March 18, 2012

L2.APEWS.ORG False Positive #13

Typical eh, spoke too soon! Got a user claiming the following shouldn't have been in his junk folder and on further checking we find the IP address to be that of a website offering a newsletter. CIDR seems OK too, here is the email header;

Sat 2012-03-17 03:26:37: [7708:766] Accepting SMTP connection from [71.19.224.98]
Sat 2012-03-17 03:26:37: [7708:766] Looking up PTR record for 71.19.224.98 (98.224.19.71.IN-ADDR.ARPA)
Sat 2012-03-17 03:26:37: [7708:766] D=98.224.19.71.IN-ADDR.ARPA TTL=(59) PTR=[www3.tiltedpixel.com]
Sat 2012-03-17 03:26:37: [7708:766] Gathering A-records for PTR hosts
Sat 2012-03-17 03:26:38: [7708:766] D=www3.tiltedpixel.com TTL=(240) A=[71.19.224.98]
Sat 2012-03-17 03:26:38: [7708:766] --> 220 xxx.xxx.xxx ESMTP MDaemon 6.7.9; Sat, 16 Mar 2012 13:06:38 -0500
Sat 2012-03-17 03:26:38: [7708:766] <-- EHLO www3.tiltedpixel.com
Sat 2012-03-17 03:26:38: [7708:766] Performing reverse lookup on www3.tiltedpixel.com (looking for 71.19.224.98)
Sat 2012-03-17 03:26:38: [7708:766] D=www3.tiltedpixel.com TTL=(240) A=[71.19.224.98]
Sat 2012-03-17 03:26:38: [7708:766] --> 250-xxx.xxx.xxx Hello www3.tiltedpixel.com, pleased to meet you
Sat 2012-03-17 03:26:38: [7708:766] --> 250-ETRN
Sat 2012-03-17 03:26:38: [7708:766] --> 250-AUTH=LOGIN
Sat 2012-03-17 03:26:38: [7708:766] --> 250-AUTH LOGIN CRAM-MD5
Sat 2012-03-17 03:26:38: [7708:766] --> 250-8BITMIME
Sat 2012-03-17 03:26:38: [7708:766] --> 250 SIZE 0
Sat 2012-03-17 03:26:38: [7708:766] <-- MAIL FROM: SIZE=1656
Sat 2012-03-17 03:26:38: [7708:766] Performing reverse lookup on www3.tiltedpixel.com (looking for 71.19.224.98)
Sat 2012-03-17 03:26:38: [7708:766] D=www3.tiltedpixel.com TTL=(239) A=[71.19.224.98]
Sat 2012-03-17 03:26:38: [7708:766] Spam Blocker A-record resolution of [98.224.19.71.L2.APEWS.ORG] in progress (DNS Server: 192.168.1.2)...
Sat 2012-03-17 03:26:38: [7708:766] Spam Blocker D=98.224.19.71.L2.APEWS.ORG TTL=(35) A=[127.0.0.2]
Sat 2012-03-17 03:26:38: [7708:766] L2.APEWS.ORG LISTED
Sat 2012-03-17 03:26:38: [7708:766] Message will be accepted and X-RBL-Warning: header will be inserted.
Sat 2012-03-17 03:26:38: [7708:766] --> 250 , Sender ok
Sat 2012-03-17 03:26:38: [7708:766] <-- RCPT TO:
Sat 2012-03-17 03:26:38: [7708:766] --> 250 , Recipient ok
Sat 2012-03-17 03:26:38: [7708:766] <-- DATA
Sat 2012-03-17 03:26:38: [7708:766] --> 354 Enter mail, end with .
Sat 2012-03-17 03:26:38: [7708:766] --> 250 Ok, message saved
Sat 2012-03-17 03:26:38: [7708:766] <-- QUIT
Sat 2012-03-17 03:26:38: [7708:766] --> 221 See ya in cyberspace
Sat 2012-03-17 03:26:38: [7708:766] SMTP session successful, 959 bytes transferred.
Sat 2012-03-17 03:26:38: [7708:766] Shuffling message(s) into proper queue(s)
Sat 2012-03-17 03:26:38: [7708:766] Message received from www3.tiltedpixel.com [71.19.224.98] with SMTP for [Size 948] {j:\localq\md000000.msg}

Hopefully this one will get resolved shortly too.

