[60313] in North American Network Operators' Group
Re: a list of hosts in a RPC BOTNET, mostly 209.x.x.x,
daemon@ATHENA.MIT.EDU (Henry Linneweh)
Wed Aug 6 11:54:42 2003
Date: Wed, 6 Aug 2003 08:53:28 -0700 (PDT)
From: Henry Linneweh <hrlinneweh@sbcglobal.net>
To: Drew Weaver <drew.weaver@thenap.com>, nanog@merit.edu
In-Reply-To: <75634F04BFCFD511BF69009027DC86497D18CF@mailman.thenap.com>
Errors-To: owner-nanog-outgoing@merit.edu
--0-544482457-1060185208=:88640
Content-Type: text/plain; charset=us-ascii
When looking at IRC and chat networks in general you have to look at them
from the internet since the attacks are launched from the internet outside
of any irc. The originators of the attacks use irc as a front to distract the
investigators effort to find their real points of origin.
In the past I have stated circa 1998 - 2000 time frame, that ISP's that
fail to address the issue should be held liable for damages sustained
by other parties that fail to terminate clients for AUP violations, where
there is conclusive overwhelming proof as to the source of the attack,
(point of origin).
Drew Weaver <drew.weaver@thenap.com> wrote:
I've tried contacting abuse departments of several of these isps and none of them seem to care, so I figured I would post the info here, and maybe someone will let them know, the biggest offender is atlantech. These are all hosts that have been compromised by the same person, they're being used to SYN flood 65.110.34.100
If you want to see this glorious channel for your self its called #!LPOL! on Undernet.
Basically the way this works is your box gets attacked, then it sits on this irc channel and waits for commands, in this case the command is !SYN 65.110.34 1000 6667 9999 -s
Anyways here is the list, and every 30 seconds or so 2 or 3 more jump into this room.. the botnet is growing!
#!LPOL! Jessica74 H Peter90@adsl-209-204-181-32.sonic.net :3 Jessica743071
#!LPOL! Claire272 H ~Claire272@80-192-182-73.cable.ubr05.wi.blueyonder.co.uk
#!LPOL! Sophia554 H ~Sophia554@209.195.200.6 :3 Sophia554325
#!LPOL! Chloe9013 H Karolina80@209.202.78.152 :3 Chloe901312
#!LPOL! Sydney542 H Mariah0494@209.191.9.227 :3 Sydney542199
#!LPOL! Elsa12423 H Angelina42@15.shnt4.xdsl.nauticom.net :3 Elsa124230
#!LPOL! Minki7099 H Zoe756815@209.194.190.16 :3 Minki709990
#!LPOL! Makayla57 H Natalie572@209.195.218.54 :3 Makayla574543
#!LPOL! Leslie525 H Svala28188@pppoe-64-91-70-20.rb.lax.centurytel.net :3 Leslie525606
#!LPOL! Autumn319 H Grace99989@AC9F6DA8.ipt.aol.com :3 Autumn319583
#!LPOL! Samantha3 H Autumn9932@host25.brooksml-2.cust.sover.net :3 Samantha394828
#!LPOL! Yamilla15 H Claire4282@host26.brooksml-2.cust.sover.net :3 Yamilla150205
#!LPOL! Grace2018 H Adriana488@8.svnf1.xdsl.nauticom.net :3 Grace201892
#!LPOL! Lujan7794 H Josie11923@a5.c3bed1.client.atlantech.net :3 Lujan779454
#!LPOL! Minki7888 H Victoria72@ep190.ips.PaulBunyan.net :3 Minki788839
#!LPOL! Briana185 H Alyssa5638@209.205.172.43 :3 Briana185975
#!LPOL! Angela274 H Laura15269@host33.brooksml-2.cust.sover.net :3 Angela274842
#!LPOL! Anna79907 H Madeline32@user-101.city.urbana.il.us :3 Anna799072
#!LPOL! Sung42146 H ~Sung42146@216.13.67.57 :3 Sung421466
#!LPOL! Estella68 H Daniela968@209.198.126.76 :3 Estella680044
#!LPOL! Jenna5293 H Adriana023@209.202.78.179 :3 Jenna529394
#!LPOL! Courtney6 H Chloe43907@209.190.200.152 :3 Courtney697581
#!LPOL! Caroline5 H Melissa162@d-191-144-nospr3.i-55.com :3 Caroline527031
#!LPOL! Shannon50 H ~Shannon50@209.201.28.156 :3 Shannon505552
#!LPOL! Beyonce82 H Olivia5920@209.189.232.237 :3 Beyonce828929
#!LPOL! Kelsey198 H Alyssa5678@209.203.75.134 :3 Kelsey198278
#!LPOL! Nicole203 H Julia74311@209.189.250.214 :3 Nicole203361
#!LPOL! Jasmine27 H Andrea3792@dsl-132-ndcr2.i-55.com :3 Jasmine270357
#!LPOL! Niki68912 H Grace06891@9.e1bed1.client.atlantech.net :3 Niki689129
#!LPOL! Bailey427 H ~Bailey427@d3.e8bed1.client.atlantech.net :3 Bailey427581
#!LPOL! Emily9352 H Morena9837@a4.e3bed1.client.atlantech.net :3 Emily935216
#!LPOL! Nicole893 H Isabella19@pc66.cbk.gov.kw :3 Nicole893482
#!LPOL! Hannah294 H ~Hannah294@209.189.244.252 :3 Hannah294622
#!LPOL! Savannah7 H Sierra3410@d-174-51-nospr3.i-55.com :3 Savannah707812
#!LPOL! Marissa29 H ~Marissa29@host210.terransolutions.com :3 Marissa298910
#!LPOL! Marissa89 H Laura07290@www.bdrtransport.com :3 Marissa898535
#!LPOL! Shakira76 H user14@209.202.78.118 :3 Shakira762665
#!LPOL! Jenna8438 H ~Jenna8438@d-173-32-nospr2.i-55.com :3 Jenna843871
#!LPOL! Ashley377 H Faith87547@19.crcr6.xdsl.nauticom.net :3 Ashley377799
#!LPOL! Andrea434 H Elizabeth9@209.202.78.59 :3 Andrea434270
#!LPOL! Jessica49 H Yamilla634@cp209-202-78-157.cp.telus.net :3 Jessica494079
#!LPOL! Caitlin83 H Mackenzie6@5a.e1bed1.client.atlantech.net :3 Caitlin835383
#!LPOL! Denise777 H Molly48369@df.ebbed1.client.atlantech.net :3 Denise777131
#!LPOL! Nicole948 H Aaliyah253@209.183.203.7 :3 Nicole948345
#!LPOL! Haley0390 H Leslie5962@b5.e2bed1.client.atlantech.net :3 Haley039010
#!LPOL! Samantha1 H Lauren9830@209.178.193.220 :3 Samantha151353
#!LPOL! Niki13026 H Kimberly97@a7.c8bed1.client.atlantech.net :3 Niki130268
I hope this isn't off topic.
-Drew
--0-544482457-1060185208=:88640
Content-Type: text/html; charset=us-ascii
<DIV>When looking at IRC and chat networks in general you have to look at them</DIV>
<DIV>from the internet since the attacks are launched from the internet outside</DIV>
<DIV>of any irc. The originators of the attacks use irc as a front to distract the</DIV>
<DIV>investigators effort to find their real points of origin.</DIV>
<DIV> </DIV>
<DIV>In the past I have stated circa 1998 - 2000 time frame, that ISP's that </DIV>
<DIV>fail to address the issue should be held liable for damages sustained</DIV>
<DIV>by other parties that fail to terminate clients for AUP violations, where</DIV>
<DIV>there is conclusive overwhelming proof as to the source of the attack,</DIV>
<DIV>(point of origin).<BR><BR><B><I>Drew Weaver <drew.weaver@thenap.com></I></B> wrote:</DIV>
<DIV>
<BLOCKQUOTE style="PADDING-LEFT: 5px; MARGIN-LEFT: 5px; BORDER-LEFT: #1010ff 2px solid; WIDTH: 100%">
<META content="Microsoft Word 10 (filtered)" name=Generator>
<STYLE>
<!--
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0in;
margin-bottom:.0001pt;
font-size:12.0pt;
font-family:"Times New Roman";}
a:link, span.MsoHyperlink
{color:blue;
text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
{color:purple;
text-decoration:underline;}
span.EmailStyle17
{font-family:Arial;
color:windowtext;}
@page Section1
{size:8.5in 11.0in;
margin:1.0in 1.25in 1.0in 1.25in;}
div.Section1
{page:Section1;}
-->
</STYLE>
<DIV class=Section1>
<P class=MsoNormal><FONT face=Arial size=2><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">I've tried contacting abuse departments of several of these isps and none of them seem to care, so I figured I would post the info here, and maybe someone will let them know, the biggest offender is atlantech. These are all hosts that have been compromised by the same person, they're being used to SYN flood 65.110.34.100</SPAN></FONT></P>
<P class=MsoNormal><FONT face=Arial size=2><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"></SPAN></FONT> </P>
<P class=MsoNormal><FONT face=Arial size=2><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">If you want to see this glorious channel for your self its called #!LPOL! on Undernet.</SPAN></FONT></P>
<P class=MsoNormal><FONT face=Arial size=2><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"></SPAN></FONT> </P>
<P class=MsoNormal><FONT face=Arial size=2><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">Basically the way this works is your box gets attacked, then it sits on this irc channel and waits for commands, in this case the command is !SYN 65.110.34 1000 6667 9999 -s</SPAN></FONT></P>
<P class=MsoNormal><FONT face=Arial size=2><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"></SPAN></FONT> </P>
<P class=MsoNormal><FONT face=Arial size=2><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">Anyways here is the list, and every 30 seconds or so 2 or 3 more jump into this room.. the botnet is growing!</SPAN></FONT></P>
<P class=MsoNormal><FONT face=Arial size=2><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"></SPAN></FONT> </P>
<P class=MsoNormal><FONT face=Arial size=2><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">#!LPOL! Jessica74 H Peter90@adsl-209-204-181-32.sonic.net :3 Jessica743071</SPAN></FONT></P>
<P class=MsoNormal><FONT face=Arial size=2><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">#!LPOL! Claire272 H ~Claire272@80-192-182-73.cable.ubr05.wi.blueyonder.co.uk</SPAN></FONT></P>
<P class=MsoNormal><FONT face=Arial size=2><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">#!LPOL! Sophia554 H ~Sophia554@209.195.200.6 :3 Sophia554325</SPAN></FONT></P>
<P class=MsoNormal><FONT face=Arial size=2><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">#!LPOL! Chloe9013 H Karolina80@209.202.78.152 :3 Chloe901312</SPAN></FONT></P>
<P class=MsoNormal><FONT face=Arial size=2><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">#!LPOL! Sydney542 H Mariah0494@209.191.9.227 :3 Sydney542199</SPAN></FONT></P>
<P class=MsoNormal><FONT face=Arial size=2><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">#!LPOL! Elsa12423 H Angelina42@15.shnt4.xdsl.nauticom.net :3 Elsa124230</SPAN></FONT></P>
<P class=MsoNormal><FONT face=Arial size=2><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">#!LPOL! Minki7099 H Zoe756815@209.194.190.16 :3 Minki709990</SPAN></FONT></P>
<P class=MsoNormal><FONT face=Arial size=2><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">#!LPOL! Makayla57 H Natalie572@209.195.218.54 :3 Makayla574543</SPAN></FONT></P>
<P class=MsoNormal><FONT face=Arial size=2><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">#!LPOL! Leslie525 H Svala28188@pppoe-64-91-70-20.rb.lax.centurytel.net :3 Leslie525606</SPAN></FONT></P>
<P class=MsoNormal><FONT face=Arial size=2><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">#!LPOL! Autumn319 H Grace99989@AC9F6DA8.ipt.aol.com :3 Autumn319583</SPAN></FONT></P>
<P class=MsoNormal><FONT face=Arial size=2><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">#!LPOL! Samantha3 H Autumn9932@host25.brooksml-2.cust.sover.net :3 Samantha394828</SPAN></FONT></P>
<P class=MsoNormal><FONT face=Arial size=2><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">#!LPOL! Yamilla15 H Claire4282@host26.brooksml-2.cust.sover.net :3 Yamilla150205</SPAN></FONT></P>
<P class=MsoNormal><FONT face=Arial size=2><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">#!LPOL! Grace2018 H Adriana488@8.svnf1.xdsl.nauticom.net :3 Grace201892</SPAN></FONT></P>
<P class=MsoNormal><FONT face=Arial size=2><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">#!LPOL! Lujan7794 H Josie11923@a5.c3bed1.client.atlantech.net :3 Lujan779454</SPAN></FONT></P>
<P class=MsoNormal><FONT face=Arial size=2><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">#!LPOL! Minki7888 H Victoria72@ep190.ips.PaulBunyan.net :3 Minki788839</SPAN></FONT></P>
<P class=MsoNormal><FONT face=Arial size=2><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">#!LPOL! Briana185 H Alyssa5638@209.205.172.43 :3 Briana185975</SPAN></FONT></P>
<P class=MsoNormal><FONT face=Arial size=2><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">#!LPOL! Angela274 H Laura15269@host33.brooksml-2.cust.sover.net :3 Angela274842</SPAN></FONT></P>
<P class=MsoNormal><FONT face=Arial size=2><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">#!LPOL! Anna79907 H Madeline32@user-101.city.urbana.il.us :3 Anna799072</SPAN></FONT></P>
<P class=MsoNormal><FONT face=Arial size=2><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">#!LPOL! Sung42146 H ~Sung42146@216.13.67.57 :3 Sung421466</SPAN></FONT></P>
<P class=MsoNormal><FONT face=Arial size=2><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">#!LPOL! Estella68 H Daniela968@209.198.126.76 :3 Estella680044</SPAN></FONT></P>
<P class=MsoNormal><FONT face=Arial size=2><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">#!LPOL! Jenna5293 H Adriana023@209.202.78.179 :3 Jenna529394</SPAN></FONT></P>
<P class=MsoNormal><FONT face=Arial size=2><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">#!LPOL! Courtney6 H Chloe43907@209.190.200.152 :3 Courtney697581</SPAN></FONT></P>
<P class=MsoNormal><FONT face=Arial size=2><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">#!LPOL! Caroline5 H Melissa162@d-191-144-nospr3.i-55.com :3 Caroline527031</SPAN></FONT></P>
<P class=MsoNormal><FONT face=Arial size=2><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">#!LPOL! Shannon50 H ~Shannon50@209.201.28.156 :3 Shannon505552</SPAN></FONT></P>
<P class=MsoNormal><FONT face=Arial size=2><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">#!LPOL! Beyonce82 H Olivia5920@209.189.232.237 :3 Beyonce828929</SPAN></FONT></P>
<P class=MsoNormal><FONT face=Arial size=2><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">#!LPOL! Kelsey198 H Alyssa5678@209.203.75.134 :3 Kelsey198278</SPAN></FONT></P>
<P class=MsoNormal><FONT face=Arial size=2><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">#!LPOL! Nicole203 H Julia74311@209.189.250.214 :3 Nicole203361</SPAN></FONT></P>
<P class=MsoNormal><FONT face=Arial size=2><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">#!LPOL! Jasmine27 H Andrea3792@dsl-132-ndcr2.i-55.com :3 Jasmine270357</SPAN></FONT></P>
<P class=MsoNormal><FONT face=Arial size=2><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">#!LPOL! Niki68912 H Grace06891@9.e1bed1.client.atlantech.net :3 Niki689129</SPAN></FONT></P>
<P class=MsoNormal><FONT face=Arial size=2><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">#!LPOL! Bailey427 H ~Bailey427@d3.e8bed1.client.atlantech.net :3 Bailey427581</SPAN></FONT></P>
<P class=MsoNormal><FONT face=Arial size=2><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">#!LPOL! Emily9352 H Morena9837@a4.e3bed1.client.atlantech.net :3 Emily935216</SPAN></FONT></P>
<P class=MsoNormal><FONT face=Arial size=2><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">#!LPOL! Nicole893 H Isabella19@pc66.cbk.gov.kw :3 Nicole893482</SPAN></FONT></P>
<P class=MsoNormal><FONT face=Arial size=2><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">#!LPOL! Hannah294 H ~Hannah294@209.189.244.252 :3 Hannah294622</SPAN></FONT></P>
<P class=MsoNormal><FONT face=Arial size=2><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">#!LPOL! Savannah7 H Sierra3410@d-174-51-nospr3.i-55.com :3 Savannah707812</SPAN></FONT></P>
<P class=MsoNormal><FONT face=Arial size=2><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">#!LPOL! Marissa29 H ~Marissa29@host210.terransolutions.com :3 Marissa298910</SPAN></FONT></P>
<P class=MsoNormal><FONT face=Arial size=2><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">#!LPOL! Marissa89 H Laura07290@www.bdrtransport.com :3 Marissa898535</SPAN></FONT></P>
<P class=MsoNormal><FONT face=Arial size=2><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">#!LPOL! Shakira76 H user14@209.202.78.118 :3 Shakira762665</SPAN></FONT></P>
<P class=MsoNormal><FONT face=Arial size=2><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">#!LPOL! Jenna8438 H ~Jenna8438@d-173-32-nospr2.i-55.com :3 Jenna843871</SPAN></FONT></P>
<P class=MsoNormal><FONT face=Arial size=2><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">#!LPOL! Ashley377 H Faith87547@19.crcr6.xdsl.nauticom.net :3 Ashley377799</SPAN></FONT></P>
<P class=MsoNormal><FONT face=Arial size=2><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">#!LPOL! Andrea434 H Elizabeth9@209.202.78.59 :3 Andrea434270</SPAN></FONT></P>
<P class=MsoNormal><FONT face=Arial size=2><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">#!LPOL! Jessica49 H Yamilla634@cp209-202-78-157.cp.telus.net :3 Jessica494079</SPAN></FONT></P>
<P class=MsoNormal><FONT face=Arial size=2><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">#!LPOL! Caitlin83 H Mackenzie6@5a.e1bed1.client.atlantech.net :3 Caitlin835383</SPAN></FONT></P>
<P class=MsoNormal><FONT face=Arial size=2><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">#!LPOL! Denise777 H Molly48369@df.ebbed1.client.atlantech.net :3 Denise777131</SPAN></FONT></P>
<P class=MsoNormal><FONT face=Arial size=2><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">#!LPOL! Nicole948 H Aaliyah253@209.183.203.7 :3 Nicole948345</SPAN></FONT></P>
<P class=MsoNormal><FONT face=Arial size=2><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">#!LPOL! Haley0390 H Leslie5962@b5.e2bed1.client.atlantech.net :3 Haley039010</SPAN></FONT></P>
<P class=MsoNormal><FONT face=Arial size=2><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">#!LPOL! Samantha1 H Lauren9830@209.178.193.220 :3 Samantha151353</SPAN></FONT></P>
<P class=MsoNormal><FONT face=Arial size=2><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">#!LPOL! Niki13026 H Kimberly97@a7.c8bed1.client.atlantech.net :3 Niki130268</SPAN></FONT></P>
<P class=MsoNormal><FONT face=Arial size=2><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"></SPAN></FONT> </P>
<P class=MsoNormal><FONT face=Arial size=2><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">I hope this isn't off topic.</SPAN></FONT></P>
<P class=MsoNormal><FONT face=Arial size=2><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"></SPAN></FONT> </P>
<P class=MsoNormal><FONT face=Arial size=2><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">-Drew</SPAN></FONT></P>
<P class=MsoNormal><FONT face=Arial size=2><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"></SPAN></FONT> </P></DIV></BLOCKQUOTE></DIV>
--0-544482457-1060185208=:88640--