[an error occurred while processing this directive]
The report for this spam can be found at: Deadbeats Page 15.
Return-Path: <38859756@hotmail.com>
Received: from ul1.satlink.com (root@ul1.satlink.com [200.0.224.2])
by tomcat.ns.net (8.8.5/8.8.5) with ESMTP id QAA23103 for <cpicket@ns.net>;
Sun, 23 Nov 1997 16:34:56 -0800 (PST)
From: 38859756@hotmail.com
Received: from tournet.tournet.com.ar ([200.16.195.46]) by ul1.satlink.com (8.8.7/8.8.7)
with ESMTP id WAA23939; Sat, 22 Nov 1997 22:23:51 -0300 (GMT-3)
Received: from tournet.com.ar (ip35.charleston.sc.pub-ip.psi.net [38.14.118.35])
by tournet.tournet.com.ar (8.8.5/SCA-6.6) with SMTP id BAA12914;
Sun, 23 Nov 1997 01:24:43 GMT
Received: from mailhost.nowhere.com (alt.1nowhere.com (208.9.77.65))
by nowhere.com (8.8.5/8.6.5) with SMTP id GAA09778 for <UcanDoit@kolomiec.rosmail.com>;
Sat, 22 Nov 1997 20:06:51 -0600 (EST)
Date: Sat, 22 Nov 97 20:06:51 EST
To: UcanDoit@kolomiec.rosmail.com
Subject: FIRM UP WITHOUT GIVING UP...the food you love!
Message-ID: <199702580039DAA007056>
Reply-To: UcanDoit@hotmail.com
X-PMFLAGS: 34078848 0
Comments: Authenticated sender is <success@nowhere.com>
X-UIDL: 4590327a97abd5g342usl675po521kl
ul1.satlink.com [200.0.224.2] does in fact resolve, exposing the relaying server.
tournet.tournet.com.ar resolves to: 200.16.195.2
200.16.195.46 resolves in the same network in Agentina off the MCI network.
208.9.77.65 does not reosolve because it is forged.
(ip35.charleston.sc.pub-ip.psi.net [38.14.118.35]) does resolve. This is the point
of origination.
>whois satlink.com
SatLink S.A. (SATLINK2-DOM)
Av La Plata 141 - 1 B
1184 Buenos Aires
ARGENTINA
Domain Name: SATLINK.COM
Administrative Contact, Technical Contact, Zone Contact:
Stolovitzky, Horacio (HS3) horacio@SATLINK.NET
+54-1-327-0011 (FAX) +54-1-327-2263
Record last updated on 05-Jan-97.
Record created on 04-May-95.
Database last updated on 23-Nov-97 05:03:39 EDT.
Domain servers in listed order:
BOLERO.RAHUL.NET 192.160.13.1
HUSTLE.RAHUL.NET 192.160.13.2
NWNEXUS.WA.COM 192.135.191.1
NWFOCUS.WA.COM 192.135.191.3
Hmm, quite interesting. I am suspecting this was a very deliberate attempt to not only
hijack the server, but to attempt to make it appear that it also originated from
Agentina as well. Bad attempt.