• Welcome to Overclockers Forums! Join us to reply in threads, receive reduced ads, and to customize your site experience!

Shutting down a spammer & phisher. (A walkthrough)

Overclockers is supported by our readers. When you click a link to make a purchase, we may earn a commission. Learn More.

seadave77

Member
Joined
Jul 20, 2002
Location
Newnan, GA
This morning at work I recieved the following email.

To: xxx@xxx
Subject: CITIBANK Account Suspended
From: [email protected] <[email protected]>


<p>
<b>CITIBANK Update - Account Suspended !</b>
<br>
<br>
We recently have discovered that multiple computers have attempted to log into
your Citibank Online Account, and multiple password failures were presented
before the logons. We now require you to re-validate your account information to
us. <br>
If this is not completed by August 09, 2006, we will be forced to suspend your
account indefinitely, as it may have been used for fraudulent purposes. <br>
<br>
To continue please <a href="http://www.delta-the-animal-house.de/citi/">Click Here</a> or
on the link below to re-validate your account information : <br>
<br>
<a href="http://www.delta-the-animal-house.de/citi/">http://www.citibank.com/update.html/</a><br>
</p>
<p><span lang="EN-CA">Sincerely,<O:p></O:p></span></p>
<p><span lang="EN-CA">The </span><b>CITIBANK</b> <span lang="EN-CA">Team<O:p></O:p></span></p>
<p><span lang="EN-CA">Please do not reply to this e-mail. Mail sent to this
address cannot be answered. For assistance, log in to your </span><b>CITIBANK</b> <span lang="EN-CA">account and choose the "Help" link in the header of any page.<O:p></O:p></span></p>
<p>© 2006 <b>CITIBANK</b> Security Manager</p>


</body>

</html>

Somehow it got through the email filter. Normally I would delete this on the spot but this looked like a phishing site. :mad: So I clicked the link and went to the site. Sure enough it was. Time to shut them down! Basically, to shut them down you need to find out their webhost and contact their abuse department (Usually [email protected]). So step #1, find their host. Easiest way is using whois. I like whois.net. Type the domain name in and click search. Well delta-the-animal-house.de gave me a nice error.

[whois.melbourneit.com]
Invalid/Unsupported whois name check for: delta-the-animal-house.de

Honestly, I've never seen whois not give me anything. It's always givin me something. But their is more than one way to skin a cat. Time to play a little ball. Next I ping the name to get the IP address. Ping delta-the-animal-house.de however you want (I used command prompt) and it gave me the IP address of 212.227.119.101. Now we got something. Since IP addresses are assigned, we should be able to look up the ip and see who it goes to (hopefully thier webhost). For this I went to Network Solutions handy whois page. This allowed me to look up the IP address. What do you know...

WHOIS Record For
212.227.119.101
Record Type: IP Address

OrgName: RIPE Network Coordination Centre
OrgID: RIPE
Address: P.O. Box 10096
City: Amsterdam
StateProv:
PostalCode: 1001EB
Country: NL

ReferralServer: whois://whois.ripe.net:43

NetRange: 212.0.0.0 - 212.255.255.255
CIDR: 212.0.0.0/8
NetName: RIPE-NCC-212
NetHandle: NET-212-0-0-0-1
Parent:
NetType: Allocated to RIPE NCC
NameServer: NS-PRI.RIPE.NET
NameServer: NS3.NIC.FR
NameServer: SUNIC.SUNET.SE
NameServer: NS-EXT.ISC.ORG
NameServer: SEC1.APNIC.NET
NameServer: SEC3.APNIC.NET
NameServer: TINNIE.ARIN.NET
Comment: These addresses have been further assigned to users in
Comment: the RIPE NCC region. Contact information can be found in
Comment: the RIPE database at http://www.ripe.net/whois
RegDate: 1997-11-14
Updated: 2005-08-03

Well, this IP address is for another part of the world. (We know this already from the .de domain). And it kindly points us where to go. So I do. I go to the whois page at ripe.net and pop in the IP address. The results...
% This is the RIPE Whois query server #1.
% The objects are in RPSL format.
%
% Note: the default output of the RIPE Whois server
% is changed. Your tools may need to be adjusted. See
% http://www.ripe.net/db/news/abuse-proposal-20050331.html
% for more details.
%
% Rights restricted by copyright.
% See http://www.ripe.net/db/copyright.html

% Note: This output has been filtered.
% To receive output for a database update, use the "-B" flag.

% Information related to '212.227.119.0 - 212.227.119.127'

inetnum: 212.227.119.0 - 212.227.119.127
netname: SCHLUND-NET
descr: Schlund + Partner AG
country: DE
admin-c: UI-RIPE
tech-c: UI-RIPE
rev-srv: nsa.schlund.de
rev-srv: ns.schlund.de
rev-srv: ns2.schlund.de
status: ASSIGNED PA "status:" definitions
mnt-by: SCHLUND-MNT
source: RIPE # Filtered

role: Schlund NCC
address: Schlund + Partner AG
address: Brauerstrasse 48
address: D-76135 Karlsruhe
address: Germany
remarks: For abuse issues, please use only [email protected]
remarks: For NOC issues, please look at our AS 8560
phone: +49 721 91374 50
fax-no: +49 721 91374 20
e-mail: [email protected]
admin-c: SPNC-RIPE
tech-c: SPNC-RIPE
nic-hdl: UI-RIPE
mnt-by: SCHLUND-MNT
source: RIPE # Filtered

% Information related to '212.227.0.0/16AS8560'

route: 212.227.0.0/16
descr: SCHLUND-PA-2
origin: AS8560
mnt-by: SCHLUND-MNT
source: RIPE # Filtered

Now we have them. Almost. Notice the abuse@ emails. Well they go to schlund.com. If my thinking is correct. schulund.com should be a webhost probably in Europe. Just to double check lets go there. Well, I see a section for webhosting at the top and it's in a diffrent language. Success! Now I shoot off an email to them.

To: [email protected]
Subject: Fwd: CITIBANK Account Suspended


I received this spam message at work. I traced its IP address to be 212.227.119.101 which the RIPE whois pointed to you. Please take care of these people before they scam someone.

I also attached a full copy of the email I recieved. I get a response.
From: Abuse Department <[email protected]>
To: Clint <xxx@xxx>
Subject: Re: Fwd: CITIBANK Account Suspended


*******************************************************************


Dies ist eine automatisch generierte Mail. Wenn Sie diese nicht
mehr erhalten moechten, fuegen Sie im Betreff Ihrer Mails bitte
'NOREPLY' ein.

This mail has been generated automatically. In case you don't
want to receive it again, please insert 'NOREPLY' into the
subject line of your mails.


*******************************************************************


[ english version below ]


Vielen Dank fuer Ihre Mitteilung an unsere Abuse-Abteilung.


Das Versenden von unerwuenschten Mails oder eine sonstige
missbraeuchliche Verwendung unserer Systeme gegen andere
Internet-Nutzer oder -Systeme widerspricht unseren Richtlinien zur
Internet-Nutzung, welche sie ebenfalls in unseren 'Allgemeinen
Geschaeftsbedingungen' (kurz AGB) finden.


Wenn Kunden gegen unsere Richtlinien verstossen, werden wir
angemessene Schritte unternehmen, um den Missbrauch in Zukunft
auszuschliessen.


Wir koennen nicht auf jede Anfrage individuell antworten, aber seien
Sie versichert, dass wir Ihrer Beschwerde nachgehen, sofern sie
konkrete Daten enthaelt. Im Fall einer Mail-Belaestigung werden z. B.
die vollstaendigen Daten der E-Mail (inklusive aller Header-Zeilen)
benoetigt ansonsten Verbindungsdaten wie IP-Adresse und Datum/Uhrzeit,
sowie eine moeglichst vollstaendige und verstaendliche Beschreibung
Ihres Anliegens.


Sollten wir weitere Informationen zur Verfolgung des Sachverhalts
benoetigen, werden wir Sie kontaktieren. In besonders ernsten Faellen
(Betrug, Beleidigung, schwerer Datenmissbrauch, gehackte Server)
empfehlen wir Ihnen, Ihre Polizeidienststelle einzuschalten.



Mit freundlichen Gruessen


Ihre Schlund+Partner Abuse-Abteilung



[ english version ]


Thank you for contacting our abuse department.


Sending spam mails or any other abusive use of our systems against other
internet users or systems is strictly prohibited by our acceptable use
policy.


We will take appropriate actions against customers breaking these rules if
you send us the complete mail (including all header lines) in case of email
abuse or date/time and connection data like IP addresses and ports together
with a description of the abusive actions that were performed in case of
port scanning activities or similar.


This may be the last reply that you receive regarding your complaint. Please
do not, however, interpret a lack of response as a lack of action taken.
Please be assured that if we find that a customer is in violation of our
policies, that we will take the necessary action to stop the activity in
question.


On the other hand, sometimes it may be necessary that we contact you again
in order to receive more detailed information about the circumstances under
which the abusive actions that you are concerned about have taken place.



Yours sincerely,

Schlund+Partner Abuse Team

Well hey, it's a generic auto response but at least this tells me it's not forgotten about. Another response.

From: "Abuse-Department 1&1 Internet AG, MC" <[email protected]>
To: Clint <xxx@xxx>
Subject: Re: Fwd: CITIBANK Account Suspended


Dear Sir or Madam,


thank you for your notice in this matter. We disabled the phishingsite and
advised our customer to secure his webspace against further abuse.


Best Regards,
Martin Contento


--
Abusedepartment
1&1 Internet

Alright! Sure enough if I try to visit the site again I get a nast error in another language. Now I can be glad that I potentually foiled a scammer from taking advantage of someone less computer savvy than I.

This was my way of doing it, there are plenty of other ways. Maybe not the most efficient either but it worked. I hope this helps anyone that was curious about shutting down spammers and encourages people to try to shut them down. Some person somewhere is not filing a police report or arguing with their bank because of what I did. At least that's what I like to think. :D
 
You were incredibly lucky that this dumb phisher used a .de site and that the hoster was Schlund & Partner. When they use .cn, .kr, .ru or whatever as they usually do, you won't have as much success.
But still: good work.

Btw: whois worked fine for me right now:
[Admin-C]
Type: PERSON
Name: Uwe Hauser
Address: Delta Tau Chi - The Animal House
Address: Raiffeisenstr. 13
Pcode: 78166
City: Donaueschingen
Country: DE
Remarks: ACTION NEW
Remarks: ID [#7197523/6546487]
Changed: 2002-03-10T14:09:24+01:00
 
mmmm...in chains on the evening news...that's how I like my phish cooked. Tasty!

Very nice job tracking him down, but that last e-mail leads me to believe the real culprit is still out there, jacking into someone else's site tonight. :rolleyes:
 
yeah, it's a bummer. But every little bit helps. I can only go so far, someone with access to the log files will have to go the extra mile.
 
Back