Skip to content

Archives

Record for most blocked host on the ‘net

Wow. I think this is the most blocklist hits I’ve ever seen in a mail… the open relay 61.159.235.36 is listed in a whole 19 DNS blocklists.

  • T_RCVD_IN_DEADBEEF (0.0 points) RBL: T_RCVD_IN_DEADBEEF RBL A check: found 36.235.159.61.bl.deadbeef.com., type: 127.0.0.2
  • RCVD_IN_NJABL (1.2 points) RBL: Received via a relay in dnsbl.njabl.org RBL A check: found 36.235.159.61.dnsbl.njabl.org., type: 127.0.0.9
  • RCVD_IN_OSIRUSOFT_COM (0.5 points) RBL: Received via a relay in relays.osirusoft.com RBL A check: found 36.235.159.61.relays.osirusoft.com., type: 127.0.0.9
  • RCVD_IN_UNCONFIRMED_DSBL (0.0 points) RBL: Received via a relay in unconfirmed.dsbl.org RBL TXT check: found 36.235.159.61.unconfirmed.dsbl.org., type: http://dsbl.org/listing?ip=61.159.235.36
  • T_RCVD_IN_WIREHUB_PROXIES (0.0 points) RBL: T_RCVD_IN_WIREHUB_PROXIES RBL A check: found 36.235.159.61.proxies.blackholes.wirehub.net., type: 127.0.0.2
  • T_RCVD_IN_GIPPER (0.0 points) RBL: T_RCVD_IN_GIPPER RBL A check: found 36.235.159.61.proxy.bl.gweep.ca., type: 127.0.0.1
  • T_RCVD_IN_WIREHUB_BH (0.0 points) RBL: T_RCVD_IN_WIREHUB_BH RBL A check: found 36.235.159.61.blackholes.wirehub.net., type: 127.0.0.2
  • RCVD_IN_DSBL (4.3 points) RBL: Received via a relay in list.dsbl.org RBL TXT check: found 36.235.159.61.list.dsbl.org., type: http://dsbl.org/listing?ip=61.159.235.36
  • RCVD_IN_BL_SPAMCOP_NET (0.0 points) RBL: Received via a relay in bl.spamcop.net RBL TXT check: found 36.235.159.61.bl.spamcop.net., type: Blocked – see http://spamcop.net/bl.shtml?61.159.235.36
  • T_RCVD_IN_SORBS (0.0 points) RBL: T_RCVD_IN_SORBS RBL A check: found 36.235.159.61.dnsbl.sorbs.net., type: 127.0.0.2
  • RCVD_IN_SBL (1.1 points) RBL: Received via SBLed relay, see http://www.spamhaus.org/sbl/ RBL TXT check: found 36.235.159.61.sbl.spamhaus.org., type: Listed on SBL – see http://spamhaus.org/SBL/sbl.lasso?query=SBL5950
  • RCVD_IN_OPM (4.3 points) RBL: Received via a relay in opm.blitzed.org RBL TXT check: found 36.235.159.61.opm.blitzed.org., type: open proxy – see http://blitzed.org/proxy/?ip=61.159.235.36
  • T_RCVD_IN_OSSOCKS (0.0 points) RBL: T_RCVD_IN_OSSOCKS RBL A check: found 36.235.159.61.socks.relays.osirusoft.com., type: 127.0.0.9
  • T_RCVD_IN_MONKEYS_UPL (0.0 points) RBL: Received via a relay in proxies.relays.monkeys.com. RBL TXT check: found 36.235.159.61.proxies.relays.monkeys.com., type: BLOCKED: See http://www.monkeys.com/upl/listed-ip-0.cgi?ip=61.159.235.36
  • T_RCVD_IN_OPM_HTTP_CONNECT (0.0 points) RBL: T_RCVD_IN_OPM_HTTP_CONNECT
  • T_RCVD_IN_SORBS_HTTP (0.0 points) RBL: T_RCVD_IN_SORBS_HTTP
  • T_RCVD_IN_FIVETEN_SPAM (0.0 points) RBL: T_RCVD_IN_FIVETEN_SPAM
  • T_RCVD_IN_OPM_HTTP_POST (0.0 points) RBL: T_RCVD_IN_OPM_HTTP_POST

Aha. looking it up, it’s in China. That explains it… Full message here.

Date: Thu, 17 Apr 2003 07:51:51 +0000
From: “HGH Free Sample” (spam-protected)
To: (spam-protected)
Subject: SPAM(40.60) Shed Weight While You Sleep with HGH hyvsjpilripyoiebf

This is a multi-part message in MIME format.

