Translate

Posts mit dem Label Spamhaus werden angezeigt. Alle Posts anzeigen
Posts mit dem Label Spamhaus werden angezeigt. Alle Posts anzeigen

4/27/2014

What is Snowshoe Spamming ?

Snowshoe spamming is a spamming procedure in which the spammer (mostly a Spambot) uses a wide range of IP addresses in order to spread out the prepared spam load. The large spread of IP addresses makes it difficult to identify and trap the spam from where its originating from, allowing at least some of it to reach email inboxes. For companies which specialize in trapping spam, Snowshoe Spamming is particularly harmful, because it is difficult to trap it with traditional spam filters.


Like a snowshoe spreads the load of a traveler across a wide area of snow, snowshoe spamming is a technique used by spammers to spread spam output across many IPs and domains, in order to reduce reputation metrics and evade filters. Snowshoes are designed to spread a large weight across a wide area so that the wearer does not break through crusts of snow and ice, as snowshoe spam distributes a broad load of spam across a varied array of IP addresses in much the same way.

IP addresses in the United States were responsible for almost 27% of snowshoe campaigns

Like all spammers, snowshoe spammers anticipate that some of their unwanted emails will be trapped by spam filters. Snowshoe spamming gives more email a chance at getting through to an inbox, where it can reach a computer user.

Setting up a snowshoe spamming operation requires some resources and knowledge, as the spammer must have access to an array of IP addresses. Snowshoe spammers typically use an assortment of domains, which may be linked to different servers and providers to further spread the spam load. In a sampling of emails sent by a snowshoe spammer, repeating IP addresses are fairly rare, which means that filters must focus on the content, rather than the sender, to trap spam.

Legitimate providers of email services use a very narrow range of IP addresses for sending email. This is generally viewed as a mark of integrity, as is the use of clear disclosure about who owns the originating domain. By contrast, snowshoe spamming often involves domains which are hidden behind layers of anonymity, making it difficult to track down the owner and report abuse. Especially in nations with anti-spam legislation, tracking down the parties responsible for spam, spyware, and other malicious activities can be extremely difficult, because perpetrators are good at covering their tracks.

Several anti-spam attempts have focused on targeting specific domain registrars and hosts. Certain registrars are infamous for harboring spammers, and by identifying large numbers of spam sites in their client lists, anti-spam advocates hope to take down those sites or humiliate the registrar into tightening its terms of service. Snowshoe spamming sometimes exposes a systemic problem with a particular host, as anti-spam advocates realize that large amounts of spam originates from domains managed by the same company.

Snowshoe spam accounted for all but about 5% of spam from the U.S. top 10
Snowshoers use many fictitious business names (DBA - Doing Business As), fake names and identities, and frequently changing postal dropboxes and voicemail drops. Conversely, legitimate mailers try hard to build brand reputation based on a real business address, a known domain and a small, permanent, well-identified range of sending IPs. Snowshoers often use anonymized or unidentifiable whois records, whereas legitimate senders are proud to provide their bona fide identity.

Some showshoers use tunneled connections from their back-end spam cannon to the spam egress IP. The back-end IP address is not in the spam headers. ISPs, you are in a position to detect those back-end spam cannons by checking where traffic flows are coming from. Remember, the tunneled connection is not necessarily on port 25. Spamhaus always appreciates such information.

http://www.spamhaus.org/faq/section/Glossary#233

3/09/2014

RECENT DETECTION: alkhaleejperfumes.com
Redirects with Trojan.JS.Redirector.aaw to Russian (Perfume)-Phishing
Russian Federation & United States


MALWARE: Trojan.JS.Redirector.aaw
(PERFUME PHISHING)

DOMAIN:
http://alkhaleejperfumes.com/
  • https://www.virustotal.com/de/url/4bba656a716030859df99c8ecb9dd5dee4a6ba47fd1e8ddb8e80fdbf0eb4ccf9/analysis/1394391837/
Trojan.JS.Redirector.aaw
  • https://www.virustotal.com/de/file/709c7765d82d32cdfa2654b58703b439a41b8e75d88d8ed31026c469264b98b4/analysis/1394391738/
--->

Spamhaus DROP Listed Traffic Inbound group 5
http://91.239.15.61/google.js
  • https://www.virustotal.com/de/url/afcd08ea9a1a624f0151b849b1d1b3d92be1aa89624c7ca7aa621122e71d7182/analysis/1394392195/
OTHER IP:
http://205.251.156.146/
  • https://www.virustotal.com/de/url/6ff1953bbfa5881e8ea13c832d049bca05ea53875180e59abf9dd53b872e4aa1/analysis/1394392398/
  • https://www.virustotal.com/de/ip-address/205.251.156.146/information/

1/28/2014

SPAM:
www.globalcitybusiness.com (LISTED AT DBL SPAMHAUS) &
www.streamlife.de (GERMANY)

Dieser Newsletter ist kein SPAM. Sie erhalten ihn, weil Sie bei
ihrer Anmeldung bei uns bzw. auf unserer Partnerseite dem
Newsletterempfang zugestimmt haben.

Die Angebote sind Anzeigen der jeweiligen Werbekunden, die für den Inhalt verantwortlich sind. Bei Fragen zum Inhalt, wenden Sie sich bitte an den Anbieter und nicht an die Adress Butler Ltd. da diese ausschliesslich der technische Versender dieser Nachricht ist!
Bitte antworten Sie nicht direkt auf diese E-Mail, da diese nicht zugestellt werden kann.

Technischer Versender der E-Mail ist die AdressButler Ltd,
Karl-Heinz-Beckurts-Str. 13, 52428 Jülich
Selbstverständlich können Sie der Nutzung Ihrer Daten jederzeit wiedersprechen. Sie wünschen keine weiteren Informationen,
klicken Sie bitte hier um sich abzumelden.
http://www.globalcitybusiness.com/unsubscribe.php

POTENTIALLY MALICIOUS SPAM DOMAIN(s): 
SCAM, PHISHING ETC. (LISTED AT SPAMHAUS)
www.globalcitybusiness.com
  • https://www.virustotal.com/de/url/111618ab5b6305880338fff2038a6dbdd5007efe2b7ae7886a91a25fb04cc1d9/analysis/1390927191/
www.globalcitybusiness.com/link.php
  • https://www.virustotal.com/de/url/352dbbd057b010a71041a76563b676358c7b98297fba1fda87b24f0386bb7b24/analysis/1390927504/
  • https://www.virustotal.com/de/file/23d32b79f3e71e41c2eb3d8811f58f72a2b6b5eb04c0981f16f61ab009945054/analysis/1386786113/
www.globalcitybusiness.com/open.php
  • https://www.virustotal.com/de/url/7a7a15b5d7f022340d21f099685c49ea8ff4f291b190d7ecb5cdd6417c8fa46d/analysis/1390927570/
  • https://www.virustotal.com/de/file/dd5bdccb831d1b19c505bd3e67553f6049cea2e20dba7eb231a02ed0103e521f/analysis/1390580473/
www.globalcitybusiness.com/unsubscribe.php
  • https://www.virustotal.com/de/url/a52381179dbe95f686a83ef039f938f62d3ddd1ac90c0898d1ed898f4cbf3745/analysis/1390927632/
  • https://www.virustotal.com/de/file/baefeec3f91b70b39b03c556d29dd1ad4eff87fe7bb0ba91fc3b774e70089281/analysis/1386768007/
  • http://www.urlvoid.com/scan/globalcitybusiness.com/
LISTED AT SPAMHAUS (DBL): 
(and not without reason, as they state in the e-mail: THIS IS NO SPAM)
  • http://www.spamhaus.org/query/domain/globalcitybusiness.com
 
E-Mail SS (ScreenShot)

www.streamlife.de
  • https://www.virustotal.com/de/url/87771b9dd41a23e777709022835837a7f32da2b361c54e3f6805bc6a9c554312/analysis/1390934550/
  • https://www.mywot.com/en/scorecard/streamlife.de
  • http://www.urlvoid.com/scan/streamlife.de/

1/20/2014

Category MALICIOUS DOMAIN & IP:
newquickonline.com & 66.111.239.213
"Comment Devenir Riche ?" (How getting Rich ?)
PHISHING, SCAM, SPAM


Salut, ce secret me rend malade
et je ne peux plus le garder pour
moi uniquement. J'ai donc decidé
de le partager avec vous, vous
allez découvrir comment des
centaines de personnes sont devenu
riche avec...

Ce système est très simple et un
enfant de 10 ans pourrait l'appliquer
sans aucune connaissance.

Allez je ne vous fait pas plus
attendre et je vous donne les
explications maintenant

Cliquez ici pour accèder au site>>>


Tenez-moi informe svp et si
besoin revenez vers moi.

How will i get rich...

Screenshot from newquick.blablabla SPAM-Mail
MALICIOUS DOMAIN: PHISHING, SCAM, SPAM
newquickonline.com
  • https://www.virustotal.com/de/url/8dc180690322fb938db7d494d01be61b662bd29f4bdf29833ba7ad15d15aeedb/analysis/1390244230/
HTML:
  • https://www.virustotal.com/de/file/faf4a27477bc73e59cb23ca28c0a2f7e8c0e687b380a14bf587118be749b52e0/analysis/1390244772/
  • http://jsunpack.jeek.org/?report=ec57c2558a8d13640f7875169e82616b25fab79e
newquickonline.com/unsubscribe.php
  • https://www.virustotal.com/de/url/995fa55fb73aa1d432a8a14dc9f517d0c8cb1ada8f5697b785f118f9fffce323/analysis/1390245841/
  • http://zulu.zscaler.com/submission/show/f38f148811a55cb99c4cc61af4b3b92c-1390244259
  • https://www.mywot.com/en/scorecard/newquickonline.com
  • http://www.urlvoid.com/scan/newquickonline.com/
LISTED AT SPAMHAUS:
  • http://www.spamhaus.org/query/domain/newquickonline.com
LISTED AT SURBL:
  • http://www.surbl.org/surbl-analysis
-----------------------------------------------------------------------------------------------------------------------------------

IP: 66.111.239.213
  • https://www.virustotal.com/de/url/7ea04d745a797e563f76710b1962e6d1c712eebead72ce2e17d17669a9cf1ebf/analysis/1390246347/
LISTED AT SPAMHAUS (SBL):
  • http://www.spamhaus.org/query/ip/66.111.239.213

Email Reputation: POOR
WEB Reputation: POOR

  • http://www.senderbase.org/lookup/?search_string=66.111.239.213


1/17/2014

Czech Republic: danika84.sololocalsaresexxy.com
Malicious Site
JS:ScriptIP-inf [Trj]

MALICIOUS DOMAIN:

danika84.sololocalsaresexxy.com
  • https://www.virustotal.com/de/url/7f0b85f39adbfe3f92daf236dc37be72dedb609890a3d0d1d7ec0088a1487d66/analysis/1389911621/
JS:ScriptIP-inf [Trj]
  • https://www.virustotal.com/de/file/8d2eb1bd576bd55c50cd0d6f5d2dec328fffb5ec9fd6e4bf990ff381e3631896/analysis/1389951479/
THE DOMAIN IS LISTED AT SPAMHAUS (DBL):
  • http://www.spamhaus.org/dbl/removal/record/sololocalsaresexxy.com
SEE ALSO:
  • http://zulu.zscaler.com/submission/show/484ac89dce0dd04b3e7626fb8a3a821a-1389911691

12/02/2013

Manchester SCAM from: Charles Morgan - charlesmorgan1963@yahoo.co.uk



Mr. Charles Morgan wrote on November 11th 2013:

"Hello,

Thank you so much for your response to my proposal. Good fortune has blessed you with a name that has planted you into the centre of relevance in my life. I want you to know that this transaction will be 100% legal and legitimate. Such opportunities only come ones' way
once in a lifetime. I cannot let this chance pass me by, for once I find myself in total control of my destiny. These chances won’t pass me by. You should not have anything to worry about, I will do everything legally required to ensure that the project goes smoothly, it shall pass through all Laws of International Banking, and you have my word. The attorney will prepare the necessary Affidavits which shall put you in place as next of kin; he will obtain the necessary clearances from the UK authorities which will cover all the aspects involved in this transaction.

The attorney shall be handling all matters of probate on your behalf, he will have
all the documents perfected, and with these documents he shall come forward to my bank to apply for the immediate release and transfer of the funds to the account you shall open. I have been a banker for many years and I know perfectly how the system works. I can assure you that you will not in any way regret your involvement with me. We can do this if we join our hands together and work in good faith. Firstly I want to assure you that this transaction is 100% risk and hitch free and also you will need to assure me that I will have unlimited access to my 50% of the funds (US$9M) once the funds has been transferred into your account because the funds is going to be transferred into your account and not mine so you are the one to assure me that you will give my own part to me. In light of the above,

I will need you to provide me with the following details.
Your name and address in full.
Your home telephone and office telephone numbers.
Your fax numbers.
A detailed profile of yourself and
company if any.
A valid identification

As soon as I get the information I will have my lawyer go ahead to procure the relevant documents which will confirm you with the rights of the next of kin to deceased and as such I requested your information above as this documents will be documented at the probate office here in London so as to give this venture legal backing and authenticity. Upon receipt of this information the lawyer would go ahead and procure this documents and as soon as we have
secured the documents, I will help you make official application to my bank on the strength of the documents that the funds should be released to you as the bona-fide next of kin to the  deceased Immediately the document is ready and approved by my bank, it will be forwarded to the bank that is presently with the funds to release the funds to you as the bonafide next of  kin, You need not to worry as I would use my position to facilitate the approval and the subsequent release of the funds to you. I am now in contact with a foreign online bank; I now intend that you open an account in your name in this foreign bank. The money would be transferred to your account which you will open in the bank for both of us, this is the best way, I have found, it will protect us from my bank. I want us to enjoy this money in peace when we conclude, so you should listen to my instructions and follow them religiously. Also You have to know that I cannot
transfer this money in my name as my bank will be aware that it is from me, this is where I need you.

