[102881] in North American Network Operators' Group
Re: Scan traffic from 121.8.0.0/16
daemon@ATHENA.MIT.EDU (Jon R. Kibler)
Thu Mar 6 15:18:32 2008
Date: Thu, 06 Mar 2008 15:10:39 -0500
From: "Jon R. Kibler" <Jon.Kibler@aset.com>
To: Rich Sena <ras@thick.net>
CC: NANOG <nanog@merit.edu>
In-Reply-To: <Pine.LNX.4.64.0803061500590.21778@noc1>
Errors-To: owner-nanog@merit.edu
This is a multi-part message in MIME format...
------------=_1204834370-514-366
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
Rich Sena wrote:
>
> Anyone seeing anything similar - trying to determine if this is spoofed
> etc...
>
Why would you think it is a problem? It's China Telecom. What else would you expect?
Off the sarcastic and onto the serious, I am seeing hits on 53/UDP and 25/TCP from a couple of hosts in that netblock.
From my experience, these are probably spambots.
Jon K.
--
Jon R. Kibler
Chief Technical Officer
Advanced Systems Engineering Technology, Inc.
Charleston, SC USA
o: 843-849-8214
m: 843-224-2494
==================================================
Filtered by: TRUSTEM.COM's Email Filtering Service
http://www.trustem.com/
No Spam. No Viruses. Just Good Clean Email.
------------=_1204834370-514-366--