Hi all!
I haven't been here for a decade or so, but there is a spammer that I'm
quite fed up with, but my spamfighting is a little rusty, so I'd like
some help if you can.
First, can I have a hat check on Bluehost.com, please? That's his ISP,
and he's been there for a while. I've sent first one detailed complaint
there, they said they had taken action. Then, he continued, they said
they had taken action, and now I just got another. I don't know if there
is a point sending more in their direction. If not, can anybody help me
find their upstream?
The specific spamvertized site is friluftsbutikken.com. It is run by a
company called "Romerike profilering":
https://www.purehelp.no/m/company/details/romerikeprofileringas/999329497 tracking that down, I find them to be associated with this man:
https://www.purehelp.no/m/role/viewBoardMember/46930801/joakimtonidahlbom
which is a name I recognize. He started his spam operation in 2009, and
has been bothering me ever since, but with low frequency.
Between 2012 and 2015, he had developed a sense of impunity so that he
stopped being shy about it, and used his full name in public
whois-registries, but after 2015, nobody does that anymore, so it became
harder to tell it is him. His operational pattern is to spam a lot for
a while, then get new domain names and wait a few months before a new
spam run. So, it is a whack-a-mole game.
For some time now, he has spamvertized what appears to be his own
operation or possibly his affiliate's operation, friluftsbutikken.com.
This has caused a major problem for an unrelated shop,
friluftsbutikken.no, and I am embarrassed to admit I fired a complaint
to them, and they said that they got a lot of these complaints. I've had
quite enough.
In addition to friluftsbutikken.com, his domains include habrev.com, probrev.com, probrev.site. They seem to at least have Bluehost as their
DNS provider. He's also figured regularly on SURBL, but apparently not
now. I have a list about 30 domains that he have used earlier. The most
recent spam came from nyhetsbrev1.org.
As I said, I have sent complaints to Bluehost (the first in late June),
but they have had no effect. So, what do you suggest I do next?
Please see below for the most recent spam with most of it.
Cheers,
Kjetil
---------- Spam excerpt ------------
Return-Path: <
[email protected]>
Delivered-To:
[email protected]
Received: (qmail 10454 invoked by uid 121); 31 Jul 2021 06:37:57 -0000 X-Spam-Checker-Version: SpamAssassin 3.4.2 (2018-09-13) on pooh.kjernsmo.net X-Spam-Level: *********
X-Spam-Status: Yes, score=9.0 required=5.0 tests=BAYES_99,BAYES_999,
DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,HTML_IMAGE_RATIO_02,
HTML_MESSAGE,SPF_HELO_NONE,SPF_PASS autolearn=disabled version=3.4.2
X-Spam-Flag: YES
X-Virus-Checked: by ClamAV 0.103.2 on pooh
X-Virus-Found: No
Received: from server.nyhetsbrev1.org (HELO server.nyhetsbrev1.org) (162.214.212.208)
by pooh (qpsmtpd/0.94) with ESMTP; Sat, 31 Jul 2021 08:37:54 +0200 Authentication-Results: pooh; auth=none
