I think they are running open mail servers. I get 50+ of these in my logs every day
61.231.90.92 - - [06/Sep/2013:23:03:47 -0400] "CONNECT mx3.mail2000.com.tw:25 HTTP/1.0" 403 202 "-" "-"
I don't know why it has bad reputation. This site is a paid (non-free) email web host that I have paid for years to use their email service. They do not provide any contents; it's just an email host, so the "malicious content" thing is just ridiculous. It provides a very special feature called "discardable email address", which let you set up many email addresses in one account so you can give a special email address to an untrustworthy party, and later when you decide they have spammed you or sold it, you just discard that email address so you cannot be harmed anymore. However, I guess this is probably the reason of its bad reputation, because spammers could also take advantage of this feature.
Oh, and it's not in the HMOS black list.