{"id":1901,"date":"2013-01-08T10:46:26","date_gmt":"2013-01-08T01:46:26","guid":{"rendered":"http:\/\/www.joewein.net\/blog\/?p=1901"},"modified":"2013-01-08T10:47:22","modified_gmt":"2013-01-08T01:47:22","slug":"the-raspberry-ultra-drops-spammers","status":"publish","type":"post","link":"https:\/\/joewein.net\/blog\/2013\/01\/08\/the-raspberry-ultra-drops-spammers\/","title":{"rendered":"The &#8220;Raspberry Ultra Drops&#8221; spammers"},"content":{"rendered":"<p>Large number of abused Yahoo accounts are being used for sending out spam that includes links to hacked websites with PHP code that links to sites selling weight loss products. Typically the mails have multiple recipients, no subject line and a single link in the message body that uses a PHP page, such as <\/p>\n<p><code>http:\/\/www.example.com\/images\/stories\/ronnd.php?faze=faze<\/code><\/p>\n<p>The PHP code redirects to a spam domain, or another PHP page redirecting to a spam domain. Here is a list of some of the spam domains advertised recently:<\/p>\n<blockquote><p>12fox-news.com<br \/>\n12newsfx.com<br \/>\n1newstime.com<br \/>\nberryextra.com<br \/>\nberryrasps.com<br \/>\nberrythins.com<br \/>\nbestnewsfx.com<br \/>\nbuy-raspberry.com<br \/>\nbuyberrysdiet.com<br \/>\nchannel6nws.com<br \/>\ndiet12news.com<br \/>\ndietberryshop.com<br \/>\ndietsraspberry.com<br \/>\ne-raspberryshop.com<br \/>\nefoxnws.com<br \/>\nextra5news.com<br \/>\nfocsnewss.com<br \/>\nfox-nws.com<br \/>\nfox5diet.com<br \/>\nfox5nws.com<br \/>\nfoxclocknews.com<br \/>\nfoxfxnws.com<br \/>\nfoxnws24.com<br \/>\nfx-nwstop.com<br \/>\nfxnews12.com<br \/>\nfxsclock.com<br \/>\nfxsnws12.com<br \/>\nfxx-news.com<br \/>\ngreencoffeediet.ru<br \/>\nhoursfox.com<br \/>\ni-foxnews.com<br \/>\ni-raspberrys.com<br \/>\niclocknews.com<br \/>\njustraspberry.com<br \/>\nlimitedberry.com<br \/>\nlossdietketone.com<br \/>\nluxurynws.com<br \/>\nnaturalberrys.com<br \/>\nnewoclocks.com<br \/>\nnews24fox.com<br \/>\nnewsfx12.com<br \/>\nnewsfx24.com<br \/>\nnewsfxs12.com<br \/>\nnewsviagrow.ru<br \/>\nnowslimberry.com<br \/>\nnwscofee.com<br \/>\nnwsfox.com<br \/>\nnwsfox5.com<br \/>\nnwsfxs12.com<br \/>\nnwshour.com<br \/>\nonraspberry.com<br \/>\nonraspberrys.com<br \/>\nraspberry-slims.com<br \/>\nraspberrybest.com<br \/>\nraspberryelites.com<br \/>\nraspberryfresh.com<br \/>\nraspberryseller.com<br \/>\nraspberrysold.com<br \/>\nraspberrywinter.com<br \/>\nraspdiet.com<br \/>\nraspdiets.com<br \/>\nraspsberry.com<br \/>\nraspsworld.com<br \/>\nraspthinberry.com<br \/>\nsalesraspberry.com<br \/>\nshopraspberry.com<br \/>\nslimketone.com<br \/>\nslimraspberry.com<br \/>\nslimsberrys.com<br \/>\nslimsfox.com<br \/>\nsoldraspberry.com<br \/>\ntopberrydiet.com<br \/>\ntrimfatrasp.com<br \/>\ntrimraspberry.com<br \/>\nultraraspberry.ru\n<\/p><\/blockquote>\n<p>These domains use Russian name servers such as ns1.dnsmax.ru (219.87.170.82), ns1.dnscentral.ru (219.87.170.82), ns2.dnsmax.ru (89.103.247.13), ns2.dnscentral.ru (89.103.247.13). The use of hacked Yahoo accounts for mailing, of hacked PHP websites to mask the spam domain and the fake references to Fox News are similar to the <a href=\"\/blog\/2012\/11\/23\/work-from-home-mum-scams\/\">&#8220;Work from home mom&#8221; scam<\/a> that has been going around for a while, so they are probably connected.<\/p>\n<p>My advice: Don&#8217;t buy from spammers. Why should you hand your credit card details to a criminal?<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Large number of abused Yahoo accounts are being used for sending out spam that includes links to hacked websites with PHP code that links to sites selling weight loss products. Typically the mails have multiple recipients, no subject line and &hellip; <a href=\"https:\/\/joewein.net\/blog\/2013\/01\/08\/the-raspberry-ultra-drops-spammers\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[21,2],"tags":[],"class_list":["post-1901","post","type-post","status-publish","format-standard","hentry","category-scams","category-spam"],"_links":{"self":[{"href":"https:\/\/joewein.net\/blog\/wp-json\/wp\/v2\/posts\/1901","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/joewein.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/joewein.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/joewein.net\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/joewein.net\/blog\/wp-json\/wp\/v2\/comments?post=1901"}],"version-history":[{"count":3,"href":"https:\/\/joewein.net\/blog\/wp-json\/wp\/v2\/posts\/1901\/revisions"}],"predecessor-version":[{"id":1904,"href":"https:\/\/joewein.net\/blog\/wp-json\/wp\/v2\/posts\/1901\/revisions\/1904"}],"wp:attachment":[{"href":"https:\/\/joewein.net\/blog\/wp-json\/wp\/v2\/media?parent=1901"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/joewein.net\/blog\/wp-json\/wp\/v2\/categories?post=1901"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/joewein.net\/blog\/wp-json\/wp\/v2\/tags?post=1901"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}