[spam] rara wie is de spammer

Pagina: 1
Acties:
  • 522 views sinds 30-01-2008
  • Reageer

  • Grolsch
  • Registratie: Maart 2003
  • Laatst online: 21:35
Hallo Mensen,

Ik krijg nu binnen 20 uur, duizende email binnen van iemand die waarschijnlijk gespooft wordt, met een email met een hoax en een .doc file belangrijk.

het is gewoon in het nederlands, dus geen viagra shit.

dit zijn de headers
Microsoft Mail Internet Headers Version 2.0
Received: from synusflex.com ([213.144.250.54]) by server.bedrijf.nl with Microsoft SMTPSVC(5.0.2195.6713);
Fri, 21 Jul 2006 10:02:59 +0200
Received: from mail pickup service by synusflex.com with Microsoft SMTPSVC;
Thu, 20 Jul 2006 16:45:46 +0200
X-KINE-FWD: 1
Delivery-Date: Thu, 20 Jul 2006 16:53:54 +0200
Received-SPF: none (mxeu7: 213.144.250.54 is neither permitted nor denied by domain of erdelt.nl) client-ip=213.144.250.54; envelope-from=info@erdelt.nl; helo=synusflex.com;
X-KINE-FWD: 1
Delivery-Date: Thu, 20 Jul 2006 12:12:57 +0200
Received-SPF: none (mxeu2: 80.60.216.72 is neither permitted nor denied by domain of erdelt.nl) client-ip=80.60.216.72; envelope-from=info@erdelt.nl; helo=plato.BTH.local;
Delivered-To: 34-info@bth-oldenzaal.nl
X-KINE-FWD: 1
Delivery-Date: Thu, 20 Jul 2006 10:49:20 +0200
Received-SPF: none (mxeu11: 62.250.3.110 is neither permitted nor denied by domain of erdelt.nl) client-ip=62.250.3.110; envelope-from=info@erdelt.nl; helo=relay.versatel.net;
Delivered-To: ipdeve@vuurwerk.nl
Delivered-To: virtualdomains-info@ip-deventer.nl
Message-ID: <001501c6ac0b$2f0803f0$5f00a8c0@synusflex.local>
X-Envelope-To: info@ip-deventer.nl
From: "Erdelt Hengelo" <info@erdelt.nl>
To: "!" honderden email adessen met naam en email adres
Subject: FW: Doorsturen!!!!!!!!!!!!!!!!!!!!
Content-Transfer-Encoding: 7bit
Date: Thu, 20 Jul 2006 16:45:46 +0200
MIME-Version: 1.0
Content-Type: multipart/mixed;
boundary="----=_NextPart_000_002E_01C6ABE7.FFF79AD0"
X-Mailer: Microsoft Office Outlook, Build 11.0.5510
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.3790.2663
thread-index: Acary/z0HpLKzBfOEdugAwAAORqRKwAAJw1AAAFe+xAAAUFEUA==
Content-Class: urn:content-classes:message
Importance: normal
Priority: normal
X-Envelope-To: <info@synusflex.com>
X-OriginalArrivalTime: 20 Jul 2006 08:00:26.0562 (UTC) FILETIME=[8F7F8A20:01C6ABD2]
X-Versatel-Spam-DNSBL: NO
X-Versatel-Spam-DNSBL-Info: Mail filtered by Versatel DNSBL system
X-Versatel-AntiVirus: checked by Vexira Anti Virus 1.57.4, vdb: 9.25.6
X-Envelope-To: <info@synusflex.com>
X-Envelope-To: <info@synusflex.com>
Envelope-To: pbtigroupcom@pbtigroup.com
X-Spam-Checker-Version: SpamAssassin 3.0.2 (2004-11-16) on Mail01.happy
X-Spam-Level:
X-Spam-Status: No, score=0.2 required=5.0 tests=ALL_TRUSTED,AWL,DATE_IN_PAST_03_06,HEAD_LONG,PLING_PLING autolearn=no version=3.0.2
X-Envelope-To: <info@synusflex.com>
Return-Path: info@erdelt.nl

------=_NextPart_000_002E_01C6ABE7.FFF79AD0
Content-Type: text/plain;
charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

------=_NextPart_000_002E_01C6ABE7.FFF79AD0
Content-Type: application/msword;
name="BELANGRIJK.doc"
Content-Transfer-Encoding: base64
Content-Disposition: attachment;
filename="BELANGRIJK.doc"
mijn vraag is, welk ip adres veroorzaakt deze "shit" nu :?

