Vitavonni

Thu, 07 Oct 2004

Spammers getting smarter - especially more stubborn: 15 retries using different zombies to drop a spam mail

Today i watched a spammer trying to deliver his spam using multiple hosts.

Well, they don't really get smarter, they just put in more effort.

If he would be smart, he wouldn say hello each time with rnddg[2].rnddg[2].rnddg[2].rnddg[2] (literally, not random digits...)

I can't say for sure that this is the same spammer, this account seems to get a lot of spam. But the timeframe and the rnddg stupidity suggests this is the same idiot. Only the first attempt used an email address made up from the reverse lookup, all other were probably from their database.

First attempt at 01:08:26 from an AOL IP, using the AOL hostname both for HELO and for sender. Rejected due to dynamic ip range listing.

Second attempt at 01:08:31 from host-$IP.midco.net rejected due to invalid helo.

Third attempt at 01:08:34 from $IP.fl.comcast.net blocked due to dynamic ip listing.

Forth attempt at 01:08:37 from an unknown IP (Oklahoma Office of State Finance) - blocked again due to the rnddg stuff.

Fifth attempt at 01:08:42 from another AOL IP, blocked due to dialin IP.

Sixth attempt at 01:08:46 from some charter.com address. blocked using dialin IP range again.

Seventh attempt at 01:08:49 from some cinci.rr.com address. Again dialin block.

Eigth attempt at 01:09:01 from dialup.*.ev1.net - dialin IP block.

Ninth attempt at 01:09:17 from cura.net, again dialin IP block.

Tenth attempt at 01:09:30 from unknown IP (charter-net). RBL block.

01:09:32 - some spam from a different spammer made it through using some charter.net IP without reverse lookup and got 28.9 Hits in SpamAssassin.

Eleventh attempt at 01:09:47 from .ppp.*.epix.net - dialin block.

Twelvth attempt at 01:10:43 from dial.plus.net - dialin block.

Thirteenth attempt at 01:11:16 from dial-up.net - dialin block.

Foureenth attempt at 01:11:19 from .va.comcast.net - dialin block.

Fifteenth attempt at 01:11:23 from unknown IP (rr.com) - helo rejected.

Sixteenth attempt at 01:11:27 from swbell.net - dialin block. (not rnddg)

Seveneenth attempt at 01:11:30 from chello.nl - dialin block. (not rnddg)

Eighteenth attempt at 01:11:33 from .mi.comcast.net - dialin block. (not rnddg)

Nineteenth attempt at 01:11:37 from east.verizon.net - dialin block. (not rnddg)

At 01:11:41 another spam made it through from rr.com, scored 7 hits in SpamAssassin.

Another - probably different - spam attempt is made at 01:17:33, the next at 01:53:20. At 02:09:21 another mail comes through and scores 9.7 hits.

So this spammer took like 15 tries, immedeately followed by one taking 5 tries to find a zombie i do not block. And even the mails that did make it through (most probably mails by other spammers) got eaten by spamassassin.

Please never complain to me again for not accepting mails from dialup lines. If you are dialup, find a trustworthy mail server you can use smtp-auth on.

Menu
[planet.debian]
[planet.xmlhack]
[planet SELinux]
[munichblogs]
[email]
[RSS 2 feed]
[English RSS 2]
Categories
< October 2004 >
SuMoTuWeThFrSa
      1 2
3 4 5 6 7 8 9
10111213141516
17181920212223
24252627282930
31      
Archives
2010-Mar
2010-Feb
2010-Jan
2009-Dec
2009-Nov
2009-Oct
2009-Sep
2009-Aug
2009-Jul
2009-Jun
2009-May
2009-Apr
2009-Mar
2009-Feb
2009-Jan
2008-Dec
2008-Nov
2008-Oct
2008-Sep
2008-Aug
2008-Jul
2008-May
2008-Apr
2008-Mar
2008-Feb
2008-Jan
2007-Dec
2007-Nov
2007-Oct
2007-Sep
2007-Aug
2007-Jul
2007-Jun
2007-May
2007-Apr
2007-Mar
2007-Feb
2007-Jan
2006-Dec
2006-Nov
2006-Oct
2006-Sep
2006-Aug
2006-Jul
2006-Jun
2006-May
2006-Apr
2006-Mar
2006-Feb
2006-Jan
2005-Dec
2005-Nov
2005-Oct
2005-Sep
2005-Aug
2005-Jul
2005-Jun
2005-May
2005-Apr
2005-Mar
2005-Feb
2005-Jan
2004-Dec
2004-Nov
2004-Oct
2004-Sep
2004-Aug
2004-Jul
Other links:
Swing and the City - Lindy Hop in Munich