DNSアンプ攻撃観測 (irlwinning.com ANY)

irlwinning.com も数日引けなかったけれど,復活している.


$ dig @::1 irlwinning.com any
;; Truncated, retrying in TCP mode.

; <<>> DiG 9.7.6-P1 <<>> @::1 irlwinning.com any
; (1 server found)
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 38409
;; flags: qr rd ra; QUERY: 1, ANSWER: 244, AUTHORITY: 0, ADDITIONAL: 2

;; QUESTION SECTION:
;irlwinning.com.			IN	ANY

;; ANSWER SECTION:
irlwinning.com.		20371	IN	NS	ns1.irlwinning.com.
irlwinning.com.		20371	IN	NS	ns2.irlwinning.com.
irlwinning.com.		21600	IN	A	1.1.1.147
irlwinning.com.		21600	IN	A	1.1.1.148
irlwinning.com.		21600	IN	A	1.1.1.149
irlwinning.com.		21600	IN	A	1.1.1.150
irlwinning.com.		21600	IN	A	1.1.1.151
irlwinning.com.		21600	IN	A	1.1.1.152
irlwinning.com.		21600	IN	A	1.1.1.153
irlwinning.com.		21600	IN	A	1.1.1.154
irlwinning.com.		21600	IN	A	1.1.1.155
irlwinning.com.		21600	IN	A	1.1.1.156
irlwinning.com.		21600	IN	A	1.1.1.157
irlwinning.com.		21600	IN	A	1.1.1.158
irlwinning.com.		21600	IN	A	1.1.1.159
irlwinning.com.		21600	IN	A	1.1.1.160
irlwinning.com.		21600	IN	A	1.1.1.161
irlwinning.com.		21600	IN	A	1.1.1.162
irlwinning.com.		21600	IN	A	1.1.1.163
irlwinning.com.		21600	IN	A	1.1.1.164
irlwinning.com.		21600	IN	A	1.1.1.165
irlwinning.com.		21600	IN	A	1.1.1.166
irlwinning.com.		21600	IN	A	1.1.1.167
irlwinning.com.		21600	IN	A	1.1.1.168
irlwinning.com.		21600	IN	A	1.1.1.169
irlwinning.com.		21600	IN	A	1.1.1.170
irlwinning.com.		21600	IN	A	1.1.1.171
irlwinning.com.		21600	IN	A	1.1.1.172
irlwinning.com.		21600	IN	A	1.1.1.173
irlwinning.com.		21600	IN	A	1.1.1.174
irlwinning.com.		21600	IN	A	1.1.1.175
irlwinning.com.		21600	IN	A	1.1.1.176
irlwinning.com.		21600	IN	A	1.1.1.177
irlwinning.com.		21600	IN	A	1.1.1.178
irlwinning.com.		21600	IN	A	1.1.1.179
irlwinning.com.		21600	IN	A	1.1.1.180
irlwinning.com.		21600	IN	A	1.1.1.181
irlwinning.com.		21600	IN	A	1.1.1.182
irlwinning.com.		21600	IN	A	1.1.1.183
irlwinning.com.		21600	IN	A	1.1.1.184
irlwinning.com.		21600	IN	A	1.1.1.185
irlwinning.com.		21600	IN	A	1.1.1.186
irlwinning.com.		21600	IN	A	1.1.1.187
irlwinning.com.		21600	IN	A	1.1.1.188
irlwinning.com.		21600	IN	A	1.1.1.189
irlwinning.com.		21600	IN	A	1.1.1.190
irlwinning.com.		21600	IN	A	1.1.1.191
irlwinning.com.		21600	IN	A	1.1.1.192
irlwinning.com.		21600	IN	A	1.1.1.193
irlwinning.com.		21600	IN	A	1.1.1.194
irlwinning.com.		21600	IN	A	1.1.1.195
irlwinning.com.		21600	IN	A	1.1.1.196
