Spam from an IP range...
J.Ede at birchenallhowden.co.uk
Sun Feb 22 09:06:42 GMT 2009
Over the last few days I've noticed we're getting a lot of spam from the IP range 188.8.131.52/24
Normally with subjects such as Win Free Laser Eye Surgery - Optical Express
X-Greylist: delayed 00:20:01 by SQLgrey-1.7.5
Received: from permforce.com (248.permforce.com [184.108.40.206])
by gateway.birchenallhowden.com (Postfix) with ESMTP id 981F71D707EA
for <XXXX at XXXXXXXXX>; Sun, 22 Feb 2009 08:44:03 +0000 (GMT)
Received: by permforce.com id hk48560ikece for < XXXX at XXXXXXXXX >; Sun, 22 Feb 2009 08:24:00 +0000 (envelope-from <wonderful at permforce.com>)
Date: 22 Feb 2009 08:24:00 GMT
Message-Id: <11F9D156843.9Dk4F71C at permforce.com>
From: Vision Repair<wonderful at permforce.com>
To: XXXX at XXXXXXXXX
Subject: Win Free Laser Eye Surgery - Optical Express
Content-Type: text/html; charset="ISO-8859-1"
They're coming from different addresses in that range and different domains such as unaskedtool.com unaskeddrive.com. The emails are all getting nuked by spamassassin and sanesecurity defs so far.
Does anyone else know much about this range and if could just safely block the entire /24 range?
-------------- next part --------------
An HTML attachment was scrubbed...
More information about the MailScanner