Walmart Brazil: What’s with all the spamming?

The Brazilian division of U.S. and global retailer WalMart is sending bulk email to an array of personal email addresses and spamtraps via a number of ESPs. The ESP that sent the attached sample was MGS Comunicação Multimídia, but I have seen spams advertising Walmart Brazil from a number of Brazilian ESPs.

The IP that sent this spam has no rDNS, which is very unusual for a legitimate ESP. Most ESPs know better than to do this; they know that IPs that send bulk email and have no rDNS are slammed into private blocklists and firewalls immediately on sight.

Sending IP: 189.1.164.237

Spam Sample:

Actual Headers:

Received: from reverse1.hospedagemdesite.com ([189.1.164.237]:<xxx> 
        helo=www.mgscomunicacao.com.br)
        by <xxx> with esmtp (Exim 4.77 (FreeBSD))
        (envelope-from <xxx>)
        id <xxx>
        for <xxx>; Sat, 22 Oct 2011 10:xx:xx -0500
Received: from mail pickup service by www.mgscomunicacao.com.br with Microsoft SMTPSVC;
         Sat, 22 Oct 2011 14:xx:xx -0200
thread-index: <xxx>==
Thread-Topic: IMPACTO: Por R$1298 Note HP Core i3 c/ Roteador 150Mbps + Pen drive.
From: "MGS - Walmart.com.br" <mgs.walmart@mgscomunicacao.com.br>
To: <xxx>
Subject: IMPACTO: Por R$1298 Note HP Core i3 c/ Roteador 150Mbps + Pen drive.
Date: Sat, 22 Oct 2011 14:xx:xx -0200
Message-ID: <<xxx>@mgscomunicacao.com.br>
MIME-Version: 1.0
Content-Type: multipart/alternative;
        boundary="----=_NextPart_<xxx>"
X-Mailer: Microsoft CDO for Windows 2000

Readable Email:

From: MGS – Walmart.com.br <mgs.walmart@mgscomunicacao.com.br>
To: <spamtrap>
Subject: IMPACTO: Por R$1298 Note HP Core i3 c/ Roteador 150Mbps + Pen drive.

Para visualizar esse e-mail em seu navegador, confira aqui as nossas ofertas!

<removed>

Se voc=EA n=E3o quer mais receber nossas mensagens por e-mail, cancele sua inscricio aqui

One Response to Walmart Brazil: What’s with all the spamming?

  1. ” a number of Brazilian ESPs.”? Let us be canonical, (Also, I’m not certain all of these would qualify as ESPs so much as hosted spam cannons).

    IP
    67.21.115.31 – Illuminated Hosting Service, LLC
    67.21.115.32 – Illuminated Hosting Service, LLC
    67.21.115.33 – Illuminated Hosting Service, LLC
    67.21.115.34 – Illuminated Hosting Service, LLC
    67.21.115.35 – Illuminated Hosting Service, LLC
    67.21.115.36 – Illuminated Hosting Service, LLC
    67.21.115.37 – Illuminated Hosting Service, LLC
    67.21.115.40 – Illuminated Hosting Service, LLC
    67.21.115.41 – Illuminated Hosting Service, LLC
    67.21.115.42 – Illuminated Hosting Service, LLC
    67.21.115.43 – Illuminated Hosting Service, LLC
    67.21.115.44 – Illuminated Hosting Service, LLC
    67.21.115.53 – Illuminated Hosting Service, LLC
    67.21.115.54 – Illuminated Hosting Service, LLC
    67.21.115.55 – Illuminated Hosting Service, LLC
    67.21.115.56 – Illuminated Hosting Service, LLC
    67.21.115.57 – Illuminated Hosting Service, LLC
    67.21.115.66 – Illuminated Hosting Service, LLC
    67.21.115.67 – Illuminated Hosting Service, LLC
    67.21.115.88 – Illuminated Hosting Service, LLC
    67.21.115.89 – Illuminated Hosting Service, LLC
    67.23.47.220 – Rackspace Hosting / Slicehost LLC
    173.203.238.243 – Rackspace Hosting / Slicehost LLC
    174.143.204.208 – Rackspace Hosting / Slicehost LLC
    186.202.20.170 – Locaweb Servios de Internet S/A
    186.202.20.171 – Locaweb Servios de Internet S/A
    186.202.20.174 – Locaweb Servios de Internet S/A
    186.202.28.195 – Locaweb Servios de Internet S/A
    186.202.28.208 – Locaweb Servios de Internet S/A
    187.61.27.70 – Universo Online S.A.
    187.61.27.186 – Universo Online S.A.
    187.61.27.187 – Universo Online S.A.
    187.61.27.218 – Universo Online S.A.
    187.61.27.220 – Universo Online S.A.
    187.61.27.237 – Universo Online S.A.
    187.61.28.15 – Universo Online S.A.
    187.61.28.36 – Universo Online S.A.
    187.61.28.51 – Universo Online S.A.
    187.61.28.56 – Universo Online S.A.
    187.61.28.57 – Universo Online S.A.
    187.61.28.103 – Universo Online S.A.
    187.61.28.139 – Universo Online S.A.
    187.61.28.147 – Universo Online S.A.
    187.61.28.179 – Universo Online S.A.
    187.61.28.229 – Universo Online S.A.
    187.61.28.243 – Universo Online S.A.
    187.61.29.31 – Universo Online S.A.
    187.61.29.60 – Universo Online S.A.
    187.61.29.93 – Universo Online S.A.
    187.61.29.106 – Universo Online S.A.
    187.61.29.158 – Universo Online S.A.
    187.61.29.165 – Universo Online S.A.
    187.61.29.184 – Universo Online S.A.
    187.61.29.212 – Universo Online S.A.
    187.61.29.231 – Universo Online S.A.
    187.61.29.235 – Universo Online S.A.
    187.61.30.2 – Universo Online S.A.
    187.61.30.31 – Universo Online S.A.
    187.61.30.33 – Universo Online S.A.
    187.61.30.187 – Universo Online S.A.
    187.61.30.193 – Universo Online S.A.
    187.61.34.109 – Universo Online S.A.
    187.61.36.46 – Universo Online S.A.
    187.61.36.70 – Universo Online S.A.
    187.61.36.162 – Universo Online S.A.
    187.61.36.196 – Universo Online S.A.
    187.61.37.28 – Universo Online S.A.
    187.61.37.34 – Universo Online S.A.
    187.61.37.152 – Universo Online S.A.
    187.61.37.230 – Universo Online S.A.
    187.61.37.248 – Universo Online S.A.
    187.61.43.37 – Universo Online S.A.
    187.61.43.43 – Universo Online S.A.
    187.61.43.48 – Universo Online S.A.
    187.61.43.104 – Universo Online S.A.
    187.61.43.122 – Universo Online S.A.
    187.61.43.134 – Universo Online S.A.
    187.61.43.137 – Universo Online S.A.
    187.61.43.143 – Universo Online S.A.
    187.61.43.191 – Universo Online S.A.
    200.250.189.3 – Cikel Logstica e Servios Ltda
    209.85.161.169 – Google Inc.
    209.114.34.246 – Rackspace Hosting / Slicehost LLC
    209.114.47.133 – Rackspace Hosting / Slicehost LLC
    209.114.47.134 – Rackspace Hosting / Slicehost LLC
    209.114.47.135 – Rackspace Hosting / Slicehost LLC
    209.114.47.136 – Rackspace Hosting / Slicehost LLC

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Go back to top