<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Inboxrevenge&#039;s Twitter Blog</title>
	<atom:link href="http://inboxrevenge.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://inboxrevenge.wordpress.com</link>
	<description>InBoxRevenge Backup Blog</description>
	<lastBuildDate>Thu, 27 Oct 2011 01:30:48 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='inboxrevenge.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Inboxrevenge&#039;s Twitter Blog</title>
		<link>http://inboxrevenge.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://inboxrevenge.wordpress.com/osd.xml" title="Inboxrevenge&#039;s Twitter Blog" />
	<atom:link rel='hub' href='http://inboxrevenge.wordpress.com/?pushpress=hub'/>
		<item>
		<title>Dirt Jumper DDoS Bot &#8211; detailed on Deep End Research</title>
		<link>http://inboxrevenge.wordpress.com/2011/10/27/dirt-jumper-ddos-bot-detailed-on-deep-end-research/</link>
		<comments>http://inboxrevenge.wordpress.com/2011/10/27/dirt-jumper-ddos-bot-detailed-on-deep-end-research/#comments</comments>
		<pubDate>Thu, 27 Oct 2011 01:25:09 +0000</pubDate>
		<dc:creator>reportscams</dc:creator>
				<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[rogue networks]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://inboxrevenge.wordpress.com/?p=494</guid>
		<description><![CDATA[Announced in October 2011: we are asking you to check out a new anti-botneteffort. DeepEnd Research.org. There is a lot of new information there about organized malicious activity called Dirt Jumper DDoS bot. I look forward to participating in the efforts. Unfortunately, I have not been able to update this blog in over a year [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=inboxrevenge.wordpress.com&amp;blog=8143881&amp;post=494&amp;subd=inboxrevenge&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Announced in October 2011: we are asking you to check out a new anti-botneteffort. <a href="http://www.deependresearch.org/">DeepEnd Research.org.</a></p>
<p>There is a lot of new information there about organized malicious activity called Dirt Jumper DDoS bot.</p>
<p>I look forward to participating in the efforts.</p>
<p>Unfortunately, I have not been able to update this blog in over a year already, nonetheless, I hope to make a few updates before the end of 2011 as time permits. It took me a long time to approve a few old comments here for some old entries.  I will respond to a few of the responses when I get a chance. I want to thank you for reading this blog and taking the time to respond to my research. I look forward to posting more information soon about various forms of cybercrime soon.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/inboxrevenge.wordpress.com/494/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/inboxrevenge.wordpress.com/494/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/inboxrevenge.wordpress.com/494/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/inboxrevenge.wordpress.com/494/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/inboxrevenge.wordpress.com/494/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/inboxrevenge.wordpress.com/494/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/inboxrevenge.wordpress.com/494/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/inboxrevenge.wordpress.com/494/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/inboxrevenge.wordpress.com/494/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/inboxrevenge.wordpress.com/494/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/inboxrevenge.wordpress.com/494/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/inboxrevenge.wordpress.com/494/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/inboxrevenge.wordpress.com/494/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/inboxrevenge.wordpress.com/494/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=inboxrevenge.wordpress.com&amp;blog=8143881&amp;post=494&amp;subd=inboxrevenge&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://inboxrevenge.wordpress.com/2011/10/27/dirt-jumper-ddos-bot-detailed-on-deep-end-research/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/86c0ba68c3a092f5479d56543de3d9a5?s=96&#38;d=&#38;r=G" medium="image">
			<media:title type="html">reportscams</media:title>
		</media:content>
	</item>
		<item>
		<title>Anti-Phishing Group Posts Intriguing Report</title>
		<link>http://inboxrevenge.wordpress.com/2010/05/16/anti-phishing-group-posts-intriguing-report/</link>
		<comments>http://inboxrevenge.wordpress.com/2010/05/16/anti-phishing-group-posts-intriguing-report/#comments</comments>
		<pubDate>Sun, 16 May 2010 15:21:12 +0000</pubDate>
		<dc:creator>reportscams</dc:creator>
				<category><![CDATA[blacklist]]></category>
		<category><![CDATA[blocklist]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[rogue networks]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[110mb.com]]></category>
		<category><![CDATA[Abuse]]></category>
		<category><![CDATA[anti-phishing]]></category>
		<category><![CDATA[APWG]]></category>
		<category><![CDATA[Avalanche]]></category>
		<category><![CDATA[banking]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[Brazil]]></category>
		<category><![CDATA[CERT.br]]></category>
		<category><![CDATA[compromise]]></category>
		<category><![CDATA[eCrime]]></category>
		<category><![CDATA[Incident Response]]></category>
		<category><![CDATA[isp]]></category>
		<category><![CDATA[ns11-wistee.fr]]></category>
		<category><![CDATA[phishing sites]]></category>
		<category><![CDATA[t35.com]]></category>
		<category><![CDATA[ZeuS botnet]]></category>

