December 13, 2012

L2.APEWS.ORG False Positive #18

Here is the full email header for a newsletter that was found in the junk folder but that the recipient subscribed to;

Thu 2012-12-13 03:14:01: [7552:543] Accepting SMTP connection from [89.31.209.89]
Thu 2012-12-13 03:14:01: [7552:543] --> 220 xxx.xxx.xxx ESMTP MDaemon 6.7.9; Thu, 13 Dec 2012 03:14:01 -0100
Thu 2012-12-13 03:14:01: [7552:543] <-- HELO newsletter.gan.co.za
Thu 2012-12-13 03:14:01: [7552:543] --> 250 xxx.xxx.xxx Hello newsletter.gan.co.za, pleased to meet you
Thu 2012-12-13 03:14:01: [7552:543] <-- MAIL FROM:<bounce-00000000-00000000@ newsletter.gan.co.za>
Thu 2012-12-13 03:14:01: [7552:543] Spam Blocker A-record resolution of [89.209.31.89.L2.APEWS.ORG] in progress (DNS Server: 192.168.1.2)...
Thu 2012-12-13 03:14:01: [7552:543] Spam Blocker D=89.209.31.89.L2.APEWS.ORG TTL=(35) A=[127.0.0.2]
Thu 2012-12-13 03:14:01: [7552:543] L2.APEWS.ORG LISTED
Thu 2012-12-13 03:14:01: [7552:543] Message will be accepted and X-RBL-Warning: header will be inserted.
Thu 2012-12-13 03:14:01: [7552:543] --> 250 <bounce-00000000-00000000@ newsletter.gan.co.za>, Sender ok
Thu 2012-12-13 03:14:01: [7552:543] <-- RCPT TO:<xxx@ xxx.xxx>
Thu 2012-12-13 03:14:01: [7552:543] --> 250 <xxx@ xxx.xxx>, Recipient ok
Thu 2012-12-13 03:14:02: [7552:543] <-- DATA
Thu 2012-12-13 03:14:02: [7552:543] --> 354 Enter mail, end with <CRLF>.<CRLF>
Thu 2012-12-13 03:14:03: [7552:543] --> 250 Ok, message saved <Message-ID: SUPPORT-00000000-00000000-2012.12.13-00.00.00--xxx#xxx.xxx@ newsletter.gan.co.za>
Thu 2012-12-13 03:14:03: [7552:543] <-- RSET
Thu 2012-12-13 03:14:03: [7552:543] Shuffling message(s) into proper queue(s)
Thu 2012-12-13 03:14:03: [7552:543] Message received from newsletter.gan.co.za [89.31.209.89] <bounce-00000000-00000000@ newsletter.gan.co.za> with SMTP for <xxx@ xxx.xxx> [Size 55311] {j:\localq\0000231504.msg}
Thu 2012-12-13 03:14:03: [7552:543] SMTP session successful, 55322 bytes transferred.
Thu 2012-12-13 03:14:03: [7552:543] --> 250 RSET? Well, ok.
Thu 2012-12-13 03:14:08: [7552:543] <-- QUIT
Thu 2012-12-13 03:14:08: [7552:543] --> 221 See ya in cyberspace
Thu 2012-12-13 03:14:08: [7552:543] SMTP session successful, 55328 bytes transferred.

49 comments:

  1. Great, this IP has been delisted recently so we can expect the newsletter to be in the inbox next issue and without complaint by the user.

    ReplyDelete
  2. APEWS
    E-579191
    ip : 181.65.251.178/255.255.255.240
    l2.apews.org
    please remove mi ip address , i cant send messages.

    ReplyDelete
  3. APNEWS

    CASE: C-630
    IP 64.20.51.58
    Please remove IP
    No Spam Here

    ReplyDelete
  4. I am the admin and we just moved to TW Telecom and it appears the Ip we have been given was listed over a year ago. we just got this Dec 1, 2012. Please remove us, we have a spam appliance which stops all spam in/out.

