At 08:15 AM 7/31/99 -0400, "Craig A. Isdahl" <[EMAIL PROTECTED]> wrote:
>I've attached a small snippet of our log file.  My question is... is this 
>a spam attempt?  Our log file size hasn't significantly increased but 
>we have seen the same entries for a couple days.  It attempts to 
>send to multiple ips on the imail box without success.

It looks like spammer dung probing for an open relay. I'd say he pointed
whatever spawn of hell probe program he's using at your IP block, or
whatever larger block yours is part of, and he's sitting back waiting to
get a mail through. When he does, he tracks back the vunerable IP from the
header and starts spewing his demonic messages through it like the piece of
filth that he is.

>By the way, the ip address for jdedwards.com is 208.249.49.37 
>when checking whois, NOT 63.69.25.118 as displayed in the log 
>file.

Don't forget whois.arin.net, in addition to nslookup as Dusty pointed out;
UUNET Technologies, Inc. (NETBLK-UUNET63) UUNET63    63.64.0.0 - 63.79.255.255
JD Edwards (NETBLK-UU-63-69-24) UU-63-69-24          63.69.24.0 - 63.69.25.255


-- 
Kirk Mitchell-General Manager        [EMAIL PROTECTED]
Keystone Connect                     Unlock Your World
Altoona, PA   814-941-5000      http://www.keyconn.net

Please visit http://www.ipswitch.com/support/mailing-lists.html 
to be removed from this list.

Reply via email to