Sign Up!
Login
Welcome to Spacequad AntiSpam Services
Saturday, February 04 2012 @ 05:17 AM Eastern Standard Time

Open letter to ICANN and all the Registrars

This is an open letter to ICANN and all the Registrars,

Comments are welcomed by everyone.  Please read all.

Have you ever thought about how the spammers are getting away with the crimes that they commit?  We we have and its very disturbing that ICANN allows this to happen right under their noses.  We will try to explain this as simple and with real information as possible.  First of all you may receive an email toting some frivolous junk advertising like below:

Yep.  Its very sad.  The spammers can't even make a decent message that conforms to the HTML standards, let along proper grammar.  Here is the original HTML from the email and below that is the same one, but cleaned up so that it could be properly displayed

-----------------------------------------------------------

Original HTML message


Even if you have no erection problems = Cialis would=20 help you to make better sex more often and to bring unimaginable = plesure=20 to her. Just disolve half a pill under your tongue and get ready for = action in=20 15 minutes! The tests showed that the majority of men after taking = this=20 medication were able to have perfect erection during 36 hours!

Package Quantity Price in your = local drugstore* Our = price

Learn
More
Now

10 tabs 20 doses $95.95 $34.19
30 tabs 60 doses $349.95 $104.66
60 tabs 120 doses $549.95 $180.15
90 tabs 180 doses $789.95 $242.06
180 tabs 360 doses $1325.95 $445.61

When you are young and stressed = up…
When you are aged and never give up…
Cialis gives you confidence in any chance, every time.

-----------------------------------------------------------

Here is the cleaned up version.  Notice all the equal signs are no longer showing.  Even the table is showing properly and the the link actually shows now

Even if you have no erection problems  Cialis would help you to make better sex more often and to bring unimaginable  pleasure to her. Just dissolve half a pill under your tongue and get ready for  action in 15 minutes! The tests showed that the majority of men after taking  this medication were able to have perfect erection during 36 hours!

Package Quantity Price in your  local drugstore* Our  price

Learn
More
Now

10 tabs 20 doses $95.95 $34.19
30 tabs 60 doses $349.95 $104.66
60 tabs 120 doses $549.95 $180.15
90 tabs 180 doses $789.95 $242.06
180 tabs 360 doses $1325.95 $445.61

When you are young and stressed  up…
When you are aged and never give up…
Cialis gives you confidence in any chance, every time.

-----------------------------------------------------------

Still the message is not as eloquent as it should be if written professionally.  Well anyways, here comes the next part of this story.  When you start to dig into this, its a real mess.   Lets see if we can make any sense of the info that is about to be presented.

The domain name of wentstore.com from the link in the email.  We look it up and get the following on the whois record.

The data in this whois database is provided to you for information
purposes only, that is, to assist you in obtaining information about or
related to a domain name registration record. We make this information
available "as is," and do not guarantee its accuracy. By submitting a
whois query, you agree that you will use this data only for lawful
purposes and that, under no circumstances will you use this data to: (1)
enable high volume, automated, electronic processes that stress or load
this whois database system providing you this information; or (2) allow,
enable, or otherwise support the transmission of mass unsolicited,
commercial advertising or solicitations via direct mail, electronic
mail, or by telephone. The compilation, repackaging, dissemination or
other use of this data is expressly prohibited without prior written
consent from us. We reserve the right to modify these terms at any time.
By submitting this query, you agree to abide by these terms.
Domain name: wentstore.com
Registrant Contact:
liu haijun
haijun liu cncliup@21cn.com
+86.2732290023 fax: +86.2732290023
wuhan
wuhan hubei 361004
cn
Administrative Contact:
haijun liu cncliup@21cn.com
+86.2732290023 fax: +86.2732290023
wuhan
wuhan hubei 361004
cn
Technical Contact:
haijun liu cncliup@21cn.com
+86.2732290023 fax: +86.2732290023
wuhan
wuhan hubei 361004
cn
Billing Contact:
liu haijun cncliup@21cn.com
+86.2732290023 fax: +86.2732290023
wuhan
wuhan hubei 361004
cn
DNS:
ns0.freednsservice1.com
ns0.rootsystemrestore.com
Created: 2007-10-27
Expires: 2008-10-27

Lets take a look at the ISP's that are hosting the spammers website more in detail.  We see that they are currently on several of these IPs as listed, and now if we look at these IPs and see who the ISP is, we see that they are being hosted by several for redundancy backup and failover.  

89.178.164.56    
122.18.253.140
122.123.207.122
125.229.129.121
210.96.207.70
221.127.56.248
81.198.215.67
85.11.167.7
85.179.49.227
85.179.83.181
85.180.252.140
85.250.76.137
89.110.4.27
89.138.196.38
89.178.31.146
Corbin Telecom -  Russia
OCN NTT Communications - Japan
HiNet Internet Service - China
HiNet Internet Service - China
DACOM BoraNet - Korea
Hutchison Global Communications - Japan
Lattelecom - Latvia
SKKNET - Russia
HanseNet Telekommunikation - Germany
HanseNet Telekommunikation - Germany
HanseNet Telekommunikation - Germany
NetVision - Isreal
North-West Telecom - Russia
NetVision - Isreal
Corbin Telecom -  Russia

Now this is one serious spammer that wants to keep their site(s) up and running just for that one domain name.  We've noticed that they are running most likely several domain names that run the same content for Canadian Pharmacy.

Now that we've seen this and start looking thru the whois, wow, where's all the proper information that's supposed to be listed?  We see a name, email name and phone numbers listed.  However, they are most likely bogus (fake) info so that they couldn't easily be tracked.  Okay so we continue our investigation on up the line looking at the DNS provider:

The Data in Paycenter's WHOIS database is provided by Paycenter 
for information purposes, and to assist persons in obtaining 
information about or related to a domain name registration 
record.
Paycenter does not guarantee its accuracy. By submitting 
a WHOIS query, you agree that you will use this Data only 
for lawful purposes and that, under no circumstances will 
you use this Data to:
(1) allow, enable, or otherwise support the transmission 
of mass unsolicited, commercial advertising or solicitations 
via e-mail (spam); or 
(2) enable high volume, automated, electronic processes that 
apply to Paycenter or its systems. 
Paycenter reserves the right to modify these terms at any time. 
By submitting this query, you agree to abide by this policy. 

Domain Name:freednsservice1.com
Registrant: 
Mei guo
Mei guo
610000


Administrative Contact: 
Mei guo
Mei guo
Mei guo
Mei guo 610000
United States
tel: 86 028 89866665 
fax: 86 028 89866665 
df@hotmail.com

Technical Contact: 
Mei guo
Mei guo
Mei guo
Mei guo 610000
United States
tel: 86 028 89866665 
fax: 86 028 89866665 
df@hotmail.com

Billing Contact: 
Mei guo
Mei guo
Mei guo
Mei guo 610000
United States
tel: 86 028 89866665 
fax: 86 028 89866665 
df@hotmail.com

Registration Date: 2007-09-25
Update Date: 2007-09-25
Expiration Date: 2008-09-25

Primary DNS: ns0.kopepharas.com 221.127.56.248
Secondary DNS: ns0.mukopkufude.com 193.77.45.29

And of course lets get the other one involved as well

The Data in Paycenter's WHOIS database is provided by Paycenter 
for information purposes, and to assist persons in obtaining 
information about or related to a domain name registration 
record.
Paycenter does not guarantee its accuracy. By submitting 
a WHOIS query, you agree that you will use this Data only 
for lawful purposes and that, under no circumstances will 
you use this Data to:
(1) allow, enable, or otherwise support the transmission 
of mass unsolicited, commercial advertising or solicitations 
via e-mail (spam); or 
(2) enable high volume, automated, electronic processes that 
apply to Paycenter or its systems. 
Paycenter reserves the right to modify these terms at any time. 
By submitting this query, you agree to abide by this policy. 