    Oooops 50.58.226.20 is currently listed in APEWS :-(
    Entry matching your Query: E-501369
    50.58.0.0/15
    CASE: C-131
    Unallocated CIDR, no traffic until allocated,
    or allocated to bad reputation provider
    or allocated but dynamic / generically named IPs,
    or bogons, see www.cidr-report.org,
    or orphaned IP / CIDR in routing table
    History:
    Entry created 2011-11-29

    ReplyDelete
  5. Dear Admin,

    We use this IP (200.111.175.237) only to send and receive emails, but now we are in the black list and we bounce. Please borrenos, we will analyze all our equipment and we have no problem.

    Thank you.

    ReplyDelete
  6. This comment has been removed by the author.

    ReplyDelete
  7. Hi Team,

    E-316757

    My Server IP 202.164.36.37 is blacklisted at your end. Actually earlier anti spam was not properly configured on my mail server but now i have properly configured it and it works efficiently. So I request you to please remove it from spam list at your side.

    ReplyDelete
  8. Please unblock my ip address since 122.129.192.4 is not the part of 122.128.0.0/12 blok.

    -------------------------------------

    Oooops 122.129.192.4 is currently listed in APEWS :-(
    Entry matching your Query: E-430999
    122.128.0.0/12
    CASE: C-1404
    IP allocations to providers with a bad reputation
    History:
    Entry created 2010-11-02
    ---------------------------------------

    ReplyDelete
  9. Please unblock my ip pool we have a /26 starting from 108.165.0.193 to 108.165.0.254, we dont have anything to do with spambots/zombies.

    please understand that an /9 are 8 millions of ip addresses... some people are getting affected for this action.

    i appreciate your help on this matter.

    MP.

    ----------------------------------------

    Entry matching your Query: E-411975
    108.128.0.0/9CASE: C-1375
    Spambots/zombies within CIDRHistory:
    Entry created 2010-09-08

    ReplyDelete
  10. Hello,

    I represent a Travel Agency from Romania and we use this IP adress and the domains: zboaragratis.ro and ciambient.ro for e-mails between our company and partner companyes and clients. Soon we changed our ISP and it looks like the curent IP adress is banned over 2 years ago and this causes major problems in conducting our normal business operations.
    I request you to please remove it from spam list becouse we have advanced equipment to stop spam and other illegal internet activities.

    APEWS.ORG Databasetest

    Testresults

    Oooops 86.125.27.158 is currently listed in APEWS :-(
    Entry matching your Query: E-438646
    86.125.0.0/18
    CASE: C-17
    Spambots, zombies, contaminated CIDR, bad reputation provider
    History:
    Entry created 2010-12-20

    Best regards,

    Cosmin Onescu
    General Manager

    Phone: +40 21 3000 166
    Mobile: +40 732 734 734
    mailto:cosmin.onescu@ciambient.ro

    ReplyDelete
  11. Please unblock my IP
    Oooops 202.134.110.10 is currently listed in APEWS :-(


    --------------------------------------------------------------------------------
    Entry matching your Query: E-353804
    202.134.108.0/22
    --------------------------------------------------------------------------------
    CASE: C-1402
    Spambots in CIDR, little or no action by NOC
    --------------------------------------------------------------------------------
    Special Reason:
    Only the ASN/CIDR owner can solve this listing by actioning FAQ 42 apews.org SHUTDOWN BOTS, ZOMBIES, NET ABUSE
    --------------------------------------------------------------------------------
    History:
    Entry created 2008-06-05

    ReplyDelete
  12. Please remove ip 61.19.249.30 from blacklist

    I have been checking ip 61.19.249.30
    Please remove ip 61.19.249.30 from blacklist
    Thank you very much.

    ReplyDelete
  13. Please remove ip 223.27.234.5,115.31.142.234,115.31.142.235 from blacklist

    I have been checking ip 223.27.234.5,115.31.142.234,115.31.142.235 Please remove ip 223.27.234.5,115.31.142.234,115.31.142.235 from blacklist
    Thank you very much.

    ReplyDelete
  14. Please remove ip 61.19.249.30,223.27.234.5,115.31.142.234,115.31.142.235 from blacklist

    I have been checking ip 61.19.249.30,223.27.234.5,115.31.142.234,115.31.142.235
    Please remove ip 61.19.249.30,223.27.234.5,115.31.142.234,115.31.142.235 from blacklist
    Thank you very much.

    ReplyDelete
  15. Hello,

    Please remove these two IP's from blaclist, 121.96.36.4 and 202.78.114.4 I have been fixing my two mail server for email auto responder.

    "/var/spool/vacation/vacation.pl". Command output: Can't locate
    MIME/EncWords.pm in @INC (@INC contains: /usr/local/lib/perl5/5.14.2/BSDPAN
    /usr/local/lib/perl5/site_perl/5.14.2/mach
    /usr/local/lib/perl5/site_perl/5.14.2 /usr/local/lib/perl5/5.14.2/mach
    /usr/local/lib/perl5/5.14.2 .) at /var/spool/vacation/vacation.pl line 99.
    BEGIN failed--compilation aborted at /var/spool/vacation/vacation.pl line
    99.

    ReplyDelete
  16. Please remove my company IP as we had check and remove th virus.
    Thank you.


    Oooops 219.92.229.66 is currently listed in APEWS :-(


    --------------------------------------------------------------------------------
    Entry matching your Query: E-238843
    219.92.192.0/18
    --------------------------------------------------------------------------------
    CASE: C-174
    AS4788 MY, ISP permits abuse and/or ignores criminal activity
    --------------------------------------------------------------------------------
    History:
    Entry created 2007-07-07

    ReplyDelete
  17. Hello
    Please remove these two IP's from blacklist 89.35.6.15 and 89.35.6.16. I have been fixing my two mail server for email auto responder.


    Oooops 89.35.6.15 is currently listed in APEWS :-(
    --------------------------------------------------------------------------------
    Entry matching your Query: E-271256
    89.35.4.0/22
    --------------------------------------------------------------------------------
    CASE: C-669
    AS30890 RO, ISP permits abuse and/or ignores criminal activity
    --------------------------------------------------------------------------------
    Special Reason:
    ISP permits abuse and/or ignores criminal activity
    ------------------------------------------------------------------
    Entry matching your Query: E-271256
    89.35.4.0/22
    --------------------------------------------------------------------------------
    CASE: C-669
    AS30890 RO, ISP permits abuse and/or ignores criminal activity
    --------------------------------------------------------------------------------
    Special Reason:
    ISP permits abuse and/or ignores criminal activity
    --------------
    History:
    Entry created 2007-07-17

    ReplyDelete
  18. please remove our ip 85.43.150.90 , we can't send the e-mail.
    We are an Italian school that sends the e-mail to professors.
    Thank you

    ReplyDelete
  19. Please remove the following two sub-nets from your list? These are assigned to us form our carrier, CenturyLink (Formerly Qwest) who has the 46.182.56.0/21 block within the 46.182.0.0/16 currently listed.

    46.182.58.1/29
    46.182.58.8/29

    ---------------------------------------------------
    Oooops 46.182.58.1 is currently listed in APEWS :-(
    Entry matching your Query: E-533344
    46.182.0.0/16
    CASE: C-131
    Unallocated CIDR, no traffic until allocated,
    or allocated to bad reputation provider
    or allocated but dynamic / generically named IPs,
    or bogons, see www.cidr-report.org,
    or orphaned IP / CIDR in routing table
    History:
    Entry created 2012-04-29

    ReplyDelete
  20. Please remove our IP 178.250.133.227 from your blacklist. We are a registered charity.

    ReplyDelete
  21. Please remove our IP address 203.199.134.153. Our Email Service is not working due to this blacklisting please remove it.

    ReplyDelete
  22. Hello, sirs

    It appears E-498046 is a false positive.

    200.115.128.0/19 is listed as unallocated but part of it is allocated.

    200.115.128.0/20 is allocated as seen on http://lacnic.net/cgi-bin/lacnic/whois?lg=SP&query=200.115.128/20

    Please delist the entry from APEWS.

    Thanks

    ReplyDelete
  23. Hello,

    Please remove our IP addres from APEWS.

    We registered our domain in 2011-08-29 and the IP we have been given was listed in APEWS in 2007-06-22


    Testresults
    Oooops 89.161.136.125 is currently listed in APEWS :-(
    Entry matching your Query: E-217285
    89.161.128.0/17CASE: C-82
    IP space of "hot" UCE/UBE operations per NANAS, NANAE, UCEtraps & published statisticsSpecial Reason:
    One/more bots in CIDR, see Usenet news.admin.net-abuse.sightings SHUT DOWN BOTS, ZOMBIES, NET ABUSEHistory:
    Entry created 2007-06-22

    ReplyDelete
  24. Hi,

    Our our customer is using this blacklist to filter spam and our IP 74.7.210.133 is currently listed.

    It looks like this is an old entry from 2008-07-25. This blacklist is blocking a larger segment of IP addresses, and we should not be included.

    Please remove. Thanks.

    --------------------
    Oooops 74.7.210.133 is currently listed in APEWS :-(
    Entry matching your Query: E-362517
    74.7.208.0/21
    CASE: C-1403
    Dynamic IP space, generic DNS/rDNS, no PTR
    Direct connections to MX not permitted, you
    need to use your ISP servers or smarthost
    Special Reason:
    Dynamic IP, generic DNS, missing rDNS/PTR not permitted for direct email connection. You must use correctly configured [with registered working abuse contact] static IP / ISP mail servers / smarthost service
    History:
    Entry created 2008-07-25

    ReplyDelete
  25. Please delist the following sub-net. I, "Dream Train Internet" got some prefixes including this listed subnet (27.120.64.0/18 and 27.120.128.0/17) and no one is spamming.

    Entry matching your Query: E-599513
    27.120.0.0/13

    -----
    Oooops 27.120.102.82 is currently listed in APEWS :-(
    Entry matching your Query: E-599513
    27.120.0.0/13
    CASE: C-18
    Spambots, zombies, contaminated CIDR, bad reputation provider
    History:
    Entry created 2012-08-25

    ReplyDelete
  26. Dear Administrator ,

    Please remove our IP from your database its blacklisted

    83.229.43.140 and 83.229.43.142

    We are unable to send emails and we have anitspam and antivirus service in place, pls request you to do so, it has been 3 weeks now we are unable to send emails

    Thanks
    Suhasini

    ReplyDelete
  27. hello, pls remove our Ip 83.229.43.142 and 83.229.43.140 , its showing up in your blacklist database.

    ReplyDelete
  28. Hello Administrator. Please remove 210.1.31.82 and 210.1.31.84 from the database. Thank you so much.

    Oooops 210.1.31.82 is currently listed in APEWS :-(
    Entry matching your Query: E-238692
    210.1.31.0/24CASE: C-173
    AS4750 TH, ISP permits abuse and/or ignores criminal activityHistory:
    Entry created 2007-07-07
    -------------------------------------------------------------------------
    Oooops 210.1.31.84 is currently listed in APEWS :-(
    Entry matching your Query: E-238692
    210.1.31.0/24CASE: C-173
    AS4750 TH, ISP permits abuse and/or ignores criminal activityHistory:
    Entry created 2007-07-07

    ReplyDelete
  29. Please remove, this is not spam...

    APEWS

    Oooops 188.165.93.5 is currently listed in APEWS :-(
    Entry matching your Query: E-439134
    188.165.64.0/18
    CASE: C-17
    Spambots, zombies, contaminated CIDR, bad reputation provider
    History:
    Entry created 2010-12-23

    ReplyDelete
  30. Hello,
    I'm an admin at ISP which owns 89.46.160.0/19. These are static assigned IPs to busniess customers (not home user)
    Please remove this bloc from the list, or at least IPs: 89.46.160.131 89.46.160.142

    Entry matching your Query: E-432499
    89.46.160.0/19
    CASE: C-130
    One or more bots in ASN / CIDR, unprofessional / negligent owner
    History:
    Entry created 2010-11-12

    ReplyDelete
  31. Hello,
    I'm an ISP, please delete the following subnet from your list
    Thank you!!

    212.89.160.0/19
    descr: ECSNET
    origin: AS49864
    mnt-by: ROCKY-MNT

    Oooops 212.89.191.10 is currently listed in APEWS :-(

    Entry matching your Query: E-274202
    212.89.160.0/19

    CASE: C-732
    AS8509 GR, ISP permits abuse and/or ignores criminal activity

    Special Reason:
    ISP permits abuse and/or ignores criminal activity

    History:
    Entry created 2007-07-19

    ReplyDelete
  32. APEWS: E-287089

    Oooops 89.190.64.21 is currently listed in APEWS :-(

    Entry matching your Query: E-287089
    89.190.64.0/19

    CASE: C-130
    One or more bots in ASN / CIDR, unprofessional / negligent owner

    Special Reason:
    Only the ASN/CIDR owner can solve this listing by actioning FAQ 42 apews.org SHUTDOWN BOTS, ZOMBIES, NET ABUSE

    History:
    Entry created 2007-08-20

    route: 89.190.64.0/19
    descr: "N_SYS s.r.o."
    origin: AS41088
    mnt-by: CZNSYS-MNT

    Hello, we're ISP and have listed whole network. Can you please check if it's not a mistake? I don't believe that our network is so long on blacklist when it's not listed anywhere elese. I checked many other black lists. Now our customer has a problem with sending e-mails. Thank you.

    ReplyDelete
  33. Good morning Apews, we need your help, we are a serious company in the area of consulting IT, we are not spammers, I believe it is a failure that ran our control where all measures are being taken to correct them, we need the range of ips 68.169.48.0/20 is removed from the blacklist because it is affecting business. description follows:

    Oooops 68.169.54.220 is currently listed in APEWS :-(
    Entry matching your Query: E-497239
    68.169.48.0/20CASE: C-258
    Spambots, zombies, Contaminated CIDR, bad reputation provider

    my contacts follows:


    jose.lima @ aotrabalho.com.br
    jose.lima @ brwit.com.br

    Thank you for your attention and understanding.

    ReplyDelete
  34. Please remove, this is not spam...

    APEWS

    46.165.221.15 is currently listed in APEWS we setup a brand new webserver on Leaseweb 2 months ago and cannot send emails because of this listing please remove.

    ReplyDelete
  35. Hello,

    I am the 82.223.148.232 server administrator.
    The SMTP service is configured properly and does not allow the sending spam.
    I wish our IP eliminated from your list, Thanks.

    --------------------------

    Oooops 82.223.148.232 is currently listed in APEWS :-(

    --------------------------------------------------------------------------------
    Entry matching your Query: E-567431
    82.223.148.0/24
    --------------------------------------------------------------------------------
    CASE: C-36
    Spammer / Scammer / Scanner / Zombie / other within this CIDR
    --------------------------------------------------------------------------------
    History:
    Entry created 2012-06-02

    ------

    Eduardo Juan
    SMJ S.L.U

    ReplyDelete
  36. Dear Dir,

    This time I am writing to withdraw from its blacklist, for our part have made the respective corrected the error checks.

    IP addresses are:

    181.177.232.4
    181.177.232.5
    181.177.232.6


    Sincerly

    Elvis Espinoza

    ReplyDelete
  37. Dear good day. Please delete the following IP 190.222.90.222 from its blacklist. Computer equipment were reviewed and all this correctly. Use is important because we can not send or receive corporate emails. In advance thanks for the support. Atte. Mario Benites

    ReplyDelete
  38. APEWS
    Testresults
    Oooops 200.62.224.209 is currently listed in APEWS
    Entry matching your Query: E-266017
    200.62.224.209
    200.62.224.201
    CASE: C-534
    AS12252 PE, ISP permits abuse and/or ignores criminal activity
    Special Reason:
    ISP permits abuse and/or ignores criminal activity
    History:
    Entry created 2007-07-16

    Dominio: mincetur.gob.pe
    l2.apews.org
    please remove mi ip address , i cant send messages.

    ReplyDelete
  39. Please remove ip 112.78.11.204 form blacklist
    thanks you!

    ReplyDelete
  40. Hello, we are not span

    Our ip 200.208.155.202 is locked and can not longer send nor receive some e-mails, please remove us from your list, thank you.

    ReplyDelete
  41. please remove ip 61.19.249.30 from blacklist l2.apews.org

    thank you

    ReplyDelete
  42. Oooops 87.241.38.184 is currently listed in APEWS :-(

    Entry matching your Query: E-461711
    87.241.32.0/19
    CASE: C-20
    Spambots, zombies, contaminated CIDR, bad reputation provider
    History: Entry created 2011-03-05

    Please remove ip 87.241.38.184

    ReplyDelete
  43. Oooops 205.151.45.4 is currently listed in APEWS :-(
    Entry matching your Query: E-449985
    205.151.45.0/24
    CASE: C-14
    Spambots, zombies, contaminated CIDR, bad reputation provider
    History:
    Entry created 2011-01-16

    Please clear the ip adr range.

    ReplyDelete
  44. Oooops 103.26.43.153 is currently listed in APEWS :-(
    Entry matching your Query: E-629717
    103.26.0.0/16
    CASE: C-131
    Unallocated CIDR, no traffic until allocated,
    or allocated to bad reputation provider
    or allocated but dynamic / generically named IPs,
    or bogons, see www.cidr-report.org,
    or orphaned IP / CIDR in routing table

    For your info, we have split our IP range to smaller range as below :

    103.26.43.192/27
    103.26.42.0/24
    103.26.43.0/25
    103.26.43.224/27
    103.26.43.128/26
    103.26.40.0/24
    103.26.41.0/24

    can you please whitelist our IP range?

    ReplyDelete
  45. This comment has been removed by the author.

    ReplyDelete
  46. Hello,
    our companys IP listed on your blacklist please remove it from blacklist.
    we are not spammers

    ReplyDelete
  47. Hi,

    Please remove the following IP address from blacklist. (213.229.189.190)

    If I search this IP on APEWS I obtained the following result :
    Entry matching your Query: E-449125
    213.229.188.0/22
    CASE: C-15
    Spambots, zombies, contaminated CIDR, bad reputation provider
    History:
    Entry created 2011-01-12

    Thanks in advance.

    ReplyDelete
  48. Hi,

    Please remove the following IP address from blacklist. (193.193.255.65)

    If I search this IP on APEWS I obtained the following result :

    193.193.255.65 is currently listed in APEWS :-(
    Entry matching your Query: E-541234
    193.193.224.0/19CASE: C-258
    Spambots, zombies, contaminated CIDR, bad reputation providerHistory:
    Entry created 2012-05-06

    Thanks in advance.

    ReplyDelete
  49. Oooops 122.129.77.147 is currently listed in APEWS :-(
    Entry matching your Query: E-430999
    122.128.0.0/12CASE: C-1404
    IP allocations to providers with a bad reputationHistory:
    Entry created 2010-11-02

    Please remove my IP or suggest any solution. Thank you.

    ReplyDelete