We have received a large number of spams containing a virus from Digital Ocean address spaces. We are receiving these exclusively from digital address space. For every one of these I have sent e-mail to their published abuse address, abuse@digitalocean.com and to their NOC at noc@digitalocean.com.
I have yet to receive a single reply and as a consequence I initially started blocking individual addresses these came from. But still they continue. Now I am blocking entire address blocks as we receive this virus / spam. I am also sending this to blacklist maintainers as well as using it as a source to train our baysian filters.
At present the following address space is blocked for incoming mail:
167.172.127.122 REJECT Spam Digital Ocean
165.227.147.88 REJECT Spam Digital Ocean
128.199.13.160 REJECT Digital Ocean Virus
159.203.181.43 REJECT Digital Ocean Virus
188.166.64.227 REJECT Digital Ocean Virus
209.97.155.51 REJECT Digital Ocean Virus
204.48.23.113 REJECT Digital Ocean Virus
104.248.58.145 REJECT Digital Ocean Virus
198.199.120.66 REJECT Digital Ocean Virus
138.197.0.0/16 REJECT Digital Ocean Virus
143.110.128.0/17 REJECT Digital Ocean Virus
142.93.0.0/16 REJECT Digital Ocean Virus
159.203.0.0/16 REJECT Digital Ocean Virus
159.89.0.0/16 REJECT Digital Ocean Virus
159.65.0.0/16 REJECT Digital Ocean Virus
174.138.0.0/17 REJECT Digital Ocean Virus
64.227.0.0/17 REJECT Digital Ocean Virus
188.166.0.0/17 REJECT Digital Ocean Virus
I don’t like to do this but when a company will not respond to complaints and the spams are viral in nature, I am left with little choice. I have also submitted a copy to clam-av folks to generate a signature for this.