Sa incepem un thread pe care sa facem de kko spamerii din .ro. Aici se posteaza numai date despre spameri unde avem ceva date de contact.
Sa incepem:
Transfer bancar, huh? Bine. Ia se vedem la cine merge transferul:Return-Path: <mailuri_sender@yahoo.com>
Delivered-To:
Received: from yahoo988.com (unknown [85.120.37.232])
by
From: Mailuri - peste 400.000 RO <mailuri_sender@yahoo.com>
To:
Reply-To: mail_comenzi@yahoo.com
Subject: BAZA DE DATE + 2 SOFT BONUS
Date: Sat, 19 Jan 2008
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary="9fb95942-8e37-4221-a13c-1df4de19075e"
Message-Id:
This is a multi-part message in MIME format
--9fb95942-8e37-4221-a13c-1df4de19075e
Content-Type: text/plain; charset=iso-8859-1
Content-Transfer-Encoding: quoted-printable
Baza de date cu peste 400.000 de adrese de e-mail publice din Romania (pers. =
fizice si pers. juridice) pe suport CD. Promoveaza-ti produsele, siteul sau =
serviciile pe care le vinzi cu ajutorul reclamei prin mail.
Pret: 65,00 RON (taxe postale INCLUSE, in cazul in care preferati metoda prin =
ramburs postal)
BONUS1: soft pentru trimis mail-uri in masa (pana la 5000 / min. - in functie =
de conexiunea pe care o aveti). Excelent pentru Newsletter!
BONUS2: Un soft cu ajutorul caruia puteti extrage in masa date de pe =
site-urile care va intereseaza sau din motoarele de cautare (numere de tel, =
adrese, mail-uri, URL etc.)
Pentru a comanda baza de date cu cele 2 bonusuri exista doua modalitati:
1. (COLET RAMBURS POSTAL) Trimiteti la adresa mail_comenzi@yahoo.com un =
e-mail avand subiectul "COMANDA" iar in continutul acestuia obligatoriu =
numele si adresa dumneavoastra completa (nume, prenume, strada, nr, bl, sc, =
et, ap, sector, cod postal, localitate si judet) , adresa la care veti primi =
coletul prin ramburs postal.
2. (TRANSFER BANCAR) Trimiteti un email la adresa mail_comenzi@yahoo.com =
avand subiectul COMANDA TRANSFER BANCAR cu datele dvs. personale si adresa =
dvs. Banii ii veti depune intr-un cont bancar iar soft-ul il veti primi la =
adresa de mail dorita de dvs. In cel mai scurt timp va vom trimite toate =
detalile necesare pentru a va putea onora comanda cu succes.
Multumesc.
--9fb95942-8e37-4221-a13c-1df4de19075e--
Deci spamerul noastru ar putea fi X. Desigur ar putea sa fie doar un fraier de interpus, dar e suficient sa fie bagat la beci doua zile si spune el si ce lapte a suptX-Apparently-To: via 68.180.199.107; Mon, 21 Jan 2008 05:08:48 -0800
X-Originating-IP: [217.146.182.181]
Return-Path: <mail_comenzi@yahoo.com>
Authentication-Results: mta179.mail.re3.yahoo.com from=yahoo.com; domainkeys=pass (ok)
Received: from 217.146.182.181 (HELO n4.bullet.ukl.yahoo.com) (217.146.182.181) by mta179.mail.re3.yahoo.com with SMTP; Mon, 21 Jan 2008 05:08:48 -0800
Received: from [217.12.4.214] by n4.bullet.ukl.yahoo.com with NNFMP; 21 Jan 2008 13:08:40 -0000
Received: from [216.252.122.219] by t1.bullet.ukl.yahoo.com with NNFMP; 21 Jan 2008 13:08:40 -0000
Received: from [69.147.84.88] by t4.bullet.sp1.yahoo.com with NNFMP; 21 Jan 2008 13:08:40 -0000
Received: from [127.0.0.1] by omp204.mail.sp1.yahoo.com with NNFMP; 21 Jan 2008 13:08:40 -0000
X-Yahoo-Newman-Property: ymail-3
X-Yahoo-Newman-Id: 49855.2108.bm@omp204.mail.sp1.yahoo.com
Received: (qmail 48364 invoked by uid 60001); 21 Jan 2008 13:08:39 -0000
DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=s1024; d=yahoo.com; h=X-YMail-OSG:Receivedate:From:Subject:To:In-Reply-To:MIME-Version:Content-Type:Content-Transfer-Encoding:Message-ID; b=BsdxUkxhKCUEpYrtwCRJ/j2HbcBbXNVS867hQwWEU5dNcBiVWYOo98/StEOsHDCTjaPRHca4JlLufQMTuSlOs9RymQk1PmWgJvPyvditw LaL0jUI7XHnyY5EtOjDf2kODXecfMJHW822Rw1p5shNdQHVGHw RW13jqnHjZeFSDYM=;
X-YMail-OSG: ciu8I70VM1nHmxvovb028EEjcT0iB40soze0cx09.nn4WB6RL4 _bRN8xn6wSet_6rGiBLaWeDD_BaIOIT.lcQr0HTQ--
Received: from [85.120.37.232] by web45503.mail.sp1.yahoo.com via HTTP; Mon, 21 Jan 2008 05:08:39 PST
Date: Mon, 21 Jan 2008 05:08:39 -0800 (PST)
From: "Baza de Date Soft Bonus" <mail_comenzi@yahoo.com> Add to Address Book Add Mobile Alert
Yahoo! DomainKeys has confirmed that this message was sent by yahoo.com. Learn more
Subject: Re: COMANDA TRANSFER BANCAR
To:
In-Reply-To:
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="0-539455213-1200920919=:46067"
Content-Transfer-Encoding: 8bit
Message-ID:
Content-Length: 1930
Buna.
Pentru a putea face tranzactia mergeti la o sucursala Raiffeisen Bank din orasul dvs. si depuneti suma de 65 RON in contul X Y dupa care trimiteti un e-mail de confirmare la aceasta adresa.
Multumesc.
Ce mai putem afla despre spamer? Putem afla din ce oras este.
Mesajul initial vine de la:
Mesajul de raspuns, in care ne spune contul bancar are in header:Received: from yahoo988.com (unknown [85.120.37.232])
Verificam adresa IP 85.120.37.232. Mergem la dns stuff:Received: from [85.120.37.232] by web45503.mail.sp1.yahoo.com via HTTP
Foloseste un ISP din orasul Sântana,judeţul Arad% Information related to '85.120.37.0 - 85.120.37.255'
inetnum: 85.120.37.0 - 85.120.37.255
netname: SC-ARY-CAB-SAN-SRL
descr: SC ARY CAB SAN SRL
descr: str Muncii ,Nr 83A
descr: Santana, Arad
country: RO
admin-c: PM4303-RIPE
tech-c: PM4303-RIPE
status: ASSIGNED PA
mnt-by: AS3233-MNT
mnt-lower: AS3233-MNT
mnt-routes: ASTRALTELECOM-MNT
remarks: object maintained by ROTLD local registry
notify: **********@rnc.ro
changed: **********@ripe.net 20070522
source: RIPE
Daca nu e doar un proxy (remote desktop, shell, etc.), atunci politia are o treaba usoara, deoarece localitatea are numai 15.000 locuitori.