		<guid isPermaLink="false">http://inboxrevenge.wordpress.com/?p=474</guid>
		<description><![CDATA[The APWG (Anti-Phishing Work Group) recently held its Counter Crime Operations Summit (CeCOS) in São Paulo, Brazil on May 11-13th, 2010. Over the years, the APWG has held its conferences in different countries reflecting the internationalism of this type of fighting cybercrime (phishing spam). The next conference of the APWG is the eCrime Researchers Summit [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=inboxrevenge.wordpress.com&amp;blog=8143881&amp;post=474&amp;subd=inboxrevenge&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>The <a href="http://www.antiphishing.org">APWG</a> (Anti-Phishing Work Group) recently held its Counter Crime Operations Summit (CeCOS) in S<em></em>ão Paulo, Brazil on May 11-13th, 2010. Over the years, the APWG has held its <a href="http://www.antiphishing.org/events/events.html">conferences</a> in different countries reflecting the internationalism of this type of fighting cybercrime (phishing spam). The next conference of the APWG is the <a href="http://www.ecrimeresearch.org/">eCrime Researchers Summit</a> in Dallas, Texas in October 2010.</p>
<p>The admirable reporting by the <a href="http://www.cert.br/">CERT.br</a> (Brazilian CERT team) and other <a href="http://www.cert.br/contato-br.html">Brazilian Incident Response teams</a> deserves a mention because they appear to be among the most proactive of Incident Response teams worldwide  in reporting phishing, malware and other types of internet abuse incidents to various ISPs world-wide.  Brazilian-related cybercrime gets more attention because of such strong efforts than cybercrime related to other countries such as China or Russia (countries mentioned with a large online presence) because of this important task at hand.</p>
<p><strong>Global Phishing Survey</strong></p>
<p>In May 2010, APWG researchers Greg Aaron and Rod Rasmussen published this report <strong> <a href="http://www.antiphishing.org/reports/APWG_GlobalPhishingSurvey_2H2009.pdf">Global Phishing Survey: Domain Name Use and Trends in 2H2009</a></strong> about Avalanche phishing group making up two thirds of all phishing attacks based on data collected in the second half of 2009.</p>
<p><strong>Subdomain Abuse on Free Webhosters</strong></p>
<p>The Global Phishing Survey gives a very detailed view of phishing site attacks based on TLD (top level domains) and compromised phishing sites that were reported. The detailed report also noted free hosting subdomain services that were abused by phishers as it compiled a top 20 offender list on page 20 of the APWG report.  These free subdomain services are not doing enough to minimize fraudulent signups. It would appear that cybercriminals flock to such sites in droves to defraud others, even if the reaction is whack-a-mole.  The typical approach is the scams are reported after their spam run, then the hoster shuts them down.</p>
<p>The number one offender of phishing sites on subdomains was<strong> t35.com</strong> which is hosted in the US by the <a href="http://interserver.net/">webhoster</a> Interserver.net of New Jersey; (t35.com&#8217;s A record is on  69.10.32.154 / AS19318).  Other failures to curb phishing sign-ups to note in the top 5: <strong>110mb.com, ns11-wistee.fr, tripod.com</strong> and <strong>justfree.com</strong></p>
<p><strong>Avalanche Phishing and ZeuS botnet</strong></p>
<p>The 33 page report provides detail as to the reported phishing website trends as of the second half of 2009.  Avalanche is the current name for fast flux DNS of phishing site hosting on large botnets, which involved many fraudulent domain name sign ups with unresponsive registrars worldw ide and spoofs of many brands. This large phishing organization (2006-2008) had been dubbed <a href="http://en.wikipedia.org/wiki/Rock_Phish">Rockphish</a> due to the patterns found in folder names. At that time, the rockphish group was quite successful in stealing millions of dollars.</p>
<p>This newer group, now called Avalanche, uses similar techniques to that of the Rockphish. The Avalanche group is also making use of the ZeuS botnet to steal banking information from users who download the malware they received via spam. Current ZeuS botnet statistics found online can be found on the <a href="https://zeustracker.abuse.ch/">ZeuS Botnet Tracker</a>.</p>
<p>According to the <a href="http://www.antiphishing.org/reports/APWG_GlobalPhishingSurvey_2H2009.pdf">APWG report</a>, compromised phishing attacks are still very plentiful, and tend to stay online longer than the lifespan of the fast flux Avalanche botnet phishing sites.</p>
<p>It is very hard to say if the groups behind this large phishing enterprise will be caught and prosecuted, but at the time of this post, their activity appears to be still going strong based on the reports referenced here by APWG. It is worth noting that continued international cooperation amongst law enforcement, private industry, independent researchers, academics and governments against cybercrime is truly a must to stem the problem of cybercrime in general. Other efforts matter as well, but international cooperation is probably the most important aspect to fighting online crime. International efforts such as APWG are commendable.</p>
<p>Selected Media References:</p>
<p>Ars Technica:  <a href="http://arstechnica.com/security/news/2010/05/phishing-servers-being-killed-off-faster-than-ever.ars">Phishing servers being killed off faster than ever</a></p>
<p>Network World: <a href="http://www.networkworld.com/news/2010/051310-avalanche-phishing.html?t51hb">Worst phishing menace may be prepping more dangerous version of itself </a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/inboxrevenge.wordpress.com/474/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/inboxrevenge.wordpress.com/474/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/inboxrevenge.wordpress.com/474/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/inboxrevenge.wordpress.com/474/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/inboxrevenge.wordpress.com/474/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/inboxrevenge.wordpress.com/474/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/inboxrevenge.wordpress.com/474/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/inboxrevenge.wordpress.com/474/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/inboxrevenge.wordpress.com/474/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/inboxrevenge.wordpress.com/474/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/inboxrevenge.wordpress.com/474/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/inboxrevenge.wordpress.com/474/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/inboxrevenge.wordpress.com/474/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/inboxrevenge.wordpress.com/474/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=inboxrevenge.wordpress.com&amp;blog=8143881&amp;post=474&amp;subd=inboxrevenge&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://inboxrevenge.wordpress.com/2010/05/16/anti-phishing-group-posts-intriguing-report/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/86c0ba68c3a092f5479d56543de3d9a5?s=96&#38;d=&#38;r=G" medium="image">
			<media:title type="html">reportscams</media:title>
		</media:content>
	</item>
		<item>
		<title>Romania: A Well-known Cybercrime Haven</title>
		<link>http://inboxrevenge.wordpress.com/2010/04/11/romania-a-well-known-cybercrime-haven/</link>
		<comments>http://inboxrevenge.wordpress.com/2010/04/11/romania-a-well-known-cybercrime-haven/#comments</comments>
		<pubDate>Sun, 11 Apr 2010 18:09:18 +0000</pubDate>
		<dc:creator>reportscams</dc:creator>
				<category><![CDATA[419]]></category>
		<category><![CDATA[blacklist]]></category>
		<category><![CDATA[blocklist]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[registrars]]></category>
		<category><![CDATA[rogue networks]]></category>
		<category><![CDATA[scareware]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[.RO]]></category>
		<category><![CDATA[2010]]></category>
		<category><![CDATA[advance fee fraud]]></category>
		<category><![CDATA[AFF]]></category>
		<category><![CDATA[AS31571]]></category>
		<category><![CDATA[AS38913]]></category>
		<category><![CDATA[AS6663]]></category>
		<category><![CDATA[Bucharest]]></category>
		<category><![CDATA[CIA Factbook]]></category>
		<category><![CDATA[DDICOT]]></category>
		<category><![CDATA[DICCOT]]></category>
		<category><![CDATA[Eastern Bloc]]></category>
		<category><![CDATA[Eastern Europe]]></category>
		<category><![CDATA[European Union]]></category>
		<category><![CDATA[euroweb.ro]]></category>
		<category><![CDATA[FBI]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[IRC]]></category>
		<category><![CDATA[isp]]></category>
		<category><![CDATA[McAfee]]></category>
		<category><![CDATA[NATO]]></category>
		<category><![CDATA[phishers]]></category>
		<category><![CDATA[powerhost.ro]]></category>
		<category><![CDATA[Romania]]></category>
		<category><![CDATA[Romanian]]></category>
		<category><![CDATA[Romanian Government]]></category>
		<category><![CDATA[Romanians]]></category>
		<category><![CDATA[ROTLD]]></category>
		<category><![CDATA[scams]]></category>
		<category><![CDATA[Soviet Union]]></category>
		<category><![CDATA[spamhaus]]></category>
		<category><![CDATA[spamming]]></category>
		<category><![CDATA[US]]></category>
		<category><![CDATA[USSR]]></category>
		<category><![CDATA[Warsaw Pact]]></category>

		<guid isPermaLink="false">http://inboxrevenge.wordpress.com/?p=436</guid>
		<description><![CDATA[Romania is a country that many Internet security researchers and various law enforcement agencies equate with cybercrime and have probably had that mind for quite a while now.  Even some casual readers of spam news know about Romania&#8217;s bad reputation online. The good news is over the years more and more people directly involved cybercrime [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=inboxrevenge.wordpress.com&amp;blog=8143881&amp;post=436&amp;subd=inboxrevenge&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Romania is a country that many Internet security researchers and various law enforcement agencies equate with cybercrime and have probably had that mind for quite a while now.  Even some casual readers of spam news know about Romania&#8217;s bad reputation online. The good news is over the years more and more people directly involved cybercrime rings based in Romania have been caught.</p>
<p>In the latest news, on 6th April, 2010, 70 people were arrested in Romania for phishing and other Internet related fraud. The arrests which were undertaken by the Directorate for the Investigation of Organized Crime in Romania, together with police officers, and followed by over 90 searches issued by prosecutors (<a href="http://www.diicot.ro/index.php?option=com_content&amp;view=article&amp;id=298">Article in Romanian by DIICOT</a>).</p>
<p><strong>Update: 4/12/10 Current time zone: EEST 12:11 AM<br />
</strong></p>
<p><a href="http://netscammers.blogspot.com/2010/04/70-romanians-arrested-on-6th-of-april.html">The Internet Scammers blog</a> which broke the story earlier last week in English has updated the names of some 34 of these Romanian scammers who engaged in eBay, 419 and other auction fraud  a form of (advance fee fraud &#8211; AFF). The source of the story in Romanian is  <a href="http://www.masuramedia.ro/news/11267.html">Romanian Masura Media</a>. which was posted on the 8th of April 2010.</p>
<p>The <a href="http://translate.google.com/translate?u=http%3A%2F%2Fwww.masuramedia.ro%2Fnews%2F11267.html&amp;sl=ro&amp;tl=en&amp;hl=&amp;ie=UTF-8">rough translation into English</a> via Google is here as kindly provided by the <a href="http://twitter.com/no_muie">writer</a> at the Internet Scammers blog.  According to the translation into the English with the aid of the FBI, DDICOT, and other law enforcement agencies, <em>according to investigators since 2006, the three organized criminal groups have acted in several countries  including: Spain, Italy, France, New Zealand, Denmark, Sweden, Germany, Austria, USA, Canada, and Switzerland. They were organizing fraudulent auctions through the Internet. &#8230; There could be up to 250 people involved in three separate criminal groups.<br />
</em></p>
<p><strong>Backstory in Clamping down on Romanian Cybercrime</strong></p>
<p>In more recent years, there has been more success by various law enforcement agencies to arrest Romanian-based cybercriminals. Romanian officials have been working harder with international law enforcement to make these arrests possible. <a href="http://www.youtube.com/watch?v=dYcui1M8MZ0">Romanian Prosecutor-General</a> Laura Codruta Kövesi was noted as a <a href="http://www.mcafee.com/us/about/corporate/fight_cybercrime/awards/">McAfee Cybercrime Fighter Award Winner</a> in 2008. These recent successes of arrests are worth definitely noting, so that more cybercriminals are eventually caught in other countries in part to more increased government cooperation with international law enforcement, in other nations nearby such as Russia, Estonia, Ukraine, and some other East European nations.</p>
<div id="attachment_446" class="wp-caption aligncenter" style="width: 157px"><a href="http://inboxrevenge.files.wordpress.com/2010/04/romanian-flag-flat.png"><img class="size-full wp-image-446" title="Romanian-Flag-Flat" src="http://inboxrevenge.files.wordpress.com/2010/04/romanian-flag-flat.png?w=147&#038;h=111" alt="" width="147" height="111" /></a><p class="wp-caption-text">Romanian Flag</p></div>
<p>Romania has had a strong presence or digital footprint online for well over a decade now as compared to some other countries of its size. Romania has around 22 million people and ranks as the <a href="https://www.cia.gov/library/publications/the-world-factbook/rankorder/2119rank.html?countryName=Romania&amp;countryCode=ro&amp;regionCode=eu&amp;rank=51#ro">51th most populated country</a> in the world according to the <a href="https://www.cia.gov/library/publications/the-world-factbook/geos/ro.html">CIA Factbook</a>. Romania&#8217;s presence online in terms of users and that of Internet IP hosts does outranks many other countries relative to its size and outranks some larger countries as well who are not as wired in general. Romania has an active hacker community and Romanians are <a href="http://irc.netsplit.de/chat/romania.php">well represented</a> on IRC (Instant Relay Chat).</p>
<p>Since breaking away from the shackles of the Soviet Bloc in policy lead by the brutal dictator Nicolae Ceauşescu whose rule ended violently in 1989, Romania has gone through a lot of political transformation from a communist country to that of aligning itself more with Western Europe and the United States for the past 2 decades. Romania joined NATO since 2004 has been in the European Union since 2007. For more about Romania&#8217;s geopolitical history as former Soviet Satellite, check out its English-language <a href="http://en.wikipedia.org/wiki/Romania">Wikipedia entry</a>.</p>
<p>While Broadband penetration study for European countries in percentage amongst Romanians is not ranked very high (24%) <a href="http://techcrunchies.com/broadband-penetration-in-european-households/">according to Tech Crunchies,</a> the average Romanian enjoys a very high speed on the Internet  as ranked with those from other countries: <a href="http://techcrunchies.com/countries-with-highest-average-broadband-speed/">Ranked #4 in the Top 10</a> with 6.2 Mbps. (Download Speeds of Megabits per Second).</p>
<p>Romanians have been involved in cybercrime in larger numbers for at least a decade now which is quite a longtime for the average lifespan of any particular online activity. For several years now, Romania has had a tarnished reputation similar to those cybercriminal reputations of much larger countries such as Nigeria, Brazil, Russia, China and the United States.</p>
<p><strong>70 Romanians Arrested in April 2010</strong></p>
<p>Despite these facts, there have been recent arrests of large numbers of cybercriminals in Romania in the past few years. We  are highlighting the most recent arrest of 70 people arrested in Romania on April 6th, 2010 which was <a href="http://netscammers.blogspot.com/2010/04/70-romanians-arrested-on-6th-of-april.html">first posted on Internet Scammers blog in English</a>. We will post more details as they come available.</p>
<p><strong>Spamhaus Blocklists large swaths of Romanian ISP EuroWeb.RO: </strong></p>
<p>In early April 2010, <a href="http://www.spamhaus.org">Spamhaus</a> blocklisted large IP ranges of this Romanian ISP: <a href="http://euroweb.ro/">Euroweb.ro</a> for hosting botnet and various cybercrime enterprises with the latest name <a href="http://powerhost.ro/">Powerhost.ro</a>. Due to the recent blocklistings, it would be a good guess this provider will get rid of these blackhat accounts. The downstream which is causing these listings is called Powerhost.ro. At the time of this posting, there were <a href="http://www.spamhaus.org/sbl/listings.lasso?isp=euroweb.ro">7 active SBLs for Euroweb.ro</a></p>
<p>The most recent listings are:</p>
<p>07-Apr-2010 to  11-Apr-2010 Listed on SBL<br />
<a href="http://www.spamhaus.org/sbl/sbl.lasso?query=SBL88578">SBL88578</a> 77.81.192.0/19    euroweb.ro<br />
SBL88577   86.55.96.0/23     euroweb.ro<br />
SBL88576   86.55.206.0/23    euroweb.ro<br />
SBL88575   89.114.9.0/24     euroweb.ro<br />
SBL88572  188.213.128.0/20    euroweb.ro<br />
SBL88571  188.213.96.0/20   euroweb.ro<br />
SBL88570   86.55.210.0/23   euroweb.ro</p>
<p>The /19 listing is over 8000 IP addresses. The smallest netblock is /24 which is 256 IP addresses.  A few details to note below from the <a href="http://www.spamhaus.org/sbl/sbl.lasso?query=SBL88578">SBL88578</a> :</p>
<blockquote><p>SBL88578<br />
77.81.192.0/19     euroweb.ro<br />
07-Apr-2010 01:21 GMT<br />
Botnet/cybercrime spammer hosting: powerhost.ro</p>
<p>AS6663 EUROWEBRO<br />
AS38913 Enter-Net-Team-AS<br />
AS31571 ALtNet Bucharest, ROMANIA</p></blockquote>
<p><strong>Notable External Links for Further Reading / Information:</strong></p>
<p>There have been several recent arrests of cybercriminals in Romania over the past few years. Below are some recent highlights:</p>
<p><strong>Informational Blogs to Video Links</strong>:</p>
<p>Internet Scammers: <a href="http://netscammers.blogspot.com/2010/04/70-romanians-arrested-on-6th-of-april.html">70 Romanians Arrested on 6th of April 2010</a></p>
<p>CyberCrime &amp; Doing Time: <a href="http://garwarner.blogspot.com/2010/04/70-romanian-phishers-fraudsters.html">70 Romanian Phishers &amp; Fraudsters Arrested</a></p>
<p><strong>Video:</strong></p>
<p>YouTube:<strong> </strong><a href="http://www.youtube.com/watch?v=s6oPm0jipUU">Safe Internet &#8211; Romanian Child Safety Commercia</a>l &#8211; (1 min)</p>
<p><strong>Older News Stories &#8211; (incomplete)<br />
</strong></p>
<p>2008:<strong> </strong><a href="http://www.scmagazineus.com/romanian-cybercrime-ring-busted/article/112600/">SC: Romanian cybercrime ring busted</a></p>
<p>2003: <a href="http://www.msnbc.msn.com/id/3226837/">MSNBC: How Romania became a center of cybercrime</a></p>
<p><strong>Other:</strong></p>
<p><a href="http://www.nirsoft.net/countryip/ro.html">NirSoft: Romanian IP Ranges</a></p>
<p><a href="http://portal.rotld.ro/pages/en/2/">ROTLD Registry: .RO rules for TLD usage</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/inboxrevenge.wordpress.com/436/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/inboxrevenge.wordpress.com/436/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/inboxrevenge.wordpress.com/436/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/inboxrevenge.wordpress.com/436/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/inboxrevenge.wordpress.com/436/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/inboxrevenge.wordpress.com/436/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/inboxrevenge.wordpress.com/436/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/inboxrevenge.wordpress.com/436/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/inboxrevenge.wordpress.com/436/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/inboxrevenge.wordpress.com/436/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/inboxrevenge.wordpress.com/436/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/inboxrevenge.wordpress.com/436/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/inboxrevenge.wordpress.com/436/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/inboxrevenge.wordpress.com/436/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=inboxrevenge.wordpress.com&amp;blog=8143881&amp;post=436&amp;subd=inboxrevenge&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://inboxrevenge.wordpress.com/2010/04/11/romania-a-well-known-cybercrime-haven/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/86c0ba68c3a092f5479d56543de3d9a5?s=96&#38;d=&#38;r=G" medium="image">
			<media:title type="html">reportscams</media:title>
		</media:content>

