mailing list archives
From: Jeroen van Aart <jeroen () mompl net>
Date: Fri, 31 Aug 2012 11:38:30 -0700
The below email exchange may be of interest to some of you. The
practical upshot is that it appears "the 126.96.36.199/22 range was
hijacked and should be included into the DROP list".
As an interesting aside, quoting a friend:
"the original company (that performed dangerous waste utilization) may
have been a shady thing in and of itself (..) what most companies
calling themselves "ecoservice" (with variations) do is take money for
"safe utilisation" of hazardous waste, and then dump it in some old
quarry out in the remote (or not so remote) corner of a forest or other
natural area (..) they always have criminal links and protection from
corrupts officials (often co-owners) and security/law enforcement services"
From: Jeroen van Aart
nothing but crap coming from 188.8.131.52/24. Amongst other things
attempts to spam (through) wordpress sites.
inetnum: 184.108.40.206 - 220.127.116.11
descr: DonEkoService Ltd
Don - name of the nearby large river.
"EkoService" means ecological service.
person: Haralevich Piotr
address: novocherkassk, ul stremyannaya d.6
changed: admin () donecoserv ru 20101117
The company performed dangerous waste utilization:
But domains donecoserv.ru and donekoservis.ru don't exist anymore.
11 router02.spbbm18.ru.edpnet.net (18.104.22.168) 65.979 ms 65.971 ms
12 22.214.171.124.static.edpnet.net (126.96.36.199) 88.868 ms 47.809 ms
13 188.8.131.52 (184.108.40.206) 48.235 ms 48.546 ms 48.664 ms
14 ajursrv.parohod.biz (220.127.116.11) 47.957 ms 47.752 ms 47.606 ms
15 mail.rx-helps.com (18.104.22.168) 48.206 ms 48.302 ms 48.237 ms
SPb (Sankt-Peterburg) is 1500 km from Novocherkassk.
parohod.biz also is in Sankt-Peterburg, they offer SEO (which I consider
spamming websites and search engines).
http://support.clean-mx.de/clean-mx/viruses.php?email=admin () donecoserv ru&response=
| January 3, 2011
| inetnum: 22.214.171.124 126.96.36.199
| netname: Donekoserv
| descr: DonEkoService Ltd
| country: RU
| org: ORG-DS41-RIPE
| organisation: ORG-DS41-RIPE
| org-name: DonEko Service
| org-type: OTHER
| address: novocherkassk, ul stremyannaya d.6
| e-mail: admin () bulletproof-web com
Therefore, the 188.8.131.52/22 range was hijacked
and should be included into the DROP list.
- 184.108.40.206/22 hijacked? Jeroen van Aart (Aug 31)