did the pills not work, but they were neither "100% herbal" nor "safe," because they contained sildenafil – the active ingredient in Viagra. At the FTC's request, the pills were tested by the FDA. According to medical experts, men taking nitrate-containing drugs – which are commonly prescribed to treat diabetes, high blood pressure, high cholesterol, or heart disease – can experience an unsafe drop in their blood pressure when they also take sildenafil.


And more:

The FTC also alleges that the defendants made false claims about the security of consumers' credit card information and the other data they were required to provide to buy goods. In operating the online pharmacy, which was called "Target Pharmacy" and later "Canadian Healthcare," the defendants' Web site assured potential consumers that "TARGET PHARMACY treats your personal information (including credit card data) with the highest level of security," according to papers filed with the court. The Web site went on to describe its encryption process, which supposedly involved "Secure Socket Layer (SSL) technology." FTC investigators, however, found no indication that the Web sites were encrypted using SSL technology.

The FTC also challenged claims made for a weight-loss supplement pill purportedly containing Hoodia gordonii, a cactus-like plant found in southern Africa that supposedly could cause users to lose up to six pounds a week. The FTC charged that the claims were false and violated federal law.


Really: just read the whole thing. It'll bring a huge smile to your face. If you have an email address, you've most likely (98% chance) received spam for these "products", and anybody with half a brain already knows most of what was just quoted above.

This is a good day, and makes this among the worst years ever for illegal spammers, as well as their sponsors and supply chain operators.

I fully expect to see lots of nonchalant postings on any of the remaining underground spam forums (whatever happened to Bulkerforum.biz anyway?) They can all claim that we should have all "just deleted" all of the billions of inbound messages that these scumbags continually pumped into everybody's inboxes with impugnity. They're wrong. [How does one "just delete" 3000 of these per day without throwing the baby out with the bathwater? They've essentially ruined email as a usable form of communication.]

My congratulations and gratitude go out to members of New Zealand law enforcement who worked so diligently over the past 9 months to fully investigate these cretins. Also: kudos to the author of spaminmyinbox.com who did such great investigative work on his own, as well as Simon Cox from the BBC.

SiL / IKS / concerned citizen

Monday, August 18, 2008

Some Spammers Are "Getting Out Of The Business"

If you've been reading any tech news sites lately, you've probably noticed two distinct trends:

1) Lots of reporting of the storm worm, with sub-stories related to mass hijacks of publicly-owned websites for the purposes of infecting the public's PC's with the Storm worm. (With still further subsets focusing on the "Russian Business Network" (or "RBN") being behind the whole setup.)
2) Lots of arrests, convictions, and imprisonments of large-scale illegal spammers. (Including one murder-suicide of a previously incarcerated illegal spammer.)
3) More raids in Romania of online scammers, predominantly eBay scammers.
4) Lots of arrests and indictments related to the TJ Maxx identity theft incidents from last year.

As with last year, 2008 is proving to be an extremely bad year for illegal spammers.

I define an illegal spammer as the following, which is more specific than CAN-SPAM:

- They don't care who they send to, or whether they actually ever wanted to hear from them in the first place.
- Further to that point: they actively seek out email addresses of total strangers to start spamming them. They know that these email addresses are not actively seeking to be sent spam. They don't care.
- They try to get as much deliverability out of their messages whenever they know that their messages are being specifically filtered against (remember: they know these people don't want the messages in the first place.)
- They spam the same individual numerous times per day. (And in many cases: per hour.)
- They spam urls representing largely illegal or fraudulent websites, selling either fake or counterfeit products, in violation of international law.
- They never opt anyone out, ever, and never honor any inbound communication regarding spamming.
- In many cases, their sites actively filter for any words related to spamming in their email or contact forms. They are well aware that they operate in violation of the law, and the public's privacy.
- Their "opt-out policy" is to tell anyone who complains to "find your delete key."

Robert Soloway was just such an individual. He knowingly spammed millions of people, several times per day, promoting "products" which either didn't work (his so-called "turnkey email marketing solution") or a variety of other bogus products. He ignored, and then later actively retaliated against any complaints regarding spamming.

Soloway was recently quoted as saying "I can honestly say, even though I'm going to federal prison, for once in my life, I have a focus. I'm very sorry for what I did. I'm hoping people can forgive me." (source) This is in very stark contrast to previous statements he had made in chat rooms and web forums. e.g.: "I always win ... regardless of the judgment amount ... losing is not an option, and I never ever, ever have to pay a single cent to anyone." (source)

Well we now know just how wrong he was.

