Re: Russian Anal Probing + Malware

2019-06-23 Thread Rich Kulawiec
On Fri, Jun 21, 2019 at 05:13:35PM -0700, Ronald F. Guilmette wrote: > Is there anybody on this list who keeps firewall logs and who > DOESN'T have numerous hits recorded therein from one or more > of the following IP addresses? Well, I *did*, but having noticed their activities and grown tired of

Re: Russian Anal Probing + Malware

2019-06-23 Thread Dan Hollis
On Sat, 22 Jun 2019, Filip Hruska wrote: It's just a port/vulnerability scanner, I really don't see anything special about this particular case. they are pushing exploits. trying to RCE, wget a binary, chmod 777 on routers and rm -rf files. this goes way beyond scanner and into criminal tres

Re: Russian Anal Probing + Malware

2019-06-23 Thread Randy Bush
>> It's just a port/vulnerability scanner, I really don't see anything >> special about this particular case. > > they are pushing exploits. trying to RCE, wget a binary, chmod 777 on > routers and rm -rf files. > > this goes way beyond scanner and into criminal trespass and > destruction of prop

Re: Russian Anal Probing + Malware

2019-06-23 Thread Brad via NANOG
See inline responses... ‐‐‐ Original Message ‐‐‐ On Friday, June 21, 2019 6:13 PM, Ronald F. Guilmette wrote: > https://twitter.com/GreyNoiseIO/status/1129017971135995904 > https://twitter.com/JayTHL/status/1128718224965685248 After forwarding these links to a sanitized client on anot

Re: Russian Anal Probing + Malware

2019-06-23 Thread Dan Hollis
On Sun, 23 Jun 2019, Randy Bush wrote: It's just a port/vulnerability scanner, I really don't see anything special about this particular case. they are pushing exploits. trying to RCE, wget a binary, chmod 777 on routers and rm -rf files. this goes way beyond scanner and into criminal trespass

Re: Russian Anal Probing + Malware

2019-06-23 Thread Andy Smith
Hi Brad, On Sun, Jun 23, 2019 at 09:43:00PM +, Brad via NANOG wrote: > On Friday, June 21, 2019 6:13 PM, Ronald F. Guilmette > wrote: > > > https://twitter.com/GreyNoiseIO/status/1129017971135995904 > > https://twitter.com/JayTHL/status/1128718224965685248 > > After forwarding these links

Re: Russian Anal Probing + Malware

2019-06-23 Thread Hank Nussbacher
On 24/06/2019 00:23, Randy Bush wrote: e.g. i am aware of researchers scanning to see patching spread and trying to make a conext paper dreadline this week or infocom next month. hard to tell the sheep from the goats and the wolf from the sheep. i get the appended. sheep or wholf? i sure do n