Google Answers Logo
View Question
 
Q: Spam from "Group 16" is overwhelming me ( No Answer,   2 Comments )
Question  
Subject: Spam from "Group 16" is overwhelming me
Category: Computers
Asked by: genpow-ga
List Price: $5.00
Posted: 13 Dec 2002 19:19 PST
Expires: 13 Dec 2002 22:28 PST
Question ID: 124475
I am receiving over 200 spam emails perday. Since each usually has a
large file attachment, it is taking forever to access my email. None
of my spam filters seem to stop this stuff. Here is a typical message
header:
Status: 
                   U 
      Return-Path: 
                   <happyacres@microsoft.com> 
         Received: 
                   from mta5.srv.hcvlny.cv.net ([167.206.5.31]) by emu
                   (EarthLink SMTP Server) with ESMTP id 
                   18lyI64cY3NZFnx0 for <kathysteve@earthlink.net>; 
                   Mon, 9 Dec 2002 16:57:18 -0800 (PST) 
         Received: 
                   from asv8.srv.hcvlny.cv.net (asv8.srv.hcvlny.cv.net
                   [167.206.5.47]) by mta5.srv.hcvlny.cv.net (iPlanet
                   Messaging Server 5.2 HotFix 1.05 (built Nov 6
2002))
                   with ESMTP id 
                   <0H6V00MA6P82RU@mta5.srv.hcvlny.cv.net> for 
                   kathysteve@earthlink.net; Mon, 09 Dec 2002 19:55:14
                   -0500 (EST) 
         Received: 
                   from mail.optonline.net 
                   (ool-18b995ab.dyn.optonline.net [24.185.149.171])
by
                   asv8.srv.hcvlny.cv.net (8.11.6/8.11.6) with SMTP id
                   gBA0sxT20613 for <kathysteve@earthlink.net>; Mon, 
                   09 Dec 2002 19:55:00 -0500 (EST) 
              Date: 
                   Mon, 09 Dec 2002 19:55:24 +0000 (PM) 
             From: 
                   group16 <happyacres@microsoft.com> 
           Subject: 
                   Fw: Outside Consult Letter 
                To: 
                   kathysteve@earthlink.net 
       Message-ID: 
                   <200212100055.gBA0sxT20613@asv8.srv.hcvlny.cv.net>
     MIME-version: 
                   1.0 
          X-Mailer: 
                   Microsoft Outlook Express 5.50.4133.2400 
     Content-type: 
                   multipart/mixed; 
                   boundary="Boundary_(ID_EYfGsezhRNq3BVaI/F7AUw)" 
  X-Mozilla-Status: 
                   8001 
 X-Mozilla-Status2: 
                   00000000 
           X-UIDL: 
                   18lyI64cY3NZFnx0.0
Answer  
There is no answer at this time.

Comments  
Subject: Re: Spam from "Group 16" is overwhelming me
From: skywize-ga on 13 Dec 2002 20:34 PST
 
For spam which you don't want to download (means delete on the
mailserver) a program called mailwasher seems to be good:
http://www.mailwasher.net/

The best spam filter in general is popfile, a learning email
classification tool, http://popfile.sourceforge.net/.
Subject: Re: Spam from "Group 16" is overwhelming me
From: mathtalk-ga on 13 Dec 2002 22:17 PST
 
Don't you just wish these folks could be outed?

Well, from the header information shown, the culprits are at
optonline.net.

The apparent-From "Group 16" is forged.

Here's what the NetworkSolutions/Verisign WHOIS has to say about this
domain:

Registrant:
CSC Holdings, Inc. (OPTONLINE2-DOM)
   1111 Stewart Ave.
   Bethpage, NY 11714
   US

   Domain Name: OPTONLINE.NET

   Administrative Contact:
      eMedia Administrator  (VTDCADRGXO)		cvdomain@CABLEVISION.COM
      eMedia Administrator
      1111 STEWART AVE
      BETHPAGE, NY 11714-3533
      US
      516-803-3000 fax: - - 516-803-1186
   Technical Contact:
      Hostmaster, OOL  (APTKWSNRPI)		hostmaster@CV.NET
      
      111 New South Road
      Hicksville, NY  11801
      US
      (516)393-3281 (516)390-9439

   Record expires on 08-Oct-2005.
   Record created on 07-Oct-1996.
   Database last updated on 14-Dec-2002 01:04:22 EST.

   Domain servers in listed order:

   NS.CV.NET                    167.206.1.30
   NS.CVNET.COM                 167.206.1.103

I would send email with the quoted headers shown in your post here to:

abuse@optonline.net
abuse@cablevision.net
abuse@cv.net

I wouldn't expect much from the first addressee; I have a gut feeling
this domain was set up for no other purpose than spam bots.  But the
other addresses seem to reflect their domain hosts.  If they fail to
reply within 3 business days, I'd refer the matter to
abuse@earthlink.net, with a recommendation that all email forwarding
from those domains be blocked.

regards, mathtalk-ga

Important Disclaimer: Answers and comments provided on Google Answers are general information, and are not intended to substitute for informed professional medical, psychiatric, psychological, tax, legal, investment, accounting, or other professional advice. Google does not endorse, and expressly disclaims liability for any product, manufacturer, distributor, service or service provider mentioned or any opinion expressed in answers or comments. Please read carefully the Google Answers Terms of Service.

If you feel that you have found inappropriate content, please let us know by emailing us at answers-support@google.com with the question ID listed above. Thank you.
Search Google Answers for
Google Answers  


Google Home - Answers FAQ - Terms of Service - Privacy Policy