From: Michael Tremer <michael.tremer@ipfire.org>
To: development@lists.ipfire.org
Subject: Re: Question regarding AS205092 and AS210180
Date: Tue, 27 Nov 2018 10:12:50 +0000 [thread overview]
Message-ID: <cca702761cdf2ede3660612ec3e7dd5869fbba72.camel@ipfire.org> (raw)
In-Reply-To: <58a82937-3d3e-8253-76e5-3dd4d51c55db@link38.eu>
[-- Attachment #1: Type: text/plain, Size: 1840 bytes --]
Hey,
On Sun, 2018-11-25 at 21:20 +0100, Peter Müller wrote:
> Hello,
>
> at some point since late summer this year, I observe an usual high amount
> of attacks (mainly SSH brute force) against several system I own or
> administer.
>
> Origin of these are AS205092 (OUTSOURCE GRID LIMITED) and AS210180
> (PRISM BUSINESS SERVICES LTD). Both own just a single /24 IPv4 range each,
> and are connected to just one (little known) peer.
>
> AS205092 claims to be located in GB, and its postal address points to
> a dilapidated building somewhere in West Midlands (116 Bloomfield Road,
> Tipton, DY4 9ES).
> Only some of the assigned IPv4 addresses were conspicuous by attacks,
> and are mostly listed at Spamhaus XBL, too. The full range is 185.222.211.0/24
> .
>
> AS210180 has set VE (Venezuela) as geographic location, which also matches
> the postal address. However, its full appeareance leaves doubts whether
> this is correct or not - a website mentioned in the RIR object claims
> an offshore location as office address, with telephone number in US.
> Its IPv4 range (185.222.210.0/24) is also listed as prefix for AS49877
> (RM Engineering LLC).
>
> Both AS claim to provide hosting services, and look highly suspicious
> (bad upstream connectivity, dubious contact/postal addresses, similar
> BGP setup). While it is not mentioned anywhere they are just another
> two rogue ISPs, they would perfectly fit the bill.
>
> Is anybody observing attacks from these too or is in possession of further
> details (exact location, purpose, history, connection between AS210180
> and AS49877)?
No, I did not observe anything although I am usually not paying too much
attention to these things :)
-Michael
>
> Please drop me a line. :-)
>
> Thank you, and best regards,
> Peter Müller
prev parent reply other threads:[~2018-11-27 10:12 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2018-11-25 20:20 Peter Müller
2018-11-27 10:12 ` Michael Tremer [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=cca702761cdf2ede3660612ec3e7dd5869fbba72.camel@ipfire.org \
--to=michael.tremer@ipfire.org \
--cc=development@lists.ipfire.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox