<html><head><style id="axi-htmleditor-style" type="text/css">p { margin: 0px; }</style></head><body dir="" style="font-size: 10pt; font-family: "Source Sans Pro", sans-serif; background-image: none; background-repeat: repeat; background-attachment: fixed;">IPVolume/Incrediserv, are the new incantation of 'Ecatel'. <div><br></div><div>'Good luck' (try to peer with them and throttle the bw/ to 28k8 modem speed, lessens the impact somewhat).<br><div class="x-axi-signature"><br><div class="x-axi-signature" style="; font-size: 10pt; font-family: " source="" sans="" pro",="" sans-serif;"="">-- <div>IDGARA | Alex de Joode | alex@idgara.nl | +31651108221 | Skype:adejoode</div></div></div><br>On Wed, 12-02-2020 18h 50min, Javier Martín <javier.martin@centrored.net> wrote:<br><blockquote style="margin-left: 10px; padding-left: 10px; border-left: 1px solid #ccc;"><div id="__MailbirdStyleContent" style="font-size: 12pt;font-family: Calibri;color: #000000">
Hi all.<div class="mb_sig"></div>
<div><div>This one of the abuse emails that cries out to heaven.</div><div>There is an idiot who does not stop attacking us and does not answer the abuse email.</div></div><div>Someone knows what to do in this cases? RIPE said that is nothing to do because there is not a "return from their server" to our email.</div><div>This provider is full of spam, we banned all theirs ips. </div><div><a href="https://en.asytech.cn/check-ip/89.248.160.193" data-saferedirecturl="redir.hsp?url=https%3A%2F%2Fen.asytech.cn%2Fcheck-ip%2F89.248.160.193" target="_blank">https://en.asytech.cn/check-ip/89.248.160.193</a><br></div><div><a href="https://ipinfo.io/AS202425" data-saferedirecturl="redir.hsp?url=https%3A%2F%2Fipinfo.io%2FAS202425" target="_blank">https://ipinfo.io/AS202425</a><br></div><div>It is very striking how a Seychelles provider with a new AS number can spam without limits.</div><div>Kind regards.</div><div>Javier</div><blockquote class="history_container" type="cite" style="border-left-style: solid;border-width: 1px;margin-top: 20px;margin-left: 0px;padding-left: 10px;min-width: 500px">
<p style="color: #AAAAAA; margin-top: 10px;">Sobre 12/02/2020 18:44:24, Alex de Joode <alex@idgara.nl> escribió:</p><div style="font-family:Arial,Helvetica,sans-serif"><div>Alessandro,</div><div><br></div>The abuse notification below, is absolutely terrible: it only highlights the OVH IP that was used, however it completely fails to identify the IP/hostname that was "attacked", no action (other than forward the notice to the user of the IP) can be taken.<div><br></div><div>Please in the future include all relevant data in you abuse notice. (src+dst ip are relevant!)<br><div class="x-axi-signature"><br></div><div class="x-axi-signature">Thx.</div><div class="x-axi-signature"><div class="x-axi-signature" style="font-size: 10pt;font-family: " source="" sans="" pro="" serif="">-- <div>IDGARA | Alex de Joode | alex@idgara.nl | +31651108221 | Skype:adejoode</div></div></div><br>On Wed, 12-02-2020 13h 16min, Alessandro Vesely <vesely@tana.it> wrote:<blockquote style="margin-left: 10px;padding-left: 10px;border-left: 1px solid #ccc;min-width: 500px"><div style="font-family: " source="" sans="" pro="" serif="" font="font" size="" pt=""><br>Dear Abuse Team<br><br>The following abusive behavior from IP address under your constituency<br>188.165.221.36 has been detected:<br><br> 2020-02-11 11:39:25 CET, 188.165.221.36, old decay: 86400, prob: 34.72%, SMTP auth dictionary attack<br><br>188.165.221.36 was caught 102 times since Fri May 18 01:42:13 2018<br><br>original data from the mail log:<br> 2020-02-11 11:39:05 CET courieresmtpd: started,ip=[188.165.221.36],port=[58534]<br> 2020-02-11 11:39:05 CET courieresmtpd: started,ip=[188.165.221.36],port=[62026]<br> 2020-02-11 11:39:05 CET courieresmtpd: started,ip=[188.165.221.36],port=[63198]<br> 2020-02-11 11:39:25 CET courieresmtpd: started,ip=[188.165.221.36],port=[58743]<br> 2020-02-11 11:39:25 CET courieresmtpd: started,ip=[188.165.221.36],port=[50520]<br> 2020-02-11 11:39:25 CET courieresmtpd: error,relay=188.165.221.36,port=58743,msg="535 Authentication failed.",cmd: AUTH LOGIN 42D117A2.9F10013D<br><br><br></div></blockquote></div></div></blockquote></div></blockquote></div></body></html>