————=_3E9E19A5.69236551

Content-Disposition: inline

This mail is probably spam. The original message has been attached along with this report, so you can recognize or block similar unwanted mail in future. See http://spamassassin.org/tag/ for more details.

Content preview: As seen on NBC, CBS, CNN, and even Oprah! The health

discovery that actually reverses aging while burning fat.

Content analysis details: (40.60 points, 5 required) T_DATE_SPAMWARE_Y2K (0.0 points) Date header uses unusual Y2K formatting ADDR_FREE (0.8 points) From Address contains FREE RATWARE_EGROUPS (4.3 points) Bulk email software fingerprint (eGroups) foun d in headers FROM_ENDS_IN_NUMS (0.7 points) From: ends in numbers BANG_OPRAH (4.3 points) BODY: Talks about Oprah with an exclamation! SOME_BREAKTHROUGH (0.9 points) BODY: Describes some sort of breakthrough WHILE_YOU_SLEEP (2.6 points) BODY: While you Sleep REVERSE_AGING (2.9 points) BODY: Reverses Aging BANG_EXERCISE (2.7 points) BODY: Talks about exercise with an exclamation ! DIET (0.0 points) BODY: Lose Weight Spam AS_SEEN_ON (3.3 points) BODY: As seen on national TV! T_AS_SEEN_ON (0.0 points) BODY: /seenn\b\s*(?:TV|ABC|NBC|CBS|CNN|Op rah|USA Today|48 Hours|(The )?New York Times|\w+\s+TV|:)/i T_BLANK_LINE_RATIO_01_08_10 (0.0 points) BODY: T_BLANK_LINE_RATIO_01_08_10 HTML_50_60 (0.1 points) BODY: Message is 50% to 60% HTML BAYES_90 (2.9 points) BODY: Bayesian classifier says spam probabilit y is 90 to 99%

[score: 0.9050] HTML_MESSAGE (0.0 points) BODY: HTML included in message T_BLANK_LINE_RATIO_20_08_10 (0.0 points) BODY: T_BLANK_LINE_RATIO_20_08_10 T_BLANK_LINE_RATIO_04_08_10 (0.0 points) BODY: T_BLANK_LINE_RATIO_04_08_10 T_BLANK_LINE_RATIO_08_08_10 (0.0 points) BODY: T_BLANK_LINE_RATIO_08_08_10 HTML_TAG_BALANCE_HTML (0.0 points) BODY: HTML has unbalanced “html” tags T_MIME_QP (0.0 points) RAW: T_MIME_QP MIME_HTML_NO_CHARSET (0.0 points) RAW: Message text in HTML without specified charset FORGED_RCVD_HELO (1.0 points) Received: contains a forged HELO DATE_IN_FUTURE_03_06 (1.5 points) Date: is 3 to 6 hours after Received: date T_RCVD_IN_DEADBEEF (0.0 points) RBL: T_RCVD_IN_DEADBEEF

[RBL A check: found 36.235.159.61.bl.deadbeef.com., type: 12 7.0.0.2] RCVD_IN_NJABL (1.2 points) RBL: Received via a relay in dnsbl.njabl.org

[RBL A check: found 36.235.159.61.dnsbl.njabl.org., type: 12 7.0.0.9] RCVD_IN_OSIRUSOFT_COM (0.5 points) RBL: Received via a relay in relays.osiruso ft.com

[RBL A check: found 36.235.159.61.relays.osirusoft.com., typ e: 127.0.0.9]
RCVD_IN_UNCONFIRMED_DSBL (0.0 points) RBL: Received via a relay in unconfirmed .dsbl.org

[RBL TXT check: found 36.235.159.61.unconfirmed.dsbl.org., t ype: http://dsbl.org/listing?ip=61.159.235.36]
T_RCVD_IN_WIREHUB_PROXIES (0.0 points) RBL: T_RCVD_IN_WIREHUB_PROXIES

[RBL A check: found 36.235.159.61.proxies.blackholes.wirehub .net., type: 127.0.0.2] T_RCVD_IN_GIPPER (0.0 points) RBL: T_RCVD_IN_GIPPER

[RBL A check: found 36.235.159.61.proxy.bl.gweep.ca., type: 127.0.0.1] T_RCVD_IN_WIREHUB_BH (0.0 points) RBL: T_RCVD_IN_WIREHUB_BH

[RBL A check: found 36.235.159.61.blackholes.wirehub.net., t ype: 127.0.0.2]
RCVD_IN_DSBL (4.3 points) RBL: Received via a relay in list.dsbl.org

[RBL TXT check: found 36.235.159.61.list.dsbl.org., type: ht tp://dsbl.org/listing?ip=61.159.235.36] RCVD_IN_BL_SPAMCOP_NET (0.0 points) RBL: Received via a relay in bl.spamcop.ne t

