A new flood from btinternet.com (well, actually this is from giganews -
BT is not competent enough to have its own news servers ?) is hitting
almost every single group with multipart messages.
Message headers sample:
-----------------------
Path:
..!border1.nntp.dca.giganews.com!Bl.tags.giganews.com!border2.nntp.dca.giganews.com!nntp.giganews.com!backlog2.nntp.dca.giganews.com!nntp.bt.com!news.bt.com.POSTED!not-for-mail
NNTP-Posting-Date: Sat, 29 Aug 2009 00:10:01 -0500
From: "Robert Bates" <speed...@live.co.uk>
Subject: XXX IS A CHILD ABUSERNBP Unregistered.
Newsgroups: rec.toys.lego
Content-Type: multipart/alternative;
boundary="=_NextPart_2rfkindysadvnqw3nerasdf";
MIME-Version: 1.0
Date: Sat, 29 Aug 2009 06:10:04 +0100
X-Priority: 3
X-Library: Indy 8.0.25
Message-ID: <jbadnWDFdK60JQXX...@bt.com>
Lines: 27
X-Usenet-Provider: http://www.giganews.com
X-AuthenticatedUsername: NoAuthUser
X-Trace:
sv3-gPxpm2q0Adtkx5rfsdIU9R5TfrNW9ZCmFdkCjXc0szN0ol668O71Zar7W3FS6NB9VN6wXOjsOqs3IYM!0SEOGUvi35/Iujv2UvRvLTC
tWvMAr1lBj/GLBybFx97OIEUIyjyFBuQRcQ2icBffXvAbC5wy81U=
X-Complaints-To: ab...@btinternet.com
X-DMCA-Complaints-To: ab...@btinternet.com
X-Abuse-and-DMCA-Info: Please be sure to forward a copy of ALL headers
X-Abuse-and-DMCA-Info: Otherwise we will be unable to process your
complaint properly
X-Postfilter: 1.3.39
X-Original-Bytes: 7526
Message-Id samples:
-------------------
Message-ID: <jbadnQTFdK4TKgXX...@bt.com>
Message-ID: <jbadnQDFdK4JKgXX...@bt.com>
Message-ID: <jbadnTzFdK4GKgXX...@bt.com>
Message-ID: <jbadnTrFdK44KgXX...@bt.com>
Message-ID: <jbadnTTFdK41KgXX...@bt.com>
Message-ID: <P-CdnXQYvZj7zAXX...@bt.com>
Message-ID: <P-CdnXMYvZjwzAXX...@bt.com>
Message-ID: <P-CdnWsYvZjkzAXX...@bt.com>
Message-ID: <P-CdnWoYvZjmzAXX...@bt.com>
Message-ID: <P-CdnWUYvZjhzAXX...@bt.com>
Message-ID: <P-CdnWAYvZgYzAXX...@bt.com>
Message-ID: <P-CdnWIYvZgVzAXX...@bt.com>
Message-ID: <P-CdnZ8bvZgRzAXX...@bt.com>
Message-ID: <P-CdnZUbvZgIzAXX...@bt.com>
Message-ID: <P-CdnZQbvZgKzAXX...@bt.com>
Message-ID: <P-CdnXUYvZj5zAXX...@bt.com>
Message-ID: <P-CdnaAevZi20AXX...@bt.com>
Message-ID: <P-Cdnc8evZjR0AXX...@bt.com>
Message-ID: <P-CdndcevZjd0AXX...@bt.com>
Message-ID: <P-CdnYITvZiqwwXX...@bt.com>
Message-ID: <P-CdnY8TvZi-wwXX...@bt.com>
Message-ID: <P-CdnY4TvZi5wwXX...@bt.com>
..
| Hi folks,
| A new flood from btinternet.com (well, actually this is from giganews -
| BT is not competent enough to have its own news servers ?) is hitting
| almost every single group with multipart messages.
Note in the header...
X-Library: Indy 8.0.25
Indy v8.x, v9.x and v10.x is the preferred spammer tool as it recursively post through
every group in every hierarchy, post randomly in every group in every hierarchy or
selectively post where desired.
All news admins are encouraged to filter posts that have "X-Library: Indy xxxxxx" in the
header.
--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp
> Note in the header...
> X-Library: Indy 8.0.25
> Indy v8.x, v9.x and v10.x is the preferred spammer tool as it
> recursively post through every group in every hierarchy, post randomly
> in every group in every hierarchy or selectively post where desired.
> All news admins are encouraged to filter posts that have "X-Library:
> Indy xxxxxx" in the header.
That's interesting. Sounds like a new scoring rule for Cleanfeed. :)
Thanks
>>Note in the header...
>>X-Library: Indy 8.0.25
>>Indy v8.x, v9.x and v10.x is the preferred spammer tool as it
>>recursively post through every group in every hierarchy, post randomly
>>in every group in every hierarchy or selectively post where desired.
>>All news admins are encouraged to filter posts that have "X-Library:
>>Indy xxxxxx" in the header.
>That's interesting. Sounds like a new scoring rule for Cleanfeed. :)
Is it? A spamming tool that creates messages that are easily killed?
Could someone verify this independently?
> Is it? A spamming tool that creates messages that are easily killed?
> Could someone verify this independently?
It does sound incongruous. I'll log messages with that header and see
what turns up.
Here is a different spam sample using Indy v9.x
Path: news.spamcop.net!not-for-mail
From: "apartamento jardim camburi" <apart...@jardim-camburi-vitoria.com>
Newsgroups: spamcop.mail
Subject: Ligue agora mesmo 0xx27 3084-5709 vendo apartamento em jardim
camburi , oportunidade de negocio apto 2461327710
Date: Wed, 10 Jun 2009 19:40:48 -0300
Organization: apartamentos jardim camburi
Lines: 20
Sender: apartamento jardim camburi <apart...@jardim-camburi-vitoria.com>
Message-ID: <h0pcrr$mng$6...@news.spamcop.net>
Reply-To: aparta...@casas.jardimcamburi-3qtos.com.br
NNTP-Posting-Host: 189.115.213.239
X-Trace: news.spamcop.net 1244673724 23280 189.115.213.239 (10 Jun 2009 22:42:04 GMT)
X-Complaints-To: ne...@news.spamcop.net
NNTP-Posting-Date: Wed, 10 Jun 2009 22:42:04 +0000 (UTC)
X-Priority: 3
X-Library: Indy 9.00.10
Xref: news.spamcop.net spamcop.mail:22562
Why not? Lots of spam engines have well-known spoor.
Seth
>>>>All news admins are encouraged to filter posts that have "X-Library:
>>>>Indy xxxxxx" in the header.
>>>That's interesting. Sounds like a new scoring rule for Cleanfeed. :)
>>Is it? A spamming tool that creates messages that are easily killed?
>Why not? Lots of spam engines have well-known spoor.
I should have thought the point was self evident.