Sobig.F spam-style source IP

G

Guest

For what its worth to anyone tracing this stuff,
the IP address 68.57.109.238 was sending sobig.F bulk-email
on Wed 20 Aug 2003 using my address as a faked envelope.
That's from within the comcast.net domain and I can't
think of anyone I know or who knows me who would have me
in their address book inside comcast.net but I do get a
fair bit of SPAM so it is evidence that there is some
link between sobig and spam address lists.

see here... http://www.triode.net.au/~telford/virus-spam.txt

Hopefully the sobig author gets careless and uses an IP
with high-grade logging so they get traced home... one can
only hope. Maybe sobig.F just got lucky and managed to infect
a spammer's machine, maybe there are so many spammers on the
internet these days that this happens often *shrug*.

Readers with lots of imagination and free time may want to
look at my rambling discussion of a system to replace emails
and newsgroups with something that is more difficult to
spam-up:

http://www.triode.net.au/~telford/strew/strew.html


- Tel
 
G

Gabriele Neukam

On that special day, (e-mail address removed),
([email protected]) said...
Hopefully the sobig author gets careless and uses an IP
with high-grade logging so they get traced home... one can
only hope.

Just today I read that Sobig.F had been kind of injected over Easynews
into Usenet groups, and that the Easynews account was created with a
stolen credit card number.

http://www.easynews.com/press.html

Now if that isn't criminal behaviour, what else is it?


Gabriele Neukam

(e-mail address removed)
 
S

Splash

We've had over 35,000 attempts to relay such mail through one of our
servers during the past 48 hours, despite having mail relaying disabled.
They all seem to be coming from about a dozen or so IP addresses and
many use a fake envelope address ending in .tw

Successful methods to combat:
1) IP address blocking on the router
(The sender seems to overcome this fairly quickly by using a
different IP)
2) GWAVA for Novell GroupWise
(With the correct filters applied, this seems to be 100% effective)
(Only for users of Novell GroupWise)
(Unsuitable for users of Mickey Mouse Microsoft email solutions !)
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top