Another three-month look at Spamtraps: ESPs – July, August, September 2018

July to September 2018 in Spamtraps: ESPs

July to September 2018 in Spamtraps: ESPs

We had an unexpected participant in Hobsons, who traditionally send effectively nothing to us, only just about enough for us to have recognized that they even exist. It appears their network space is shared between the ESP and some other branch of their operations. The servers of the non-ESP operations were misconfigured on April 10 shortly before 8 pm UTC and started spewing out backscatter (bounces of spam to the forged sender addresses). This went on until 9/11 @ 11 am UTC, peaking in July.

With Yesmail, the money mule spammers (subjects: “New offer”, “New vacancies in our company”, “Interesting work”, “Staff Wanted”, “Good day!”, “Hello!”, “Interesting offer”, “Welcome to our company”) started appearing in April, peaked in July, and were effectively out by September. The numbers of this type of spam on any other ESP platform are never measured in more than the single digits.

Worst senders:

  1. SendGrid: Advisor Perspectives, by a margin of more than 2x to the next contestant, month after month (with a slight nod in the general direction of Airbnb in July)
  2. SMC/ExactTarget: Kohls (only barely), with Marcus Millichap popping up in September
  3. MailChimp: Advisor Perspectives (WTH?)
  4. Oracle: Nordstrom (only barely)
  5. Mailgun: The Italian affiliate spammers (see previous blogs)
  6. Yesmail: After the money mule trash,
  7. Amazon SES:
  8. CheetahMail:,, (all almost below the noise floor)
  9. Constant Contact: (only barely)
  10. IBM:,
  11. Mapp:
  12. Epsilon: DICK’S Sporting Goods, Inc.

On The Forensic Capabilities of LeadForensics

The study of forensics refers to scientific tests or techniques used in connection with the detection of crime. It is an odd choice of name for what I think is a data seller, especially one whose targeting seems poor enough to be spamming me. They claim to want to help me generate more leads for my website, but my website doesn’t sell anything. I do not really need any leads.

They are sending from IP address, which appears to be an email platform called Message Focus or Adestra.

From what I can tell, the only forensic capability this entity has shown me is that they seem to buy B2B spam leads, which is very disappointing.

Siltaraha Oy / Finlandia Finance Oy

In May 2016, a Finnish B2B financing company (or “payday loans for businesses”, if you like) called Siltaraha Oy (www, biz reg, people responsible) started advertising its activities in B2B spam to purchased lists.
Read more…

New Finnish B2B spammer: /

Here’s the culprit

Domains have been registered a week ago. The LI profile indicates the operation has started in July 2018. The people whose network the spam was sent from already know. Not just abuse@, the actual people.

If you’re reading this, Mr. A, take my advice: stop now.

Rule #4: The natural course of a spamming business is to go bankrupt.

June 2018 in Spamtraps: ESPs

ESP spam seen in spamtraps, June 2018

ESP spam seen in spamtraps, June 2018

Read more…

A three-month look at Spamtraps: ESPs

Good morning, Munich…

Hostinger International: fraudulent hosting provider

According to Hostinger International these people have recommended their services:

Too bad none of the people exist (all of the names are phony) and a trivial Google image search reveals that the images are from commonly available image banks, such as “Ida & Paavo”, whose image is cropped from

Don’t trust these people.

A four-month look at Spamtraps: ESPs

November 2017 to February 2018 in Spamtraps: ESPs

Nuff said. All the data is there and questions are welcome, either in comments to this article or in other avenues. Just haven’t gotten around to writing it up.

October 2017 in Spamtraps: ESPs

ESP spam seen in spamtraps, October 2017

ESP spam seen in spamtraps, October 2017

Read more…

Go back to top