Jump to content

Strange spamming tactic


Recommended Posts

Received 7 "identical" spam (apart from originating IP address, Message-ID: and Date:) in 7 minutes and 49 seconds which seems like a "human" sort of effort, as opposed to robot.

Typical is http://www.spamcop.net/sc?id=z5227873458z5...fff1f4dbc9be17z

Origin and time differences: (UA) Thu, 19 Jan 2012 16:42:19 +0100 (VE) Thu, 19 Jan 2012 16:45:43 +0100 (RO) Thu, 19 Jan 2012 16:46:05 +0100 (SI) Thu, 19 Jan 2012 16:47:24 +0100 (BA) Thu, 19 Jan 2012 16:47:32 +0100 (PL) Thu, 19 Jan 2012 16:49:50 +0100 (BR) Thu, 19 Jan 2012 16:50:08 +0100

Another oddity is in the time zones - most of those (well, four of them) are wrong for the origin (and those times all tie in closely with the received stamps from my provider). I suppose someone affiliated with de.generic4all.com is trying out some sort of snow-shoeing mass mailer?

I've never seen anything quite like it before. More than usually annoying and ineffectual if the actual mission is to coax sad souls to the target website. Oh well, who can know the mind of the spammer? Is that even "proper" idiomatic German in the message body? The Subject:, by the way (since the parser doesn't render it from Base64), is "Bist Du schlecht im Bett?". Spammers lie.

Link to comment
Share on other sites

Well spotted. Only (Homenet Softlab, Gdansk, Poland) was not shown as open relay and not listed in CBL, all the others were the same as No matter what, each of them seems to have operated as an outgoing SMTP terminal and was trustingly accepted by iiNet - like "Received: from unknown (HELO generic4all.com) ([])" which is a nonsense. Oh well, I have spam filtering turned off at the account level anyway, I suppose a goodly proportion of the little spam I still get comes through with issues like that, I don't think I've ever really looked.

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.


  • Create New...