CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 937
Comments: 25
block bottom
spacer spacer

SIRT(TM)

Spam Incident Reporting and Termination(TM) Squad

A global spam termination operation launched by CastleCops, the volunteer SIRT Squad is comprised of folks who report spam, investigate spam, and actively work on spam takedown and termination. SIRT is funded by CastleCops. Become a SIRT Squad terminator by reporting spam today!

[ How-To / FAQ ]

SIRT -> Confirmed Spam | Terminated Spam


evidence status: confirmed spam

HTTP Response
11 Jul, 2008
10:33:05
HTTP/1.1 301 Moved Permanently
HTTP/1.1 403 Forbidden
ID173190 (termination link)
TitleBotnet, Canadian Pharmacy, Geocities redirect
Entry
SIRT Squad
Reporter
0
Timestamp11 May, 2008 @ 21:46:15
Topic ID221637 - Read/respond to SIRT commentary.
Handler Note:
12 May, 2008
03:30:41
newangels:
Criminal Evidence

** REDIRECTOR **

> Yahoo

This site is using redirections to access a hidden criminal site. See
http://www.spamtrackers.eu/wiki/index.php?title=Geocities
http://www.spamtrackers.hk/wiki/index.php?title=Geocities for China
See the Spam Wiki entry at http://www.spamtrackers.eu/wiki/index.php?title=Redirections
or from China: http://www.spamtrackers.hk/wiki/index.php?title=Redirections


Please remove all redirections to sites that continue to abuse your terms of service. Please remove all redirections to sites that continue to abuse your terms of service. This site is using hidden redirection using java script. Use it to identify all similar redirections.

Here are the Sites That are Abusing your service, Link Provided Below:

http://rss.uribl.com/hosters/geocities_com.html



** TARGET SITE **

See the Spam Wiki entry at http://www.spamtrackers.eu/wiki/index.php?title=Canadian_Pramacy
or from China: http://www.spamtrackers.hk/wiki/index.php?title=Canadian_Pharmacy
See the McAfee Site Advisor information at http://siteadvisor.com/sites/designrub.com


> XIN NET
REGISTRATION OF THE WEB SITE: Desingrub.com
ACTION: To suspend this criminal site which breaks your terms of service, set the domain status to clientHold


> XIN NET
REGISTRATION OF THE NAME SERVERS
These name servers are registered by criminals to resolve only illegal web sites. This breaks your terms of service. You can safely suspend them:

ns0.nameedns.com 79.172.64.80
ns0.nameedns1.com 98.221.151.60
ns0.renewwdns.com 91.66.83.97
ns0.renewwdns1.com 203.73.152.85

ACTION: To suspend these name servers successfully, follow these steps.
1. set the ns Address records to a non-routable address, such as 127.0.0.1 or 61.61.61.61.
2. Set the domain status to clientUpdateProhibited, clientTransferProhibited, clientDeleteProhibited, and clientHold


The Is evidence that this site is running on a botnet.

Addresses for this domain

Address | Reverse | BL | Country | Reporting nameserver | Links
61.18.251.12 | N/A | | Hong Kong | ns0.nameedns.com |
61.92.120.6 | N/A | | Hong Kong | ns0.nameedns.com |
66.53.210.137 | N/A | | United States | ns0.nameedns.com |
70.224.193.79 | N/A | Yes | United States | ns0.nameedns.com | http://www.spamhaus.org/query/bl?ip=70.224.193.79 |
76.208.138.156 | N/A | Yes | United States | ns0.nameedns.com | http://www.spamhaus.org/query/bl?ip=76.208.138.156 |
78.106.37.72 | N/A | | Russian Federation | ns0.nameedns.com |
82.193.102.108 | N/A | | Ukraine | ns0.nameedns.com |
93.80.33.11 | N/A | Yes | | ns0.nameedns.com | http://www.spamhaus.org/query/bl?ip=93.80.33.11 |
93.80.50.129 | N/A | | | ns0.nameedns.com |
93.80.227.91 | N/A | Yes | | ns0.nameedns.com | http://www.spamhaus.org/query/bl?ip=93.80.227.91 |
98.221.151.60 | N/A | | United States | ns0.nameedns.com |
118.170.10.95 | N/A | | | ns0.nameedns.com |
210.106.5.136 | N/A | | Korea, Republic of | ns0.nameedns.com |
218.173.156.36 | N/A | Yes | Taiwan | ns0.nameedns.com | http://www.spamhaus.org/query/bl?ip=218.173.156.36 |
218.232.78.196 | N/A | | Korea, Republic of | ns0.nameedns.com |
218.252.100.82 | N/A | Yes | Hong Kong | ns0.nameedns.com | http://www.spamhaus.org/query/bl?ip=218.252.100.82 |
221.127.36.183 | N/A | Yes | Hong Kong | ns0.nameedns.com | http://www.spamhaus.org/query/bl?ip=221.127.36.183 |
221.127.164.253 | N/A | | Hong Kong | ns0.nameedns.com |
221.138.213.232 | N/A | Yes | Korea, Republic of | ns0.nameedns.com |
222.167.120.55 | N/A | | Hong Kong | ns0.nameedns.com |





Handler Note:
12 May, 2008
03:33:57
newangels: Generated and sent email spam alert to respective parties.
Fetched URLs

Report for at 11 May, 2008 @ 21:47:34


fetched page

at 11 May, 2008 @ 21:47:38
MD5 Fingerprint: 6ac7b1c5045db944605344b3d8b4e796
SHA1 Fingerprint: 525526d0ec0b5eb72cf8654f3e2114ebebe87b0a

fetched page

at 12 May, 2008 @ 02:41:09
MD5 Fingerprint: 7157a4059c453d4deaeefcd6f90ee886
SHA1 Fingerprint: 7f6b2ce8acb5a83913119b2ce317eb530fa7a4b6
Version 1.0
spacer spacer