This site generates SPAM with PHISHING content and disguises its real email address and server.
EXAMPLE:
"From: "Carolyn Blackburn" <405111618@163.com>
Reply-To: "Carolyn Blackburn" <vlebedev518@gmail.com>
To: <torres7513@gmail.com>"
163.com is operated by netease.com.
Netease has a poor reputation:
www.mywot.com/scorecard/netease.com (The poor reputation of netease.com)
www.robtex.com/dns/163.com.html#graph
Other:
dnstinations.com is listed as a point of contact domain name for 163.com, run by netease.com which has a poor reputation. See:
https://www.markmonitor.com/cgi-bin/affsearch.cgi?dn=163.com (dnstinations.com is listed as a contact domain name)
www.mywot.com/en/scorecard/dnstinations.com (the lack of reputation of dnstinations.com)
163.com -- 365 day loans. $1000 Pre-Approval. 1 Hour Deposits! All Credit OK! 2nd Unsolicited spam sent from China (121.100.161.63). Same spam received from carvelbegulfs.com , ceppirogi.com, driftagesciurine.com , caudicesvavasor.com, click.katudirect.com, click.justyeqy.in, click.superyskcsite.inj, hidavy.com , onyclas.com, nreepted
Registrant:
Domain Administrator
Netease.com, Inc
No.16, Ke Yun Rd Tianhe District
GuangZhou GuangDong 510665
CN
+86.2085106370 Fax: +86.2085106370
123.com -- 365 day loans. $1000 Pre-Approval. 1 Hour Deposits! All Credit OK! 2nd Unsolicited spam sent from China (121.100.161.63). Same spam received from carvelbegulfs.com , ceppirogi.com, driftagesciurine.com , caudicesvavasor.com, click.katudirect.com, click.justyeqy.in, click.superyskcsite.inj, hidavy.com , onyclas.com, nreepted
Registrant:
Empresa Nacional de Telecomunicaciones S.A
Empresa Nacional de Telecomunicaciones S.A Empresa Nacional de Telecomunicaciones S.A
Avenida Andres Bello #2687 Las Condes
Santiago, 0000
CL
Phone: +1.3053659442
Email:
carvelbegulfs.com – 365 day loans. $1000 Pre-Approval. 1 Hour Deposits! All Credit OK! 2nd Unsolicited spam sent from China (121.100.161.63). Same spam received from ceppirogi.com, driftagesciurine.com , caudicesvavasor.com, click.katudirect.com, click.justyeqy.in, click.superyskcsite.inj, hidavy.com , onyclas.com, nreepted.com
carvelbegulfs.com – Loan Approvals Dept. Your $2500 Approval. BAD or NO Credit = OK! Unsolicited spam sent from China (121.100.161.63). Same spam received from ceppirogi.com, driftagesciurine.com , caudicesvavasor.com, click.katudirect.com, click.justyeqy.in, click.superyskcsite.inj, hidavy.com , onyclas.com, nreepted.com
Domain name: carvelbegulfs.com
Creation date: 20 Sep 2012
Administrative Contact:
WhoisGuard
WhoisGuard Protected ( )
+1.6613102107
Fax: +1.6613102107
11400 W. Olympic Blvd. Suite 200
Los Angeles, CA 90064
US
ceppirogi.com – 365 day loans. Loan up $1000. Unsolicited spam sent from Germany (5.28.216.233 ) Same spam sent from driftagesciurine.com , caudicesvavasor.com, click.katudirect.com, click.justyeqy.in, click.superyskcsite.inj, hidavy.com , onyclas.com, nreepted.com
Domain name: ceppirogi.com
Creation date: 20 Sep 2012
Administrative Contact:
WhoisGuard
WhoisGuard Protected ( )
+1.6613102107
Fax: +1.6613102107
11400 W. Olympic Blvd. Suite 200
Los Angeles, CA 90064
US
driftagesciurine.com – 1st USA loans. loan up to $1000 immediately. Unsolicited spam sent from Germany (93.127.237.147). Same spam sent from caudicesvavasor.com
Domain name: driftagesciurine.com
Administrative Contact:
WhoisGuard
WhoisGuard Protected ( )
+1.6613102107
Fax: +1.6613102107
