PPRuNe Forums - View Single Post - Mail tagged as "Authenntic Sender", what is it?
Old 2nd October 2004 | 22:11
  #7 (permalink)  
Naples Air Center, Inc.
The Oracle
 
Joined: Aug 2001
Posts: 2,902
Likes: 0
From: Naples, Florida U.S.A.
stickyb,

It looks like it came from either here:

OrgName: XO Communications
OrgID: XOXO
Address: Corporate Headquarters
Address: 11111 Sunset Hills Road
City: Reston
StateProv: VA
PostalCode: 20190-5339
Country: US

ReferralServer: rwhois://rwhois.eng.xo.com:4321/

NetRange: 64.220.0.0 - 64.221.255.255
CIDR: 64.220.0.0/15
NetName: XOXO-BLK-5
NetHandle: NET-64-220-0-0-1
Parent: NET-64-0-0-0-0
NetType: Direct Allocation
NameServer: NAMESERVER1.CONCENTRIC.NET
NameServer: NAMESERVER2.CONCENTRIC.NET
NameServer: NAMESERVER3.CONCENTRIC.NET
NameServer: NAMESERVER.CONCENTRIC.NET
Comment:
RegDate:
Updated: 2003-08-08

OrgAbuseHandle: XCNV-ARIN
OrgAbuseName: XO Communications, Network Violations
OrgAbusePhone: +1-866-285-6208
OrgAbuseEmail: [email protected]

OrgTechHandle: XCIA-ARIN
OrgTechName: XO Communications, IP Administrator
OrgTechPhone: +1-703-547-2000
OrgTechEmail: [email protected]
Or here:

OrgName: Computer Sciences Corporation
OrgID: CSC-68
Address: 3170 Fairview Park Drive
City: Falls Church
StateProv: VA
PostalCode: 22042
Country: US

NetRange: 20.0.0.0 - 20.255.255.255
CIDR: 20.0.0.0/8
NetName: CSC
NetHandle: NET-20-0-0-0-1
Parent:
NetType: Direct Assignment
NameServer: NS1.CSC.COM
NameServer: NS2.CSC.COM
Comment:
RegDate: 1989-09-04
Updated: 2002-05-31

TechHandle: PG618-ARIN
TechName: Gross, Pete
TechPhone: +1-703-641-3322
TechEmail: [email protected]

OrgAbuseHandle: PG618-ARIN
OrgAbuseName: Gross, Pete
OrgAbusePhone: +1-703-641-3322
OrgAbuseEmail: [email protected]

OrgTechHandle: PG618-ARIN
OrgTechName: Gross, Pete
OrgTechPhone: +1-703-641-3322
OrgTechEmail: [email protected]

It looks like the sender was using M$ Outlook to send it form. (Good chance they were hit by Malware and are sending it out without knowing.)

Too bad you do not have the X-ClientAddr IP.

Take Care,

Richard
Naples Air Center, Inc. is offline