Something still amiss..
These headers:
QUOTE
Microsoft Mail Internet Headers Version 2.0
Received: from Lando.sdgworld.net ([172.16.10.7]) by Harry.sdgworld.net with Microsoft SMTPSVC(6.0.3790.0);
Mon, 5 Jul 2004 13:30:59 +0100
Received: from mx1.exponential-e.com ([62.244.177.19]) by Lando.sdgworld.net with Microsoft SMTPSVC(5.0.2195.6713);
Mon, 5 Jul 2004 13:30:59 +0100
Received: from [140.122.200.115] (port=3795 helo=62.244.177.193)
by mx1.exponential-e.com with smtp (Exim 4.24)
id 1BhSZY-0003Ut-3p
for b.freeman@sdgworld.net; Mon, 05 Jul 2004 12:27:48 +0000
Received: from 128.40.59.67 by 140.122.200.115; Mon, 05 Jul 2004 07:30:00 -0600
Message-ID: <UWQSEBRREUBUWQMTCAEKH@goodmail.com>
From: "Angelina Coleman" <kzedzo@voicestream.net>
Reply-To: "Angelina Coleman" <kzedzo@voicestream.net>
To: b.freeman@sdgworld.net
Subject: b.freeman@sdgworld.net -We have CEOs as students.
Date: Mon, 05 Jul 2004 18:26:00 +0500
X-Mailer: Microsoft Outlook, Build 10.0.2616
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary="--180711651860536"
X-Priority: 3
X-MSMail-Priority: Normal
Return-Path: kzedzo@voicestream.net
X-OriginalArrivalTime: 05 Jul 2004 12:30:59.0234 (UTC) FILETIME=[ED2CF820:01C4628B]
----180711651860536
Content-Type: text/html;
Content-Transfer-Encoding: quoted-printable
1.29 wants to send to:
ABUSE@ULCC.AC.UK
POSTMASTER@CWI.NL
POSTMASTER@ANS.NET
ABUSE@ANS.NET
ABUSE@UCL.AC.UK
CERT@UCL.AC.UK
ABUSE@JA.NET
CERT@CERT.JA.NET
The AC.UK addresses are probably derived from the received: line containing 128.40.59.67, but this is an obvious forgery.
the previous received line:
Received: from [140.122.200.115] (port=3795 helo=62.244.177.193)
Shows the actual sending system [140.122.200.115] with a forged helo.
yet the 140.122.200.115 address is not picked up at all.
This resolved to twnic.net and an email: address of tanetadm@moe.edu.tw
Confirmed by processing it through spamcop.
Bazz