New prolific bad actor using @google cloud IPs, throwaway domains, to send #malware to our #JAPANESE friends.. @GoogleCloudTech can you check out the guys using 35.212.143.]21 et al?
You know what happens when you add BulletProof hosters to your Blacklists? They just start relaying out other suspect networks. PITLINE 77.83.36.]0/22 being used to relay phishing out IPs on @ExabytesWebHost 202.157.176.]0/23
Fairly quiet weekend, just an increase in #botnet traffic, then Monday rolls around.. #JOHINDER appears to have gotten access to more IP space. Just an early alert, havent' determined how they got access yet.. eg BGP hijacking? Or someone reselling IP space.
Okay, people .. today is pick on #netherlands day, let's share what 'hinky' network operators based out of the netherlands are you tracking, here's another one.. Hosting the @QuickBooks scammer on 79.141.165.]253 right now, but lots of other activity tracked.. AS59711
For the record, @Shadowserver@DutchPolice be nice if you go after these guys.. Threat actors also operating large botnets, via IPs in this range, used for password spray attacks. Welcome to reach out for evidence.
#JOHINDER found new IPs to use for his fake coupon spam runs, this time on AS16003 #Fornex and @Leaseweb MAIL FROM address: [mahasteakhouse@wwwhwgo.]com]
Oh @sendgrid_ops you REALLY have to start addressing these compromises in your systems.. #FAKE@TD_Canada notifications this time..149.72.123.]24 start including the originating IP, and we can help you determine who this actor is.
This @QuickBooks@QBCares scammer/phisher sure is getting cocky and agressive.. And you wonder why @ContaboCom gets a bad name for allowing these.. Starting to feel that all the #opsec guys have been let go at hosting companies.. Noone watching the gates?
New rule.. any domain registered within a week, and sending from Hetzner IPs.. *poof* ;0 Oh, I mean HETZNER should check for these.. *sigh*, a hundred ways to stop this actor if they cared..
Pet Peeve# 486: Company the size of @netflix can't manage their own mailouts, have to use a shared Amazon SES platform.. Let the #phishing begin.. @mailer.members.netflix.com via a114-75.smtp-out.us-east-2.amazonses.]com. Can't afford a dedicated IP address? Who is going to add THAT to their whitelist ;)
Why the @BytedanceTalk@tiktok_us servers in the US don't have rDNS/PTR records.. plain silly for a company that size.. (SERVFAIL) Even sillier to try sending email..
Not the first time we have reported IPs from #xserver in #ukraine, but always still suprised to see .ru domains on a 'Ukranian' network.. RIPE country registrar shows Bulgaria, addresses in Kharkiv, geo located to HongKong.. a bit messy.. what do you say? 4k3uht3t.hosted-by-24hg.]ru 138.249.247.]249