Thursday, July 08, 2004
Casino Online On-Line (part 3)
Well, the casino moron struck POPFile again. That got Manni agitated enough to do some heavy chongqing research to go along with what I have already done in part 1, part 2, and more on this topic.
I am not 100% certain they are connected, but if you click many of the links on the casino-online-on-line site it takes you to an identical looking site at btdcasino.com. And at the top of the page of both sites it says Be The Dealer Casino. There is little useful whois info on either except they were both registered through GoDaddy which could be more than coincidence. Manni did get some possible clues out of the info though.
I suspect casino online on-line a cover for their spamming. Their real domain looks totally legitimate and non-spammy so if their spam url's host gets complaints they can't be directly connected to the real site. Hopefully we can find a way to prove it.
For more evidence I did a diff between the main pages at casino-online-on-line dot com and btdcasino dot com. Its obvious they are trying to cover their tracks. On casino on-line they removed the note about who wrote the javascript, but they used a lot of identical javascript and HTML code between pages.
Both sites have a link to the same install program on the same server from Netherlands Antilles hidden in some javascript:
btdcasino dot com : 193.109.194.162
casino-online-on-line dot com : 63.241.136.201
This is btdcasino's HTTP header:
Here is casino-online-on-line's:
Also take a look at:
I am not 100% certain they are connected, but if you click many of the links on the casino-online-on-line site it takes you to an identical looking site at btdcasino.com. And at the top of the page of both sites it says Be The Dealer Casino. There is little useful whois info on either except they were both registered through GoDaddy which could be more than coincidence. Manni did get some possible clues out of the info though.
I suspect casino online on-line a cover for their spamming. Their real domain looks totally legitimate and non-spammy so if their spam url's host gets complaints they can't be directly connected to the real site. Hopefully we can find a way to prove it.
For more evidence I did a diff between the main pages at casino-online-on-line dot com and btdcasino dot com. Its obvious they are trying to cover their tracks. On casino on-line they removed the note about who wrote the javascript, but they used a lot of identical javascript and HTML code between pages.
Both sites have a link to the same install program on the same server from Netherlands Antilles hidden in some javascript:
- http://209.58.23.130/dl/did2090/installBTDcasino.exe
http://209.58.23.130/dl/did1549/installBTDcasino.exe
btdcasino dot com : 193.109.194.162
- looking up that IP gives gns.customer.areti.co.uk which has a few links including
the-best-casino-online dot us which looks very familiar.
casino-online-on-line dot com : 63.241.136.201
- looking this IP up gives linhost101.mesa1.secureserver.net, sadly there was no website setup for that hostname to compare.
This is btdcasino's HTTP header:
- HTTP/1.1 200 OK
Connection: keep-alive
Date: Thu, 08 Jul 2004 19:52:38 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 19855
Content-Type: text/html
Expires: Wed, 07 Jul 2004 10:32:38 GMT
Set-Cookie: aff=affiliation%5Fcode=1429&language%5Fid=1; expires=Fri, 08-Jul-2005 19:52:38 GMT; path=/
Set-Cookie: ASPSESSIONIDSQRBQCCS=PDKPPHMCBGLNIALIEMMMDHJI; path=/
Cache-control: private
Here is casino-online-on-line's:
- HTTP/1.1 200 OK
Date: Thu, 08 Jul 2004 17:55:38 GMT
Server: Apache/1.3.29 (Unix) FrontPage/5.0.2.2634
Last-Modified: Tue, 06 Jul 2004 16:59:26 GMT
ETag: "2cba4ac-6f3f-40eada6e"
Accept-Ranges: bytes
Content-Length: 28479
Keep-Alive: timeout=15, max=100
Connection: Keep-Alive
Content-Type: text/html
Also take a look at:
- casino-online-on-line dot com/online-casino-online-news.html
That looks very spammy to me. All 3000 something pages were edited on the same time and day and all I looked at had the same content. That obvious spamdexing for Google PageRank.
Comments:
<< Home
Thanks. He just hit POPFile's wiki this morning too. We will add this one to our lists. And here are some of his keywords for Google to pickup: Buy Viagra Online, viagra, order viagra, cheap viagra online, best prices
Edit
Post a Comment
Edit
<< Home