Seeing a marked increase in porn spam sent directly from AOL
accounts (and not simply spam with aol.com addresses forged
into the headers). This seems odd since it's been a _long_
time since I saw a spam actually from AOL. (I saw a total
of five in 2004, with the last one being in April. I've
seen the same number for January 2005...)
Anyone else seeing this? Wondering if someone at aol managed
to break something, or if this is the result of a new round of
spam trojan infestations... Most of them are porn spams for
sites hosted with chinese ISPs such as cnc-noc.net. No response
from AOL so far.
Sample header [1]
Return-Path: <zinn...@strathroy.com>
Received: from ACD60BE2.ipt.aol.com (ACD60BE2.ipt.aol.com
[172.214.11.226])
by xxxxxxxxxxxx (8.11.6/8.11.6) with ESMTP id j0VDi8D26957
for <xxxxxxxxxxxxxxxxxxx>; Mon, 31 Jan 2005 08:44:10 -0500
Received: from strathroy.com (mail.coolhandle.com [64.49.213.235])
by ACD60BE2.ipt.aol.com with esmtp
id D82FE37F2A for <xxxxxxxxxx>; Mon, 31 Jan 2005 05:44:11 -0800
Message-ID: <010001c5079a$16081f2a$db88e47e@strathroy.com>
From: "Purveyor S. Rules" <zinn...@strathroy.com>
To: xxxxxxxxxxxxxxxxxxxx
Subject: Beautiful 30 to 40 girls cheating
Date: Mon, 31 Jan 2005 05:44:11 -0800
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary="----=_NextPart_000_0031_F52736F2.5999B484"
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2800.1437
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2462.0000
X-GMX-Antivirus: 0 (no virus found)
Sample header [2]
Return-Path: <tgcsc...@ACA898FB.ipt.aol.com>
Received: from rly-ip03.mx.aol.com (rly-ip03.mx.aol.com [64.12.138.7])
by xxxxxxxxxxxxxxxxxxxxx (8.11.6/8.11.6) with ESMTP id j0TIxuD25925
for <xxxxxxxxxxxxxxxxxxxxxxxxx>; Sat, 29 Jan 2005 14:00:01 -0500
Received: from smtp-mtc04.proxy.aol.com (smtp-mtc04.proxy.aol.com
[64.12.118.82]) by rly-ip03.mx.aol.com (v98.19) with ESMTP id
RELAYIN8-941fbdd20111; Sat, 29 Jan 2005 13:59:44 -0400
Received: from ACA898FB.ipt.aol.com (ACA898FB.ipt.aol.com
[172.168.152.251])
by smtp-mtc04.proxy.aol.com (8.12.11/8.12.11) with ESMTP id
j0TIxdLM008309
for <xxxxxxxxxxxxxxxxxxxxxx>; Sat, 29 Jan 2005 13:59:41 -0500
Message-Id: <200501291859.j0TIxdLM008...@smtp-mtc04.proxy.aol.com>
From: Abraham Fletcher <tgcsc...@ACA898FB.ipt.aol.com>
To: xxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Subject: Boys Shock low y.o., xxxxxxxxxx!
Date: Sat, 29 Jan 2005 18:12:26 +0000
MIME-Version: 1.0
Content-Type: text/plain;
charset="Windows-1252"
X-Scanned-By: MIMEDefang 2.43
X-Apparently-From: ERR_USER_NULL
X-AOL-IP: 64.12.118.82
Content-Transfer-Encoding: 8bit