Title: Message
Hey Andrew,
Are you sending your logs to a UNIX box, or running a ported version
of grep/egrep for windows?
 
Mike


From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Colbeck, Andrew
Sent: Thursday, June 16, 2005 17:34
To: sniffer@SortMonster.com
Subject: RE: [sniffer] Spam blocks loading me up with spam

I haven't noticed this spam leaking through, but at your prompting I did a:
 
egrep ".+From: .+To: .+IP: 200\.49\." dec0616.log
 
and saw about 46.  A glance through these to:from:ip: lines definitely shows messages that fit your description, along with messages that don't (I'm deliberately looking at the 16 bit subnet) and I see messages today from:
 
200.49.37.0/24
200.49.44.0/24
 
in addition to the blocks you listed, and a spot check of two of them did not turn up any hits with sniffer.  Total volume was low, at less than 50 messages.
 
One other interesting comment that I can add is that I'm seeing them use VERP like MAILFROM addresses, e.g.:
 
 
Of course, jsmith and example.com are not the actual text, but the recipient at my domain.
 
Andrew 8)
-----Original Message-----
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Scott Fisher
Sent: Thursday, June 16, 2005 3:04 PM
To: sniffer@SortMonster.com
Subject: [sniffer] Spam blocks loading me up with spam

 
Am I the only one getting blasted by these spam from these IP blocks? Sniffer seems a little behind on catching these.
 
200.49.48.0/24  200.49.48.0/24     
200.49.49.0/24  200.49.49.0/24  mowz2.com  
200.49.50.0/24  200.49.50.0/24  qckcstmr.com  
200.49.51.0/24  200.49.51.0/24  srvdupfrsh.com  
200.49.52.0/24  200.49.52.0/24  aahtv.com  
200.49.53.0/24  200.49.53.0/24  aakai.com  
200.49.54.0/24  200.49.54.0/24  aakib.com  
200.49.55.0/24  200.49.55.0/24  aakli.com  
200.49.56.0/24  200.49.56.0/24  aafix.com  
200.49.57.0/24  200.49.57.0/24  aaaae.com  
200.49.58.0/24  200.49.58.0/24      
200.49.59.0/24  200.49.59.0/24    
 
Domain names and links seem to be five chars beginning with aa. They also seem to be progressing through the IP blocks.  
 
i think they started in on the June 15th and have been spamming pretty consistantly.

Reply via email to