11400 W. Olympic Blvd. Suite 200
Los Angeles, CA 90064
US
click.flickyourdeals.com – 250 free business cards. Unsolicited spam sent from Russia (176.112.217.117 )
Domain name: flickyourdeals.com
Registrant Contact:
WhoisGuard
WhoisGuard Protected ()
Fax: +1.6613102107
11400 W. Olympic Blvd. Suite 200
Los Angeles, CA 90064
US
Email: 31ca6fe7fa6b443884605bc90c3a34e4.protect@whoisguard.com
caudicesvavasor.com – e-cigarette free trial. Unsolocited spam sent from Germany (37.114.114.115 ). Same spam received from regcomnetw0rk.com,salindorm.com, smartsolsoft.com and nreepted.com, mtelxenica.com, liopin.com ,nreepted.com
caudicesvavasor.com – Loan Approval Up to $2500. Unsolocited spam sent from China (121.100.169.217 ). Same spam sent from click.katudirect.in, click.justyeqy.in, click.superyskcsite.inj, hidavy.com , onyclas.com, nreepted.com
Domain name: caudicesvavasor.com
Creation date: 20 Sep 2012 02:20:00
Registrant Contact:
WhoisGuard
WhoisGuard Protected ( )
+1.6613102107
Fax: +1.6613102107
11400 W. Olympic Blvd. Suite 200
Los Angeles, CA 90064
US
stijo.t15.org -- facebook identity theft sent from Turkey !!! Beware!!!
Domain Registered:
Admin ID:999cefafed5dd8fe
Admin Name:WhoisGuard Protected
Admin Organization:WhoisGuard
Admin Street1:11400 W. Olympic Blvd. Suite 200
Admin Street2:
Admin Street3:
Admin City:Los Angeles
Admin State/Province:CA
Admin Postal Code:90064
Admin Country:US
Admin Phone:+1.6613102107
Admin Phone Ext.:
Admin FAX:+1.6613102107
Admin FAX Ext.:
Admin Email: dfeat19b5d4794afaa78962e2a77a2597.protect@whoisguard.com
Originating IP Address: 89.106.12.62
organisation: ORG-GBTA1-RIPE
org-name: Grid Bilisim Teknolojileri A.S.
org-type: LIR
address: Grid Bilisim Teknolojileri A.S. Hakan Akan Ayazmadere cad. Aksit Plaza No:12 Kat:2 Fulya Besiktas 34349 Istanbul TURKEY
phone: +902122600400
fax-no: +902122367929
mnt-ref: RIPE-NCC-HM-MNT
mnt-ref: MNT-GRID
mnt-by: RIPE-NCC-HM-MNT
admin-c: IH647-RIPE
admin-c: YA160-RIPE
admin-c: HA1243-RIPE
admin-c: MS27230-RIPE
source: RIPE # Filtered
person: Yusuf Alakavuk
mnt-by: MNT-GRID
address: Ayazmadere cad. Aksit Plaza
address: No:12 Kat:2 Fulya
address: Besiktas Istanbul Turkey
phone: +90 212 310 09 00
fax-no: +90 212 236 79 29
nic-hdl: YA160-RIPE
source: RIPE # Filtered
***BEWARE*** Carlos Sanchez at corndogschangedmylife.com is associated with 307 domains. A lot of the spam he sends is also sent from Romanian domains.
yeknworld.in – zoosk. Find 6 new Flirts on Zoosk. Unsolicited spam. Same spam received from click.yourqykn.in
Domain ID:D6403052-AFIN
Domain Name:YEKNWORLD.IN
Created On:23-May-2012
Registrant ID:6fe9c65a8026b401
Registrant Name:Carlos Sanchez
click.cefpd.in – Your credit score may have been updated. Unsolicited spam
Domain ID:D6402917-AFIN
Domain Name:CEFPD.IN
Created On:23-May-2012 19:10:58 UTC
Registrant ID:6fe9c65a8026b401
Registrant Name:Carlos Sanchez
click.yourlvka.in – Loan up to $2500. Unsolicited spam
Domain ID:D6403238-AFIN
Domain Name:YOURLVKA.IN
Created On:23-May-2012 19:26:42 UTC
Registrant ID:6fe9c65a8026b401
Registrant Name:Carlos Sanchez
click.buystockchina.in – Cash loan $1000 overnight bad credit ok. Unsolicited spam sent from South Africa (197.238.209.61 )
Domain ID:D6402840-AFIN
Domain Name:BUYSTOCKCHINA.IN
Created On:23-May-2012 19:04:35 UTC
Registrant ID:6fe9c65a8026b401
Registrant Name:Carlos Sanchez
click.yourqykn.in – find 6 new flirts on zoosk. Unsolicited spam.
Domain Name:YOURQYKN.IN
Created On:23-May-2012 19:13:54 UTC
Registrant Name:Carlos Sanchez
click.bestgujarat.in – need cash today. Prequalified for cash loan. Unsolicited spam
Domain ID:D6402880-AFIN
Domain Name:BESTGUJARAT.IN
Created On:23-May-2012 19:07:55 UTC
Registrant ID:6fe9c65a8026b401
Registrant Name:Carlos Sanchez
Registrant Organization:Rhada Administracion de datos
Registrant Street1:Calle Diluvio #2189
Registrant Street2:Seccion Dorado
Registrant Street3:
Registrant City:Playas de Tijuana
Registrant State/Province:Tijuana Baja California
Registrant Postal Code:22505
Registrant Country:MX
Registrant Phone:+52.1664596
Registrant Phone Ext.:
Registrant FAX:
Registrant FAX Ext.:
Registrant Email: abuse@corndogschangedmylife.com
click.thelving.in– Bed Bugs Epidemic. Unsolicited spam sent from Russia (5.8.64.195). Same spam received from click.yourqyye.in , shfujod.com, nctravnews.com, omtelanet.com
Domain ID:D6403227-AFIN
Domain Name:THELVING.IN
Created On:23-May-2012 19:26:10 UTC
Sponsoring Registrar:Enom Inc. (R46-AFIN)
Registrant ID:6fe9c65a8026b401
Registrant Name:Carlos Sanchez
Registrant Organization:Rhada Administracion de datos
Registrant Street1:Calle Diluvio #2189
Registrant Street2:Seccion Dorado
Registrant Street3:
Registrant City:Playas de Tijuana
Registrant State/Province:Tijuana Baja California
Registrant Postal Code:22505
Registrant Country:MX
Registrant Phone:+52.1664596
Registrant Email: abuse@corndogschangedmylife.com
click.yourqyye.in – Bed Bugs Epidemic. Unsolicited spam sent from Russia (5.101.22.137 ). Same spam received from shfujod.com, nctravnews.com, omtelanet.com
Domain ID:D6402992-AFIN
Domain Name:YOURQYYE.IN
Created On:23-May-2012 19:14:14 UTC
Sponsoring Registrar:Enom Inc. (R46-AFIN)
Registrant ID:6fe9c65a8026b401
Registrant Name:Carlos Sanchez
Registrant Organization:Rhada Administracion de datos
Registrant Street1:Calle Diluvio #2189
Registrant Street2:Seccion Dorado
Registrant Street3:
Registrant City:Playas de Tijuana
Registrant State/Province:Tijuana Baja California
Registrant Postal Code:22505
Registrant Country:MX
Registrant Phone:+52.1664596
Registrant Email: abuse@corndogschangedmylife.com
click.katudirect.in – Loan Approval Center Up to $2500 cash loan now. Unsolocited spam sent from South Africa (197.238.116.227). Same spam sent from click.justyeqy.in, click.superyskcsite.inj, hidavy.com , onyclas.com, nreepted.com
Domain ID:D6403276-AFIN
Domain Name:KATUDIRECT.IN
Created On:23-May-2012 19:28:36 UTC
Sponsoring Registrar:Enom Inc. (R46-AFIN)
Registrant ID:6fe9c65a8026b401
Registrant Name:Carlos Sanchez
Registrant Organization:Rhada Administracion de datos
Registrant Street1:Calle Diluvio #2189
Registrant Street2:Seccion Dorado
Registrant Street3:
Registrant City:Playas de Tijuana
Registrant State/Province:Tijuana Baja California
Registrant Postal Code:22505
Registrant Country:MX
Registrant Phone:+52.1664596
Registrant Email: abuse@corndogschangedmylife.com
click.theknye.in – Psychic Readings. Unsolicited spam sent from Zaire
Domain ID:D6402958-AFIN
Domain Name:THEKNYE.IN
Created On:23-May-2012 19:12:38 UTC
Sponsoring Registrar:Enom Inc. (R46-AFIN)
Registrant ID:6fe9c65a8026b401
Registrant Name:Carlos Sanchez
Registrant Organization:Rhada Administracion de datos
Registrant Street1:Calle Diluvio #2189
Registrant Street2:Seccion Dorado
Registrant Street3:
Registrant City:Playas de Tijuana
Registrant State/Province:Tijuana Baja California
Registrant Postal Code:22505
Registrant Country:MX
Registrant Phone:+52.1664596
Registrant Email: abuse@corndogschangedmylife.com
click.mattjamms.in – Credit score OK. Unsolicited spam sent from Zaire
Domain ID:D6402764-AFIN
Domain Name:MATTJAMMS.IN
Created On:23-May-2012 18:53:29 UTC
Sponsoring Registrar:Enom Inc. (R46-AFIN)
Registrant ID:6fe9c65a8026b401
Registrant Name:Carlos Sanchez
Registrant Organization:Rhada Administracion de datos
Registrant Street1:Calle Diluvio #2189
Registrant Street2:Seccion Dorado
Registrant Street3:
Registrant City:Playas de Tijuana
Registrant State/Province:Tijuana Baja California
Registrant Postal Code:22505
Registrant Country:MX
Registrant Phone:+52.1664596
Registrant Email: abuse@corndogschangedmylife.com
click.thetudios.in Rent to Own. Unsolicited spam from Tijuana
Domain Name: THETUDIOS.IN
Created On:23-May-2012 19:14:31 UTC
Sponsoring Registrar:Enom Inc. (R46-AFIN)
Registrant ID:6fe9c65a8026b401
Registrant Name:Carlos Sanchez
Registrant Organization:Rhada Administracion de datos
Registrant Street1:Calle Diluvio #2189
Registrant Street2:Seccion Dorado
Registrant Street3:
Registrant City:Playas de Tijuana
Registrant State/Province:Tijuana Baja California
Registrant Postal Code:22505
Registrant Country:MX
Registrant Phone:+52.1664596
Registrant Email: abuse@corndogschangedmylife.com
click.justyeqy.in - $2500 cash loan now bad or no credit ok. Unsolicited spam from Tijuana
Domain Name:JUSTYEQY.IN
Created On:23-May-2012 19:14:31 UTC
Sponsoring Registrar:Enom Inc. (R46-AFIN)
Registrant ID:6fe9c65a8026b401
Registrant Name:Carlos Sanchez
Registrant Organization:Rhada Administracion de datos
Registrant Street1:Calle Diluvio #2189
Registrant Street2:Seccion Dorado
Registrant Street3:
Registrant City:Playas de Tijuana
Registrant State/Province:Tijuana Baja California
Registrant Postal Code:22505
Registrant Country:MX
Registrant Phone:+52.1664596
Registrant Email: abuse@corndogschangedmylife.com
click.superyskcsite.in -- $1000 cash loan “Last Chance, we are waiting to deposit $1000 into your account.” 3rd Unsolicited spam from Tijuana
click.superyskcsite.in -- $1000 cash loan “Last Chance, we are waiting to deposit $1000 into your account.” 2nd Unsolicited spam from Tijuana
click.superyskcsite.in -- $1000 cash loan “Last Chance, we are waiting to deposit $1000 into your account.” Unsolicited spam from Tijuana
Domain Name:SUPERYSKCSITE.IN
Created On:23-May-2012 19:04:26 UTC
Sponsoring Registrar:Enom Inc. (R46-AFIN)
Registrant ID:6fe9c65a8026b401
Registrant Name:Carlos Sanchez
Registrant Organization:Rhada Administracion de datos
Registrant Street1:Calle Diluvio #2189
Registrant Street2:Seccion Dorado
Registrant Street3:
Registrant City:Playas de Tijuana
Registrant State/Province:Tijuana Baja California
Registrant Postal Code:22505
Registrant Country:MX
Registrant Phone:+52.1664596
Registrant Email: abuse@corndogschangedmylife.com
TrojanDownloader:Win32/Small.AHY connects to this, or 2 other websites, to check for an active internet connection when executed.
After that, TrojanDownloader:Win32/Small.AHY connects to another chinese site to download malware to the infected computer.
A source of spam and spam mail drop links. This domain is run by the notorious netease.com, which owns more than a few spam sites or sites that operate as spam mail drop boxes.