Message 1
From: Tim Williams Tim@myteamex.comMessage 2
To: Tony Blair [tony@victimdomain]
Date: 28 March 2014 14:09
Subject: Early closing due to bad conditions.
Early closing due to bad conditions.
This will be the only notification to tony@victimdomain and just disregard if sent to the incorrect individual. Thank you.
From: Michael Miller Michael@leadbyinnovation.comThe email contains no link and no attachment. So what it is it?
To: Victor Echo [vecho@victimdomain]
Date: 28 March 2014 11:12
Subject: Early closing due to poor weather.
Early closing due to poor weather.
This will be the only notification to vecho@victimdomain and just disregard if sent to the incorrect person. Thank you.
A close look at to "To" field is interesting. Tony Blair? Well, he's an ex-Prime Minister of Britain, and he just happens to be mentioned on my website here. And Victor Echo? Well, that's not a person at all but is mentioned on this page about the NATO Phonetic Alphabet.
So, in each case a name has been harvested from my web site and an email address guessed (tony@ and vecho@) in order to send the spam.
I've seen this process of scraping my web site and guessing email addresses before by a business called CIO Summits which is part of a spammy business called BizSummits run by a gentleman called Michael Price. But perhaps this is a coincidence?
So let's look at the mail headers of the two messages:
Message 1
Received: from [64.21.19.104] (port=59519 helo=mail.myteamex.com)
by [redacted] with esmtp (Exim 4.80)
(envelope-from <Tim@myteamex.com>)
id 1WTXTM-00062J-14
for tony@[redacted]; Fri, 28 Mar 2014 14:09:32 +0000
Received: from 76809236.myteamex.com
by mail.myteamex.com (Merak 8.9.1) with ASMTP id ORL87326
for <tony@[redacted]>; Fri, 28 Mar 2014 07:09:26 -0700
Message-ID: <20140328070921.6e9e4d6b5e@5d7e>
From: "Tim Williams" <Tim@myteamex.com>
To: "Tony Blair" <tony@[redacted]>
Subject: Early closing due to bad conditions.
Date: Fri, 28 Mar 2014 07:09:21 -0700
X-Priority: 3
X-Mailer: Host
MIME-Version: 1.0
Content-Type: text/plain;
charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
Received-SPF: pass ([redacted]: domain of Tim@myteamex.com designates 64.21.19.104 as permitted sender) client-ip=64.21.19.104 envelope-from=Tim@myteamex.com helo=mail.myteamex.com
Message 2
Received: from [64.21.70.64] (port=1970 helo=mail.leadbyinnovation.com)What these headers tell us is that the emails originated from 64.21.70.64 and 64.21.19.104 (Net Access Corporation, US), and that those servers are genuine mail relays for the domains leadbyinnovation.com and myteamex.com.. in other words the message is not spoofed and whoever owns these domains is responsible for the mail.
by [redacted] with esmtp (Exim 4.80)
(envelope-from <Michael@leadbyinnovation.com>)
id 1WTUi8-0007x8-KZ
for vecho@[redacted]; Fri, 28 Mar 2014 11:12:38 +0000
Received: from 37649152.leadbyinnovation.com
by mail.leadbyinnovation.com (Merak 8.9.1) with ASMTP id OOO71531
for <vecho@[redacted]>; Fri, 28 Mar 2014 04:12:31 -0700
Message-ID: <20140328041226.3f8f7d6c7b@9e8c>
From: "Michael Miller" <Michael@leadbyinnovation.com>
To: "Victor Echo" <vecho@[redacted]>
Subject: Early closing due to poor weather.
Date: Fri, 28 Mar 2014 04:12:26 -0700
X-Priority: 3
X-Mailer: SMTP Forwarder v.9
MIME-Version: 1.0
Content-Type: text/plain;
charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
Received-SPF: pass ([redacted]: domain of Michael@leadbyinnovation.com designates 64.21.70.64 as permitted sender) client-ip=64.21.70.64 envelope-from=Michael@leadbyinnovation.com helo=mail.leadbyinnovation.com
The WHOIS contain the following details:
leadbyinnovation.com
Registrant Name: DNS Administratormyteamex.com
Registrant Organization: LeadByInnovation
Registrant Street: 1200-Abernathy Rd
Registrant City: Atlanta
Registrant State/Province: Georgia
Registrant Postal Code: 30328
Registrant Country: United States
Registrant Phone: +1.7705552343
Registrant Phone Ext:
Registrant Fax:
Registrant Fax Ext:
Registrant Email: dnsadmin@leadbyinnovation.com
Registry Admin ID:
Registrant Name: DNS Admin
Registrant Organization: MyTeamEx
Registrant Street: 17th Floor
Registrant Street: 1200 Abernathy
Registrant City: Atlanta
Registrant State/Province: Georgia
Registrant Postal Code: 30328
Registrant Country: United States
Registrant Phone: +1.4044983847
Registrant Phone Ext:
Registrant Fax:
Registrant Fax Ext:
Registrant Email: dnsadmin@myteamex.com
Perhaps is is just a coincidence that the WHOIS details for bizsummits.org are very similar:
Registrant ID:CR38175629
Registrant Name:DNS Administrator
Registrant Organization:BizSummits
Registrant Street: 1200 Abernathy Rd, 17th Floor
Registrant City:Atlanta
Registrant State/Province:Georgia
Registrant Postal Code:30328
Registrant Country:US
Registrant Phone:+1.8006003389
Registrant Phone Ext:
Registrant Fax:
Registrant Fax Ext:
Registrant Email:dnsadmin@bizsummits.org
1200 Abernathy Rd is a big office building in Atlanta, and the office address could well be a virtual office in any case. But isn't it a coincidence that all three companies are based in the same building?
Well.. no, it's not a coincidence because if you look at the historical WHOIS details for myteamex.com for just last month we see they are:
Registrant Name: Michael Price
Registrant Organization:
Registrant Street: 801 Kellerman Kreek
Registrant City: Marietta
Registrant State/Province: Georgia
Registrant Postal Code: 30068
Registrant Country: United States
Registrant Phone: +1.7709989999
Registrant Phone Ext:
Registrant Fax:
Registrant Fax Ext:
Registrant Email: MPrice@mobilesoft.com
Michael Price? Yes, that's the same Michael Price who runs BizSummits. So, it's not a coincidence at all, is it?
This particular spam run has also been discussed on the SpamCop forum which indentifies the four following domains in connection with this spam run:
trainingleadership.org
zipscheduler.net
gotofacts.net
openames.com
Each one of these tells a different story. trainingleadership.org has the same semi-anonymous registration details as the others, but just a few days ago (20th March 2014) the registrant was "Biz Summits". gotofacts.net has also had the registrant details changed.. on 18th March that was registered to "Michael Price".
Finally, openames.com is a bit odder. It too has had the registrant details change (it was "Michael Price" on 18th January 2014), but it is hosted on an IP address belonging to a children's hospital in Illinois (199.125.18.11: Illinois - Chicago - Children's Memorial Medical Center)
So what are these messages? I believe that BizSummits (or whatever Mr Price's current operation is called, perhaps mobilesoft.com / mobilebriefs.com) is probing mail servers to see what sort of format email addresses are so that further spam can be sent. Most mail systems will reject invalid messages, so basically this is a sort of enumeration exercise. Is this illegal? It's hard to say. But in my opinion it is certainly unethical.
Incidentally BizSummits has a rotten reputation at the BBB, and in my personal opinion offer business summits of very little worth, and that they prey upon the vanity of the people who receive the email (which is just a basically just spam). A quick a Google for bizsummits spam comes up with a large number of complaints, and I must recommend this particular blog entry if you want an overview of how BizSummits allegedly pitch their business.
The BBB lists the following domains as being part of BizSummits. I would recommend avoiding them:
cfosummit.org
ciosummit.org
thecmosummit.net
trainingsummit.org
csosummit.org
corpdevsummit.org
hrsummit.org
theoperationssummit.net
productdevsummit.org
thepublicrelationssummit.org
qualitymanagementsummit.org
risingexecutivesummit.org
riskmanagementsummit.org
thecorpdevsummit.org
associationgrowthsummit.net
UPDATE: more information about BizSummits and some of it's websites can be found here.
Update (2300 GMT 2014-03-28): another "Tony Blair" one..
From: Stan Moore Stan@texasbusinesschamber.orgThe mail headers confirm that texasbusinesschamber.org was the sender, this time from 64.21.70.72 (Net Access Corporation again):
To: Tony Blair tblair@[redacted]
Date: 28 March 2014 22:52
Subject: Closed early due to poor weather.
Closed early due to poor weather.
This will be the only notification to tblair@[redacted] and just disregard if sent in error. Thank you.
Received: from [64.21.70.72] (port=3018 helo=mail.texasbusinesschamber.org)texasbusinesschamber.org WHOIS today:
by [redacted]with esmtp (Exim 4.80)
(envelope-from <Stan@texasbusinesschamber.org>)
id 1WTfdq-0002i5-AG
for tblair@[redacted]; Fri, 28 Mar 2014 22:52:50 +0000
Received: from 37402341.texasbusinesschamber.org
by mail.texasbusinesschamber.org (Merak 8.9.1) with ASMTP id OZC63549
for <tblair@[redacted]>; Fri, 28 Mar 2014 15:52:49 -0700
Message-ID: <20140328155244.5b6c3d3e2c@2e5c>
From: "Stan Moore" <Stan@texasbusinesschamber.org>
To: "Tony Blair" <tblair@[redacted]>
Subject: Closed early due to poor weather.
Date: Fri, 28 Mar 2014 15:52:44 -0700
X-Priority: 3
X-Mailer: System-Forwarder
MIME-Version: 1.0
Content-Type: text/plain;
charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
Received-SPF: pass ([redacted]: domain of Stan@texasbusinesschamber.org designates 64.21.70.72 as permitted sender) client-ip=64.21.70.72 envelope-from=Stan@texasbusinesschamber.org helo=mail.texasbusinesschamber.org
Registrant ID:CR156687418texasbusinesschamber.org WHOIS on 22nd February (just over one month ago)
Registrant Name:DNS Admin
Registrant Organization:Texas Business Chamber
Registrant Street: Floor 17
Registrant City:Atlanta
Registrant State/Province:Georgia
Registrant Postal Code:30327
Registrant Country:US
Registrant Phone:+1.7705863645
Registrant Phone Ext:
Registrant Fax:
Registrant Fax Ext:
Registrant Email:dnsadmin@texasbusinesschamber.org
Registrant ID:CR156687418
Registrant Name:Michael Price
Registrant Organization:
Registrant Street: 801 Kellerman Kreek
Registrant City:Marietta
Registrant State/Province:Georgia
Registrant Postal Code:30068
Registrant Country:US
Registrant Phone:+1.7709989999
Registrant Phone Ext:
Registrant Fax:
Registrant Fax Ext:
Registrant Email:MPrice@mobilesoft.com
Update (0700 GMT 2014-03-29): A slightly different one..
From: Jim Moore Jim@ituckins.comThis time the spammers are probing "Victor Echo" using the victor@ address. Mail headers are:
To: Victor Echo
Date: 29 March 2014 03:17
Subject: Closed early due to expected snow.
Closed early due to expected snow.
This will be the only notification to victor@[redacted] and just ignore if sent to the wrong person. Thank you.
Received: from [209.200.118.35] (port=2643 helo=mail.ituckins.com)This domain has been excised of useful details in the WHOIS records, but it follows the same pattern and is undoubtedly Michael Price and BizSummits.
by [redacted] with esmtp (Exim 4.80)
(envelope-from <Jim@ituckins.com>)
id 1WTjm8-0001jI-Ia
for victor@[redacted]; Sat, 29 Mar 2014 03:17:45 +0000
Received: from 34460524.ituckins.com
by mail.ituckins.com (Merak 8.9.1) with ASMTP id PGU70938
for <victor@[redacted]>; Fri, 28 Mar 2014 20:17:38 -0700
Message-ID: <20140328201734.5b7d6b2f9d@2e2e>
From: "Jim Moore" <Jim@ituckins.com>
To: "Victor Echo" <victor@[redacted]>
Subject: Closed early due to expected snow.
