Here are a pair of odd spam email messages:
Message 1
From: Tim Williams Tim@myteamex.com
To: Tony Blair [tony@victimdomain]
Date: 28 March 2014 14:09
Subject: Early closing due to bad conditions.
Early closing due to bad conditions.
This will be the only notification to tony@victimdomain and just disregard if sent to the incorrect individual. Thank you.
Message 2
From: Michael Miller Michael@leadbyinnovation.com
To: Victor Echo [vecho@victimdomain]
Date: 28 March 2014 11:12
Subject: Early closing due to poor weather.
Early closing due to poor weather.
This will be the only notification to vecho@victimdomain and just disregard if sent to the incorrect person. Thank you.
The email contains no link and no attachment. So what it is it?
A close look at to "To" field is interesting. Tony Blair? Well, he's an ex-Prime Minister of Britain, and he just happens to be mentioned on my website
here. And Victor Echo? Well, that's not a person at all but is mentioned on this page about the
NATO Phonetic Alphabet.
So, in each case a name has been harvested from my web site and an email address guessed (
tony@ and
vecho@) in order to send the spam.
I've seen this process of scraping my web site and guessing email addresses before by a business called
CIO Summits which is part of a spammy business called
BizSummits run by a gentleman called Michael Price. But perhaps this is a coincidence?
So let's look at the mail headers of the two messages:
Message 1
Received: from [64.21.19.104] (port=59519 helo=mail.myteamex.com)
by [redacted] with esmtp (Exim 4.80)
(envelope-from <Tim@myteamex.com>)
id 1WTXTM-00062J-14
for tony@[redacted]; Fri, 28 Mar 2014 14:09:32 +0000
Received: from 76809236.myteamex.com
by mail.myteamex.com (Merak 8.9.1) with ASMTP id ORL87326
for <tony@[redacted]>; Fri, 28 Mar 2014 07:09:26 -0700
Message-ID: <20140328070921.6e9e4d6b5e@5d7e>
From: "Tim Williams" <Tim@myteamex.com>
To: "Tony Blair" <tony@[redacted]>
Subject: Early closing due to bad conditions.
Date: Fri, 28 Mar 2014 07:09:21 -0700
X-Priority: 3
X-Mailer: Host
MIME-Version: 1.0
Content-Type: text/plain;
charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
Received-SPF: pass ([redacted]: domain of Tim@myteamex.com designates 64.21.19.104 as permitted sender) client-ip=64.21.19.104 envelope-from=Tim@myteamex.com helo=mail.myteamex.com
Message 2
Received: from [64.21.70.64] (port=1970 helo=mail.leadbyinnovation.com)
by [redacted] with esmtp (Exim 4.80)
(envelope-from <Michael@leadbyinnovation.com>)
id 1WTUi8-0007x8-KZ
for vecho@[redacted]; Fri, 28 Mar 2014 11:12:38 +0000
Received: from 37649152.leadbyinnovation.com
by mail.leadbyinnovation.com (Merak 8.9.1) with ASMTP id OOO71531
for <vecho@[redacted]>; Fri, 28 Mar 2014 04:12:31 -0700
Message-ID: <20140328041226.3f8f7d6c7b@9e8c>
From: "Michael Miller" <Michael@leadbyinnovation.com>
To: "Victor Echo" <vecho@[redacted]>
Subject: Early closing due to poor weather.
Date: Fri, 28 Mar 2014 04:12:26 -0700
X-Priority: 3
X-Mailer: SMTP Forwarder v.9
MIME-Version: 1.0
Content-Type: text/plain;
charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
Received-SPF: pass ([redacted]: domain of Michael@leadbyinnovation.com designates 64.21.70.64 as permitted sender) client-ip=64.21.70.64 envelope-from=Michael@leadbyinnovation.com helo=mail.leadbyinnovation.com
What these headers tell us is that the emails originated from
64.21.70.64 and
64.21.19.104 (Net Access Corporation, US), and that those servers are genuine mail relays for the domains
leadbyinnovation.com and
myteamex.com.. in other words the message is not spoofed and whoever owns these domains is responsible for the mail.
The WHOIS contain the following details:
leadbyinnovation.com
Registrant Name: DNS Administrator
Registrant Organization: LeadByInnovation
Registrant Street: 1200-Abernathy Rd
Registrant City: Atlanta
Registrant State/Province: Georgia
Registrant Postal Code: 30328
Registrant Country: United States
Registrant Phone: +1.7705552343
Registrant Phone Ext:
Registrant Fax:
Registrant Fax Ext:
Registrant Email: dnsadmin@leadbyinnovation.com
Registry Admin ID:
myteamex.com
Registrant Name: DNS Admin
Registrant Organization: MyTeamEx
Registrant Street: 17th Floor
Registrant Street: 1200 Abernathy
Registrant City: Atlanta
Registrant State/Province: Georgia
Registrant Postal Code: 30328
Registrant Country: United States
Registrant Phone: +1.4044983847
Registrant Phone Ext:
Registrant Fax:
Registrant Fax Ext:
Registrant Email: dnsadmin@myteamex.com
Perhaps is is just a coincidence that the WHOIS details for
bizsummits.org are very similar:
Registrant ID:CR38175629
Registrant Name:DNS Administrator
Registrant Organization:BizSummits
Registrant Street: 1200 Abernathy Rd, 17th Floor
Registrant City:Atlanta
Registrant State/Province:Georgia
Registrant Postal Code:30328
Registrant Country:US
Registrant Phone:+1.8006003389
Registrant Phone Ext:
Registrant Fax:
Registrant Fax Ext:
Registrant Email:dnsadmin@bizsummits.org
1200 Abernathy Rd is a
big office building in Atlanta, and the office address could well be a virtual office in any case. But isn't it a coincidence that all three companies are based in the same building?
Well.. no, it's not a coincidence because if you look at the historical WHOIS details for
myteamex.com for just last month we see they are:
Registrant Name: Michael Price
Registrant Organization:
Registrant Street: 801 Kellerman Kreek
Registrant City: Marietta
Registrant State/Province: Georgia
Registrant Postal Code: 30068
Registrant Country: United States
Registrant Phone: +1.7709989999
Registrant Phone Ext:
Registrant Fax:
Registrant Fax Ext:
Registrant Email: MPrice@mobilesoft.com
Michael Price? Yes, that's the same
Michael Price who runs BizSummits. So, it's not a coincidence at all, is it?
This particular spam run has also been discussed on the
SpamCop forum which indentifies the four following domains in connection with this spam run:
trainingleadership.org
zipscheduler.net
gotofacts.net
openames.com
Each one of these tells a different story.
trainingleadership.org has the same semi-anonymous registration details as the others, but just a few days ago (20th March 2014) the registrant was "Biz Summits".
gotofacts.net has also had the registrant details changed.. on 18th March that was registered to "Michael Price".
Finally,
openames.com is a bit odder. It too has had the registrant details change (it was "Michael Price" on 18th January 2014), but it is hosted on an IP address belonging to a children's hospital in Illinois (
199.125.18.11: Illinois - Chicago - Children's Memorial Medical Center)
So what
are these messages? I believe that BizSummits (or
whatever Mr Price's current operation is called, perhaps
mobilesoft.com /
mobilebriefs.com) is probing mail servers
to see what sort of format email addresses are so that further spam can
be sent. Most mail systems will reject invalid messages, so basically
this is a sort of enumeration exercise. Is this illegal? It's hard to say. But in my opinion it is certainly unethical.
Incidentally BizSummits has a
rotten reputation at the BBB, and in my personal opinion offer business summits of very little worth, and that they prey upon the vanity of the people who receive the email (which is just a basically just spam). A quick a Google for
bizsummits spam comes up with a large number of complaints, and I must recommend this
particular blog entry if you want an overview of how BizSummits allegedly pitch their business.
The BBB lists the following domains as being part of BizSummits. I would recommend avoiding them:
cfosummit.org
ciosummit.org
thecmosummit.net
trainingsummit.org
csosummit.org
corpdevsummit.org
hrsummit.org
theoperationssummit.net
productdevsummit.org
thepublicrelationssummit.org
qualitymanagementsummit.org
risingexecutivesummit.org
riskmanagementsummit.org
thecorpdevsummit.org
associationgrowthsummit.net
UPDATE: more information about BizSummits and some of it's websites can be found
here.
Update (2300 GMT 2014-03-28): another "Tony Blair" one..
From: Stan Moore Stan@texasbusinesschamber.org
To: Tony Blair tblair@[redacted]
Date: 28 March 2014 22:52
Subject: Closed early due to poor weather.
Closed early due to poor weather.
This will be the only notification to tblair@[redacted] and just disregard if sent in error. Thank you.
The mail headers confirm that
texasbusinesschamber.org was the sender, this time from
64.21.70.72 (Net Access Corporation again):
Received: from [64.21.70.72] (port=3018 helo=mail.texasbusinesschamber.org)
by [redacted]with esmtp (Exim 4.80)
(envelope-from <Stan@texasbusinesschamber.org>)
id 1WTfdq-0002i5-AG
for tblair@[redacted]; Fri, 28 Mar 2014 22:52:50 +0000
Received: from 37402341.texasbusinesschamber.org
by mail.texasbusinesschamber.org (Merak 8.9.1) with ASMTP id OZC63549
for <tblair@[redacted]>; Fri, 28 Mar 2014 15:52:49 -0700
Message-ID: <20140328155244.5b6c3d3e2c@2e5c>
From: "Stan Moore" <Stan@texasbusinesschamber.org>
To: "Tony Blair" <tblair@[redacted]>
Subject: Closed early due to poor weather.
Date: Fri, 28 Mar 2014 15:52:44 -0700
X-Priority: 3
X-Mailer: System-Forwarder
MIME-Version: 1.0
Content-Type: text/plain;
charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
Received-SPF: pass ([redacted]: domain of Stan@texasbusinesschamber.org designates 64.21.70.72 as permitted sender) client-ip=64.21.70.72 envelope-from=Stan@texasbusinesschamber.org helo=mail.texasbusinesschamber.org
texasbusinesschamber.org WHOIS today:
Registrant ID:CR156687418
Registrant Name:DNS Admin
Registrant Organization:Texas Business Chamber
Registrant Street: Floor 17
Registrant City:Atlanta
Registrant State/Province:Georgia
Registrant Postal Code:30327
Registrant Country:US
Registrant Phone:+1.7705863645
Registrant Phone Ext:
Registrant Fax:
Registrant Fax Ext:
Registrant Email:dnsadmin@texasbusinesschamber.org
texasbusinesschamber.org WHOIS on 22nd February (just over one month ago)
Registrant ID:CR156687418
Registrant Name:Michael Price
Registrant Organization:
Registrant Street: 801 Kellerman Kreek
Registrant City:Marietta
Registrant State/Province:Georgia
Registrant Postal Code:30068
Registrant Country:US
Registrant Phone:+1.7709989999
Registrant Phone Ext:
Registrant Fax:
Registrant Fax Ext:
Registrant Email:MPrice@mobilesoft.com
Update (0700 GMT 2014-03-29): A slightly different one..
From: Jim Moore Jim@ituckins.com
To: Victor Echo
Date: 29 March 2014 03:17
Subject: Closed early due to expected snow.
Closed early due to expected snow.
This will be the only notification to victor@[redacted] and just ignore if sent to the wrong person. Thank you.
This time the spammers are probing "Victor Echo" using the victor@ address. Mail headers are:
Received: from [209.200.118.35] (port=2643 helo=mail.ituckins.com)
by [redacted] with esmtp (Exim 4.80)
(envelope-from <Jim@ituckins.com>)
id 1WTjm8-0001jI-Ia
for victor@[redacted]; Sat, 29 Mar 2014 03:17:45 +0000
Received: from 34460524.ituckins.com
by mail.ituckins.com (Merak 8.9.1) with ASMTP id PGU70938
for <victor@[redacted]>; Fri, 28 Mar 2014 20:17:38 -0700
Message-ID: <20140328201734.5b7d6b2f9d@2e2e>
From: "Jim Moore" <Jim@ituckins.com>
To: "Victor Echo" <victor@[redacted]>
Subject: Closed early due to expected snow.
Date: Fri, 28 Mar 2014 20:17:34 -0700
X-Priority: 3
X-Mailer: Package Forwarder 6.3
MIME-Version: 1.0
Content-Type: text/plain;
charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
Received-SPF: pass ([redacted]: domain of Jim@ituckins.com designates 209.200.118.35 as permitted sender) client-ip=209.200.118.35 envelope-from=Jim@ituckins.com helo=mail.ituckins.com
This domain has been excised of useful details in the WHOIS records, but it follows the same pattern and is undoubtedly Michael Price and BizSummits.
Registry Registrant ID:
Registrant Name: Dns Admin
Registrant Organization: eTuckins
Registrant Street: 1200 Abernathy Rd
Registrant City: Atlanta
Registrant State/Province: Georgia
Registrant Postal Code: 30068
Registrant Country: United States
Registrant Phone: +1.7705763847
Registrant Phone Ext:
Registrant Fax:
Registrant Fax Ext:
Registrant Email: dnsadmin@etuckins.com
Note that
ituckins.com refers to
etuckins.com in the WHOIS record, revealing yet another spam site in the chain.
Update (1800 GMT 2014-03-29): two more spams from the same domain..
From: Stan Davis Stan@opendetails.com
To: Oscar Yankee <oscar@[redacted]>
Date: 29 March 2014 12:39
Subject: Early closing due to poor weather.
Early closing due to poor weather.
This will be the only notification to oscar@[redacted] and disregard if sent to the incorrect individual. Thank you.
-----
From: Steve Williams Steve@opendetails.com
To: Oscar Yankee <oyankee@[redacted]>
Date: 29 March 2014 11:54
Subject: Closed early due to inclement weather.
Closed early due to inclement weather.
This will be the only notification to oyankee@[redacted] and please ignore if sent to the incorrect person. Thank you.
This time they are sent to "Oscar Yankee" (using a name scraped from
this page) using both observed variants of oyankee@ and oscar@. The mail headers again verify that the message isn't spoofed, and
opendetails.com is the actual sender.
Received: from [208.52.161.186] (port=59373 helo=mail.opendetails.com)
by [redacted] with esmtp (Exim 4.80)
(envelope-from <Steve@opendetails.com>)
id 1WTrqb-0001rc-3u
for oyankee@[redacted]; Sat, 29 Mar 2014 11:54:53 +0000
Received: from 97584292.opendetails.com
by mail.opendetails.com (Merak 8.9.1) with ASMTP id POG42002
for <oyankee@[redacted]>; Sat, 29 Mar 2014 04:55:02 -0700
Message-ID: <20140329045456.3f2b7e1b4b@5c5f>
From: "Steve Williams" <Steve@opendetails.com>
To: "Oscar Yankee" <oyankee@[redacted]>
Subject: Closed early due to inclement weather.
Date: Sat, 29 Mar 2014 04:54:56 -0700
X-Priority: 3
X-Mailer: Perpetual Host v.1
MIME-Version: 1.0
Content-Type: text/plain;
charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
Received-SPF: pass ([redacted]: domain of Steve@opendetails.com designates 208.52.161.186 as permitted sender) client-ip=208.52.161.186 envelope-from=Steve@opendetails.com helo=mail.opendetails.com
The WHOIS details have been altered in an attempt to hide the sender, but it still shows Michael Price's email address. Oops.
Registrant Name: DNS Admin
Registrant Organization: OpenDetails.com
Registrant Street: Floor 17
Registrant Street: 12O0 Abernathy
Registrant City: Atlanta
Registrant State/Province: Georgia
Registrant Postal Code: 30329
Registrant Country: United States
Registrant Phone: +1.7705643366
Registrant Phone Ext:
Registrant Fax:
Registrant Fax Ext:
Registrant Email: mprice@mobilesoft.com
If we go back to the registration details in January 2014 then Michael Price's name and address are on them.
Registry Registrant ID:
Registrant Name: Michael Price
Registrant Organization:
Registrant Street: 801 Kellerman Kreek
Registrant City: Marietta
Registrant State/Province: Georgia
Registrant Postal Code: 30068
Registrant Country: United States
Registrant Phone: +1.7709989999
Registrant Phone Ext:
Registrant Fax:
Registrant Fax Ext:
Registrant Email: MPrice@mobilesoft.com
So again, there is very little doubt as to who is sending this rather large spam run.
Update (0200 GMT 2014-03-30): the spam shows no signs of letting up. Subjects include the following:
Closing early due to bad weather.
Closed tomorrow due to inclement weather.
Closed tomorrow due to poor weather.
Closing early due to bad conditions.
Names scraped from my website include "Juliet Tango", "Michael Moore" and "Mark Tape". This spam run has two new domains,
texasbusinesschamber.com and
opendetailz.com , the first of which has valid SPF records, the second does not.
Received: from [207.36.209.108] (port=4719 helo=mail.texasbusinesschamber.com)
by [redacted] with esmtp (Exim 4.80)
(envelope-from <Tony@texasbusinesschamber.com>)
id 1WU2JB-0005bA-EE
for michael@[redacted]; Sat, 29 Mar 2014 23:05:02 +0000
Received: from 47912934.texasbusinesschamber.com
by mail.texasbusinesschamber.com (Merak 8.9.1) with ASMTP id PAI19600
for <michael@[redacted]>; Sat, 29 Mar 2014 16:05:00 -0700
Message-ID: <20140329160458.6b8c5e8f4d@7e5d>
From: "Tony Moore" <Tony@texasbusinesschamber.com>
To: "Michael Moore" <michael@[redacted]>
Subject: Closing early due to bad weather.
Date: Sat, 29 Mar 2014 16:04:58 -0700
X-Priority: 3
X-Mailer: EmailRemitter v.8
MIME-Version: 1.0
Content-Type: text/plain;
charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
Received-SPF: pass ([redacted]: domain of Tony@texasbusinesschamber.com designates 207.36.209.108 as permitted sender) client-ip=207.36.209.108 envelope-from=Tony@texasbusinesschamber.com helo=mail.texasbusinesschamber.com
Received: from [208.52.168.58] (port=58797 helo=mail.opendetailz.com)
by [redacted] with esmtp (Exim 4.80)
(envelope-from <Brad@opendetailz.com>)
id 1WU0hT-0004Z3-MB
for juliet@[redacted]; Sat, 29 Mar 2014 21:22:03 +0000
Received: from 20646396.opendetailz.com
by mail.opendetailz.com (Merak 8.9.1) with ASMTP id PYZ68711
for <juliet@[redacted]>; Sat, 29 Mar 2014 14:22:11 -0700
Message-ID: <20140329142206.1f6f5b7b2e@2d3f>
From: "Brad Johnson" <Brad@opendetailz.com>
To: "Juliet Tango" <juliet@[redacted]>
Subject: Closing early due to bad conditions.
Date: Sat, 29 Mar 2014 14:22:06 -0700
X-Priority: 3
X-Mailer: MailServer 5.2
MIME-Version: 1.0
Content-Type: text/plain;
charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
Received-SPF: none ([redacted]: domain of Brad@opendetailz.com does not designate permitted sender hosts) client-ip=208.52.168.58 envelope-from=Brad@opendetailz.com helo=mail.opendetailz.com
The WHOIS records for
texasbusinesschamber.com have been stripped of any identifying details:
Registry Registrant ID:
Registrant Name: DNS Admin
Registrant Organization: Texas Business Chamber
Registrant Street: Suite 1700
Registrant Street: 1200 -Abernathy
Registrant City: Atlanta
Registrant State/Province: Georgia
Registrant Postal Code: 30328
Registrant Country: United States
Registrant Phone: +1.7709989999
Registrant Phone Ext:
Registrant Fax:
Registrant Fax Ext:
Registrant Email: dnsadmin@texasbusinesschamber.com
But back in February, it was registered to Michael Price:
Registry Registrant ID:
Registrant Name: Michael Price
Registrant Organization:
Registrant Street: 801 Kellerman Kreek
Registrant City: Marietta
Registrant State/Province: Georgia
Registrant Postal Code: 30068
Registrant Country: United States
Registrant Phone: (770) 998-9999
Registrant Phone Ext:
Registrant Fax:
Registrant Fax Ext:
Registrant Email: MPrice@mobilesoft.com
Registry Admin ID:
opendetailz.com doesn't pass the SPF check, but it is sufficiently close to the verified domain of opendetail
s.com seen previously that it is almost certainly genuine. The WHOIS details are:
Registry Registrant ID:
Registrant Name: DNS Admin
Registrant Organization: OpenDetailsz.com
Registrant Street: Floor-17
Registrant Street: 12OO Abernathy
Registrant City: Atlanta
Registrant State/Province: Georgia
Registrant Postal Code: 30327
Registrant Country: United States
Registrant Phone: +1.6783843388
Registrant Phone Ext:
Registrant Fax:
Registrant Fax Ext:
Registrant Email: dnsadmin@opendetailz.com
On the 18th March 2014 they were:
Registry Registrant ID:
Registrant Name: Michael Price
Registrant Organization:
Registrant Street: 801 Kellerman Kreek
Registrant City: Marietta
Registrant State/Province: Georgia
Registrant Postal Code: 30068
Registrant Country: United States
Registrant Phone: +1.7709989999
Registrant Phone Ext:
Registrant Fax:
Registrant Fax Ext:
Registrant Email: MPrice@mobilesoft.com
Registry Admin ID:
Update (2300 GMT 2014-03-30): yet more evidence linking this spam run to BizSummit's Michael Price..
