[an error occurred while processing this directive]
The report for this spam can be found at: 1998 Deadbeats Page 02.
Return-Path: <16632040@msn.com>
Received: from africa (africa.nicoh.com [198.60.251.1])
by tomcat.ns.net (8.8.5/8.8.5) with SMTP id XAA00889 for <cpicket@ns.net>;
Sat, 31 Jan 1998 23:57:26 -0800 (PST)
From: 16632040@msn.com
Received: from mail.nicoh.com (ip76.sacramento2.ca.pub-ip.psi.net [38.12.122.76])
by africa (SMI-8.6/mail.byaddr) with SMTP id AAA15736;
Sun, 1 Feb 1998 00:46:29 -0700
Received: from bob.ted.carol.and.alice(6985.3.88.24) by 6785555@msn.com (8.8.5/8.6.5)
with SMTP id GAA09118 for <19888765@msn.com>; Sat, 31 Jan 1998 21:27:05 -0600 (EST)
Date: Sat, 31 Jan 98 21:27:05 EST
To: 19888765@msn.com
Subject: ALERT - Internet Fraud and Spying
Message-ID: <this.company.is.not.endorsed.by.or.affiliated.with.msn.or.aol.or.any.other.isp>
Reply-To: 56788891@msn.com
Comments: Authenticated sender is <private.company.and.not.a.internet.service.provider>
X-UIDL: 78927499998765666777777722234562
>nslookup 198.60.251.1
Server: dns.mediacity.com
Address: 205.216.172.10
Name: africa.nicoh.com
Address: 198.60.251.1
Yet another server hijacked by this spammer
>nslookup 38.12.122.76
Server: dns.mediacity.com
Address: 205.216.172.10
Name: ip76.sacramento2.ca.pub-ip.psi.net
Address: 38.12.122.76
And there it is, the point of origination. Everthing else are lame forgeries.
Let me gather some more information on the relaying site and I'm done.
>whois nicoh.com
NICOH Net (NICOH-DOM)
200 S. Main, Suite O
Pocatello, ID 83204
Domain Name: NICOH.COM
Administrative Contact, Technical Contact, Zone Contact:
Simmons, Daniel (DS302) simmdan@NICOH.COM
(800) 406-3191
Record last updated on 08-Jan-97.
Record created on 04-Nov-94.
Database last updated on 31-Jan-98 04:13:10 EDT.
Domain servers in listed order:
AFRICA.NICOH.COM 198.60.251.1
UX1.ISU.EDU 134.50.254.5