Showing posts with label Abuse. Show all posts
Showing posts with label Abuse. Show all posts

Thursday, August 27, 2015

CONFIRMED BREACHED: August Benefits Inc - Attack on SLC Security

The following host have been detected as being potentially breached based on data from SLC Security owned and operated sensors. We have decided that we would start publishing a daily list to help these organizations get their network under control. While we believe these host to be breached they may also be involved in hacking attempts on other entities or may be used by hackers as a jump point to conduct other attacks. The following list are the bad entities for the last 24 hours. Our volunteers have detected the following attackers:

Our Security Operations Center has detected a US company attempting to hack into our network. We believe this host to be compromised and have sent a notification to August Benefits to alert them of the situation.

173.220.57.150 - Observed in Attacks

Monday, August 10, 2015

Recent Attackers

Seems these attackers would like to be blocked on 400+ corporations networks.

Domain,IP,Subnet,"MX Hostname","MX IP",DNS,"IP ISP","ISP City","ISP Region","ISP Country","IP Organization","Org City","Org Region","Org Country"
125.ip-92-222-221.eu,92.222.221.125,92.222.221.0,-,,-,"OVH SAS",france,Unknown,FR,"OVH SAS",france,Unknown,FR
freelive.arvixevps.com,198.58.95.13,198.58.95.0,-,,-,"Arvixe, LLC","Santa Rosa",CA,US,"Arvixe, LLC","Santa Rosa",CA,US
101.212.67.21,101.212.67.21,101.212.67.0,-,,-,Unknown,gurgaon,Unknown,IN,AIRCEL-Kolakta-MobileBroadband-Customer,gurgaon,Unknown,IN
nairobi.pollmans.co.ke,196.207.30.180,196.207.30.0,smtpin.accesskenya.com.,127.255.255.255,-,"African Network Information Center",Ebene,Unknown,MU,NET-196-207-30-180,Unknown,Unknown,KE
89.121.207.234,89.121.207.234,89.121.207.0,-,,-,Unknown,vitan,Unknown,RO,"Romtelecom Data Network",vitan,Unknown,RO
199.58.185.178,199.58.185.178,199.58.185.0,-,,-,"Total Server Solutions L.L.C.",Atlanta,GA,US,"Total Server Solutions L.L.C.",Atlanta,GA,US
193.0.200.135,193.0.200.135,193.0.200.0,-,,-,Unknown,moscow,Unknown,RU,"MediaServicePlus Ltd",moscow,Unknown,RU
193.0.200.134,193.0.200.134,193.0.200.0,-,,-,Unknown,moscow,Unknown,RU,"MediaServicePlus Ltd",moscow,Unknown,RU
asco-78-120.dns-iol.com,195.200.78.120,195.200.78.0,-,,-,"INFORMATIQUE ON LINE SARL",france,Unknown,FR,"INFORMATIQUE ON LINE SARL",france,Unknown,FR
101.212.72.107,101.212.72.107,101.212.72.0,-,,-,Unknown,gurgaon,Unknown,IN,AIRCEL-Kolakta-MobileBroadband-Customer,gurgaon,Unknown,IN
185.40.4.32,185.40.4.32,185.40.4.0,-,,-,Hostgrad,ivanovo,Unknown,RU,Hostgrad,ivanovo,Unknown,RU
118.98.75.78,118.98.75.78,118.98.75.0,-,,-,"PT TELKOM INDONESIA",Unknown,Unknown,ID,"PT TELKOM INDONESIA",Unknown,Unknown,ID
190.144.93.54,190.144.93.54,190.144.93.0,-,,-,Unknown,bogota,Unknown,CO,"Telmex Colombia S.A.",bogota,Unknown,CO
50-193-219-125-static.hfc.comcastbusiness.net,50.193.219.125,50.193.219.0,-,,-,"Comcast Cable Communications Holdings, Inc","Mt Laurel",NJ,US,"Comcast Cable Communications Holdings, Inc","Mt Laurel",NJ,US
23.238.235.108,23.238.235.108,23.238.235.0,-,,-,"Psychz Networks",Walnut,CA,US,"Psychz Networks",Walnut,CA,US
ip-97-74-114-49.ip.secureserver.net,97.74.114.49,97.74.114.0,-,,-,"GoDaddy.com, LLC",Scottsdale,AZ,US,"GoDaddy.com, LLC",Scottsdale,AZ,US
cri8.ro,80.97.51.238,80.97.51.0,mx2.zohomail.com.,74.201.154.201,ns1.cri8.ro.,"SC Full Duplex SRL",lacul,Unknown,RO,"SC Full Duplex SRL",lacul,Unknown,RO
ns3006932.ip-151-80-35.eu,151.80.35.207,151.80.35.0,-,,-,"RIPE Network Coordination Centre",Amsterdam,Unknown,NL,"OVH SAS",france,Unknown,FR
124.2.53.233,124.2.53.233,124.2.53.0,-,,-,Unknown,seoul,Unknown,KR,"SK Networks co., Ltd",seoul,Unknown,KR
76.66.232.19,76.66.232.19,76.66.232.0,-,,-,"Bell Canada",Ottawa,ON,CA,"Medix School",Scarborough,ON,CA
201.137.62.171,201.137.62.171,201.137.62.0,-,,-,"Gesti?n de direccionamiento UniNet",mexico,Unknown,MX,"Gesti?n de direccionamiento UniNet",mexico,Unknown,MX
180.250.214.34,180.250.214.34,180.250.214.0,-,,-,Unknown,jakarta,Unknown,ID,"PT TELKOM INDONESIA",jakarta,Unknown,ID
75.126.79.105-static.reverse.softlayer.com,75.126.79.105,75.126.79.0,-,,-,"SoftLayer Technologies Inc.",Dallas,TX,US,"SoftLayer Technologies Inc.",Dallas,TX,US
119.94.3.26,119.94.3.26,119.94.3.0,-,,-,PLDT_JNEHUBS002_DHCP,makati,Unknown,PH,PLDT_JNEHUBS002_DHCP,makati,Unknown,PH
ns3007688.ip-151-80-97.eu,151.80.97.75,151.80.97.0,-,,-,"RIPE Network Coordination Centre",Amsterdam,Unknown,NL,"OVH SAS",france,Unknown,FR

Saturday, April 25, 2015

Malicious Activity: Harvard University

On 4/25/2015 SLC Security Services LLC has notified Harvard of a security issue with some host on their network. We will advise if we receive any response concerning the issue.


Tuesday, April 21, 2015

ALERT: 43.255.0.0/16 Netblock Extremely Active and Noisy

We wanted to put out an alert that many of our sensors and clients are reporting inbound SMTP infected dyzera and ssh scanning. What's interesting is that the actors appears to not care how noisy they are. We highly recommend blocking the entire /16 netblock.

Thursday, November 20, 2014

BOTNET Wall of Shame 11-20-2014

11-20-2014,50.193.61.78,Comcast Cable Communications Holdings, Inc
11-20-2014,54.68.211.27,Amazon Technologies Inc.
11-20-2014,67.222.114.236,Transwave Communications Systems, Inc.
11-20-2014,72.182.33.119,Time Warner Cable Internet LLC
11-20-2014,98.223.50.225,Comcast Cable Communications, Inc.

Monday, November 17, 2014

BOTNET Wall of Shame

11-17-2014,71.43.89.74,Time Warner Cable Internet LLC
11-17-2014,70.154.153.120,BellSouth.net Inc.

Sunday, November 16, 2014

SLC Security Services LLC OSINT system attacked by botnet

We want to send out personal thank you to the operators of this particular botnet for allowing us the opportunity to map out all the host that were part of your campaign. You see it takes us a long time to find compromised host so we can protect our clients but this type of activity makes it easy for us to collect our intelligence.

In addition it was very nice of you to identify one of our customers issues for us. Security is not 100% but we definitely appreciate the help. Starting at 9:00PM EST on 11-15-2014 we started seeing an influx in the number of failed logins to several of our systems. Within minutes our mining operation had collected over 7000 node endpoint IP addresses and added them to our paid blacklist product. Over the next 3 hours over 100 organizations that have purchased or operate our devices and software were updated with some great intelligence information that will now allow them to protect themselves.

Thanks guys... The whole purpose of open source is to collect this type of information so you actually gave us a great amount of data that is invaluable to our organization. Have a great week!

No systems were compromised and the attackers were blacklisted after the third attempt to login. Also it's funny seeing usernames come in during our two factor authentication process. This helps us to collect the data more easily as it was logged. This was truly awesome! 

Monday, November 3, 2014

Today's Naughty List - 3 Nov 2014


50.74.234.66   United States (USA)   New York New York  
  81.137.204.83   United Kingdom (GBR)   n/a n/a  
  37.159.209.6   Italy (ITA)   n/a n/a  
  95.48.123.105   Poland (POL)   Kujawsko-Pomorskie Polska  
  200.241.45.146   Brazil (BRA)   n/a n/a  
  81.137.204.83   United Kingdom (GBR)   n/a n/a  
  196.38.228.2   South Africa (ZAF)   n/a n/a  
  151.236.52.44   United Kingdom (GBR)   n/a n/a  

Wednesday, October 29, 2014

Today's Naughty List - 28 Oct 2014

  89.248.169.94   Netherlands (NLD)   n/a n/a  
  208.105.81.202   United States (USA)   New York New York  
  121.52.209.123   China (CHN)   n/a n/a  
  115.205.159.65   China (CHN)   Zhejiang Hangzhou

Tuesday, October 28, 2014

Noisy Much?

 kevin109.190.158.183smtp2014-10-27 16:42:51
 kevin109.190.158.183system2014-10-27 16:41:37
 kevin109.190.158.183smtp2014-10-27 16:42:15

Didn't we already report you guys in a previous compromised host report? I thought so!


109.190.158.183   France (FRA)   n/a n/a

Wednesday, October 22, 2014

ABUSE: CARI.NET (www.cari.net) Complaints

We started fielding complaints this morning from cari.net in California. Our clients are reporting brute force attacks from this entity.

Contact Information:
8929 Complex Dr, San Diego, CA 92123 (858) 974-5080

Please note that this attacker has also appeared on our Naughty List entries today. This indicates large amounts of external reports of malicious activity from this host.