CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

Add / Change Registrar
Goto page Previous  1, 2, 3, 4, 5, ... 13, 14, 15  Next
 
Post new topic   Reply to topic       All -> FavForums -> Complainterator [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
AlphaCentauri

SIRT Handler
Premium Member

Joined: Nov 20, 2003
Posts: 2859

Premium

PostPosted: Thu May 08, 2008 4:55 am    Post subject:
Reply with quote

Wow...

I've never seen a traversal like that.

But as far as contact addresses, for Hinet I found hidomain@hinet.net and for TWNIC I found an online reporting form at http://www.twnic.net.tw/service/

As far as the letters it generates, you can kind of get something by pausing it every time it tries to look up "com.tw" or "edu.hk" and substituting the full domain name, but you will have to do major proofreading to make the changes anywhere necessary in the letters so you don't send one requesting they remove a domain named "com.tw."

Also, twnic.net.tw is the registrar's own domain, so you would delete those reports altogether. addwe.com.tw was registered in 2000, and cuhk.edu.hk was registered in 1995, so they aren't going to be spammer nameservers, either. So you're down to the one email for betcity.com.tw anyway.

For Taiwan domains, it is helpful to know about the whois server at http://whois.twnic.net/ when who.is can't find them.

Back to top
View users profile Send private message
pwillener

SRT Trainee
SRT Trainee
Premium Member

Joined: Apr 17, 2006
Posts: 1813
Location: Japan
Premium

PostPosted: Thu May 08, 2008 6:27 am    Post subject:
Reply with quote

kamaraju wrote:
I am not sure, if this is the appropriate thread for these kind of problems. Please point me to a better one if needed.

This is where malfunctions of the latest Complainterator version is usually reported CastleCops Link/t218903-Complainterator_Version_21_0_April_4_2008.html

Back to top
View users profile Send private message Visit posters website
tembow

Blue Angel
Premium Member

Joined: Oct 10, 2005
Posts: 2933

Blue Security Premium

PostPosted: Fri May 09, 2008 1:08 am    Post subject:
Reply with quote

kamaraju wrote:
I am not sure, if this is the appropriate thread for these kind of problems. Please point me to a better one if needed.

Complainterator breaks while reporting while trying to report hxxp://edm2.betcity.com.tw . The actual spamvertized link is hxxp://edm2.betcity.com.tw/event/20080411/


Are you requesting that ADDWE's whole Taiwan web site operation be shut down because one of its pages was mentioned in a spam?

Or is there more evidence of criminal events that I have not seen?

Most times when I hear complaints that Complainterator is failing to generate a request I feel relieved that it seems to know better than the user. Smile But if you can show me more evidence I will be happy to hear it.

Back to top
View users profile Send private message Visit posters website AIM Address
kamaraju

Corporal
Corporal


Joined: Mar 07, 2007
Posts: 66
Location: USA

PostPosted: Fri May 09, 2008 2:22 pm    Post subject:
Reply with quote

tembow wrote:

Are you requesting that ADDWE's whole Taiwan web site operation be shut down because one of its pages was mentioned in a spam?

Or is there more evidence of criminal events that I have not seen?


I have only one spamvertized link. I did not know that hxxp://edm2.betcity.com.tw is a good website. The homepage looks similar to the spamvertized link. That is why I was planning on requesting its removal. I do not know the language of that page, so I could not comprehend any of the content there.

Quote:
But if you can show me more evidence I will be happy to hear it.


I have evidence only for that spamvertized link. Sorry!

Back to top
View users profile Send private message
pwillener

SRT Trainee
SRT Trainee
Premium Member

Joined: Apr 17, 2006
Posts: 1813
Location: Japan
Premium

PostPosted: Tue May 13, 2008 3:42 am    Post subject:
Reply with quote

Spammed domain: vasurni.com
Registrar: REG2C.COM, INC.
Contact: info [at] reg2c.com

Back to top
View users profile Send private message Visit posters website
efa

Lieutenant
Lieutenant


Joined: Aug 31, 2007
Posts: 163
Location: Italy

PostPosted: Wed May 14, 2008 11:41 pm    Post subject:
Reply with quote

Spammed domain: hotnewadobe.com
Registrar: FORTUNE INTERNET, INC.
Contact: I do not know???

