probable DDOS to 195.238.3.33

Daniel Roesen dr at cluenet.de
Mon Feb 10 20:31:37 UTC 2003


On Mon, Feb 10, 2003 at 12:05:55PM -0800, Bulger, Tim wrote:
> We're seeing packets with spoofed source addresses destined to
> 195.238.3.33 getting dropped on firewalls at several locations going
> outbound.  Googling has turned up nothing relating to that destination
> IP address.

inetnum:      195.238.0.0 - 195.238.31.255
netname:      SKYNET-B
descr:        Belgacom Skynet SA/NV
descr:        Internet access provider
descr:        A subsidiary of BELGACOM SA/NV
country:      BE

route:        195.238.0.0/19
descr:        Belgacom Skynet SA/NV
origin:       AS5432
notify:       noc at skynet.be

$ host irc.skynet.be
irc.skynet.be. is an alias for chick.skynet.be.
chick.skynet.be. has address 195.238.0.13

Well, close... :-P

You might want to contact noc at skynet.be...


Regards,
Daniel



More information about the NANOG mailing list