I just posted the MO of two spammers. Both affiliates of topsearch10.com.
The whois info comes back to this outfit:
Dimago Overseas GmbH
Jaan Randolph (searchadv@gmail.com)
Suites 25 and 27, Second Floor,
Oliaji Trade Centre, Francis Rachel Street, P
Victoria
Mahe,120000
SC
Tel. +42.0723233092
What’s interesting here, is that this is the outfit behind other websites, with permutations of the term umax. Which usually means - Russian stuff.
And if you look at the Alexa page for the domain, it’s got Umax contact info.
And yes, if I follow the trail of domains associated with Dimago, I end up with this e-mail address:
wello@mail.ru
The address given is in Prague, but I’ve seen him posting on Russian sites like he’s living there.
And according to his ICQ page (169184030), his first name is Alexey, he speaks Russian and English and is interested in high profile sports cars. He also says he lives in the US, and was born 24-nov-1968. His nickname is unimaxxximmuuus.
I also find lists of cws infected sites, with some of his on them.
And he’s got another network, run with the name Rex Services Ltd. Also on CWS lists.
But this company has an anti parasite tool, named Security iGuard. Problem is, that TOO has landed itself on some uncool lists. Namely rogue spyware. In this case, it’s on the list because it’s often advertized through CWS sites.
I found a WIPO case for a domain that appeared to knock off MSN search. The respondent’s name was given as Serge Kovalev. He used the domain to promote Rex Service’s programs, though I can’t be sure it’s the same person, due to lack of detail in the WIPO document (ie, affiliate links or not?).
Sans reports a pharming attack in March 2005, with one of his sites as the beneficiary.
I’ll dig some more later, but I’ve got stuff to do, so posting for now.
Update July 9, 2006:
Found this:
APS Telecom APS-EPSI (NET-216-195-32-0-1)
216.195.32.0 - 216.195.63.255
Dimago Overseas GmbH NET-216-195-51-0 (NET-216-195-51-0-1)
216.195.51.0 - 216.195.51.255
Details:
CustName: Dimago Overseas GmbH
Address: Suites 25 and 27, Second Floor, Oliaji Trade Centre, Francis Rachel Street
City: Victoria
StateProv: Mahe
PostalCode: 120000
Country: SC
RegDate: 2005-05-04
Updated: 2005-05-04
abuse is at 0ad.net
What this means, is that the Dimago overseas whois info we’ve been seeing, might be whois protection from the sub-netblock owner.