Re: Persistant worm sender

"Mike Easter" <[email protected]>
Newsgroups gmane.mail.spam.spamcop.email
Organization SpamCop
Message-ID <[email protected]>
Turan Fettahoglu wrote:
> I keep on receiving one or two worm e-mails like this. It comes from a
> Nigerian address and contains a Bagle worm.

It comes from a .ng IP address

> SpamCop says this address is listed.

The IP address is listed all over the place, including spews, which
indicates that the provider is unresponsive.

> The complaint address seems to be the sender's address.

I don't know what you mean by that.  But I don't think the information
which SC is using is very good.

> What would be
> a reasonable address for a complaint - without exposing oneself to
> the sender? It seems to be the revenge of a Nigerian scam artist.

Almost never is a virmail or virm [virus worm email] an intentional
mailing.  They are almost universally due to an infected propagation.
The problem is whether or not you are able to notify a responsive
provider for the IP address.

> Received: from dorinet4.com ([213.181.81.242])

Sourceline.

213.181.81.242  no rDNS

whois -h whois.ripe.net 213.181.81.242 ...
inetnum:      213.181.64.0 - 213.181.95.255
org:          ORG-BL4-RIPE
netname:      NG-BROADBANDTECH-20000327
descr:        BT Limited
admin/tech-c  IO243-RIPE
e-mail:       [email protected]
e-mail:       [email protected]

SC sez [email protected]

I disagree with the SC notify.  That is not a good notify for that
netblock.  Neither of those domainnames belong in that netblock and also
the IP address is known to be non-responsive.

You should look for alternate notifies while also notifying both of
those admin/tech addies.  Notice also that BT Limited in there.

Here's some more information on one of the admin/tech contacts:

person:       Israel Oyeleke
address:      BT Limited
e-mail:       [email protected]
nic-hdl:      IO243-RIPE
notify:       [email protected]
changed:      [email protected] 20010605
changed:      [email protected] 20030917

So, my first strategy would be to include the abuse addies for btlimited
as well as Israel's btlimited addy

whois -h whois.abuse.net btlimited.com ...
[email protected]   [email protected]
[email protected]

Then, I might consider also evaluating the ASN provider for the IP using
radb and cymru

whois -h whois.radb.net 213.181.81.242 ...
route:              213.0.0.0/8
descr:              REACH (Customer Route)
tech-c:             RRNOC1-REACH
origin:             AS23649

whois -h whois.cymru.com 213.181.81.242 ...
ASN     | IP               | Name
16422   | 213.181.81.242   | NEWSKI New Skies Networks, Inc

There's that newskies information again.  I like that better than Reach.
I'm going for abuse.net on newskies

whois -h whois.abuse.net newskies.com ...
[email protected]  [email protected]   [email protected]
[email protected] (for newskies.com)

So, I would notify all of the admin/tech contacts for the ripe IP block
[email protected] & [email protected]
plus all of the abuse.net for newskies, which includes the same addies
as for btlimited.  I don't think it does any good to go upstream for
something like a provider not doing anything about virm propagations.
However, if you want to go up from newskies because the IP is listed in
spews and numerous other db/s for being unresponsive, that's up to you.

-- 
Mike Easter
kibitzer, not SC admin
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.