SMS Spam: 502-4562-0820

Yet another SMS spam. This one reads:

“FELICIDADES” IUSACEL, Te Inf. Gracias a tu Mòvil eres Ganador : US$ 45,000 Y 1 TOYOTA PRADO 2012 ” Gracias ” A : HONDUTEL Mayor info. PBX: 01150242582314.

Google translates it as:

“CONGRATULATIONS” IUSACEL, Information Thank you for your cell phone you are Winner: U.S. $ 45.000 and 1 TOYOTA PRADO 2012 “Thank you” A: HONDUTEL More Info. PBX: 01150242582314.

I’m assuming that it comes from Honduras.

Scam Alert: samplerewardsonline.com

UPDATE:
samplerewardsonline.com has the IP 38.101.10.141 which belongs to Cogent.
Please contact: abuse@cogentco.com

——-

First, there is no such thing as iPhone 5 at this point in time. Apple is not looking for iPhone 5 testers and never did so in the past with their product.

This investigation was prompted by a spam SMS from +1 (646) 709-7845 that says:

Apple is looking for iPhone 5 testers! The first 1000 users that go to http://mobile-testers.com and enter code 0214 will get to test & keep a new iPhone 5

The site mobile-testers.com is a portal to samplerewardsonline.com. The domain name was registered on February 1st, 2012 through eNom, Inc. and hosted by HostGator. The domain registration is also protected by WhoisGuard based on whois query.

You can enter any 4-character-code into the field and continue and it will redirect to samplerewardsonline.com.

Whois information on samplerewardsonline.com:

Lions-share:~ suspicious-bagel$ whois samplerewardsonline.com

Whois Server Version 2.0

Domain names in the .com and .net domains can now be registered
with many different competing registrars. Go to http://www.internic.net
for detailed information.

Domain Name: SAMPLEREWARDSONLINE.COM
Registrar: DYNAMIC DOLPHIN, INC.
Whois Server: whois.dynamicdolphin.com
Referral URL: http://www.dynamicdolphin.com
Name Server: NS1.SAMPLEREWARDSONLINE.COM
Name Server: NS2.SAMPLEREWARDSONLINE.COM
Status: clientTransferProhibited
Updated Date: 21-sep-2011
Creation Date: 21-sep-2011
Expiration Date: 21-sep-2012

>>> Last update of whois database: Tue, 07 Feb 2012 02:14:38 UTC <<<

NOTICE: The expiration date displayed in this record is the date the
registrar’s sponsorship of the domain name registration in the registry is
currently set to expire. This date does not necessarily reflect the expiration
date of the domain name registrant’s agreement with the sponsoring
registrar.  Users may consult the sponsoring registrar’s Whois database to
view the registrar’s reported date of expiration for this registration.

TERMS OF USE: You are not authorized to access or query our Whois
database through the use of electronic processes that are high-volume and
automated except as reasonably necessary to register domain names or
modify existing registrations; the Data in VeriSign Global Registry
Services’ (“VeriSign”) Whois database is provided by VeriSign for
information purposes only, and to assist persons in obtaining information
about or related to a domain name registration record. VeriSign does not
guarantee its accuracy. By submitting a Whois query, you agree to abide
by the following terms of use: You agree that you may use this Data only
for lawful purposes and that under no circumstances will you use this Data
to: (1) allow, enable, or otherwise support the transmission of mass
unsolicited, commercial advertising or solicitations via e-mail, telephone,
or facsimile; or (2) enable high volume, automated, electronic processes
that apply to VeriSign (or its computer systems). The compilation,
repackaging, dissemination or other use of this Data is expressly
prohibited without the prior written consent of VeriSign. You agree not to
use electronic processes that are automated and high-volume to access or
query the Whois database except as reasonably necessary to register
domain names or modify existing registrations. VeriSign reserves the right
to restrict your access to the Whois database in its sole discretion to ensure
operational stability.  VeriSign may restrict or terminate your access to the
Whois database for failure to abide by these terms of use. VeriSign
reserves the right to modify these terms at any time.