irlwinning.com.		21600	IN	A	1.1.1.197
irlwinning.com.		21600	IN	A	1.1.1.198
irlwinning.com.		21600	IN	A	1.1.1.199
irlwinning.com.		21600	IN	A	1.1.1.200
irlwinning.com.		21600	IN	A	1.1.1.201
irlwinning.com.		21600	IN	A	1.1.1.202
irlwinning.com.		21600	IN	A	1.1.1.203
irlwinning.com.		21600	IN	A	1.1.1.204
irlwinning.com.		21600	IN	A	1.1.1.205
irlwinning.com.		21600	IN	A	1.1.1.206
irlwinning.com.		21600	IN	A	1.1.1.207
irlwinning.com.		21600	IN	A	1.1.1.208
irlwinning.com.		21600	IN	A	1.1.1.209
irlwinning.com.		21600	IN	A	1.1.1.210
irlwinning.com.		21600	IN	A	1.1.1.211
irlwinning.com.		21600	IN	A	1.1.1.212
irlwinning.com.		21600	IN	A	1.1.1.213
irlwinning.com.		21600	IN	A	1.1.1.214
irlwinning.com.		21600	IN	A	1.1.1.215
irlwinning.com.		21600	IN	A	1.1.1.216
irlwinning.com.		21600	IN	A	1.1.1.217
irlwinning.com.		21600	IN	A	1.1.1.218
irlwinning.com.		21600	IN	A	1.1.1.219
irlwinning.com.		21600	IN	A	1.1.1.220
irlwinning.com.		21600	IN	A	1.1.1.221
irlwinning.com.		21600	IN	A	1.1.1.222
irlwinning.com.		21600	IN	A	1.1.1.223
irlwinning.com.		21600	IN	A	1.1.1.224
irlwinning.com.		21600	IN	A	1.1.1.225
irlwinning.com.		21600	IN	A	1.1.1.226
irlwinning.com.		21600	IN	A	1.1.1.227
irlwinning.com.		21600	IN	A	1.1.1.228
irlwinning.com.		21600	IN	A	1.1.1.229
irlwinning.com.		21600	IN	A	1.1.1.230
irlwinning.com.		21600	IN	A	1.1.1.231
irlwinning.com.		21600	IN	A	1.1.1.232
irlwinning.com.		21600	IN	A	1.1.1.233
irlwinning.com.		21600	IN	A	1.1.1.234
irlwinning.com.		21600	IN	A	1.1.1.235
irlwinning.com.		21600	IN	A	1.1.1.236
irlwinning.com.		21600	IN	A	1.1.1.237
irlwinning.com.		21600	IN	A	1.1.1.238
irlwinning.com.		21600	IN	A	1.1.1.239
irlwinning.com.		21600	IN	A	1.1.1.240
irlwinning.com.		21600	IN	A	1.1.1.241
irlwinning.com.		21600	IN	A	1.1.1.1
irlwinning.com.		21600	IN	A	1.1.1.2
irlwinning.com.		21600	IN	A	1.1.1.3
irlwinning.com.		21600	IN	A	1.1.1.4
irlwinning.com.		21600	IN	A	1.1.1.5
irlwinning.com.		21600	IN	A	1.1.1.6
irlwinning.com.		21600	IN	A	1.1.1.7
irlwinning.com.		21600	IN	A	1.1.1.8
irlwinning.com.		21600	IN	A	1.1.1.9
irlwinning.com.		21600	IN	A	1.1.1.10
irlwinning.com.		21600	IN	A	1.1.1.11
irlwinning.com.		21600	IN	A	1.1.1.12
irlwinning.com.		21600	IN	A	1.1.1.13
irlwinning.com.		21600	IN	A	1.1.1.14
irlwinning.com.		21600	IN	A	1.1.1.15
irlwinning.com.		21600	IN	A	1.1.1.16
irlwinning.com.		21600	IN	A	1.1.1.17
irlwinning.com.		21600	IN	A	1.1.1.18
irlwinning.com.		21600	IN	A	1.1.1.19
irlwinning.com.		21600	IN	A	1.1.1.20