[RBL TXT check: found 36.235.159.61.bl.spamcop.net., type: B locked – see http://spamcop.net/bl.shtml?61.159.235.36] T_RCVD_IN_SORBS (0.0 points) RBL: T_RCVD_IN_SORBS

[RBL A check: found 36.235.159.61.dnsbl.sorbs.net., type: 12 7.0.0.2] RCVD_IN_SBL (1.1 points) RBL: Received via SBLed relay, see http://www. spamhaus.org/sbl/

[RBL TXT check: found 36.235.159.61.sbl.spamhaus.org., type:

Listed on SBL - see http://spamhaus.org/SBL/sbl.lasso?query=SBL5950]

RCVD_IN_OPM (4.3 points) RBL: Received via a relay in opm.blitzed.org

[RBL TXT check: found 36.235.159.61.opm.blitzed.org., type: 

open proxy – see http://blitzed.org/proxy/?ip=61.159.235.36] T_RCVD_IN_OSSOCKS (0.0 points) RBL: T_RCVD_IN_OSSOCKS

[RBL A check: found 36.235.159.61.socks.relays.osirusoft.com

., type: 127.0.0.9] T_RCVD_IN_MONKEYS_UPL (0.0 points) RBL: Received via a relay in proxies.relays .monkeys.com.

[RBL TXT check: found 36.235.159.61.proxies.relays.monkeys.c

om., type: BLOCKED: See http://www.monkeys.com/upl/listed-ip-0.cgi?ip=61.159.23 5.36] T_RCVD_IN_OPM_HTTP_CONNECT (0.0 points) RBL: T_RCVD_IN_OPM_HTTP_CONNECT T_RCVD_IN_SORBS_HTTP (0.0 points) RBL: T_RCVD_IN_SORBS_HTTP T_RCVD_IN_FIVETEN_SPAM (0.0 points) RBL: T_RCVD_IN_FIVETEN_SPAM T_RCVD_IN_OPM_HTTP_POST (0.0 points) RBL: T_RCVD_IN_OPM_HTTP_POST MISSING_MIMEOLE (0.1 points) Message has X-MSMail-Priority, but no X-MimeOL E MIME_HTML_ONLY (0.1 points) Message only has text/html MIME parts HG_HORMONE (1.0 points) Talks about hormones for human growth T_MIME_HTML_NO_DOCTYPE (0.0 points) T_MIME_HTML_NO_DOCTYPE MISSING_OUTLOOK_NAME (0.0 points) Message looks like Outlook, but isn’t

The original message did not contain plain text, and may be unsafe to open with some email clients; in particular, it may contain a virus, or confirm that your address can receive spam. If you wish to view it, it may be safer to save it to a file and open it with an editor.

————=_3E9E19A5.69236551

Content-Description: original message before SpamAssassin
Content-Disposition: attachment

by localhost.jmason.org (Postfix) with ESMTP id 714158B318 for (spam-protected) Wed, 16 Apr 2003 23:03:54 -0400 (EDT)

by localhost with IMAP (fetchmail-5.9.0) for (spam-protected) (single-drop); Wed, 16 Apr 2003 20:03:54 -0700 (PDT)

From: “HGH Free Sample” (spam-protected)
To: (spam-protected)
Subject: Shed Weight While You Sleep with HGH hyvsjpilripyoiebf
Date: Thu, 17 Apr 03 07:51:51 GMT

This is a multi-part message in MIME format.

–8_0AED7_CBCE_D_E.1F.

<

p>

> As seen on

NBC, CBS, CNN, and even Oprah!

> The health

discovery that actually reverses aging while burning fat.

> Without dieting

or exercise!

<

p>

> Forget aging

and dieting forever!

> l, Helvetica, sans-serif”>Get

<

p> Your Free Bottle Now! Visit Us Here

<

p align=’3D”center”‘>  

<

p align=’3D”center”‘>  

<

p align=’3D”center”‘>  

<

p align=’3D”center”‘>  

<

p align=’3D”center”‘>  

<

p align=’3D”center”‘>  

 

 

Why was this email sent to you? At some point you registered or made a purchase on a Web site with privacy policies explaining that they may share your information with partners who will send you valuable offers from time to time.

If you no longer wish to be notified of th= e latest

scientific breakthroughs or valuable offers, you may simply choo= se to

take yourself out of the database permanently by choosing this link.

aumyfi flmpycuoji wv siskt u g jhuqxgtzvhftswxogtid xpypp

–8_0AED7_CBCE_D_E.1F.–

————=_3E9E19A5.69236551–