MailerLite.fi: A Finnish branch office of a Lithuanian(?) ESP that doesn’t even observe its own AUP
Somewhat unfortunately, my traps are in receipt of spam that was sent by Webcore, aka MailerLite.fi, to a purchased list, one that contains addresses of natural persons, and outdated and erroneous personal data. So their own AUP doesn’t appear to apply to themselves, and hence is worth exactly the loo roll it was printed on.
mailerlite.fi (“WebCore”, webcore.fi, a d/b/a of Agrolink Ab) appears to be the Finnish reseller of the supposedly UK business MailerLite.com. (Now the domain registrations for mailerlite.com and mlsend.com indicate UAB “Itema” in Lithuania, and the RIPE WHOIS of the network where soutX.mlsend.com reside, 92.61.38.0/24, is in Lithuania as well… But that’s beside the point, isn’t it.)
MailerLite’s Anti-spam Policy reads just fine. You can’t send to purchased lists, and you can’t send to harvested lists. The Finnish equivalent is identical in substance as it should be.
Spamming IP: 92.61.38.{3,4,5,6}
Spam headers:
From newsletter@mlsend.com Wed Oct 3 10:50:51 2012 Return-Path: <newsletter@mlsend.com> Received: from sout2.mlsend.com (sout2.mlsend.com [92.61.38.4]) by x (Postfix) with ESMTP id x for <x>; Wed, 3 Oct 2012 hh:mm:ss +0300 (EEST) Received: from sout2.mlsend.com (sout2.mlsend.com [92.61.38.4]) by sout2.mlsend.com (Postfix) with ESMTP id x for <x>; Wed, 3 Oct 2012 hh:mm:ss +0300 (EEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=mlsend.com; s=ml; t=timestamp; bh=0hSHAVv4noCDaAoejCm0JkZoVxqDg/rZOgx37rker2w=; h=Date:To:From:Reply-To:Subject:List-Unsubscribe; b=nWA/rYMUf7hhuAtbnPONtb6yzv1M0DsHuZCydUCdM2j5K6h5O02KldPQ8u2FaBMkW bWe4VMmoYoZ8Fx56iROLMOBJqfolEUjp1bCnWTP7cgFHbYNdTUVqxOnewBmxP0bD63 RCC81hMYc0DS5gTA+tsBHxebDCZvMx1JcT/eHA6k= Received: from localhost.localdomain (unknown [92.61.38.189]) by sout2.mlsend.com (Postfix) with ESMTP id x for <x>; Wed, 3 Oct 2012 hh:mm:ss +0300 (EEST) Date: Wed, 3 Oct 2012 hh:mm:ss +0000 To: x From: Webcore <info@webcore.fi> Reply-To: Webcore <info@webcore.fi> Subject: =?utf-8?Q?Haluatko=20keskitty=C3=A4=20kaupantekoon=20ja=20siirt=C3=A4=C3=A4=20it-ongelmat,=20serverit=20ja=20muut=20luotettaviin=20k=C3=A4siin?= Message-ID: <x@localhost.localdomain> X-Priority: 3 X-Mailer: MailerLite (http://www.mailerlite.com) X-Mailer-BounceId: x;x;x Sender: =?utf-8?Q?"Webcore"?=<info=webcore.fi@mlsend.com> List-Unsubscribe: <http://webcore.mailerlite.fi/subscription/unsubscribe/x/x/x/>, <mailto:subscriber-x-x@mlsend.com?subject=x> MIME-Version: 1.0 Content-Type: multipart/alternative; boundary="b1_x" Content-Length: 23559 Lines: 650
Human-readable contents: Practically HTML only, and heavily infested with tracking information. Omitting from here, available on request. Missing mandatory information on the personal data file and its controller, of course. The addresses they’ve been sending to are guaranteed to have been bought, harvested, or both.
MailerLite are now spamming from
[whois.ripe.net]
inetnum: 31.193.196.0 – 31.193.196.255
netname: LT-HOSTEX
descr: Client servers LAN
country: LT
Pingback: OfficeHelpsX Oy: Selling printing supplies to spamtraps » MainSleaze
Today, Webcore.fi (Agrolink Ab) wants to sell Thinkpad laptops to spamtraps, and predictably, the message is coming from MailerLite infrastructure, to spamtraps that must be Fonecta originated, and the spam fails to include the legally mandatory mention of the personal data file they used. Nothing new under the sun, in other words?
They’ve been at it for a while. A quick check revealed that they have sent me spam on Oct 9th, Oct 11th, Nov 19th and Nov 26th. Webcore has a “very poor” trust rating on MyWot.
They also lie on their website (www.webcore.fi):
“Yksityishenkilöille ei myönnetä yritysverkkotunnusta. Sen sijaan voidaan nykyään käyttää pp-verkkotunnusta. Ainoa edellytys on, että verkkotunnus on vapaana. Tällaisessa tapauksessa sähköpostiosoitteesi on muotoa: sinä@minkä-haluat.pp.fi ja kotisivusi saa osoitteen: http://www.minkähaluat.pp.fi.”
Translation: Corporate domains are not granted to individuals. Nowadays you can use a pp-domain instead. The only requirement is that the domain is free. In a case like this your email is of the form: you@whateveryouwant.pp.fi and your homepage gets the address: http://www.whateveryouwant.pp.fi.
For the record, fi-domains are available to all >15yo’s living in Finland with a Finnish personal id number.
Sounds like a professional scam business.
Any chance of you posting copies of their spam texts, or maybe even just subject lines, from the dates you mention?
For the record, I don’t think the bit you quoted from their web page (regarding substitute personal .fi domains) is a deliberate lie. Just seriously outdated, which doesn’t surprise me at all. It’s only since 1 March 2006 that private individuals have been able to apply for .fi domain names proper… Do you actually expect a business in the Internet age to react to news in 8 years? 😀
I was wondering about the data being purely out of date, but the page also does advertise IDNA-domains which were allowed in late 2005 I think. So there would only be a window few months in 2005-2006 when the page might have been valid.
Here are the samples:
Subject: Puinen konvehtirasia
Subject: Puinen konvehtirasia
Subject: Aarteita joululahjoiksi
Subject: Herkkuja ja hemmottelua
All html messages and advertising Valkila Oy, links to either or both Mlsend and/or Mailerlite.fi.
Hello,
sysadmin from mailerlite.com here, this site has been brought to my attention from ahbl.org blacklist guys (many thanks to them).
We had some problems with Finnish partner (local reseller of our services). Now we have taken this region back to our main office, so if you’ll happen to see abusers or spamers from mlsend.com please let us know about it.
Please send your report here abuse {+at+} mlsend.com
If Agrolink Ab are no longer involved with the .fi version of MailerLite in any way, you should seek to have that reflected in the FICORA WHOIS, that is, in the domain registration.