create your own

using whois to find out who is spamming you

65
rate or flag this page

By doctorjay

A spam arrives

One of my hosted email accounts (as opposed to free accounts such as Yahoo mail and gmail) I only use rarely (mainly for my paypal account and commission junction). So I know any email not coming from a few sources are bound to be spam.

Most of the spam is caught by the spam catcher but some get through and land in my inbox.

Today an email arrived saying that I had joined a certain web site. It was not a phishing email as there was no asking me to go and enter my information that typical phishing emails do.


It's so good I doubt myself

The email started:

Dear ,

Thank you for becoming a Fairfax Digital Member. Your username and password give you access to a range of services across the Fairfax Digital sites, including....

Note:

  • this is spam and has nothing to do with the Australian newspapers web sites Fairfax Digital.
  • They write Dear but do not know my name. Any memship site (free or paid would know your name and use it).

The email continued with:

Access to some Fairfax Digital websites
Fairfax Digital websites such www.smh.com.au, www.theage.com.au, www.rugbyheaven.com, and www.realfooty.com.au require users to register in order to gain access to content within the site. Registration is free, and only needs to be done once.

All the above sites are real Australian sites (I checked associated with the real Fairfax Digital)

The truth is revealed

In Microsoft Outlook as you go over a link you see the actual place the link would take you to. So I noticed that the sites the spam email was trying to send me to.

They were sites in India.

It was an HTML email (it has to be to have links in it). So I looked at the email source. Part of it showed me where they were trying to send me:

<A rel="nofollow" target="_blank" href="http://theirshoppinglist.in/" onclick="return cfm(this);" >Fairfax Digital Privacy Policy</A> |
<A rel="nofollow" target="_blank" href="http://thelikelife.in/" onclick="return cfm(this);" >Member Agreement</A> |
<A rel="nofollow" target="_blank" href="http://theleadingarthritis.in/" onclick="return cfm(this);" >Conditions of Use</A> |
<A rel="nofollow" target="_blank" href="http://theirshoppinglist.in/">Contact Us</A></FONT></P>

If you do not read HTML all you need to know is that thelikelife.in is one of the domains they are trying to send me to.


How to find out who the spammer is

I searched WHOIS for thelikelife.inĀ  to see who the owner is.

WHOIS a web service like DNS which displays the ownership details with the domain registry. Often people will have private registry and we only see the private registrant but this may cost extra and the phishing and other spammers at times do not use private registrants.

And the winner is:

Actually you could be the loser if you clicked on their links. I'm not going to risk it. This is the WHOIS record for thelikelife.in (note I changed the perso:

Domain ID:D3579342-AFIN
Domain Name:THELIKELIVE.IN
Created On:24-Apr-2009 13:48:48 UTC
Last Updated On:24-Apr-2009 13:48:49 UTC
Expiration Date:24-Apr-2010 13:48:48 UTC
Sponsoring Registrar:Redacted
Status:CLIENT TRANSFER PROHIBITED
Status:TRANSFER PROHIBITED
Registrant ID:DI_9759019
Registrant Name:First Name - Last Name
Registrant Organization:First Name - Last Name
Registrant Street1:Redacted
Registrant Street2:
Registrant Street3:
Registrant City:Moscow
Registrant State/Province:Moscow
Registrant Postal Code:125445
Registrant Country:RU
Registrant Phone:Redacted
Registrant Phone Ext.:
Registrant FAX:Redacted
Registrant FAX Ext.:
Registrant Email:

Note most of these sites will be knocked off soon (at least I hope so). The domain was bought April 24th and today is May 13th.

Also note that even though the pretend site was Australian and the domain itself is Indian the spammer is Russian and his email is from Austria.

More over the spammer: "First Name - Last Name" owns about 866 other domains.

I have redacted all information about the spammer as I do not know the appropriate HubPage rules. The information is public and anyone can run the WHOIS for any website and find out relevant information. I'll write about how I've ben burned by not reading rules and contracts in another Hub.

Unfortunately so long as emails can be sent for free and idiots buy from spammers and unknowing people are fooled by phishing emails this is going to continue.

No doubt First Name - Last Name sends millions and perhaps billions of email a day and he only needs get on person per million to fall for his spam and he will make lots of money and have a great time in his Moscow home.


Print   —   Rate it:  up  down  flag this hub

Comments

RSS for comments on this Hub

No comments yet.

Submit a Comment

Members and Guests

Sign in or sign up and post using a hubpages account.


optional


  • No HTML is allowed in comments, but URLs will be hyperlinked
  • Comments are not for promoting your hubs or other sites

working