Tuesday, May 14, 2013

[NL] 188.95.48.25 - AS57172

General Information:


Attacked IP: 188.95.48.25
Country: Netherlands

Start: 2013-05-14 09:46:41
End: 2013-05-14 19:36:31
Duration: 9:49:00
Average query rate: 0.0322580645161

Requested DNS record: directedat.asia
Query count: 19

IPrange: 188.95.48.0/21
AS Number: Global Layer network
ISP: AS57172

IP has a reverse DNS value of: minerva.netnibble.net

This IP has been seen on the following days:

  • 11-May-2013 11x
  • 14-May-2013 20x

Observed 1 attack:
  • Attack 1 from 9:00 till 20:00
Details of the DNS Amplification attack:


Requested DNS record: directedat.asia
Query count: 19


Start: 2013-05-14 09:46:41
End: 2013-05-14 19:36:31
Duration: 9:49:00
Average query rate: 0.0322580645161

All request were made with the DNS id: 0x8f1c / 36636

Average query size: 86 bytes
Average response size: 200 bytes

Amplification: 133%

Total query size: 1634 bytes / 1 kilobytes
Response size: 3812 bytes / 3 kilobytes
TotalBandwidth: 5446 bytes / 5 kilobytes

The following 2 TTL values were observed:

  • 244 1x
  • 243 18x

Unique query UDP source ports observed: 19


>>Read Before Rage<<<

No comments:

Post a Comment