Saturday, November 17, 2007

spam-court ddosed again

And this time Dreamhost has shut the door for good.
So that's it.

Friday, November 16, 2007

Snippets

A collection where small snippets are saved temporarily and gradually expanded towards an independent blogpost.
More like memos to myself. Read them if you like, but don't expect much.
Mainly regarding members of bulkerforum.biz who are offering services that are illegal in most countries.

AbdAllah


[Nov 16, 2007]
His second post on bulkerforum.biz:

BP servers & hosting for mailing, trojan's, exploit's, etc. in Turkey, Malaysia, HongKong, USA, Thailand, China.
Fast setup, cheap price.
Please contact ICQ: 483-384-343 (Mr.Abdulla)
or write to PM.
Thank you !

One example of the typical hard working, honest members of bulkerforum.biz.

And the moderator Crypto greets him:

He is a well known russian BP provider.
Dobro pajalovati na bulkerforum AbdAllah.


We know that hosting mule scams is one of those included in his term "etc.", but what else is possible?
Child porn, carder sites? Not unlikely.

Honored with an SBL-listing in Spamhaus in November 2007, SBL59691.

To be continued ........

ProfDDoS


Nick says it all.
His post #5 on bulkerforum.biz:
Greeting!!!!

Let me to bring to your attention professional DDoS service!
Quality is guaranteed by uniqueness of the updated and supported software. Huge, constantly growing quantity of bots worldwide online.
Destroy a site of the competitor!!!
The prices depend on duration and complexity of the project.
For information welcome in the icq.
For all questions: ICQ support 448845. skype ss_support1

Moderators Dollar and Crypto are not totally happy about that post.
A bit strange regarding Crypto when reading his greetings to AbdAllah, but who knows what's inside these guys brains.
Crypto has not been showing too much intelligence in his posts, so it is perhaps not so strange after all.

Phantom rushes to his defense:

I have to disagree here guys LOL this person has been of great service to us all without you even knowing about it ..Thanks guy

ProfDDoS is the same guy as, or in bed with .....damn I lost that part.

Maybe continued.

Phantom


One of the moderators.
Been hanging around for some years now.
Always been very slippery, but now the smelly ex-wannabee-spammer "Nick Danger" (Marion Sidney Lynn) claims to have his identity and has "outed" him.

We have seen that info earlier, but we are not totally convinced about how real this is.
Two long and wild shots: This "outed" identity is either a middleman or a deliberate smoke screen.

Both Veru and myself are going more in the direction of "back to the roots" like WarriorForum and Bulkbarn, like Phantom himself indirectly suggests in his various postings on different forums during the last years. And like magic, some info fits. Pure magic it is.
This indicates another identity, but this does not seem very likely either.
The fact that both of us, originally independent of each other, went in that direction is a sign that there may be something here. And so is the fact that some of our findings were identical. That's magical.
It still seems unlikely though, so we are open for suggestions and speculations combined with hard facts.
Especially hard facts about the identity "outed" by the smelly chicken of an ex-wannabee-spammer.

escape

Usman Ahzaz, escap3@gmail.com, ahsen_@hotmail.com

Snippets:
  • olatesuite
  • exploits
  • Ucraine
  • drug spammer
.

From a posting about a month ago on bulkerforum, someone asked for this:

subject: Need a persistent exe application
One that will take an exe I already have and make it 'persistent' - hidden from the filesystem, hard to remove, etc

skype: myst231 or pm me here (i dont know if the pm situation has been resolved)


And the OlateSuitemaster of exploits answers:

escape
Joined: 15 Sep 2006
Posts: 55

votes: 2 Posted: Wed Oct 17, 2007 3:30 pm Post subject: y0
i can help you out
_________________
OlateSuite - HiSpeed Mirrored BP Shared Hosting & Dedicated Servers...
Exclusive Ip Restricted Socks4


The Christmas season is approaching, so watch out for OlateSuits exploits this year too:
Happy Holiday Season, TrendLabs article from 2006 about OlateSuit exploit
Watch out for any Holiday Season Blowout Sales this year.

See also:
http://garwarner.blogspot.de/2009/05/phishers-try-msn-worms-to-steal.html

Yet another hard working, honest businessman on the bulkerforum.

kref/spamit (glavmed)


Probably two guys, belonging to the same gang.
Crypto hugs kref:
kref, is known in the BlackSEO biz. He is a good guy and pay on time.
Have his own design/coders team(for his rx websites), and the affilate system for mailers looks very nice
He have a lot of references, just pm him, and find out more,
I think you gonna like it.

With such good references, we don't hesitate to label those guys as criminal spammers.
Snippets:
  • despmedia.com
  • glavmed.com
  • glavmed.org
  • hzmedia.info
  • spamit.com
  • thecanadianmeds.com
  • saintd / saintdmitry
  • Michael_sun2k
  • Their "designers": dadaev.com

To come


  • David (from Houston, TX.)
  • perka (from Romania - ZedCash)
  • rxnic
  • TLCmail / Stolder / leadz / empharmpartners (this is probably Impulse Marketing Group, or at least connected to them)
  • toxicdog (alex0ra, alexora, goomenuk, Prague, spamilka.com, Black Network, 69.50.177.122)
  • Note to self: The nick "n" is probably also known as elitet0kr, EvilAnarchistGuy, nathanownzu, t0k3d, EliteRAHA. Remember the guy from a couple of years back: Nathan?

sanjay / sancash

A quick note to self:
This guy is involved with Elite Herbal.
How high up he is in the food chain cannot be established accurately.
If not on top, he is very high up.