Date: Fri, 28 Mar 2014 20:17:34 -0700
X-Priority: 3
X-Mailer: Package Forwarder 6.3
MIME-Version: 1.0
Content-Type: text/plain;
charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
Received-SPF: pass ([redacted]: domain of Jim@ituckins.com designates 209.200.118.35 as permitted sender) client-ip=209.200.118.35 envelope-from=Jim@ituckins.com helo=mail.ituckins.com
Registry Registrant ID:Note that ituckins.com refers to etuckins.com in the WHOIS record, revealing yet another spam site in the chain.
Registrant Name: Dns Admin
Registrant Organization: eTuckins
Registrant Street: 1200 Abernathy Rd
Registrant City: Atlanta
Registrant State/Province: Georgia
Registrant Postal Code: 30068
Registrant Country: United States
Registrant Phone: +1.7705763847
Registrant Phone Ext:
Registrant Fax:
Registrant Fax Ext:
Registrant Email: dnsadmin@etuckins.com
Update (1800 GMT 2014-03-29): two more spams from the same domain..
From: Stan Davis Stan@opendetails.comThis time they are sent to "Oscar Yankee" (using a name scraped from this page) using both observed variants of oyankee@ and oscar@. The mail headers again verify that the message isn't spoofed, and opendetails.com is the actual sender.
To: Oscar Yankee <oscar@[redacted]>
Date: 29 March 2014 12:39
Subject: Early closing due to poor weather.
Early closing due to poor weather.
This will be the only notification to oscar@[redacted] and disregard if sent to the incorrect individual. Thank you.
-----
From: Steve Williams Steve@opendetails.com
To: Oscar Yankee <oyankee@[redacted]>
Date: 29 March 2014 11:54
Subject: Closed early due to inclement weather.
Closed early due to inclement weather.
This will be the only notification to oyankee@[redacted] and please ignore if sent to the incorrect person. Thank you.
Received: from [208.52.161.186] (port=59373 helo=mail.opendetails.com)The WHOIS details have been altered in an attempt to hide the sender, but it still shows Michael Price's email address. Oops.
by [redacted] with esmtp (Exim 4.80)
(envelope-from <Steve@opendetails.com>)
id 1WTrqb-0001rc-3u
for oyankee@[redacted]; Sat, 29 Mar 2014 11:54:53 +0000
Received: from 97584292.opendetails.com
by mail.opendetails.com (Merak 8.9.1) with ASMTP id POG42002
for <oyankee@[redacted]>; Sat, 29 Mar 2014 04:55:02 -0700
Message-ID: <20140329045456.3f2b7e1b4b@5c5f>
From: "Steve Williams" <Steve@opendetails.com>
To: "Oscar Yankee" <oyankee@[redacted]>
Subject: Closed early due to inclement weather.
Date: Sat, 29 Mar 2014 04:54:56 -0700
X-Priority: 3
X-Mailer: Perpetual Host v.1
MIME-Version: 1.0
Content-Type: text/plain;
charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
Received-SPF: pass ([redacted]: domain of Steve@opendetails.com designates 208.52.161.186 as permitted sender) client-ip=208.52.161.186 envelope-from=Steve@opendetails.com helo=mail.opendetails.com
Registrant Name: DNS AdminIf we go back to the registration details in January 2014 then Michael Price's name and address are on them.
Registrant Organization: OpenDetails.com
Registrant Street: Floor 17
Registrant Street: 12O0 Abernathy
Registrant City: Atlanta
Registrant State/Province: Georgia
Registrant Postal Code: 30329
Registrant Country: United States
Registrant Phone: +1.7705643366
Registrant Phone Ext:
Registrant Fax:
Registrant Fax Ext:
Registrant Email: mprice@mobilesoft.com
Registry Registrant ID:So again, there is very little doubt as to who is sending this rather large spam run.
Registrant Name: Michael Price
Registrant Organization:
Registrant Street: 801 Kellerman Kreek
Registrant City: Marietta
Registrant State/Province: Georgia
Registrant Postal Code: 30068
Registrant Country: United States
Registrant Phone: +1.7709989999
Registrant Phone Ext:
Registrant Fax:
Registrant Fax Ext:
Registrant Email: MPrice@mobilesoft.com
Update (0200 GMT 2014-03-30): the spam shows no signs of letting up. Subjects include the following:
Closing early due to bad weather.
