hey^) how are you?) do you have a girlfriend?)... i have not boyfriend(( I very
want to meet real men...which will know woman's need ...like in a cinema ... you
know))))lets chat!) i am pretty girl)) I have a lot of time for meetings and if you
have any ideas how to spend it with me... just email me back at
CAROLINE@onlineflh.com and i will reply back with some nice ;) photos with me
...and maybe, you will want to write me again))) CAROLINE@onlineflh.com
Perhaps "Caroline" is trying to data a LISP programmer? There's no website for onlineflh.com, but mail is handled by 79.135.167.51 which is the same as before.. although now the only two websites on that server are Ammae.com and Amnocx.com.
In these circumstances, a tool like Robtex can be useful. It turns out that 79.135.167.51 is a infrastructure server for a number of domains. The IP address noted as belonging to a ROKSO listed spammer, most likely some affiliate of the Russian Business Network (RBN).
Supported domains are:
- alllam.com
- cardrealc.com
- ezshl.com
- famplayfit.cn
- firstlam.com
- flasheon.com
- gosfordw.com
- llcam.com
- morerd.com
- onlineflh.com
- onlineshl.com
- planetflh.com
- rdplanet.com
- towadapointhalf.cn
- virtuellmal.com
The Spamhaus DROP list goes further and lists the entire 79.135.160.0/19 block (79.135.160.0 - 79.135.191.255) as being rogue. That's probably overkill as there do seem to be some legitimate (mostly Turkish) websites hosted in that range.
These were more fun when they had a picture of a pretty girl attached.