Call for packets - Traffic from 116.177.0.0/16
If you have log records or packets for traffic from this particular subnet. If you have anything you can share I'd appreciate it.
Likely what you will have is DNS open resolver checks, as well as SSH bruteforce pwd guessing attacks. I'm interested in those as well as anything else from this subnet.
Regards
Mark H - markh.isc (at) gmail.com
(Thanks to those of you that have provided packets, logs and other info, much appreciated)
Keywords:
9 comment(s)
×
Diary Archives
Comments
Anonymous
Jun 27th 2014
1 decade ago
ip | http requests parameter after the fqdn
| 116.117.45.62 | /www.iamsharer.com/js.php | - |
| 116.117.45.62 | /mm.iamsharer.com/js.php | - |
| 116.117.45.62 | /www.iamsharer.com/js.php | - |
| 116.117.45.62 | /mm.iamsharer.com/js.php | - |
| 116.117.45.62 | /www.iamsharer.com/js.php | - |
| 116.117.45.62 | /mm.iamsharer.com/js.php | - |
| 116.117.58.95 | /admin/_content/_About/AspCms_AboutEdit.asp | - |
| 116.117.58.95 | /admin/_content/_About/AspCms_AboutEdit.asp | -
| 116.117.228.177 | /69639/9811877.html | - |
| 116.117.228.177 | /69639/9811479.html | - |
| 116.117.228.177 | /71128/10439411.html | - |
| 116.117.228.177 | /71128/9243519.html | - |
| 116.117.228.177 | /69639/9811479.html | -
Anonymous
Jun 27th 2014
1 decade ago
Anonymous
Jun 27th 2014
1 decade ago
Anonymous
Jun 27th 2014
1 decade ago
M
Anonymous
Jun 28th 2014
1 decade ago
Anonymous
Jun 28th 2014
1 decade ago
Anonymous
Jun 28th 2014
1 decade ago
Was there a typo in the original post? Or did someone read the original ISC post IP range wrong?
Anonymous
Jun 28th 2014
1 decade ago
Anonymous
Jun 29th 2014
1 decade ago