Been receiving many spams advertising 'premier pharmacy'. EditSorry - that's wrong. It's Pharmacy Express./edit The actual networks used to send the spam seem to be many, various and ever-changing. So I decided to try going after the spamvertised site itself. The domains change constantly but the IP seems much more 'stable' whilst the content is always identical.
I used spamcop to identify 'risinglordames.com' as being hosted by hichina.com / chinatietong.com. Previous domains used by the same spammer include:
ascendingmorsab.com
wicipasse.com
otecoureis.com
baicoscu.com
ploretocea.com
edeavilat.com and many many more
Currently they seem to be on www.degreisapo.com at the usual IP of 61.233.42.4
Eh up, we're onto www.vanteweks.com now, in the space of 5 minutes; IP... 61.233.42.4; same site content.
Spamcop reports all these as being hosted by hichina.com
After reporting several hundred spams via spamcop with no let up in the frequency, I began reporting them directly to abuse[at]hichina.com. I eventually received a reply from a personage at hichina, but they said the site had nothing to do with them:
QUOTE
You mentioned has brought to our attention.But these illegal, the repugnant activity has nothing to do with us.
we have received the attached unsolicited e-mail from your domain.we do not wish to receive such messages in the future, so please take the appropriate measures
to ensure that this unsolicited e-mail is not repeated.
Thank you again ! Best greetings.
we have received the attached unsolicited e-mail from your domain.we do not wish to receive such messages in the future, so please take the appropriate measures
to ensure that this unsolicited e-mail is not repeated.
Thank you again ! Best greetings.
In the past I've found a combination of spamcop & manual reporting to be very effective at stopping spam, but this particular online pharmacy spam seems to be exceptionally good at persisting. I know I could just filter the spam I get for this site & it's many variants (about 300 spams per day) but they bug me & if I can report them to the correct place that would be very satisfying. If, that is, the 'correct place' actually recognises the problem in the first place..
They send a subject line always of the format 'drug name in capitals, interspersed with a few random lower case letters', 'space', followed by 'new' or 'news':
http://img96.imageshack.us/img96/883/ffffff4yv.jpg
I've tried doing a network lookup independent of spamcop on a couple of these domains & they seem to confirm hichina / chinatietong / china railway as the host, contrary to the email I recieved. Either that or else what they're trying to say is, they don't see hosting a spam site as a problem so long as they're not actually carrying the mail itself.. I'm kinda confused here. (Maybe belinn's post is of relevance to this situation?) I know vaguely how to work a few IP tools but I'm no network expert. Maybe neither hichina.com nor chinatietong.com really have anything to do with it at all & it's some kinda case of forged headers?
Here is an example of spamcop's analysis (an expanded excerpt of the part where it investigates a spamvertised web address).. one of hundreds all ultimately reaching the same conclusion as to the origin of the sites' hosting:
CODE
Resolving link obfuscation
http://www.risinglordames.com
Host www.risinglordames.com (checking ip) = 61.233.42.4
host 61.233.42.4 (getting name) no name
Tracking link: http://www.risinglordames.com
Resolves to 61.233.42.4
Routing details for 61.233.42.4
Reports routes for 61.233.42.4:
routeid:19140192 61.232.0.0 - 61.237.255.255 to:crnet_mgr[at]chinatietong.com
Administrator found from whois records
routeid:19140193 61.232.0.0 - 61.237.255.255 to:crnet_tec[at]chinatietong.com
Administrator found from whois records
Tracking details
"whois 61.233.42.4[at]whois.apnic.net" (Getting contact from whois.apnic.net mirror)
$ whois 61.233.42.4
[spamcop mirror]
inetnum: 61.232.0.0 - 61.237.255.255
netname: CRTC
country: CN
descr: CHINA RAILWAY TELECOMMUNICATIONS CENTER
admin-c: LQ112-AP
tech-c: LM273-AP
status: ALLOCATED PORTABLE
changed: ipxx[at]cnxxxxxxxxxx 20030121
mnt-by: MAINT-CNNIC-AP
source: APNIC
person: liu min
nic-hdl: LM273-AP
e-mail: crxxxxxxx[at]chxxxxxxxxxxxxxx
address: 22F Yuetan Mansion,Xicheng District,Beijing,P.R.China
phone: +86-10-51848796
fax-no: +86-10-51842426
country: CN
changed: ipxx[at]cnxxxxxxxxxx 20041208
mnt-by: MAINT-CNNIC-AP
source: APNIC
person: LV QIANG
nic-hdl: LQ112-AP
e-mail: crxxxxxxx[at]chxxxxxxxxxxxxxx
address: 22F Yuetan Mansion,Xicheng District,Beijing,P.R.China
phone: +86-10-51892106
fax-no: +86-10-51890674
country: CN
changed: ipxx[at]cnxxxxxxxxxx 20050823
mnt-by: MAINT-CNNIC-AP
source: APNIC
lq112-ap = crnet_mgr[at]chinatietong.com
lm273-ap = crnet_tec[at]chinatietong.com
whois.apnic.net 61.233.42.4 = crnet_mgr[at]chinatietong.com, crnet_tec[at]chinatietong.com
whois: 61.232.0.0 - 61.237.255.255 = crnet_mgr[at]chinatietong.com, crnet_tec[at]chinatietong.com
Routing details for 61.233.42.4
Reports routes for 61.233.42.4:
routeid:19140215 61.232.0.0 - 61.237.255.255 to:crnet_mgr[at]chinatietong.com
Administrator found from whois records
routeid:19140216 61.232.0.0 - 61.237.255.255 to:crnet_tec[at]chinatietong.com
Administrator found from whois records
Using abuse net on crnet_mgr[at]chinatietong.com
abuse net chinatietong.com = postmaster[at]chinatietong.com, abuse[at]hichina.com
Using best contacts postmaster[at]chinatietong.com abuse[at]hichina.com
Cached whois for 61.233.42.4 : crnet_mgr[at]chinatietong.com crnet_tec[at]chinatietong.com
Using abuse net on crnet_mgr[at]chinatietong.com
abuse net chinatietong.com = postmaster[at]chinatietong.com, abuse[at]hichina.com
Using best contacts postmaster[at]chinatietong.com abuse[at]hichina.com
Any advice welcome thanks
At the mo I've given up on these lot & am just filtering it all into the bin.
