Spam filter

ecampbell

Piney
Jan 2, 2003
2,889
1,029
For a week now I have been getting daily grouped spam with the title starting with one of my email account names “shopppp”. Sure I could filter “shopppp” but sometimes it’s legit.

spam.jpg


One day the sender will be “coupon code included” <jerking@firstgreenlawn.com>
Another Jennifer@greattreehotel.com , congenially@coveredpretzelssite.com and so on.

What’s going on here and can I filter a moving domain?

Return-Path: jennifer@greattreehotel.com
Received: from imta30.emeryville.ca.mail.comcast.net (LHLO
imta30.emeryville.ca.mail.comcast.net) (76.96.27.233) by
sz0109.wc.mail.comcast.net with LMTP; Sat, 6 Mar 2010 14:42:37 +0000 (UTC)
Received: from bus189.greenlawncenter.com ([68.168.32.189])
by imta30.emeryville.ca.mail.comcast.net with comcast
id pqic1d00a44pyLs0Wqic6s; Sat, 06 Mar 2010 14:42:37 +0000
X-CAA-SPAM: 00000
X-Authority-Analysis: v=1.1 cv=YyubQmonq14onws1AfBBhRiDSD1sciFRB/bSLlonDDU=
c=1 sm=1 a=zBFnpXEXi6cA:10 a=8nJEP1OIZ-IA:10 a=h8LeXreGpHCm8YdGc8J//Q==:17
a=DUgJsoLoAAAA:8 a=C_IRinGWAAAA:8 a=qTQDE_1Kehw9S61BOBIA:9
a=UzdhDAEnATs_FZK3pQ0A:7 a=ZxQyGD1icsWSMBuNW1rvbyuyF98A:4 a=wPNLvfGTeEIA:10
a=si9q_4b84H0A:10 a=h8LeXreGpHCm8YdGc8J//Q==:117
From: HW101.com <Jennifer@greattreehotel.com>
Subject: shopppp, Is Your Home at Risk? Find Out Now
MIME-Version: 1.0
Content-Transfer-Encoding: 8bit
Content-Type: text/html; charset="iso-8859-1"


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META http-equiv=Content-Type content="text/html; charset=iso-8859-1">
<META content="MSHTML 6.00.2900.2523" name=GENERATOR>
</HEAD>
<BODY>

Return-Path: lam@coveredpretzelssite.com
Received: from imta15.westchester.pa.mail.comcast.net (LHLO
imta15.westchester.pa.mail.comcast.net) (76.96.62.54) by
sz0109.wc.mail.comcast.net with LMTP; Fri, 5 Mar 2010 13:32:40 +0000 (UTC)
Received: from mamba.trunknetworks.com ([109.238.85.132])
by imta15.westchester.pa.mail.comcast.net with comcast
id pRYe1d01u2rJov90FRYfpD; Fri, 05 Mar 2010 13:32:40 +0000
X-CAA-SPAM: 00000
X-Authority-Analysis: v=1.1 cv=3r9ESkDpnBZOywlkrnwv1bvI+olQ2LiSLqPueafoPys=
c=1 sm=1 a=1z-HDNte3lkA:10 a=bC6GBUpkwlzFAcUAL0bdpg==:17 a=f27nk8QaAAAA:8
a=C_IRinGWAAAA:8 a=ZeVCbr9CrtjusU0XYQcA:9 a=puL8JCxYAi9UoYSi0n0A:7
a=UNmkm3wdb_RLWVf-xck3OF3ysNkA:4 a=si9q_4b84H0A:10
a=bC6GBUpkwlzFAcUAL0bdpg==:117
From: LASIK Vision Institute <lam@coveredpretzelssite.com>
Subject: shopppp, Lasik Special - Now Starting at $299 - Act Now
MIME-Version: 1.0
Content-Transfer-Encoding: 8bit
Content-Type: text/html; charset="iso-8859-1"


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META http-equiv=Content-Type content="text/html; charset=iso-8859-1">
<META content="MSHTML 6.00.2900.2523" name=GENERATOR>
</HEAD>
<BODY>


Ed
 

46er

Piney
Mar 24, 2004
8,837
2,144
Coastal NJ
You could try contacting their ISP's and file a complaint with them. If it is one of the bigger ones, it might help.

If you don't know the ISP, try this, should give you all you need, just enter the IP address of the eamil addy. When its done, click the 'table' tab.

http://visualroute.visualware.com/
 

Ben Ruset

Administrator
Site Administrator
Oct 12, 2004
7,619
1,878
Monmouth County
www.benruset.com
You get legitimate email with the word "shopppp" in the title? I'd just filter based off of that and be done with that. Complaining to an ISP won't help - I'd be a shiny nickel that those are being sent from a botnet, which means that it'd be pretty much near impossible to shut down.

Just filter and be done with it.
 

MarkBNJ

Piney
Jun 17, 2007
1,875
73
Long Valley, NJ
www.markbetz.net
You get legitimate email with the word "shopppp" in the title? I'd just filter based off of that and be done with that. Complaining to an ISP won't help - I'd be a shiny nickel that those are being sent from a botnet, which means that it'd be pretty much near impossible to shut down.

Just filter and be done with it.

This is embarrassing to admit, because I usually pride myself on running a pretty tight network, but with the kids getting older and other devices and whatnot I now have like 10 interfaces connected to the net from inside the house. Anyway, I let the virus protection on my wife's laptop expire and she got a really bad infection including a rootkit. For a couple of days the machine was doing whatever the botnet owners wanted it to, which was pretty much spam emails. Comcast sent me a notification that they had detected this activity and blocked port 25 at my modem, so they are watching, and reports to ISPs do filter back to the people responsible for the IP doing the spamming, at least some of the time. The problem is that they have tens of thousands of cpus hijacked (in some cases) and the load automatically shifts to other systems.

I would advise pretty much everyone to block port 25 at your home router. Most ISPs support port 587 with authentication, or 366 without, as alternatives. I ended up having to wipe my wife's system and rebuild it. Nothing I found could get that crap off her disk.
 
Top