Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. Observation: with the beginning of the war against Iran, botnets more or less stopped attacking my mailserver.

Observation: with the beginning of the war against Iran, botnets more or less stopped attacking my mailserver.

Scheduled Pinned Locked Moved Uncategorized
sysadminlife
7 Posts 4 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • jwildeboer@social.wildeboer.netJ This user is from outside of this forum
    jwildeboer@social.wildeboer.netJ This user is from outside of this forum
    jwildeboer@social.wildeboer.net
    wrote last edited by
    #1

    Observation: with the beginning of the war against Iran, botnets more or less stopped attacking my mailserver. From typically 300–500 IP addresses per day it's now less than 5 since a week. Indicates that maybe quite some C&C (Command and Control) servers were operating from Iranian IP addresses and fell victim to the internet shutdown there.

    #SysAdminLife @homelab

    thoralf@soc.umrath.netT tandemblog@mastodon.socialT jwildeboer@social.wildeboer.netJ 3 Replies Last reply
    1
    0
    • jwildeboer@social.wildeboer.netJ jwildeboer@social.wildeboer.net

      Observation: with the beginning of the war against Iran, botnets more or less stopped attacking my mailserver. From typically 300–500 IP addresses per day it's now less than 5 since a week. Indicates that maybe quite some C&C (Command and Control) servers were operating from Iranian IP addresses and fell victim to the internet shutdown there.

      #SysAdminLife @homelab

      thoralf@soc.umrath.netT This user is from outside of this forum
      thoralf@soc.umrath.netT This user is from outside of this forum
      thoralf@soc.umrath.net
      wrote last edited by
      #2

      @jwildeboer @homelab oh, that’s interesting.
      Any idea why?

      jwildeboer@social.wildeboer.netJ 1 Reply Last reply
      0
      • thoralf@soc.umrath.netT thoralf@soc.umrath.net

        @jwildeboer @homelab oh, that’s interesting.
        Any idea why?

        jwildeboer@social.wildeboer.netJ This user is from outside of this forum
        jwildeboer@social.wildeboer.netJ This user is from outside of this forum
        jwildeboer@social.wildeboer.net
        wrote last edited by
        #3

        @thoralf I added my educated guess that C&C servers might have been running on Iranian IP addresses. @homelab

        1 Reply Last reply
        0
        • jwildeboer@social.wildeboer.netJ jwildeboer@social.wildeboer.net

          Observation: with the beginning of the war against Iran, botnets more or less stopped attacking my mailserver. From typically 300–500 IP addresses per day it's now less than 5 since a week. Indicates that maybe quite some C&C (Command and Control) servers were operating from Iranian IP addresses and fell victim to the internet shutdown there.

          #SysAdminLife @homelab

          tandemblog@mastodon.socialT This user is from outside of this forum
          tandemblog@mastodon.socialT This user is from outside of this forum
          tandemblog@mastodon.social
          wrote last edited by
          #4

          @jwildeboer @homelab Or they have been reassigned to other tasks

          1 Reply Last reply
          0
          • jwildeboer@social.wildeboer.netJ jwildeboer@social.wildeboer.net

            Observation: with the beginning of the war against Iran, botnets more or less stopped attacking my mailserver. From typically 300–500 IP addresses per day it's now less than 5 since a week. Indicates that maybe quite some C&C (Command and Control) servers were operating from Iranian IP addresses and fell victim to the internet shutdown there.

            #SysAdminLife @homelab

            jwildeboer@social.wildeboer.netJ This user is from outside of this forum
            jwildeboer@social.wildeboer.netJ This user is from outside of this forum
            jwildeboer@social.wildeboer.net
            wrote last edited by
            #5

            @homelab The attacking IP addresses were always from many countries, with a bit of clustering in the US, China and indo-pacific countries. These botnets mostly use malware infected domestic devices. They do get their targets from the C&C servers and these seem to have gone quiet.

            unixwitch@social.tchncs.deU 1 Reply Last reply
            0
            • jwildeboer@social.wildeboer.netJ jwildeboer@social.wildeboer.net

              @homelab The attacking IP addresses were always from many countries, with a bit of clustering in the US, China and indo-pacific countries. These botnets mostly use malware infected domestic devices. They do get their targets from the C&C servers and these seem to have gone quiet.

              unixwitch@social.tchncs.deU This user is from outside of this forum
              unixwitch@social.tchncs.deU This user is from outside of this forum
              unixwitch@social.tchncs.de
              wrote last edited by
              #6

              @jwildeboer @homelab
              Another possibility: They now have more specific targets which are not your servers?

              jwildeboer@social.wildeboer.netJ 1 Reply Last reply
              0
              • unixwitch@social.tchncs.deU unixwitch@social.tchncs.de

                @jwildeboer @homelab
                Another possibility: They now have more specific targets which are not your servers?

                jwildeboer@social.wildeboer.netJ This user is from outside of this forum
                jwildeboer@social.wildeboer.netJ This user is from outside of this forum
                jwildeboer@social.wildeboer.net
                wrote last edited by
                #7

                @unixwitch Sure, also possible. The attacks have been ongoing for more than 3 years. The timing of them giving up on my machine may be coincidence. I share my observation in the hope that other people maybe confirm similar things in their logs. @homelab

                1 Reply Last reply
                0
                • R relay@relay.an.exchange shared this topic
                Reply
                • Reply as topic
                Log in to reply
                • Oldest to Newest
                • Newest to Oldest
                • Most Votes


                • Login

                • Login or register to search.
                • First post
                  Last post
                0
                • Categories
                • Recent
                • Tags
                • Popular
                • World
                • Users
                • Groups