irlwinning.com.		21600	IN	A	1.1.1.21
irlwinning.com.		21600	IN	A	1.1.1.22
irlwinning.com.		21600	IN	A	1.1.1.23
irlwinning.com.		21600	IN	A	1.1.1.24
irlwinning.com.		21600	IN	A	1.1.1.25
irlwinning.com.		21600	IN	A	1.1.1.26
irlwinning.com.		21600	IN	A	1.1.1.27
irlwinning.com.		21600	IN	A	1.1.1.28
irlwinning.com.		21600	IN	A	1.1.1.29
irlwinning.com.		21600	IN	A	1.1.1.30
irlwinning.com.		21600	IN	A	1.1.1.31
irlwinning.com.		21600	IN	A	1.1.1.32
irlwinning.com.		21600	IN	A	1.1.1.33
irlwinning.com.		21600	IN	A	1.1.1.34
irlwinning.com.		21600	IN	A	1.1.1.35
irlwinning.com.		21600	IN	A	1.1.1.36
irlwinning.com.		21600	IN	A	1.1.1.37
irlwinning.com.		21600	IN	A	1.1.1.38
irlwinning.com.		21600	IN	A	1.1.1.39
irlwinning.com.		21600	IN	A	1.1.1.40
irlwinning.com.		21600	IN	A	1.1.1.41
irlwinning.com.		21600	IN	A	1.1.1.42
irlwinning.com.		21600	IN	A	1.1.1.43
irlwinning.com.		21600	IN	A	1.1.1.44
irlwinning.com.		21600	IN	A	1.1.1.45
irlwinning.com.		21600	IN	A	1.1.1.46
irlwinning.com.		21600	IN	A	1.1.1.47
irlwinning.com.		21600	IN	A	1.1.1.48
irlwinning.com.		21600	IN	A	1.1.1.49
irlwinning.com.		21600	IN	A	1.1.1.50
irlwinning.com.		21600	IN	A	1.1.1.51
irlwinning.com.		21600	IN	A	1.1.1.52
irlwinning.com.		21600	IN	A	1.1.1.53
irlwinning.com.		21600	IN	A	1.1.1.54
irlwinning.com.		21600	IN	A	1.1.1.55
irlwinning.com.		21600	IN	A	1.1.1.56
irlwinning.com.		21600	IN	A	1.1.1.57
irlwinning.com.		21600	IN	A	1.1.1.58
irlwinning.com.		21600	IN	A	1.1.1.59
irlwinning.com.		21600	IN	A	1.1.1.60
irlwinning.com.		21600	IN	A	1.1.1.61
irlwinning.com.		21600	IN	A	1.1.1.62
irlwinning.com.		21600	IN	A	1.1.1.63
irlwinning.com.		21600	IN	A	1.1.1.64
irlwinning.com.		21600	IN	A	1.1.1.65
irlwinning.com.		21600	IN	A	1.1.1.66
irlwinning.com.		21600	IN	A	1.1.1.67
irlwinning.com.		21600	IN	A	1.1.1.68
irlwinning.com.		21600	IN	A	1.1.1.69
irlwinning.com.		21600	IN	A	1.1.1.70
irlwinning.com.		21600	IN	A	1.1.1.71
irlwinning.com.		21600	IN	A	1.1.1.72
irlwinning.com.		21600	IN	A	1.1.1.73
irlwinning.com.		21600	IN	A	1.1.1.74
irlwinning.com.		21600	IN	A	1.1.1.75
irlwinning.com.		21600	IN	A	1.1.1.76
irlwinning.com.		21600	IN	A	1.1.1.77
irlwinning.com.		21600	IN	A	1.1.1.78
irlwinning.com.		21600	IN	A	1.1.1.79
irlwinning.com.		21600	IN	A	1.1.1.80
irlwinning.com.		21600	IN	A	1.1.1.81
irlwinning.com.		21600	IN	A	1.1.1.82
irlwinning.com.		21600	IN	A	1.1.1.83
irlwinning.com.		21600	IN	A	1.1.1.84
irlwinning.com.		21600	IN	A	1.1.1.85
