#1257 closed request (wontfix)

Your server 31.133.188.165 has been registered as an attack source

Reported by: (none) Owned by: llynch@…
Priority: tbd Milestone: ietf-103
Component: incoming Keywords:
Cc: My Current Location:
My MAC Address: My OS:

Description

Dear Provider,


I’m George Egri, the Co-Founder and CEO of BitNinja Server Security. I’m writing to inform you that we have detected malicious requests from the IP 31.133.188.165 directed at our clients’ servers.


As a result of these attacks, we have added your IP to our greylist to prevent it from attacking our clients’ servers.


Servers are increasingly exposed as the targets of botnet attacks and you might not be aware that your server is being used as a “bot” to send malicious attacks over the Internet.


I've collected the 3 earliest logs below, and you can find the freshest 100, that may help you disinfect your server, under the link.
http://bitninja.io/incidentReport.php?details=0b16a1a44c2b1f02f2?utm_source=incident&utm_content=publicpage. The timezone is UTC +1:00.

<pre style='padding:10px 20px; background:#e6e6e6;margin-bottom:10px'>{
    "PORT HIT": "31.133.188.165:49298-&gt;69.175.109.50:23"
}</pre><pre style='padding:10px 20px; background:#e6e6e6;margin-bottom:10px'>{
    "PORT HIT": "31.133.188.165:54046-&gt;199.168.186.10:23"
}</pre><pre style='padding:10px 20px; background:#e6e6e6;margin-bottom:10px'>{
    "PORT HIT": "31.133.188.165:54077-&gt;199.168.186.10:23"
}</pre>

Please keep in mind that after the first intrusion we log all traffic between your server and the BitNinja-protected servers until the IP is removed from the greylist. This means you may see valid logs beside the malicious actions in the link above. If you need help finding the malicious logs, please don’t hesitate to contact our incident experts by replying to this e-mail.

For more information on analyzing and understanding outbound traffic, check out this:
https://doc.bitninja.io/_images/bitninja-incident-report-1.jpg?utm_source=incident&utm_campaign=investigation&utm_content=image

We’ve also dedicated an entire site help people prevent their server from sending malicious attacks: 
https://doc.bitninja.io/investigations.html?utm_source=incident&utm_campaign=investigation&utm_content=documentation


Thank you for helping us make the Internet a safer place!


Regards,


George Egri
CEO at BitNinja.io

BitNinja.io @ BusinessInsider UK

BitNinja.io hits the WHIR.com
BitNinja @ CodeMash conference

Added by email2trac

Added by email2trac

Attachments (2)

logo.png (4.8 KB) - added by incident-report@… 13 months ago.
Added by email2trac
partners.png (36.9 KB) - added by incident-report@… 13 months ago.
Added by email2trac

Download all attachments as: .zip

Change history (5)

Changed 13 months ago by incident-report@…

Attachment: logo.png added

Added by email2trac

Changed 13 months ago by incident-report@…

Attachment: partners.png added

Added by email2trac

comment:1 Changed 13 months ago by llynch@…

Owner: changed from < default > to jim@…
Status: newassigned

comment:2 Changed 12 months ago by llynch@…

Owner: changed from jim@… to llynch@…
Reporter: incident-report@… deleted

comment:3 Changed 12 months ago by llynch@…

Resolution: wontfix
Status: assignedclosed
Note: See TracTickets for help on using tickets.