The Registry database contains ONLY .COM, .NET, .EDU domains and
Registrars.
Registration Service Provided By: DYNAMIC DOLPHIN, INC
Contact: +1.7208723477

Domain Name: SAMPLEREWARDSONLINE.COM

Registrant:
Dynamic Dolphin Privacy Protection
Privacy Protect        (privacyprotect@dynamicdolphin.com)
5023 W 120th Ave #233
Broomfield
Colorado,80020
US
Tel. +001.7208723477

Creation Date: 21-Sep-2011
Expiration Date: 21-Sep-2012

Domain servers in listed order:
ns1.samplerewardsonline.com
ns2.samplerewardsonline.com

Administrative Contact:
Dynamic Dolphin Privacy Protection
Privacy Protect        (privacyprotect@dynamicdolphin.com)
5023 W 120th Ave #233
Broomfield
Colorado,80020
US
Tel. +001.7208723477

Technical Contact:
Dynamic Dolphin Privacy Protection
Privacy Protect        (privacyprotect@dynamicdolphin.com)
5023 W 120th Ave #233
Broomfield
Colorado,80020
US
Tel. +001.7208723477

Billing Contact:
Dynamic Dolphin Privacy Protection
Privacy Protect        (privacyprotect@dynamicdolphin.com)
5023 W 120th Ave #233
Broomfield
Colorado,80020
US
Tel. +001.7208723477

Status:LOCKED
Note: This Domain Name is currently Locked. In this status the domain
name cannot be transferred, hijacked, or modified. The Owner of this
domain name can easily change this status from their control panel.
This feature is provided as a security measure against fraudulent domain name hijacking.

samplerewardsonline.com is registered through Dynamic Dolphin, Inc.

samplerewardsonline.com IP is 38.101.10.141 which in the same block with similar scam sites such as Populargiftsforyou.com and PlanetGiftRewards.com

Scam and Spam Alert: mobile-testers.com

New round of SMS spam that is also a scam from mobile-testers.com. The unsolicited SMS is coming from +1 (646) 709-7845 and the message is saying:

Apple is looking for iPhone 5 testers! The first 1000 users that go to http://mobile-testers.com and enter code 0214 will get to test & keep a new iPhone 5

Apple IS NOT looking for iPhone 5 testers. Apple IS NOT calling the next iPhone by “iPhone 5” name yet. This is clearly a SCAM.

The domain mobile-testers.com is registered through eNom, Inc. and protected by WhoisGuard (see WhoIs information at the bottom of this post).

If you’re getting this SMS spam, you should:

  • Report mobile-testers.com as spam to WhoisGuard through the Report Spam page.
  • File complaints on FCC site.
    File a complaint on FCC site http://esupport.fcc.gov/complaints.htm
    You should file form 1088G to report this violation.
    You can also call 1-888-CALL-FCC (1-888-2255-322) voice; 1-888-TELL-FCC (1-888-8355-322) TTY.
    According to FCC, this type of “marketing” does violate CAN-SPAM Act.

At the time of this posting mobile-testers.com displays:

Service Unavailable
Server currently undergoing maintenance. Webmaster: please contact support.

UPDATE:
From Google Cache

Based on the WhoIs information, mobile-testers.com is using HostGator DNS. The IP address is 174.132.151.98, a SoftLayer/ThePlanet.com IP which is assigne to HostGator; a reseller of the service.

 

Whois information on mobile-testers.com:

Lions-share:~ suspicious-bagel$ whois mobile-testers.com

Whois Server Version 2.0

Domain names in the .com and .net domains can now be registered
with many different competing registrars. Go to http://www.internic.net
for detailed information.

Domain Name: MOBILE-TESTERS.COM
Registrar: ENOM, INC.
Whois Server: whois.enom.com
Referral URL: http://www.enom.com
Name Server: NS1343.HOSTGATOR.COM
Name Server: NS1344.HOSTGATOR.COM
Status: clientTransferProhibited
Updated Date: 05-feb-2012
Creation Date: 01-feb-2012
Expiration Date: 01-feb-2013

>>> Last update of whois database: Mon, 06 Feb 2012 20:39:31 UTC <<<

NOTICE: The expiration date displayed in this record is the date the
registrar’s sponsorship of the domain name registration in the registry is
currently set to expire. This date does not necessarily reflect the expiration
date of the domain name registrant’s agreement with the sponsoring
registrar.  Users may consult the sponsoring registrar’s Whois database to
view the registrar’s reported date of expiration for this registration.

TERMS OF USE: You are not authorized to access or query our Whois
database through the use of electronic processes that are high-volume and
automated except as reasonably necessary to register domain names or
modify existing registrations; the Data in VeriSign Global Registry
Services’ (“VeriSign”) Whois database is provided by VeriSign for
information purposes only, and to assist persons in obtaining information
about or related to a domain name registration record. VeriSign does not
guarantee its accuracy. By submitting a Whois query, you agree to abide
by the following terms of use: You agree that you may use this Data only
for lawful purposes and that under no circumstances will you use this Data
to: (1) allow, enable, or otherwise support the transmission of mass
unsolicited, commercial advertising or solicitations via e-mail, telephone,
or facsimile; or (2) enable high volume, automated, electronic processes
that apply to VeriSign (or its computer systems). The compilation,
repackaging, dissemination or other use of this Data is expressly
prohibited without the prior written consent of VeriSign. You agree not to
use electronic processes that are automated and high-volume to access or
query the Whois database except as reasonably necessary to register
domain names or modify existing registrations. VeriSign reserves the right
to restrict your access to the Whois database in its sole discretion to ensure
operational stability.  VeriSign may restrict or terminate your access to the
Whois database for failure to abide by these terms of use. VeriSign
reserves the right to modify these terms at any time.

The Registry database contains ONLY .COM, .NET, .EDU domains and
Registrars.
=-=-=-=

Registration Service Provided By: Namecheap.com
Contact: support@namecheap.com
Visit: http://namecheap.com

Domain name: mobile-testers.com

Registrant Contact:
WhoisGuard
WhoisGuard Protected ()

Fax:
11400 W. Olympic Blvd. Suite 200
Los Angeles, CA 90064
US

Administrative Contact:
WhoisGuard
WhoisGuard Protected (ddeb681058d445c29c606b0a45f3dab0.protect@whoisguard.com)
+1.6613102107
Fax: +1.6613102107
11400 W. Olympic Blvd. Suite 200
Los Angeles, CA 90064
US

Technical Contact:
WhoisGuard
WhoisGuard Protected (ddeb681058d445c29c606b0a45f3dab0.protect@whoisguard.com)
+1.6613102107
Fax: +1.6613102107
11400 W. Olympic Blvd. Suite 200
Los Angeles, CA 90064
US

Status: Locked

Name Servers:
ns1343.hostgator.com
ns1344.hostgator.com

Creation date: 01 Feb 2012 15:15:00
Expiration date: 01 Feb 2013 07:15:00

——-

Also filed under Text-Spammer

Spammer Alert: superdooperdeals.com

Readers sent us a few info about new round of spam from superdooperdeals.com. Do not give them your email addresses with hope you’d be unsubscribed from their spam bombardments. superdooperdeals.com site includes some fake testimonials that don’t even make any sense.

Whois info on superdooperdeals.com:

Registration Service Provided By: Namecheap.com
Contact: support@namecheap.com
Visit: http://namecheap.com

Domain name: Superdooperdeals.com

Registrant Contact:
SuperDooperDeals
Liam Carroll ()

Fax:
15500 SW Jay Street #38743
Beaverton, OR 97006
US

Administrative Contact:
SuperDooperDeals
Liam Carroll (liam@superdooperdeals.com)
+1.5033038404
Fax: +1.5555555555
15500 SW Jay Street #38743
Beaverton, OR 97006
US

Technical Contact:
SuperDooperDeals
Liam Carroll (liam@superdooperdeals.com)
+1.5033038404
Fax: +1.5555555555
15500 SW Jay Street #38743
Beaverton, OR 97006
US

Status: Locked

Name Servers:
ns1.superdooperdeals.com
ns2.superdooperdeals.com

Creation date: 23 Mar 2011 03:15:00
Expiration date: 22 Mar 2012 22:15:00

Other Domain Registered by superdooperdeals.com:

  • bingolikey.com
  • carz-online.com
  • luxuryhosting.net
  • yourkeywords.net
  • we-mean-business.org
  • playwithusdaily.com

We will add more info whenever we get them.

eNom and namecheap are the DNS Registrar that superdooperdeal.com uses, but they are willing to resolve the issue.

This is a sample of namecheap.com reply to the complaints:

Hello,

Thank you for your email regarding researchsneeze.info domain name. The domain that you reported is registered with NameCheap but hosted with another company. Please contact the hosting company for help with investigating the incident of spam. You will need to forward entire email with full headers to them. Here are contact details of the company that owns IP address assigned to the domain:

http://who.is/whois-ip/108.60.156.10/
——————–
Regards,
Marta K.
Customer Support

http://whois.arin.net/rest/nets;q=108.60.156.10?showDetails=true&showARIN=false

Other good and responsible DNS Registrars would take the complaints seriously and actually do something to disable the offending domains.

File complaints to FTC: https://www.ftccomplaintassistant.gov/FTC_Wizard.aspx?Lang=en for the violation of CAN-SPAM Act.

Scam Alert: Fake Email Pretending To Be From Apple.

UPDATE:
The DNS registration information was changed on 2011-05-19, also noted by a reader.

Domain Name: APPLESDOWNLOAD.COM
Registrar: ELB GROUP, INC.
Whois Server: whois.retailstudio.com
Referral URL: http://www.retailstudio.com
Name Server: NS1.QUCKBO.RU
Name Server: NS2.QUCKBO.RU
Name Server: NS3.QUCKBO.RU
Name Server: NS4.QUCKBO.RU
Status: clientTransferProhibited
Updated Date: 19-may-2011
Creation Date: 14-mar-2011
Expiration Date: 14-mar-2012

>>> Last update of whois database: Thu, 19 May 2011 20:15:58 UTC <<<

Whois info as of 2011-05-19

Domain Name: APPLESDOWNLOAD.COM

Registrant:
Vanna Berglund
Vanna Berglund        (stalk@mailae.com)
Danska Vagen 68-70
Gothenburg
Västra Gotalandslän,SE-41659
SE
Tel. +46.317078999

Creation Date: 14-Mar-2011
Expiration Date: 14-Mar-2012

Domain servers in listed order:
ns1.quckbo.ru
ns2.quckbo.ru
ns3.quckbo.ru
ns4.quckbo.ru

Administrative Contact:
Vanna Berglund
Vanna Berglund        (stalk@mailae.com)
Danska Vagen 68-70
Gothenburg
Västra Gotalandslän,SE-41659
SE
Tel. +46.317078999

Technical Contact:
Vanna Berglund
Vanna Berglund        (stalk@mailae.com)
Danska Vagen 68-70
Gothenburg
Västra Gotalandslän,SE-41659
SE
Tel. +46.317078999

Billing Contact:
Vanna Berglund
Vanna Berglund        (stalk@mailae.com)
Danska Vagen 68-70
Gothenburg
Västra Gotalandslän,SE-41659
SE
Tel. +46.317078999

Status:LOCKED

——-

A reader sent in a screenshot of an email pretending to be from Apple.

All clicks lead to: http://tariacuri.crefal.edu.mx/dweb/images/smilies/index.php which redirects to applesdownload.com.
It is likely that tariacuri.crefal.edu.mx site has been compromised.

applesdownload.com whois info:

Domain Name: APPLESDOWNLOAD.COM

Registrant:
Lyubov Bushmakina
Lyubov Bushmakina        ()
ul.Yuriya Gagarina d.38 k.2 kv.99
Sankt-Peterburg
Sankt-Peterburg,196105
RU
Tel. +7.8125540822
Fax. +7.8125540822

Creation Date: 14-Mar-2011
Expiration Date: 14-Mar-2012

Domain servers in listed order:
ns1.thejobrano.com
ns2.thejobrano.com

Administrative Contact:
Lyubov Bushmakina
Lyubov Bushmakina        ()
ul.Yuriya Gagarina d.38 k.2 kv.99
Sankt-Peterburg
Sankt-Peterburg,196105
RU
Tel. +7.8125540822
Fax. +7.8125540822

Technical Contact:
Lyubov Bushmakina
Lyubov Bushmakina        ()
ul.Yuriya Gagarina d.38 k.2 kv.99
Sankt-Peterburg
Sankt-Peterburg,196105
RU
Tel. +7.8125540822
Fax. +7.8125540822

Billing Contact:
Lyubov Bushmakina
Lyubov Bushmakina        ()
ul.Yuriya Gagarina d.38 k.2 kv.99
Sankt-Peterburg
Sankt-Peterburg,196105
RU
Tel. +7.8125540822
Fax. +7.8125540822

Status:LOCKED

The site is currently still up.

This is not the first time such email pretending to come from Apple.