<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>webcops.net &#187; TexTAG Affiliate Spam</title>
	<atom:link href="http://www.webcops.net/tag/textag-affiliate-spam/feed" rel="self" type="application/rss+xml" />
	<link>http://www.webcops.net</link>
	<description>... to make our internet a safer place</description>
	<lastBuildDate>Sun, 09 Jan 2011 02:24:03 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Unsubscribe Experiment Part II</title>
		<link>http://www.webcops.net/unsubscribe-experiment-part-ii_70.html</link>
		<comments>http://www.webcops.net/unsubscribe-experiment-part-ii_70.html#comments</comments>
		<pubDate>Sat, 20 Jun 2009 23:24:56 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Spammers]]></category>
		<category><![CDATA[affiliate spammers]]></category>
		<category><![CDATA[Just Think Media Spam]]></category>
		<category><![CDATA[Provo Utah Spammer]]></category>
		<category><![CDATA[Red Mountain Media Spammer]]></category>
		<category><![CDATA[SPAM unsubscribe]]></category>
		<category><![CDATA[TexTAG Affiliate Spam]]></category>

		<guid isPermaLink="false">http://www.webcops.net/?p=70</guid>
		<description><![CDATA[In our FirstÂ  Unsubscribe from SPAM Experiment we were unable toÂ  stop the the SPAM flood of Degree Spam originated by Eclipse Media / Degree Spam from Education Dynamics Spammer. Let&#8217;s continue the unsubscribe experiment by identifying and tracking another spam entity. This time we have unsubscribed from entities who localize their addresses in Utah. [...]]]></description>
			<content:encoded><![CDATA[<p>In our FirstÂ  <a title="Unsubscribe from Spam Experiment" href="http://www.webcops.net/the-unsubscribe-experiment_39.html" target="_self">Unsubscribe from SPAM Experiment</a> we were unable toÂ  stop the the SPAM flood of <a title="Eclipse Media SPAM" href="http://www.webcops.net/tag/eclipsemedia-spam">Degree Spam originated by Eclipse Media</a> / <a title="Education Dynamics Spam" href="http://www.webcops.net/tag/education-dynamics-spam" target="_blank">Degree Spam from Education Dynamics</a> Spammer.</p>
<p>Let&#8217;s continue the unsubscribe experiment by identifying and tracking another spam entity.</p>
<p>This time we have unsubscribed from entities who localize their addresses in Utah.</p>
<p>First <strong>Unsubscription</strong> was from a Spammer who sent us more<strong> degree spam</strong>: this one is advertising Medical Transcriptions Degree</p>
<p>Received: from [74.55.10.100] (helo=mx1.pansound.com)<br />
by -redacted- with smtp (Exim 4.69)<br />
(envelope-from &lt;adkg@pansound.com&gt;)<br />
idÂ  -redacted-<br />
forÂ  -redacted-; Thu, 18 Jun 2009 -redacted-<br />
Received: from mx4.pansound.com ([74.55.10.98])<br />
by mx1.pansound.com (8.13.8/8.13.8) with STMP id vnjgcpre;<br />
for &lt; -redacted-&gt;; Thu, 18 Jun 2009Â  -redacted-<br />
Content-Language: en-us<br />
Message-Id: &lt; -redacted-@mx1.pansound.com&gt;</p>
<p>The spam is the typical affiliate showshoe spam that looks like this</p>
<div id="attachment_71" class="wp-caption alignnone" style="width: 298px"><img class="size-full wp-image-71" title="provo-utah-spam" src="http://www.webcops.net/wp-content/uploads/2009/06/provo-utah-spam.jpg" alt="Spam from 223 W Bulldog Blvd #551 Provo, UT 84604" width="288" height="319" /><p class="wp-caption-text">Spam from 223 W Bulldog Blvd #551 Provo, UT 84604</p></div>
<p>The intermediary domain redirected to the textag.com site with this landing link</p>
<p>forms.nextag.com/goto.jsp?url=/serv/main/buyer/education.jsp?doSearch=n&amp;tm=y&amp;search=education_text_links_95_h8a5d&amp;<strong>S=23471</strong>&amp;p=5548&amp;node4</p>
<p>We are going to assume that <strong>S=23471 in that link is the affiliate ID</strong></p>
<p>Another spam mail promoting the same Medical transcription degree</p>
<p>also redirected to NexTag and had a little different <strong>affiliate ID</strong> <strong>s=23393</strong></p>
<p>forms.nextag.com/goto.jsp?url=/serv/main/buyer/education.jsp?doSearch=n&amp;tm=y&amp;search=education_text_links_95_h8a57&amp;<strong>s=23393</strong>&amp;p=5548&amp;node4</p>
<p>The Spam looked like this</p>
<div id="attachment_79" class="wp-caption alignnone" style="width: 450px"><img class="size-full wp-image-79" title="medicaltranscriptio-spam" src="http://www.webcops.net/wp-content/uploads/2009/06/medicaltranscriptio-spam.jpg" alt="Medical Transcription Training SPAM" width="440" height="363" /><p class="wp-caption-text">Medical Transcription Training SPAM</p></div>
<div id="attachment_80" class="wp-caption alignnone" style="width: 261px"><img class="size-full wp-image-80" title="provo-unsub-image-link" src="http://www.webcops.net/wp-content/uploads/2009/06/provo-unsub-image-link.jpg" alt="Unsubcscribe Image Link" width="251" height="47" /><p class="wp-caption-text">Unsubcscribe Image Link</p></div>
<p>and this Spam was received as</p>
<p>Received: from [216.1.192.99] (helo=mx27.greatwesterninc.com)<br />
by-redacted- with smtp (Exim 4.69)<br />
(envelope-from &lt;kaylarokmh@greatwesterninc.com&gt;)<br />
id -redacted-<br />
for-redacted- ; Thu, 18 Jun 2009 -redacted-<br />
Received: from mx7.greatwesterninc.com ([216.1.192.79])<br />
by mx27.greatwesterninc.com (8.13.8/8.13.8) with STMP id -redacted- ;<br />
for &lt;-redacted- &gt;; Thu, 18 Jun 2009 -redacted-<br />
From: MedicalTranscriptionist &lt;kaylarokmh@greatwesterninc.com&gt;</p>
<p>Subject: {Definitely Spam?} Train for your medical transcription degree online.</p>
<p>As expected the domain nameÂ <a title="Spam DOmain" href="http://whois.domaintools.com/greatwesterninc.com" target="_blank"> greatwesterninc.com</a> has Canadian entiry owner admin info</p>
<p>RegistrationÂ ServiceÂ ProvidedÂ By:Â SANDECS<br />
Contact:Â +800.2952614</p>
<p>DomainÂ Name:Â GREATWESTERNINC.COM</p>
<p>Registrant:<br />
N/A<br />
SteveÂ Smith<br />
9Â JenkinsÂ Lane<br />
Ajax<br />
Ontario,L1SÂ 3N7<br />
CA<br />
Tel.Â +011.9056868831</p>
<p>CreationÂ Date:Â 25-Jun-2008<br />
ExpirationÂ Date:Â 25-Jun-2009</p>
<p>DomainÂ serversÂ inÂ listedÂ order:<br />
ns1.greatwesterninc.com<br />
ns0.greatwesterninc.com</p>
<p>AdministrativeÂ Contact:<br />
N/A<br />
SteveÂ Smith<br />
9Â JenkinsÂ Lane<br />
Ajax<br />
Ontario,L1SÂ 3N7<br />
CA<br />
Tel.Â +011.9056868831</p>
<p>and the IP address this SPAM originated and host on <a title="SPAMMER IP" href="http://www.senderbase.org/senderbase_queries/detailip?search_string=216.1.192.79" target="_blank">216.1.192.79</a> has a typical SPAM Reputation profile at SenderBase.</p>
<p>So we went to the unsubscribe link given at the domain pansound.com and unsubscribed the email address (the email address never subscribed or bought anything on line, it is a service email address given on one of our websites so it was obviously harvested by a bot) Here is the unsubscribe screen and the confirmation of the unsubscribe.</p>
<div id="attachment_72" class="wp-caption alignnone" style="width: 515px"><img class="size-full wp-image-72" title="provoutah-unsubscribe" src="http://www.webcops.net/wp-content/uploads/2009/06/provoutah-unsubscribe.jpg" alt="Unsubscribe from Spam Screen" width="505" height="250" /><p class="wp-caption-text">Unsubscribe from Spam Screen</p></div>
<div id="attachment_73" class="wp-caption alignnone" style="width: 420px"><img class="size-full wp-image-73" title="provoutah-unsubscribed" src="http://www.webcops.net/wp-content/uploads/2009/06/provoutah-unsubscribed.jpg" alt="Unsubscribed confirmation screen" width="410" height="157" /><p class="wp-caption-text">Unsubscribed confirmation screen</p></div>
<p>Some additional lookups on the identity of the spammer:</p>
<p>The address given by this spammer appears to be UPS Store drop box according to a <a title="Spam and Fraudulent credit card charges" href="http://www.dslreports.com/forum/r21987342-Adipose-RX">consumer who had a fraudulent credit card charge originating from a drop box by entity called loseweightsystems.com</a> at that location and another <a title="Rip Off Report on 223 W Bulldog Blvd  Provo, UT 84604" href="http://www.ripoffreport.com/reports/0/443/RipOff0443798.htm" target="_blank">unhappy consumer who was ripped off by Vinitti Cash Flow System</a> <a title="Rip Off Report on 223 W Bulldog Blvd  Provo, UT 84604" href="http://www.ripoffreport.com/reports/0/443/RipOff0443798.htm" target="_blank">claiming drop box</a> that location.</p>
