While we all see occasional false information used by spammers to get hosting IP Space, in an age where IPv4 addresses are scarce you always wonder when large swathes of brand new IP space are used for spamming.
And in this case, this is something we have seen over the last few months, but we see the same operator getting more and more IP(s), which is the surprising part.
They call themselves “Wireless Network Solutions Ltd.” and as of four days ago, it seems they received another 6 Class C’s, and within four days they started abusing the internet quite quickly with spam.
Today, two of those Class C’s fired up, triggering alerts all across North America.
220.127.116.11 : essexsilverlinewest.owenbathrooms.com
18.104.22.168 : hcmcorp-com.websterbathrooms.com
22.214.171.124 : hhgregg.wolfmodernbath.com
126.96.36.199 : inspire-productions.macdonaldcopdfacts.com
188.8.131.52 : dwyerproductions.leblanccopdfacts.com
184.108.40.206 : crewof4.lestercopdsource.com
220.127.116.11 : newkirkpainting.josephcopdsource.com
18.104.22.168 : daltoncarpetone.bowmancomsystems.com
22.214.171.124 : plasm.marshcomsystems.com
126.96.36.199 : cartridgehq.boonebusinessnet.com
188.8.131.52 : bon2-net.maddenbusinessnet.com
184.108.40.206 : mingomedia.craiggetaways.com
220.127.116.11 : maggieumc.mooneyvacations.com
18.104.22.168 : cynthiayoung.sweeneyvacations.com
22.214.171.124 : mlewisdental.webstergetaways.com
This is the same pattern they used in the last block of IP(s) they got, throw away domain names, used to spam at a very high rate.
(A couple of other Class C’s fired up as well)
The obvious question, what kind of a company is this? Doesn’t sound like a wireless company..
126.96.36.199 : footbridgemedia.summerspainhelp.com
188.8.131.52 : nycwebstudio.frenchpainhelp.com
184.108.40.206 : micnguyen.clinepainhelp.com
220.127.116.11 : centralcoastis.delgadopainmanagement.com
18.104.22.168 : gginb.heathcruiselines.com
22.214.171.124 : gildeallc.rubiocruiselines.com
126.96.36.199 : grasslandgranite.mosleytravelpartners.com
188.8.131.52 : barr-02.bryantravelpartners.com
184.108.40.206 : littleturtleknits.davenportbizdegrees.com
220.127.116.11 : mlcplus.burchmbadegrees.com
18.104.22.168 : vldedgsrv1.barberbillingeducation.com
22.214.171.124 : goldiegroup.bartonbillingeducation.com
126.96.36.199 : justplainannies.averybillingeducation.com
188.8.131.52 : magicmini.murillomedcoding.com
184.108.40.206 : dougekos.georgemedcoding.com
220.127.116.11 : multicolors.reportsecurcheckinform.com
18.104.22.168 : momulti.yearadditionreportsinform.com
22.214.171.124 : allsc-net.itemlistinformchecks.com
126.96.36.199 : apsops.checkreturnreportexam.com
188.8.131.52 : lytal.pettyonlinelearning.com
184.108.40.206 : kirkconstruction.armstrongdegreechoice.com
220.127.116.11 : ideastudiosinc.durhamdegreechoice.com
18.104.22.168 : jaegerinteractive.mcclureonlinelearning.com
22.214.171.124 : garanww.hollandonlinelearning.com
126.96.36.199 : dancinwithpam.hermantravelupgrades.com
188.8.131.52 : betasproxy.hodgenetworksolutions.com
And on and on and on..