		<media:content url="http://inboxrevenge.files.wordpress.com/2010/04/romanian-flag-flat.png" medium="image">
			<media:title type="html">Romanian-Flag-Flat</media:title>
		</media:content>
	</item>
		<item>
		<title>Advance Fee Fraud goes beyond 419 Scams</title>
		<link>http://inboxrevenge.wordpress.com/2010/03/21/advance-fee-fraud-goes-beyond-419-scams/</link>
		<comments>http://inboxrevenge.wordpress.com/2010/03/21/advance-fee-fraud-goes-beyond-419-scams/#comments</comments>
		<pubDate>Sun, 21 Mar 2010 23:38:50 +0000</pubDate>
		<dc:creator>reportscams</dc:creator>
				<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[rogue networks]]></category>
		<category><![CDATA[scareware]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[419]]></category>
		<category><![CDATA[aa419]]></category>
		<category><![CDATA[advance fee fraud]]></category>
		<category><![CDATA[blacklists]]></category>
		<category><![CDATA[filtering]]></category>
		<category><![CDATA[interpol]]></category>
		<category><![CDATA[lawyers]]></category>
		<category><![CDATA[nigerian]]></category>
		<category><![CDATA[Phishbucket]]></category>
		<category><![CDATA[scammers]]></category>
		<category><![CDATA[spammers]]></category>
		<category><![CDATA[sweetheart scams]]></category>
		<category><![CDATA[UBE]]></category>
		<category><![CDATA[UCE]]></category>

		<guid isPermaLink="false">http://inboxrevenge.wordpress.com/?p=419</guid>
		<description><![CDATA[Online Advance Fee Fraud  (AFF) scams are plentiful and involve several people: the fraudsters themselves, money mules (people who are often duped into commit crimes, as middle men), but think they are earning extra money and then the individuals and businesses who have been defrauded.  Most of the general public who are active online, may [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=inboxrevenge.wordpress.com&amp;blog=8143881&amp;post=419&amp;subd=inboxrevenge&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Online Advance Fee Fraud  (AFF) scams are plentiful and involve several people: the fraudsters themselves, <a href="http://en.wikipedia.org/wiki/Money_mule">money mules</a> (people who are often duped into commit crimes, as middle men), but think they are earning extra money and then the individuals and businesses who have been defrauded.  Most of the general public who are active online, may have heard of the Nigerian letter scam (419 scam) called 419 due to its code number in current Nigerian law.</p>
<p>There are <a href="http://www.joewein.de/sw/419scam.htm">many ways</a> a scammer poses as someone else to steal a victim&#8217;s money.  Advance Free Fraud scams take place anywhere the Internet is in use, not just to victims in the Western nations.  Usually the intended victim cashes a fraudulent check from an account whose information was stolen. Many of these scenarios start with endusers answering spam that appears in their inboxes. Typically in most cases the money mule (person who unwittingly commits a crime) is left holding the bag by being responsible for the amount on the stolen check they had received.</p>
<p>These scams take place in many countries, from <a href="http://savethemailblog.sendio.com/e-mail/63-a-bad-apple-example-south-african-woman-loses-178k-in-419-scam">South Africa</a>, to the <a href="http://www.scambuster419.co.uk/">UK</a>, United States, Japan, Germany, and other nations.  Fraudsters catch their intended victims by other means such as posting ads on Craigslist, answering for sale ads, taking over eBay accounts that were phished, and posting elsewhere online where people want to buy and sell things. Also people (male or female) looking for dates online have been swindled many times in what is called <a href="http://afroclub.net/scammer-pictures-used-in-scam-3.htm">sweetheart scams.</a> The sweetheart scams haven going on for quite sometime; note this <a href="http://www.msnbc.msn.com/id/8704213/">2005 MSN article</a>.  Scammers also <a href="http://observertoday.com/page/content.detail/id/537419.html">hack into people&#8217;s email accounts</a> and send spam saying they are stranded overseas and need money after being robbed.  Now with the popularity of social networking sites such as Facebook and Twitter, these fraudsters continue to dupe their victims after hacking into accounts and pretending to be the victim, asking for money.</p>
<p>For those not familiar with the term Advance Fee Fraud, check out this definition according to the <a href="http://en.wikipedia.org/wiki/Advance-fee_fraud">Wikipedia</a>:</p>
<blockquote><p>An advance-fee fraud is a confidence trick in which the target is persuaded to advance sums of money in the hope of realizing a significantly larger gain.[1] Among the variations on this type of scam, are the Nigerian Letter (also called the 419 fraud, Nigerian scam, Nigerian bank scam, or Nigerian money offer[2]),[3] the Spanish Prisoner, the black money scam as well as Russian/Ukrainian scam (also extremely widespread, though far less popular than the former). The so-called Russian and Nigerian scams stand for wholly dissimilar organised-crime traditions; they therefore tend to use altogether different breeds of approaches.</p></blockquote>
<p>The Nigerian letter scam is probably the most well known of the advance fee fraud scams. There are organizations with devoted volunteers who actively combat these crimes. <a href="http://wiki.aa419.org/">AA419</a> for example, reports fraudulent advance fee fraud domains to webhosts, and registrars for take-downs. Another website which documents and reports online fraud is <a href="http://bobbear.co.uk/">Bobbear.co.uk</a>.</p>
<p><strong>The Main Difference between Phishers and Advance Fee Fraudsters</strong></p>
<p>There are many  methods to defraud victims online, from fake eBay auctions, to scam job opportunity scams. Another website dedicated to job fraud is <a href="http://www.phishbucket.org/main/">PhishBucket</a>.  These types of scams are a bit different from <a href="http://en.wikipedia.org/wiki/Phishing">phishing scams</a> where fraudsters use spam to spoof financial institutions such as banks in order to steal the victim&#8217;s username and password in order to steal money from the victim&#8217;s banking account.  The main difference is phishers are spoofing an actual company that exists while the run of the mill job scammers simply create fraudulent shell companies or purchase fraudulent domain names with dummy company information listed.</p>
<p><strong>Advance Fee Fraud Victims</strong></p>
<p>Many people ware of this problem tend to think that victims are internet newbies.  Many people who have fallen for these online scams have been retired professors, <a href="http://www.theinternetpatrol.com/new-version-of-419-scam-aimed-at-lawyers/">lawyers</a> and other professionals.</p>
<p>The way for people to avoid online scams is to think about this old adage which is somewhat paraphrased: &#8220;if something is too good to be true, then it probably is.&#8221;</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/inboxrevenge.wordpress.com/419/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/inboxrevenge.wordpress.com/419/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/inboxrevenge.wordpress.com/419/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/inboxrevenge.wordpress.com/419/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/inboxrevenge.wordpress.com/419/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/inboxrevenge.wordpress.com/419/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/inboxrevenge.wordpress.com/419/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/inboxrevenge.wordpress.com/419/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/inboxrevenge.wordpress.com/419/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/inboxrevenge.wordpress.com/419/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/inboxrevenge.wordpress.com/419/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/inboxrevenge.wordpress.com/419/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/inboxrevenge.wordpress.com/419/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/inboxrevenge.wordpress.com/419/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=inboxrevenge.wordpress.com&amp;blog=8143881&amp;post=419&amp;subd=inboxrevenge&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://inboxrevenge.wordpress.com/2010/03/21/advance-fee-fraud-goes-beyond-419-scams/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/86c0ba68c3a092f5479d56543de3d9a5?s=96&#38;d=&#38;r=G" medium="image">
			<media:title type="html">reportscams</media:title>
		</media:content>
	</item>
		<item>
		<title>The United States &#8211; Malware and Spam Central Online</title>
		<link>http://inboxrevenge.wordpress.com/2010/02/24/the-united-states-malware-and-spam-central-online/</link>
		<comments>http://inboxrevenge.wordpress.com/2010/02/24/the-united-states-malware-and-spam-central-online/#comments</comments>
		<pubDate>Wed, 24 Feb 2010 03:01:28 +0000</pubDate>
		<dc:creator>reportscams</dc:creator>
				<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[rogue networks]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[China]]></category>
		<category><![CDATA[isp]]></category>
		<category><![CDATA[Russia]]></category>
		<category><![CDATA[United States]]></category>

