Saturday, January 24, 2009

Spammers 1/24/2009

Road Runner is definitely the champion of spam if you view the traffic from the past few weeks. It seems that whomever is generating the Road Runner spam is randomly generating email addresses to try to find addresses that are not in use. It seems like they take an address that was once valid and alter it slightly to come up a with a new address.

For instance might become or

This kind of goes back to my idea that someone is trying to find addresses that are NOT valid on a network and send emails around that won't get to a legitimate end user but allows the "spammers" to filter these messages through the Internet. Is this some kind of covert messaging?

Another possible reason I conjured up was that perhaps they are taking previous email addresses that are now being rejected (with the help of Postini) and altering them to try to figure out what the address has changed to. Not sure - just imaging the reasons.

Or perhaps they are looking for unused addresses to try to use those addresses on unsecured mail systems to hijack the business of the other company.

As for Joe's Datacenter - someone responded to one email telling me they have gotten rid of the customer causing the spam. However it seems like the spam is not one customer but filtering through their different customers and IP ranges. Has one master device or computer been hacked? Is someone internally who supports all these systems generating this spam? Are the servers not patched and up to date? Who knows.

At any rate here are some spammers for the week:
OrgName: Global Net Access, LLC
NetRange: -
Sat, 24 Jan 2009 14:41:37 -0800 (PST)
Sat, 24 Jan 2009 12:18:18 -0800 (PST)
Fri, 23 Jan 2009 09:15:20 -0800 (PST)
OrgName: Road Runner HoldCo LLC
NetRange: -
Sat, 24 Jan 2009 13:10:33 -0800 (PST)
OrgName: R & D Technologies, LLC
NetRange: -
Sat, 24 Jan 2009 12:41:39 -0800 (PST)
Sat, 24 Jan 2009 18:16:19 -0800 (PST)
Sat, 24 Jan 2009 22:23:51 -0800 (PST)
Sun, 25 Jan 2009 08:47:30 -0800 (PST)
Aarons.Net JOESDATACENTER (NET-208-94-240-0-1) -
DataTran Systems, LLC. JDC-CUST-1173-240-209 (NET-208-94-240-208-1) -
Sat, 24 Jan 2009 08:16:38 -0800 (PST)
Aarons.Net JOESDATACENTER (NET-208-94-240-0-1) -
Provectus, Inc JDC-CUST-1101-244-1 (NET-208-94-244-0-1) -
Fri, 23 Jan 2009 21:12:19 -0800 (PST)
OrgName: Turnkey Internet Inc.
NetRange: -
Fri, 23 Jan 2009 21:12:19 -0800 (PST)
Fri, 23 Jan 2009 03:26:19 -0800 (PST)
OrgName: Oxford Networks
NetRange: -
Thu, 22 Jan 2009 23:29:46 -0800 (PST)
Affinity Internet, Inc AFFINITY-207-36-0-0 (NET-207-36-0-0-1) -
Affinity Dedicated AFFIN-DED-207-36-0 (NET-207-36-0-0-2) -
Sun, 25 Jan 2009 00:33:59 -0800 (PST)
OrgName: Curatel, LLC
NetRange: -
Sun, 25 Jan 2009 01:25:16 -0800 (PST)
OrgName: Abacus America Inc.
NetRange: -
Sun, 25 Jan 2009 07:24:03 -0800 (PST)

NOTE: Abacus America has long been in the spammer IP range list - for years I have seen them send spam to my accounts. What is up over there?
OrgName: PSINet, Inc.
NetRange: -
Sun, 25 Jan 2009 12:20:43 -0800 (PST)

NOTE: Cogentco is another network range that is notoriously generating spam of all kinds - from garbage traffic on my web server using various bots to spam in my in box. They are on the Performance Systems International network.
OrgName: Travail Systems, LLC
NetRange: -
Sun, 25 Jan 2009 12:22:13 -0800 (PST)

Travail Systems continues to spam - repeatedly.

Mzima Networks, Inc. NETBLK-MZIMA-04 (NET-67-201-0-0-1) -
Sirius Telecom MZIMA04-CUST-SIRIUSTELE04 (NET-67-201-20-0-1) -
OrgName: RackVibe LLC
NetRange: -
Sun, 25 Jan 2009 13:48:01 -0800 (PST)