Trends in Networks: Spam #8

Another week, and sadly nothing has changed. Spoke too soon last week, nothing has been done about Digital Ocean IPs spamming with Freenom TLDs in the PTR record.

Oct1
164.90.146.134	x1	rdns0.okisat.xyz
165.227.161.178	x7	bizcloud-send0.servar.xyz
165.227.164.181	x1	vcu0.minixo.gq
206.189.210.58	x1	loanassist.xyz
46.101.17.55	x2	vcu0.ginio.ga
46.101.202.40	x6	bounce.nowisthetimes.xyz

Oct2
134.122.53.183	x1	techbbk.gq
138.68.88.163	x18	mailer.danoshop.tk
142.93.188.215	x13	srv0.mails40.ga
167.172.141.181	x2	rdns0.frsdas.xyz
167.172.157.27	x2	rdns0.kijdas.xyz
188.166.61.236	x1	techbbk.cf
68.183.144.13	x3	srv0.mails40.cf
68.183.54.168	x2	srv0.mails40.gq

Oct3
104.131.115.50	x1	techdealer.xyz
188.166.53.231	x1	techwebss.cf

Oct4
139.59.111.16	x1	postal.nakul.tk
167.172.128.58	x1	tubefire.xyz

Oct5
104.131.60.163	x19	s1.biotox.ml
104.131.80.179	x1	flight.navaneeth.xyz
104.131.81.189	x1	flight.nemsiz.xyz
104.248.85.5	x2	techwebss.ml
128.199.37.251	x1	motion.noisyfond.xyz
128.199.43.31	x1	motion.oadkv.xyz
134.122.53.183	x1	techbbk.gq
134.122.97.89	x8	dfl0.minixo.ml
134.209.81.62	x1	motion.oasischeap.xyz
139.59.35.119	x1	dfl0.ginio.cf
139.59.90.252	x3	dfl0.531.mulxi.ml
142.93.35.36	x2	reply.wowik.xyz
143.110.158.243	x1	late.wcalqw.xyz
157.230.53.149	x2	music.thoiss.xyz
157.230.53.154	x1	music.toewr.xyz
159.203.118.169	x1	view.toristan.xyz
159.203.122.128	x1	view.turkmol.xyz
161.35.14.69	x1	table.namictu.xyz
165.22.243.189	x1	mx13.colonize25083.xyz
165.22.45.43	x1	flight.nfjp.xyz
165.227.167.204	x2	dfl0.ginio.gq
167.172.141.103	x1	music.tolittle.xyz
178.128.225.240	x2	office.onedrivexav.xyz
178.128.34.134	x1	reply.wodepad.xyz
178.62.197.176	x1	oktechsoft.tk
178.62.33.81	x1	server.pilihdulu.xyz
188.166.14.139	x1	auth.yazai.xyz
188.166.19.99	x1	techwebss.tk
198.199.82.25	x21	mail.greeg.xyz
64.225.68.161	x1	techwebss.ga
67.205.137.194	x4	dfl0.rekio.ml
68.183.46.49	x1	server.peermeans.xyz

Oct6
134.122.29.246	x1	oktechsoft.cf
143.110.188.136	x34	awef0.327.cicmo.ml
159.203.190.214	x1	dealsodime.xyz
167.99.207.65	x2	server.tizax.cf
188.166.83.193	x8	server.xzxo.cf
198.199.122.148	x2	box.prominet.xyz
207.154.202.56	x1	power0.deeutschepost.ga

Oct7
138.68.82.235	x1	vesta.circulo-inf.ga
165.227.142.199	x3	power0.dhlcloudservice.ml
165.227.82.184	x15	rdns0.beresa.xyz
198.199.122.148	x1	box.prominet.xyz

Oct8
128.199.159.225	x4	power0.dhlcloudservice.cf
134.209.25.99	x12	pzx0.809.vuvin.ml
157.245.91.231	x1	mail.tochile.xyz
159.89.198.91	x2	power0.deliverysfexpress.cf
159.89.23.28	x27	pzx0.824.vuvin.ml
159.89.28.76	x1	rtyn007-anki08.dfysuccess.xyz
167.71.233.175	x7	pzx0.822.vuvin.ml
167.71.233.22	x3	pzx0.802.vuvin.ml
167.71.235.22	x1	pzx0.818.vuvin.ml
188.166.99.107	x2	pzx0.805.vuvin.ml
188.166.99.60	x3	pzx0.vuvin.ga
188.166.99.61	x1	pzx0.801.vuvin.ml
188.166.99.86	x10	pzx0.814.vuvin.ml
198.199.122.148	x1	box.prominet.xyz
207.154.209.76	x8	pzx0.816.vuvin.ml

This entry was posted in Informative and tagged , , , , , , , . Bookmark the permalink.

Leave a Reply