Categories: links, linux, programming, python, snark, solaris, spam, sysadmin, tech, unix, web.
|
2007-09-15 Weekly spam summary on September 15th, 2007This week, we:
Volume is down a fair bit from last week, although it is nowhere near the levels I would like it to be at. The daily volume stats show major swings throughout the week:
Kernel level packet filtering top ten: Host/Mask Packets Bytes 206.123.109.0/27 23682 1306K otcpicknews.com 68.230.240.0/23 18260 887K cox.net 72.249.13.81 15825 870K 213.29.7.0/24 11265 676K centrum.cz 71.85.201.136 10054 603K 207.188.79.237 7854 388K 62.105.78.18 6290 302K 67.78.182.166 6090 292K 62.105.73.23 5684 341K 67.101.244.202 5181 249K Volume is actually down a bit from last week, somewhat to my surprise, apparently because the top sources this week weren't as active as the top sources last week. Also, rather to my shock, most of the webmail advance fee fraud netblocks have fallen out of the top ten.
Connection time rejection stats:
192650 total
106734 bad or no reverse DNS
75182 dynamic IP
7801 class bl-cbl
679 class bl-pbl
346 class bl-dsbl
165 class bl-sdul
91 class bl-njabl
90 qsnews.net
68 71.6.140.0/24
43 class bl-sbl
The 71.6.140.0/24 subnet belongs to something called 'Bushido Marketing', bushidomarketing.com. Due to various events we have decided that we are not interested in accepting email from them; looking at the list of domain names trying to talk to us, I don't think we're missing anything we want. You would think that people want to have their email accepted would pick better domain names than easyinternetdeal.com, newmoneyonline.com, and hotbusinessforyou.com. The highest source of SBL rejections this week is SBL48694 with 10 rejections, who return from third place last week. Sixteen of the top 30 most rejected IP addresses were rejected 100 times
or more this week; the leader is 58.34.210.69 (250 rejections), followed
by 88.241.170.220 (214 rejections) and 201.220.91.208 (206 rejections).
Twenty of the top 30 are currently in the CBL, one is currently in
(Locally, 22 were rejected for bad or missing reverse DNS, 7 for being dynamic IP addresses, and one for being versanet.de.) This week Hotmail had:
And the final numbers:
The leading source of bad Bad bounces were sent to 105 different bad usersnames this week, with
the most popular one being a tie between This week's most active single source is the informatively named
|
These are my WanderingThoughts GettingAround This is part of CSpace, and is written by ChrisSiebenmann. * * * Atom feeds are available; see the bottom of most pages. Categories: links, linux, programming, python, snark, solaris, spam, sysadmin, tech, unix, web |