42 comments:

  1. we send out e-bills from dsibilling.com 83.244.165.130 and note that that ip is listed and should not be.

    ReplyDelete
    Replies
    1. Just checked this IP address, also no longer listed.

      Delete
  2. This was one of those CIDR that hadn't been allocated at the time APEWS listed it to prevent it being abused by hijackers. It was subsequently allocated in smaller CIDR so rightfully we now find that the IP address has been delisted.

    ReplyDelete
  3. We have an exchange server at 65.82.187.121 kwblaw.com it is listed. It should not be.

    ReplyDelete
    Replies
    1. In the last day or so your IP address has been delisted. Interestingly the CIDR was listed for being of generic dns or missing reverse dns. Much of the ISP-announced CIDR is as described and not in the spirit of the RFCs for the sending of emails.

      Delete
  4. We have an exchange server at 70.28.33.149 aquadis.com it is listed. It should not be.

    ReplyDelete
    Replies
    1. Checked this IP address and it is still listed at this time.

      Delete
    2. Correction, it is still listed but the listing has changed suggesting that is is or has received attention. It now shows as a /19 with incomplete or missing rDNS etc. There are spam sources in that CIDR, even in the /24 i.e. your close IP address neighbors.

      Delete
    3. This IP address is not now listed but the CIDR has many abusive hosts in it. There are even spammers inside your /24 i.e. your close IP address neighbors and that can easily result in blacklisting elsewhere including private lists, you must decide the value of your emails and sending them from that IP address.

      Delete
  5. Hello, we have a Zimbra server at 200.111.150.74 atomica.cl it is listed, but it shouldn't be, please remove from your blacklist database ASAP.

    Best regards
    Patricio Rebolledo
    Network Administrator
    Atomica Audiovisual Ltda.

    ReplyDelete
    Replies
    1. This IP address is not now listed but the CIDR has many abusive hosts in it. There are even spammers inside your /24 i.e. your close IP address neighbors and that can easily result in blacklisting elsewhere including private lists, you must decide the value of your emails and sending them from that CIDR / ISP or an alternative.

      Delete
  6. Hello Admin,
    Our mailserver at 80.89.176.226, 80.89.176.227, 80.89.176.228 is listed, and it shouldn't be.

    Entry matching your Query: E-176296
    80.89.176.0/24CASE: C-82
    IP space of "hot" UCE/UBE operations per NANAS, NANAE, UCEtraps & published statisticsSpecial Reason:
    Escalations, high risk /24 blocksHistory:
    Entry created 2007-05-23

    Please help remove.

    BR
    Ugorji Nnanna
    L3 Support
    Cobranet Limited

    ReplyDelete
    Replies
    1. Cobranet manage CIDR in Nigeria according to Whois, and the reference in that listing is for scalation which would suggest a reputation for inaction against abuse. The IP addresses are still listed at this time, need to check again in case of a change.

      Delete
  7. Hello Admin,

    My IP at 203.125.59.88 is listed, and it shouldn't be.


    Oooops 203.125.59.88 is currently listed in APEWS :-(

    --------------------------------------------------------------------------------
    Entry matching your Query: E-467392
    203.125.32.0/19
    --------------------------------------------------------------------------------
    CASE: C-258
    Spambots, zombies, contaminated CIDR, bad reputation provider
    --------------------------------------------------------------------------------
    History:
    Entry created 2011-04-02

    Could you please help me to remove it.

    Thanks.

    James Ng
    IT administrator of alpine

    ReplyDelete
    Replies
    1. Your IP address appears to have been delisted recently.

      Delete
  8. I have a server 122.252.14.176 that is listed and shouldn't be. Can you please remove it?

    ReplyDelete
    Replies
    1. This IP address was also delisted in the last few days.

      Delete
  9. Hello
    Oooops 213.184.245.118 is currently listed in APEWS :-(
    Entry matching your Query: E-449711
    213.184.240.0/20
    CASE: C-14
    Spambots, zombies, contaminated CIDR, bad reputation provider
    History:
    Entry created 2011-01-15

    Could you please help me to remove it.

    Thanks.

    ReplyDelete
    Replies
    1. Your IP address was also delisted in recent days.

      Delete
  10. please remove ip address 87.101.137.10 from the list

    Thanks

    Oooops 87.101.137.10 is currently listed in APEWS :-(
    Entry matching your Query: E-409666
    87.101.128.0/20CASE: C-1375
    Spambots/zombies within CIDRHistory:
    Entry created 2010-08-28

    ReplyDelete
    Replies
    1. This IP address is still listed but then Whois says "SaudiArabia PPPOE WIMAX for ZOOOM Residential customers" which doesn't seem right for commercial email servers?

      Delete
    2. Please remove ip address 87.101.137.10 from the APEWS blacklist.This ip address is used for commercial email server only.

      Delete
  11. Hi Administrator
    We are a serious company and our server 200.44.114.162 that is listed and shouldn't be. Can you please remove it?
    Oooops 200.44.114.162 is currently listed in APEWS :-(

    --------------------------------------------------------------------------------
    Entry matching your Query: E-359159
    200.44.64.0/18
    --------------------------------------------------------------------------------
    CASE: C-1375
    Spambots/zombies within CIDR

    ReplyDelete
  12. Hello Administrator,

    We are a publishing company and our web servers 63.131.154.227, 63.131.154.228 & 63.131.154.229 are listed.

    Can we be removed please.

    Entry matching your Query: E-435641
    63.131.152.0/21CASE: C-17
    Spambots, zombies, contaminated CIDR, bad reputation providerHistory:
    Entry created 2010-12-10

    ReplyDelete
  13. Dear Team,

    As we found our mail server ip address: 202.71.153.148/147 has been listed in apews.org site so we are requesting please remove it as soon as possible.


    Thanks & Regards,
    Jagannath Patro

    ReplyDelete
  14. Dear Team,

    My self Jagannath Patro working as a system administrator for a Indian based company and we found wrongly our mail server ip address: 202.71.153.148/147 has been listed in apews.org site so we are requesting please remove it as soon as possible.


    Thanks & Regards,
    Jagannath Patro

    Oooops 202.71.153.148 is currently listed in APEWS :-(


    --------------------------------------------------------------------------------
    Entry matching your Query: E-243427
    202.71.153.0/24
    --------------------------------------------------------------------------------
    CASE: C-232
    AS17447 IN, ISP permits abuse and/or ignores criminal activity
    --------------------------------------------------------------------------------
    History:
    Entry created 2007-07-07

    ReplyDelete
  15. IP Address 67.59.183.77 is listed in APEWS but it should not be. Please remove from the list.

    Oooops 67.59.183.77 is currently listed in APEWS :-(
    Entry matching your Query: E-452976
    67.59.176.0/21
    CASE: C-813
    Spambots, zombies, contaminated CIDR, bad reputation provider
    History:
    Entry created 2011-01-27

    ReplyDelete
  16. Please, remove 122.201.113.199 & 122.201.113.200 listings.

    http://www.mxtoolbox.com/SuperTool.aspx?action=blacklist%3a122.201.113.199

    My ISP insists apews.org is wrong, but they have no recourse.

    The addresses above are our corporate static addresses, so we have the authority to request whitelisting.

