Spam Alert: unsubyourself.net

A number of spam emails are originating from one source: unsubyourself.net.

The spammer who registered the following domain names through moniker.com:

  • exectsided.net
  • fabrias.net
  • fahroats.net
  • januited.net
  • moripic.net
  • licanneced.net

is now using a .ro TLD to register:

  • addejersed.ro
  • substatic.ro
  • berenotioning.ro
  • walsate.ro

The .ro TLD registrar are no help in this matter.

All these domains are/were pointing to one single domain that is unsubyourself.net (http://unsubyourself.net/c/unsubscribe.php)

Whois info on unsubyourself.net:

Domain Name: UNSUBYOURSELF.NET
Registrar: MONIKER

Registrant [3472147]:
Moniker Privacy Services UNSUBYOURSELF.NET@domainservice.com
Moniker Privacy Services
20 SW 27th Ave.
Suite 201
Pompano Beach
FL
33069
US

Administrative Contact [3472147]:
Moniker Privacy Services UNSUBYOURSELF.NET@domainservice.com
Moniker Privacy Services
20 SW 27th Ave.
Suite 201
Pompano Beach
FL
33069
US
Phone: +1.9549848445
Fax:   +1.9549699155

Billing Contact [3472147]:
Moniker Privacy Services UNSUBYOURSELF.NET@domainservice.com
Moniker Privacy Services
20 SW 27th Ave.
Suite 201
Pompano Beach
FL
33069
US
Phone: +1.9549848445
Fax:   +1.9549699155

Technical Contact [3472147]:
Moniker Privacy Services UNSUBYOURSELF.NET@domainservice.com
Moniker Privacy Services
20 SW 27th Ave.
Suite 201
Pompano Beach
FL
33069
US
Phone: +1.9549848445
Fax:   +1.9549699155

Domain servers in listed order:

NS1.DOMAINSERVICE.COM         208.73.210.41
NS2.DOMAINSERVICE.COM         208.73.211.42
NS3.DOMAINSERVICE.COM
NS4.DOMAINSERVICE.COM

Record created on:        2010-12-27 16:07:27.0
Database last updated on: 2010-12-27 16:07:32.943
Domain Expires on:        2011-12-27 16:07:27.0

It is registered through moniker.com.

Please send email to abuse@moniker.com and legal@moniker.com to file complaints.

Scam Alert: Fake OpenOffice.org download.

I was going through the server log parsing out spammy referrer links and one of the sites triggered a pop-up:

First off, the official OpenOffice.org site is in its name: OpenOffice.org.

This galleries.secure-softwaremanager.com must be spreading malwares. It actually checks the Operating System. Since I was using Camino Browser on Mac OS X, it returned an error message:

I am adding this url to the site blacklist.

By the way, if you are looking into downloading OpenOffice.org, you might want to check LibreOffice. It is a project forked from OpenOffice.org development.

Whois information on secure-softwaremanager.com:

http://www.networksolutions.com

Visit AboutUs.org for more information about SECURE-SOFTWAREMANAGER.COM
<a href=”http://www.aboutus.org/SECURE-SOFTWAREMANAGER.COM”>AboutUs: SECURE-SOFTWAREMANAGER.COM </a>

Registrant:
Pinball Corp
3600 1 36th place Se.
Bellevue, WA 98006
US

Domain Name: SECURE-SOFTWAREMANAGER.COM

————————————————————————
Promote your business to millions of viewers for only $1 a month
Learn how you can get an Enhanced Business Listing here for your domain name.
Learn more at http://www.NetworkSolutions.com/
————————————————————————

Administrative Contact, Technical Contact:
Pinball Corp        neteng@pinballcorp.com
3600 1 36th place Se.
Bellevue, WA 98006
US
425-279-1200

Record expires on 08-Dec-2011.
Record created on 08-Dec-2010.
Database last updated on 26-Feb-2011 00:44:52 EST.

Domain servers in listed order:

NS1.PINBALLCORP.COM
NS2.PINBALLCORP.COM

What is this pinballcorp.com?

Visit Safenames at www.safenames.net
+1 703 574 5313 in the US/Canada
+44 1908 200022 in Europe

Domain Name: PINBALLCORP.COM

[REGISTRANT]
Organisation Name: Pinball Corp
Contact Name:      William Freeman
Address Line 1:    3600 136th Place SE
Address Line 2:
City / Town:       Bellevue
State / Province:
Zip / Postcode:    WA 98006
Country:           US
Telephone:         +1.0114252791177
Fax:
Email:             wfreeman@pinballcorp.com

[ADMIN]
Organisation Name: Safenames Ltd
Contact Name:      International Domain Administrator
Address Line 1:    PO Box 5085
Address Line 2:
City / Town:       Milton Keynes MLO
State / Province:  Bucks
Zip / Postcode:    MK6 3ZE
Country:           UK
Telephone:         +44.1908200022
Fax:               +44.1908325192
Email:             hostmaster@safenames.net

[TECHNICAL]
Organisation Name: International Domain Tech
Contact Name:      International Domain Tech
Address Line 1:    PO Box 5085
Address Line 2:
City / Town:       Milton Keynes MLO
State / Province:  Bucks
Zip / Postcode:    MK6 3ZE
Country:           UK
Telephone:         +44.1908200022
Fax:               +44.1908325192
Email:             tec@safenames.net

The Data in the Safenames Registrar WHOIS database is provided by Safenames for
information purposes only, and to assist persons in obtaining information about
or related to a domain name registration record.  Safenames does not guarantee
its accuracy.  Additionally, the data may not reflect updates to billing
contact information.

As suspected, pinballcorp.com looks fishy.

Spammers are using URL shorteners a lot more.

I have been seeing a lot of questionable referrers in my WordPress statistic. They obviously are coming from spammers and scammers. For the past week or so there are a lot of referrers using URL shortening services such as tinyurl.com, bit.ly, etc. I cautiously opened the links to confirm my suspicions and almost all of them are pointing to domains I have already blocked.

While the URL shortening services are very valuable, they are also easily abused by the unscrupulous.

 

Scam Alert: Adobe Acrobat Reader 2011

UPDATE:
Shawn Sijnstra has been contacting us and explaining that he was a victim of identity theft. He has a blog explaining his story.: http://sijnstra.name/blog/

Please note that:
The latest version of Adobe Reader X can be obtained from Adobe.com.

There is no such thing as Adobe Acrobat Reader 2011, contrary to the scam/spam email sent to unsuspecting users.

From:     Adobe <newsletter@adobe-acrobat-upgrades.com>
Subject:     New Version Release : Adobe Acrobat Reader 2011, Upgrade Available Now !
Date:     February 16, 2011 XXXXXXXXXXXXXXXXXX
To:     XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
Reply-To:     newsletter@adobe-acrobat-upgrades.com

ADOBE ACROBAT READER 2011 UPDATE NOTIFICATION

This is to remind that a new version of Adobe Acrobat Reader 2011 with enhanced features for viewing, creating, editing, printing and internet-sharing PDF documents has been released.

To check and download the latest version , go to :

http://www.adobe-acrobat-upgrades.com

Start downloading the update right now and let us know what you think about it.

We’re working on making Adobe Acrobat Reader better all the time !

Thanks and best regards,

Adobe Support

© 2011 Adobe Systems Incorporated. All rights reserved.
Adobe Systems Incorporated | 343 Preston Street | Ottawa | ON | K1S 1N4 | Canada |

UPDATE:
WhoIs information has changed.

Whois information on adobe-acrobat-upgrades.com

% By submitting a query to RU-CENTER’s Whois Service
% you agree to abide by the following terms of use:
% http://www.nic.ru/about/servpol.html (in Russian)
% http://www.nic.ru/about/en/servpol.html (in English).

Domain name:             ADOBE-ACROBAT-UPGRADES.COM
Creation Date:           2011.02.17
Expiration Date:         2012.02.17

Status:                  NOT DELEGATED

Registrant ID:           AVNEP9R-RU
Registrant Name:         JSC “Regional Network Information Center”
Registrant Organization: JSC “Regional Network Information Center”
Registrant Street1:      2/1, 3d Khoroshevskaya str.
Registrant City:         Moscow
Registrant Postal Code:  123182
Registrant Country:      RU

Administrative, Technical Contact
Contact ID:              AVNEP9R-RU
Contact Name:            JSC “Regional Network Information Center”
Contact Organization:    JSC “Regional Network Information Center”
Contact Street1:         2/1, 3d Khoroshevskaya str.
Contact City:            Moscow
Contact Postal Code:     123182
Contact Country:         RU
Contact Phone:           +7 495 737 0601
Contact Fax:             +7 495 737 0602
Contact E-mail:          auction@nic.ru

Registrar:               Regional Network Information Center, JSC dba RU-CENTER

Last updated on 2011.12.01 01:48:51 MSK/MSD

WhoIs Information on adobe-reader-upgrades.com:

