The report for this spam can be found at: 1998 Deadbeats Page 12.
Return-Path: <carolanne12@ibm.com>
Received: from advanstar.com ([204.220.140.35])
by santaclara01.pop.internex.net (Post.Office MTA v3.1.2
release (PO203-101c) ID# 0-34792U7500L7500S0) with ESMTP
id AAA7930 for <chris@lanets.com>;
Sat, 25 Jul 1998 05:30:36 -0700
Received: from gateway.advanstar.com ([204.189.161.37]) by gateway.advanstar.com
with SMTP id <27471>; Sat, 25 Jul 1998 06:21:44 -0500
Date: Sat, 25 Jul 1998 03:12:10 -0500
From: carolanne12@ibm.com
To: newnewz@newzdomain.com
Subject: Just A Reminder!!
Message-ID: <9807241426.AA01369@kickory.eye.com>
Reply-To: carolanne12@ibm.com
X-UIDL: 46k87d34n74z12j09f63e33n76a23j88d
Comments: Authenticated sender is <carolanne12@ibm.com>
>nslookup 204.220.140.35
Server: ns.mediacity.com
Address: 205.216.172.10
Name: gateway.advanstar.com
Address: 204.220.140.35
>nslookup advanstar.com
Server: ns.mediacity.com
Address: 205.216.172.10
Name: advanstar.com
Address: 204.220.140.35
Relaying server located.
>nslookup 204.189.161.37
Server: ns.mediacity.com
Address: 205.216.172.10
Name: usr1-dialup37.Atlanta.mci.net
Address: 204.189.161.37
Despite the forgery, the spammer has been located.
Now onto the address harvesting site:
>nslookup www.stopMySpam.com
Server: ns.mediacity.com
Address: 205.216.172.10
Name: stopmyspam.com
Address: 209.52.184.164
Aliases: www.stopMySpam.com
>traceroute www.stopMySpam.com
traceroute to stopmyspam.com (209.52.184.164), 30 hops max, 40 byte packets
1 grfge002 (205.216.172.1) 0.367 ms 0.304 ms 0.293 ms
2 bordercore2-hssi0-0-0.SanFrancisco.mci.net (166.48.15.249) 2.795 ms 2.275ms 2.281 ms
3 core1.SanFrancisco.mci.net (204.70.4.169) 3.525 ms 3.801 ms 3.656 ms
4 border2-fddi-0.SanFrancisco.mci.net (204.70.3.162) 128.621 ms 192.966 ms8.055 ms
5 bc-tel.SanFrancisco.mci.net (204.70.33.14) 98.086 ms 67.468 ms 24.191 ms
6 reg4-2.bctel.net (204.174.67.53) 21.651 ms 21.710 ms 21.587 ms
7 207.194.239.97 (207.194.239.97) 25.413 ms 25.779 ms 25.365 ms
8 209.52.184.164 (209.52.184.164) 26.748 ms 29.383 ms 26.666 ms
>whois stopmyspam.com
Registrant:
IDSI Online (STOPMYSPAM-DOM)
14560 SW Chesterfield
Tigard, OR 97224
US
Domain Name: STOPMYSPAM.COM
Administrative Contact:
Proctor, Robert (RP4456) videofactory@MSN.COM
503524-7530 (FAX) 503524-7530
Technical Contact, Zone Contact:
Adlersparre, Erik (EA48) erik@NETPIK.COM
250.475.2311
Billing Contact:
Proctor, Robert (RP4456) videofactory@MSN.COM
503524-7530 (FAX) 503524-7530
Record last updated on 08-May-98.
Record created on 08-May-98.
Database last updated on 25-Jul-98 04:18:21 EDT.
Domain servers in listed order:
NS4.NETPIK.COM 209.52.182.122
NS2.INETWAVE.COM 209.52.182.72
I want to see who owns this netblock so I can get this domain removed.
>whois -h whois.arin.net 209.52.184.0
BC TEL Advanced Communications (NETBLK-BCTEL-207-BLK3) BCTEL-207-BLK3
209.52.0.0 - 209.53.127.255
Top Choice Systems (NETBLK-TOPCHOICE1-CA) TOPCHOICE1-CA
209.52.182.0 - 209.52.186.255
>whois -h whois.arin.net TOPCHOICE1-CA
Top Choice Systems (NETBLK-TOPCHOICE1-CA)
1815 Blanshard St.
Victoria, British Columbia V8T 4H9
Canada
Netname: TOPCHOICE1-CA
Netblock: 209.52.182.0 - 209.52.186.255
Coordinator:
Adlersparre, John (JA798-ARIN) john@NETPIK.COM
604.477.1812
Record last updated on 07-Nov-97.
Database last updated on 24-Jul-98 16:13:44 EDT.
Done!
But finally, I want to dig into the easy remove function:
>whois ibm.com
IBM Corporation (IBM-DOM) IBM.COM
International Business Machines (IBM4-HST) IBM.COM 129.34.139.30
OK, it is a valid domain. That's all I wanted to know.
|