person: Igor Gilmutdinov
address: Malkova, 12
address: 614087
address: Perm
address: RUSSIAN FEDERATION
phone: +73422000289
nic-hdl: IG2940-RIPE
mnt-by: ru-permtelecom-1-mnt
created: 2016-04-01T13:54:40Z
last-modified: 2016-04-01T13:54:40Z
source: RIPE
% Information related to '92.51.2.0/24AS209588'
route: 92.51.2.0/24
origin: AS209588
mnt-by: ru-permtelecom-1-mnt
created: 2023-05-12T12:04:13Z
last-modified: 2023-05-12T12:04:13Z
source: RIPE
On 7/11/24 20:04, Randolf Richardson 張文道 wrote:
...
person: Igor Gilmutdinov
address: Malkova, 12
address: 614087
address: Perm
address: RUSSIAN FEDERATION
phone: +73422000289
nic-hdl: IG2940-RIPE
mnt-by: ru-permtelecom-1-mnt
created: 2016-04-01T13:54:40Z
last-modified: 2016-04-01T13:54:40Z
source: RIPE
% Information related to '92.51.2.0/24AS209588'
route: 92.51.2.0/24
origin: AS209588
mnt-by: ru-permtelecom-1-mnt
created: 2023-05-12T12:04:13Z
last-modified: 2023-05-12T12:04:13Z
source: RIPE
Reporting to NATO?
On 7/11/24 20:04, Randolf Richardson 張文道 wrote:
...
person: Igor Gilmutdinov
address: Malkova, 12
address: 614087
address: Perm
address: RUSSIAN FEDERATION
phone: +73422000289
nic-hdl: IG2940-RIPE
mnt-by: ru-permtelecom-1-mnt
created: 2016-04-01T13:54:40Z
last-modified: 2016-04-01T13:54:40Z
source: RIPE
% Information related to '92.51.2.0/24AS209588'
route: 92.51.2.0/24
origin: AS209588
mnt-by: ru-permtelecom-1-mnt
created: 2023-05-12T12:04:13Z
last-modified: 2023-05-12T12:04:13Z
source: RIPE
Reporting to NATO?
I'm wondering, has anyone encountered attacks from
any other IP addresses in this /24? I'm not finding
anything aside from 95.51.2.78 in our logs.
On fre, 2024/07/12 at 05:35:57 +0200, tjoen wrote:
On 7/11/24 20:04, Randolf Richardson ??? wrote:
...
I am sure NATO is well aware. This is part of Russia's "Hybrid Warfare".
Do what you can to stay patched and secure. Aside from that, not a whole
lot we can do. Until their leadership changes, this will be happening with >increasing intensity.
Domain trudheim.com[end quoted excerpt]
Registrar Ascio Technologies, Inc
Registered On 2003-02-04T00:00:00Z
Expires On 2027-02-04T16:57:21Z
Updated On 2024-05-26T09:58:22Z
Status OK https://icann.org/epp#ok
Name Servers ds723.trudheim.com
ns1.loopia.se
ns2.loopia.se
# Copyright (c) 1997- The Swedish Internet Foundation.
On 11.07.2024 um 11:04 Uhr Randolf Richardson 張文道 wrote:
I'm wondering, has anyone encountered attacks from
any other IP addresses in this /24? I'm not finding
anything aside from 95.51.2.78 in our logs.
I assume this is just a hacked machine that is being part of a botnet.
It isn't even listed on uceprotect, spamhaus nor blocklist, so the
amount of attacks to a wide range of addresses isn't that much.
fail2ban should handle that.
Sysop: | Keyop |
---|---|
Location: | Huddersfield, West Yorkshire, UK |
Users: | 463 |
Nodes: | 16 (2 / 14) |
Uptime: | 141:55:39 |
Calls: | 9,381 |
Calls today: | 1 |
Files: | 13,558 |
Messages: | 6,094,751 |