Friday, May 17, 2013

[FR] 213.44.37.253 - AS5410

General Information:


Attacked IP: 213.44.37.253
Country: France

Start: 2013-05-17 20:54:53
End: 2013-05-17 20:56:35
Duration: 1 minute(s)
Average query rate: 268 per minute

Requested DNS record: isc.org
Query count: 268

IPrange: 213.44.0.0/16
AS Number: Bouygues Telecom ISP
ISP: AS5410

IP has a reverse DNS value of: i07v-213-44-37-253.d4.club-internet.fr

This IP was only seen today


Observed 1 attack:
  • Attack 1 from 20:00 till 21:00
Details of the DNS Amplification attack:


Requested DNS record: isc.org
Query count: 268


Start: 2013-05-17 20:54:53
End: 2013-05-17 20:56:35
Duration: 1 minute(s)
Average query rate: 268 per minute

All request were made with the DNS id: 0x1d42 / 7490

Average query size: 78 bytes
Average response size: 612 bytes

Amplification: 684%

Total query size: 20904 bytes / 20 kilobytes
Response size: 164016 bytes / 160 kilobytes
TotalBandwidth: 184920 bytes / 180 kilobytes

All observed queries were made with a TTL of: 116

Because of this I think the attack was most likely performed from a single host rather than by a botnet.

All request were made with a UDP source port of: 49940


>>Read Before Rage<<<

No comments:

Post a Comment