I'm not going to comment on the Eddie Davidson murder suicide. It was very tragic and ultimately had very little to do with his prior spamming exploits (other than the fact that he escaped from the prison he was sent to for doing so.) What I will comment on is that Davidson was an active and willing informant to the FBI and other law enforcement agencies, something very few press outlets covered. He was already providing lots of information on how stock spamming worked, and was allegedly assisting in the case against his former business partner Darrel Uselton, known to be a rampant, unrepentant stock spammers for years. Jack and Darrel Uselton are both awaiting trial on Sept. 29th and continue to be under investigation by several states and the US Securities and Exchange Commission (SEC). (See the Texas AG's press release dated July 9, 2008.)

That doesn't bode well for many spammers, and could also have the ancilliary effect of further damaging Alan Ralsky, currently under a similar indictment in Michigan related to his repeated stock spamming activities, and profiting from stock market manipulation.

There was also the conviction of Michael Dolan relating to his AOL phishing and spamming practices.

All of this is summed up rather nicely in a recent forum thread I was made privy to in the past few weeks.

If You Live In The U.s.a - Please Stop Spamming, It's just not worth it anymore

gerogeyboy0101
Posted: Jul 16 2008, 03:45 PM

On a roll...
*

Group: Members
Posts: 253
Member No.: 1368
Joined: 21-September 04

I have met online and dealt with many of you throughout the years, and some of you are simply terrific people who got caught up into something a long time ago that used to be innocent and legal, but now has been blown into astronomical proportions of bad.

People all over the USA are going down for illegal activity related to spam. I myself became a target for the IRS and was questioned by the fbi all because I told the truth about the fact that I had received 1099's from two spammers that had spam lawsuits against them.

Surveillance technology and the Patriot Act and further bills being signed into being are completely destroying liberal, human, and privacy rights for citizens in the united states.

I don't know if some of you guys realize it but these guys do not close, they do not stop. They take our tax dollars and get paid to sit in rooms and spy and follow leads, and investigate and do whatever it takes to catch whoever they can whenever they can. They are relentless and uncaring. If you're going to spam and you have to, hey, a man (or woman) has gotta do what they gotta do. But using proxys or botnets or unauthorized access on anyones computer is simply not worth it anymore.

They will put you away for years, no ifs, ands, or buts about it. I'm not trying to scare anyone, Im just saying, be careful, and watch your asses, because they are out to get you 24/7.


The thread contnues with a lot of basically "shrugging" comments about how this has always been the case, followed by general agreement that everybody should be careful not to use their real identities when "doing business", and then referring to the US as a "fascist" country.

They are all missing the point.

All of these recent arrests are pointing to a rather obvious point: if you commit crimes, no matter where you are or who you claim to be, you will be found, you will be arrested, you will be prosecuted, and you will be convicted. The few times this has not happened, it still results in suspects vastly changing their lives by moving to a completely different geographic location, and setting up whole new identities. If you're spamming illegally, and especially if that spamming is surrounded by other illegal acts (hacking, hijacking of public computers, infection of public computers, fraud, wire fraud, computer trespassing, unauthorized sale of controlled substances, securities fraud, etc. etc. etc.) trust me: you are going down. Maybe not today. Maybe not this year. But you will.

Regarding the Russian Business Network: this shadowy group are continuing to erode the public perception of the country of Russia. Russian cybercriminals are behind perhaps 90% of the virus-laden emails the general public has been receiving. There are several reports that have linked them to the following:


  • Recent attacks against websites and network infrastructure of the country of Georgia, starting at precisely the same moment as the attacks on the ground.

  • Spam messages claiming to be from either MSNBC or CNN featuring links to bogus "breaking news" stories.

  • Server hijacks and exploits causing them to deliver these same infections.

  • Spam for "Canadian Pharmacy", a known Spamit / Glavmed sponsored property.



And of course there are the less-substantiated claims that they also have been behind spam campaigns and hijacked hosting for a variety of child pornography website operations, and that they were also involved in the cyber-attack against Estonia last year.

Prosecution of whoever is behind this group, especially within Russia, is unlikely. But that's soon going to become less of a problem since much of their target audience is actually geographically located within the US, as are (it is believed) several of their operatives. Also: a lot of the people who spam on behalf of these Russian groups and individuals (notably Spamit / Glavmed) are located in the US, Canada, and several countries in Europe. Arresting them can cut off a major source of cashflow and infrastructure. It also can draw out further details of where these individuals can be found, and subsequently arrested, if not by Russian police, then by international law enforcement. It's a pretty small planet, after all.

