I’ve been tracking certain comment spams that had …interesting contents.
The first I was aware of advertized e-mail lists for “email marketing”. The payoff in the spam was an e-mail address, but I also found a website address. On that website, spam hosting is especially mentioned. There’s a debate raging on a Russian forum about his services. How long the site will last etc.
Today I found two messages from the same outfit. This time selling skimmers. Yes, I’m talking about bank card skimmers! This is clearly illegal. He’s also selling dumps and pins. I’m guessing he’s referring to card numbers with pin numbers.
As I checked the logs, I found the same IP address and user agent selling those Russian grandmother dolls. The e-mail address used in those spam comments are linked with the e-mail lists through earlier spams I found on the internet. Those are mainly written in Russian.
The name on the registration of the domains involved is:
person: Alexey A Gusarov
phone: +7 906 1373729
e-mail: rassilka2006@yahoo.co.uk
At first I was unsure if this was the person behind the spam (due to the nature of Russian domain registrations), but the e-mail address is also used in the spam runs.
He’s also implicated in ICQ spam:
Domains (if you want to run him to ground…):
modmo.ru
424000.com
interneo.ru
E-mail addresses used in the spams (some of them hidden):
klimenkov-alekse@inbox.ru
kloffert007@yahoo.co.uk
eduard-rozumov@mail.ru
interneoster@gmail.com
admin@megafona.net
ICQ: 194-8-194
He’s spamming forums, with a registered user: Interneohyk007
The Russian sites has Alexey A. Gusarov as the owner, but the non-Russian ones have different whois info, probably fake:
megafona.net
Dougherty, Kevin arnybiz@yahoo.co.uk
616 Richards Lane
Champaign, IL 61820
US
9090909099
424000.com
Haza Int
Arnold Drew
Russia
Yoshka, MR 424000
RU
Phone: 1.75784845
Fax..: none
Email: arnybiz@yahoo.co.uk