Fortune isn't an accredited registrar.

Back to top
View users profile Send private message
efa

Lieutenant
Lieutenant


Joined: Aug 31, 2007
Posts: 163
Location: Italy

PostPosted: Thu May 15, 2008 12:23 am    Post subject:
Reply with quote

Spammed domain: elcalor.lt
Registrar: UAB "BALTNETOS KOMUNIKACIJOS"
Contact: I do not know???

UAB isn't an accredited registrar.

Back to top
View users profile Send private message
AlphaCentauri

SIRT Handler
Premium Member

Joined: Nov 20, 2003
Posts: 2859

Premium

PostPosted: Thu May 15, 2008 2:09 am    Post subject:
Reply with quote

efa wrote:
Spammed domain: elcalor.lt
Registrar: UAB "BALTNETOS KOMUNIKACIJOS"
Contact: I do not know???

UAB isn't an accredited registrar.


I found

Juridinio asmens pavadinimas UAB "BALTNETOS KOMUNIKACIJOS"
Interneto svetainė http://www.balt.net
El. pašto adresas info@balt.net

on the .lt whois at http://www.domreg.lt/whois

efa wrote:
Spammed domain: hotnewadobe.com
Registrar: FORTUNE INTERNET, INC.
Contact: I do not know???

Fortune isn't an accredited registrar.


http://www.fortuneinternet.com/
part of answerable.com

spam reporting form
http://answerable.com/reports.php?action=report_spam

false whois reporting form
http://answerable.com/reports.php?action=report_false_whois

whois is at
http://www.0101domain.net/domain.php?action=whois

Back to top
View users profile Send private message
pwillener

SRT Trainee
SRT Trainee
Premium Member

Joined: Apr 17, 2006
Posts: 1813
Location: Japan
Premium

PostPosted: Thu May 15, 2008 3:01 am    Post subject:
Reply with quote

Change in reporting method

Spammed domain: krapobrav.com
Registrar: INNERWISE, INC. D/B/A ITSYOURDOMAIN.COM
Current contact: tcucci [at] itsyourdomain.com (bounces)
ICANN suggested contact: info [at] iyd.com (returns the following autoresponse)

Quote:
Hello,

Thank you for contacting ItsYourDomain.

We are no longer using this address, but that doesn't mean we don't want you to
get in contact with us!

Instead, please visit http://help.IYD.com use our Customer Service
Center(CSC) and send us your question.

If you have never used the Customer Service Center before, you will need to
subscribe to keep track of your requests. The login process for the CSC is
extremely easy and quick. Just choose the email address you’d like us to contact

you with and pick a password:

http://help.IYD.com/register

If you have already started using the CSC, please use the following link to
recover your password if required:

https://help.domaindirect.com/index.php?_m=core&_a=lostpassword

We welcome your comments and feedback which will help us improve the Customer
Service Center.

Also, to see current News or check for any system outages (and expected fix
times) please, also visit:

https://help.domaindirect.com/index.php?_m=news&_a=view

Sincerely,

Your Customer Service Team
ItsYourDomain / IYD.com
http://help.IYD.com
Local: 416-531-2084
Toll Free: 866-337-8633
Fax: 416-352-0113

New notification should be: ***_PASTE_INTO_https://help.domaindirect.com/

Back to top
View users profile Send private message Visit posters website
tembow

Blue Angel
Premium Member

Joined: Oct 10, 2005
Posts: 2933

Blue Security Premium

PostPosted: Thu May 15, 2008 3:42 am    Post subject:
Reply with quote

Latest updates to the contact list

DIRECTI INTERNET SOLUTIONS PVT. LTD. D/B/A PUBLICDOMAINREGISTRY.COM ~ abuse@publicdomainregistry.com
Regtime LTD (1362) ~ info@regtime.net
HINET ~ erwinfan@ms77.hinet.net
GX Networks Ltd t/a 123-Reg.co.uk [Tag = 123-REG] ~ contact@gxn.net
REG2C.COM, INC. ~ info@reg2c.com
UAB "BALTNETOS KOMUNIKACIJOS" ~ vidmantas@kitoki.com hostmaster@balt.net
FORTUNE INTERNET, INC. ~ helpdesk@0101host.com contact@0101domain.com



Last edited by tembow on Thu May 15, 2008 10:48 pm, edited 1 time in total
Back to top
View users profile Send private message Visit posters website AIM Address
efa

Lieutenant
Lieutenant


Joined: Aug 31, 2007
Posts: 163
Location: Italy

PostPosted: Thu May 15, 2008 2:55 pm    Post subject:
Reply with quote

Spammed domain: grtrrh.co.uk
Registrar: GX Networks Ltd t/a 123-Reg.co.uk [Tag = 123-REG]
Contact: I do not know???

