Jump to content
ViRGE

Did The spam Deletion Policy Change?

Recommended Posts

I'm not sure if anyone else has noticed this, but I'm suddenly seeing a fair bit of spam come through on my old Spamcop account. It tends to mostly be of the "Buy cheap Meds" variety, and prior to about two weeks ago I wasn't seeing anything like this.

Given how obvious and easy to block it is, I'm wondering whether Cisco changed their forwarding policy to stop silently dropping spam. Though there aren't any headers to indicate that the Ironport equipment is IDing it as spam...

Share this post


Link to post
Share on other sites

I'm not sure if anyone else has noticed this, but I'm suddenly seeing a fair bit of spam come through on my old Spamcop account. It tends to mostly be of the "Buy cheap Meds" variety, and prior to about two weeks ago I wasn't seeing anything like this.

Given how obvious and easy to block it is, I'm wondering whether Cisco changed their forwarding policy to stop silently dropping spam. Though there aren't any headers to indicate that the Ironport equipment is IDing it as spam...

Yes must of been a glitch?

Stopped now.

It was all BOTNET spam FAKE DRUG OR PLAIN PHISHING

Share this post


Link to post
Share on other sites

It's still going on this morning, so whatever it was it hasn't stopped. :(

And actually it's a bit annoying not because it's getting through, but because since it's being handed off via SC/Cisco's servers, it's getting negative (ham) points with SpamAssassin for coming from a reliable source.

Edited by ViRGE

Share this post


Link to post
Share on other sites

It's still going on this morning, so whatever it was it hasn't stopped. :(

And actually it's a bit annoying not because it's getting through, but because since it's being handed off via SC/Cisco's servers, it's getting negative (ham) points with SpamAssassin for coming from a reliable source.

I find it pays to effectively report spam

(I check the abuse addresses are correct SC uses "abuse.net which often by default uses "abuse at" even though SC picks up correct address)

SpamCop won't send reports to "spam [ AT ] access.ironport.com"?

Try sending them from your private account with SpamCop Tracking URL not sure if it's acknowledged but I'm not now getting BOTNET spam now?

I did but in SC report also looked up who had the Botnet and reported it to countries "cert" as well

I do spend a bit of time making spam reports pretty thorough though.

https://www.spamcop.net/sc?id=z6172948368z52220b2c850cfbc036a566bf0a4194e1z

This one I were the only one to report it.

1.52.195.225 is still listed as a Bornet though, it's not now on SC Blocklist it was when I reported it.

My boiler plate though my be what they implement

Example

1.52.195.225
BOTNET ATTACK HOST
http://www.abuseat.org/lookup.cgi?ip=1.52.195.225
BLOCK OUTBOUND PORT 25,
RESERVE FOR LEGIT EMAIL SERVER
CHANGE TO SECURE PASSWORD
SCAN INFECTED COMPUTER FOR MALWARE

Share this post


Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×