		<guid isPermaLink="false">http://inboxrevenge.wordpress.com/?p=406</guid>
		<description><![CDATA[In the online world, on computers and servers hosted within United States is where a lot of cybercrime originates. How often does one read about that? Usually China and Russia are mentioned at the drop of a hat in regards to online malicious activity while there seems to be less focus on such large problems [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=inboxrevenge.wordpress.com&amp;blog=8143881&amp;post=406&amp;subd=inboxrevenge&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>In the online world, on computers and servers hosted within United States is where a lot of cybercrime originates. How often does one read about that? Usually China and Russia are mentioned at the drop of a hat in regards to online malicious activity while there seems to be less focus on such large problems on networks within the United States.</p>
<p>The rankings posted on Spamhaus is one example where one may guage online fraudulent activity. Take a look at the top 10 SBL <a href="http://www.spamhaus.org/statistics/countries.lasso">offenders by country</a>.  The United States is way ahead with over 2000 current SBLs. China is in a distant 2nd place.</p>
<p>Below lists the top 3 as of 2/24/2010.</p>
<p><strong>As at 24 February 2010 the world&#8217;s worst Spam Haven countries for production and export of spam are:</strong></p>
<table style="height:40px;" border="0" cellspacing="0" cellpadding="6" width="544">
<tbody>
<tr>
<td width="20" valign="middle" bgcolor="#ff3300">
<div><strong> 1 </strong></div>
</td>
<td valign="middle" bgcolor="#e6e6e6">United States</td>
<td width="280" valign="middle" bgcolor="#e6e6e6">Number of Current Live Spam Issues: 2189</td>
</tr>
</tbody>
</table>
<p><img src="http://www.spamhaus.org/images/shad02.gif" border="0" alt="" width="544" height="15" /></p>
<table style="height:40px;" border="0" cellspacing="0" cellpadding="6" width="544">
<tbody>
<tr>
<td width="20" valign="middle" bgcolor="#ff3600">
<div><strong> 2 </strong></div>
</td>
<td valign="middle" bgcolor="#e6e6e6">China</td>
<td width="280" valign="middle" bgcolor="#e6e6e6">Number of Current Live Spam Issues: 590</td>
</tr>
</tbody>
</table>
<p><img src="http://www.spamhaus.org/images/shad02.gif" border="0" alt="" width="544" height="15" /></p>
<table style="height:40px;" border="0" cellspacing="0" cellpadding="6" width="544">
<tbody>
<tr>
<td width="20" valign="middle" bgcolor="#ff3900">
<div><strong> 3 </strong></div>
</td>
<td valign="middle" bgcolor="#e6e6e6">Russian Federation</td>
<td width="280" valign="middle" bgcolor="#e6e6e6">Number of Current Live Spam Issues: 457</td>
</tr>
</tbody>
</table>
<p>Another gage to use is reported malware websites by ASN, found here on <a href="http://maliciousnetworks.org">Malicious Networks</a>.  14 out of the 20 ISPs listed are in the United States. This should be of very big concern to all of us. Hosters in the US and elsewhere need to be more proactive in taking down activity deemed as malicious. Webhosting and other organizations with large online content also need to secure their servers better and try to put more measures in minimizing fraudulent signups of accounts.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/inboxrevenge.wordpress.com/406/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/inboxrevenge.wordpress.com/406/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/inboxrevenge.wordpress.com/406/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/inboxrevenge.wordpress.com/406/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/inboxrevenge.wordpress.com/406/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/inboxrevenge.wordpress.com/406/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/inboxrevenge.wordpress.com/406/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/inboxrevenge.wordpress.com/406/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/inboxrevenge.wordpress.com/406/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/inboxrevenge.wordpress.com/406/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/inboxrevenge.wordpress.com/406/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/inboxrevenge.wordpress.com/406/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/inboxrevenge.wordpress.com/406/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/inboxrevenge.wordpress.com/406/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=inboxrevenge.wordpress.com&amp;blog=8143881&amp;post=406&amp;subd=inboxrevenge&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://inboxrevenge.wordpress.com/2010/02/24/the-united-states-malware-and-spam-central-online/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/86c0ba68c3a092f5479d56543de3d9a5?s=96&#38;d=&#38;r=G" medium="image">
			<media:title type="html">reportscams</media:title>
		</media:content>

		<media:content url="http://www.spamhaus.org/images/shad02.gif" medium="image" />

		<media:content url="http://www.spamhaus.org/images/shad02.gif" medium="image" />
	</item>
		<item>
		<title>Telefonica.es (AS3352) #1 on Spamhaus ISP SBL</title>
		<link>http://inboxrevenge.wordpress.com/2010/01/17/telefonica-es-as3352-1-on-spamhaus-isp-sbl/</link>
		<comments>http://inboxrevenge.wordpress.com/2010/01/17/telefonica-es-as3352-1-on-spamhaus-isp-sbl/#comments</comments>
		<pubDate>Sun, 17 Jan 2010 08:22:08 +0000</pubDate>
		<dc:creator>reportscams</dc:creator>
				<category><![CDATA[blacklist]]></category>
		<category><![CDATA[blocklist]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[rogue networks]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[Argentina]]></category>
		<category><![CDATA[AS16276]]></category>
		<category><![CDATA[AS22185]]></category>
		<category><![CDATA[AS2828]]></category>
		<category><![CDATA[AS3257]]></category>
		<category><![CDATA[AS3352]]></category>
		<category><![CDATA[blocklisting]]></category>
		<category><![CDATA[Colombia]]></category>
		<category><![CDATA[Fabio Petta - Jnternet]]></category>
		<category><![CDATA[France]]></category>
		<category><![CDATA[network]]></category>
		<category><![CDATA[OVH.net]]></category>
		<category><![CDATA[RBL]]></category>
		<category><![CDATA[ROKSO]]></category>
		<category><![CDATA[SBL]]></category>
		<category><![CDATA[Spain]]></category>
		<category><![CDATA[spamhaus]]></category>
		<category><![CDATA[spamming]]></category>
		<category><![CDATA[Telefonica]]></category>
		<category><![CDATA[telefonica.com.ar]]></category>
		<category><![CDATA[telefonica.es]]></category>
		<category><![CDATA[tiscali.it]]></category>
		<category><![CDATA[USA]]></category>
		<category><![CDATA[xo.com]]></category>

