AppyMail: Sending Cheery Little Messages About Mobile Apps to a Spamtrap
AppyMail, a marketer of mobile apps, recently began to send its newsletter to an email address that was closed years before mobile apps or the mobile web existed. I’m not sure why, but the email address is not a likely candidate for a typo. The ESP is PulsePoint.
Sending IP: 96.46.137.114
Spam Sample:
Actual Headers:
Received: from mail2.confirm.appymail.net (mail2.confirm.appymail.net [96.46.137.114])
by <xxx> (Postfix) with ESMTP id <xxx>
for <xxx>; Tue, 27 Mar 2012 17:xx:xx
DKIM-Signature: <xxx>
DomainKey-Signature: <xxx>
Received: by mail2.confirm.appymail.net id <xxx>
for <xxx>; Tue, 27 Mar 2012 09:xx:xx
(envelope-from <bounce-<xxx>@confirm.appymail.net>)
From: AppyMail <AppyMail@confirm.appymail.net>
Reply-To: AppyMail <<xxx>@confirm.appymail.net>
To: <xxx>
Message-ID: <<xxx>.JavaMail.root@confirm.appymail.net>
Subject: New zoo game comes to Android
MIME-Version: 1.0
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable
X-PONT: <xxx>
list-unsubscribe: <mailto:unsub-<xxx>@confirm.appymail.net>
Precedence: bulk
X-PVIQ: <xxx>
Date: Tue, 27 Mar 2012 <xxx>
Readable Email:
From: AppyMail <AppyMail@confirm.appymail.net>
To: <spamtrap>
Subject: New zoo game comes to Android
Reply-To: AppyMail <<xxx>@confirm.appymail.net>
Build and grow a virtual zoo on your Android phone. Tap Zoo is the most popular zoo game on the iPhone and it’s now available on Android. The games by Pocket Gems have been downloaded over 40 million times, see what millions of smartphone owners have already discovered! Download here on the Android Market.
<removed>
This email was sent by Pontiflex, Inc
45 Main Street, Suite 1100 Brooklyn, NY 11201 USA
By any chance, was this trap address the same one that was hit in the HEB post (http://mainsleaze.spambouncer.org/?p=1087#more-1087)?
Here’s why I ask. It’s a completely different client of ours who sent this, but knowing both Pontiflex’s model and the other client’s model, where their sign up forms require an action to opt-in via a co-reg form (i.e. there is an unchecked box that needs to be checked and an email address needs to be physically provided), if they both happened to hit the same trap, then there is certainly some partner of theirs who is feeding them data from a purchased list in place of legitimate sign-ups.
Ideally, we’ll be able to identify the site who is passing the bad data to them in place of the real sign-ups that they are supposed to be providing.
Thanks
Damian
Apologies on the delayed response, Damian. I was out of town and busy with other thing last week, and ignored the blog.
I just checked my archives. No, this was not sent to the same email address or an email address at the same domain as the previous email that you refer to. Is this the same customer as the previous incident, by the way? It doesn’t appear to be…
Thanks for the response…just a hunch I wanted to follow-up on. No, this is not the same customer, but they are in the same industry and could potentially be working with some of the same partners.
Damian
Gotcha. Let us know what you find out.