Thursday, November 10, 2011

Ticks and leaches...

I receive no sense of anything when I send a spam email to somewhere it is supposed to receive attention.

It's like catching a nasty parasite as it walks over your carpet and then acting, for me in an unusually thoughtful kind of citizenship way, taking it to the council, prepared to demand that this public health issue be dealt with...only to find- after exhaustive traipsing around from department to department- nothing but an empty room that is supposed to be the right place (no way to tell), no one there, nothing...just a note on the door telling you to post specimens through the cat flap at the bottom of the door.

So what are people supposed to do?
Spamming back is illegal...which is a shame...

It's hard to judge, but how many people know how to find headers (to show where the email has really come from...)  and how many people would bother to find a correct address to forward the damn thing to? I get a bit tired of books that are supposed to contain dialogues with spammers.

I'm also very bored with the all spam comes from Nigeria theory.

It just isn't true.

Spam in the physical world is so much more satisfying: tear the message into tiny bits and return to sender.

Bet that's illegal.

I've given up forwarding emails for investigation, better to post them here for the email gathering bots to harvest their sorry email addresses for other spammers.

So, without further ado, one from Sgt Fred Smith who wants me to visit the ever so reputable BBC news site, and another from PayPal who would like my bank account details.
Hello, My name is Sgt Frederick Smith a United States Army and a member of the USARPAC Medical Team that was stationed in Baghdad, Iraq.

I want to share important information about my experience while serving with the U.S 1st Armored here in Iraq that would be of mutual benefit to us. I however cannot reveal all the information now due to the fact that we have not yet agreed to cooperate in this mutually beneficial enterprise. In other words, I am constrained to hold back some information for security reasons for now, until you have find the time to visit the BBC website links below to enable you have an insight into what I intend to share with you, hoping that the information contained there will pique your interest one way or the other, US Soldiers have been evacuated from Iraq in line with Mr. President's directive and I am among the 50,000 US soldiers left behind to train Iraqi soldiers, Please view the bbc news website below;

http://news.bbc.co.uk/2/.....

After digesting the information contained in the website I will like a confirmation of that so that we can discuss a matter of high importance and mutual interest. I must confess that I am very uncomfortable sending this message to you as I cannot predict your reaction, you may misconstrue the importance and decide to go public, which will be rather unfortunate.

With the worse in mind, I have to say that the essence of this message is strictly for mutual benefit.I will be more explicit upon a response from you. Please respond with a confirmation that you have visited the website and that you are keen on learning more. I will await your thoughts via my personal email address;
sgtfredericksmith@shqiptar.eu
Thanks for your time,

Best Regards,
Sgt Frederick Smith

From Sgt Frederick Smith Wed Nov 9 13:00:57 2011
X-Apparently-To: rideflame via 217.146.188.93; Wed, 09 Nov 2011 16:07:08 +0000
Return-Path:
X-YahooFilteredBulk: 164.73.144.2
Received-SPF: none (domain of fmed.edu.uy does not designate permitted sender hosts)
X-YMailISG: Ys0ApK8WLDuZvupZNxopHEEC.dC09BdARuPurOlzq.IM1gJC
VRibFULvGnEtEQTySPCofZJY67lJ805MPcrnQFEmuo9CDFhbMcWM9yZLaKEL
i1P1G2IVdzUTOsdQnGjBUy0JcP124tBLEFyfSRCPSSqfaAvnV_2z3iX4_nVZ
4.S7Q9gSak7ihgTuKp4YN.HfxK_Zq5.Yyf61WA489a28KBmzfJxD1iUb0lie
pxn86EBtyO2OHfOppxJViLKEuHiXZDA0wLCi8_CFmzeNjP.wUTQJYmepF0pd
jpsJCfqONkfB1ltIGQEACMqu4ZKeSKJnPdI9g2GEWDpG7CTnhZLlBVZBpBai
RyR9zfBUw9xUxq3TQyRPiZLvJpiBy.0H

X-Originating-IP: [164.73.144.2]

