Uh oh, Steve Corsi is on fire!
Somebody better grab a fire extinguisher, because Steve Corsi is on fire. I’m not sure who Steve Corsi is, but GamedayNetwork.com is so eager to tell everyone about this that they seem to have purchased a list containing many spamtrap addresses. I’m seeing copies of this mailing to multiple addresses, including both never-valid addresses and addresses that have been dead for more than 10 years.
The ESP is SimplyCast.
The text version of the message was empty except for a couple of “click here” links. I did not load or include the HTML as I did not want to falsely register image load activity to imply that my spamtrap addresses were alive.
Source IP: 64.50.149.22
Return-Path: x@bounce.scsend.net Received: from scsend.net (bb22.scsend.net. [64.50.149.22]) by x with ESMTP id x; Sun, 05 Aug 2012 x:x:x -x (x) X-Unsubscribe: unsubscribe@scsend.net From: "GamedayNetwork.com" To: x Message-ID: Subject: Steve Corsi On Fire - Huge NFL Preseason Lock plus MLB Mega Play Today! Return-Path: x@bounce.scsend.net Content-Type: multipart/alternative; boundary="=x" List-Unsubscribe: x DKIM-Signature: x X-Complaints-To: abuse@scsend.net Date: Sun, 05 Aug 2012 x:x:x -x MIME-Version: 1.0
They did indeed purchase a list, and hit several of our spamtraps. That resulted in an SBL listing that was removed when SimplyCast terminated service to them earlier this afternoon.
This spammer was not just Gameday Network, but used several domains all of which received name service from ns1.free-picks.com and ns2.free-picks.com. All of the domains were registered with Domains by Proxy. DBP is by no means the spammiest of the Whois cloaking companies, but Whois cloaking is in itself disreputable when used by a company, especially one that makes heavy use of bulk email.