		<guid isPermaLink="false">http://inboxrevenge.wordpress.com/?p=374</guid>
		<description><![CDATA[According to  Spamhaus Top 10 Network offenders on its Spamhaus Block List Advisory, an ISP called AS3352 TELEFONICA-DATA-ESPANA has the most SBLs on Spamhaus list as of January 17th, 2010. Based on Spamhaus&#8216; research, this ISP is considered the current &#8220;World&#8217;s Worst Network.&#8221;  At time of this post, there are 95 SBLs belonging to Telefonica.es. [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=inboxrevenge.wordpress.com&amp;blog=8143881&amp;post=374&amp;subd=inboxrevenge&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>According to  Spamhaus Top 10 Network offenders on its <a href="http://www.spamhaus.org/sbl/">Spamhaus Block List Advisory</a>, an ISP called <a href="http://www.fixedorbit.com/AS/3/AS3352.htm">AS3352</a> TELEFONICA-DATA-ESPANA has the most SBLs on Spamhaus list as of January 17th, 2010. Based on <a href="http://www.spamhaus.org/statistics/networks.lasso">Spamhaus</a>&#8216; research, this ISP is considered the current &#8220;World&#8217;s Worst Network.&#8221;  At time of this post, there are 95 SBLs belonging to <a href="http://www.telefonica.es">Telefonica.es</a>.</p>
<p><a href="http://inboxrevenge.files.wordpress.com/2010/01/spamhausworstnetworks-top5-1-15-103.png"><img class="aligncenter size-full wp-image-392" title="SpamhausWorstNetworks-Top5-1-15-10" src="http://inboxrevenge.files.wordpress.com/2010/01/spamhausworstnetworks-top5-1-15-103.png?w=500&#038;h=330" alt="" width="500" height="330" /></a></p>
<p><strong>Spamhaus: The 10 Worst Spam Support ISPs</strong><br />
As at 17 January 2010 the ISPs with the poorest abuse control of spammers are:</p>
<p>Rank / SBL #  ISP domain / ASN / URL<br />
1. <strong>95</strong> telefonica.es AS3352 / <a href="http://www.telefonica.es/">http://www.telefonica.es/</a><br />
2. <strong>64 </strong> ovh.net  AS16276 / <a href="http://ovh.net/">http://ovh.net/</a><br />
3. <strong>59 </strong>telefonica.com.ar AS22185 /  <a href="http://www.telefonica.com.ar">http://www.telefonica.com.ar</a>/<br />
4. <strong>46</strong> tiscali.it AS3257 /  <a href="http://www.tiscali.it/">http://www.tiscali.it/</a><br />
5. <strong>44</strong> xo.com AS2828 /  <a href="http://www.xo.com/">http://www.xo.com/</a><br />
6. <strong>38</strong> integratelecom.com AS7385 / <a href="http://integratelecom.com/">http://integratelecom.com/</a><br />
7. <strong>38</strong> charter.com AS20115 / <a href="http://www.charter.com/">http://www.charter.com/</a><br />
8. <strong>38</strong> ono.com AS6739 / <a href="http://www.ono.es/">http://www.ono.es/</a><br />
9. <strong>35</strong> verizon.com AS19262 / <a href="http://www.verizon.com/">http://www.verizon.com/</a><br />
10. <strong>34</strong> telecom.com.ar AS7303 / <a href="http://www.telecom.com.ar/">http://www.telecom.com.ar/</a></p>
<p>Many SBLs of telefonica.es (Telefonica de Espana, AS3352, netname: RIMA ) are /32 (1 IP address) blacklistings with lots of ROKSO <a href="http://www.spamhaus.org/rokso/listing.lasso?file=1099">Canadian Pharmacy</a> listings. Many of the Telefonica.es SBLs were added from October to December 2009. ROKSO is a list compiled by Spamhaus of the worst spamming organizations. ROKSO stands for Registry of Known Spam Operatives.</p>
<p>While Second ranking OVH&#8217;s listings are /32 as well, not so many current SBLs are those of ROKSO spammers. OVH.net offers both dedicated and shared hosting; unfortunately, spammers are attracted to either one. OVH.net was noted as the Worst Offending ISP on this <a href="http://inboxrevenge.wordpress.com/2009/12/07/ovh-net-worst-network-offender-on-spamhaus/">blog back in December 2009</a>. The <a href="http://forum.ovh.co.uk/showthread.php?p=25172">good news</a> about OVH is that it appears the admins are working on riding its network of spammers. Telefonica.com.ar is in 3rd place with 59 SBLs has larger blocklistings, such as numerous /24 which are 256 IP addresses. The ROKSO spammer&#8217;s listings on tiscali.it is  <a href="http://www.spamhaus.org/rokso/listing.lasso?file=972">Fabio Petta &#8211; Jnternet</a>.</p>
<p>One note about this top 10 list is the number of Spanish-speaking ISPs. For example: telefonica.es and ono.com / ono.es are located in Spain, while Argentina is represented by telefonica.com.ar and telecom.com.ar. Telefónica <a href="http://www.telefonica.com/en/about_telefonica/html/quienessomos/quienessomos.shtml">explains on its website</a> that it is one of the largest telecommunications companies by market (Spain, Europe and Latin America).</p>
<p>The 2 other Euoropean-based ISPs are OVH of France and Tiscali.it in Italy. The 4 US-based providers on the Spamhaus Block List are:  XO, Charter, Integra Telecom and Verizon.  XO.com is a large  Tier-2 NSP (network service provider), while Integra Telecom is a regional ISP in the midwest and western US states, and Charter is a regional ISP.  Verizon (made up of Baby Bell companies) as an ISP is offered in most markets in the US. Verizon is also a leading wireless cell phone provider.</p>
<p>Spamhaus&#8217; SBL ranking is based on Spamhaus own research of spam and so the list has its <a href="http://ksforum.inboxrevenge.com/viewtopic.php?f=1&amp;t=2036">own limitations</a>.  Among the reasons: ISPs have to contact Spamhaus to get their SBLs removed, so the SBL list is a manual process, and not automated like CBL.</p>
<p>If a researcher wants to know more volumes of ISP spam emiters, one can use other online tools available such as <a href="http://www.spamcop.net/w3m?action=hoshame">Spamcop&#8217;s list by hostname/ IP.</a> Though much smaller in scope than Spamcop, German Powerweb&#8217;s DNSBL.de has a <a href="http://dnsbl.de/">top 20 providers list</a> on its main page by spam volume based on the ASN (Autonomous System Number) which is used to identify a network by the Internet Protocol addresses authorities.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/inboxrevenge.wordpress.com/374/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/inboxrevenge.wordpress.com/374/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/inboxrevenge.wordpress.com/374/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/inboxrevenge.wordpress.com/374/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/inboxrevenge.wordpress.com/374/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/inboxrevenge.wordpress.com/374/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/inboxrevenge.wordpress.com/374/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/inboxrevenge.wordpress.com/374/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/inboxrevenge.wordpress.com/374/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/inboxrevenge.wordpress.com/374/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/inboxrevenge.wordpress.com/374/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/inboxrevenge.wordpress.com/374/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/inboxrevenge.wordpress.com/374/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/inboxrevenge.wordpress.com/374/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=inboxrevenge.wordpress.com&amp;blog=8143881&amp;post=374&amp;subd=inboxrevenge&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://inboxrevenge.wordpress.com/2010/01/17/telefonica-es-as3352-1-on-spamhaus-isp-sbl/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/86c0ba68c3a092f5479d56543de3d9a5?s=96&#38;d=&#38;r=G" medium="image">
			<media:title type="html">reportscams</media:title>
		</media:content>

		<media:content url="http://inboxrevenge.files.wordpress.com/2010/01/spamhausworstnetworks-top5-1-15-103.png" medium="image">
			<media:title type="html">SpamhausWorstNetworks-Top5-1-15-10</media:title>
		</media:content>
	</item>
		<item>
		<title>Newest Spamhaus ROKSO Addition: Tactara</title>
		<link>http://inboxrevenge.wordpress.com/2009/12/13/newest-spamhaus-rokso-addition-tactara/</link>
		<comments>http://inboxrevenge.wordpress.com/2009/12/13/newest-spamhaus-rokso-addition-tactara/#comments</comments>
		<pubDate>Sun, 13 Dec 2009 18:40:05 +0000</pubDate>
		<dc:creator>reportscams</dc:creator>
				<category><![CDATA[blacklist]]></category>
		<category><![CDATA[blocklist]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[registrars]]></category>
		<category><![CDATA[rogue networks]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[anonymous WHOIS]]></category>
		<category><![CDATA[AS18687]]></category>
		<category><![CDATA[ASN]]></category>
		<category><![CDATA[colo]]></category>
		<category><![CDATA[colocated]]></category>
		<category><![CDATA[inboxrevenge]]></category>
		<category><![CDATA[Los Angeles]]></category>
		<category><![CDATA[MAAWG]]></category>
		<category><![CDATA[MPower]]></category>
		<category><![CDATA[patent]]></category>
		<category><![CDATA[redirects]]></category>
		<category><![CDATA[ROKSO]]></category>
		<category><![CDATA[SBL]]></category>
		<category><![CDATA[shell]]></category>
		<category><![CDATA[snowshoe]]></category>
		<category><![CDATA[spamhaus]]></category>
		<category><![CDATA[spamming]]></category>
		<category><![CDATA[spamvertizing]]></category>
		<category><![CDATA[tactara]]></category>
		<category><![CDATA[The Spam Diaries]]></category>
		<category><![CDATA[Traffix]]></category>
		<category><![CDATA[USA]]></category>
		<category><![CDATA[Webzero]]></category>
		<category><![CDATA[Wyoming]]></category>

		<guid isPermaLink="false">http://inboxrevenge.wordpress.com/?p=351</guid>
		<description><![CDATA[In December 2009, Spamhaus added a new entry in its ROKSO database called Tactara.  (ROKSO: Register of Known Spam Operations). A persistent spamming group is given this title when it is determined that the spamming operation has been removed (services terminated) from at least 3 ISPs. The first blogger to note this update of the [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=inboxrevenge.wordpress.com&amp;blog=8143881&amp;post=351&amp;subd=inboxrevenge&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>In December 2009, Spamhaus added a new entry in its ROKSO database called <a href="http://www.spamhaus.org/rokso/listing.lasso?-op=cn&amp;spammer=Tactara">Tactara</a>.  (ROKSO: Register of Known Spam Operations). A persistent spamming group is given this title when it is determined that the spamming operation has been removed (services terminated) from at least 3 ISPs. The first blogger to note this update of the Spamhaus ROKSO entry was <a href="http://thespamdiaries.blogspot.com/2009/12/tactera-added-to-spamhaus.html">Ed Falk of The Spam Diaries</a>.  Usually Spamhaus names such groups based on the identities the spammers have given themselves. Some ROKSO entries are under individual names while other ROKSO names are under company names the spammers have used in the past or present.</p>
<p><strong>Where is Tactara located?</strong></p>
<p>Spamhaus indicates this Tactara operation is out of Wyoming in the United States. These groups have set up shell companies in Wyoming, Nevada, and some other US states. Another name Tactara has used is Webzero when it created its company name in Wyoming in 2006. Tactara has engaged in various forms of snowshoe spamming, which is spamming from many IPs and netblocks in order to evade blacklists. As typical with snowshoe spamming operations, Tactara has used many anonymized domains for spam emitting, spamvertizing and nameservers. Based on the ARIN Allocations from 11/2009 in the <a href="http://www.spamhaus.org/rokso/evidence.lasso?rokso_id=ROK8926">ROKSO listing</a>, the Tactara group has operated out of  colocated data centers in the area of Los Angeles, California.  Tactara&#8217;s <a href="http://tactara.com">website</a> says its offices are in Los Angeles.</p>
<p>Below is a partial ARIN record of Tactara that was active as of December 2009. Note the ASN is:  <a href="http://www.fixedorbit.com/AS/18/AS18687.htm">AS18687</a> which is listed under MPower Communications.</p>
<blockquote>
<pre>CustName:   Tactara
Address:    550 S Hope St. Suite 2825
City:       LOS ANGELES
StateProv:  CA
PostalCode: 90017
Country:    US
RegDate:    2009-09-11
Updated:    2009-09-11
<pre>NetRange:   208.57.149.224 - 208.57.149.231
CIDR:       208.57.149.224/29
OriginAS:   AS18687
NetName:    TACTARA
NetHandle:  NET-208-57-149-224-1
Parent:     NET-208-57-0-0-1
NetType:    Reassigned
Comment:
RegDate:    2009-09-11
Updated:    2009-09-11

RTechHandle: ZM147-ARIN
RTechName:   MPOWER COMMUNICATIONS CORP
RTechPhone:  +1-702-310-4578
RTechEmail:  ip-mgmt@mpowercom.net 

OrgAbuseHandle: MIAA-ARIN
OrgAbuseName:   Mpower IP Abuse Administrator
OrgAbusePhone:  +1-877-642-4375
OrgAbuseEmail:  ip-abuse@mpowercom.net

OrgTechHandle: MITA-ARIN
OrgTechName:   Mpower IP Technical Administrator
OrgTechPhone:  +1-702-310-4578
OrgTechEmail:  ip-mgmt@mpowercom.net

# ARIN WHOIS database, last updated 2009-12-11 20:</pre>
</pre>
</blockquote>
<p>According to Spamhaus, this group pretends to be ISP brokers and lease out space to customer mostly in /24 blocks in leasing from colocation providers.  The addresses of these numerous shell companies are usually drop mail boxes at UPS stores located in Wyoming or Delaware. Most of the IPs within these blocks of Tactara then have a landing page with a simple unsubscribe page on them<strong>.<br />
</strong></p>
<p><strong>Snowshoe and Spamhaus CSS</strong></p>
<p>In October 2009, Spamhaus recently <a href="http://www.spamhaus.org/css/">launched its CSS</a> service to ferret out snoeshow spamming operations in an automated manner.  So as Spamhaus has mentioned specifically in its <a href="http://www.spamhaus.org/news.lasso?article=650">recent blog entry from 12/09</a>, many ISPs are taking immediate action due to the SBLs by terminating snowshoe spamming accounts.</p>
<p><strong>Tactara and a Patent</strong></p>
<p>As already noted by <a href="http://thespamdiaries.blogspot.com/2009/12/tactera-added-to-spamhaus.html">Spam Diaries</a>, Tactara LLC even <a href="http://patft.uspto.gov/netacgi/nph-Parser?Sect2=PTO1&amp;Sect2=HITOFF&amp;p=1&amp;u=%2Fnetahtml%2FPTO%2Fsearch-bool.html&amp;r=1&amp;f=G&amp;l=50&amp;d=PALL&amp;RefSrch=yes&amp;Query=PN%2F7594035">applied for a patent</a> for its particular type of snowshoe spamming. On its website, <a href="http://www.tactara.com/about.aspx">Tactara</a> also makes an apparent false claim to be a member of <a href="http://www.maawg.org/home">MAAWG</a> (Messaging Anti-Abuse Working Group).</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/inboxrevenge.wordpress.com/351/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/inboxrevenge.wordpress.com/351/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/inboxrevenge.wordpress.com/351/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/inboxrevenge.wordpress.com/351/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/inboxrevenge.wordpress.com/351/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/inboxrevenge.wordpress.com/351/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/inboxrevenge.wordpress.com/351/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/inboxrevenge.wordpress.com/351/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/inboxrevenge.wordpress.com/351/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/inboxrevenge.wordpress.com/351/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/inboxrevenge.wordpress.com/351/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/inboxrevenge.wordpress.com/351/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/inboxrevenge.wordpress.com/351/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/inboxrevenge.wordpress.com/351/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=inboxrevenge.wordpress.com&amp;blog=8143881&amp;post=351&amp;subd=inboxrevenge&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://inboxrevenge.wordpress.com/2009/12/13/newest-spamhaus-rokso-addition-tactara/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/86c0ba68c3a092f5479d56543de3d9a5?s=96&#38;d=&#38;r=G" medium="image">
			<media:title type="html">reportscams</media:title>
		</media:content>
	</item>
		<item>
		<title>OVH.net Worst Network Offender on Spamhaus</title>
		<link>http://inboxrevenge.wordpress.com/2009/12/07/ovh-net-worst-network-offender-on-spamhaus/</link>
		<comments>http://inboxrevenge.wordpress.com/2009/12/07/ovh-net-worst-network-offender-on-spamhaus/#comments</comments>
		<pubDate>Mon, 07 Dec 2009 23:12:48 +0000</pubDate>
		<dc:creator>reportscams</dc:creator>
				<category><![CDATA[blacklist]]></category>
		<category><![CDATA[blocklist]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[rogue networks]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[AS16276]]></category>
		<category><![CDATA[AS2828]]></category>
		<category><![CDATA[AS3257]]></category>
		<category><![CDATA[AS46562]]></category>
		<category><![CDATA[AS7315]]></category>
		<category><![CDATA[block list]]></category>
		<category><![CDATA[mzima.net]]></category>
		<category><![CDATA[rogue network]]></category>
		<category><![CDATA[SBL]]></category>
		<category><![CDATA[spamblock]]></category>
		<category><![CDATA[spamhaus]]></category>
		<category><![CDATA[spamming]]></category>
		<category><![CDATA[telefonica.es]]></category>
		<category><![CDATA[tiscali.it]]></category>
		<category><![CDATA[xo.com]]></category>

		<guid isPermaLink="false">http://inboxrevenge.wordpress.com/?p=342</guid>
		<description><![CDATA[Since around August 2009 or so, French provider OVH.net (AS16276) has been the top offender by current SBLs on Spamhaus. Here is a screenshot of that list on Spamhaus as of December 5th, 2009. Also, note. The list below as of 12/5/09. 1. ovh.net  AS16276 = 77 SBLs 2. telefonica.es AS3352 = 59 SBLs 3. [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=inboxrevenge.wordpress.com&amp;blog=8143881&amp;post=342&amp;subd=inboxrevenge&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Since around August 2009 or so, French provider <a href="http://ovh.net/">OVH.net</a> (<a href="http://www.robtex.com/as/as16276.html">AS16276)</a> has been the <a href="http://www.spamhaus.org/statistics/networks.lasso">top offender</a> by current SBLs on Spamhaus.</p>
<p>Here is a screenshot of that list on Spamhaus as of December 5th, 2009.</p>
<p>Also, note. The list below as of 12/5/09.<br />
1. ovh.net  AS16276 = 77 SBLs<br />
2. telefonica.es AS3352 = 59 SBLs<br />
3. xo.com AS2828 = 48 SBLs<br />
4. tiscali.it  AS3257 = 43 SBLs<br />
5. mzima.net AS46562 = 38 SBLs<br />
6. internap.com AS11855 = 37 SBLs<br />
7. telefonica.com.ar  AS22927 = 37 SBLs<br />
8. ttnet.net.tr AS9121 = 34 SBLs<br />
9. ono.com as6739  = 33  SBLs<br />
10. interbusiness.it  = 29 SBLs</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/inboxrevenge.wordpress.com/342/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/inboxrevenge.wordpress.com/342/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/inboxrevenge.wordpress.com/342/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/inboxrevenge.wordpress.com/342/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/inboxrevenge.wordpress.com/342/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/inboxrevenge.wordpress.com/342/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/inboxrevenge.wordpress.com/342/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/inboxrevenge.wordpress.com/342/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/inboxrevenge.wordpress.com/342/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/inboxrevenge.wordpress.com/342/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/inboxrevenge.wordpress.com/342/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/inboxrevenge.wordpress.com/342/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/inboxrevenge.wordpress.com/342/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/inboxrevenge.wordpress.com/342/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=inboxrevenge.wordpress.com&amp;blog=8143881&amp;post=342&amp;subd=inboxrevenge&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://inboxrevenge.wordpress.com/2009/12/07/ovh-net-worst-network-offender-on-spamhaus/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/86c0ba68c3a092f5479d56543de3d9a5?s=96&#38;d=&#38;r=G" medium="image">
			<media:title type="html">reportscams</media:title>
		</media:content>
	</item>
		<item>
		<title>InBoxRevenge Under Attack Again</title>
		<link>http://inboxrevenge.wordpress.com/2009/11/16/inboxrevenge-under-attack-again/</link>
		<comments>http://inboxrevenge.wordpress.com/2009/11/16/inboxrevenge-under-attack-again/#comments</comments>
		<pubDate>Mon, 16 Nov 2009 20:06:32 +0000</pubDate>
		<dc:creator>reportscams</dc:creator>
				<category><![CDATA[blacklist]]></category>
		<category><![CDATA[blocklist]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[rogue networks]]></category>
		<category><![CDATA[scareware]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[attack]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[DDoS]]></category>
		<category><![CDATA[Denial of Service Attack]]></category>
		<category><![CDATA[IBR]]></category>
		<category><![CDATA[Inbound DOS]]></category>
		<category><![CDATA[inboxrevenge]]></category>
		<category><![CDATA[offline]]></category>
		<category><![CDATA[spammers]]></category>
		<category><![CDATA[Syn Flood]]></category>
		<category><![CDATA[website outage]]></category>

		<guid isPermaLink="false">http://inboxrevenge.wordpress.com/?p=322</guid>
		<description><![CDATA[This is the third attack on the InBoxRevenge antispam forums within one month. The first DDoS attack which was posted below was on October 28, 2009. Since about 10:45 Eastern Time on Monday, November 16th, 2009, IBR&#8217;s forums are once again offline. We will give you more details as they become available. It seems that [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=inboxrevenge.wordpress.com&amp;blog=8143881&amp;post=322&amp;subd=inboxrevenge&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>This is the third attack on the <a href="http://ksforum.inboxrevenge.com">InBoxRevenge</a> antispam forums within one month. The first DDoS attack which was posted below was on <a href="http://inboxrevenge.wordpress.com/2009/10/28/301/">October 28, 2009</a>.</p>
<p>Since about 10:45 Eastern Time on Monday, November 16th, 2009, IBR&#8217;s forums are once again offline.</p>
<p>We will give you more details as they become available. It seems that spammers are definitely still very angry with the content posted on <a href="http://ksforum.inboxrevenge.com">IBR</a>.</p>
<p>We will continue to spread information online via <a href="http://twitter.com/InBoxRevenge">various</a> <a href="http://twitter.com/spamislame">twitter</a> <a href="http://twitter.com/thegilesmark">accounts</a>, <a href="http://inboxrevenge.blogspot.com/">blogs</a>, and other websites about collecting information which leads to shutting down illegal spammer operations. Attacks such as this one and others do not stop our efforts as we continue to report spamming operations.</p>
<p>As a reminder, check out our other websites online for updates:</p>
<p>Twitter: <a href="http://twitter.com/inboxrevenge">http://twitter.com/inboxrevenge</a><br />
Other blogs:</p>
<p><a href="http://inboxrevenge.blogspot.com/">http://garwarner.blogspot.com/</a></p>
<p><a href="http://inboxrevenge.blogspot.com/">http://inboxrevenge.blogspot.com</a><br />
<a href="http://spamtrackers.org/"></a><a href="http://inboxrevenge.spaces.live.com/"></a></p>
<p><a href="http://inboxrevenge.spaces.live.com/">http://inboxrevenge.spaces.live.com</a></p>
<p>Wiki:</p>
<p><a href="http://spamtrackers.org/">http://spamtrackers.org</a></p>
<p>Please note: that SiL also has his two blogs, which also accept moderated comments:<br />
<a href="http://ikillspammers.blogspot.com/">http://ikillspammers.blogspot.com</a><br />
<a href="http://spamitmustfall.blogspot.com/"></a></p>
<p><a href="http://spamitmustfall.blogspot.com/">http://spamitmustfall.blogspot.com</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/inboxrevenge.wordpress.com/322/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/inboxrevenge.wordpress.com/322/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/inboxrevenge.wordpress.com/322/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/inboxrevenge.wordpress.com/322/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/inboxrevenge.wordpress.com/322/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/inboxrevenge.wordpress.com/322/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/inboxrevenge.wordpress.com/322/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/inboxrevenge.wordpress.com/322/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/inboxrevenge.wordpress.com/322/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/inboxrevenge.wordpress.com/322/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/inboxrevenge.wordpress.com/322/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/inboxrevenge.wordpress.com/322/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/inboxrevenge.wordpress.com/322/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/inboxrevenge.wordpress.com/322/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=inboxrevenge.wordpress.com&amp;blog=8143881&amp;post=322&amp;subd=inboxrevenge&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://inboxrevenge.wordpress.com/2009/11/16/inboxrevenge-under-attack-again/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/86c0ba68c3a092f5479d56543de3d9a5?s=96&#38;d=&#38;r=G" medium="image">
			<media:title type="html">reportscams</media:title>
		</media:content>
	</item>
		<item>
		<title>Italian Phishing site spoofing CartaSi</title>
		<link>http://inboxrevenge.wordpress.com/2009/11/05/italian-phishing-site/</link>
		<comments>http://inboxrevenge.wordpress.com/2009/11/05/italian-phishing-site/#comments</comments>
		<pubDate>Thu, 05 Nov 2009 16:45:49 +0000</pubDate>
		<dc:creator>inboxrevenge</dc:creator>
				<category><![CDATA[blacklist]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[banking spoof]]></category>

		<guid isPermaLink="false">http://inboxrevenge.wordpress.com/?p=318</guid>
		<description><![CDATA[Italian banking site phishing URL spoofing CartaSi is live on compromised host: phone.codmanacademy.org &#8211; IP: 69.38.149.93 which is on AS19406 (Towerstream.com). Munged URL: hxxp://phone.codmanacademy.org/home/polycom/.redirecting.titolari.cartasi.it.portal.server.pt.acceso.reg.recupero.gateway.nome.utente.o.password.se.hai.dimenticato/ URL was already reported to Netcraft and Phishtank.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=inboxrevenge.wordpress.com&amp;blog=8143881&amp;post=318&amp;subd=inboxrevenge&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Italian banking site phishing URL spoofing CartaSi is live on compromised host: phone.codmanacademy.org &#8211; IP: 69.38.149.93 which is on AS19406 (Towerstream.com).</p>
<p>Munged URL:</p>
<p>hxxp://phone.codmanacademy.org/home/polycom/.redirecting.titolari.cartasi.it.portal.server.pt.acceso.reg.recupero.gateway.nome.utente.o.password.se.hai.dimenticato/</p>
<p>URL was already reported to Netcraft and Phishtank.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/inboxrevenge.wordpress.com/318/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/inboxrevenge.wordpress.com/318/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/inboxrevenge.wordpress.com/318/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/inboxrevenge.wordpress.com/318/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/inboxrevenge.wordpress.com/318/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/inboxrevenge.wordpress.com/318/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/inboxrevenge.wordpress.com/318/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/inboxrevenge.wordpress.com/318/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/inboxrevenge.wordpress.com/318/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/inboxrevenge.wordpress.com/318/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/inboxrevenge.wordpress.com/318/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/inboxrevenge.wordpress.com/318/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/inboxrevenge.wordpress.com/318/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/inboxrevenge.wordpress.com/318/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=inboxrevenge.wordpress.com&amp;blog=8143881&amp;post=318&amp;subd=inboxrevenge&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://inboxrevenge.wordpress.com/2009/11/05/italian-phishing-site/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/aae59ae0ad08baf7480890c2912e290b?s=96&#38;d=&#38;r=G" medium="image">
			<media:title type="html">InBoxRevenge</media:title>
		</media:content>
	</item>
	</channel>
</rss>
