Re: Persistant worm sender
"Mike Easter" <[email protected]>
| Newsgroups | gmane.mail.spam.spamcop.email |
|---|---|
| Organization | SpamCop |
| Message-ID | <[email protected]> |
Turan Fettahoglu wrote: > I keep on receiving one or two worm e-mails like this. It comes from a > Nigerian address and contains a Bagle worm. It comes from a .ng IP address > SpamCop says this address is listed. The IP address is listed all over the place, including spews, which indicates that the provider is unresponsive. > The complaint address seems to be the sender's address. I don't know what you mean by that. But I don't think the information which SC is using is very good. > What would be > a reasonable address for a complaint - without exposing oneself to > the sender? It seems to be the revenge of a Nigerian scam artist. Almost never is a virmail or virm [virus worm email] an intentional mailing. They are almost universally due to an infected propagation. The problem is whether or not you are able to notify a responsive provider for the IP address. > Received: from dorinet4.com ([213.181.81.242]) Sourceline. 213.181.81.242 no rDNS whois -h whois.ripe.net 213.181.81.242 ... inetnum: 213.181.64.0 - 213.181.95.255 org: ORG-BL4-RIPE netname: NG-BROADBANDTECH-20000327 descr: BT Limited admin/tech-c IO243-RIPE e-mail: [email protected] e-mail: [email protected] SC sez [email protected] I disagree with the SC notify. That is not a good notify for that netblock. Neither of those domainnames belong in that netblock and also the IP address is known to be non-responsive. You should look for alternate notifies while also notifying both of those admin/tech addies. Notice also that BT Limited in there. Here's some more information on one of the admin/tech contacts: person: Israel Oyeleke address: BT Limited e-mail: [email protected] nic-hdl: IO243-RIPE notify: [email protected] changed: [email protected] 20010605 changed: [email protected] 20030917 So, my first strategy would be to include the abuse addies for btlimited as well as Israel's btlimited addy whois -h whois.abuse.net btlimited.com ... [email protected] [email protected] [email protected] Then, I might consider also evaluating the ASN provider for the IP using radb and cymru whois -h whois.radb.net 213.181.81.242 ... route: 213.0.0.0/8 descr: REACH (Customer Route) tech-c: RRNOC1-REACH origin: AS23649 whois -h whois.cymru.com 213.181.81.242 ... ASN | IP | Name 16422 | 213.181.81.242 | NEWSKI New Skies Networks, Inc There's that newskies information again. I like that better than Reach. I'm going for abuse.net on newskies whois -h whois.abuse.net newskies.com ... [email protected] [email protected] [email protected] [email protected] (for newskies.com) So, I would notify all of the admin/tech contacts for the ripe IP block [email protected] & [email protected] plus all of the abuse.net for newskies, which includes the same addies as for btlimited. I don't think it does any good to go upstream for something like a provider not doing anything about virm propagations. However, if you want to go up from newskies because the IP is listed in spews and numerous other db/s for being unresponsive, that's up to you. -- Mike Easter kibitzer, not SC admin