Doesn't look like another hack btw just the same old address lists bouncing round again.
Definitely is being sent from dodgy servers rather than through Yahoo.
Even sending it over TLS which is a nice touch in case the NSA was wanting to intercept their spam


01:51:46.285 Thread 10388 (v7.3.0.7277) running for new message.
01:51:46.285 TX: <220 smtp.xyz.co.nz ESMTP Trustwave SEG (v7.3.0.7277) Ready>
01:51:46.566 RX: <EHLO out-mta10.ai270.net>
01:51:46.566 <94.126.40.165> has a PTR record, but does not match HELO string <out-mta10.ai270.net>, accepting anyway
Ptrs = out-mta21.ai270.net
01:51:46.566 TX: <250-smtp.xyz.co.nz Hello out-mta10.ai270.net (94.126.40.165)
250-STARTTLS
250 SIZE
>
01:51:46.847 RX: <STARTTLS>
01:51:46.878 TX: <220 Ready to start TLS>
01:51:47.455 TLS negotiation successful.
01:51:47.455 TLS version: TLSv1.2, TLS cipher: AES128-SHA
01:51:47.736 RX: <EHLO out-mta10.ai270.net>