[SGVLUG] interesting spam, full headers - what do you think

Emerson, Tom (*IC) Tom.Emerson at wbconsultant.com
Wed Mar 31 12:20:07 PDT 2010


> -----Original Message----- Of Mike Rubel
> [of matti]:
> > the IP address 68.142.206.152 resolves back to yahoo.

> I suspect that 68.142.206.152 is a spam-filtering system
> belonging to yahoo, and that the real source is
> 190.255.246.61, which is apparently somewhere in Colombia.

The 68...150, .152, & .154 addresses belong to machines named web33501, web33503, & web33505.mail.mud.yahoo.com (respectively) - i.e., the e-mail/webmail "farm" at yahoo

(host/dig is your friend :) )

[...]


More information about the SGVLUG mailing list