Authentication-Results: mta1001.bt.mail.ird.yahoo.com from=fmed.edu.uy; domainkeys=neutral (no sig); from=fmed.edu.uy; dkim=neutral (no sig)
Received: from 127.0.0.1 (EHLO minerva.fmed.edu.uy) (164.73.144.2)
by mta1001.bt.mail.ird.yahoo.com with SMTP; Wed, 09 Nov 2011 16:07:07 +0000
Received: from ra.fmed.edu.uy ([164.73.144.4] helo=www.webmail.fmed.edu.uy)
by minerva.fmed.edu.uy with esmtpsa (TLS1.0:DHE_RSA_AES_256_CBC_SHA1:32)
(Exim 4.69)
(envelope-from )
id 1ROA8H-0006Ks-23; Wed, 09 Nov 2011 13:32:13 -0200
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8;
format=flowed
Content-Transfer-Encoding: 7bit
Date: Wed, 09 Nov 2011 05:00:57 -0800
From: Sgt Frederick Smith
To: undisclosed-recipients:;
Subject: RE
Reply-To:
Mail-Reply-To:
Message-ID: <7f841e385248d8839ce380ac34027995@fmed.edu.uy>
X-Sender: eklasse@fmed.edu.uy
User-Agent: Roundcube Webmail/0.5.1
X-Spam-Score: -1.4
X-Spam-Report: Spam detection software, running on the system "minerva.fmed.edu.uy", has
identified this incoming email as possible spam. The original message
has been attached to this so you can view it (if it isn't spam) or label
similar future email. If you have any questions, see
the administrator of that system for details.
Content analysis details: (-1.4 points, 4.0 required) pts rule name description
---- ---------------------- --------------------------------------------------
-1.4 ALL_TRUSTED Passed through trusted hosts only via SMTP
Content-Length: 1827


Dear PayPal Customer,
You have added Matthew2011@btxyzt,com as a new email address for your Paypal account.

If you did not authorize this change, check with family members and others who may have access to your account first. If you still feel that an unauthorized person has changed your email, submit the form attached to your email in order to keep your original email and restore your Paypal account.

NOTE: The form needs to be opened in a modern browser which has javascript enabled (ex: Internet Explorer 7, Firefox 3, Safari 3, Opera 9)

Please understand that this is a security measure intended to help protect you and your account. We apologize for any inconvenience. If you choose to ignore our request, you leave us no choice but to temporary suspend your account.

Sincerely, PayPal Account Review Department.
Please do not reply to this e-mail. Mail sent to this address cannot be answered. For assistance, log in to your PayPal account and choose the "Help" link in the footer of any page.

From PayPal Wed Nov 9 18:19:47 2011
X-Apparently-To: rideflame via 217.146.188.86; Wed, 09 Nov 2011 18:28:20 +0000
Return-Path:
X-YahooFilteredBulk: 219.234.80.221
Received-SPF: none (domain of ppal.com does not designate permitted sender hosts)
X-YMailISG: RXb9VmkWLDvirz05SNbvgl4Ch3oGwDdoZVVuxE6obJ6BXILa
jJTNJtb7WGyFK3pThal8zkwu7x5Y2Z4_TBa2eYtpio3mH_l8RyIyVGvYN_Dy
Y8G2Ty7F2CpDqmgfpyIvSZe6NY0e6yYCvf06ilMjb1231VocYsjipkaXpmAx
wDfHQ3R1r1TzInWN0b98tSUXnoTWG9nMjlsOHEVr_NZ4JWp0np3H3GP6YZDt
G98ob2T2dED4dGKPehne_tINmxAz_QlKyCpP_P9H5ggpDADKxvD.GuGEDuMo
AJwRsLazTlSLQkJBxcrL9FK60.UH8IowqzcBWYuLza7lZpXz1JyKQFCWWwm2
JmpPCCOWNg--

X-Originating-IP: [219.234.80.221]

Authentication-Results: mta1006.bt.mail.ird.yahoo.com from=ppal.com; domainkeys=neutral (no sig); from=ppal.com; dkim=neutral (no sig)
Received: from 127.0.0.1 (EHLO mailuntai.cn) (219.234.80.221)
by mta1006.bt.mail.ird.yahoo.com with SMTP; Wed, 09 Nov 2011 18:28:20 +0000
Received: from User (unknown [92.83.40.40])
by mailuntai.cn (Postfix) with ESMTP id 5BCB01018E;
Thu, 10 Nov 2011 02:16:02 +0800 (CST)
From: "PayPal"
Subject: You have changed your PayPal email address
Date: Wed, 9 Nov 2011 20:19:47 +0200
MIME-Version: 1.0
Content-Type: multipart/mixed;
boundary="----=_NextPart_000_0029_01C2A9A6.44867D20"
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2600.0000
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000
Message-Id: <20111109181603.5BCB01018E@mailuntai.cn>
To: undisclosed-recipients:;
Content-Length: 68721
The PayPal spam comes from China:
http://whois.domaintools.com/219.234.80.221

And dear Fred Smith is in Latin America:
http://www.lacnic.net/cgi-bin/lacnic/whois?lg=EN