Discussion:
Spam from @gmail.com addresses originating from news.xlned.com
(too old to reply)
Grant Taylor
2023-12-15 03:39:16 UTC
Permalink
Hi,

Is anyone else seeing spam from @gmail.com addresses with the Path:
showing that the messages are coming from news.xlned.com / ams1 (in some
permutation)?

I've seen six messages today when I haven't seen much non-GG / non-troll
spam in quite a while.

I'm wondering if some of the spammers have realized that the free ride
that was GG is over and starting to look elsewhere for service.

N.B. I've set Followup-To: news.admin.net-abuse.usenet.
--
Grant. . . .
Marco Moock
2023-12-15 08:05:30 UTC
Permalink
Post by Grant Taylor
I'm wondering if some of the spammers have realized that the free
ride that was GG is over and starting to look elsewhere for service.
IIRC I read that some already tried to use E-S to post Thai spam, but
the filter stopped them.
Andrew
2023-12-15 11:15:16 UTC
Permalink
Post by Marco Moock
Post by Grant Taylor
I'm wondering if some of the spammers have realized that the free
ride that was GG is over and starting to look elsewhere for service.
IIRC I read that some already tried to use E-S to post Thai spam, but
the filter stopped them.
I would hope that attempts to spam via E-S - or other similar candidates
- would give the admins of these servers a better clue as to who is
behind this stuff.
That's the optimistic standpoint, the pessimistic one is that they will
find another server whose admins simply don't care.
Marco Moock
2023-12-15 11:20:40 UTC
Permalink
Post by Andrew
Post by Marco Moock
Post by Grant Taylor
I'm wondering if some of the spammers have realized that the free
ride that was GG is over and starting to look elsewhere for
service.
IIRC I read that some already tried to use E-S to post Thai spam,
but the filter stopped them.
I would hope that attempts to spam via E-S - or other similar
candidates
- would give the admins of these servers a better clue as to who is
behind this stuff.
That's the optimistic standpoint, the pessimistic one is that they
will find another server whose admins simply don't care.
Google already gives that - the IP addresses of the spamming systems
are known, the ISP of them mostly don't care.
Just check those IPs and network in dnsbl list about email spam.
They are full of email spammers too and the ISPs accept that.
The Doctor
2023-12-15 16:16:16 UTC
Permalink
Post by Marco Moock
Post by Andrew
Post by Marco Moock
Post by Grant Taylor
I'm wondering if some of the spammers have realized that the free
ride that was GG is over and starting to look elsewhere for service.
IIRC I read that some already tried to use E-S to post Thai spam,
but the filter stopped them.
I would hope that attempts to spam via E-S - or other similar
candidates
- would give the admins of these servers a better clue as to who is
behind this stuff.
That's the optimistic standpoint, the pessimistic one is that they
will find another server whose admins simply don't care.
Google already gives that - the IP addresses of the spamming systems
are known, the ISP of them mostly don't care.
Just check those IPs and network in dnsbl list about email spam.
They are full of email spammers too and the ISPs accept that.
Incompetence for you!
--
Member - Liberal International This is ***@nk.ca Ici ***@nk.ca
Yahweh, King & country!Never Satan President Republic!Beware AntiChrist rising!
Look at Psalms 14 and 53 on Atheism ; unsubscribe from Google Groups to be seen
Merry Christmas 2023 and Happy New year 2024 Beware https://mindspring.com
Retro Guy
2023-12-15 14:03:55 UTC
Permalink
Post by Grant Taylor
Hi,
showing that the messages are coming from news.xlned.com / ams1 (in some
permutation)?
I've seen six messages today when I haven't seen much non-GG / non-troll
spam in quite a while.
I noticed that a few days ago and modified my filters. I haven't been
watching if it's continuing as I don't see the spam now.

Whether they have a @gmail.com address or not, I didn't check. That's not
a header I filter, it's too simple to spoof.
Grant Taylor
2023-12-15 15:34:35 UTC
Permalink
Post by Retro Guy
I noticed that a few days ago and modified my filters. I haven't been
watching if it's continuing as I don't see the spam now.
I saw a few more messages already today.
Post by Retro Guy
not a header I filter, it's too simple to spoof.
Agreed.

