Quoting Rebecca Kaiser abuse@wholesaleinternet.net:
Thanks, Rebecca
I see no further malicious activity from DataShack and Wholesale Internet. Still ongoing attack from Limestone and Ubiquity/Nobistech and a few other US ISP's, and of course malicious traffic from IP addresses from one specific foreign country.
Any explanation from your foreign customers as to why they are engaging in what appears to be illegal activity, at least as far as US laws apply?
- Kent
We've received confirmation from our client that this has been shut down.
From: Kent Backman [mailto:kent@kentbackman.com] Sent: Tuesday, March 26, 2013 8:08 PM To: abuse@rr.com Cc: abuse@nobistech.net; security@datashack.net; noc@psychz.net; abuse@limestonenetworks.com; abuse@wholesaleinternet.net; abuse@he.net Subject: ongoing denial of service attack against Road Runner IP address 98.150.237.177 by botnet operating out of Nobistech, Datashack, Limestone, HE, Pegtech, WholeSale Interent, and Psychz VPS nodes Importance: High
Correction, I am still showing these guys:
IP Address ISP Organization 142.54.182.5 DataShack, LC Zhou Pizhong 142.54.181.36 DataShack, LC EVL Gaming, LLC. 142.54.181.41 DataShack, LC EVL Gaming, LLC. 142.54.181.39 DataShack, LC EVL Gaming, LLC. 142.54.181.38 DataShack, LC EVL Gaming, LLC. 142.54.182.57 DataShack, LC Zhou Pizhong 142.54.182.54 DataShack, LC Zhou Pizhong 142.54.182.9 DataShack, LC Zhou Pizhong 142.54.182.8 DataShack, LC Zhou Pizhong 142.54.181.37 DataShack, LC EVL Gaming, LLC. 142.54.182.6 DataShack, LC Zhou Pizhong 142.54.182.10 DataShack, LC Zhou Pizhong 142.54.182.53 DataShack, LC Zhou Pizhong 142.54.182.4 DataShack, LC Zhou Pizhong 142.54.182.58 DataShack, LC Zhou Pizhong 142.54.182.7 DataShack, LC Zhou Pizhong 142.54.182.56 DataShack, LC Zhou Pizhong 142.54.182.55 DataShack, LC Zhou Pizhong
Quoting Kent Backman kent@kentbackman.com:
Quoting Rebecca Kaiser abuse@wholesaleinternet.net:
Thanks, Rebecca
I see no further malicious activity from DataShack and Wholesale Internet. Still ongoing attack from Limestone and Ubiquity/Nobistech and a few other US ISP's, and of course malicious traffic from IP addresses from one specific foreign country.
Any explanation from your foreign customers as to why they are engaging in what appears to be illegal activity, at least as far as US laws apply?
- Kent
We've received confirmation from our client that this has been shut down.
From: Kent Backman [mailto:kent@kentbackman.com] Sent: Tuesday, March 26, 2013 8:08 PM To: abuse@rr.com Cc: abuse@nobistech.net; security@datashack.net; noc@psychz.net; abuse@limestonenetworks.com; abuse@wholesaleinternet.net; abuse@he.net Subject: ongoing denial of service attack against Road Runner IP address 98.150.237.177 by botnet operating out of Nobistech, Datashack, Limestone, HE, Pegtech, WholeSale Interent, and Psychz VPS nodes Importance: High
My bridge relay often shows regular pulses in its bandwidth graph, as per the attached. Do these represent some housekeeping on the network? - eliaz
tor-relays@lists.torproject.org