[SIRT#196361] Pharmacy Express on biomedgene.eu

CastleCops -> SIRT Reports

Author: jimVOLocation: USA PostPosted: Sat Jul 05, 2008 6:44 pm    Post subject: [SIRT#196361] Pharmacy Express on biomedgene.eu

Spam Alert
 
 Full Report: CastleCops Link/Pharmacy_Express_spam196361.html
 
 Changed status to confirmed spam.IP Converted: 200.171.139.77

dword = 3366685517
hex1 = 0xc8ab8b4d
hex2 = 0xc8.0xab.0x8b.0x4d
oct = 0310.0253.0213.0115
View CIDR AS27699 Report: http://www.cidr-report.org/cgi-bin/as-report?as=27699

"27699 | BR | lacnic | 2003-06-24 | TELECOMUNICACOES DE SAO PAULO S/A - TELESP"<br />
Extended information for AS27699:
State/Province:
Country: br
Responsible Domain: telesp.com.br
Abuse Email: abuse@telesp.net.br
Criminal Evidence

See the Spam Wiki entry at http://www.spamtrackers.eu/wiki/index.php?title=$title$
or from China: http://www.spamtrackers.hk/wiki/index.php?title=$title$
See the McAfee Site Advisor information at http://siteadvisor.com/sites/biomedgene.eu


> OnlineNIC
REGISTRATION OF THE WEB SITE: biomedgene.eu
ACTION: To suspend this criminal site which breaks your terms of service, set the domain status to clientHold


> BEIJING INNOVATIVE LINKAGE TECHNOLOGY
REGISTRATION OF THE NAME SERVERS
These name servers are registered by criminals to resolve only illegal web sites. This breaks your terms of service. You can safely suspend them:
ns1.capsulesweight.com 83.14.132.126 ebc126.internetdsl.tpnet.pl Clean Poland URIBL
ns2.capsulesweight.com 211.139.7.70 211.139.7.70 Clean China URIBL

ACTION: To suspend these name servers successfully, follow these steps.
1. set the ns Address records to a non-routable address, such as 127.0.0.1 or 61.61.61.61.
2. Set the domain status to clientUpdateProhibited, clientTransferProhibited, clientDeleteProhibited, and clientHold


> TELECOMUNICACOES DE SAO PAULO
IP ADDRESS OF HOST: 200.171.139.77
The IP address of this criminal site is within your allocated address space.
ACTION: Black-hole the route to this address to prevent further criminal activity
Quote:
http://biomedgene.eu

Author: tembow PostPosted: Sat Jul 05, 2008 9:43 pm    Post subject:

Arrival-Date: Sat, 5 Jul 2008 18:45:23 +0000 (UTC)

Final-Recipient: rfc822; cnreg@dns.com.cn
Action: failed
Status: 5.0.0
Remote-MTA: dns; mail.dns.com.cn
Diagnostic-Code: smtp; 550 Does not like recipient,your mail is rejected!

Final-Recipient: rfc822; huyan@dns.com.cn
Action: failed
Status: 5.0.0
Remote-MTA: dns; mail.dns.com.cn
Diagnostic-Code: smtp; 550 Does not like recipient,your mail is rejected!

Author: tembow PostPosted: Fri Jul 11, 2008 3:07 am    Post subject:

Arrival-Date: Sat, 5 Jul 2008 18:45:23 +0000 (UTC)

Final-Recipient: rfc822; abuse@telesp.net.br
Action: failed
Status: 4.4.2
Diagnostic-Code: X-Postfix; lost connection with
gbrsecurity02.telesp.net.br[200.171.222.87] while receiving the initial
server greeting



CastleCops -> SIRT Reports

All times are GMT

Page 1 of 1


Powered by phpBB © 2001 phpBB Group