Isn't an accredited registrar.

Back to top
View users profile Send private message
efa

Lieutenant
Lieutenant


Joined: Aug 31, 2007
Posts: 163
Location: Italy

PostPosted: Thu May 15, 2008 2:58 pm    Post subject:
Reply with quote

P.S. contact[at]gxn.net bounce all my email as spam

Back to top
View users profile Send private message
AlphaCentauri

SIRT Handler
Premium Member

Joined: Nov 20, 2003
Posts: 2859

Premium

PostPosted: Thu May 15, 2008 6:31 pm    Post subject:
Reply with quote

My email to contact at gxn.net didn't bounce, but they've ignored it anyway -- and it was a phish report, which most registrars act on pretty quickly.

Back to top
View users profile Send private message
tembow

Blue Angel
Premium Member

Joined: Oct 10, 2005
Posts: 2933

Blue Security Premium

PostPosted: Thu May 15, 2008 11:07 pm    Post subject:
Reply with quote

efa wrote:
Spammed domain: grtrrh.co.uk
Registrar: GX Networks Ltd t/a 123-Reg.co.uk [Tag = 123-REG]
Contact: I do not know???

Isn't an accredited registrar.


No site loads at that address. What brand of spammed site is it?

Relevant dates:
Registered on: 14-May-2008
Renewal date: 14-May-2010
Last updated: 14-May-2008

Registration status:
Registration request being processed.

From the traversal:

ns1.grnew.me.uk [200.72.139.67] 85.150.209.34 Chile NS
ns2.grnew.me.uk [202.44.71.148] 85.150.209.34 Thailand NS

The IP address 85.150.209.34 sure looks bad:
From: http://www.bobbear.co.uk/newmesmeis.html

The domains newmanesrg.org, newmanesrb.net, newmanesrb.com and newmanesrg.com are all hosted on the zombie IP 85.150.209.34 which is a compromised or criminal owned customer machine, (5596d122.adsl.wanadoo.nl), on the Orange Nederland Breedband B.V. network. They are still using 'in house' nameservers hosted on the usual 'Blackhat' Entel Chile IP 200.72.139.67 and the equally unhelpful NETVIGATOR (PCCW Limited) IP (219.76.235.93) both of which have been reported many times with no response, never mind action.

Back to top
View users profile Send private message Visit posters website AIM Address
tembow

Blue Angel
Premium Member

Joined: Oct 10, 2005
Posts: 2933

Blue Security Premium

PostPosted: Thu May 15, 2008 11:16 pm    Post subject:
Reply with quote

http://www.123-reg.co.uk/contactUs.shtml


Getting in touch

The easiest way to contact us is through the Ask a Question page on our support site. You need to be a customer!

It'll send your query straight through to the appropriate expert on the 123-reg team, so you'll get a quicker response. It also lets you track all the questions you’ve asked, so if the same problem crops up again you’ll already have the solution to hand.
Other ways to contact us

Write to us: 123-reg GX Networks Ltd 5 Roundwood Avenue Stockley Park Uxbridge UB11 1FF

Telephone us on 0871 230 9525. We're here 9am - 7pm Monday to Friday. Calls cost 10p per minute from a BT landline. We sometimes get busy at peak times.

Technical Contact:
Ltd, GX Networks services [@] 123-reg.co.uk
5 Roundwood Avenue
Stockley Park
Uxbridge, Middlesex UB11 1FF
GB
+44.48712309525 Fax: +44.8701650437

Back to top
View users profile Send private message Visit posters website AIM Address
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Complainterator All times are GMT
Goto page Previous  1, 2, 3, 4, 5, ... 13, 14, 15  Next
Page 3 of 15

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer