Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 12-02-2010, 03:48 AM   #1
GlazedMedia
Registered User
 
Industry Role:
Join Date: Nov 2010
Posts: 70
Federal Investigators Identify Russian ?Mega-D? Spam Kingpin ($467k over 6 months)

Check out this story...he generated some $467k over 6 months using spam (see how he was receiving the affiliate payments...)

Quote:
Federal investigators have identified a 23-year-old Russian man as the mastermind behind the notorious ?Mega-D? botnet, a network of spam-spewing PCs that once accounted for roughly a third of all spam sent worldwide.

According to public court documents related to an ongoing investigation, a grand jury probe has indicted Moscow resident Oleg Nikolaenko as the author and operator of the Mega-D botnet.

Federal agents settled on Nikolaenko thanks to information provided by Lance Atkinson, an Australian man named as a co-conspirator in the ?Affking? e-mail marketing and counterfeiting operation that was shuttered in 2008 after investigations by the FBI, the Federal Trade Commission and international law enforcement authorities. The Affking program generated revenues of $500,000 a month using spam to promote counterfeit Rolexes, herbal ?male enhancement? pills and generic prescription drugs.

As part of his guilty plea to spam violations, Atkinson provided investigators information on the top spammers who helped to promote the Affking products. Among them was an affiliate who used the online nickname ?Docent,? who earned nearly $467,000 in commissions over a six month period in 2007.

Atkinson told investigators that Docent?s commissions were sent to an ePassporte account, under the name ?Genbucks_dcent,? that was tied to the e-mail address [email protected].? Records subpoenaed by the grand jury found that the ePassporte account was registered in Nikolaenko?s name to an address in Moscow.

According to court documents, investigators found numerous executable files in Docent?s Gmail inbox. Those files were analyzed by researchers at SecureWorks, an Atlanta based security firm, which found them to be samples of the Mega-D malware.

But U.S. investigators missed at least two chances to apprehend Nikolaenko: The grand jury said a review of U.S. State Department records indicate that Nikolaenko entered the United States in Los Angeles on July 17, 2009, and left the country ten days later. He returned to the U.S. on Oct. 29, 2009, entering from New York and visiting Las Vegas before exiting the country on Nov. 9 from Los Angeles.

Investigators say Nikolaenko was supposed to leave Los Angeles on Nov. 11, but cut his trip short by two days. They concluded that the 23-year-old left early because he wanted to get home to repair damage that security experts had inflicted on his botnet. On Nov. 4, 2009, researchers from Milpitas, Calif. based FireEye executed a ?stun? attack on Mega-D by seizing control over the botnet?s control networks.

?Based on the timing of the Fireeye attack on the Mega-D botnet, I believe that Nikolaenko left the U.S. early to repair damage caused by Fireeye,? wrote Special Agent Brett E. Banner, in the government?s complaint against Nikolaenko.

After the FireEye takedown, spam from Mega-D all but disappeared. But in the days following his return to Moscow, the botnet recovered gradually, and by Nov. 22, spam from Mega-D was back to pre-takedown activity levels. By Dec. 13, Mega-D was responsible for sending nearly 17 percent of spam worldwide, according to security vendor M86 Security.

Joe Stewart, a senior security researcher at SecureWorks, said that at the beginning of Nov. 2009, there were at least 120,000 computers infected with Mega-D that were relaying spam, but Stewart said he hasn?t seen any signs of activity from Mega-D over the past several months.

While Mega-D may be dead, information obtained by KrebsOnSecurity.com suggests that Nikolaenko has nonetheless continued spamming, and that, until at least June 2010, he was a top-earning affiliate for Spamit.com. Prior to its closure at the end of Sept. 2010 ? Spamit was the world?s most active affiliate program for promoting knockoff prescription drugs.

A Spamit affiliate using the same [email protected]? address made nearly $81,000 in the first five months of 2010 promoting online pharmacies for Spamit. The earnings were deposited into the same ?Genbucks_dcent? ePassporte account named in the criminal complaint against Nikolaenko. It?s not clear whether Nikolaenko was able to enjoy all of those earnings: ePassporte also went belly-up in September, leaving thousands of customers without access to millions of dollars in funds.
Source:
krebsonsecurity.com/2010/12/
__________________
Hsted.com: Website Advertising Services.
Adult Traffic For Sale - Pops, Skimmed, Clicked, Banner, Text Ads etc. Large Volumes Available.
Email us here for full details.
GlazedMedia is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-02-2010, 03:54 AM   #2
Angry Jew Cat - Banned for Life
(felis madjewicus)
 
Industry Role:
Join Date: Jul 2006
Location: In Mom & Dad's Basement
Posts: 20,368
Saw something about this yesterday. Where will the the Russian spammers go for their affiliate payments now? lol
Angry Jew Cat - Banned for Life is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-02-2010, 04:07 AM   #3
BJ
Confirmed User
 
BJ's Avatar
 
Join Date: Mar 2002
Location: asia
Posts: 5,590
this where companies like paxum can get in trouble, when they facilitate these types of payments, and they really have no way of knowing until its too late.
BJ is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-02-2010, 06:52 AM   #4
PornoStar69
Confirmed User
 
Join Date: Oct 2008
Location: xxweekxx mothers bed.
Posts: 2,017
ytcracker - spammer shit
__________________
GFY King?
PornoStar69 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-02-2010, 08:16 AM   #5
Phoenix
BACON BACON BACON
 
Industry Role:
Join Date: Nov 2002
Location: Poems everybody, the laddie fancies himself a poet
Posts: 35,457
spammin is bad
__________________
Skype Phoenixskype1
Telegram PhoenixBrad
https://quantads.io
Phoenix is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-02-2010, 08:21 AM   #6
BlackCrayon
Too lazy to set a custom title
 
BlackCrayon's Avatar
 
Join Date: Jun 2003
Location: Ottawa
Posts: 19,631
affkings finally got in trouble.
__________________
you don't know you're wearing a leash if you sit by the peg all day..
BlackCrayon is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-02-2010, 08:43 AM   #7
~Ray
visit hardlinks.org
 
~Ray's Avatar
 
Industry Role:
Join Date: Jun 2003
Location: Las Vegas , Nv >>> [email protected] or icq 94994627 anytime
Posts: 18,362
serves them right
~Ray is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-02-2010, 08:57 AM   #8
Altwebdesign
Guest
 
Posts: n/a
epasse, wander if his funds are in motion. . ?
  Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.