Spam from an IP range...

Jason Ede J.Ede at birchenallhowden.co.uk
Sun Feb 22 09:06:42 GMT 2009


Over the last few days I've noticed we're getting a lot of spam from the IP range 209.152.178.0/24

Normally with subjects such as Win Free Laser Eye Surgery - Optical Express

For example...

X-Greylist: delayed 00:20:01 by SQLgrey-1.7.5
Received: from permforce.com (248.permforce.com [209.152.178.248])
     by gateway.birchenallhowden.com (Postfix) with ESMTP id 981F71D707EA
     for <XXXX at XXXXXXXXX>; Sun, 22 Feb 2009 08:44:03 +0000 (GMT)
Received: by permforce.com id hk48560ikece for < XXXX at XXXXXXXXX >; Sun, 22 Feb 2009 08:24:00 +0000 (envelope-from <wonderful at permforce.com>)
Date: 22 Feb 2009 08:24:00 GMT
Message-Id: <11F9D156843.9Dk4F71C at permforce.com>
From: Vision Repair<wonderful at permforce.com>
To: XXXX at XXXXXXXXX
Subject: Win Free Laser Eye Surgery - Optical Express
Mime-Version: 1.0
Content-Type: text/html; charset="ISO-8859-1"


They're coming from different addresses in that range and different domains such as unaskedtool.com unaskeddrive.com. The emails are all getting nuked by spamassassin and sanesecurity defs so far.

Does anyone else know much about this range and if could just safely block the entire /24 range?

Jason
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20090222/7d7fab46/attachment.html


More information about the MailScanner mailing list