Re: [mailop] Digital Ocean Broken Bot attack, just in case it's you and not me..

2020-08-27 Thread Chris via mailop
Lots of attacks coming from this block I'm only seeing non-SMTP attacks however. Things like attempted SMB breakins, telnet password probing (likely IoT), VOIP attacks, a variety of botnets. This could be a badly infected netblock or a dynamic segment with no method to prevent IP hopping.

Re: [mailop] Digital Ocean Broken Bot attack, just in case it's you and not me..

2020-07-10 Thread Markus E. via mailop
Hello! On Thu, 9 Jul 2020, Benoit Panizzon via mailop wrote: Range, 192.241.227.0/24 One connect each on Thu, Sat, Sun, and Mon. Did EHLO after banner, then closed the connection. 116 connections between 27. June and 1. July to my spamtrap / honeypot, mostly sending "EHLO zg-0626-127" and

Re: [mailop] Digital Ocean Broken Bot attack, just in case it's you and not me..

2020-07-09 Thread Benoit Panizzon via mailop
> >Range, 192.241.227.0/24 > > One connect each on Thu, Sat, Sun, and Mon. Did EHLO after banner, then > closed the connection. 116 connections between 27. June and 1. July to my spamtrap / honeypot, mostly sending "EHLO zg-0626-127" and then disconnecting. Mit freundlichen Grüssen -Benoî

Re: [mailop] Digital Ocean Broken Bot attack, just in case it's you and not me..

2020-07-07 Thread Michael Rathbun via mailop
On Tue, 7 Jul 2020 16:45:24 -0700, Michael Peddemors via mailop wrote: >Very High volume SMTP Auth type attacks, but either a broken bot, or an >attempt at Denial of Service.. > >Range, 192.241.227.0/24 One connect each on Thu, Sat, Sun, and Mon. Did EHLO after banner, then closed the connect

[mailop] Digital Ocean Broken Bot attack, just in case it's you and not me..

2020-07-07 Thread Michael Peddemors via mailop
Very High volume SMTP Auth type attacks, but either a broken bot, or an attempt at Denial of Service.. Range, 192.241.227.0/24 Naming Convention: zg-0626-70.stretchoid.com It's a 'fast talker' attack, sending EHLO before waiting for the CONNECT string.. Just in case anyone else is encounter