December 13, 2011

L2.APEWS.ORG False Positive #9

For those that are receiving the newsletters from the folks doing the dolphin watch documentary etc, Ocean Preservation Society, this latest false positive would have been serious. OPS have used CreateSend.com for their newsletter and the subscriber user on our network found it in the spam folder. Shame, lets hope that like with the previous ones, putting it here gets the server IP delisted;

Sat 2011-12-10 15:07:33: [968:7309] Accepting SMTP connection from [184.106.86.136]
Sat 2011-12-10 15:07:33: [968:7309] Looking up PTR record for 184.106.86.136 (136.86.106.184.IN-ADDR.ARPA)
Sat 2011-12-10 15:07:33: [968:7309] D=136.86.106.184.IN-ADDR.ARPA TTL=(5) PTR=[mr136.createsend.com]
Sat 2011-12-10 15:07:33: [968:7309] Gathering A-records for PTR hosts
Sat 2011-12-10 15:07:33: [968:7309] D=mr136.createsend.com TTL=(120) A=[184.106.86.136]
Sat 2011-12-10 15:07:33: [968:7309] --> 220 xxx.xxx.xxx ESMTP MDaemon 6.7.9; Sat, 10 Dec 2011 15:07:33 -0500
Sat 2011-12-10 15:07:33: [968:7309] <-- EHLO mr136.createsend.com
Sat 2011-12-10 15:07:33: [968:7309] Performing reverse lookup on mr136.createsend.com (looking for 184.106.86.136)
Sat 2011-12-10 15:07:33: [968:7309] D=mr136.createsend.com TTL=(119) A=[184.106.86.136]
Sat 2011-12-10 15:07:33: [968:7309] --> 250-xxx.xxx.xxx Hello mr136.createsend.com, pleased to meet you
Sat 2011-12-10 15:07:33: [968:7309] --> 250-ETRN
Sat 2011-12-10 15:07:33: [968:7309] --> 250-AUTH=LOGIN
Sat 2011-12-10 15:07:33: [968:7309] --> 250-AUTH LOGIN CRAM-MD5
Sat 2011-12-10 15:07:33: [968:7309] --> 250-8BITMIME
Sat 2011-12-10 15:07:33: [968:7309] --> 250 SIZE 0
Sat 2011-12-10 15:07:33: [968:7309] <-- MAIL FROM: BODY=8BITMIME
Sat 2011-12-10 15:07:33: [968:7309] Performing reverse lookup on createsend3.com (looking for 184.106.86.136)
Sat 2011-12-10 15:07:33: [968:7309] D=createsend3.com TTL=(720) A=[27.126.145.32]
Sat 2011-12-10 15:07:33: [968:7309] P=010 D=createsend3.com TTL=(240) MX=[mx1.createsend3.com] {27.126.144.2}
Sat 2011-12-10 15:07:33: [968:7309] Spam Blocker A-record resolution of [136.86.106.184.l2.apews.org] in progress (DNS Server: 192.168.1.2)...
Sat 2011-12-10 15:07:33: [968:7309] Spam Blocker D=136.86.106.184.l2.apews.org TTL=(35) A=[127.0.0.2]
Sat 2011-12-10 15:07:33: [968:7309] APEWS listed, 99.7% certain it is spam
Sat 2011-12-10 15:07:33: [968:7309] Message will be accepted and X-RBL-Warning: header will be inserted.
Sat 2011-12-10 15:07:33: [968:7309] --> 250 , Sender ok
Sat 2011-12-10 15:07:33: [968:7309] <-- RCPT TO:
Sat 2011-12-10 15:07:33: [968:7309] --> 250 , Recipient ok
Sat 2011-12-10 15:07:33: [968:7309] <-- DATA
Sat 2011-12-10 15:07:33: [968:7309] --> 354 Enter mail, end with .
Sat 2011-12-10 15:07:33: [968:7309] --> 250 Ok, message saved
Sat 2011-12-10 15:07:33: [968:7309] <-- QUIT
Sat 2011-12-10 15:07:33: [968:7309] --> 221 See ya in cyberspace
Sat 2011-12-10 15:07:33: [968:7309] SMTP session successful, 26599 bytes transferred.
Sat 2011-12-10 15:07:33: [968:7309] Shuffling message(s) into proper queue(s)
Sat 2011-12-10 15:07:33: [968:7309] Message received from mr136.createsend.com [184.106.86.136] with SMTP for [Size 26584] {j:\localq\md00000000.msg}

5 comments:

  1. This IP address is no longer listed, awesome.

    ReplyDelete
  2. My Website is blacklisted WHY ?
    Hello, im the owner of ELLOY.NET and the ip adress of it is 184.154.104.226 and since a week ago my antivirus detect that my website is blacklisted ? im not a spammer and i dont event know anything about spamm ?? all i know that im using joomla and iv got hacked 2 times twice and backed up my website but i dont know how to spamm or anything


    Now all i need is to know how to get my website back ? i mean to make it clean and remove it from the blacklist


    Thank you

    ReplyDelete
    Replies
    1. That IP address is in Singlehop address space and they do not have a good reputation in my opinion. If you are serious about deliverability then you should consider a smart host that has a good reputation and with IP addresses that are not blacklisted. Prices of renting IP addresses should reflect the reputation of the IP management.

      Delete
  3. Dear APEWS!

    Remove the black list the IP address of the following:
    Joker.com.tr
    212.109.99.7
    212.109.99.5

    Your IP re-check our terms.


    Sincerely,

    FOREIGN TRADE ATM PAZ.A.Ş.

    ReplyDelete
  4. HI.

    Please remove the blacklist the ip 200.27.153.41

    Thank you..

    Sincerelu,

    Walter Muñoz Riquelme
    Rhein Chile S.A.

    ReplyDelete