Re: Russian Anal Probing + Malware

2019-06-22 Thread Ronald F. Guilmette
In message , "Keith Medcalf" wrote: >On Friday, 21 June, 2019 18:14, Ronald F. Guilmette com> wrote: > >>https://twitter.com/GreyNoiseIO/status/1129017971135995904 >>https://twitter.com/JayTHL/status/1128718224965685248 > >Sorry, don't twitter ... Too much malicious JavaScript there.

Re: Russian Anal Probing + Malware

2019-06-22 Thread Andy Smith
Hello, On Sat, Jun 22, 2019 at 11:01:13AM -0600, Keith Medcalf wrote: > What malware slinging? Some user there is trying to exploit CVE-2018-10149: 2019-06-11 11:28:35 SMTP protocol synchronization error (next input sent too soon: pipelining was not advertised): rejected "RCPT TO:"

Re: Russian Anal Probing + Malware

2019-06-22 Thread Filip Hruska
On 6/22/19 2:13 AM, Ronald F. Guilmette wrote: https://twitter.com/GreyNoiseIO/status/1129017971135995904 https://twitter.com/JayTHL/status/1128718224965685248 Friday Questionaire: Is there anybody on this list who keeps firewall logs and who DOESN'T have numerous hits recorded

Re: Russian Anal Probing + Malware

2019-06-22 Thread Troy Mursch
AS202425 = AS29073. Formerly known as Quasi Networks / Ecatel. See previous NANOG thread here: https://mailman.nanog.org/pipermail/nanog/2017-August/091956.html On Sat, Jun 22, 2019 at 10:03 AM Keith Medcalf wrote: > On Friday, 21 June, 2019 18:14, Ronald F. Guilmette > wrote: > > >

RE: Russian Anal Probing + Malware

2019-06-22 Thread Keith Medcalf
On Friday, 21 June, 2019 18:14, Ronald F. Guilmette wrote: >https://twitter.com/GreyNoiseIO/status/1129017971135995904 >https://twitter.com/JayTHL/status/1128718224965685248 Sorry, don't twitter ... Too much malicious JavaScript there. >Friday Questionaire: >Is there anybody on this