Whoops I didn't go down the header.. see what happens when I take a few days off. *brain lock* -----Original Message----- From: plug-discuss-admin@lists.PLUG.phoenix.az.us [mailto:plug-discuss-admin@lists.PLUG.phoenix.az.us]On Behalf Of Gorman, John Sent: Thursday, March 29, 2001 2:28 PM To: 'plug-discuss@lists.PLUG.phoenix.az.us' Subject: RE: anyone up for a little spam analysis? What is this script doing? Going through differnt wet sites? Anybody have more insight on this? The "Received: from 96139.com ([202.107.34.130])" is actually coming from China: inetnum: 202.107.0.0 - 202.107.127.255 netname: CHINANET-LN descr: CHINANET Liaoning province network descr: Data Communication Division descr: China Telecom country: CN admin-c: CH93-AP tech-c: ZZ49-AP mnt-by: MAINT-CHINANET mnt-lower: MAINT-CN-CHINANET-LN changed: weitj@cndata.com 20010307 source: APNIC person: Chinanet Hostmaster address: A12,Xin-Jie-Kou-Wai Street phone: +86-10-62370437 fax-no: +86-10-62053995 country: CN e-mail: hostmaster@ns.chinanet.cn.net nic-hdl: CH93-AP mnt-by: MAINT-CHINANET changed: hostmaster@ns.chinanet.cn.net 20000101 source: APNIC person: Zhang Tielong Zhang Tielong address: Liaoning Shenyang phone: +86-24-22801997 fax-no: +86-24-22800376 country: CN e-mail: lndcb2@pub.sy.ln.cn nic-hdl: ZZ49-AP mnt-by: MAINT-NEW changed: lndcb2@pub.sy.ln.cn 19990416 source: APNIC And === Domain Name:96139.com Registrant: Liaoning Mobile Information Industry Ltd No.79-1,Nan shi Road,Heping District Shenyang Shenyang 110005 China Administrative Contact: Gao ChunLin ShenYang Public Information Property CO. LTD. NO.268 DAXI ROAD,SHENHE DISTRICT,SHENYANG, ShenYang Shenyang 110014 China tel: 86 024 22945649 fax: 86 024 22865151 gcl@pub.ln.cninfo.net Technical Contact: Gao ChunLin ShenYang Public Information Property CO. LTD. NO.268 DAXI ROAD,SHENHE DISTRICT,SHENYANG, ShenYang Shenyang 110014 China tel: 86 024 22945649 fax: 86 024 22865151 gcl@pub.ln.cninfo.net Billing Contact: Wang DongQi ShenYang Public Information Property CO. LTD. NO.268 DAXI ROAD,SHENHE DISTRICT,SHENYANG, ShenYang Shenyang 110014 China tel: 86 024 22945649 fax: 86 024 22865151 gcl@pub.ln.cninfo.net Registration Date: 2000-11-03 Update Date: 2001-02-27 Expiration Date: 2002-11-03 Primary DNS: ns.sy163.net 202.96.64.84 Secondary DNS: ns.cn-clic.com 202.96.82.68 John -----Original Message----- From: Gary Nichols [mailto:gnichols@qwest.net] Sent: Thursday, March 29, 2001 1:32 PM To: plug-discuss@lists.PLUG.phoenix.az.us Subject: RE: anyone up for a little spam analysis? Forward that to abuse@home.com. Whoever is at 24.0.95.232 is either knowingly (or maybe unknowingly!) passing out spam. They are good at sticking to their AUP. -----Original Message----- From: plug-discuss-admin@lists.PLUG.phoenix.az.us [mailto:plug-discuss-admin@lists.PLUG.phoenix.az.us]On Behalf Of Lucas Vogel Sent: Thursday, March 29, 2001 1:27 PM To: plug1 Subject: anyone up for a little spam analysis? I got an interesting piece of spam today, and I'm not entirely sure what it's doing. the source code: ---------------------------------------------------------- Return-Path: Received: from mh7-sfba.mail.home.com ([24.0.95.236]) by mail1.rdc1.az.home.com (InterMail vM.4.01.03.00 201-229-121) with ESMTP id <20010329180004.XIVE9238.mail1.rdc1.az.home.com@mh7-sfba.mail.home.com> for ; Thu, 29 Mar 2001 10:00:04 -0800 Received: from mx7-sfba.mail.home.com (mx7-sfba.mail.home.com [24.0.95.232]) by mh7-sfba.mail.home.com (8.9.3/8.9.0) with ESMTP id KAA23931 for ; Thu, 29 Mar 2001 10:00:03 -0800 (PST) From: tomjones@otenet.gr Received: from 96139.com ([202.107.34.130]) by mx7-sfba.mail.home.com (8.11.1/8.11.1) with ESMTP id f2TI01p20903 for ; Thu, 29 Mar 2001 10:00:01 -0800 (PST) Received: from PACMAN_[207.94.232.21] [207.94.232.21] by 96139.com (SMTPD32-6.06 EVAL) id A4716A0114; Thu, 29 Mar 2001 20:02:57 +0800 Received: from mail-in.pol.net.uk by PACMAN with ESMTP; Thu, 29 Mar 2001 06:04:27 -0600 Message-ID: <00005e014f59$000064fc$000013d6@mail-in.pol.net.uk> To: Subject: The economy needs a 2nd wind 5078 Date: Thu, 29 Mar 2001 06:04:20 -0600 MIME-Version: 1.0 Content-Type: text/html; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable X-Priority: 3 X-MSMail-Priority: Normal Reply-To: bobsuejones454@arabia.com Hello

---------------------- Lucas ________________________________________________ See http://PLUG.phoenix.az.us/navigator-mail.shtml if your mail doesn't post to the list quickly and you use Netscape to write mail. Plug-discuss mailing list - Plug-discuss@lists.PLUG.phoenix.az.us http://lists.PLUG.phoenix.az.us/mailman/listinfo/plug-discuss ________________________________________________ See http://PLUG.phoenix.az.us/navigator-mail.shtml if your mail doesn't post to the list quickly and you use Netscape to write mail. Plug-discuss mailing list - Plug-discuss@lists.PLUG.phoenix.az.us http://lists.PLUG.phoenix.az.us/mailman/listinfo/plug-discuss ________________________________________________ See http://PLUG.phoenix.az.us/navigator-mail.shtml if your mail doesn't post to the list quickly and you use Netscape to write mail. Plug-discuss mailing list - Plug-discuss@lists.PLUG.phoenix.az.us http://lists.PLUG.phoenix.az.us/mailman/listinfo/plug-discuss