CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

ESTDomains and Spam?

 
Post new topic   Reply to topic       All -> FavForums -> Spam [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
moike

PIRT Handler
Premium Member

Joined: May 26, 2006
Posts: 1873

Phishing Squad Premium

PostPosted: Sat Aug 30, 2008 3:57 pm    Post subject: ESTDomains and Spam?
Reply with quote

ESTDomains is generally very responsive to phishing takedown requests via the web form. Are they as good about Spam domains? I remember some recent thread, but I can't find it now.

If you have any comments, these blog post comments will provide direct feedback to ESTDomains http://voices.washingtonpost.com/securityfix/2008/08/report_slams_us_host_as_major.html#comments

Back to top
View users profile Send private message
Tromso

Corporal
Corporal
Premium Member

Joined: May 25, 2007
Posts: 59

Premium

PostPosted: Sat Aug 30, 2008 10:03 pm    Post subject:
Reply with quote

Very interesting. Here are more articles connected with this:

http://www.spamhaus.org/news.lasso?article=636

http://www.knujon.com/news.html#directi
(See Aug 29th and earlier 28th Aug article)

Spamhaus's concluding comment made me chuckle:

Quote:

Perhaps one may be wondering about the costs of hosting at Atrivo/Intercage or how to sign up? Well, don't expect to find this information at the company's websites as they were empty for years and for the last year have just shown "Website Coming Soon."

http://www.atrivo.com => "InterCage, Inc. INTENSE SERVERS. Website Coming Soon:"
Last Updated: Thursday, September 06, 2007 4:32:59 PM

http://www.intercage.com => "InterCage, Inc. INTENSE SERVERS. Website Coming Soon:"
Tuesday, September 04, 2007 6:45:52 PM

At one time after being asked, "how on earth does your company get business?" an Atrivo/Intercage representative coyly said, "by word of mouth." That seems to be quite obvious.

Back to top
View users profile Send private message
moike

PIRT Handler
Premium Member

Joined: May 26, 2006
Posts: 1873

Phishing Squad Premium

PostPosted: Sun Aug 31, 2008 1:03 am    Post subject:
Reply with quote

Thanks for the additional articles - fascinating analysis by Knujon. I loved the Spamhaus comments also!

Back to top
View users profile Send private message
s0tet

PIRT Handler


Joined: May 21, 2005
Posts: 2976

Phishing Squad

PostPosted: Sun Aug 31, 2008 3:23 am    Post subject:
Reply with quote

The latest Spamhaus blog entry (and Knujon's) about Atrivo/Intercage is good reading. Thanks for pointing that out.

Back to top
View users profile Send private message Send email
pwillener

SRT Trainee
SRT Trainee
Premium Member

Joined: Apr 17, 2006
Posts: 1838
Location: Japan
Premium

PostPosted: Mon Sep 01, 2008 1:20 am    Post subject:
Reply with quote

I also found the Knujon 'directi.com' / 'publicdomainregistry.com' article interesting, especially the aspect of where they are located.

The servers for www.directi.com [209.62.85.50] and www.publicdomainregistry.com [209.62.85.57] are located in New York. Email replies from PDR regarding abuse reports come from mail.internal.directi.com [203.199.114.35] which is in Mumbai, India.

Back to top
View users profile Send private message Visit posters website
s0tet

PIRT Handler


Joined: May 21, 2005
Posts: 2976

Phishing Squad

PostPosted: Sun Sep 07, 2008 1:00 am    Post subject:
Reply with quote

Informative blog entry by Gadi Evron

He is calling Atrivo / Intercage: an American RBN

http://gadievron.blogspot.com/2008/09/cyber-crimean-economic-problem.html

Back to top
View users profile Send private message Send email
Tromso

Corporal
Corporal
Premium Member

Joined: May 25, 2007
Posts: 59

Premium

PostPosted: Tue Sep 09, 2008 12:15 am    Post subject:
Reply with quote

The chief executive of EstDomains , 27-year-old Vladimir Tsastsin apparently has a criminal past.

http://voices.washingtonpost.com/securityfix/2008/09/estdomains_a_sordid_history_an.html

Quote:
Tartu County Court just found a man working as the acting manager of an IT company guilty of entering illegal data into card payment systems of Internet stores for the purpose of material gain, creating forged documents, using forged documents, and money laundering.

The court sentenced 27 year old Vladimir Tsastsin to three years imprisonment of which 6 months and 11 days must be served , according to Tartu County Court press office.

Since Tsastsin already spent that much time in pretrial detention, it will be counted as time served.


Joint statement from Directi, HostExploit and Kunujon Sept 7th 2008
http://hostexploit.com

Worth remembering:
"Directi reaffirmed that its abuse team will suspend privacy protection on any domain for which they receive a genuine complaint in less than 24 hours."

Atrivo seems to be losing its internet connections and some of its IP addresses are being recalled. See comment updates:

http://voices.washingtonpost.com/securityfix/2008/09/scam-heavy_us_isp_grows_more_i.html

Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Spam All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer