Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: Spam reporting addresses - SANS Internet Storm Center SANS ISC InfoSec Forums


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!
Spam reporting addresses
        It's been a quiet day, with a few reports of phish and pop-up
spam.  It looks like we haven't covered spam reporting in a while.

        Because I work so much with spam already as part of the
sa-blacklist and SURBL projects, I take an additional step and report
spam to the organizations and agencies that have interest in certain
spam categories.  I tend to prefer email accounts to which I can
<a href="http://www.stearns.org/doc/spamassassin-setup.current.html#redirect">bounce</a>
spam emails as this is easier to script than trying to send the emails
through web forms.

        First, the FTC will take any spam you get; send it to
uce_at_ftc.gov .  Also, spamarchive.org is interested in any spam you
have, but please send it as an RFC822 attachment (see your email client
docmuentation on "How to send as an attachment") to
submitautomated_at_spamarchive.org .

        Here are the reporting addresses I use, by category:

- Theft of cable services: ocst_at_ncta.com

- Child pornography: children_at_interpol.int, gmail_at_cybertip.ca .
Other than these, do <i>not</i> redistribute the spams, visit any
advertised sites, or keep the emails.  You shouldn't send these to
spamarchive.org as these are republished on an ftp server.

- Nigerian/419 scams
(<a href="http://home.rica.net/alphae/419coal/">http://home.rica.net/alphae/419coal/</a>):
419.fcd_at_usss.treas.gov

- OEM software: netpiracy_at_siia.net, piracy_at_microsoft.com

- Phish scams: reportphishing_at_antiphishing.org,
phish_at_ists.dartmouth.edu, spam_at_mailpolice.com .  Also,
postmaster_at_corp.mailsecurity.net.au and report_at_reportphish.org are
interested, but please send the phish mail as an RFC822 attachment.

- Pills: webcomplaints_at_ora.fda.gov, drugs_at_interpol.int

- Pyramid scams: fraud_at_uspis.gov

- Rolex/replicas: steve.gobin_at_rolex.com, expert_at_lpconline.com

- Stock/pump and dump: enforcement_at_sec.gov

- Tobacco: alctob_at_ttb.treas.gov

- Viruses: avsubmit_at_symantec.com, newvirus_at_kaspersky.com,
samples_at_F-Secure.com, virus_at_cai.com, virus_at_commandcom.com,
virus_at_pandasoftware.com, virus_doctor_at_trendmicro.com,
virus_research_at_nai.com

        Some of the above came from
<a href="http://spamlinks.net">Spamlinks</a>
<a href="http://spamlinks.net/track-report-addresses.htm">Reporting</a>
page - many thanks for an excellent resource.  The email addresses I
covered above tend to be focused on US agencies; definitely visit
spamlinks if you live outside of the US.

        -- Bill Stearns (
<a href="http://www.stearns.org">http://www.stearns.org</a>,
<a href="mailto:wstearns@pobox.com">wstearns@pobox.com</a>)

William

80 Posts

Sign Up for Free or Log In to start participating in the conversation!