Sunday, February 12, 2006

Don't ever fly to China - The latest on Chinese spam

In my quest to figure out how and where and why all the spam I get is from China, I ended up with something quite scary. I got a new spam email, actually two of them, pointing me to the same web site for refinancing my mortgage. A lookup on that website pointed me to the following IP number: 211.155.31.249

Here is the fun part... Normally a search on APNIC ends up pointing to some Chinese ISP through which spammers operate. But this time the story is different. The APNIC search shows that 211.155.31.249 / =<<.refi456yourhome.com">http://>=<<.refi456yourhome.com is hosted at Baiyun Airport Guangzhou China. An airport? and the description for this listing is: Airtraffic Control Bureau. WTF? Chinese airport traffic controllers are now hosting web sites that are looking to help me refinance my mortgage? And they get my business by sending spam? LOL.... this is hilarious. Chairman Mao in his grave or whatever must be one happy man. China is finally making it big and sticking it to the capitalist world.

Having said that, I suggest you rethink flying to China ;-)

Also, as a followup. Of all my gmail addresses the only one that gets spam is the one I use solely for reporting spam to the Chinese network administrators. This email address has not been used for any other purpose. Thereby implying that the Chinese are not innocent victims of some larger scam behind the spam but infact are the primary perpetrators of the crime.

Chairman Mao must be happy in his grave for his nation is sticking it to the capitalists.... LOL. Good job China, you have mastered sending man to space and sending spam, all from one PC ;-)

Given how easily Google bent over and handed its arse to the Chinese, I wonder if Google will report my identity to them. After all I doubt Mao's croonies (even though its generations later) are liking what I am writing. But then again, I doubt anyone reads this blog....

And just in case anyone is reading this blog, I would like to reiterate, neither I nor my writing in this blog is pointed at the Chinese people. Its only the Chinese government that is pissing me off right now :-)

Here is the APNIC listing:

inetnum: 211.155.31.0 - 211.155.31.255
netname: Lantian
country: CN
descr: Airtraffic Control Bureau
admin-c: YK5-AP
tech-c: YK5-AP
status: ASSIGNED NON-PORTABLE
changed: liucheng@gzidc.com 20050225
mnt-by: MAINT-CN-XYD
source: APNIC
person: yongheng Kuang
nic-hdl: YK5-AP
e-mail: spam@gzidc.com
address: Baiyun Airport Guangzhou China
phone: +86-20-86122080
fax-no: +86-20-8612203
country: CN
changed: liucheng@gzidc.com 20050224
mnt-by: MAINT-CN-XYD
source: APNIC
inetnum: 211.155.31.0 - 211.155.31.255
netname: Lantian
country: CN
descr: Airtraffic Control Bureau
admin-c: YK5-CN
tech-c: YK5-CN
status: ASSIGNED NON-PORTABLE
changed: liucheng@gzidc.com 20050225
mnt-by: MAINT-CN-XYD
source: CNNIC
person: yongheng Kuang
nic-hdl: YK5-CN
e-mail: spam@gzidc.com
address: Baiyun Airport Guangzhou China
phone: +86-20-86122080
fax-no: +86-20-8612203
country: CN
changed: liucheng@gzidc.com 20050224
mnt-by: MAINT-CN-XYD
source: CNNIC

Wednesday, February 01, 2006

More on my experience with China spam

First of all, I would like to say these posts are not about China the country as much as they are about spam. I get a lot of spam and off late I have decided to try and track down the source. As mentioned in my previous post, it doesn't matter where the email is coming from. What is important is where the email is trying to send me. The destination is the creator of the spam, not the source.

Keeping that strategy in mind I started doing a Domain name lookup for each web site that the spam emails try to send me to. White the site names change for each email, the IP numbers behind those sites remain the same. I use APNIC whois to determine who owns or manges these IP numbers. And the answer is alswyas one of about 3 networks in China.

I have sent various emails reporting the spam. Sometimes the spam stops, then starts again but with a new IP number, which of course again comes from these networks in China. I am not certain as to how the spammers are setup, but I intend to find out.

So for example today I received 14 spam emails asking me to visit various web sites. The table below is a sample of my investigation on 4 of those. I investigated all 14, just keeping this post short by listing a subset.

Date Spam ID IP Network Email Country
2/1/2006 1 221.4.152.197 China Network Communications Group Corporation abuse@cnc-oc.net China
2/1/2006 1 211.144.147.200 Beijing Xiao Xiang Commerce Co.,Ltd abuse@srit.com.cn China
2/1/2006 2 211.144.147.200 Beijing Xiao Xiang Commerce Co.,Ltd abuse@srit.com.cn China
2/1/2006 2 221.4.152.197 China Network Communications Group Corporation abuse@cnc-noc.net China
2/1/2006 3 211.144.147.200 Beijing Xiao Xiang Commerce Co.,Ltd abuse@srit.com.cn China
2/1/2006 3 221.4.152.197 China Network Communications Group Corporation abuse@cnc-noc.net China
2/1/2006 4 211.144.147.200 Beijing Xiao Xiang Commerce Co.,Ltd abuse@srit.com.cn China
2/1/2006 4 221.4.152.197 China Network Communications Group Corporation abuse@cnc-noc.net China

Interesting pattern ins't it? Well I intend to monitora report these for a while. Will post an update as and when I collect more information.
Free Website Counters
Free Website Counters