Domain ID:D161523747-LROR
Domain Name:ADOBE-READER-UPGRADES.ORG
Created On:16-Feb-2011 22:20:46 UTC
Last Updated On:18-Apr-2011 03:51:45 UTC
Expiration Date:16-Feb-2012 22:20:46 UTC
Sponsoring Registrar:Regional Network Information Center, JSC dba RU-CENTER (R148-LROR)
Status:CLIENT HOLD
Status:CLIENT TRANSFER PROHIBITED
Registrant ID:AVNEP9R-RU
Registrant Name:JSC “Regional Network Information Center”
Registrant Organization:JSC “Regional Network Information Center”
Registrant Street1:2/1, 3d Khoroshevskaya str.
Registrant Street2:
Registrant Street3:
Registrant City:Moscow
Registrant State/Province:
Registrant Postal Code:123182
Registrant Country:RU
Registrant Phone:+7.4957370601
Registrant Phone Ext.:
Registrant FAX:+7.4957370602
Registrant FAX Ext.:
Registrant Email:auction@nic.ru
Admin ID:AVNEP9R-RU
Admin Name:JSC “Regional Network Information Center”
Admin Organization:JSC “Regional Network Information Center”
Admin Street1:2/1, 3d Khoroshevskaya str.
Admin Street2:
Admin Street3:
Admin City:Moscow
Admin State/Province:
Admin Postal Code:123182
Admin Country:RU
Admin Phone:+7.4957370601
Admin Phone Ext.:
Admin FAX:+7.4957370602
Admin FAX Ext.:
Admin Email:auction@nic.ru
Tech ID:AVNEP9R-RU
Tech Name:JSC “Regional Network Information Center”
Tech Organization:JSC “Regional Network Information Center”
Tech Street1:2/1, 3d Khoroshevskaya str.
Tech Street2:
Tech Street3:
Tech City:Moscow
Tech State/Province:
Tech Postal Code:123182
Tech Country:RU
Tech Phone:+7.4957370601
Tech Phone Ext.:
Tech FAX:+7.4957370602
Tech FAX Ext.:
Tech Email:auction@nic.ru
Name Server:NS1.ADOBE-PDF-UPGRADES.COM
Name Server:NS2.ADOBE-PDF-UPGRADES.COM
Name Server:
Name Server:
Name Server:
Name Server:
Name Server:
Name Server:
Name Server:
Name Server:
Name Server:
Name Server:
Name Server:
DNSSEC:Unsigned

WhoIs information on adobe-acrobat-upgrades.com:

% By submitting a query to RU-CENTER’s Whois Service
% you agree to abide by the following terms of use:
% http://www.nic.ru/about/servpol.html (in Russian)
% http://www.nic.ru/about/en/servpol.html (in English).

Domain name: ADOBE-ACROBAT-UPGRADES.COM
Name Server: ns1.adobe-pdf-upgrades.com
Name Server: ns2.adobe-pdf-upgrades.com
Creation Date: 2011.02.17

Status: DELEGATED

Registrant ID: CRABZUX-RU
Registrant Name: Shawn Sijnstra
Registrant Organization: Shawn Sijnstra
Registrant Street1: 2938 Avenue Street
Registrant City: New York
Registrant Postal Code: 20394
Registrant Country: US

Administrative, Technical Contact
Contact ID: CRABZUX-RU
Contact Name: Shawn Sijnstra
Contact Organization: Shawn Sijnstra
Contact Street1: 2938 Avenue Street
Contact City: New York
Contact Postal Code: 20394
Contact Country: US
Contact Phone: +1 877 8663849
Contact E-mail:  Shawn@yahoo.com

Registrar: Regional Network Information Center, JSC dba RU-CENTER

Last updated on 2011.02.17 02:46:12 MSK/MSD

Notice that the creation date is 2011.02.17 (or 2011.02.16 in Pacific Time).

Another one using adobe-reader-upgrades.org:

Domain ID:D161523747-LROR
Domain Name:ADOBE-READER-UPGRADES.ORG
Created On:16-Feb-2011 22:20:46 UTC
Last Updated On:16-Feb-2011 22:20:48 UTC
Expiration Date:16-Feb-2012 22:20:46 UTC
Sponsoring Registrar:Regional Network Information Center, JSC dba RU-CENTER (R148-LROR)
Status:CLIENT TRANSFER PROHIBITED
Status:TRANSFER PROHIBITED
Status:ADDPERIOD
Registrant ID:CRABZUX-RU
Registrant Name:Shawn Sijnstra
Registrant Organization:Shawn Sijnstra
Registrant Street1:2938 Avenue Street
Registrant Street2:
Registrant Street3:
Registrant City:New York
Registrant State/Province:
Registrant Postal Code:20394
Registrant Country:US
Registrant Phone:+1.8778663849
Registrant Phone Ext.:
Registrant FAX:
Registrant FAX Ext.:
Registrant Email: Shawn@yahoo.com
Admin ID:CRABZUX-RU
Admin Name:Shawn Sijnstra
Admin Organization:Shawn Sijnstra
Admin Street1:2938 Avenue Street
Admin Street2:
Admin Street3:
Admin City:New York
Admin State/Province:
Admin Postal Code:20394
Admin Country:US
Admin Phone:+1.8778663849
Admin Phone Ext.:
Admin FAX:
Admin FAX Ext.:
Admin Email: Shawn@yahoo.com
Tech ID:CRABZUX-RU
Tech Name:Shawn Sijnstra
Tech Organization:Shawn Sijnstra
Tech Street1:2938 Avenue Street
Tech Street2:
Tech Street3:
Tech City:New York
Tech State/Province:
Tech Postal Code:20394
Tech Country:US
Tech Phone:+1.8778663849
Tech Phone Ext.:
Tech FAX:
Tech FAX Ext.:
Tech Email: Shawn@yahoo.com
Name Server:NS1.ADOBE-PDF-UPGRADES.COM
Name Server:NS2.ADOBE-PDF-UPGRADES.COM
Name Server:
Name Server:
Name Server:
Name Server:
Name Server:
Name Server:
Name Server:
Name Server:
Name Server:
Name Server:
Name Server:
DNSSEC:Unsigned

