[dns-operations] MX record scanning

Simon Munton Simon.Munton at communitydns.net
Mon May 9 16:46:39 UTC 2011


We are also seeing this across four of the ccTLDs we host, we notified 
the ccTLD managers when we were confident it wasn't just going to go away.

It started about 8pm Friday (UTC) and has been going on since, for 
example :-

http://stats.cdns.net/public/0.0.0.1/00116B-933516.html

The pattern of nodes it is hitting suggests the traffic is originating 
from China Telecom, but we've not substantiated that for certain yet.

Its using a wide range of different source IP Addresses, but isn't 
really high enough in volume to be called an "attack".


-------------- next part --------------
A non-text attachment was scrubbed...
Name: stats.cdns.net/public/0.0.0.1/00116B-933516-week.png
Type: image/png
Size: 30607 bytes
Desc: not available
URL: <http://lists.dns-oarc.net/pipermail/dns-operations/attachments/20110509/529e8164/attachment.png>


More information about the dns-operations mailing list