On 11.03.13 15:24, Daniel Stirnimann wrote:

> Has anyone an idea what the source of this traffic pattern is? It's also
> interesting to note that quite a lot of 2nd-level queries result in
> NXDOMAIN responses.

Someone responded offlist to me. It's one of the messaging bots which is
causing this traffic which has a broken resolver.

McAfee Labs recently posted a nice summary of the messaging botnets:
http://blogs.mcafee.com/mcafee-labs/an-overview-of-messaging-botnets

Thanks,
Daniel
_______________________________________________
dns-operations mailing list
[email protected]
https://lists.dns-oarc.net/mailman/listinfo/dns-operations
dns-jobs mailing list
https://lists.dns-oarc.net/mailman/listinfo/dns-jobs

Reply via email to