I just wonder if some spammers are finding that their playground is
coming to and end and the rats are jumping ship.
--
Grant. . . .
The Doctor
2023-12-15 16:18:19 UTC
Permalink
Post by Grant Taylor
Post by Retro Guy
I noticed that a few days ago and modified my filters. I haven't been
watching if it's continuing as I don't see the spam now.
I saw a few more messages already today.
Post by Retro Guy
not a header I filter, it's too simple to spoof.
Agreed.
I just wonder if some spammers are finding that their playground is
coming to and end and the rats are jumping ship.
WEll I will not sign up Google abusers!
Post by Grant Taylor
--
Grant. . . .
--
Member - Liberal International This is ***@nk.ca Ici ***@nk.ca
Yahweh, King & country!Never Satan President Republic!Beware AntiChrist rising!
Look at Psalms 14 and 53 on Atheism ; unsubscribe from Google Groups to be seen
Merry Christmas 2023 and Happy New year 2024 Beware https://mindspring.com
The Doctor
2023-12-15 16:16:59 UTC
Permalink
Post by Retro Guy
Post by Grant Taylor
Hi,
showing that the messages are coming from news.xlned.com / ams1 (in some
permutation)?
I've seen six messages today when I haven't seen much non-GG / non-troll
spam in quite a while.
I noticed that a few days ago and modified my filters. I haven't been
watching if it's continuing as I don't see the spam now.
a header I filter, it's too simple to spoof.
I will filter GG until 1 MArch 2024!
--
Member - Liberal International This is ***@nk.ca Ici ***@nk.ca
Yahweh, King & country!Never Satan President Republic!Beware AntiChrist rising!
Look at Psalms 14 and 53 on Atheism ; unsubscribe from Google Groups to be seen
Merry Christmas 2023 and Happy New year 2024 Beware https://mindspring.com
yamo'
2023-12-16 09:23:38 UTC
Permalink
Hi,
Post by Retro Guy
I noticed that a few days ago and modified my filters. I haven't been
watching if it's continuing as I don't see the spam now.
Could you give some Message-ID, Newsgroups?
--
Stéphane
Retro Guy
2023-12-16 10:42:28 UTC
Permalink
Post by yamo'
Hi,
Post by Retro Guy
I noticed that a few days ago and modified my filters. I haven't been
watching if it's continuing as I don't see the spam now.
Could you give some Message-ID, Newsgroups?
These are some from 13 Dec. They are listed in NoCeM:
<bot-spam-***@i2pn2.org>

-----
<***@4ax.com>
microsoft.public.word.docmanagement,soc.culture.punjab,microsoft.public.project,comp.lang.lisp
<***@4ax.com>
microsoft.public.word.docmanagement,soc.culture.punjab,microsoft.public.project,comp.lang.lisp
<***@4ax.com>
microsoft.public.word.docmanagement,soc.culture.punjab,microsoft.public.project,comp.lang.lisp
<***@4ax.com>
microsoft.public.word.docmanagement,soc.culture.punjab,microsoft.public.project,comp.lang.lisp
<***@4ax.com>
microsoft.public.word.docmanagement,soc.culture.punjab,microsoft.public.project,comp.lang.lisp
<***@4ax.com>
microsoft.public.word.docmanagement,soc.culture.punjab,microsoft.public.project,comp.lang.lisp
<***@4ax.com>
microsoft.public.word.docmanagement,soc.culture.punjab,microsoft.public.project,comp.lang.lisp
<***@4ax.com>
microsoft.public.word.docmanagement,soc.culture.punjab,microsoft.public.project,comp.lang.lisp
<***@4ax.com> comp.compression
<***@4ax.com>
microsoft.public.word.docmanagement,soc.culture.punjab,microsoft.public.project,comp.lang.lisp
<***@4ax.com>
microsoft.public.word.docmanagement,soc.culture.punjab,microsoft.public.project,comp.lang.lisp
<***@4ax.com>
microsoft.public.word.docmanagement,soc.culture.punjab,microsoft.public.project,comp.lang.lisp
<***@4ax.com>
microsoft.public.word.docmanagement,soc.culture.punjab,microsoft.public.project,comp.lang.lisp
<***@4ax.com>
microsoft.public.word.docmanagement,soc.culture.punjab,microsoft.public.project,comp.lang.lisp
<***@4ax.com>
microsoft.public.word.docmanagement,soc.culture.punjab,microsoft.public.project,comp.lang.lisp
<***@4ax.com>
microsoft.public.word.docmanagement,soc.culture.punjab,microsoft.public.project,comp.lang.lisp
<***@4ax.com>
microsoft.public.word.docmanagement,soc.culture.punjab,microsoft.public.project,comp.lang.lisp
<***@4ax.com> comp.compression
<***@4ax.com> comp.compression
<***@4ax.com> comp.compression
<***@4ax.com> comp.compression
<***@4ax.com>
microsoft.public.word.docmanagement,soc.culture.punjab,microsoft.public.project,comp.lang.lisp
<***@4ax.com>
microsoft.public.word.docmanagement,soc.culture.punjab,microsoft.public.project,comp.lang.lisp
<***@4ax.com>
microsoft.public.word.docmanagement,soc.culture.punjab,microsoft.public.project,comp.lang.lisp
<***@4ax.com>
microsoft.public.word.docmanagement,soc.culture.punjab,microsoft.public.project,comp.lang.lisp
yamo'
2023-12-17 19:15:54 UTC
Permalink
Hi,
Thanks!
So they have been catched by the bot, good news.

I have also updated my cleanfeed.local
--
Stéphane
Grant Taylor
2023-12-16 19:46:41 UTC
Permalink
Post by yamo'
Could you give some Message-ID, Newsgroups?
Sure.

Message-ID: <***@4ax.com>
Message-ID: <***@4ax.com>
Message-ID: <***@4ax.com>
Message-ID: <***@4ax.com>
Message-ID: <***@4ax.com>
Message-ID: <***@4ax.com>
Message-ID: <***@4ax.com>
Message-ID: <***@4ax.com>

Let me know if you want anything else.
--
Grant. . . .
Frank Slootweg
2023-12-16 20:21:32 UTC
Permalink
Post by Grant Taylor
Post by yamo'
Could you give some Message-ID, Newsgroups?
Sure.
Let me know if you want anything else.
I've only looked at the first one, but not only their drugs are
psychedelic, but so is their list of Newsgroups:

Newsgroups: comp.compression,microsoft.public.mac.office.word,alt.sys.pdp10,comp.lang.lisp,bit.listserv.ibm-main,mmicrosoft.public.word.docmanagement

Note the pdp10, the microsoft.*, the stuttering, etc.! :-)

Their NSP is UsenetServer, which is not evident from the Path:, but is
shown in the X-Complaints-To and Organization:

Path: ...!npeer.as286.net!npeer-ng0.as286.net!peer02.ams1!peer.ams1.xlned.com!news.xlned.com!fx10.ams1.POSTED!not-for-mail
X-Complaints-To: ***@usenetserver.com
Organization: UsenetServer - www.usenetserver.com

Judging from their User-Agent header, they're cheapskates (unless
that's faked (but then the Message-ID is faked as well)):

User-Agent: ForteAgent/8.00.32.1272 trialware

FWIW, I've a filter for all-caps Subject:s since eons:

Subject: BEST DMT CARTS FOR SALE AND DMT VAPE PENS FOR SALE IN UK

All in all, AFAICT, this is 'normal' Usenet spam, nothing out of the
ordinary.

P.S. Sorry for the Dutch aspects. Normally the slogan is "If it ain't
Dutch, it ain't much!", but in this case, the slogan doesn't seem to
apply! :-)
Grant Taylor
2023-12-16 20:38:31 UTC
Permalink
Post by Frank Slootweg
I've only looked at the first one, but not only their drugs are
Agreed.
Post by Frank Slootweg
Their NSP is UsenetServer, which is not evident from the Path:,
I noticed that too.
Post by Frank Slootweg
Judging from their User-Agent header, they're cheapskates (unless
The Message-ID may be a forgery, but it is the ID that the message goes
by none-the-less. So ... is it really a /fake/? }:-)
Prior to the recent Google BS I largely left cleanfeed at defaults.
I've had to get more stringent before simply adding Google as a banned
host in the Path: header.
Post by Frank Slootweg
All in all, AFAICT, this is 'normal' Usenet spam, nothing out of
the ordinary.
Agreed.
Post by Frank Slootweg
P.S. Sorry for the Dutch aspects. Normally the slogan is "If it ain't
Dutch, it ain't much!", but in this case, the slogan doesn't seem to
apply! :-)
You're fine.
--
Grant. . . .
yamo'
2023-12-17 19:18:01 UTC
Permalink
Hi,
Post by Grant Taylor
Let me know if you want anything else.
Thanks a lot Grant!
--
Stéphane
Grant Taylor
2023-12-17 21:34:07 UTC
Permalink
Post by yamo'
Thanks a lot Grant!
You're welcome.
--
Grant. . . .
Loading...