Weekly spam summary on August 18th, 2007This week, we:
So much for any chance that volume would go down compared to last week. I believe that the higher session volume is at least partly because of compromised spam zombies getting past my relatively weak greylisting precautions.
The peak day may be migrating back to Wednesday, but really, all that seems reasonably apparent is that some spammers take weekends off. Kernel level packet filtering top ten: Host/Mask Packets Bytes 213.4.149.12 25371 1319K terra.es 68.230.240.0/23 19247 935K cox.net 213.29.7.0/24 17643 1059K centrum.cz 68.168.78.0/24 11520 553K adelphia.net 213.4.149.68 8350 484K 195.238.6.228 7739 371K 61.128.0.0/10 6192 342K China 85.114.132.50 5932 356K 62.94.0.34 4727 212K 200.63.215.74 4568 219K Volume here is down from last week, and not as many of the usual open webmail suspects have shown up.
Connection time rejection stats:
203098 total
96920 bad or no reverse DNS
91776 dynamic IP
10786 class bl-cbl
1121 class bl-pbl
264 class bl-sdul
264 class bl-dsbl
213 class bl-sbl
154 dartmail.net
48 acceleratebiz.com
46 officepubs.com
45 67.98.250.0/24
19 class bl-njabl
This is quite a volume increase over last week, almost all of it in the top four reasons. The highest source of SBL rejections this week is SBL57804, a /18 listed as a 'spam source range', with 66 rejections. Following it is SBL49824 )a /27 listed 27 January) with 21 rejections, and SBL52705 (85.114.132.50) with 19 rejections, and SBL55920 (another advance fee fraud spam source) with 17 rejections. Eighteen of the top 30 most rejected IP addresses were rejected 100 times
or more this week. The leader is 200.63.215.74 (2,259 rejections), followed
by 201.9.243.8 (644 rejections) and 190.65.82.107 (572 rejections).
Seventeen of the top 30 are currently in the CBL, seven are currently in
(Locally, 19 were rejected for bad or missing reverse DNS, 10 for being dynamic IP addresses, and one for being in the CBL.) This week, Hotmail had:
And the final numbers:
The leading source of bad Bad bounces were sent to 297 different bad usernames this week, with
the most popular one being |
These are my WanderingThoughts GettingAround This is part of CSpace, and is written by ChrisSiebenmann. * * * Atom feeds are available; see the bottom of most pages. Categories: links, linux, programming, python, snark, solaris, spam, sysadmin, tech, unix, web |