[MASOCH-L] dominio super fraudulento

Leandro leandro at spfbl.net
Tue Jun 20 22:21:33 -03 2017


Isso. Peguei aqui. Saiu desse cara aqui:

34.211.172.192 (ec2-34-211-172-192.us-west-2.compute.amazonaws.com)

É um IP dinâmico das instâncias EC2 da AWS. O cara ganha um IP desse range
sempre que inicia um EC2. Ganha um IP novo a cada inicialização da VM, por
isso é considerado IP dinâmico. Costumam instanciar a VM, disparar o lixo,
reiniciam a máquina e mandam mais lixo com IP novo, repetindo o
procedimento.

O Outlook.com permite você definir DNSBLs para seu domínio Bruno?

Leandro
SPFBL.net

2017-06-20 22:09 GMT-03:00 Bruno Cabral <bruno at openline.com.br>:

> O cabeçalho?
>
>
> Received: from DM3NAM03HT162.eop-NAM03.prod.protection.outlook.com
>  (10.164.10.155) by SN1PR19MB0686.namprd19.prod.outlook.com with HTTPS via
>  SN1PR10CA0059.NAMPRD10.PROD.OUTLOOK.COM; Tue, 20 Jun 2017 11:52:55 +0000
> Received: from DM3NAM03FT014.eop-NAM03.prod.protection.outlook.com
>  (10.152.82.51) by DM3NAM03HT162.eop-NAM03.prod.protection.outlook.com
>  (10.152.82.219) with Microsoft SMTP Server (version=TLS1_2,
>  cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P384) id 15.1.1178.14; Tue,
> 20
>  Jun 2017 11:52:54 +0000
> Authentication-Results: spf=none (sender IP is 34.211.172.192)
>  smtp.mailfrom=99750.cloudwaysapps.com; openline.com.br; dkim=none
> (message
>  not signed) header.d=none;openline.com.br; dmarc=none action=none
>  header.from=netflix;
> Received-SPF: None (protection.outlook.com: 99750.cloudwaysapps.com does
> not
>  designate permitted sender hosts)
> Received: from BAY004-PAMC1F5.hotmail.com (10.152.82.59) by
>  DM3NAM03FT014.mail.protection.outlook.com (10.152.82.81) with Microsoft
> SMTP
>  Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P384)
> id
>  15.1.1178.14 via Frontend Transport; Tue, 20 Jun 2017 11:52:53 +0000
> X-IncomingTopHeaderMarker: OriginalChecksum:FFEA2C4765AFD87F49E9D51B6E68FF
> 9DC90A839C594599B92598817795E5F980;UpperCasedChecksum:
> A28AE8B6575B251EB3D3EB076BB216F8F1AA01D70CE0FC30C94CCF77A6DF
> B83E;SizeAsReceived:648;Count:10
> Received: from 99750.cloudwaysapps.com ([34.211.172.192]) by
> BAY004-PAMC1F5.hotmail.com with Microsoft SMTPSVC(7.5.7601.23143);
>      Tue, 20 Jun 2017 04:52:52 -0700
> Received: by 99750.cloudwaysapps.com (Postfix, from userid 1002)
>     id 0A4D766292; Tue, 20 Jun 2017 11:45:13 +0000 (UTC)
> Content-Type: text/html
> Subject: [Caro] cliente netflix .
> From: <suporte at netflix>
> To: <bruno at openline.com.br>
> Message-ID: <20170620114513.0A4D766292 at 99750.cloudwaysapps.com>
> Date: Tue, 20 Jun 2017 11:45:13 +0000
> Return-Path: master_rfunwjpymf at 99750.cloudwaysapps.com
> X-OriginalArrivalTime: 20 Jun 2017 11:52:52.0925 (UTC)
> FILETIME=[BF90A6D0:01D2E9BB]
> X-IncomingHeaderCount: 10
> X-MS-Exchange-Organization-Network-Message-Id: a16c83d5-68fd-431d-1b3a-
> 08d4b7d2e343
> X-EOPAttributedMessage: 0
> X-EOPTenantAttributedMessage: 84df9e7f-e9f6-40af-b435-aaaaaaaaaaaa:0
> X-MS-Exchange-Organization-MessageDirectionality: Incoming
> CMM-sender-ip: 34.211.172.192
> CMM-sending-ip: 34.211.172.192
> CMM-Authentication-Results: hotmail.com; spf=none (sender IP is
>  34.211.172.192) smtp.mailfrom=master_rfunwjpymf at 99750.cloudwaysapps.com;
>  dkim=none header.d=netflix; x-hmca=none header.id=suporte at netflix
> CMM-X-SID-PRA: suporte at netflix
> CMM-X-AUTH-Result: NONE
> CMM-X-SID-Result: NONE
>
>
>
>
> ________________________________
> De: masoch-l <masoch-l-bounces at eng.registro.br> em nome de Leandro <
> leandro at spfbl.net>
> Enviado: terça-feira, 20 de junho de 2017 21:59
> Para: Mail Aid and Succor, On-line Comfort and Help
> Assunto: Re: [MASOCH-L] dominio super fraudulento
>
> Você tem o IP de origem dessa mensagem aí contigo Bruno?
>
> Leandro
> SPFBL.net
>
> Em 20/06/2017 21:55, "Bruno Cabral" <bruno at openline.com.br> escreveu:
>
> Obrigado!
>
>
> interessante que esse chegou com remetente suporte at netflix sem nenhum
> sufixo...
>
>
> !3runo
>
> __
> masoch-l list
> https://eng.registro.br/mailman/listinfo/masoch-l
>



More information about the masoch-l mailing list