Notice that the creation date is 2011.02.16

A partial list of Domain Names used by spammers and scammers.

Attach is partial list of domain names used by spammers and scammers. Add them to the blacklist in the hosts file. It is only a partial list,

2c1804-7thgkluallbz4qk0q1h.hop.clickbank.net
alipbaata.co.cc
alpordessirempit.xpac.info
aouwch.com
asmidary.com
autofeed.bestproceed.com
badlymetal.net
beaming-smiles4all.net
bestbusinesssearch.net
bestbuygiftcard.cz.cc
bestfishingtool.com
bestproceed.com
bluesquareframe.com
bonsaicareonline.com
brenaleecosmetics.net
bulletinsite.info
candidll.com
cangencorp.com
catexamine.net
cierrainteriors.com
clicktvseries.com
codemaster-helpnetwork.net
counter.bestproceed.com
counter.visitorstatistic.com
crosshairoutdoorgear.net
desidiomusicalliance.net
designscapital.com
destinationexotictrips.net
digital-hdcamcorder.com
dominopiece.com
dreamnetassociates.com
drinkingstrawstirs.com
drive-traffic-to-your-website.co.cc
e-hiburan.co.cc
earliam.com
emailgeneral.com
ent-hiburan.co.cc
everstrong-storage.net
facebook.bestproceed.com
fat-loss-4–idiots.com
featherbuy.net
firestarproductdevelopment.com
free20usd.tk
freegiftscentre.info
freezone2u.com
freidrichconstuction.net
get-back-with-the-ex.com
gets20usd.tk
graphicplusdesignteam.net
greatoffersforhomeowners.net
hopefulspiritsgroup.net
hosted-predictivedialer.com
indiana-toll-road-traffic.co.cc
internationalmesothelioma.net
interorga.biz
investmentfinancing.bloggerreviews.org
jeanrempitmmampos.xpac.info
john-onlineblog.tk
justifyingsense.com
laensenanzapereira.edu.co
lawsuitmesothelioma.passas.us
lilacmeadowdayspa.net
lyrics.myra-world.com
m.arkibrealistik.net
mambang-x.com
mesotheliomasettlementnow.com
mkt059.com
montreauxandsons.com
multiresults.com
myshutterclicks.com
netinfozones.com
netwizardinstructionalguides.net
newsodrome.com
newworldmarketgroup.net
nycpartysceneonline.com
officialdealcenteronline.net
online-dating-websites.info
or.cangencorp.com
pericardialmesotheliomasite.com
photoangels-online.net
psychologybachelors.info
quikloan.info
reptilianstudios.net
rockypoint-enterprises.net
safewayvaultcompany.com
sakindary.com
sanchez-correaimporters.net
seetruewall.com
serveubetterhosting.com
sinido.com
sizzlingblog.com
slideshowexhibition-nys.net
soapinstall.net
statistics.bestproceed.com
studentloan-consolidation-info.info
studentloaninterest.org
swagbucks.com
synergytrainingfacility.com
theblogisdead.com
tl2.candidemail.com
totalcloths.net
updatecustomerdata.com
usalatestnews.com
ushardwaredev.net
viruzreload.co.cc
vivendicapitalinc.net
web.oxyme.com
www.acterize.com
www.bestgamingcomputer.info
www.bigextracash.com
www.bigextracash.com
www.blogobo.com
www.buy-a-computer.co.cc
www.carisoprodolabuse.info
www.club-asteria.com
www.cruisejobline.com
www.cruisejobsblog.com
www.galaxycelebrity.com
www.gamerszone.info
www.greentreemortgage.org
www.i-am-stupid-am-i.co.cc
www.ipadawe.com
www.ipadz2011.com
www.mobilephonereviewssite.com
www.moredietplan.com
www.ohamerica.us
www.psychologybachelors.info
www.refinancing-home.student-loan-consilidation.com
www.zapposhoes.org
yct.com.my
yourcarguide.org
yunkissmee.xpac.info
zero-credit.info