ERRR... SA is rejecting this. this is getting better... notice the whois registration address "20222 shadowood parkway" matches those found here.. http://www.joewein.net/fraud/fraud-job-2006-04.htm (thanks joe)
anyone looking for a job from these places is in for a suprise.. see, now you can go to your client and tell them you saved them money and maybe their identity! ;) looks like its going through another change right now. # host -tNS uhmcargo_MUNGED.net Host uhmcargo_MUNGED.net not found: 3(NXDOMAIN) whois now lists the following ns. ns1.narrowtok.net ns2.narrowtok.net # host -tNS uhmcargo_MUNGED.net ns1.narrowtok.net Using domain server: Name: ns1.narrowtok.net Address: 67.167.254.42#53 Aliases: uhmcargo_MUNGED.net name server ns1.narrowtok.net. uhmcargo_MUNGED.net name server ns2.narrowtok.net. # host -tA uhmcargo_MUNGED.net ns1.narrowtok.net Using domain server: Name: ns1.narrowtok.net Address: 67.167.254.42#53 Aliases: uhmcargo_MUNGED.net has address 85.53.1.76 uhmcargo_MUNGED.net has address 213.37.6.147 uhmcargo_MUNGED.net has address 172.201.36.111 uhmcargo_MUNGED.net has address 24.205.215.159 > -----Original Message----- > From: qqqq [mailto:[EMAIL PROTECTED] > Sent: Tuesday, May 09, 2006 14:42 > To: Dallas L. Engelken; users@spamassassin.apache.org > Subject: Re: My only problem with URIBL_BLACK > > Chris and Dallas, > > Thank you for pointing this out. I will convey this back to > the customer. > > QQQQ > > > > ----- Original Message ----- > From: "Dallas L. Engelken" <[EMAIL PROTECTED]> > To: <users@spamassassin.apache.org> > Sent: Tuesday, May 09, 2006 1:20 PM > Subject: RE: My only problem with URIBL_BLACK > > > | > -----Original Message----- > | > From: qqqq [mailto:[EMAIL PROTECTED] > | > Sent: Tuesday, May 09, 2006 14:12 > | > To: Chris Santerre; 'Matt Kettler' > | > Cc: users@spamassassin.apache.org > | > Subject: Re: My only problem with URIBL_BLACK > | > > | > RE: My only problem with URIBL_BLACKHere's one that just got > | > captured. The mailing was from Monster.com and the customer > | > is livid :-( > | > > | > X-Spam-Report: > | > * 0.0 MIME_HTML_ONLY BODY: Message only has text/html MIME parts > | > * 1.1 URIBL_SBL Contains an URL listed in the SBL blocklist > | > * [URIs: uhmcargo_MUNGED.net] > | > * 3.0 URIBL_BLACK Contains an URL listed in the URIBL blacklist > | > * [URIs: uhmcargo_MUNGED.net] > | > * 3.4 URIBL_JP_SURBL Contains an URL listed in the JP SURBL > | > blocklist > | > * [URIs: uhmcargo_MUNGED.net] > | > > | > I had to _MUNGED the domain because the mailing hit 13.5 > and bounced > | > > | > The threshold is 5.5 > | > > | > > | > Here is from my original stats post: > | > 1 URIBL_BLACK 163397 7.09 29.11 > | > 78.05 0.50 > | > 5 URIBL_JP_SURBL 118251 5.13 21.07 > | > 56.48 0.09 > | > > | > What are your thoughts guys? Lower the score for > URI_BLACK and JP? > | > > | > | seriously? the domains is 3 days old and is unreachable, and uses > | outfitter.net NS's which appear to have an identity crisis. > | > | April 25th, > | ns1.outfiter.net 206.173.156.105 > | ns2.outfiter.net 24.98.13.40 > | > | April 27th, > | ns1.outfiter.net 24.182.165.233 > | ns2.outfiter.net 67.64.112.94 > | > | May 4th, > | ns1.outfiter.net 24.247.114.91 > | ns2.outfiter.net 68.36.53.205 > | > | May 8th, > | ns1.outfiter.net 24.168.96.193 > | ns2.outfiter.net 24.247.114.91 > | > | Right Now, > | ns1.outfitter.net 66.199.187.181 > | ns2.outfitter.net 66.199.187.181 > | > | > | > | > | > | > | > | dallas > | > | > | >