Categories: links, linux, programming, python, snark, solaris, spam, sysadmin, tech, unix, web.
|
2007-06-30 Weekly spam summary on June 30th, 2007This week, we:
Volume is definitely up from last week. As the per day table illustrates, spammers seem to still prefer Wednesday for their big day:
Kernel level packet filtering top ten: Host/Mask Packets Bytes 213.4.149.12 48724 2534K 205.152.59.0/24 18437 836K bellsouth.net 206.123.109.0/27 17088 944K otcpicknews.com 68.230.240.0/23 16148 784K cox.net 68.167.174.246 12468 584K 199.239.248.157 11273 556K 68.168.78.0/24 10395 499K adelphia.net 64.191.86.69 5511 331K 208.108.197.97 4850 266K 209.16.79.66 4122 198K Here too volume is up from last week, although not as much.
Connection time rejection stats:
85848 total
48063 bad or no reverse DNS
30626 dynamic IP
5052 class bl-cbl
318 class bl-pbl
249 qsnews.net
164 dartmail.net
110 class bl-dsbl
96 class bl-sdul
85 class bl-sbl
42 216.75.6.0/24
30 class bl-njabl
The highest source of SBL rejections this week was technically 200.221.11.147 with 16 rejections, but their SBL record has already been removed; since this is zipmail.com.br, I will speculate wildly that they were listed for sourcing lots of advance fee fraud spam, which is certainly why we don't talk to them. After that was SBL56008 with 13 rejections and SBL53722 with 10 rejections; both of them seem to have been listed as advance fee fraud spam sources. Nine of the top 30 most rejected IP addresses were rejected 100 times or more; the champion is 202.61.62.248 (1,296 rejections), followed by 202.196.43.168 (750 rejections), 189.130.216.253 (437 rejections, bad), 189.130.216.241 (362 rejections), and 189.130.216.208 (178 rejections). All of them were rejected for bad or missing reverse DNS, but except for 202.196.43.168, of them are also on either or both of the CBL and the PBL. Thirteen of the top 30 are currently in the CBL, two are in the SBL (in
SBL55457 and
SBL52160, which
is a depressing March 22nd listing of a Chinese /18 for spammer hosting),
five are currently in (Locally, 22 were rejected for bad or missing reverse DNS, 4 for being dynamic IPs, and 4 for being various people we don't want to talk to.) This week, Hotmail had:
And the final numbers:
Things got bad this week. While I expected to find a big source or
two of bad Bad bounces were sent to 276 different bad usernames this week, with
the most popular one by far being
|
These are my WanderingThoughts GettingAround This is part of CSpace, and is written by ChrisSiebenmann. * * * Atom feeds are available; see the bottom of most pages. Categories: links, linux, programming, python, snark, solaris, spam, sysadmin, tech, unix, web |