From: Stan Miller Stan@gotofacts.net
To: George Bush <george@[redacted]>
Date: 30 March 2014 18:29
Subject: Will be closed due to bad conditions.
Will be closed due to bad conditions.
This will be the only notification to george@[redacted] and ignore if sent to the wrong email. Thank you.
----------------
From: John Moore John@gotofacts.net
To: George Bush <[redacted]>
Date: 30 March 2014 23:11
Subject: Will be closed due to bad weather.
Will be closed due to bad weather.
This will be the only notification to gbush@[redacted] and disregard if sent to the wrong person. Thank you.
These messages are sent to
George Bush (!). Again, the mail headers reveal that there is a valid SPF record, therefore
gotofacts.net really did send the message:
Received: from [64.21.19.120] (port=64747 helo=mail.gotofacts.net)
by [redacted] with esmtp (Exim 4.80)
(envelope-from <Stan@gotofacts.net>)
id 1WUJXi-0001yE-Iq
for george@[redacted]; Sun, 30 Mar 2014 18:29:14 +0100
Received: from 78693058.gotofacts.net
by mail.gotofacts.net (Merak 8.9.1) with ASMTP id QUH61409
for <george@[redacted]>; Sun, 30 Mar 2014 10:29:09 -0700
Message-ID: <20140330102904.4d9e7f4e6f@7d6f>
From: "Stan Miller" <Stan@gotofacts.net>
To: "George Bush" <george@[redacted]>
Subject: Will be closed due to bad conditions.
Date: Sun, 30 Mar 2014 10:29:04 -0700
X-Priority: 3
X-Mailer: FlashTransmitter version 8.1
MIME-Version: 1.0
Content-Type: text/plain;
charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
Received-SPF: pass ([redacted]: domain of Stan@gotofacts.net designates 64.21.19.120 as permitted sender) client-ip=64.21.19.120 envelope-from=Stan@gotofacts.net helo=mail.gotofacts.net
The WHOIS records for
gotofacts.net have been stripped of useful data:
Registry Registrant ID:
Registrant Name: DNS Admin
Registrant Organization: GoToFacts
Registrant Street: 1200 Abernathy
Registrant City: Atlanta
Registrant State/Province: Georgia
Registrant Postal Code: 30328
Registrant Country: United States
Registrant Phone: +1.7705863984
Registrant Phone Ext:
Registrant Fax:
Registrant Fax Ext:
Registrant Email: dnsadmin@gotofacts.net
But on March 18th it was registered to:
Registry Registrant ID:
Registrant Name: Michael Price
Registrant Organization:
Registrant Street: 801 Kellerman Kreek
Registrant City: Marietta
Registrant State/Province: Georgia
Registrant Postal Code: 30068
Registrant Country: United States
Registrant Phone: +1.7709989999
Registrant Phone Ext:
Registrant Fax:
Registrant Fax Ext:
Registrant Email: MPrice@mobilesoft.com
Registry Admin ID: