Wandering Thoughts archives

2005-10-30

Weekly spam summary on October 29th, 2005

This week we received 12,079 email messages from 226 different IP addresses. Our SMTP server handled 44,167 sessions from 4,794 different IP addresses. Session volume is up a bit compared to last week, but well within what I now consider normal fluctuations.

Because we rebooted this machine Monday evening, we're about 36 hours short on kernel-level and total connection volume stats (and I'm not going to bother with per-day breakdowns). We had 190,650 connections since Monday evening, from at least 30,420 different IP addresses; from Sunday to just before the reboot, we had 30,190 connections. A straightforward total would make this a fairly ordinary week.

Kernel level packet filtering top ten:

Host/Mask           Packets   Bytes
66.154.124.9          13678    766K
64.52.16.234          11451    535K
85.214.22.252          9863    473K
212.216.176.0/24       9416    478K
66.147.35.53           5457    255K
202.96.0.0/12          4856    263K
80.169.152.25          4443    213K
217.57.113.212         4401    264K
218.102.53.0/24        4327    200K
66.179.44.52           4232    203K

This week, chinanet.cn.net has clawed its way back into the top ten and 66.154.124.9 finishes out its third week in first place, earning 66.154.124.0/28, aka SBL24721, an entry in the permanent blocklist. So much for Surge Media.

  • 66.179.44.52 is the only other IP address returning from last week or indeed any previous week; it's been blocked for repeated bad HELO names.
  • 85.214.22.252 is on the ORDB.
  • 217.57.113.212 is an interbusiness.it 'dialup' address; we don't talk to interbusiness.it anyways, but we especially don't talk to anything that has a generic interbusiness.it hostname.
  • everyone else got blocked for repeated bad HELO names.

Connection-time rejection stats:

  26507 total
  11429 dynamic IP
   7076 bad or no reverse DNS
   2179 class bl-cbl
   1516 class bl-ordb
   1400 class bl-spews
    675 class bl-sbl
    651 class bl-dsbl
    533 Chinese spam involvement
    199 class bl-njabl
    128 class bl-sdul
     14 class bl-opm

Several machines made outstanding contributions to these stats this week. 85.214.22.252, already featured in the kernel level stats, added 405 to the ORDB count, along with 196.1.211.35's 260; 210.51.25.177 gave 444 to the 'bad rDNS' count, with 203.167.99.194 assisting for 207. Several machines in SBL24721 gave the SBL stats a nice assist, as you might guess, but no one really stands out for SPEWS.

what # this week (distinct IPs) # last week (distinct IPs)
Bad HELOs 18117 922 13278 731
Bad bounces 2985 1690 4038 2261

Interestingly, bad HELOs are up from last week but bounces are once again down. 64.52.16.234 HELO'd with a bad name 872 times this week before we blocked it (and then it made the top ten kernel filters list), but there aren't any other really big contributors.

Since I enjoy depressing myself, here are more Hotmail statistics:

  • one actual email accepted all week.
  • five Hotmail messages refused due to their originating IP addresses (three listed in the SBL, one from Gilat-Satcom, one from Nigeria).
  • 257 messages from Hotmail refused because they came from non-Hotmail email addresses.

Apparently our first set of Hotmail stats from two weeks ago were gathered during a slow week; Hotmail is now running only 0.4% 'email traffic we actually wish to accept'. If that.

spam/SpamSummary-2005-10-29 written at 00:54:43;


Page tools: See As Normal.
Search:
Login: Password:

This dinky wiki is brought to you by the Insane Hackers Guild, Python sub-branch.