It appears the botnet Joe Job has started again. This time it’s “enlargement” products they’re hawking.
I’ve gotten 180 bounces since about 6:00pm yesterday. At this rate I may be forced to disable my catch-all, but it’s going to be a major PITA. I’ve probably got over a hundred aliases in use, and they aren’t individually registered. This means that I’m going to have to grovel through all of my previously received and sent emails and pull out the addresses I used and create explicit forwarding entries for each one.
Update 1: Got five more just in the two minutes it took me to write this entry.
Update 1a: Up to 226 as of 3:39pm.
Update 2: All of the spams link to various nonsense domains that contain “information” about something called “Man XL.” The scammer behind this nonsense is an entity calling itself “WW3 DISTRIBUTERS LLC.” Should you receive such an email, beware clicking the link unless you want to see Prasad’s “business” (if you were unfortunate enough to have clicked, you’ll know what I mean by that).
Update 3: Internally, all of these sites have a frameset that pulls the main frame content from http://www.cabaretmarin.net. Hitting that address causes a redirect to http://barbarises.net/ms/?bb, which then redirects to http://barbarises.net/ms/index.php?k=<garbage>. That appears to be a “campaign” tracking link (i.e. this particular batch of redirects through cabaretmarin.net seems to share this “k” value).
I did a random check of several of these “.info” domains that are in the emails. The all have similar information (i.e. same name, address, email) and were registered just a few days ago via RegisterFly. Here’s an example:
Registrant ID:tuJCnDTXYin4eSHs
Registrant Name:patrice pennetier
Registrant Organization:pennetier
Registrant Street1:rue notre dame, 21
Registrant Street2:
Registrant Street3:
Registrant City:tubize
Registrant State/Province:NA
Registrant Postal Code:1480
Registrant Country:BE
Registrant Phone:+1.3292313108
Registrant Phone Ext.:
Registrant FAX:+1.3292313108
Registrant FAX Ext.:
Registrant Email:pennetier@lagema.com
Information on “barbarises.net”:
Domain Name:barbarises.net
Registrant:
Mike Vester
Allensteiner Strasse 24
47237
Administrative Contact:
Mike Vester
Mike Vester
Allensteiner Strasse 24
Duisburg 47237
Germany
tel: 49 7161 3079405
fax: 49 7161 3079405
mike.vester@jelled.net
Technical Contact:
Mike Vester
Mike Vester
Allensteiner Strasse 24
Duisburg 47237
Germany
tel: 49 7161 3079405
fax: 49 7161 3079405
mike.vester@jelled.net
Billing Contact:
Mike Vester
Mike Vester
Allensteiner Strasse 24
Duisburg 47237
Germany
tel: 49 7161 3079405
fax: 49 7161 3079405
mike.vester@jelled.net
Registration Date: 2006-07-14
Update Date: 2006-08-31
Expiration Date: 2007-07-14
Primary DNS: ns1.buckraming.com 220.179.67.133
Secondary DNS: ns2.buckraming.com 220.179.67.133
The cabaretmarin.net domain appears to have been registered via a privacy service, though, which is not surprising as this is the first real link in the chain to his spam site:
Registration Service Provided By: Registerfly.com
Contact: support@registerfly.com
Visit: http://www.registerfly.com
Domain name: cabaretmarin.net
Registrant Contact:
RegisterFly.com – Ref# 19298483
Whois Protection Service – ProtectFly.com (q0seacfx9h23tj@protectfly.com)
+1.8458183604
Fax: +1.8456984014
P.O. Box 969
Margaretville, NY 12455
US
Administrative Contact:
RegisterFly.com – Ref# 19298483
Whois Protection Service – ProtectFly.com (fm1v2n5rhvt9jan@protectfly.com)
+1.8458183604
Fax: +1.8456984014
P.O. Box 969
Margaretville, NY 12455
US
Technical Contact:
RegisterFly.com – Ref# 19298483
Whois Protection Service – ProtectFly.com (qy5r8qhg3urbbxu@protectfly.com)
+1.8458183604
Fax: +1.8456984014
P.O. Box 969
Margaretville, NY 12455
US