And looking up that 211.101.254.226 address gives:
--8<--
# dig 226.254.101.211.in-addr.arpa.
; <<>> DiG 9.2.1 <<>> 226.254.101.211.in-addr.arpa.
;; global options: printcmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 2931
;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 0
;; QUESTION SECTION:
;226.254.101.211.in-addr.arpa. IN A
;; AUTHORITY SECTION:
254.101.211.in-addr.arpa. 10800 IN SOA ns.capitalnet.com.cn.
hostmaster
.ns.capitalnet.com.cn. 2001041201 3600 900 1209600 43200
;; Query time: 231 msec
;; SERVER: 127.0.0.1#53(127.0.0.1)
;; WHEN: Thu Nov 7 17:21:45 2002
;; MSG SIZE rcvd: 113
--8<--
The Chinese are at it again, either second hand through a hacked host or
first hand. Send them a nice email thanking them for the order for 1000
reprints of the Falun Gong Handbook. That should shut them up REAL quick.
{^_-}
----- Original Message -----
From: "Mike Chambers" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Thursday, November 07, 2002 16:34 PM
Subject: Re: strange e-mail from root
> ----- Original Message -----
> From: "Christian Thibodeau" <[EMAIL PROTECTED]>
> To: <[EMAIL PROTECTED]>
> Sent: Thursday, November 07, 2002 2:13 PM
> Subject: Re: strange e-mail from root
>
>
> > I also received one, and it originated from the same IP address as the
> > ones mentioned on the list so far: 211.101.140.97. The address does not
> > resolve, and traceroute is not very informative. The last few lines of
> > my traceroute output follow (I have removed the timings for brevity):
>
> Tracing route to 211.101.140.97 over a maximum of 30 hops
>
> 1 9 ms 9 ms 9 ms 10.28.192.1
...
> 18 267 ms 271 ms 266 ms Acc01-F010-ToGSR01.TYnoc.bj.capitalnet
> [211.101.254.226]
> 19 276 ms 276 ms 277 ms 211.101.140.97