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
d=nyhetsbrev1.org; s=default; h=Content-Type:MIME-Version:List-Owner:
List-Subscribe:List-Unsubscribe:List-Help:Message-ID:From:Date:Subject:To:
Sender:Reply-To:Cc:Content-Transfer-Encoding:Content-ID:Content-Description:
Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:
In-Reply-To:References:List-Id:List-Post:List-Archive;
bh=gdpu6nM4LMapFcIzxmn0PvECnLPNbz2SNc+Ieg5vxlI=; b=Mo/IUHEc7YhqMOPg2lj4uZL0xk
9dqEo0odX+poh3i9UHE41SGIN8twKm5gTnB61WOjgKQMWByDeNxfkRfSX6adx/uqCsr/FOrGDcmxM
HMfAlyNWKt3uZ8Cpk9PYs+L1HXOWOYFL8CaxP0r1eg+k7QtRII5Gk2J2hmMEBFiDfzaVXcEUMKM0h
XrDj5Co8JCR9zTTJZJU95Cwx3ZhFOf3Kfa7Itg8WNbDnBW1r+9BK5vJNGZisJKUUOj9/hCNdC6aI/
kHgXPBsCP04uTMw9RmkbXCC6/xNxiIDMo/qhf1+pCOjjVHRfPqwZjY09G5fVafqytBCekSw/ktsH5
pkHkTF3g==;
Received: from nyhetsb2 by server.nyhetsbrev1.org with local (Exim 4.93)
(envelope-from <
[email protected]>)
id 1m9id0-0002Ue-7d
for
[email protected]; Sat, 31 Jul 2021 00:37:46 -0600
To:
[email protected]
Subject: *** SPAM *** =?UTF-8?Q?P=C3=85_LAGER_-_RASK_LEVERING_-_Sikre_deg_din_SUP_pakke_n?= =?UTF-8?Q?=C3=A5_-_Med_5_=C3=A5rs_garanti!?=
X-PHP-Script: nyhetsbrev1.org/admin/index.php for 193.75.57.178 X-PHP-Originating-Script: 1003:class.phpmailer.php
Received: from cB2394BC1.dhcp.as2116.net [193.75.57.178] by
nyhetsbrev1.org with HTTP; Sat, 31 Jul 2021 06:37:33 +0000
Date: Sat, 31 Jul 2021 06:37:46 +0000
From: Friluftsbutikken <
[email protected]>
Message-ID: <
[email protected]> X-phpList-version: 3.4.5
X-MessageID: 6
X-ListMember:
[email protected]
Precedence: bulk
List-Help: <
http://nyhetsbrev1.org/?p=preferences&uid=94c4bcffecada8c42551eaee3e536d51> List-Unsubscribe: <
http://nyhetsbrev1.org/?p=unsubscribe&uid=94c4bcffecada8c42551eaee3e536d51&jo=1>
List-Subscribe: <
http://nyhetsbrev1.org/?p=subscribe>
List-Owner: <mailto:
[email protected]>
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary="b1_a90571cc72ce4dc9840c44f5493ed899"
X-AntiAbuse: This header was added to track abuse, please include it
with any abuse report
X-AntiAbuse: Primary Hostname - server.nyhetsbrev1.org
X-AntiAbuse: Original Domain - kjernsmo.net
X-AntiAbuse: Originator/Caller UID/GID - [1003 991] / [47 12]
X-AntiAbuse: Sender Address Domain - nyhetsbrev1.org
X-Get-Message-Sender-Via: server.nyhetsbrev1.org: authenticated_id: nyhetsb2/from_h
X-Authenticated-Sender: server.nyhetsbrev1.org:
[email protected]
X-Source:
X-Source-Args: php-fpm: pool nyhetsbrev1_org
X-Source-Dir: nyhetsbrev1.org:/public_html/admin
This is a multi-part message in MIME format.
Control Atlantic SUP pakke - Sikre deg din SUP pakke nå - Med 5 års
garanti!
<
http://nyhetsbrev1.org/lt.php?tid=MfsofQdTZu64mB9JPzGPNilIRQ9TTrISmnITDuqC2MTOx6szhp+hcLIl5xjLr2NZ>
Ønsker du de beste opplevelsene kjøper du et Control SUP.
Atlantic blir ekstremt stivt og er nesten like stivt som bambus!
Det gir svært høy stabilitet og gode egenskaper.
NÅ KUN 4999,- INKLUDERT FRAKT (Ordinærpris 7499,-)
Control SUP gir deg mest SUP for pengene - 5 års garanti!
