|
Dave, I've noticed that on my box with only about 60 domains, there's several distributed dictionary attacks every day. They seem to be controlled from a central location because the order is roughly the same across the different IP addresses they use. Mine have been spaced out and fairly low in volume, and I've seen them do this to domains with only one account. These attacks use mostly real names, although the Joe-Jobs using our domains and directed at large ISP's seemingly use more of a hacking sort of attack, trying every combination and lasting for weeks at times. I've found that many of these attacks originate from North Korea and China, and there's a good chance that there's someone on this side of the Ocean that is typing in the commands. #1 ROKSO spammer Alan Ralsky seems to be Asia's largest spam customer, and he enables a lot of this stuff. I wouldn't be surprised if someone connected to him was responsible for the viruses that have been used to create spam zombies. He certainly profits from the use of these machines. This is also the guy that has involvement in the recent Habeas spoofing for that drug site (the payload was hosted on his IP space in China). This stuff either comes from zombies controlled by IP's in unfriendly countries, or it comes from unfriendly countries. Good luck serving a warrant. It might be a better idea to look at the payloads and figure out what the connections are. SBL probably tracks much of that stuff if you simply resolve the domain name to an IP address and look for patterns. BTW, was this a large domain that's being attacked, or do these guys just simply stupid abusive idiots (as opposed to smart abusive idiots I guess)? Matt Dave Doherty wrote:
-- ===================================================== MailPure custom filters for Declude JunkMail Pro. http://www.mailpure.com/software/ ===================================================== |
- [Declude.JunkMail] Mailfrom? Kami Razvan
- Re: [Declude.JunkMail] Mailfrom? R. Scott Perry
- RE: [Declude.JunkMail] Mailfrom? Kami Razvan
- Re[2]: [Declude.JunkMail] Mailfrom? Sanford Whiteman
- Re: [Declude.JunkMail] Mailfrom? Matt
- [Declude.JunkMail] Distributed Dictionar... Dave Doherty
- Re: [Declude.JunkMail] Distributed ... Matt
- Re: [Declude.JunkMail] Distributed ... R. Scott Perry
- Re: [Declude.JunkMail] Distribu... Matt
- Re: [Declude.JunkMail] Dist... Dave Doherty
- RE: [Declude.JunkMail] Dist... Jason
- Re: [Declude.JunkMail] Dist... Matt
- [Declude.JunkMail] IPNOTINM... Robert Shubert
- Re: [Declude.JunkMail] IPNO... Matt
- Re: [Declude.JunkMail] IPNO... Dan Geiser
- Re: [Declude.JunkMail] Dist... Dave Doherty
- Re[2]: [Declude.JunkMail] D... Sanford Whiteman
