Zahariev’s latest project
I found a referrer in my log for a domain I hadn’t seen before:
tammynishijima
Right now it’s connected to the oingo parked domain program. And it’s owned by Kalin Stamenov, with Todor’s e-mail address attached. But that was the last thing I checked.
When I saw the IP number it was spamvertized from, I had this uh oh feeling. I guess my subconscious is better at this than my conscious:
82.103.65.225
inetnum: 82.103.65.224 - 82.103.65.239
netname: ZAHARIEV-BG
descr: Todor Zahariev
country: BG
admin-c: TZ32-RIPE
tech-c: TZ32-RIPE
tech-c: TD939-RIPE
rev-srv: ns.spnet.net
rev-srv: purgatory.spnet.net
status: ASSIGNED PA
mnt-by: SPNET-MNT
source: RIPE # Filtered
person: Todor Zahariev
address: Sofia, Bulgaria
phone: +359 2
e-mail: todor@twins-bg.com
nic-hdl: TZ32-RIPE
source: RIPE # Filtered
person: Tatiana Dimitrova
address: Spectrum Net
address: 36, G.M.Dimitrov blvd.
address: BG 1797 Sofia
address: Bulgaria
phone: +359 2 9867481
fax-no: +359 2 9657646
e-mail: taniad@spnet.net
nic-hdl: TD939-RIPE
mnt-by: SPNET-MNT
source: RIPE # Filtered
% Information related to ‘82.103.64.0/18AS8717′
route: 82.103.64.0/18
descr: Spectrum NET PA space
origin: AS8717
mnt-by: SPNET-MNT
source: RIPE # Filtered
I found a number of accesses from that IP number, starting from May 13. Not spam, but clearly a bot. Then yesterday there was a fake Google referrer, and the user agent changed to:
MSIE 5.0
And there are no identifying marks at all on the headers.
Block the IP number.
May 30th, 2005 at 7:21 am
It’s nailing me too. I’ve taken action - you want the grepped traffic from my logs?
May 30th, 2005 at 10:58 am
Yes and no. By now he’s so advanced, log info alone isn’t enough. Now it’s down to http headers.
I do however want a running commentary on the latest domain names he’s peddling. How about I set up a wiki page that can be updated by the readers?