On 16 Jan 2021, at 11:51, Rob PE1CHL via 44Net
<44net(a)mailman.ampr.org> wrote:
On 1/16/21 12:35 PM, Jann Traschewski via 44Net wrote:
On 16.01.2021 11:50, Rob PE1CHL via 44Net wrote:
And why is (s)he portscanning for SSH servers?
It is hacked and is looking for other targets.
I already notified Igor, 9A6NVI, to take it offline.
I was starting to suspect that. But still I think that people should register
their allocations in DNS (and have their own DNS servers only when the also
make the reverse working), because I see no way to find the owner of that
address right now.
Any issues of this sort should be emailed to abuse(a)ampr.org <mailto:abuse@ampr.org>
and I will get right on it.
I have full visibility of all subnet allocations and who is responsible for them.
I’ve had several compromised systems reported recently, more in last 6 weeks than in the
last 6 months for some reason!
73,
Chris - G1FEF