CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

Spam or targeted commercials ?

 
Post new topic   Reply to topic       All -> FavForums -> Spam [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
fritz2cat

Cadet
Cadet


Joined: Aug 21, 2008
Posts: 4
Location: Belgium

PostPosted: Tue Sep 02, 2008 1:18 pm    Post subject: Spam or targeted commercials ?
Reply with quote

Hello the community,

One of my users is a victim of a "marketing group" question which sends him 100~200 e-mails every week .

Currently I am completely barring every mail from a certain number of hosting providers. The blocking will remain in place until I may decide to remove it by hand.

Below you will find :
1) the list of all addresses the spammers have presented in the "RCPT To" smtp dialog during the last 7 days. The "From:" clause in the mail headers usually contains something else. (if I let the mail in Confused )
2) the list of all their hostnames and IP addresses that have contacted my server during the last 7 days.
3) the block list currently enforced, with some comments

Is there anybody here experiencing the same problem ?

The e-mail messages themselves contain a lot of tracking data. Usually thay contain a "click here to get removed" link, but I would not recommend using it.

Most of these messages bear a postal address, e.g.

Entertainment Publications, Inc.,
1414 East Maple Road,
Troy, MI 48083
1-866-826-1619

Pedi Paws is located at P.O Box 600991 San Diego, CA 92160

6965 El Camino Real
Suite 105 - 698
La Costa, CA 92009

Consumer Service 9-334 Queen Street South, Suite 200, Bolton, Ontario, Canada L7E-2N9

Technical Support
30 East 23 rd. St. New York, NY 10010

Pure Play, 660 4TH Street, Ste 294, San Francisco, CA 94107

All the sending hosts have SPF published data, and they run an MTA able to handle a mailqueue (thus defeating the greylisting)

Happy to hear from you, if you experince the same.

Frederic

(and now the promised attachments)::
1) the list of all addresses presented during the last 7 days.

Quote:
123Inkjets@pinablekilly.info
24HourSaleonprinter_inkcartridges@facornet.com
CherylTiegs@untilsail.com
CherylTiegs@waspinger.com
ChurchDating@conventionalnets.com
ChurchDating@redflowertail.com
Clarisonic@fandillo.com
Colonox.com@arcfinal.info
Colonox.com@untilsail.com
Dollars4Gold.com@arcfinal.info
Dollars4Gold.com@untilsail.com
EndurRxSpecialOffer@envelody.com
ENSupport@gascarcountry.com
ENSupport@redflowertail.com
ENSupport@untilsail.com
FoodSampleSurvey@envelody.com
GiftDepotDirect@bearstray.com
Glycogone@juiceabrender.com
Glycogone@undercovendial.com
GrantsOnline@pinablekilly.info
GrantsOnline@untilsail.com
GrassSeed@arcfinal.info
GrassSeed@untilsail.com
GroceryCoupons@envelody.com
GroceryCoupons@untilsail.com
HomeownersInsurance@juiceabrender.com
HumanResources@pounceroom.com
HumanResources@untilsail.com
Hydroderm@bikeflay.info
Hydroderm@insidersighter.biz
InsuranceCompany@envelody.com
InsuranceCompany@undercovendial.com
InsuranceCompany@untilsail.com
JohnCummuta@juiceabrender.com
Moneyisavailable@arcfinal.info
noreply@arcfinal.info
noreply@bearstray.com
noreply@bedstreeting.com
noreply@bikeflay.info
noreply@chindalo.info
noreply@conventionalnets.com
noreply@emarketresponse.com
noreply@envelody.com
noreply@facornet.com
noreply@fandillo.com
noreply@gascarcountry.com
noreply@juiceabrender.com
noreply@oblivendo.com
noreply@pinablekilly.info
noreply@pounceroom.com
noreply@redflowertail.com
noreply@undercovendial.com
noreply@unidollahj.com
noreply@waspinger.com
noreply@wranchsail.com
ParkRoyalCancun@arcfinal.info
PCServiceNews@gascarcountry.com
PCServiceNews@redflowertail.com
PDFSolution@gascarcountry.com
PDFSolution@undercovendial.com
PerfectSmile@untilsail.com
PerfectSmile@waspinger.com
Pomevie@envelody.com
PureC@waspinger.com
quotes@bikeflay.info
RobertAllen@undercovendial.com
SellTimeshare@arcfinal.info
SellTimeshare@redflowertail.com
SmokeFreeIn30Days@bedstreeting.com
StopForeclosureOption@redflowertail.com
swimmingpoolquotes@juiceabrender.com
Trade-In@arcfinal.info
UnlimitedInternetMovieDownloadCenter@facornet.com
Vegas4Free@fandillo.com
Victoria@bearstray.com
VitalAcai@chindalo.info
VitalAcai@fandillo.com
Weightloss@bedstreeting.com
WorldSeriesOfPokerSeatOpportunity@envelody.com
WRF@facornet.com


2) the list of all their hostnames and IP addresses, in the last 7 days
Quote:
ssl.pounceroom.com [216.75.6.231]
ssl.wranchsail.com [216.75.6.232]
ssl.insidersighter.biz [64.187.120.82]
ssl.arcfinal.info [64.187.120.85]
ssl.waspinger.com [64.187.120.89]
ssl.emarketresponse.com [64.187.126.146]
ssl.conventionalnets.com [64.187.126.153]
ssl.pinablekilly.info [64.187.127.77]
ssl.juiceabrender.com [64.187.127.81]
ssl.facornet.com [64.187.127.83]
ssl.untilsail.com [64.187.127.84]
ssl.redflowertail.com [64.187.127.90]
ssl.bearstray.com [66.63.175.2]
ssl.bedstreeting.com [66.63.175.4]
ssl.benger2i.info [66.63.175.5]
ssl.bikeflay.info [66.63.175.6]
ssl.chindalo.info [66.63.175.7]
ssl.envelody.com [66.63.175.9]
ssl.fandillo.com [70.38.23.100]
ssl.gascarcountry.com [70.38.23.101]
ssl.undercovendial.com [70.38.23.103]
ssl.unidollahj.com [70.38.23.104]
ssl.oblivendo.com [70.38.23.108]

3) the block list currently enforced, with some comments
Quote:
# 10-04-2008
76.76.96.0/19 Interweb
#67.18.238.0
67.18.0.0/16 ThePlanet
# 15-04
67.205.64.0/18 iWeb
69.64.32.0/19 Server4You
207.36.188.0/22 Affinity
207.36.192.0/22 Affinity
#
38.100.214.0/24 PSI
# 21/04
64.187.96.0/19 AccelerateBiz
# Reports2008@xxx
69.30.192.0/18 WholeSale Internet
#
66.63.160.0/19 OC3 Networks
# 6-may 70.87.144.241
70.84.0.0/14 ThePlanet
# 7 may 67.198.199.158
67.198.128.0/17 VPLS
# 8 may 64.235.55.227
64.235.32.0/19 A-Plus
# 23 may 207.36.8.254
207.36.0.0/21 Affinity
207.36.8.0/24 Affinity
# 69.42.169.*
69.42.160.0/20 Colocentral-Selectchoicehosts
# 5 june 204.15.132.142
204.15.132.0/22 NDChost
# july 2008, 208.71.169.13
208.71.168.0/21 NDChost
# 23/7 208.82.117.xx (xx=30,29,28,26,25,131)
208.82.112.0/21 NDChost
# 11/8 208.110.69.182
208.110.69.0/24
# 11/8 66.111.196.153
66.111.196.0/22
# 69.42.97.18 on 15/8, .17 and .19 on 18/8
69.42.97.0/24 Terrenap
# 25/8 216.75.6.233
216.75.0.0/18 Cari Network
# 25/8 70.38.23.110
70.38.0.0/17 iWeb

Back to top
View users profile Send private message
AlphaCentauri

SIRT Handler
Premium Member

Joined: Nov 20, 2003
Posts: 2859

Premium

PostPosted: Tue Sep 02, 2008 5:28 pm    Post subject:
Reply with quote

If I get spam that looks like it's actually trying to be CAN-SPAM compliant (it isn't, since my email address was harvested by webcrawling bots before being sold to folks like this), I forward it to spamcop.net. The tracking information lets them know who reported them without giving them the impression that that person actually looked at the email. (After all, CAN-SPAM requires them to remove my name from their mailing list; it doesn't keep them from selling it to other spammers on a premium-priced "people who open spam" list.) Since they are mailing from their own servers instead of hijacked proxies, they do have an interest in staying off the Spamcop blocklist, so I've found they will eventually stop mailing to me.

It's kind of silly they ever mail to me in the first place, as I know my addresses are on a list spammers circulate of people who report to Spamcop and also the list of people who used to report to Blue Frog. They could save themselves a lot of trouble by removing the names of people who will never buy anything -- and who will probably report them -- before sending out their spam.

Could my address be on that premium list, since I sometimes can't investigate a site without using the link code? Probably. But anyone who is on the Spamcop and Blue Frog lists and also on an opens-spam list is probably an anti-spammer, someone who they definitely want to avoid mailing to.

Back to top
View users profile Send private message
fritz2cat

Cadet
Cadet


Joined: Aug 21, 2008
Posts: 4
Location: Belgium

PostPosted: Thu Sep 04, 2008 7:25 pm    Post subject:
Reply with quote

Thank you for the reply -- I will try to automate the task ...

Frédéric

Back to top
View users profile Send private message
hansBF

Blue Angel
Premium Member

Joined: May 03, 2006
Posts: 276
Location: USA
Blue Security Premium Team F@H

PostPosted: Fri Sep 05, 2008 5:24 am    Post subject:
Reply with quote

AlphaCentauri wrote:
...anyone who is on the Spamcop and Blue Frog lists and also on an opens-spam list is probably an anti-spammer, someone who they definitely want to avoid mailing to.


It certainly is a strange business model. Could it be that spammers are just stupid? Rolling Eyes

Hans


_________________
Websplasher website design. Design with a splash.
Back to top
View users profile Send private message Visit posters website
PaulW2

Lieutenant
Lieutenant
Premium Member

Joined: May 04, 2006
Posts: 150
Location: U.K.
Premium

PostPosted: Fri Sep 05, 2008 6:18 pm    Post subject: Re: Spam or targeted commercials ?
Reply with quote

fritz2cat wrote:
One of my users is a victim of a "marketing group" question which sends him 100~200 e-mails every week .

I was in the same position a few months ago. Each day I would receive at least ten emails from a Versaweb client and a few from another source, the exact details of which I have forgotten. All the emails were to the same format, well laid out, offered a long coded unsubscribe link and were obviously targeted at US recipients, I am in the UK.

In time, every email was reported to SpamCop, initially without success. I then started to add comments advising the SpamCop report recipient how many reports I had made that day. Still no success, so I decided to send copies of the SpamCop reports to additional unames at Versaweb such as 'sales', 'support', 'billing' and 'accounts' on the basis that other departments would become annoyed at the abuse department for not stopping thei client sending spam. The spam very quickly dried up. Coincidence? I'll never know but it is a tactic I have used several times now with success.

I probably broke a SpamCop rule but in my opinion the result justified the means. Confused

Back to top
View users profile Send private message
fritz2cat

Cadet
Cadet


Joined: Aug 21, 2008
Posts: 4
Location: Belgium

PostPosted: Fri Sep 05, 2008 6:39 pm    Post subject:
Reply with quote

Here they are not all formatted the same way -- from the same originating domain, one is html with only images that I didn't download, the other one is pure text...

Here is a recent item: (xxxxxx are from me)

Quote:

Received: by ssl.moremanagment.com ([66.63.168.79]) xxxxxxx
Date: Fri, 5 Sep 2008 xxxxxxx
From: "Dr. Suzanne" <noreply@moremanagment.com>
Subject: This is why you're fat
To: xxxxxxxxx
Content-Type: text/plain; charset=us-ascii

Hi,

My name is Suzanne, and I'm a real doctor that would like to show you why you may be "fat" and why you're unable to lose weight no matter how hard you try.

First off, please always know that it's not your fault...I would like to show you the disgusting truth right now as to what is keeping you fat!

Press here to see the disgusting truth that is keeping you from losing fat:
http://moremanagment.com/c/xxxxxxxxxxx.html?0

After you see what the problem is, I will then show you how easy it is to finally lose the fat that you want to lose.

Thank you!

Dr. Suzanne

-----
To not receive future offers/promotions from "Dr. Suzy" please press on the below
link and scroll to the bottom of the page:
http://moremanagment.com/c/xxxxxxxxxxxxx?1

Or send us a letter at:

6965 El Camino Real
Suite 105 - 698
La Costa, CA 92009
To remove yourself from this list, click here http://moremanagment.com/u/xxxxxxxxxxx.html or write to us at:848 N. Rainbow Blvd #2511Las Vegas, NV 89107

Frederic

Back to top
View users profile Send private message
fritz2cat

Cadet
Cadet


Joined: Aug 21, 2008
Posts: 4
Location: Belgium

PostPosted: Fri Sep 12, 2008 3:02 pm    Post subject:
Reply with quote

AlphaCentauri wrote:
If I get spam that looks like it's actually trying to be CAN-SPAM compliant ... , I forward it to spamcop.net. The tracking information lets them know who reported them .


Thank you Alphacentauri for the tip.

I have sent (human) e-mails to some human at two of their hosting providers, telling them that I would start report *every* piece of spam to Spamcop. I got no answer, but the next day, I got around 20 mails from various hosts controlled by this gang, all reported in realtime ; the next day all at once, the flow has stopped.

But the automatic reporting to Spamcop is still in place, should they change their mind Twisted Evil

Frédéric

Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Spam All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer