You are viewing a single comment's thread.

view the rest of the comments →

bolus ago

Can you share the evidence?

Archive of the /24 registry, for example, goes to Delaware. Hidden by cachenet:

http://archive.is/OIgtQ

And the arin registration for the ip of the last hop off a tracert to them shows "trans-media" and passes through an att-cable address :

104-160-16-2.cable.attcabletv.com

http://archive.is/kSwyC

Which isn't telling of anything in particular, but i wouldn't expect dyncorp to run out of an apparent consumer-grade connection.

Still looking, though, this is interesting stuff.

Ha!

And the geo location of the last hop before your attackers subnet is in Dublin.

Funny business.

RebelSkum ago

Working on it currently. Got logs and everything, but I don't want to publish any information on legitimate users so I have to edit them out. I believe we're up to 7 different IPs attempting shenanigans, though.