July 18, 2013

L2.APEWS.ORG False Positive #21

We're publishing this one for the record, the newsletter was found in the junk folder by the user but was in fact subscribed to. The IP address has already been de-listed so this is just for information;

Tue 2013-07-16 05:49:33: [6716:1620] Accepting SMTP connection from [63.121.28.41]
Tue 2013-07-16 05:49:33: [6716:1620] Looking up PTR record for 63.121.28.41 (41.28.121.63.IN-ADDR.ARPA)
Tue 2013-07-16 05:49:34: [6716:1620] D=41.28.121.63.IN-ADDR.ARPA TTL=(59) PTR=[unicamailman301-q1.sb.monster.com]
Tue 2013-07-16 05:49:34: [6716:1620] Gathering A-records for PTR hosts
Tue 2013-07-16 05:49:34: [6716:1620] D=unicamailman301-q1.sb.monster.com TTL=(60) A=[63.121.28.41]
Tue 2013-07-16 05:49:34: [6716:1620] --> 220 xxx.xxx.xxx ESMTP MDaemon 6.7.9; Tue, 16 Jul 2013 05:49:34 -0500
Tue 2013-07-16 05:49:34: [6716:1620] <-- HELO unicamailman301-q1.sb.monster.com
Tue 2013-07-16 05:49:34: [6716:1620] Performing reverse lookup on unicamailman301-q1.sb.monster.com (looking for 63.121.28.41)
Tue 2013-07-16 05:49:34: [6716:1620] D=unicamailman301-q1.sb.monster.com TTL=(60) A=[63.121.28.41]
Tue 2013-07-16 05:49:34: [6716:1620] --> 250 xxx.xxx.xxx Hello unicamailman301-q1.sb.monster.com, pleased to meet you
Tue 2013-07-16 05:49:34: [6716:1620] <-- MAIL FROM:<smas.30-230433_448550_3@e0.monster.com>
Tue 2013-07-16 05:49:34: [6716:1620] Performing reverse lookup on e0.monster.com (looking for 63.121.28.41)
Tue 2013-07-16 05:49:34: [6716:1620] D=e0.monster.com TTL=(10) A=[63.112.169.1]
Tue 2013-07-16 05:49:35: [6716:1620] P=020 D=e0.monster.com TTL=(10) MX=[mailsorter.sb.monster.com] {63.121.30.235}
Tue 2013-07-16 05:49:35: [6716:1620] P=020 D=e0.monster.com TTL=(10) MX=[mailsorter.be.tmpw.net] {208.71.195.235}
Tue 2013-07-16 05:49:35: [6716:1620] Spam Blocker A-record resolution of [41.28.121.63.L2.APEWS.ORG] in progress (DNS Server: 192.168.1.2)...
Tue 2013-07-16 05:49:35: [6716:1620] Spam Blocker D=41.28.121.63.L2.APEWS.ORG TTL=(35) A=[127.0.0.2]
Tue 2013-07-16 05:49:35: [6716:1620] L2.APEWS.ORG LISTED
Tue 2013-07-16 05:49:35: [6716:1620] Message will be accepted and X-RBL-Warning: header will be inserted.
Tue 2013-07-16 05:49:35: [6716:1620] --> 250 <smas.30-230433_4 @ .monster.com>, Sender ok
Tue 2013-07-16 05:49:35: [6716:1620] <-- RCPT TO:<xxx@xxx.xxx>
Tue 2013-07-16 05:49:35: [6716:1620] --> 250 <xxx@xxx.xxx>, Recipient ok
Tue 2013-07-16 05:49:35: [6716:1620] <-- DATA
Tue 2013-07-16 05:49:35: [6716:1620] --> 354 Enter mail, end with <CRLF>.<CRLF>
Tue 2013-07-16 05:49:36: [6716:1620] --> 250 Ok, message saved <Message-ID: emsg.826.7140f20 @ unica7emsg201.be.monster.com>
Tue 2013-07-16 05:49:36: [6716:1620] <-- QUIT
Tue 2013-07-16 05:49:36: [6716:1620] --> 221 See ya in cyberspace
Tue 2013-07-16 05:49:36: [6716:1620] SMTP session successful, 13598 bytes transferred.
Tue 2013-07-16 05:49:36: [6716:1620] Shuffling message(s) into proper queue(s)
Tue 2013-07-16 05:49:36: [6716:1620] Message received from unicamailman301-q1.sb.monster.com [63.121.28.41] <smas.30-230433_448550_3 @ .monster.com> with SMTP for <xxx@xxx.xxx> [Size 0] {j:\localq\1150000318214.msg}

6 comments:

  1. Please remove my "new" ip adress in block list.

    46.45.161.174

    ReplyDelete
  2. Please Remove our Company from your list
    InsightSoftware.com IP = 109.169.74.239
    The blacklisting found on APEWS dates back to 2011-10-05, I can confirm we did have a virus on a users computer that has long since been rectified.

    ReplyDelete
  3. Hi all,
    I'm a bit confused, any help anyone could share would be greatly appreciated.

    We're on the apews.org blacklist as follows:
    Oooops 23.25.217.57 is currently listed in APEWS :-(
    Entry matching your Query: E-179984
    23.0.0.0/8CASE: C-1404
    IP allocations to providers with a bad reputationSpecial Reason:
    No traffic until allocatedHistory:
    Entry created 2007-05-28

    Our provider is comcast. We have a handful of IP #'s.
    If I read this correctly, this entire 23.#.#.# block has been listed since 2007!!!!
    And I'm reading I can't apply to be removed.
    And contacting comcast for this is a joke!
    And I read to not worry as listings get removed with time!!!

    But really... 2007 ?!?!

    Now I'm experiencing problem emailing clients! Our site is 100% legit as one could tell by looking.

    Any help/advice is appreciated :-)
    Nat Brazil

    ReplyDelete
  4. Please remove oir IP address from your lists 200.66.107.3

    www.grupoidesa.com

    ReplyDelete
  5. Hello,
    We have detected that we are in our blacklist of l2.apenws.org, spam.dnsbl.sorbs.net we would like who are the steps to follow, for remome us.

    This is the IP adress: 186.34.71.154

    ReplyDelete
  6. Hello,
    We have detected that we are in our blacklist of
    l2.apenws.org
    dnsbl-3.uceprotect.net
    nsbl.sorbs.net
    dul.dnsbl.sorbs.net

    we would like who are the steps to follow, for remome us.
    muchas gracias

    This is the IP adress: 200.90.202.68

    ReplyDelete