North American Network Operators Group

Date Prev | Date Next | Date Index | Thread Index | Author Index | Historical

Re: Abusive traffic from Microsoft China?

  • From: Christopher Morrow
  • Date: Thu Nov 08 12:58:50 2007
  • Dkim-signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=beta; h=domainkey-signature:received:received:message-id:date:from:to:subject:cc:in-reply-to:mime-version:content-type:content-transfer-encoding:content-disposition:references; bh=9Y9ACVx48bEi7CVZz43yXJO53B5NhChvlZldqbLFue4=; b=YhXdX5fS++IwXZwN7YXwLOWgnFslU/si8qeJM8qQ9ukyuPtpW652WtbOUkirXu8W0SVwpBpDV3H1K46oZIHyV6mPFoZmhKcBTs4edzrd8PiZHslg3RZUyGrsXvYqe4IYLaSMta85MjaYz/yyV5U752FP4YoA2CNbWdy1eqgBEuk=
  • Domainkey-signature: a=rsa-sha1; c=nofws; d=gmail.com; s=beta; h=received:message-id:date:from:to:subject:cc:in-reply-to:mime-version:content-type:content-transfer-encoding:content-disposition:references; b=pafKL51xnHqr6rASMcTkyBo7cYWwEkZgb+ix1f0oUrKfDlpBTa8LYh0LD84Avkz/jSpKhxfWI7JOsNyXdYwXaXsG+St0UEPJ6i8i1Y5i/jE5Z1gOgI2kJPv7Lp2A6FNf+bmHjXrnIgunO9s5Dv59DInPqqSDm42ImxoTTNnqqjs=

On 11/8/07, Church, Charles <[email protected]> wrote:
>
> Looks fishy.  Why would a company the size of Microsoft register a
> single /25?  I doubt MS really owns that block.  Sounds more like a

They have a small office there serviced by a dsl link to the local
telco (CNCGroup)... This happens all the time.

> hacker playground to me.
>

maybe, probably not though.

> Chuck
>
> -----Original Message-----
> From: [email protected] [mailto:[email protected]] On Behalf Of
> David Hubbard
> Sent: Thursday, November 08, 2007 12:23 PM
> To: [email protected]
> Subject: Abusive traffic from Microsoft China?
>
>
>
> Just wondering if anyone else is seeing huge random
> floods of traffic from:
>
> inetnum:      202.96.51.128 - 202.96.51.255
> netname:      MICROSOFT-CO
> descr:        Microsft (China) Co.Ltd
> country:      CN
> admin-c:      CH455-AP
> tech-c:       SY21-AP
> mnt-by:       MAINT-CNCGROUP-BJ
> changed:      [email protected] 20060926
> status:       ALLOCATED NON-PORTABLE
> source:       APNIC
> changed:      [email protected] 20060926
>
> On a nearly daily basis we see them randomly open
> thousands of connections from a variety of addresses
> in that block to multiple servers.  I've emailed
> of coruse but that results in nothing.  Probably
> will just end up blocking them.
>
> Thanks,
>
> David
>