Sponsored by..

Friday 31 October 2008

Dating scams and 79.135.168.*

We've seen this type of dating scam several times before. No good will come of engaging "Chantel" in conversations as she doesn't really exist. It will be some fat sweaty Russian bloke probably.

Subject: hi from chantel

hello, I am pretty russian girl, bored tonight.
would you like to chat with me and see my pics?
if so then email me at echantel39@officialsup.com
This is hosted on 79.135.168.36 which has been fingered before for fraud. Allegedly, the netblock is registered to an outfit in the Lebanon:


inetnum: 79.135.168.0 - 79.135.168.255
netname: LB-NET
descr: Lebanon private dedicated service
country: LB
admin-c: MHB1111-RIPE
tech-c: MHB1111-RIPE
remarks: abuse mailbox: moh.b@lubnannetworks.biz
status: ASSIGNED PA "status:" definitions
mnt-by: SISTEM-NET-MNT
source: RIPE # Filtered

person: Mohamed Baga
address: Basha Garden bldg, 5th floor LB
address: Jisr El Bacha Main Road
address: Beirut - Lebanon
e-mail: moh.b@lubnannetworks.biz
remarks: abuse mailbox: moh.b@lubnannetworks.biz
phone: +961 1 512341
nic-hdl: MHB1111-RIPE
source: RIPE # Filtered

% Information related to '79.135.160.0/19AS44097'

route: 79.135.160.0/19
descr: Sistemnet Telecom
origin: AS44097
mnt-by: Sistem-Net-MNT
But just a few IP addresses away is another netblock that we have seen before in Turkey. The whole netblock is a complete sewer and is listed on the Spamhaus DROP List. There are 2000+ domains in this /24 block, but just for brevity I will list the ones on this server - avoid them all.

  • Abgol.com
  • Amnocx.com
  • Bestsup.com
  • Cahla.com
  • Cardrealc.com
  • Centralrd.com
  • Direktmal.com
  • Equipyard.com
  • Escitatop.com
  • Eupoc.com
  • Ezshl.com
  • Firstlam.com
  • Flasheon.com
  • Flhnation.com
  • Flhplanet.com
  • Flhsupplies.com
  • Freeldp.info
  • Gbizc.info
  • Gbladx.info
  • Gblhome.info
  • Gblwizard.info
  • Golbalhobby.com
  • Goldenttamil.com
  • Goldirecto.com
  • Goldpug.info
  • Golguia.com
  • Golmundo.com
  • Golottoclub.com
  • Golsitio.com
  • Goltierra.com
  • Gosfordw.com
  • Hlgag.com
  • Hollandlopflags.com
  • Hyperlam.com
  • Jenniferlop.com
  • Jflyik.com
  • Ldphome.info
  • Ldpwizard.info
  • Lgbidxx.info
  • Lopguide.com
  • Meinmal.com
  • Miniplushlop.com
  • Modhl.com
  • Morerd.com
  • Moresup.com
  • Nitgbx.info
  • Officialflh.com
  • Officialgbl.info
  • Officialldp.info
  • Officialshl.com
  • Officialsup.com
  • Oldpee.info
  • Onlineflh.com
  • Onlineshl.com
  • Onlinesup.com
  • Pacanimal.com
  • Planetflh.com
  • Planetsup.com
  • Rdplanet.com
  • Revaloplast.com
  • Shemalglobal.com
  • Shlcentral.com
  • Shlnation.com
  • Shlsupplies.com
  • Shlwizard.com
  • Solidgoldent.com
  • Soundevelop.com
  • Superldp.info
  • Superlop.com
  • Supplanet.com
  • Supwizard.com
  • Tapthelop.com
  • Theloppet.com
  • Upflyp.com
  • Uplea.com
  • Virtualldp.info
  • Virtualsup.com
  • Virtuellmal.com
  • Wildevelop.com
  • Wildpin.info
  • Worldpivot.info
  • Worldplayservices.info
  • Yourldp.info
  • Yourlopmen.com
  • Yourloprabbit.com
Namesevers are NS1.DROREAL.COM and NS2.DROREAL.COM, both on 79.135.168.36.

No comments: