Identity Theft : 2008

Spammers routinely forge the From: line in their junk emails, causing the inevitable flood of bounces, auto-acknowledgements and complaints to land in some innocent third-party's inbox. Like so many other domain names, obliquity.com is sometimes used in these forgeries.

The number of attacks perpetuated by spammers on our domains has made it impossible to track every spam run. Thousands of spam emails and bounces sent to randomly generated addresses in our domains arrive every day.

SpammerForged AddressesFirst Bounce
Date and Time (GMT)
January Storm Worm malware arlette, armfulrugs, receipts, sac, sharp, socila, voysecure, wewior, woodhandicrafts January 106:36:18
Canadian/European Pharmacy,
Casino Club V.I.P.,
Diamond/Prestige Replicas,
E2 Finance,
King Replica,
Mortgage-Infinity,
"Phony University Degrees",
Prestige Footware,
"Pump and Dump",
VPXL
two names,
name.name,
name followed by a word and another name,
name followed by a number and a letter
January 2221:51:08
January 2722:23:31
January 2922:33:48
January 3001:31:26
February February 203:51:30
ggomes, jeni.palmer, jingtao.sun, johna, jrblack, jreed, kaylaren, kendergin, solvent.bobble.pluk, spiritbv February 315:42:54
name.name,
name.LAST_NAME
February 502:41:17
name followed by a word and another name February 2312:18:41
career97, c.doornkamp, fournier, glolyoung, jjujjubong_bar, josedluc, ryo-mate, sandy.wilson, shahid.khan, sjohnson, tina.visnovska, ucyl February 2313:23:22
name followed by a word and another name February 2513:59:13
February 2514:59:08
February 2517:18:27
March Diamond/Prestige Replicas,
"Google Groups casino spammer"
March 122:45:14
Canadian/European Pharmacy,
Diamond/Prestige Replicas,
ExpressHerbals/MaxHerbal/VPXL
March 610:45:35
Canadian/European Pharmacy,
Kraken or Storm Worm malware
aunsen, cho, connington, drbahuleyan, jstead, kredman, lb_koroszczyn, marc, marcel_raimann, mickeyt13, phillips.wr, richard.scullion, stoneworks March 710:12:06
[unknown] beckyvfcathode, beckyw8chariot March 2319:14:05
Canadian/European Pharmacy,
ExpressHerbals/MaxHerbal/VPXL
joybkysnell sometimes preceded by numbers and/or letters March 2322:50:13
vindicator sometimes preceded by numbers and/or letters March 2404:12:59
deobstruent sometimes preceded or followed by numbers and/or letters March 2406:21:47
joybkysnell sometimes preceded by numbers and/or letters March 2407:40:13
dishonestyn March 2604:55:05
pearlzxfchappell sometimes preceded by numbers and/or letters March 2618:34:47
vusfa sometimes preceded by numbers and/or letters March 2700:22:28
Canadian/European Pharmacy,
International Legal RX medications
asghar.h.mirza, barrycurrey, benchakroun, budialu, leenau, lynne.benson, matt_mcmillan, pazur, rajuatkims05, sklavebob2002, sthntirc, tdky, thorntol March 2719:02:02
Diamond/Prestige Replicas,
King Replica,
Prestige Footware
reliance sometimes preceded by numbers and/or letters March 2815:04:10
likin sometimes preceded and/or followed by numbers and/or letters March 2908:33:26
ilvan March 2911:36:58
jasonrywwalker sometimes preceded by numbers and/or letters March 2916:54:59
dishonestyn, dishonestynn March 3000:47:28
silvand, silvandd March 3100:01:49
April [unknown] jk April 115:04:27
Canadian Health&Care Mall,
King Replica,
Prestige Footwear
prestigiatory sometimes preceded by numbers and/or letters April 116:50:47
Diamond/Prestige Replicas relianced April 300:04:54
[unknown] palpus April 313:24:51
jerroldtwjulio April 320:49:53
Kraken or Storm Worm malware,
Canadian Health&Care Mall,
Diamond/Prestige Replicas,
ExpressHerbals/MaxHerbal/VPXL,
King Replica
georgenbfwilson sometimes preceded by numbers and/or letters April 403:51:40
relianced sometimes preceded by numbers and/or letters April 412:59:15
[unknown] palpus April 416:27:47
Diamond/Prestige Replicas petgord34truew April 503:57:56
[unknown] dishonestyn April 507:49:59
ikin April 508:41:50
prestigiatory sometimes preceded by numbers and/or letters April 618:06:29
Kraken or StormWorm malware,
Canadian/European Pharmacy,
King Replica
assagaid sometimes preceded by numbers and/or letters April 622:44:17
Canadian/European Pharmacy,
Diamond/Prestige Replicas,
King Replica
youngun sometimes preceded by numbers and/or letters April 713:43:33
Diamond/Prestige Replicas,
King Replica
info sometimes preceded by numbers and/or letters April 816:04:58

In late February and early March we received thousands of bounces from the googlemail.com mailer daemon. These were in addition to the spam runs listed above. The forged obliquity.com address was in the form name followed by a word and another name.

From 23 March the forgeries changed in character. (Non-existent) addresses which had been receiving spam for months, sometimes years, were (sometimes) slightly altered and used in the From: line during (what were usually but not always) short-lived spam runs numbering several per day.

On 10 April we changed the email settings at obliquity.com to discard all email except those sent to a limited number of authorised addresses. Thus, we no longer track these forgeries.