Domain Name:rootsystemrestore.com
Registrant: 
Mei guo
Mei guo
610000


Administrative Contact: 
Mei guo
Mei guo
Mei guo
Mei guo 610000
United States
tel: 86 028 89866665 
fax: 86 028 89866665 
df@hotmail.com

Technical Contact: 
Mei guo
Mei guo
Mei guo
Mei guo 610000
United States
tel: 86 028 89866665 
fax: 86 028 89866665 
df@hotmail.com

Billing Contact: 
Mei guo
Mei guo
Mei guo
Mei guo 610000
United States
tel: 86 028 89866665 
fax: 86 028 89866665 
df@hotmail.com

Registration Date: 2007-09-25
Update Date: 2007-09-25
Expiration Date: 2008-09-25

Primary DNS: ns0.kopepharas.com 221.127.56.248
Secondary DNS: ns0.mukopkufude.com 193.77.45.29

Ohh you got to be kidding, right?  Looks like the same person owns both DNS domains.  Okay that's not a crime in itself.  However, falsifying information is according to ICANN rules and policies regulations

So it is our belief that the whois information listed above in the records is falsified and incorrect.  If you are a Registrar, please be advised that we intend to start submitting domain names for verification on all information listed in the domains.  If such information is found to be incorrect, it is your responsibilities to cancel these domains.  If you do not follow ICANN's policies, then you, as the Registrar are in violation and could loose your accreditation and domain name.

Everyone is welcome to submit there commets

 

5 comments

The following comments are owned by whomever posted them. This site is not responsible for what they say.
Authored by: Anonymous on Wednesday, October 31 2007 @ 02:26 PM Eastern Daylight Time Open letter to ICANN and all the Registrars
Its about time someone wrote something like this up, so that we can see how this process works. You have my vote to make changes for the better, by cancelling thier domain name if they mess up.
[ # ]
Authored by: Anonymous on Monday, November 05 2007 @ 04:21 PM Eastern Standard Time Open letter to ICANN and all the Registrars
If you believe that ICANN or any other registrars care, you are sadly mistaken.. I have tried and tried to get ICANN involved in a registrar and ISP that were using my domain name and emails in falseified headers. They wouldn't get involved. Period. It is sad that the agency responsible for the administration and regulation of registrars and how IP addresses are used, don't take an active role in stopping such activities. I guess we can only hope. But try navigating ICANN for a complaint or contact form.. Laughable.
[ # ]
Authored by: Anonymous on Thursday, November 29 2007 @ 04:28 PM Eastern Standard Time Open letter to ICANN and all the Registrars
More cannon fodder - all from cncliup@21cn.com / Canadian Pharmacy.
Registered via Bizcn.com:

coastburn.com
modernwide.com
moondiscuss.com
thattire.com
wallfresh.com
wrotesafe.com

Registered via Todaynic.com

32meds.com
43meds.com
aacsrwalty.com
aadlutswim.com
aalullbayi.com
aareydrugs.com
aarontoown.com
aaropastal.com
aasansabag.com
ablediscuss.com
beautycold.com
charactereven.com
companyhis.net
developtail.com
electricsaid.com
exercisereach.com
feedsettle.com
finalwheel.com
fivejoy.com
fronthorse.net
gardenoffer.net
grewsoil.com
halfanswer.com
kingbrought.com
largeso.com
listencarry.com
lookoffer.net
noseneck.com
numeralcity.com
producesolve.com
propercame.com
properthick.com
repeatask.com
seemdesert.com
selectmonth.com
shoreyou.net
solvewent.com
spreadperiod.com
successfree.net
syllableanger.com
tallplan.net
thousandother.com
tinydown.com
toosingle.com
townslip.com
trainfeet.com
trianglesentence.com
verbespecially.com
wouldbegin.com
writtenwhat.com

All on IP 88.255.90.2.

