Tracing a spammer

Discussion in 'Serious' started by righteous_slave, 12 Dec 2007.

  1. righteous_slave

    righteous_slave I know what a bloody Dremel is

    Joined:
    19 Aug 2007
    Posts:
    59
    Likes Received:
    0
    Digging through my email, I discovered this fascinating note.

    From this address. "Arthur Marin" <ujswnjs@boulangerairbru.com>

    My curiosity aroused, not by the message itself, but how I got it and where it came from (miraculously, I don't get that much spam, at least not from places I haven't given my spam address to), I decided to experiment. Whois.net provided this fascinating data http://tools.whois.net/index.php?fuseaction=whois.whoisbyipresults
    while goggling the email address directed me here http://www.projecthoneypot.org/i_320fbf4da1c7efaf06963f4c41d86704#comments
    Goggling the address itself turned up nothing, and I don't care to click the link to find out that way.

    Any other suggestions as to how to trace where my paths crossed with this spammer? Just as a fun little project, I thought.
     
  2. capnPedro

    capnPedro Hacker. Maker. Engineer.

    Joined:
    11 Apr 2007
    Posts:
    4,381
    Likes Received:
    241
    ujswnjs@boulangerairbru.com won't be the real address. Guaranteed that will be faked. Check the headers of the email to see which mailserver sent the message. That will get you closer, assuming it's not just an open relay.

    And if it really is the spammer's server. It actually isn't. It's some chump who makes $0.001 sending an email. The real spambarons just contract the jobs out to these clowns.

    And it is still most likely just a compromised PC in some part of a bot-net.
     
  3. Cthippo

    Cthippo Can't mod my way out of a paper bag

    Joined:
    7 Aug 2005
    Posts:
    6,785
    Likes Received:
    103
    I'm curious what's on the site. Probably ads / malware, but does anyone have a safe platform to take a look. For that matter, if you ran a linux distro from a live CD, would that be a potential route of infection? It would be nice to be able to try some of these inherently unsafe things :D
     
  4. dragontail

    dragontail 5bet Bluffer

    Joined:
    9 Jun 2005
    Posts:
    1,779
    Likes Received:
    30
    Can you can use Tor/proxy to visit the site?
     
  5. Fophillips

    Fophillips What's a Dremel?

    Joined:
    9 Oct 2006
    Posts:
    948
    Likes Received:
    1
    Look for X-Originating-IP then DDoS the **** out of it.
     
  6. Gravemind123

    Gravemind123 avatar not found

    Joined:
    26 Aug 2006
    Posts:
    1,780
    Likes Received:
    0
    Tried going to the site in my VM, nothing. Tried to ping that IP Address, connection times out.
     
  7. seebul

    seebul Minimodder

    Joined:
    9 Aug 2005
    Posts:
    1,211
    Likes Received:
    1
  8. ou7blaze

    ou7blaze sensational.

    Joined:
    5 May 2003
    Posts:
    2,653
    Likes Received:
    2
    I actually just received my first official piece of Spam email (that I didn't relate or get myself into).

    I could tell because the email msg just contained all variations in the alphabet they could come up with eg. abc abcd abcde@hotmail.com, whatever.

    I think 75percent of the time people get spam from porn sites and very very rarely spam bots.
     
  9. DarkLord7854

    DarkLord7854 What's a Dremel?

    Joined:
    22 Jun 2005
    Posts:
    4,643
    Likes Received:
    121
    Pft, as if anyone watches porn on the internet :rolleyes:
     
  10. Brett89

    Brett89 Minimodder

    Joined:
    15 Dec 2005
    Posts:
    1,329
    Likes Received:
    35
    That's technically feasible?! Spam email addresses Cheesecake.
     
  11. gbeeby

    gbeeby What's a Dremel?

    Joined:
    6 Dec 2005
    Posts:
    294
    Likes Received:
    0
    :eyebrow:
     
  12. mutznutz

    mutznutz Cos Ive got a beard u label me evil

    Joined:
    18 Nov 2007
    Posts:
    267
    Likes Received:
    0
    Maybe the sites down becuase the US government found out about the secret organization and shut them down

    An organization so secret they want you to tell everyone ... nice
     
  13. Flibblebot

    Flibblebot Smile with me

    Joined:
    19 Apr 2005
    Posts:
    4,830
    Likes Received:
    299
    I don't know, because then I'd be 6'5", which is getting on for being freakishly tall, none of my clothes would fit so I'd have to get all new clothes, and I'd have to move the car seat even further back...

    So, no, you keep your 3". I'm quite happy being 6'2"
     
  14. woof82

    woof82 What's a Dremel?

    Joined:
    18 Jul 2005
    Posts:
    2,223
    Likes Received:
    58
    I did the whois, and it told me it was an Australian address, so I did the whois on the "south pacific database" that was in the comment, and it came up with a different address... in Korea...

    So then I did a search in the Korean database:

    Code:
    KRNIC is not an ISP but a National Internet Registry similar to APNIC.
    The following is organization information that is using the IPv4 address.
    
    IPv4 Address       : 211.172.232.0-211.172.232.255
    Network Name       : HANNET-INFRA
    Connect ISP Name   : KOREACOMPUTERIDC
    Connect Date       : 20001031
    Registration Date  : 20031021
    Publishes          : Y
    
    [ Organization Information ]
    Organization ID    : ORG121372
    Org Name           : KOREA COMPUTER IDC 
    Address            : Sindaebang-dong Dongjak-gu Seoul
    Detail Address     : 295-70
    Zip Code           : 156-010
    
    [ Technical Contact Information ]
    Name               : Sung-Kwan Yoon
    Org Name           : KOREA COMPUTER IDC
    Address            : Sindaebang-dong Dongjak-gu Seoul
    Detail Address     : 295-70
    Zip Code           : 156-010
    Phone              : +82-2-829-3063
    E-Mail             : skyun@hannetidc.com
     
  15. gbeeby

    gbeeby What's a Dremel?

    Joined:
    6 Dec 2005
    Posts:
    294
    Likes Received:
    0
  16. cjmUK

    cjmUK Old git.

    Joined:
    9 Feb 2004
    Posts:
    2,553
    Likes Received:
    88
    How did you figure that one out?

    It is well documented how you get spam from bots and spiders (every openly-published email address on any of my sites is swamped within 3 months of posting), yet I can't see a way of getting spam from viewing porn sites. Sure if you sign up for anything, you are going to get hammered. You are more at risk from viruses and trojans, but that is a different issue.

    However, in the interests of fairness I shall investigate the spam threats caused by clam-lappers.com when I get home tonight.
     
  17. capnPedro

    capnPedro Hacker. Maker. Engineer.

    Joined:
    11 Apr 2007
    Posts:
    4,381
    Likes Received:
    241
    Don't forget brute force guesswork of all @hotmail.com, @gmail.com addresses...
     
  18. Blademrk

    Blademrk Why so serious?

    Joined:
    21 Nov 2003
    Posts:
    3,988
    Likes Received:
    86
    I've had my hotmail address since I was in Uni (about 10 years ago) and never got any spam until a couple of months ago. I now get about 3-5 a day, all in Japanese for some reason.
     
  19. gbeeby

    gbeeby What's a Dremel?

    Joined:
    6 Dec 2005
    Posts:
    294
    Likes Received:
    0
    lol, got a load of blokes add me on MSN t'other day trying to chat me up...........said they got my address from a gay chatroom. :eyebrow:

    moral of this story dont **** anyone off that happens to have your email address.......
     
  20. ou7blaze

    ou7blaze sensational.

    Joined:
    5 May 2003
    Posts:
    2,653
    Likes Received:
    2
    Oh! Was that you? Sorry! :blush:
     

Share This Page