The cyber-attacks against Georgia have garnered some very widely viewed headlines, and not just in tech publications. This does not help the Russian government in its bid for entry into the WTO. That was previously hindered by the renowned shuttering and resurrection of AllOfMP3.com. (Which now alternately operates as MP3Sparks and MemphisMembers.) It also isn't doing any favors for Russia in terms of how international law enforcement sees them, which I'm sure is of no consequence to the Russian government anyway. That the recent cyberattacks have gained significant news attention is now raising some questions for other governments: if they can attack Estonia and Georgia, who's to say they can't attack a larger western power? Or a specific government, or utility, or financial network? The fact is: they can. Illegal spammers and their supporters have killed off any site which gets close enough to the truth to make them uncomfortable: the KillSpammers forum (which is not completely gone, just on hiatus. :) ,) spam-court, castlecops, blue frog, etc. They will do it whenever it suits them, or when they feel that the evidence is such that it will cause problems with their cashflow. I don't doubt that they'd eventually try to attack Citibank, or PayPal, or the US Federal Reserve if it suited their needs at the time.

But that can only keep going for so long. A very bright light has been shone upon the RBN, and they are certainly aware of it. One day, inevitably, something's gotta give, one way or the other.

In any case, the past two years have made two things abundantly clear:

1) While the process may be slow, law enforcement and the courts do enforce laws against these criminals, and apply penalties resulting in real jail time
2) The public at large is definitely fed up with continually receiving email spam (or really spam of any type.)

The tally so far this year:


  • Indicted:

    • Alan Ralsky

    • Scott Bradley

    • Judy Devenow

    • John Bown

    • William Neil

    • Anki Neil

    • James Bragg

    • James Fite

    • Peter Severa

    • How Wai John Hui

    • Francis Tribble

    • Albert Gonzalez, AKA Segvec

    • Christopher Scott

    • Damon Patrick Toey

    • Maksym Yastremskiy, AKA Maksik

    • Dzmitry Burak

    • Sergey Storchak

    • Aleksander Suvorov, AKA Jonny Hell

    • Hung-Ming Chiu

    • Zhi Zhi Wang

    • Sergey Pavolvich

    • An unknown hacker named "Delpiero"



  • Arrested:

    • Alan M. Ralsky [but out on bail]

    • Albert Gonzalez, AKA Segvec

    • Maksym Yastremskiy, AKA Maksik


  • Convicted and Imprisoned:

    • Robert Soloway

    • Michael Dolan





That's 25 total. And that's actually an incomplete total since there were an additional 22 arrested back in April, notably including "Vladuz", a Romanian cybercriminal behind rampant amounts of eBay phishing attempts. So for 2008 alone, we're nearing 50 criminal prosecutions against these criminals, and it's only August.

So I think I would have to agree with ol' "gerogeyboy0101" up there: if you're spamming at all, do us all a favor and get the hell out of "the business."

SiL / IKS / concerned citizen

Oh and P.S.: anybody notice that a lot of inbound spam purporting to be for VPXL or "Canadian Healthcare" now redirect to the SpamWiki entry for SanCash? :)

e.g.:

chipadd.com [a king replica site]

now points to:

http://www.spamtrackers.eu/wiki/index.php?title=King_Replica

Hehe. Nicely done, whoever you are.

SiL

Monday, July 14, 2008

Storm Of Stupidity

I'm pretty certain that if you're reading this blog, you're well aware of these messages promoting "news stories" which are in fact links to hijacked servers pushing out new Storm Worm infections.

For the inbound spam I received over the past several days, 100% of what used to be spam for VPXL (or its bogus new names "PowerEnlarge" or "MaxGain+") is now spam promoting hijacked websites which will attempt to infect you with the Storm worm. But the idiot who's sending it has confused his subject lines and message bodies. More on that later.

Check out this utterly retarded listings of "headlines" the criminals behind the Storm Worm want us to believe are true. (Subject line and body are in sequential order):

Subject lines:


  • Even politicians need a day off

  • Cheap fuel available in Texas

  • Dark Knight free tickets up for grabs

  • Barack Obama pulls out from Presidential Race

  • Orgies discovered in Hollywood

  • Baby borned with 2 privates

  • Barack Obama graft trial begins

  • Afghan captial in mourning

  • Stray javelin kills promising US sprinter

  • Charred bodies found near White House

  • Obama's karma over slip of tongue

  • Local family found hidden gold

  • Best prediction for upcoming lottery

  • Bomb scare in JFK causes delays

  • Google-Yahoo merger announced

  • Microsoft takes over Yahoo Inc



Message Bodies:


  • Osama bin Laden spotted in Texas, vows revenge on US

  • China pulls out of hosting 2008 Olympic games

  • Picture of boss doing secretary

  • Floods in Bahamas claims hundreds of lives

  • Women love it long and hard up their love hole.

