Spammin' for and by Barracuda

The below table contains blocking information in use at gtcs.com, and some
other domains, based upon outscatter from an envelope sender indicating that
the spammer is or was spamvertising for Barracuda anti-virus/anti-spam appliances,
while trying to limit their own spam torrent by sending it somewhere else.

Outscatter below, is mail “bounce” from an automated sender to a non-existent or
otherwise non-originating account.  No such spam has been seen here in over six
months from such misconfigured or misprovisioned (and easily identified as such)
equipment in over six months, as of March 2008.

Snapshot as of 2005-08-21 10:32:39 Mountain, modified: Tue, 05 Aug 2008 15:22:13 MDT (also the Last-Modified: header for this page.)

Blocked CIDR Barracuda Spammer Claimed to be
2004-10-06 12.9.240.242 \N barracuda.sputtered-films.com
2004-06-10 12.13.161.4 slip.colsa.com barracuda.colsa.com
2004-06-09 12.13.180.135 atl-barracuda.amec.com atl-barracuda.amec.com
2004-06-23 12.14.248.6 barracuda.cp-tel.net guardian.cp-tel.net
2004-07-24 12.38.198.108 mail10.concentramc.com barracuda.concentra.com
2005-02-14 12.40.114.7 barracuda.gbs.com barracuda.gbs.com
2004-06-29 12.45.13.20 \N barracuda.aftrahr.com
2004-09-30 12.104.80.242 mail.paceint.com barracuda.paceint.com
2005-01-01 12.105.79.6 mailgw.cyrano.com barracuda.cyrano.com
2005-02-21 12.106.14.165 ip165.davisfamilyholdings.net dfhbarracuda.davisfamilyholdings.net
2005-06-22 12.111.135.134 mta.bntt.com barracuda.bntt.com
2004-09-10 12.152.166.159 cuda.sorenson.com cuda.sorenson.com
2005-03-28 12.166.242.68 mail.perimeter.org barracuda.perimeter.org
2005-02-04 12.169.68.109 mail.callawaygardens.com barracuda.callawaygardens.com
2004-06-10 12.175.41.50 barracuda.mailsouth.com barracuda.mailsouth.com
2004-10-18 38.136.242.157 bjexsrv1.bonjourcorp.com barracuda.bonjourcorp.com
2005-02-04 61.120.198.77 \N barracuda.ingeniumgroup.com
2004-11-19 62.177.147.80 \N barracuda.lanatwork.com
2004-10-14 63.76.208.68 hide68.cybergnostic.com(forged) barracuda.ecs-inc.com
2004-06-11 63.99.117.104 host104.coolbrandsww.com(forged) barracuda.coolbrandsww.com
2004-09-06 63.101.224.6 \N barracuda.gbsio.net
2005-01-20 63.113.199.195 mail.pmsi.com barracuda.pmsi.com
2005-02-04 63.145.146.103 \N ccsesa.org
2005-01-09 63.163.61.13 gfi.micros.com barracuda.micros.com
2005-03-20 63.165.233.254 \N barracuda.vseinc.com
2004-06-07 63.166.50.149 63.166.50.149 barracuda.essexgroup.com
2004-06-11 64.4.140.192 cust-64-4-140-192.dsl.fix.net barracuda.morro-bay.ca.us
2004-06-03 64.72.136.2 Fused-72-136-2.OneCall.Net barracuda.firewalls.com
2004-06-29 64.72.236.184 \N barracuda.tridel.com
2005-02-04 64.83.25.226 \N barracuda.super-server.com
2004-10-30 64.114.17.145 \N barracuda.univarcanada.com
2005-03-04 64.128.41.254 mail.medcath.com barracuda.medcath.com
2005-05-17 64.140.81.150 \N barracuda.dcncinc.com
2004-06-01 64.142.56.114 barracuda.imsisoft.com barracuda.imsisoft.com
2004-09-16 64.217.136.22 barracuda.cyberlodg.com barracuda.cyberlodg.com
2005-06-09 64.235.102.100 unassigned.ip100.packetworks.net(forged) barracuda.ugdsb.on.ca
2005-02-04 64.235.229.100 barracuda.elinuxservers.com barracuda.elinuxservers.com
2005-06-10 65.42.219.73 \N barracuda.chacinc.com
2004-10-29 — elided — elided 2008-03-04 from this page reported fixed by apparent RP
2005-01-13 65.61.198.252 barracuda.in2net.com barracuda.in2net.com
2004-12-01 65.66.76.9 cuda.tcworks.net cuda.tcworks.net
2005-04-30 65.101.160.9 mail.aiaiowa.org(forged) barracuda.hotelfortdesmoines.com
2004-11-18 65.119.31.226 \N barracuda.cacopacific.com
2004-10-26 65.119.125.67 \N barracuda.pennemblem.com
2005-02-04 65.124.142.149 barracuda.otpco.com barracuda.otpco.com
2004-07-17 65.161.116.6 \N barracuda.pinebelt.net
2004-06-30 65.164.250.3 barracuda.going1up.com barracuda.going1up.com
2004-09-06 65.209.173.242 barracuda2.covance.com barracuda.covance.com
2004-12-03 65.215.45.5 \N Barracuda.computercompany.net
2005-02-04 65.219.225.132 mail.childapp.com(forged) barracuda.childapp.com
2004-10-04 65.241.249.242 host242.llsa.com barracuda.llsa.com
2004-06-04 65.242.154.132 mail.prminfo.com barracuda.cbizmedia.com
2005-05-08 65.244.2.38 barracuda.multinet-usa.com barracuda.multinet-usa.com
2004-11-21 65.245.13.13 host13.bonhamisd.com(forged) barracuda.netexas.net
2005-06-20 65.248.81.141 mail11.concentra.com barracuda.concentra.com
2004-10-12 66.0.119.83 \N barracuda.langleyandlee.com
2005-02-04 66.42.51.50 \N barracuda.cbol.com
2005-02-04 66.60.128.66 ba.mc.surewest.net barracuda.surewest.net
2004-09-29 66.138.160.20 barracuda.seark.net barracuda.seark.net
2004-12-31 66.204.18.137 \N barracuda.fayar.net
2005-07-03 66.205.36.7 barracuda.wow.net barracuda.wow.net
2005-06-12 67.40.236.6 \N barracuda.ufcw99.com
2004-10-15 67.98.191.122 \N barracuda.jwhomes.com
2005-02-04 67.107.203.83 \N barracuda.lesolsoncompany.com
2005-05-19 67.139.223.140 \N barracuda.smarsh.com
2004-06-14 68.225.153.55 \N barracuda.mcpherson.com
2005-06-14 68.251.195.87 195-087.areanetworking.net barracuda.abcomminc.com
2005-06-18 69.19.214.248 mailgate.fullspectrumia.com mailgate.fullspectrumia.com
2004-10-06 69.27.232.7 451be807.cst.lightpath.net barracuda.reckson.com
2005-06-08 69.157.199.155 MAILEX.TOWN.AURORA.ON.CA ATH-Barracuda.aurora.local
2004-09-20 80.77.67.70 cphgw.nettest.com barracuda.nettest.com
2004-09-01 128.249.38.12 ld4.bcm.tmc.edu cuda.corp.bcm.tmc.edu
2005-01-11 130.225.57.6 mail-gw.iet.aau.dk barracuda.iet.aau.dk
2004-06-11 138.28.1.10 spamapp.kenyon.edu barracuda.kenyon.edu
2004-10-21 141.109.221.10 barracuda.stfx.ca barracuda.stfx.ca
2004-08-28 152.31.32.88 garner4.ci.garner.nc.us barracuda.ci.garner.nc.us
2005-05-23 155.225.6.7 barracuda.CITADEL.EDU barracuda.citadel.edu
2004-06-11 156.143.141.176 barracuda.furman.edu barracuda.furman.edu
2004-08-01 162.33.1.10 attila.rcc.com barracuda.rcc.com
2004-08-18 167.206.146.4 rpc.com(forged) barracuda.rpc.com
2005-01-19 168.9.72.19 barracuda.elbert.k12.ga.us barracuda.elbert.k12.ga.us
2004-09-06 192.48.176.15 \N cuda.sgi.com
2005-06-12 192.139.237.39 smtp.LoyalistC.ON.CA barracuda.loyalistc.on.ca
2004-11-15 192.189.3.74 \N barracuda.manchester.edu
2004-09-01 192.207.173.154 \N barracuda.engr.subr.edu
2004-08-10 194.179.85.4 \N barracuda.pimec.net
2005-06-10 195.27.139.75 mailsw.aviareps.com muc1-sw-01.aviareps.com
2005-05-17 195.28.200.41 mailclean2.psinet.fr barracuda.psinet.fr
2004-09-27 195.208.203.23 \N baracuda.intellisoft.ru
2004-11-18 195.244.160.107 \N barracuda.ibgebim.be
2005-06-10 198.239.93.19 barracuda.co.island.wa.us barracuda.co.island.wa.us
2004-08-09 199.2.132.187 \N barracuda.harbornet.com
2004-06-17 203.63.110.4 barracuda.fishinternet.com.au barracuda.fishinternet.com.au
2005-06-28 203.193.152.138 email.datamatics.com barracuda.datamatics.com
2004-06-09 204.60.150.15 mail.raveisre.com barracuda.raveisre.com
2004-07-28 204.111.11.46 cuda.shentel.net cuda.shentel.net
2004-10-15 204.168.71.132 \N barracuda.freelife.com
2004-10-14 204.183.91.15 barracuda.dol.net barracuda.dol.net
2004-06-07 204.235.162.17 204.235.162.17 barracuda.ship.k12.pa.us
2004-08-06 204.248.20.12 barracuda.neonramp.com barracuda.neonramp.com
2005-06-15 205.154.84.70 mail2.icoe.k12.ca.us barracuda.icoe.org
2005-07-03 205.205.16.230 mail.rchagen.com barracuda.rchagen.com
2005-06-29 205.213.42.9 barracuda.miad.edu barracuda.miad.edu
2005-06-29 205.225.148.121 \N barracuda.cccco.edu
2004-11-04 205.242.56.45 barracuda.up.net barracuda.up.net
2005-01-02 205.243.133.4 mx1.emergency.com Barracuda.emergency.com
2005-05-27 206.104.16.2 mail.charlesryan.com barracuda.charlesryan.com
2004-10-03 206.228.120.66 barracuda.ott.net barracuda.ott.net
2005-06-11 206.230.97.201 barracuda.monarchdental.com(forged) RBS-EXCHANGE.CORPCA.COM
2004-10-02 207.15.57.10 spencerreeddns.com barracuda.spencerreed.com
2004-08-29 207.55.105.2 barracuda.nu-world.com barracuda.nu-world.com
2004-11-09 207.79.14.12 \N barracuda.artisoft.com
2005-06-12 207.107.246.18 scormsx05.transcontinental.ca barracuda.transcontinental.ca
2004-06-17 207.109.223.69 mail.viracon.com barracuda.viracon.com
2004-06-24 207.140.80.2 cuda.netpluscom.com cuda.netpluscom.com
2004-09-09 207.148.205.34 \N barracuda.optimeyes.com
2004-06-08 207.165.108.6 pool-12-6.pix.aea9.k12.ia.us barracuda.wiltoncsd.org
2004-09-24 207.199.100.51 \N barracuda.gmsnet.com
2004-09-09 207.200.9.114 \N barracuda.onr-inc.com
2004-08-27 207.212.111.36 barracuda.cyberlynk.com barracuda.cyberlynk.com
2005-02-04 207.212.155.11 barracuda.succeed.net barracuda.succeed.net
2005-06-29 207.224.187.173 \N barracuda.bergegroup.com
2004-09-22 207.239.85.66 \N barracuda.flaglertitle.com
2004-08-12 207.254.192.59 barracuda.shreve.net barracuda.shreve.net
2004-07-25 208.19.29.3 \N barracuda.mrcmry.com
2005-02-04 208.35.128.6 mx1.gcentral.com barracuda.gcentral.com
2004-07-21 208.62.125.134 \N barracuda.wayxcable.com
2004-07-04 208.178.188.18 sequoyah.namfg.com barracuda.namfg.com
2005-05-19 208.190.15.1 firewall.romco.com barracuda.romco.com
2004-08-18 208.255.3.13 barracuda.teamworkswall.com spam.tigerpaw.com
2005-06-22 208.255.162.18 proxy.cti1.net barracuda.cti1.net
2004-11-15 209.7.239.18 mail.sih.net barracuda.sih.net
2004-06-17 209.11.99.120 mail.elliman.com barracuda.elliman.com
2005-06-11 209.36.131.15 barracuda.kus.com barracuda.kus.com
2005-02-13 209.56.97.1 fdcsd-inet.fort-dodge.k12.ia.us(forged) barracuda.fort-dodge.k12.ia.us
2004-07-20 209.56.97.15 I-am.fort-dodge.k12.ia.us(forged) barracuda.fort-dodge.k12.ia.us
2005-05-17 209.83.80.190 packer01.pcitrucks.com barracuda.pcitrucks.com
2005-03-23 209.107.56.131 alpine131.alpinelumber.com barracuda.alpinelumber.com
2004-08-27 209.137.244.30 barracuda.ycsi.net barracuda.ycsi.net
2005-03-03 209.147.47.29 user209x147x47x29.downey.k12.ca.us(forged) barracuda.dusd.net
2004-12-07 209.155.145.46 random-145-46.ci.mtnview.ca.us barracuda.ci.mtnview.ca.us
2004-11-21 209.176.8.8 barracuda.ctconnect.net barracuda.ctconnect.com
2004-11-04 209.176.170.11 \N barracuda.nightowl.net
2004-06-07 209.192.46.61 209.192.46.61 barracuda.ercweb.com
2005-06-13 209.210.58.245 relay.wseco.com barracuda.wseco.com
2004-09-02 209.217.50.102 barracuda.catalog.com barracuda.catalog.com
2005-01-10 209.241.94.46 \N barracuda.achillesusa.com
2004-06-18 209.250.136.146 \N barracuda.stc.ca
2004-07-16 212.55.32.120 barracuda.olivant.fo barracuda.olivant.fo
2004-06-04 213.183.112.82 noname.hw.tpu.ru(forged) barracuda.hw.tpu.ru
2005-02-04 216.17.169.130 \N barracuda.highlinecapital.com
2004-12-15 216.25.176.26 smtp.greatlakes.net barracuda.greatlakes.net
2004-07-26 216.54.231.210 pop3.offsetatlanta.com barracuda.cerqa.com
2004-11-29 216.87.85.209 \N barracuda.viawest.net
2004-11-18 216.87.85.210 \N barracuda.viawest.net
2005-02-04 216.90.233.31 exchange.happykids.com barracuda.happykids.com
2005-06-12 216.159.4.214 main6smtp.wdmcs.org barracuda.wdm.k12.ia.us
2004-07-15 216.195.219.210 \N Barracuda.mesfoundation.com
2005-06-29 216.234.25.4 mx3.cumulus.com barracuda.cumulus.com
2005-02-03 217.10.20.129 \N barracuda.kk.dk
2004-07-29 217.206.238.2 \N barracuda.rapra.net
(161 rows)
The notation "\N" indicates a null reverse-DNS (number-to-name) lookup.
The notation "(forged)" indicates that the name given in reverse-DNS does not match a
forward-DNS (name-to-number) lookup, or didn't when checked.

A similar activity is done through bad setups by Symantec anti-spam and anti-virus
gateway products, the popular QMail E-Mail server software, and the Plesk
management interface. Then there's Microsoft Exchange in a class by itself.

Some even spew this out their trusted Domain Nameservers.

The above listed sites are already participants in a DDoS attack, as described and widely
warned against in a 2004 white paper.

See also: DDoS Attack Hosts

The sad thing is that all this spam is not necessary!  Simple Settings can prevent a lot of it.

>>This<< webpage was first posted in early
February 2005.