But hello - what is this - also on this IP: believeside.com - the same website!
Whois says:
Domain Name.......... believeside.com
  Creation Date........ 2007-11-08 00:28:40
  Registration Date.... 2007-11-08 00:28:40
  Expiry Date.......... 2008-11-08 00:28:40
  Organisation Name.... tommy
  Organisation Address. tommy lee
  Organisation Address.
  Organisation Address. Foreignness
  Organisation Address. 53300
  Organisation Address. WG
  Organisation Address. NP

Admin Name........... tommy lee
  Admin Address........ tommy lee
  Admin Address........
  Admin Address........ Foreignness
  Admin Address........ 53300
  Admin Address........ WG
  Admin Address........ NP
  Admin Email.......... tomy@mlgsl.com.my
  Admin Phone.......... +0.602289988-99
  Admin Fax............ +0.603389989

Tech Name............ tommy lee
  Tech Address......... tommy lee
  Tech Address.........
  Tech Address......... Foreignness
  Tech Address......... 53300
  Tech Address......... WG
  Tech Address......... AZ
  Tech Email........... tomy@worl.com
  Tech Phone........... +0.605543228-90
  Tech Fax............. +0.605543228

Bill Name............ DB S
  Bill Address......... aa
  Bill Address.........
  Bill Address......... Shenzhen    
  Bill Address......... 31313   
  Bill Address......... GD    
  Bill Address......... CN  
  Bill Email........... agent15591@agent.dns.com.cn
  Bill Phone........... +86.13123456789-90
  Bill Fax............. +86.13123456789
  Name Server.......... ns2.holdsurface.com
  Name Server.......... ns1.holdsurface.com
Same  whois and website:
glassthrough.com
goldverb.com
mostwinter.com
scalespread.com


And more - eachwave.com - same website:
Domain Name.......... eachwave.com
  Creation Date........ 2007-11-08 00:16:38
  Registration Date.... 2007-11-08 00:16:38
  Expiry Date.......... 2008-11-08 00:16:38
  Organisation Name.... denies
  Organisation Address. cheras
  Organisation Address.
  Organisation Address. Foreignness
  Organisation Address. 43200
  Organisation Address. WG
  Organisation Address. MY

Admin Name........... denies ooi
  Admin Address........ cheras
  Admin Address........
  Admin Address........ Foreignness
  Admin Address........ 43200
  Admin Address........ WG
  Admin Address........ MY
  Admin Email.......... den@woeoeo.cm
  Admin Phone.......... +0.60920569-68
  Admin Fax............ +0.609205696

Tech Name............ DB S
  Tech Address......... aa
  Tech Address.........
  Tech Address......... Shenzhen
  Tech Address......... 31313
  Tech Address......... GD
  Tech Address......... CN
  Tech Email........... agent15591@agent.dns.com.cn
  Tech Phone........... +86.13123456789-68
  Tech Fax............. +86.13123456789

Bill Name............ DB S
  Bill Address......... aa
  Bill Address.........
  Bill Address......... Shenzhen    
  Bill Address......... 31313   
  Bill Address......... GD    
  Bill Address......... CN  
  Bill Email........... agent15591@agent.dns.com.cn
  Bill Phone........... +86.13123456789-68
  Bill Fax............. +86.13123456789
  Name Server.......... ns2.holdsurface.com
  Name Server.......... ns1.holdsurface.com
Also same whois and website:
liquidmolecule.com
magnetwide.com
mustplane.com
sevendepend.com
windowlisten.com


Please explain the "Foreignness" between these three sets of results for the same website!

Then we add fraud to the mix:
The Verisign seal is fake, it is hosted onsite:
http://scalespread.com/checker2.php

So is the American Drug Administration Seal:
http://scalespread.com/checker3.php

The Canadian International Drug Association seal is fake as well:
http://scalespread.com/checker4.php

“PharmaChecker”  is of course fake:
http://scalespread.com/checker1.php

The real Mr Thorkelson had this to say:
"The is one of many web sites created by a group that has been doing a large amount of 
spamming. They copied my information and have been using it without my consent. I have no idea
who theyare but as you can see all of their credentials are fake.

Good luck in finding out more about these people.

Kris Thorkelson
CEO of the CanadaDrugs.com Group of Companies"

From: http://spamtrackers.hk/wiki/doku.php?id=canadian_pharmacy

So we have about 60 odd domains with invalid whois details that keeps changing and is incomplete/invalid, four deliberate pieces of fraud on each web page, in total fraud has been committed 240 times!

And just by coincidence all of these are using the  holdsurface.com domain as a name server domain:
Domain Name: HOLDSURFACE.COM
   Registrar: XIN NET TECHNOLOGY CORPORATION
   Whois Server: whois.paycenter.com.cn
   Referral URL: http://www.xinnet.com
   Name Server: NS.XINNET.CN
   Name Server: NS.XINNETDNS.COM
   Status: ok
   Updated Date: 02-oct-2007
   Creation Date: 30-jul-2007
   Expiration Date: 30-jul-2008

Domain Name:holdsurface.com

Registrant:
Stephen Patterson
    9857 WEXFORD CIR
    95746 

Administrative Contact:
Stephen Patterson
    Stephen Patterson
    9857 WEXFORD CIR
    GRANITE BAY  95746
    United States
    tel: 86 916 791 6222
    fax: 86 916 791 6222
    dfere@hotmail.com
   
Technical Contact:
Stephen Patterson
    Stephen Patterson
    9857 WEXFORD CIR
    GRANITE BAY  95746
    United States
    tel: 86 916 791 6222
    fax: 86 916 791 6222
    dfere@hotmail.com
   
Billing Contact:
Stephen Patterson
    Stephen Patterson
    9857 WEXFORD CIR
    GRANITE BAY  95746
    United States
    tel: 86 916 791 6222
    fax: 86 916 791 6222
    dfere@hotmail.com
   
 Registration Date: 2007-07-30
       Update Date: 2007-10-02
   Expiration Date: 2008-07-30
   
    Primary DNS:  ns.xinnetdns.com        210.51.170.66
  Secondary DNS:  ns.xinnet.cn        210.51.171.209

A quick check shows that the telephone number is for China,
the "9857 WEXFORD CIR" address is a property listing:
http://www.movoto.com/real-estate/homes-for-sale/CA/Granite-Bay/9857-Wexford-Cir-102_70076136.htm
http://www.zillow.com/HomeDetails.htm?zprop=17722340

The oldest trick int the book!
IP addresses:
ns1.holdsurface.com [89.248.99.107] = ES-INTERDOMINIOS-COM-20060704
ns2.holdsurface.com - times out
--- Found authoritative nameserver: ns.xinnet.cn
--- contacting nameserver: ns.xinnet.cn [210.51.171.209]
    DNS Server Response 3: Name Error


Note to Mr Thorkelson - We do know who this is.

This is not some spammer in China - this is Russian Business Networks.
The IP address 88.255.90.2 belongs to AbdAllah Internet Hizmetleri. It is now public knowledge that AbdAllah Internet Hizmetleri is under the control of RBN.
From the SANS Internet Storm Center:  http://isc.sans.org/presentations/RBN_study.pdf

As such we are allowing ourselves to become cannon fodder for the RBN by allowing these domains to live on. ICANN cannot ignore the seriousness of this issue.
[ # ]

Find us on Facebook



Follow us Twitter

Blog Writers Needed

Spacequad is looking for volunteer story writers. If you think you have what it takes to be a part of our team, then submit your interests by contacting us.

Login

Username:

Password:


Don't have an account yet? Sign up as a New User
Lost your password


Consider Donating

Spacequad AntiSpam Services talks to the registrars and ISPs to get abusive domains terminated. If we encounter spam or network abuse, we let the proper authority know about it. If you find that your spam levels have gone down, its probably because we have had the spammer terminated from doing what they had been doing. Please consider donating to our cause.by using your PayPal, please click on the button below. If you feel that more needs to be done, please let us know, so that we can work with you on that.


Please consider a donation, so we can keep bringing you free services...

Testimonials

Thank you and your team. We couldn’t do it without you.

Thanks again and great job!



Tamir Jerby
888holdings

Ads

Facebook