Scan traffic from 121.8.0.0/16

Patrick Clochesy patrick at chegg.com
Thu Mar 6 20:07:34 UTC 2008


Probably not spoofed, I see a lot of scanning from China. 

route: 121.8.0.0/13 
descr: From Guangdong Network of ChinaTelecom 
origin: AS4134 
mnt-by: MAINT-CHINANET 
changed: dingsy at cndata.com 20060707 
source: APNIC 

person: Chinanet Hostmaster 
nic-hdl: CH93-AP 
e-mail: anti-spam at ns.chinanet.cn.net 
address: No.31 ,jingrong street,beijing 
address: 100032 
phone: +86-10-58501724 
fax-no: +86-10-58501724 
country: CN 
changed: dingsy at cndata.com 20070416 
mnt-by: MAINT-CHINANET 
source: APNIC 

-Patrick 

----- Original Message ----- 
From: "Rich Sena" <ras at thick.net> 
To: "NANOG" <nanog at merit.edu> 
Sent: Thursday, March 6, 2008 12:01:52 PM (GMT-0800) America/Los_Angeles 
Subject: Scan traffic from 121.8.0.0/16 


Anyone seeing anything similar - trying to determine if this is spoofed 
etc... 

-- 
Rich Sena - ras at thick.net 
ThickNET Consulting 
"On the way to understanding; you understand, and forget." 

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://mailman.nanog.org/pipermail/nanog/attachments/20080306/1541eb46/attachment.html>


More information about the NANOG mailing list