  • Don't let your kids out late - 12 juveniles missing in Connecticut

  • Hilary Clinton screams bloody murder over loss, vows revenge on Obama

  • All the best techniques to bed a girl recordered right here.

  • Tasty come is very important to women, enhance its flavor here

  • She likes her kitty stretched and do you have the capability to do it?

  • Dying for a flaming hottie, ram the slutty devil tills she cry foul.

  • Guess the right number and win 10000

  • Magic Johnson dies of AIDS at 49

  • Global warming declared a hoax by US Senate

  • Louis Vuitton gives out free bags to poor in New York

  • Celebrity blogger reveals all



This is to the tune of several hundred messages received per day.

In every single case: these are obvious, outright lies. Not only that: they're extremely poor attempts at outright lies. I know of six-year-olds who would be far more convincing at writing this stuff.

If they genuinely wanted to pique the public's interest in actual, legitimate news (something they were trying before by referring to genuine news stories, claiming that you would be downloading a video) then maybe I wouldn't be so pissed off at receiving this crap. But if they have to stoop to outright bold-faced lies, with no care whatsoever that they be taken the slightest bit seriously, I think I have to ask: who are you idiots who keep clicking on these stupid links in these emails?! How out of touch are you, exactly?

Are you that disconnected that you seriously believe that Osama Bin Laden would actually expose himself to the media in Texas? Or that after the past year and a half of campaigning (and millions of dollars spent,) that Barak Obama would pull out of the US presidential race? And what legitimate news service would ever use the word "borned" in an actual headline?

Who are you people?!

Note also that in several cases this complete moron of a mailer has confused his subject lines for the Storm worm, with message bodies promoting VPXL or PowerEnlarge. It's so obvious that this is the same mailer that it might as well be considered a fingerprint. And in the last case, the subject and body are identical to those for a VPXL spam message received last month. But the link is pointing to a storm site (again: a hijacked site, which has illegally been used for this purpose.)

Here's a sampling (far from complete I'm sure) of the infected servers which are being used in today's spam attacks promoting the Storm worm:


  • http://activiteitenclubs.info/

  • http://tatianavidal.com.br/

  • http://www.asto.sk/

  • http://www.stirparo.net/

  • http://laovejanegraylg.com/

  • http://sweetcharitygifts.org/

  • http://dc-nfz.de/

  • http://www.testforum.familien-cafe.de/

  • http://sohodesign-ec.com/

  • http://www.noniforlife.de/

  • http://neoma-interactive.com/

  • http://franjaderecho.com.ar/

  • http://216.120.229.16/

  • http://def.livenet.pl/

  • http://solscreen.com/

  • http://test-djs.com/



I'm omitting any mention of the target html or exe files which the Russian group has placed on all of these sites. (If you've received these messages, you know what they are already.)

In every case, the resulting page is attempting to mimic the infamous "PornTube" website, featuring what appears to be an underage nude female and several completely bogus (but still offensive) comments. It's most definitely not safe for work, and it's an unconvincing template.

Speaking of which:

If you actually were stupid enough to click on one of these links, assuming you'd be seeing news footage of "floods in the Bahamas": why on earth would you continue to allow this download to take place even after you discovered (essentially) that the site was instead pornographic?

Why are you people using a computer at all?

If you are reading this and you are the operator of one of these domains, you should be aware that the spammer behind this (or more likely his sponsor) have complete control over your server. If you're the ISP who is hosting one of these sites: you should really upgrade your systems.

You can discover a variety of methods this criminal group has used to gain full access to your web server at the following url:

http://www.malwaredomainlist.com/forums/index.php?topic=1878.0

That research is ongoing of course.

Spammers and their supporters love to boast about how stupid Westerners are (or basically: non-Russian's / non-Romanian's.) If you've gotten infected by knowingly clicking on links in these completely idiotic messages: you are only proving their point.

I have to ask again: Who are you people?!

Stop clicking on links within spam messages!! Whenever you do so, you are supporting known criminal organizations. Turn your computer off now.

Honestly, people...

SiL / IKS / concerned citizen