The MKT Negocios Spammers in Argentina

For years I’ve been tracking spam from Argentina that is using yopmail.com / yopmail.net disposable sender addresses.

Unlike a lot of spam sent from other countries, the advertised companies are mostly legitimate businesses, some of whom may be clueless that mail is being sent to unwilling recipients all over the globe who may not even speak Spanish.

The sender IPs tend to be on cablevision.com.ar, for example from the 190.188.0.0/15, 190.190.0.0/15 and 181.164.0.0/14 ranges.

The spamming company owns several domains, but these don’t normally show up in sender addresses or links, e.g.:

mktnegocios.net:

Domain name: mktnegocios.net
Registry Domain ID: 186887
Registrar WHOIS Server: whois.dattatec.com
Registrar URL: http://dattatec.com
Updated Date: 2017-09-20T01:00:53Z
Creation Date: 2011-09-19T11:24:51Z
Registrar Registration Expiration Date: 2018-09-19
Registrar: dattatec.com SRL
Registrar IANA ID: 1388
Registrar Abuse Contact Email: abuse@dattatec.com
Registrar Abuse Contact Phone: +54.3415169000
Domain Status: OK
Registry Registrant ID: DC282919DTT
Registrant Name: Cid Ricardo Ernesto
Registrant Organization: Cid Ricardo Ernesto
Registrant Street: Islandia 4393
Registrant City: Lanus Oeste
Registrant State/Province: Buenos Aires
Registrant Postal Code: 1824
Registrant Country: ar
Registrant Phone: +54.42679611
Registrant Phone Ext:
Registrant Fax:
Registrant Fax Ext:
Registrant Email: ricardocid@hotmail.com

mktnegocios.info:

Domain Name: MKTNEGOCIOS.INFO
Registry Domain ID: D42311407-LRMS
Registrar WHOIS Server:
Registrar URL: http://dattatec.com
Updated Date: 2017-09-19T22:22:35Z
Creation Date: 2011-09-19T11:25:09Z
Registry Expiry Date: 2018-09-19T11:25:09Z
Registrar Registration Expiration Date:
Registrar: Dattatec.com SRL
Registrar IANA ID: 1388
Registrar Abuse Contact Email:
Registrar Abuse Contact Phone:
Reseller:
Domain Status: ok https://icann.org/epp#ok
Domain Status: autoRenewPeriod https://icann.org/epp#autoRenewPeriod
Registry Registrant ID: C114356985-LRMS
Registrant Name: Cid Ricardo Ernesto
Registrant Organization: Cid Ricardo Ernesto
Registrant Street: Islandia 4393
Registrant City: Lanus Oeste
Registrant State/Province: Buenos Aires
Registrant Postal Code: 1824
Registrant Country: AR
Registrant Phone: +000.42679611
Registrant Phone Ext:
Registrant Fax:
Registrant Fax Ext:
Registrant Email: ricardocid@hotmail.com
Registry Admin ID: C114356985-LRMS
Admin Name: Cid Ricardo Ernesto
Admin Organization: Cid Ricardo Ernesto
Admin Street: Islandia 4393
Admin City: Lanus Oeste
Admin State/Province: Buenos Aires
Admin Postal Code: 1824
Admin Country: AR
Admin Phone: +000.42679611
Admin Phone Ext:
Admin Fax:
Admin Fax Ext:
Admin Email: ricardocid@hotmail.com
Registry Tech ID: C114356985-LRMS
Tech Name: Cid Ricardo Ernesto
Tech Organization: Cid Ricardo Ernesto
Tech Street: Islandia 4393
Tech City: Lanus Oeste
Tech State/Province: Buenos Aires
Tech Postal Code: 1824
Tech Country: AR
Tech Phone: +000.42679611
Tech Phone Ext:
Tech Fax:
Tech Fax Ext:
Tech Email: ricardocid@hotmail.com
Registry Billing ID: C114356985-LRMS
Billing Name: Cid Ricardo Ernesto
Billing Organization: Cid Ricardo Ernesto
Billing Street: Islandia 4393
Billing City: Lanus Oeste
Billing State/Province: Buenos Aires
Billing Postal Code: 1824
Billing Country: AR
Billing Phone: +000.42679611
Billing Phone Ext:
Billing Fax:
Billing Fax Ext:
Billing Email: ricardocid@hotmail.com
Name Server: NS21.DATTATEC.COM
Name Server: NS22.DATTATEC.COM
Name Server: NS3.HOSTMAR.COM
Name Server: NS4.HOSTMAR.COM
DNSSEC: unsigned
URL of the ICANN Whois Inaccuracy Complaint Form: https://www.icann.org/wicf/

mktnegocios.com.ar:

Datos del dominio
Nombre y Apellido: DALLAVIA FERNANDO LUCIANO VICTOR LUCIANO VIVTOR
CUIT/CUIL/ID: 20220483895
Fecha de Alta: 23/01/2017
Fecha de última Actualización: 24/01/2017
Fecha de vencimiento: 23/01/2018

On their website they explain to their prospective customers that they will spam to harvested addresses:

BASE DE DATOS :

Contamos con bases de datos argentinas y del exterior validadas la totalidad de las mismas cada 15 dias, asegurandonos asi la completa funcionalidad y validez de los emails. Los datos se obtienen a traves de extracciones de emails por medio de software en la web.

Translation:

Databases

We have Argentine and foreign databases completely validated every 15 days, thus ensuring the full functionality and validity of emails. The data is obtained through extraction of emails through software on the web.

Owners of harvested addresses have by definition not signed up to receive bulk mail. Their various mailing package go as high as 16,000,000 emails…

See also:

If you’re a business in Argentina trying to decide on online advertising, hiring a spammer like this will damage your reputation and may end up getting your domains blacklisted.

Updated jwhois.conf File for CentOS for New gTLDs

The whois command on CentOS 6.x and 7.x doesn’t handle queries for many domains in new Top Level Domains (TLDs) that were added by ICANN in the last few years.

Domains from many of these new TLDs are selling as cheap as $0.99 a pop, making them attractive to snowshoe spammers who create them in large numbers. As a spam researcher, I see lots of new spam domains from TLDs such as .xyz, .online, .top. .club, .services, .win, .site, .bid, .life and .trade.

WHOIS is an important tool for me to track the domain registrants. CentOS uses jwhois as its WHOIS client, which relies on a configuration file to tell it what servers to query for detailed information. The configuration file that comes with recent CentOS versions is woefully out of date.

I have gone through the currently existing TLDs and counted 466 of them that are not supported by jwhois but appear to have a valid WHOIS server. I have been able to verify for about half of these TLDs that the WHOIS server works and have added them to my configuraion file, which you can download here.

Many of the rest of the new TLDs are hosted on Neustar, which performs rate limiting on lookups. Because of that I didn’t fully verify functioning of all those hosts, but I verified that CNAMEs exist for the WHOIS hosts that redirect to Neustar WHOIS servers and tested a small sample of those TLDs.

Karl Marx on Donald Trump

Karl Marx on Donald Trump:

“He behaved like an unrecognized genius, whom all the world takes for a simpleton.”

Actually, he wrote that about French president Louis-Napoléon Bonaparte, nephew of Napoleon I, who in an 1851 coup turned the French Second Republic into the authoritarian Second Empire and had himself crowned Emperor Napoleon III.

Getting Rid of the EMUI Launcher on the Huawei P9 Lite

Last time I switched mobile provider here in Japan, I signed up for a contract that included a Huawei P9 Lite. My biggest grip about it is its non-standard EMUI interface that runs on top of Android 6.0.1.

Previously I was using a Nexus 5, which had worked OK for me, though the picture quality of its camera was rather mediocre. One nice thing about the Nexus 5 was that it runs stock Android, with no customization. Its user interface is identical to that of my other phone, a Nexus 6P.

I really prefer stock Android without OEM customization. For one, stock Android means you can get version upgrades sooner and for longer (or at all!).

I found the EMUI launcher confusing. For example, I did not see any easy way to launch an app that didn’t have a desktop link.

It’s possible to switch from EMUI to the standard Google launcher. Here are the steps I performed:

1) Install “Google Now Launcher” via Play Store.

2) Swipe down, select Shortcuts and then Settings

3) Enter “def” into the search box at the top (may have to scroll up first)

4) Select “Default app settings”

5) Select “Launcher” and pick “Google” instead of “Huawei Home”. Ignore the warning that tries to scare you into sticking with EMUI (you can always change back by following the same steps and selecting “Huawei Home” again).

6) There you go!

The irritating long push home button

Another irritation that seemed to happen more on the Huawei than on my other phones was the Google screen that pops up (seemingly randomly) when I just try to go to the home screen. It has a “Want answers before you ask?” prompt at the bottom and a Google search box with voice search option at the top. I really don’t need this screen because the standard Android home screen already has a Google search bar at the top. I’d rather have the home screen with all my app shortcuts come up reliably whenever I push the Home button!

It took me a while to figure out that this Google search screen comes up on what the phone thinks is a long push of the Home button, which has a different meaning from a regular short tap. If that happens, just tap again and it will go to the home screen. Or just make it your habit to double tap the home screen to go to the home screen, then this should never happen 🙂