> host 67.94.106.102Taking the above information, it appears IP address is
102.106.94.67.in-addr.arpa domain name pointer psr2906693.z106-94-67.customer.algx.net.
> whois 67.94.106.102
OrgName: XO Communications
OrgID: XOXO
Address: Corporate Headquarters
Address: 11111 Sunset Hills Road
City: Reston
StateProv: VA
PostalCode: 20190-5339
Country: US
ReferralServer: rwhois://rwhois.eng.xo.com:4321/
NetRange: 67.88.0.0 - 67.95.255.255
CIDR: 67.88.0.0/13
NetName: IALG-ALGX-9
NetHandle: NET-67-88-0-0-1
Parent: NET-67-0-0-0-0
NetType: Direct Allocation
NameServer: NS1.XO.COM
NameServer: NS2.XO.COM
Comment: ADDRESSES WITHIN THIS BLOCK ARE NON-PORTABLE
RegDate: 2001-09-26
Updated: 2005-08-09
OrgAbuseHandle: XCNV-ARIN
OrgAbuseName: XO Communications, Network Violations
OrgAbusePhone: +1-866-285-6208
OrgAbuseEmail: abuse@xo.com
OrgTechHandle: XCIA-ARIN
OrgTechName: XO Communications, IP Administrator
OrgTechPhone: +1-703-547-2000
OrgTechEmail: ipadmin@eng.xo.com
# ARIN WHOIS database, last updated 2005-08-21 19:10
> whois -h rwhois.eng.xo.com -p 4321 67.94.106.102
%rwhois V-1.5:003fff:00 rwhois.eng.xo.com (by Network Solutions, Inc. V-1.5.9)
network:Class-Name:network
network:ID:NET-XO-NET-435e6a64
network:Auth-Area:67.88.0.0/13
network:Network-Name:XO-NET-435e6a64
network:Organization;I:COMPUTECH (ALGX)
network:IP-Network:67.94.106.100/30
network:Admin-Contact;I:XCIA-ARIN
network:Tech-Contact;I:XCIA-ARIN
network:Created:20030825
network:Updated:20030825
network:Updated-By:ipadmin@eng.xo.com
> traceroute -I 67.94.106.102
traceroute to 67.94.106.102 (67.94.106.102), 64 hops max, 60 byte packets
1 gateway (192.168.0.1) 3.609 ms 3.128 ms 3.075 ms
2 ip68-101-96-1.oc.oc.cox.net (68.101.96.1) 14.974 ms * 13.711 ms
3 * 68.4.15.65 (68.4.15.65) 23.870 ms 13.802 ms
4 * ip68-4-14-93.oc.oc.cox.net (68.4.14.93) 16.812 ms 37.249 ms
5 * rsmtdsrj01-ge704.rd.oc.cox.net (68.4.14.253) 13.829 ms *
6 so-4-0.hsa2.tustin1.level3.net (65.59.168.1) 18.908 ms * 14.847 ms
7 4.68.114.21 (4.68.114.21) 21.208 ms 17.540 ms 18.878 ms
8 as-0-0.bbr2.losangeles1.level3.net (209.247.8.113) 24.458 ms
9 ge-0-0-0-53.gar2.losangeles1.level3.net (4.68.102.81) 67.350 ms
10 xo-level3-oc12.losangeles1.level3.net (209.0.227.34) 20.099 ms 18.329 ms 22.142 ms
11 p4-0-0.rar2.la-ca.us.xo.net (65.106.5.49) 20.619 ms * 103.170 ms
12 p6-0-0.rar1.dallas-tx.us.xo.net (65.106.0.13) 71.228 ms 48.954 ms *
13 p0-0-0d0.rar2.dallas-tx.us.xo.net (65.106.1.38) 54.884 ms 49.171 ms 50.923 ms
14 p6-0-0.rar1.atlanta-ga.us.xo.net (65.106.0.9) 81.589 ms 82.113 ms 80.586 ms
15 p0-0-0d0.rar2.atlanta-ga.us.xo.net (65.106.1.26) 84.866 ms 93.252 ms 82.010 ms
16 p1-0-0.rar2.washington-dc.us.xo.net (65.106.0.5) 86.888 ms 81.716 ms 80.830 ms
17 * p7-0-0.mar2.washington5-dc.us.xo.net (65.106.3.206) 83.076 ms *
18 fe4-0-0.clr11.washington5-dc.us.xo.net (71.5.190.174) 83.907 ms 84.196 ms 86.803 ms
19 psr2906693.z106-94-67.customer.algx.net (67.94.106.102) 94.735 ms 89.955 ms 146.535 ms
> whois -h whois.abuse.net xo.net
abuse@xo.com (for xo.net)
> whois -h whois.abuse.net algx.net
abuse@xo.net (for algx.net)
> telnet 67.94.106.102
Trying 67.94.106.102...
Connected to psr2906693.z106-94-67.customer.algx.net.
Escape character is '^]'.
TA 616 Gen3
I have a lot of experience with tracking down spammers, so if you prefer to not publicly disclose the IP address or your mail headers, I'd be happy to do the legwork for you. Just copy the complete mail headers from a couple of the virus-laden emails and send them to the e-mail address in my profile. I'll see if I can find you appropriate contact details.
posted by RichardP at 6:16 PM on August 21, 2005