fortypoundhead.com

dwirch

Joined:
2005-01-01
08:24

Last Seen:
2017-09-23
18:04

Posted on:
2017-09-10
06:15

Job Spammer: Prutha Siri - Javelin Systems

Report Back to Forum Back to All Forums

This one is a bit different. Someone at Javelin Systems has sent out a mass email for an SAP position in Tennessee. The interesting part is that this person has used his AWS hosted domain, bzm.mobi, to send the the mail through Zoniac.

The owner information bzm.mobi is:

Prutha Siri
Prutha Inc
1185 RR Road
El Cajon, CA 92020
prutha@cox.net
732-562-0814

Up until recently, I haven't seen too many mails coming through Zoniac. Zoniac claims to be compliant with the CAN-SPAM act, however, I don't think they can honestly do this. One of the features of their product, just like Job Diva, is the ability for a recruiter to search for resumes across many different sources, and directly email that list of potential candidates.  

Sounds innocent enough, but if this tool is wielded by someone who doesn't know what they are doing, you end up with a mass email, as shown above. This guy Prutha probably "works" for Javelin Systems, a recruiter and staffer for IT related candidates and positions. Judging by the whois record, he is probably trying to break out on his own, hence the company name of "Prutha Inc" in the company field of the whois record. However, since he is broke, he is using Javelin sponsored resources to get lists of positions and candidates, while emailing from his AWS-hosted script.

The address given in the whois record doesn't appear to exist.  The nearest similar street name is Railroad Avenue in El Cajon, CA, which is actually a vacant lot.

Javelin Systems - you might want to check this out. I've included the mail header for your information.

Delivered-To: xxxxx@xxxxx.xxx
Received: by 10.176.82.4 with SMTP id i4csp3309674uaa;
        Sun, 10 Sep 2017 00:01:17 -0700 (PDT)
X-Google-Smtp-Source: ADKCNb6pjjzHvzjaN0hBriHbB7/jp2Rg206k7ujr+5dIwQS0ettDHTuBL67Pum8COyLBzBsc/4NS
X-Received: by 10.84.130.97 with SMTP id 88mr9507942plc.138.1505026877534;
        Sun, 10 Sep 2017 00:01:17 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1505026877; cv=none;
        d=google.com; s=arc-20160816;
        b=gJq2OR9A9zE6IcChwYQhLBWhmfii1hzZsj+mzuPrHeCgHwnZn6tALz+4eJSQcQRPN/
         JScfYhSO96LUlbEOtal0IMUGfjIq96jpQoXfl7e5bAcGuTWhJC1H8Wtq6gFHKhgH+qnL
         7koY/QDjdEQnSc3wd5GL5QNJ5tQrqRRO3sraYWfPZCiFzaGEHWfKbmxy8Uj2alqQKqNX
         UsY0bNo1hFhnLtJ2Y1PuMqCk1YNSBiOWVx3qSOcXZBA725eXW6Cnyvyhrb2VgbJftYMo
         rpaqU0T7tpBqzaL7XXnGNLrBIx6pk7M6eCu4Rsr9qH9GvyhRia6TpZhClwI0UZAv9ayX
         pLtw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816;
        h=importance:mime-version:subject:message-id:to:reply-to:from:date
         :arc-authentication-results;
        bh=E25GSDABSlRS9Po29AWEwebTZ3bW3SM0UslyrbTWr6w=;
        b=wPrEBtmzmOEUvGhcCl7C63uc/fNHJAiGFhtiM8T8Tu1KtE+Ntf4Th11bb0guhqSvCm
         VyJ0rS6GuvTeVppX73c/dED6vgQIf647yKooYRuX0BJQ2KH5wFOgF255HjQ/xoTVLPVh
         Eko0PPlrtYY/lVQffGmkdlvxMWisN1PPrPbI1Wj7mOT9MSU6hnMsEj4My9cSPvFaEezg
         R17ivlXeDA7fFq05Qh7zLm7wi/+kSqt7On1X8FbibCBPbBPaLTYr8+1UwWVRVfYykei7
         j0VMjSYiyRWyxMPpNoS0z/iFgG8J7g8GQTKDsisqAFt9uR61qmgnxGQSD9KbUURUW5FU
         U43g==
ARC-Authentication-Results: i=1; mx.google.com;
       spf=pass (google.com: domain of javelinn2s@bzm.mobi designates 204.187.13.47 as permitted sender) smtp.mailfrom=javelinn2s@bzm.mobi
Return-Path: <javelinn2s@bzm.mobi>
Received: from zoniac1.nmsrv.com (zoniac1.nmsrv.com. [204.187.13.47])
        by mx.google.com with ESMTPS id w23si4694665plk.177.2017.09.10.00.01.17
        for <xxxxx@xxxxx.xxx>
        (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128);
        Sun, 10 Sep 2017 00:01:17 -0700 (PDT)
Received-SPF: pass (google.com: domain of javelinn2s@bzm.mobi designates 204.187.13.47 as permitted sender) client-ip=204.187.13.47;
Authentication-Results: mx.google.com;
       spf=pass (google.com: domain of javelinn2s@bzm.mobi designates 204.187.13.47 as permitted sender) smtp.mailfrom=javelinn2s@bzm.mobi
Received: (qmail 9869 invoked from network); 10 Sep 2017 07:01:16 -0000
Received: from ec2-184-73-225-255.compute-1.amazonaws.com (HELO ip-10-45-81-14.ec2.internal) (javelinn2s@bzm.mobi@184.73.225.255)
  by zoniac1.nmsrv.com with ESMTPA; 10 Sep 2017 07:01:16 -0000
Date: Sun, 10 Sep 2017 07:01:00 +0000 (UTC)
From: Javelin Systems <reqs@javelinsys.com>
Reply-To: reqs@javelinsys.com
To: xxxxx@xxxxx.xxx
Message-ID: <1505026860488.2674750361960869.reqs@javelinsys.com>
Subject: SAP Basis with BW / BI Integration in TN
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary="----=_Part_2520678_305134628.1505026860489"
Importance: Normal
X-Mailer: Zoniac Mailer System
X-Zoniac-TrackerID: 7d2e232c23299c730073e048f92f790c6df771666bf7a83f56eaf109c7f506e3410468aae1dfaa71df8c927a09fb124c

You must be logged in order to post a reply.




Recent Forum Posts

Advanced search added
dwirch posted on September 23, 2017 at about 13:44 in Site News

Job Spammer: Gaurav Mehta - AgreeYa Solutions
dwirch posted on September 22, 2017 at about 10:35 in Spammers

Job Spammer: Prutha Siri - Javelin Systems
dwirch posted on September 10, 2017 at about 6:15 in Spammers

New security implemented
dwirch posted on September 7, 2017 at about 7:16 in Site News

Malicious IP Checker Companion Tool
dwirch posted on August 12, 2017 at about 20:24 in Site News

Job Spammer: Steve Adams
dwirch posted on August 8, 2017 at about 7:44 in Spammers