tech support 9

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Tuesday, 30 April 2013

"Your Wire Transfer 82932922 canceled" spam / Payment reeceipt.exe / 78.139.187.6

Posted on 14:23 by Unknown


This fake wire transfer spam comes with a malicious attachment:


Date:      Tue, 30 Apr 2013 15:27:44 -0500 [16:27:44 EDT]
From:      Federal Reserve [alerts@federalreserve.gov]
Subject:      Your Wire Transfer 82932922 canceled

The Wire transfer , recently sent from your bank account , was not processed by the FedWire.
Transfer details attached to the letter.
This service is provided to you
Read More
Posted in EXE-in-ZIP, Malware, Spam, Viruses | No comments

Something evil on 96.126.108.132

Posted on 11:22 by Unknown


These sites are on (or are likely to be created on) 96.126.108.132 (Linode, US) which is a known malware server [1] [2] [3]. Blocking this IP would be wise. Some of the domains are rather.. unusual ;)

0-0-0-0-0-0-0-0-0-0-0-0-0-1-0-0-0-0-0-0-0-0-0-0-0-0-0.info0-0-0-0-0-0-0-0-0-0-0-0-0-10-0-0-0-0-0-0-0-0-0-0-0-0-0.info0-0-0-0-0-0-0-0-0-0-0-0-0-11-0-0-0-0-0-0-0-0-0-0-0-0-0.
Read More
Posted in Evil Network, Linode, Malware, Viruses | No comments

Monday, 29 April 2013

"Requested Reset of Yoyr PayPal Password" spam / frustrationpostcards.biz

Posted on 15:07 by Unknown


This fake PayPal spam leads to malware on frustrationpostcards.biz:


 Date:      Mon, 29 Apr 2013 13:22:03 -0500From:      "service@paypalmail.com" [chichisaq0@emlreq.paypalmail.com]Subject:      Requested Reset of Yoyr PayPal Password   Your account will stay on hold untill password reset.How to reset your PayPal passwordHello [redacted],To get back into your PayPal account, you'll have to
Read More
Posted in Amerika, Greece, Malware, PayPal, Spam, Sweden, Viruses | No comments

Saturday, 27 April 2013

Is CB3ROB a champion of free speech? Or a spammer?

Posted on 08:58 by Unknown


The alleged arrest of Sven Olaf Kamphuis (aka CB3ROB) of CyberBunker and the eponymous CB3ROB Ltd has thrown Anonymous into a tizzy, with a #freecb3rob campaign running on Twitter.

The arrest was made because of a suspicion that Kamphius might be behind a massive DDoS attack on Spamhaus that also impacted Cloudflare. I don't have any evidence that CB3ROB or any of his business associates are
Read More
Posted in CyberBunker, Spam | No comments

Friday, 26 April 2013

Something evil on 199.71.212.122

Posted on 06:29 by Unknown


199.71.212.122 is an IP address belonging to Psychz Networks in the US. It hosts a number of sites with malware one them according to VirusTotal and URLquery. Some of the malicious domains were recently hosted on this IP.

I suspect that there are lot more domains than the ones listed on this server, blocking access to it is probably the best approach. Sites flagged by Google as malicious are
Read More
Posted in Evil Network, Malware, Viruses | No comments

Something evil on 193.107.16.213 / Ideal Solution Ltd

Posted on 05:48 by Unknown


193.107.16.213 is a web server run by Ideal Solution Ltd in the Seychelles. It contains many malware sites that should be blocked, and you might well want to consider blocking the entire 193.107.16.0/22 (193.107.16.0 - 193.107.19.255) range.

VirusTotal detects a number of malicious sites on this server (see report) but blocking access to this IP address is probably the easiest approach.
Read More
Posted in Evil Network, Malware, Viruses | No comments

"USPS delivery failure report" spam / LABEL-ID-56723547-GFK72.zip

Posted on 02:19 by Unknown


This fake USPS message has a malicious attachment:


Date:      Fri, 26 Apr 2013 12:46:25 +0400 [04:46:25 EDT]
From:      USPS client manager Lelia Holden [reports@usps.com]
Subject:      USPS delivery failure report
Priority:      High Priority 1

Notification

Our company’s courier couldn’t make the delivery of package.

REASON: Postal code contains an error.
LOCATION OF YOUR PARCEL: New York
Read More
Posted in EXE-in-ZIP, Malware, Spam, USPS, Viruses | No comments

Thursday, 25 April 2013

RU:8080 timeline

Posted on 06:45 by Unknown





A quick bit of research for anyone following the RU:8080 gang.. where has the spam gone? Recently we've seen RU:8080 spam every weekday for some time, and there hasn't been anything since 19th April (nearly a week ago).

The current RU:8080 runs started in February 2012 (although there had been similar malware spam URLs before that). A timeline of the dates of the runs I spotted can be found
Read More
Posted in RU:8080, Russia, Spam | No comments

The "Signature Strengths" (behaviourlibrary.com) fiasco

Posted on 04:30 by Unknown


A post over at the Sqwawkbox Blog highlights the absurdity of an online behavioural survey site called "Signature Strengths" that jobseekers are "encouraged" to use. It makes the claim that no matter what you enter, it always comes up with some positive reason why you should be working. OK.. perhaps that isn't a bad thing, but it is clearly pretty absurd.

Try it for yourself by taking the test
Read More
Posted in Stupidity | No comments

"Organ donation" spam

Posted on 01:16 by Unknown


This isn't the first time that I've seen this spam...


From: timur146@mail.ruDate: 25 April 2013 02:26Subject: Organ donation.Hello.My name is Alex and I'm from Ukraine. I found your address on medical website.I want to be a living donor. I am ready to give one of my kidneys or part of my liver, but I want to receive a big compensation for that.If you need kidney or liver transplant contact me
Read More
Posted in Spam, Ukraine | No comments

Wednesday, 24 April 2013

"New Secure Message" spam / pricesgettos.info

Posted on 14:21 by Unknown


This spam leads to malware on pricesgettos.info:


Date:      Wed, 24 Apr 2013 16:41:50 +0100 [11:41:50 EDT]From:      Cooper.Anderson@csiweb.comSubject:      New Secure Message Received from Cooper.Anderson@csiweb.comNew Secure MessageRespective [redacted],You have received a new secure message from Cooper.Anderson@csiweb.com.If you are using the Secure Message Plugin in Lotus Notes this
Read More
Posted in Amerika, Korea, Malware, South Africa, Spam, Sweden, Viruses | No comments

American Express spam / SecureMail.zip

Posted on 14:04 by Unknown




Something bad happened to this spam on the way out from wherever spam emerges from. Still, it contains a malicious attachment which should be avoided.


Date:      Wed, 24 Apr 2013 12:59:38 -0500 [13:59:38 EDT]
From:      American Express [Christian_Frey@aexp.com]
Subject:      Confidential - Secure Message from AMEX

                            Secure Message
Read More
Posted in EXE-in-ZIP, Malware, Spam, Viruses | No comments

Need a new PDP-11 or VAX?

Posted on 04:30 by Unknown


As a former VAX 11/750 admin it give me a little warm glow to discover that there's still a company out there making PDP-11 and VAX compatible systems, only with more modern components in a unit that you can fit in a rack rather than a whole room.

These systems are really aimed at military and government customers who can't migrate mission critical systems (often literally mission critical) to
Read More
Posted in Retro | No comments

Something evil on 151.248.123.170

Posted on 03:34 by Unknown


151.248.123.170 (Reg.Ru, Russia) is currently hosting a number of malicious sites being used in injection attacks (example 1, example 2). These domains appear to be almost all dynamic DNS domains which I would recommend blocking, I also recommend blocking the IP address. Trying to block individual domains would probably be ineffective.

Recommended blocklist:
151.248.123.170
ns3.
Read More
Posted in Dynamic DNS, Injection Attacks, Russia | No comments

Tuesday, 23 April 2013

"CareerBuilder Notification" spam / CB_Offer_04232013_8817391.zip

Posted on 15:01 by Unknown


This fake CareerBuilder email has a malicious attachment containing malware.


Date:      Tue, 23 Apr 2013 11:13:54 -0700 [14:13:54 EDT]
From:      CareerBuilder [Herman_Gallagher@careerbuilder.com]
Subject:      CareerBuilder Notification

Hello,

I am a customer service employee at CareerBuilder. I found a vacant position that you may be interested in based on information from your resume or
Read More
Posted in EXE-in-ZIP, Malware, Spam, Viruses | No comments

Something evil on 173.246.104.104

Posted on 08:33 by Unknown


173.246.104.104 (Gandi, US) popped up on my radar after a malvertising attack apparently utilising a hacked OpenX server (I'm not 100% which one so I won't name names) and leading to a payload on [donotclick]laserlipoplasticsurgeon.com/news/pint_excluded.php (report here).

Both VirusTotal and  URLquery detect multiple malicious domains on this IP. It appears that the domains were originally
Read More
Posted in Blackhole, Gandi, Malware, Spam, Viruses | No comments

DHL Spam / DHL-LABEL-ID-2456-8344-5362-5466.zip

Posted on 02:24 by Unknown


This fake DHL spam has a malicious attachment.


Date:      Tue, 23 Apr 2013 12:21:40 +0800 [00:21:40 EDT]
From:      Ramon Brewer - DHL regional manager [reports@dhl.com]
Subject:      DHL DELIVERY REPORT NY73377
   
Web Version  |  Update preferences  |  Unsubscribe
       
DHL notification

Our company’s courier couldn’t make the delivery of parcel.

REASON: Postal code contains an error.
Read More
Posted in DHL, EXE-in-ZIP, Malware, Spam, Viruses | No comments

Monday, 22 April 2013

"Loss Avoidance Alerts" spam / tempandhost.com

Posted on 15:00 by Unknown


I haven't seen this particular spam before. It leads to malware on tempandhost.com:


Date:      Tue, 23 Apr 2013 05:41:32 +0900 [16:41:32 EDT]
From:      personableop641@swacha.org
Subject:      4/22/13 The Loss Avoidance Alerts that you requested are now available on the internet

Loss Avoidance Alert System

April 22, 2013
  
Loss Avoidance Report:
The Loss Avoidance Alerts that was
Read More
Posted in Amerika, Blackhole, Korea, Malware, South Africa, Spam, Viruses | No comments

Malware sites to block 22/4/13

Posted on 08:40 by Unknown


These domains form part of a large Kelihos botnet described over at Malware Must Die and which is related to the recent Boston Marathon and Texas Fertilizer Plant spam runs. There are probably thousands of IP addresses, but so far I have identified just 76 domains that seem to be active (there are a large number of subdomains). Monitoring for these may reveal Kelihos activity on your network.

Read More
Posted in Botnet, Evil Network, Kelihos, Malware | No comments

Friday, 19 April 2013

OVH WTF

Posted on 14:24 by Unknown


If you work in the anti-spam or anti-malware business then you've probably come across OVH. It's a company with a shockingly bad reputation in these fields, tolerating malware and spammers to an extent that no other major host does. It even has a special tag in this blog to keep track of all the crap it hosts.

One particularly bad part of the network is the "MMuskatov" block 5.135.67.128/25 (
Read More
Posted in Evil Network, OVH | No comments

American Express spam / CD0199381.434469398992.zip

Posted on 07:36 by Unknown


This fake American Express spam comes with a malicious attachment:


Date:      Fri, 19 Apr 2013 08:29:52 -0500 [09:29:52 EDT]
From:      "PAYVESUPPORT@AEXP.COM" [PAYVESUPPORT@AEXP.COM]
Subject:      PAYVE - Remit file
Part(s):        2      CD0199381.434469398992.zip      [application/zip]

A payment(s) to your company has been processed through the American Express Payment
Network.
The
Read More
Posted in EXE-in-ZIP, Malware, Spam, Turkey, Viruses | No comments

Squeaky Data / squeakydata.co.uk spam

Posted on 02:01 by Unknown


This spam selling dodgy mailing lists originates from Sally Gaskell in Sheffield.


From:     Squeaky Data [data@squeakydata.co.uk] via smtpguru.net
Date:     19 April 2013 05:12
Subject:     Squeaky Data - Qualified Prospects
Signed by:     smtpguru.net

Squeaky Data - Qualified & Opted In Prospect Data

We own the data we sell so we can keep our prices extremely competitive but still deliver
Read More
Posted in Sally Gaskell, Spam | No comments

Thursday, 18 April 2013

"Fertilizer Plant Explosion Near Waco, Texas" spam

Posted on 04:46 by Unknown
As I suspected, this didn't take long. This spam is a retread of yesterday's Boston Marathon spam.


From: Maria Numbers [mailto:tjm7@deco-club.ru]
Sent: 18 April 2013 11:51
To: UK HPEA 3
Subject: CAUGHT ON CAMERA: Fertilizer Plant Explosion Near Waco, Texas

hxxp:||83.170.192.154/news.html
At the moment the payload site is [donotclick]bigmovies777.sweans.org/aoiq.html (report here but site
Read More
Posted in Malware, Spam, Viruses | No comments

Malware sites to block 18/4/13, revisited

Posted on 01:47 by Unknown


Quite late last night I posted some malicious IP address that I recommend blocking. I've had a chance to look at these more deeply, and some of them are in known bad IP ranges that you should consider blocking.

Most of these IP ranges are in Russia, blocking them will probably block some legitimate sites. If you don't do much business with Russia then it will probably not be an issue, if you
Read More
Posted in Hetzner, Latvia, logol.ru, Malware, OVH, Russia, Sidharth Shah, Simply Transit, TheFirst-RU, Ukraine, Viruses | No comments

West, Texas explosion: be on the lookout for malware spam

Posted on 00:24 by Unknown
It took just a day or so for the bad guys to start sending out malware spam about the Boston Marathon, I strongly suspect that we will see the same for the West, Texas explosion within the next 48 hours or so. It's probably worth keeping an eye out for any such spam coming into your organisation and taking the appropriate countermeasures.

Incidentally, the following is the only actual video I
Read More
Posted in Spam | No comments

Wednesday, 17 April 2013

Malware sites to block 18/4/13

Posted on 16:06 by Unknown


These malicious domains and IPs are associated with this malware spam run. Block 'em if you can.

Read More
Posted in Evil Network, Malware, Spam, Viruses | No comments

PayPal spam / dialupwily.org

Posted on 15:15 by Unknown


This fake PayPal spam leads to malware on dialupwily.org:


From: service@paypal.com [mailto:criticizea@seneseassociates.com]Sent: Wed 17/04/2013 18:49Subject: Receipt for your PayPal payment to Konrad RotuskiFeb 18, 2013 10:54:32 PDTTransaction ID: 4F1UGYHLFMRAG1AVY Hello,You sent a payment of $149.49 USD to Konrad Rotuski (criticizea@seneseassociates.com)Thanks for using PayPal. To see all
Read More
Posted in Amerika, Malware, PayPal, Spam, Viruses | No comments

CNN.com Boston Marathon spam / thesecondincomee.com

Posted on 11:52 by Unknown


This Boston Marathon themed spam leads to malware on thesecondincomee.com:

Example 1:


Date:      Wed, 17 Apr 2013 10:32:18 -0600 [12:32:18 EDT]
From:      CNN Breaking News [BreakingNews@mail.cnn.com]
Subject:      Opinion: Boston Marathon Explosions - Obama Benefits? - CNN.com   
     
CNN.com    
Powered by    
* Please note, the sender's email address has not been verified.
Read More
Posted in Amerika, CNN, GHOSTnet, Malware, Spam, Viruses | No comments

BBB Spam / freedblacks.net

Posted on 07:00 by Unknown


Another BBB spam run today, although this time not an RU:8080 spam we saw earlier but an "Amerika" spam run instead. Interestingly, both mis-spell "Beareau" which indicates they are using the same software, even if they are different gangs. The link in the email leads to malware on freedblacks.net.


Date:      Wed, 17 Apr 2013 21:20:20 +0800 [09:20:20 EDT]
From:      BBB [bridegroomc@m.bbb.org
Read More
Posted in BBB, Germany, GHOSTnet, Malware, South Africa, Spam, Viruses | No comments

BBB Spam / janariamko.ru

Posted on 06:11 by Unknown


After a few quiet days on the RU:8080 spam front it has started again..


Date:      Wed, 17 Apr 2013 20:18:14 +0800From:      "Better Business Bureau" [guttersnipeg792@ema1lsv100249121.bbb.org]Subject:      Better Business Beareau accreditation Terminated 64A488W04    Case N. 64A488W04Respective Owner/Responsive Person:The Better Business Bureau has been filed the above said reclamation from
Read More
Posted in BBB, Canada, Malware, RU:8080, Spam, Turkey, Viruses | No comments

"Boston Marathon" spam / askmeaboutcctv.com

Posted on 02:20 by Unknown


This pretty shameful Boston marathon themed spam leads to malware on askmeaboutcctv.com:

Sample 1:


From: Graham Jarvis [mailto:alejandro.alfonzo-larrain@tctwest.net]
Sent: 17 April 2013 09:49
Subject: Video of Explosion at the Boston Marathon 2013

hxxp:||61.63.123.44/news.html
Sample 2:


From: Sally Rasmussen [mailto:artek33@risd.edu]
Sent: 17 April 2013 09:49
To: UK HPEA 2
Subject:
Read More
Posted in Malware, Spam, Viruses | No comments

Tuesday, 16 April 2013

Disgraceful Arif Khan / Mak Media spam

Posted on 14:04 by Unknown


For some time now I've been plagued with spam that looks like this:


Date:      Tue, 16 Apr 2013 09:11:37 -0400From:      "Mesothelioma" To:      [redacted]Subject:      Learn The Link Between Asbestos and Mesothelioma5670242064119134040....02158166418942886316dc91aae549f7.02158166418942886316dc91aae549f7.5670242064119134040..02158166418942886316dc91aae549f7.. 33100457.5670242064119134040..
Read More
Posted in India, Spam | No comments

"Fiserv Secure Email Notification" spam

Posted on 07:33 by Unknown


This spam has an encrypted ZIP file attached that contains malware. The passwords and filenames will vary.



From: Fiserv Secure Notification [mailto:secure.notification@fiserv.com]
Sent: Tue 16/04/2013 14:02
Subject: [WARNING : MESSAGE ENCRYPTED] Fiserv Secure Email Notification - CC3DK9WJW8IG0F5


You have received a secure message

Read your secure message by opening the attachment,
Read More
Posted in 1&1, EXE-in-ZIP, Germany, India, Linode, Malware, Spam, Turkey, Viruses, Zbot | No comments

Friday, 12 April 2013

MS13-036 buggy, withdrawn

Posted on 01:48 by Unknown


Uh-oh.. looks like the reports of problems with MS13-036 were correct.



Newer Posts Older Posts Home
Subscribe to: Posts (Atom)

Popular Posts

Categories

  • .SU
  • 1&1
  • 419
  • ADP
  • Advanced Fee Fraud
  • Advertising
  • Adware
  • AICPA
  • Amazon
  • Amerika
  • Android
  • Anti-Virus Software
  • AOL
  • Apple
  • Aruba
  • Australia
  • Austria
  • BBB
  • Black Hat
  • Blackhole
  • Blogging
  • Botnet
  • Brazil
  • Bulgaria
  • Canada
  • Chile
  • China
  • CNN
  • Colombia
  • CookieBomb
  • Crime
  • CyberBunker
  • Data Breach
  • DHL
  • DOC
  • Domains
  • Dynamic DNS
  • eBay
  • Edis
  • eFax
  • Egypt
  • Emailmovers Ltd
  • Endurance International Group
  • Estonia
  • Evil Network
  • EXE-in-ZIP
  • Facebook
  • Fail
  • Fake Pharma
  • False Positive
  • FedEx
  • Finland
  • France
  • Gandi
  • Germany
  • GHOSTnet
  • GoDaddy
  • Google
  • Greece
  • Hacked sites
  • Hetzner
  • HMRC
  • Hosting
  • Hungary
  • India
  • Injection Attacks
  • Intergenia
  • INTUIT
  • Iran
  • IRS
  • Israel
  • Italy
  • Japan
  • Job Offer Scams
  • Joe Job
  • Jolly Works Hosting
  • Kelihos
  • Kenya
  • Korea
  • Latvia
  • Law
  • Leaseweb
  • LinkedIn
  • Linode
  • Lithuania
  • Lithunia
  • logol.ru
  • Macintosh
  • Magnitude
  • Malware
  • Mea Culpa
  • Microsoft
  • Moldova
  • Money Mule
  • Mongolia
  • NACHA
  • NATO
  • Netherlands
  • Neutrino
  • Nuclear Fallout Enterprises
  • OVH
  • Pakistan
  • Patches
  • PayPal
  • Philippines
  • Phishing
  • Phishtank
  • Phones
  • Pinterest
  • Pizza
  • Poland
  • Politics
  • Porn
  • PPI
  • Printer Spam
  • Privacy
  • Pump and Dump
  • Retro
  • Romania
  • RU:8080
  • Russia
  • Sally Gaskell
  • Scam
  • Scams
  • Senegal
  • Serbia
  • Serverius
  • Sidharth Shah
  • Simply Transit
  • Singapore
  • Slicehost
  • SMS
  • South Africa
  • Spain
  • Spam
  • Stupidity
  • Sweden
  • Sweet Orange
  • Switzerland
  • Syria
  • Taiwan
  • Telepests
  • Thailand
  • TheFirst-RU
  • ThreeScripts
  • Tor
  • Turkey
  • UAE
  • UK2.NET
  • Ukraine
  • UPS
  • US Airways
  • USPS
  • VBScript
  • Virgin Media
  • Viruses
  • Waledac
  • Weather
  • Xeex
  • Yahoo
  • YouTube
  • Zbot
  • Zeus

Blog Archive

  • ▼  2013 (500)
    • ►  November (29)
    • ►  October (37)
    • ►  September (46)
    • ►  August (44)
    • ►  July (62)
    • ►  June (42)
    • ►  May (39)
    • ▼  April (67)
      • "Your Wire Transfer 82932922 canceled" spam / Paym...
      • Something evil on 96.126.108.132
      • "Requested Reset of Yoyr PayPal Password" spam / f...
      • Is CB3ROB a champion of free speech? Or a spammer?
      • Something evil on 199.71.212.122
      • Something evil on 193.107.16.213 / Ideal Solution Ltd
      • "USPS delivery failure report" spam / LABEL-ID-567...
      • RU:8080 timeline
      • The "Signature Strengths" (behaviourlibrary.com) f...
      • "Organ donation" spam
      • "New Secure Message" spam / pricesgettos.info
      • American Express spam / SecureMail.zip
      • Need a new PDP-11 or VAX?
      • Something evil on 151.248.123.170
      • "CareerBuilder Notification" spam / CB_Offer_04232...
      • Something evil on 173.246.104.104
      • DHL Spam / DHL-LABEL-ID-2456-8344-5362-5466.zip
      • "Loss Avoidance Alerts" spam / tempandhost.com
      • Malware sites to block 22/4/13
      • OVH WTF
      • American Express spam / CD0199381.434469398992.zip
      • Squeaky Data / squeakydata.co.uk spam
      • "Fertilizer Plant Explosion Near Waco, Texas" spam
      • Malware sites to block 18/4/13, revisited
      • West, Texas explosion: be on the lookout for malwa...
      • Malware sites to block 18/4/13
      • PayPal spam / dialupwily.org
      • CNN.com Boston Marathon spam / thesecondincomee.com
      • BBB Spam / freedblacks.net
      • BBB Spam / janariamko.ru
      • "Boston Marathon" spam / askmeaboutcctv.com
      • Disgraceful Arif Khan / Mak Media spam
      • "Fiserv Secure Email Notification" spam
      • MS13-036 buggy, withdrawn
      • UPS spam / juliamanako.ru
      • "Spotlite Radio" / spotliteradio2013.com spam
      • Changelog spam / juliaroberzs.ru
      • "Verizon Wireless" spam / jamtientop.ru
      • Congratulations! You are the one millionth visitor...
      • Malware sites to block 10/4/13 - part II
      • BBB Spam / jamiliean.ru
      • "Your credit line percent was changed" spam / judi...
      • Malware sites to block 10/4/13
      • ICANN: thanks for the malware spam / mailedspokesp...
      • Top porn sites lead to malware
      • Intuit spam / juhajuhaa.ru
      • LinkedIn spam / jonahgkio.ru
      • "Unable to process your most recent Bill Payment" ...
      • HP ScanJet spam / jundaio.ru
      • "Kissinger: Thatcher's strong beliefs" spam / ighj...
      • "M&I Bank bankruptcy" spam / ighjaooru.ru
      • Beware of jonejonesonley.org
      • Facebook "Reminder: Reset your password" spam / ac...
      • "Updated information" spam / accooma.org / classic...
      • "Copies of Policies" spam / ifikangloo.ru
      • "End of Aug. Statement" spam / ijsiokolo.ru
      • "Speech.doc" legal spam / itriopea.ru
      • "British Airways" spam / igionkialo.ru
      • "Bill Me Later" spam / PP_BillMeLater_Receipe04032...
      • "Have you seen how much money has Cameron spent on...
      • eFax spam / ivanikako.ru
      • Author Iain Banks has terminal cancer
      • Something evil on 151.248.123.170
      • And this is why people don't trust lawyers..
      • Sendspace spam / imbrigilia.ru
      • "End of Aug. Statement Required" spam / ivanovopos...
      • "Russian Hackers" spam / kidala.info / hack-sell.su
    • ►  March (67)
    • ►  February (60)
    • ►  January (7)
Powered by Blogger.

About Me

Unknown
View my complete profile