Hi all!
I haven't been here for a decade or so, but there is a spammer that
I'm quite fed up with, but my spamfighting is a little rusty, so I'd
like some help if you can.
First, can I have a hat check on Bluehost.com, please? That's his ISP,
and he's been there for a while. I've sent first one detailed
complaint there, they said they had taken action. Then, he continued,
they said they had taken action, and now I just got another. I don't
know if there is a point sending more in their direction. If not, can
anybody help me find their upstream?
Hi all!
I haven't been here for a decade or so, but there is a spammer that
I'm quite fed up with, but my spamfighting is a little rusty, so I'd
like some help if you can.
First, can I have a hat check on Bluehost.com, please? That's his
ISP, [...]
The specific spamvertized site is friluftsbutikken.com.
In addition to friluftsbutikken.com, his domains include habrev.com, probrev.com, probrev.site. They seem to at least have Bluehost as
their DNS provider. He's also figured regularly on SURBL, but
apparently not now.
I have a list about 30 domains that he have used earlier. The most
recent spam came from nyhetsbrev1.org.
As I said, I have sent complaints to Bluehost (the first in late[...]
June), but they have had no effect. So, what do you suggest I do
next?
Please see below for the most recent spam with most of it.
---------- Spam excerpt ------------
Return-Path: <bounces@nyhetsbrev1.org>
Delivered-To: kjetil@kjernsmo.net
Received: (qmail 10454 invoked by uid 121); 31 Jul 2021 06:37:57 -0000 X-Spam-Checker-Version: SpamAssassin 3.4.2 (2018-09-13) on pooh.kjernsmo.net X-Spam-Level: *********
X-Spam-Status: Yes, score=9.0 required=5.0 tests=BAYES_99,BAYES_999,
DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,HTML_IMAGE_RATIO_02,
HTML_MESSAGE,SPF_HELO_NONE,SPF_PASS autolearn=disabled
Received: from server.nyhetsbrev1.org (HELO server.nyhetsbrev1.org) (162.214.212.208)[...]
by pooh (qpsmtpd/0.94) with ESMTP; Sat, 31 Jul 2021 08:37:54 +0200
To: kjetil@kjernsmo.net
Subject: *** SPAM ***
=?UTF-8?Q?P=C3=85_LAGER_-_RASK_LEVERING_-_Sikre_deg_din_SUP_pakke_n?=
=?UTF-8?Q?=C3=A5_-_Med_5_=C3=A5rs_garanti!?=
X-PHP-Script: nyhetsbrev1.org/admin/index.php for 193.75.57.178 X-PHP-Originating-Script: 1003:class.phpmailer.php
Received: from cB2394BC1.dhcp.as2116.net [193.75.57.178] by nyhetsbrev1.org with HTTP; Sat, 31 Jul 2021 06:37:33 +0000
Date: Sat, 31 Jul 2021 06:37:46 +0000
From: Friluftsbutikken <friluftsbutikken@nyhetsbrev1.org>
Message-ID: <a90571cc72ce4dc9840c44f5493ed899@nyhetsbrev1.org> X-phpList-version: 3.4.5
X-MessageID: 6
X-ListMember: kjetil@kjernsmo.net
Precedence: bulk
List-Help: <http://nyhetsbrev1.org/?p=preferences&uid=94c4bcffecada8c42551eaee3e536d51>
List-Unsubscribe: <http://nyhetsbrev1.org/?p=unsubscribe&uid=94c4bcffecada8c42551eaee3e536d51&jo=1>
List-Subscribe: <http://nyhetsbrev1.org/?p=subscribe>
List-Owner: <mailto:noreply@nyhetsbrev1.org>
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report[...]
X-AntiAbuse: Primary Hostname - server.nyhetsbrev1.org
X-AntiAbuse: Original Domain - kjernsmo.net
X-AntiAbuse: Originator/Caller UID/GID - [1003 991] / [47 12]
X-AntiAbuse: Sender Address Domain - nyhetsbrev1.org X-Get-Message-Sender-Via: server.nyhetsbrev1.org: authenticated_id: nyhetsb2/from_h
X-Authenticated-Sender: server.nyhetsbrev1.org: friluftsbutikken@nyhetsbrev1.org
X-Source:
X-Source-Args: php-fpm: pool nyhetsbrev1_org
X-Source-Dir: nyhetsbrev1.org:/public_html/admin
First, can I have a hat check on Bluehost.com, please? That's his ISP,
At least in the past Bluehost did terminate spammer accounts. Didn't had
any spam recently involving them that I would know if they changed the hat color.
Seems to be spam targeted to you language. I find spam in languages other than English more interesting.
To make things easier you can sign up at Spamcop.
Bluehost.com is one of the subsidiary brands of EIG (Endurance
International Group), one of the world's largest web hosting providers.
For a company this huge, they manage their network quite well.
https://www.spamhaus.org/sbl/listings/endurance.com
Received: from cB2394BC1.dhcp.as2116.net [193.75.57.178] by nyhetsbrev1.org >> with HTTP; Sat, 31 Jul 2021 06:37:33 +0000193.75.57.178 is the origin of this message.
% Abuse contact for '193.75.56.0 - 193.75.63.255' is 'abuse@globalconnect.no' inetnum: 193.75.56.0 - 193.75.63.255
netname: VENTELO-DHCP-BERGEN
e-mail:noc@globalconnect.no
remarks:noc@globalconnect.no
abuse-mailbox:abuse@globalconnect.no
descr: BROADNET-NO-ROUTE
ascertainging how your address may have been added to this list,
apparently nearly a decade ago. It may be time to do something about
it. The lack of either or both does not portend well.
On 04.08.2021 02:08, Andreas Kohlbach wrote:
Seems to be spam targeted to you language. I find spam in languages other
than English more interesting.
Yeah :-) Interestingly, spamming private persons have been illegal for
a long time in Norway, but I have on several occasions filed a report
with the Consumer Protection Authorities, but they have taken no
action. I believe that's the reason why he developed a sense of
impunity.
To make things easier you can sign up at Spamcop.
Alright, thanks, I did. Unfortunately, it was too old (I've been on
offline holidays).
The GDPR (General Data Protection Regulation) also applies in Norway
AFAIK. One can keep a spammer busy to reply to this (where did you have
my email address from?), while threatening him to take legal action if
he doesn't reply and take action appropriately.
On 04.08.2021 19:18, Andreas Kohlbach wrote:
The GDPR (General Data Protection Regulation) also applies in Norway
AFAIK. One can keep a spammer busy to reply to this (where did you have
my email address from?), while threatening him to take legal action if
he doesn't reply and take action appropriately.
Right. Interesting, I might see if the Data Inspectorate is more
interested in taking action than the Consumer Protection is.
Bluehost responded that they had taken action again, BTW. Everything
still resolves, so I asked what that action would have been, but I
have had no response to that.
Sysop: | Keyop |
---|---|
Location: | Huddersfield, West Yorkshire, UK |
Users: | 465 |
Nodes: | 16 (2 / 14) |
Uptime: | 68:34:36 |
Calls: | 9,411 |
Calls today: | 3 |
Files: | 13,575 |
Messages: | 6,101,122 |