LES MER OG KJØP HER! <
http://nyhetsbrev1.org/lt.php?tid=MfsofQdTZu64mB9JPzGPNilIRQ9TTrISmnITDuqC2MTOx6szhp+hcLIl5xjLr2NZ>
<
http://nyhetsbrev1.org/lt.php?tid=Uj3b77TKfN+WOckJ8YXKsSlIRQ9TTtISmnITDuqC2MTOx6szhp/hcLIl5xjLr2NZ>
Ønsker du de beste opplevelsene kjøper du et Control SUP i 2 lags
materialet (double layer). 2 lags materialet blir ekstremt stivt og er
nesten like stivt som bambus! Det gir svært høy stabilitet og best egenskaper.
NÅ KUN 6999,- INKLUDERT FRAKT (Ordinærpris 8999,-)
Control SUP gir deg mest SUP for pengene - 5 års garanti!
LES MER OG KJØP HER! <
http://nyhetsbrev1.org/lt.php?tid=Uj3b77TKfN+WOckJ8YXKsSlIRQ9TTtISmnITDuqC2MTOx6szhp/hcLIl5xjLr2NZ>
Vanntett bærevæske mobiltelefon 6,5″
Ta med deg telefonen din uansett hvor du er med denne 6,5″ vanntette
vesken. Vesken er laget i holdbart materiale med IPX8 vanntett rangering og
er laget slik at telefonen er lett å bruke, selv inne i vesken.
Nå kun 189,- (Ordinært: 249,-)
LES MER OG KJØP HER! <
http://nyhetsbrev1.org/lt.php?tid=LNkSlm4yBrmfNdXio6t0cSlIRQ9TTtISmnITDuqC2MTOx6szhp+xcLIl5xjLr2NZ>
<
http://nyhetsbrev1.org/lt.php?tid=LNkSlm4yBrmfNdXio6t0cSlIRQ9TTtISmnITDuqC2MTOx6szhp+xcLIl5xjLr2NZ>
<
http://nyhetsbrev1.org/lt.php?tid=KpJfaEwB+3Wye/eUv3j0ailIRQ9TTtISmnITDuqC2MTOx6szhp8xcLIl5xjLr2NZ>
Trekopp - 270ml
Trekopp med lærrem. Turkoppen er håndlaget av tre, slik at hver kopp er
helt unik. Stilig design og enkel å holde. Skinnreimen gjør at den er
perfekt å feste utenpå tursekken. OBS: Ny og enda flottere modell.
Nå kun 189,- (Ordinært: 259,-)
LES MER OG KJØP HER! <
http://nyhetsbrev1.org/lt.php?tid=KpJfaEwB+3Wye/eUv3j0ailIRQ9TTtISmnITDuqC2MTOx6szhp8xcLIl5xjLr2NZ>
Trekopp Spesial - 270ml
Trekopp med lærrem. Turkoppen er håndlaget av tre, slik at hver kopp er
helt unik. Stilig design og enkel å holde. Skinnreimen gjør at den er
perfekt å feste utenpå tursekken. OBS: Ny og enda flottere modell.
Nå kun 199,- (Ordinært: 269,-)
LES MER OG KJØP HER! <
http://nyhetsbrev1.org/lt.php?tid=HUXmNWP3iQyeAHjOiO1ATylIRQ9TTkISmnITDuqC2MTOx6szhp/BcLIl5xjLr2NZ>
<
http://nyhetsbrev1.org/lt.php?tid=HUXmNWP3iQyeAHjOiO1ATylIRQ9TTkISmnITDuqC2MTOx6szhp/BcLIl5xjLr2NZ>
<
http://nyhetsbrev1.org/lt.php?tid=lVehU829/aimEpJhx2bZtSlIRQ9TTrISmnITDuqC2MTOx6szhp+hcLIl5xjLr2NZ>
--
Avmelding nyhetsbrev <
http://nyhetsbrev1.org/lt.php?tid=47XS5ibda5WhpUfSRXHxgilIRQ9TTgISmnITDuqC2MTOx6szhp/hcLIl5xjLr2NZ>
-- powered by phpList, www.phplist.com --
--- SoupGate-Win32 v1.05
* Origin: fsxNet Usenet Gateway (21:1/5)