As result of this, you will have to open an account in the corresponding bank. I will obtain a certificate of deposit from this my bank, it will be issued in your name, this will make you the bonafide owner of the funds. After this, the money will be banked online for both of us. We can then instruct the bank to transfer our various shares into our respective home bank accounts. I will also perfect the documentations with the assistance of my attorney to give the transaction the legal right.

I wish to inform you that should you contact me via official channels; I will deny knowing you and about this project. I repeat, I do not want you contacting me through my official phone lines nor do I want you contacting me through my official email account. Contact me only through the numbers I will provide for you and also through this email address. I do not want any direct link between you and me. My official lines are not secure lines as they are periodically monitored to assess our level of customer care in line with our Total Quality Management Policy. Please observe this instruction religiously."

Looking forward to a good business
relationship with you and hoping to hear from you soonest my good friend.


Kind Regards,
Charles



Header Analysis Quick Report
Originating IP: 89.240.69.191
Originating ISP: Talktalk
City: Manchester
Country of Origin: United Kingdom
* For a complete report on this email header goto ipTRACKERonline 
IP:



11/25/2013

Spam Site(s) : www.irubyvivaclub.com & irubystarweb.com

Mit dem 200% Willkommensbonus von Ruby Palace müssen Sie nicht länger nur träumen.

Melden Sie sich heute noch an, um dieses einmalige Angebot zu nutzen und Ihr Guthaben wird im Handumdrehen dreimal so attraktiv sein - jede Menge Spielfreude ist garantiert.

Links go to VT Analysis
http://www.irubyvivaclub.com/ REDIRECTS TO:
http://www.irubycasinogame.com/



Es wird (ZUVIEL) oft gesagt, dass aller guten Dinge drei sind. Dies ist Ihre Chance, Ihrem Guthaben etwas Gutes zu tun.

Mit freundlichen Grüßen

Ruby Palace Support
----

Bitte klicken Sie hier, um unseren gesamten E-Mail-Service abzubestellen:
http://unsubscribe.irubystarweb.com/ 

PLUS Undemanded Download of Malware:
http://irubycasinogame.com/rubyPalace_setup_DE.exe


E-Mail Screenshot:

 

IP(s):
1) IP 178.175.99.240 is double listed at Spamhaus.org.
See: http://www.spamhaus.org/query/bl?ip=178.175.99.240


2) IP 188.65.211.137 (www.irubyvivaclub.com) is listed at Spamhaus.org.


3) IP 91.239.15.222 (www.irubycasinogame.com) is double listed at Spamhaus.org
"Dirty network: VympelStroy ltd."

4) IP 195.2.77.153 (unsubscribe.irubystarweb.com) connected to Spamhaus.org:
Header Analysis Quick Report
Originating IP: 178.175.99.240
Originating ISP: Ptk Ip/mpls Network
City: Gjakovë
Country of Origin: Serbia
* For a complete report on this email header goto ipTRACKERonline

Read also this article @ Krebs on Security: Stophaus vs. Spamhaus

11/21/2013

419 SCAM OF THE DAY: 41.138.97.161
(Mrs. Linda Adama from Burkina Faso)

Mrs. Linda Adama from Burkina Faso wrote:

"Dear Friend,
Greetings to you and your family; However, it's just my urgent need for foreign partner that made me to contact you for this transaction. I work in Bank of Africa foreign department. I want to place your name as the beneficiary to Ten Million Five Hundred Thousand United States Dollars (USD10.5M).
The said funds is right here in the bank, it's the balance deposited funds by one of our late customer from France Mr. Paul Louis Halley since then nobody has come up for the claim. Therefore, I solicit for your cooperation to collaboration with me to have this done; it will be transferred into an account you will provide any where of your choice.
If you are interested, please send me your full contact information as below and thereafter I will send to you text of application form to apply for the fund next of kin (Beneficiary). "
Expecting your urgent reply!
1. Full name:.........
2. Current Address:.........
3. Telephone N=B0:...........
4. Occupation:.............
5. Copy of your identity...
6. Age:............
7. Country:........
          Yours trulyMrs. 
          Linda Adama

Screenshots:




Malicious IP:      41.138.97.161

Spamhaus.org
Dictionary Attacker & More
- Reputationauthority.org
- LOOK UP


Header Analysis Quick Report
Originating IP: 41.138.97.161
Originating ISP: Onatel/fasonet's
City: n/a
Country of Origin: Burkina Faso
* For a complete report on this email header goto ipTRACKERonline