    ReplyDelete
  17. Hello
    178.18.199.42 is currently listed in APEWS :-(
    Entry matching your Query: E-450917
    178.18.128.0/17
    CASE: C-14
    Spambots, zombies, contaminated CIDR, bad reputation provider

    ReplyDelete
  18. Oooops 201.199.100.91 is currently listed in APEWS :-(


    --------------------------------------------------------------------------------
    Entry matching your Query: E-270552
    201.199.0.0/17
    --------------------------------------------------------------------------------
    CASE: C-651
    AS11830 CR, ISP permits abuse and/or ignores criminal activity
    --------------------------------------------------------------------------------
    Special Reason:
    ISP permits abuse and/or ignores criminal activity
    --------------------------------------------------------------------------------
    History:
    Entry created 2007-07-17

    ReplyDelete
  19. IP Address 61.222.245.12 is listed in l2.apews.org but it should not be. Please remove from the list.
    thank you

    ReplyDelete
  20. Our mail server ip address 92.45.79.94 is listed only APEWS. Please remove from list.

    ReplyDelete
  21. We have an exchange server for this domain: acbz.com.br it is listed. It should not be.

    ReplyDelete
  22. Hello,
    Oooops 177.72.32.62 is currently listed in APEWS :-(
    Entry matching your Query: E-520140
    177.64.0.0/11
    CASE: C-131
    Unallocated CIDR, no traffic until allocated,
    or allocated to bad reputation provider
    or allocated but dynamic / generically named IPs,
    or bogons, see www.cidr-report.org,
    or orphaned IP / CIDR in routing table
    History:
    Entry created 2012-04-10

    Please remove from the list.
    Thanks.

    Claudio L. Santos
    IT administrator of FILOAUTO IND E COM LTDA

    ReplyDelete
  23. Our IP address is listed 66.228.48.30

    CASE: C-258
    Spambots, zombies, contaminated CIDR, bad reputation provider
    History:
    Entry created 2011-08-28

    Can you please remove, the IP address was assigned to us by our new web host in Feb. 2012. Thank you.

    Thank you,

    Jerry Johnston
    E.D. Bullard Company
    www.bullard.com

    ReplyDelete
  24. My IP address 76.216.172.229 is listed, I do not send spam out and the only lists I email to are small groups of volunteers in our small non profit.

    ReplyDelete
  25. Our IP address is listed 91.81.107.141

    Oooops 91.81.107.141 is currently listed in APEWS :-(
    Entry matching your Query: E-627481
    91.81.0.0/17
    CASE: C-258
    Spambots, zombies, contaminated CIDR, bad reputation provider
    History:
    Entry created 2013-05-01


    Can you please remove the IP address from blacklist. Thanks

    ReplyDelete
  26. Dear good morning;
    Please ask him to help me to remove my email from the blacklist, since this domain. Hojoloja. It is very important to our business,
    IP. 201.218.30.195
    testresults
    Oooops 201.218.30.195 is currently listed in APEWS :-(
    Entry matching your Query: E-281679
    201.218.30.0/24CASE​​: C-951
    AS19169 EC, ISP Permits abuse and / or criminal ignore activitySpecial Reason:
    Permits ISP abuse and / or criminal ignore activityHistory:
    Entry created 2007-08-03



    thanks

    ReplyDelete
  27. my ip address is 124.123.50.95
    E-321078 C-1402
    Spambots in CIDR, little or no action by NOC
    please delist my ip address soon and solve my problem

    ReplyDelete
  28. Hello
    Oooops 61.222.245.12 is currently listed in APEWS :-(

    Entry matching your Query: E-464614
    61.222.224.0/19
    CASE: C-18
    Spambots, zombies, contaminated CIDR, bad reputation provider
    History:
    Entry created 2011-03-14

    Can you please remove the IP address from blacklist. Thanks

    ReplyDelete
  29. نورتم احبائي
    http://jeuxjeux99.blogspot.com/
    العاب سيارات هنا سوف ستجدون تشكيلة مميزة من أروع و أفضل ما يوجد في العاب سيارات يمكنك اللعب مباشرة وبسهولة تامة بدون تحميل و مرحبا بالجميع في موقع العاب سيارات .

    ReplyDelete
  30. Please remove 64.128.246.210 from your blacklist. We are a law firm. Thank you.

    ReplyDelete