Closed tomorrow due to inclement weather.
Closed tomorrow due to poor weather.
Closing early due to bad conditions.
Names scraped from my website include "Juliet Tango", "Michael Moore" and "Mark Tape". This spam run has two new domains, texasbusinesschamber.com and opendetailz.com , the first of which has valid SPF records, the second does not.
Received: from [207.36.209.108] (port=4719 helo=mail.texasbusinesschamber.com)The WHOIS records for texasbusinesschamber.com have been stripped of any identifying details:
by [redacted] with esmtp (Exim 4.80)
(envelope-from <Tony@texasbusinesschamber.com>)
id 1WU2JB-0005bA-EE
for michael@[redacted]; Sat, 29 Mar 2014 23:05:02 +0000
Received: from 47912934.texasbusinesschamber.com
by mail.texasbusinesschamber.com (Merak 8.9.1) with ASMTP id PAI19600
for <michael@[redacted]>; Sat, 29 Mar 2014 16:05:00 -0700
Message-ID: <20140329160458.6b8c5e8f4d@7e5d>
From: "Tony Moore" <Tony@texasbusinesschamber.com>
To: "Michael Moore" <michael@[redacted]>
Subject: Closing early due to bad weather.
Date: Sat, 29 Mar 2014 16:04:58 -0700
X-Priority: 3
X-Mailer: EmailRemitter v.8
MIME-Version: 1.0
Content-Type: text/plain;
charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
Received-SPF: pass ([redacted]: domain of Tony@texasbusinesschamber.com designates 207.36.209.108 as permitted sender) client-ip=207.36.209.108 envelope-from=Tony@texasbusinesschamber.com helo=mail.texasbusinesschamber.com
Received: from [208.52.168.58] (port=58797 helo=mail.opendetailz.com)
by [redacted] with esmtp (Exim 4.80)
(envelope-from <Brad@opendetailz.com>)
id 1WU0hT-0004Z3-MB
for juliet@[redacted]; Sat, 29 Mar 2014 21:22:03 +0000
Received: from 20646396.opendetailz.com
by mail.opendetailz.com (Merak 8.9.1) with ASMTP id PYZ68711
for <juliet@[redacted]>; Sat, 29 Mar 2014 14:22:11 -0700
Message-ID: <20140329142206.1f6f5b7b2e@2d3f>
From: "Brad Johnson" <Brad@opendetailz.com>
To: "Juliet Tango" <juliet@[redacted]>
Subject: Closing early due to bad conditions.
Date: Sat, 29 Mar 2014 14:22:06 -0700
X-Priority: 3
X-Mailer: MailServer 5.2
MIME-Version: 1.0
Content-Type: text/plain;
charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
Received-SPF: none ([redacted]: domain of Brad@opendetailz.com does not designate permitted sender hosts) client-ip=208.52.168.58 envelope-from=Brad@opendetailz.com helo=mail.opendetailz.com
Registry Registrant ID:
Registrant Name: DNS Admin
Registrant Organization: Texas Business Chamber
Registrant Street: Suite 1700
Registrant Street: 1200 -Abernathy
Registrant City: Atlanta
Registrant State/Province: Georgia
Registrant Postal Code: 30328
Registrant Country: United States
Registrant Phone: +1.7709989999
Registrant Phone Ext:
Registrant Fax:
Registrant Fax Ext:
Registrant Email: dnsadmin@texasbusinesschamber.com
But back in February, it was registered to Michael Price:
Registry Registrant ID:opendetailz.com doesn't pass the SPF check, but it is sufficiently close to the verified domain of opendetails.com seen previously that it is almost certainly genuine. The WHOIS details are:
Registrant Name: Michael Price
Registrant Organization:
Registrant Street: 801 Kellerman Kreek
Registrant City: Marietta
Registrant State/Province: Georgia
Registrant Postal Code: 30068
Registrant Country: United States
Registrant Phone: (770) 998-9999
Registrant Phone Ext:
Registrant Fax:
Registrant Fax Ext:
Registrant Email: MPrice@mobilesoft.com
Registry Admin ID:
Registry Registrant ID:On the 18th March 2014 they were:
Registrant Name: DNS Admin
Registrant Organization: OpenDetailsz.com
Registrant Street: Floor-17
Registrant Street: 12OO Abernathy
Registrant City: Atlanta
Registrant State/Province: Georgia
Registrant Postal Code: 30327
Registrant Country: United States
Registrant Phone: +1.6783843388
Registrant Phone Ext:
Registrant Fax:
Registrant Fax Ext:
Registrant Email: dnsadmin@opendetailz.com
Registry Registrant ID:Update (2300 GMT 2014-03-30): yet more evidence linking this spam run to BizSummit's Michael Price..
Registrant Name: Michael Price
Registrant Organization:
Registrant Street: 801 Kellerman Kreek
Registrant City: Marietta
Registrant State/Province: Georgia
Registrant Postal Code: 30068
Registrant Country: United States
Registrant Phone: +1.7709989999
Registrant Phone Ext:
Registrant Fax:
Registrant Fax Ext:
Registrant Email: MPrice@mobilesoft.com
Registry Admin ID:
From: Stan Miller Stan@gotofacts.net
To: George Bush <george@[redacted]>
Date: 30 March 2014 18:29
Subject: Will be closed due to bad conditions.
Will be closed due to bad conditions.
This will be the only notification to george@[redacted] and ignore if sent to the wrong email. Thank you.
----------------
From: John Moore John@gotofacts.net
To: George Bush <[redacted]>
Date: 30 March 2014 23:11
Subject: Will be closed due to bad weather.
Will be closed due to bad weather.
This will be the only notification to gbush@[redacted] and disregard if sent to the wrong person. Thank you.
These messages are sent to George Bush (!). Again, the mail headers reveal that there is a valid SPF record, therefore gotofacts.net really did send the message:
Received: from [64.21.19.120] (port=64747 helo=mail.gotofacts.net)The WHOIS records for gotofacts.net have been stripped of useful data:
by [redacted] with esmtp (Exim 4.80)
(envelope-from <Stan@gotofacts.net>)
id 1WUJXi-0001yE-Iq
for george@[redacted]; Sun, 30 Mar 2014 18:29:14 +0100
Received: from 78693058.gotofacts.net
by mail.gotofacts.net (Merak 8.9.1) with ASMTP id QUH61409
for <george@[redacted]>; Sun, 30 Mar 2014 10:29:09 -0700
Message-ID: <20140330102904.4d9e7f4e6f@7d6f>
From: "Stan Miller" <Stan@gotofacts.net>
To: "George Bush" <george@[redacted]>
Subject: Will be closed due to bad conditions.
Date: Sun, 30 Mar 2014 10:29:04 -0700
X-Priority: 3
X-Mailer: FlashTransmitter version 8.1
MIME-Version: 1.0
Content-Type: text/plain;
charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
Received-SPF: pass ([redacted]: domain of Stan@gotofacts.net designates 64.21.19.120 as permitted sender) client-ip=64.21.19.120 envelope-from=Stan@gotofacts.net helo=mail.gotofacts.net
Registry Registrant ID:But on March 18th it was registered to:
Registrant Name: DNS Admin
Registrant Organization: GoToFacts
Registrant Street: 1200 Abernathy
Registrant City: Atlanta
Registrant State/Province: Georgia
Registrant Postal Code: 30328
Registrant Country: United States
Registrant Phone: +1.7705863984
Registrant Phone Ext:
Registrant Fax:
Registrant Fax Ext:
Registrant Email: dnsadmin@gotofacts.net
Registry Registrant ID:
Registrant Name: Michael Price
Registrant Organization:
Registrant Street: 801 Kellerman Kreek
Registrant City: Marietta
Registrant State/Province: Georgia
Registrant Postal Code: 30068
Registrant Country: United States
Registrant Phone: +1.7709989999
Registrant Phone Ext:
Registrant Fax:
Registrant Fax Ext:
Registrant Email: MPrice@mobilesoft.com
Registry Admin ID: