republican-creole
site Search:


 
   
story category
Phantom Spammers
No, we are not interested in your medical billing spam
by rjackson Friday 31-Aug-2007
Lately, we've been getting a lot of this medical billing stuff sent to our NOC account.
Click for full size
Click for full size



They all come from the same group of IPs, and SpamCop says the netblock owner (US LEC, who merged with PAETEC last February) doesn't accept abuse reports. So, doing a little more digging...
firefly:~ russ$ host 71.16.72.90
90.72.16.71.in-addr.arpa domain name pointer op14.officepubs.com.
 
Hmm, officepubs.com. They don't have a website, and barely any results from a Google search. In fact, it only shows up in some guy's blog where he publishes stats on the spam he receives. Not looking good.

So, checking further...
firefly:~ russ$ host officepubs.com
officepubs.com mail is handled by 0 op1.officepubs.com.
officepubs.com mail is handled by 10 op2.officepubs.com.
officepubs.com mail is handled by 20 op3.officepubs.com.
officepubs.com mail is handled by 30 op4.officepubs.com.
officepubs.com mail is handled by 40 op5.officepubs.com.
officepubs.com mail is handled by 50 op6.officepubs.com.
officepubs.com mail is handled by 51 op7.officepubs.com.
officepubs.com mail is handled by 52 op8.officepubs.com.
officepubs.com mail is handled by 53 op9.officepubs.com.
officepubs.com mail is handled by 54 op10.officepubs.com.
officepubs.com mail is handled by 55 op11.officepubs.com.
officepubs.com mail is handled by 56 op12.officepubs.com.
officepubs.com mail is handled by 57 op13.officepubs.com.
officepubs.com mail is handled by 58 op14.officepubs.com.
 
No A records and 14 mail exchangers? What legit organization would have a setup like that? I think we know the answer. It's probably safe to block these guys from sending us any more mail.

home

Burn Folder

the best blog by rjackson on dslr
view: topics flat text 
Post a:

TheUnknownAddy

@comcast.net

Phantom Spammers

> They don't have a website, and barely any results from a Google search.

Four sightings:

»groups.google.com/groups?q=officepubs.com
Rucker

join:2005-12-22
Easton, PA

Re: Phantom Spammers

US LEC should accept abuse reports at abuse@uslec.com. Did you try contacting them?

Rangerw
Just A Simple Man
Premium,MVM
join:2002-10-20
Orange, TX
I just sent a e-mail off to abuse@paetec.com and abuse@uslec.com with some full mail headers and got this automated reply:

Thank you for contacting PAETEC. We at PAETEC take abuse complaints seriously, and we are dedicated to upholding our Acceptable Use Policy (available at »www.paetec.com/aup). Should pursuit of this complaint require additional information, we will contact you. Although we are not able to respond to each report, be assured that we investigate every complaint and will take appropriate action where merited.

Thank you,

PAETEC Abuse Team

If anything comes of it I'll post again.
--
AMD Athlon 64 3700+ ClawHammer - Asus MoBo- 2GB PC3200 CAS 2 RAM - Dual Serial ATA133 7200RPM Drives in a RAID-0 config - Audigy II ZS - ATI X800 Pro 256MB

Rangerw
Just A Simple Man
Premium,MVM
join:2002-10-20
Orange, TX

Re: Phantom Spammers

Same identical reply from both paetec.com & uslec.com:

Thank you for notifying us of the violation of our Acceptable Use Policy.
The problem you are reporting has been investigated and we are currently in the process of working with our customer to resolve the problem. You will receive notification when the problem has been resolved.

Regards,

US LEC Network Security
--
AMD Athlon 64 3700+ ClawHammer - Asus MoBo- 2GB PC3200 CAS 2 RAM - Dual Serial ATA133 7200RPM Drives in a RAID-0 config - Audigy II ZS - ATI X800 Pro 256MB

Monday, 04-Jun 22:28:39 Terms of Use & Privacy | feedback | contact | Hosting by nac.net - DSL,Hosting & Co-lo
over 12.5 years online © 1999-2012 dslreports.com.