PVOUPUT - 13.400WP - Twente


  • CodeIT
  • Registratie: Juni 2002
  • Laatst online: 14:59

CodeIT

Code IT

Ik denk van 62.250.3.110. Dit is het onderste IPadres (kijk ook maar naar de tijd).

  • urk_forever
  • Registratie: Juni 2001
  • Laatst online: 04-02 17:31
dat zou ik ook denken, en het is in ieder geval via het versatel.net netwerk bij jou terecht gekomen, dus die kan je ook een abuse mailtje sturen.

Hail to the king baby!


  • sdomburg
  • Registratie: Augustus 2001
  • Laatst online: 03-09-2024
Na controle van ons mailfilter geef ik het een hele goede kans dat het gespoofd is.

  • Dark
  • Registratie: September 1999
  • Laatst online: 11-02 12:49

Dark

who tweaked the light?

Dit zegt spamcop van de header:
SpamCop v 1.589 Copyright (C) 1998-2005, IronPort Systems, Inc. All rights reserved.
Skip to Reports

Parsing header:

Received: from synusflex.com ([213.144.250.54]) by server.bedrijf.nl with Microsoft SMTPSVC(5.0.2195.6713); Fri, 21 Jul 2006 10:02:59 +0200
213.144.250.54 found
host 213.144.250.54 (getting name) = rt250bb144-213-54.routit.net.
Possible spammer: 213.144.250.54
Received line accepted

Received: from mail pickup service by synusflex.com with Microsoft SMTPSVC; Thu, 20 Jul 2006 16:45:46 +0200
Ignored
Tracking message source: 213.144.250.54:
Routing details for 213.144.250.54
[refresh/show] Cached whois for 213.144.250.54 : leon@routit.nl
Using last resort contacts leon@routit.nl
Yum, this spam is fresh!
Message is 0 hours old
213.144.250.54 not listed in dnsbl.njabl.org
213.144.250.54 not listed in dnsbl.njabl.org
213.144.250.54 not listed in cbl.abuseat.org
213.144.250.54 not listed in dnsbl.sorbs.net
213.144.250.54 not listed in relays.ordb.org.
213.144.250.54 not listed in accredit.habeas.com
213.144.250.54 not listed in plus.bondedsender.org
213.144.250.54 not listed in iadb.isipp.com
Finding links in message body
Parsing text part
error: couldn't parse head
Message body parser requires full, accurate copy of message
More information on this error..
no links found

Please make sure this email IS spam:
From: "Erdelt Hengelo" <info@erdelt.nl> (FW: Doorsturen!!!!!!!!!!!!!!!!!!!!)
------=_NextPart_000_002E_01C6ABE7.FFF79AD0
Content-Type: text/plain;
View full message

Report Spam to:

Re: 213.144.250.54 (Administrator of network where email originates)
To: leon@routit.nl (Notes)

Re: 213.144.250.54 (Third party interested in email source)
To: Cyveillance spam collection (Notes)

Re: User Notification (Notes)
To:

Additional notes (optional - max 2000 characters):

ATTENTION: Report only those e-mail addresses and web sites that you think your spammer has used. Avoid checking any boxes left empty unless you know that your spammer has used the addresses or sites thus identified. Each false report that you submit means wasted time for a network administrator, so take care. The last thing SpamCop wants are network administrators so accustomed to false claims that they no longer take these spam reports seriously.


Comments for:leon@routit.nl (213.144.250.54)

Return to report

Comments for:spamcop@imaphost.com (213.144.250.54)

Return to report

Comments for:User Notification ()

Return to report

  • Grolsch
  • Registratie: Maart 2003
  • Laatst online: 21:35
CodeIT schreef op vrijdag 21 juli 2006 @ 10:41:
Ik denk van 62.250.3.110. Dit is het onderste IPadres (kijk ook maar naar de tijd).
dat is de relay van versatel, dus niet de bron

PVOUPUT - 13.400WP - Twente


Verwijderd

Wellicht geeft jou de onderstaande link de gevraagde informatie welke je zoekt.

http://www.dnsstuff.com/t...?ip=62.250.3.110&email=on
Pagina: 1