irlwinning.com.		21600	IN	A	1.1.1.86
irlwinning.com.		21600	IN	A	1.1.1.87
irlwinning.com.		21600	IN	A	1.1.1.88
irlwinning.com.		21600	IN	A	1.1.1.89
irlwinning.com.		21600	IN	A	1.1.1.90
irlwinning.com.		21600	IN	A	1.1.1.91
irlwinning.com.		21600	IN	A	1.1.1.92
irlwinning.com.		21600	IN	A	1.1.1.93
irlwinning.com.		21600	IN	A	1.1.1.94
irlwinning.com.		21600	IN	A	1.1.1.95
irlwinning.com.		21600	IN	A	1.1.1.96
irlwinning.com.		21600	IN	A	1.1.1.97
irlwinning.com.		21600	IN	A	1.1.1.98
irlwinning.com.		21600	IN	A	1.1.1.99
irlwinning.com.		21600	IN	A	1.1.1.100
irlwinning.com.		21600	IN	A	1.1.1.101
irlwinning.com.		21600	IN	A	1.1.1.102
irlwinning.com.		21600	IN	A	1.1.1.103
irlwinning.com.		21600	IN	A	1.1.1.104
irlwinning.com.		21600	IN	A	1.1.1.105
irlwinning.com.		21600	IN	A	1.1.1.106
irlwinning.com.		21600	IN	A	1.1.1.107
irlwinning.com.		21600	IN	A	1.1.1.108
irlwinning.com.		21600	IN	A	1.1.1.109
irlwinning.com.		21600	IN	A	1.1.1.110
irlwinning.com.		21600	IN	A	1.1.1.111
irlwinning.com.		21600	IN	A	1.1.1.112
irlwinning.com.		21600	IN	A	1.1.1.113
irlwinning.com.		21600	IN	A	1.1.1.114
irlwinning.com.		21600	IN	A	1.1.1.115
irlwinning.com.		21600	IN	A	1.1.1.116
irlwinning.com.		21600	IN	A	1.1.1.117
irlwinning.com.		21600	IN	A	1.1.1.118
irlwinning.com.		21600	IN	A	1.1.1.119
irlwinning.com.		21600	IN	A	1.1.1.120
irlwinning.com.		21600	IN	A	1.1.1.121
irlwinning.com.		21600	IN	A	1.1.1.122
irlwinning.com.		21600	IN	A	1.1.1.123
irlwinning.com.		21600	IN	A	1.1.1.124
irlwinning.com.		21600	IN	A	1.1.1.125
irlwinning.com.		21600	IN	A	1.1.1.126
irlwinning.com.		21600	IN	A	1.1.1.127
irlwinning.com.		21600	IN	A	1.1.1.128
irlwinning.com.		21600	IN	A	1.1.1.129
irlwinning.com.		21600	IN	A	1.1.1.130
irlwinning.com.		21600	IN	A	1.1.1.131
irlwinning.com.		21600	IN	A	1.1.1.132
irlwinning.com.		21600	IN	A	1.1.1.133
irlwinning.com.		21600	IN	A	1.1.1.134
irlwinning.com.		21600	IN	A	1.1.1.135
irlwinning.com.		21600	IN	A	1.1.1.136
irlwinning.com.		21600	IN	A	1.1.1.137
irlwinning.com.		21600	IN	A	1.1.1.138
irlwinning.com.		21600	IN	A	1.1.1.139
irlwinning.com.		21600	IN	A	1.1.1.140
irlwinning.com.		21600	IN	A	1.1.1.141
irlwinning.com.		21600	IN	A	1.1.1.142
irlwinning.com.		21600	IN	A	1.1.1.143
irlwinning.com.		21600	IN	A	1.1.1.144
irlwinning.com.		21600	IN	A	1.1.1.145
irlwinning.com.		21600	IN	A	1.1.1.146
irlwinning.com.		900	IN	SOA	ns1.irlwinning.com. packets.irlwinning.com. 2013230901 900 900 900 900

;; ADDITIONAL SECTION:
ns1.irlwinning.com.	20371	IN	A	94.102.56.150
ns2.irlwinning.com.	20371	IN	A	94.102.56.150

;; Query time: 16 msec
;; SERVER: ::1#53(::1)
;; WHEN: Mon Oct  7 13:04:20 2013
;; MSG SIZE  rcvd: 4000
$ whois 94.102.56.150

#
# ARIN WHOIS data and services are subject to the Terms of Use
# available at: https://www.arin.net/whois_tou.html
#


#
# Query terms are ambiguous.  The query is assumed to be:
#     "n 94.102.56.150"
#
# Use "?" to get help.
#

#
# The following results may also be obtained via:
# http://whois.arin.net/rest/nets;q=94.102.56.150?showDetails=true&showARIN=false&ext=netref2
#

NetRange:       94.0.0.0 - 94.255.255.255
CIDR:           94.0.0.0/8
OriginAS:
NetName:        94-RIPE
NetHandle:      NET-94-0-0-0-1
Parent:
NetType:        Allocated to RIPE NCC
Comment:        These addresses have been further assigned to users in
Comment:        the RIPE NCC region. Contact information can be found in
Comment:        the RIPE database at http://www.ripe.net/whois
RegDate:        2007-07-30
Updated:        2009-05-18
Ref:            http://whois.arin.net/rest/net/NET-94-0-0-0-1

OrgName:        RIPE Network Coordination Centre
OrgId:          RIPE
Address:        P.O. Box 10096
City:           Amsterdam
StateProv:
PostalCode:     1001EB
Country:        NL
RegDate:
Updated:        2013-07-29
Ref:            http://whois.arin.net/rest/org/RIPE

ReferralServer: whois://whois.ripe.net:43

OrgAbuseHandle: ABUSE3850-ARIN
OrgAbuseName:   Abuse Contact
OrgAbusePhone:  +31205354444
OrgAbuseEmail:  abuse@ripe.net
OrgAbuseRef:    http://whois.arin.net/rest/poc/ABUSE3850-ARIN

OrgTechHandle: RNO29-ARIN
OrgTechName:   RIPE NCC Operations
OrgTechPhone:  +31 20 535 4444
OrgTechEmail:  hostmaster@ripe.net
OrgTechRef:    http://whois.arin.net/rest/poc/RNO29-ARIN


#
# ARIN WHOIS data and services are subject to the Terms of Use
# available at: https://www.arin.net/whois_tou.html
#

% This is the RIPE Database query service.
% The objects are in RPSL format.
%
% The RIPE Database is subject to Terms and Conditions.
% See http://www.ripe.net/db/support/db-terms-conditions.pdf

% Note: this output has been filtered.
%       To receive output for a database update, use the "-B" flag.

% Information related to '94.102.56.0 - 94.102.56.255'

inetnum:        94.102.56.0 - 94.102.56.255
netname:        NL-ECATEL
descr:          AS29073, Ecatel LTD
country:        NL
admin-c:        EL25-RIPE
tech-c:         EL25-RIPE
status:         ASSIGNED PA
mnt-by:         ECATEL-MNT
mnt-lower:      ECATEL-MNT
mnt-routes:     ECATEL-MNT
source:         RIPE # Filtered

role:           Ecatel LTD
address:        P.O.Box  19533
address:        2521 CA The Hague
address:        Netherlands
abuse-mailbox:  abuse@ecatel.info
remarks:        ----------------------------------------------------
remarks:        ECATEL LTD
remarks:        Dedicated and Co-location hosting services
remarks:        ----------------------------------------------------
remarks:        for abuse complaints : abuse@ecatel.info
remarks:        for any other questions : info@ecatel.info
remarks:        ----------------------------------------------------
admin-c:        EL25-RIPE
tech-c:         EL25-RIPE
nic-hdl:        EL25-RIPE
mnt-by:         ECATEL-MNT
source:         RIPE # Filtered

% Information related to '94.102.48.0/20AS29073'

route:          94.102.48.0/20
descr:          AS29073 Route object
origin:         AS29073
mnt-by:         ECATEL-MNT
source:         RIPE # Filtered

% This query was served by the RIPE Database Query Service version 1.69 (WHOIS3)