[nsp-sec] AS21844 ThePlanet - Xarvester C&C on-net: 174.133.73.42

Chris Morrow morrowc at ops-netman.net
Thu Feb 26 16:47:19 EST 2009



>From another security list -> (passed along with the OP's perms)

> > > Another at:
> > > 81.177.3.120:7501 RTCOMM-AS RTComm.RU Autonomous System
> >
> >Onward to Turkey now:
> >79.135.163.40 SNETTELECOM-AS Sistemnet Telekomunikasyon ve Bilgi
> > Tek. Tic. Ltd. Sti
>
> This is their "safe harbor".  Sistemnet is 100% rogue, so they will
> be no takedown there.  We may want to think about finally bringing
> this to a head with TurkTelcom.

This one shouldn't last long, right?
174.133.73.42:9401 THEPLANET-AS - ThePlanet.com Internet Services, Inc.

%rwhois V-1.5:003eff:00 whois.theplanet.com (by Network Solutions, Inc. 
V-1.5.9.5)
network:Class-Name:network
network:ID:NETBLK-THEPLANET-BLK-15
network:Auth-Area:174.132.0.0/15
network:Network-Name:TPIS-BLK-174-133-73-0
network:IP-Network:174.133.73.40/29
network:IP-Network-Block:174.133.73.40 - 174.133.73.47
network:Organization-Name:RobSteer
network:Organization-City:Chatham
network:Organization-Zip:ME4 31AB
network:Organization-Country:GBR
network:Description-Usage:customer
network:Server-Pri:ns1.theplanet.com
network:Server-Sec:ns2.theplanet.com
network:Tech-Contact;I:abuse at theplanet.com
network:Admin-Contact;I:abuse at theplanet.com
network:Created:20090222
network:Updated:20090222

passive-dns info:
semeright.biz	 A 	174.133.73.42

-Chris



More information about the nsp-security mailing list