<p>The domain used for the spam landing page and unsubscribe page has fake contact information, for example the ZIP code given by the &#8220;Owner/Admin&#8221; J0TÂ 1T0 is in Quebec, not in Manitoba.</p>
<p>RegistrationÂ ServiceÂ ProvidedÂ By:Â RIDGECRESTÂ CONSULTING<br />
Contact:Â +1.8014434741</p>
<p>DomainÂ Name:Â PANSOUND.COM</p>
<p>Registrant:<br />
N/A<br />
JimÂ KannerÂ Â Â Â Â Â Â Â (<a style="position: relative; top: -5px;" title="Search for this email address" href="http://www.domaintools.com/registrant-search/?email=c7273cd11974cac0a6f2b3dd70c9311e"><img src="http://source.domaintools.com/email.pgif?md5=c7273cd11974cac0a6f2b3dd70c9311e&amp;face=Atomic_Clock_Radio&amp;size=7&amp;color=000000&amp;bgcolor=FFFFFF&amp;face=Trebuchet&amp;size=9&amp;color=0000FF&amp;bgcolor=FFFFFF&amp;format%5B%5D=underline&amp;format%5B%5D=transparent&amp;format%5B%5D=transparent" border="0" alt="" align="middle" /></a>)<br />
2155Â 94AÂ St<br />
Waterville<br />
Manitoba,J0TÂ 1T0<br />
CA<br />
Tel.Â +1.2508887398</p>
<p>CreationÂ Date:Â 10-Jun-2009<br />
ExpirationÂ Date:Â 10-Jun-2010</p>
<p>DomainÂ serversÂ inÂ listedÂ order:<br />
ns1.pansound.com<br />
ns0.pansound.com</p>
<p>AdministrativeÂ Contact:<br />
N/A<br />
JimÂ Kanner<br />
2155Â 94AÂ St<br />
Waterville<br />
Manitoba,J0TÂ 1T0<br />
CA<br />
Tel.Â +1.2508887398</p>
<p>The IP address <a title="SPAM IP ADDRESS" href="http://www.senderbase.org/senderbase_queries/detailip?search_string=74.55.10.98" target="_blank">74.55.10.98</a> has a POOR repulation in Senderbase.</p>
<p>Â </p>
<p>This address also looks up to Red Mountain Media, which is one of the identities this hard core spammer assumes</p>
<p><a href="http://www.redmtnmedia.com/contact.html">http://www.redmtnmedia.com/contact.html</a></p>
<p>Contact Us (<span style="color: #ff0000;">the spammer contact info</span>)</p>
<p><strong>Address:</strong> Red Mountain Media, 223 W Bulldog Blvd #551, Provo, UT 84604<br />
<strong>Support:</strong> support@redmtnmedia.com<br />
<strong>Sales:</strong> sales@redmtnmedia.com</p>
<h3><em>Will a spammer who hides under fake identities, thousands of IP&#8217;s and domains, UPS drop boxes in shady neighbourhoods honor the unsubscribe request?Â  We shall report the results right here.</em></h3>
<p><span style="color: #ff0000;"><em>====================</em></span></p>
<p><span style="color: #ff0000;"><em>UPDATE 6-25-2009</em></span></p>
<p><span style="color: #ff0000;"><em>====================</em></span></p>
<p><em>Unsubscribing from Provo, UT Spammer has not worked thus far.Â Â  Spam continues to arrive to the email address that unsubscribed from this Spam,Â  see <a title="EarnMyDegree.Com spam " href="http://www.webcops.net/spam_train_for_an_in-demand_career_1839.html" target="_blank">the lastest spam sample here</a>.</em></p>
<p><span style="color: #ff0000;"><em>====================</em></span></p>
<p><span style="color: #ff0000;"><em>UPDATE 7-11-2009</em></span></p>
<p><span style="color: #ff0000;"><em>====================</em></span></p>
<p><span style="color: #ff0000;"><em><span style="color: #000000;">Spam from <a href="http://www.webcops.net/tag/provo-utah-spammer">&#8220;Provo Utah&#8221; Spammer</a> continues to hammer the email address that never subscribed and was unsubscribed from this hard core spam operation weeks ago. The unsubscribed email address continues to receive <a href="http://www.webcops.net/spam-cooking-school_7996.html">education &#8211; degree related spam &#8211; see sample here</a>, as well as the never ending barage of other related spam this Provo, Utah Snowshoe spammer hurls at American consumers by millions.</span></em></span></p>
<p><em>Thus far, based on all of our unsubscribe efforts, 0% of unsubscribe was successful.Â  The email address continues to receive spam and the amount of spam has increased.<br />
</em></p>
<p><span style="color: #ff0000;"><em><span style="color: #000000;"><br />
</span></em></span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.webcops.net/unsubscribe-experiment-part-ii_70.html/feed</wfw:commentRss>
		<slash:comments>15</slash:comments>
		</item>
	</channel>
</rss>

