Article 58E3K Do you trace “Spammers” (UBE, UCE, Phishing, others)?

Do you trace “Spammers” (UBE, UCE, Phishing, others)?

by
Michael Uplawski
from LinuxQuestions.org on (#58E3K)
Hi.

This is the third or fourth version of a post, which I think about for some time, but the topic appears hard to grasp...

A phishing campaign gives me the occasion to dig into mail-headers, domain-registrations and stuff. This time, I receive for about two weeks the always same mail:
  • From: is no matter what, *not in the least* connected to the service which the mail pretends to originate from. The sender does obviously not care to do it better.
  • The mail-services used are located in Belarus, Russia, Italy, UK or Canada. *)
  • The Web-site, where I am directed had been in a Spanish domain (operated by a nutritionist in Barcelona) but nowadays is a Swedish throw-away domain, if this exists. I have not searched further, the registrar hides the customer-data.
  • In the *always same* message, the *always same* tax refund is promised.
  • Attachments are the same since the beginning of the campaign.
In view of the persistent nature of this campaign, I wonder what might be the objective. I imagine that someone wants us to become suspicious against the tax administration's online-services.., but by repeating such dumbly conceived notifications.. ?? It all looks really futile and bungled even for Phishing.

For the time I follow the sequel, but already my filters clean away the incoming rubbish.

Do you have a routine for handling such messages or similar mail-abuse? In my case, as the thing looks really dumb, I am more surprised about the effort done and wonder about the motifs of the .., what's the word btw.? Phisher"..? I propose Idiot", a well-fitting, universal expression and most underrated, nowadays.

Edit:
*) retrieved from Received-headers. You supposed that, I confirm.latest?d=yIl2AUoC8zA latest?i=Z58ZM9v2vf8:biZrzgkhPmk:F7zBnMy latest?i=Z58ZM9v2vf8:biZrzgkhPmk:V_sGLiP latest?d=qj6IDK7rITs latest?i=Z58ZM9v2vf8:biZrzgkhPmk:gIN9vFwZ58ZM9v2vf8
External Content
Source RSS or Atom Feed
Feed Location https://feeds.feedburner.com/linuxquestions/latest
Feed Title LinuxQuestions.org
Feed Link https://www.linuxquestions.org/questions/
Reply 0 comments