Yeah no probs nothing to hide
From: Customer Security Team <
[email protected]>
Sent: 17 July 2017 09:42
To:
[email protected]
Subject: Re: [Ticket#2017071564007678] Security Alert from Talk Talk Customer
Security Team
Follow Up Flag: Follow up
Flag Status: Flagged
Dear MR J BENNETT,
We have received a complaint from an Internet user concerning alleged access attempts, or network related scans.
From the log information supplied it would appear to be the activity of a Virus or Trojan. The source of this activity has
been traced back to your account. Therefore we would like you to fully scan and if necessary clean your system(s).
Please reply to this email letting us know that your system or systems have been fully virus scanned and have been
cleared of any infections.
Temporary account suspension may be necessary in cases where the incident is causing problems to our
network.
Copy of original complaint:
15/07/2017 18:30 - Webiron Abuse Team wrote:
Hello!
=== You are receiving this e-mail in regard to abuse issues against our clients coming from the host at IP
78.xxx.xx.xxx. === (think this is mine IP not sure not even checked it but x it out)
--- Automated Message - To get a response or report issues with the reports, please see the contact info
below. ---
--- Report details are at the bottom of the e-mail. For web attacks see the "bot" links for more details about
the attack. ----
Webiron is a security service and this e-mail is being sent on behalf of our customers. We do not control how our
clients configure their protection and as a result do not control how blocks and bans are generated.
We are committed to providing useful information on abuse issues on behalf of our clients to help stop issues related
to issues that seem to originate from within your network.
We value your time and effort and appreciate your assistance in handling these issues!
If you are responsible for abuse issues however the IP being reported does not belong to you, please open a ticket or
email us to let us know of the error and we'll correct it as soon as possible.
Please note due to the retaliatory nature of attackers and the abundance of internet abuse havens and fake hosting
companies, we do not give out the exact IP of our clients. If you require further assistance we will be more than happy
to work with you. Just open a ticket our contact us with the details below.
-- Who We Are --
A little about our service, we are a server protection solution designed to help hosting companies, their customers,
and SoC departments improve their system security, stability and lower TCO and support costs.
Please feel free to send us your comments or responses. If you are inquiring for more information you must disclosed
the offending IP. To contact us via e-mail, use
[email protected], however if you require a ticket tracked
response you can open one at our SOC ticket system.
-- Abuse Criteria --
To be considered abusive, a bot must either be a clear danger (IE: exploit attempts, flooding, etc) or match at least
two items from the list
-- Removal Requests --
To be removed entirely from future reports reply to this e-mail with REMOVE (in all caps) in the subject line. Please
note this will only stop the e-mail to the address the e-mail was sent to and public notices will remain as your abuse
address will be listed on our BABL blacklist.
-- Feed/History Links --
IP Abuse Feed:
https://www.webiron.com/abuse_feed/78.144.42.159
IP Detailed Information:
https://www.webiron.com/iplookup/78.144.42.159
Your Abuse Report History:
https://www.webiron.com/abuse_feed/[email protected]
--- Blacklist Warning ---
In an ongoing effort to stop chronic abuse we maintain several blacklists available as flat data or free public DNSRBL.
For more information see:
https://www.webiron.com/rbl.html
To check the blacklist status of the offending IP, see:
https://www.webiron.com/iplookup/78.144.42.159
-- NEW --
We have now opened access to our RBL API allowing direct access to the entire RBL database. For more
information please see:
https://www.webiron.com/rbl.html
Thank you for your support,
The WebIron Team
*** Note *** - All times are in America/Phoenix (-07:00)
Unwanted and or Abusive Web Requests:
Offending/Source IP: 78.144.42.159
- Issue: Source has attempted the following botnet activity: WordPress XMLRPC Dataminer
- Block Type: New Ban
- Time: 2017-07-15 10:31:40-07:00
- Port: 80
- Service: http
- Report ID: 36368e50-26a3-4e72-923a-19af1f0ed1e9
- Bot Fingerprint: 806eb3b8ce85bf7e127dea05994aa204
- Bot Information:
https://www.webiron.com/bot_lookup/806eb3b8ce85bf7e127dea05994aa204
- Bot Node Feed:
https://www.webiron.com/bot_feed/806eb3b8ce85bf7e127dea05994aa204
- Abused Range: 5.133.182.0/24
- Requested URI: /xmlrpc.php
- User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:40.0) Gecko/20100101 Firefox/40.1
- Issue: Source has attempted the following botnet activity: WordPress Login Brute Force
- Block Type: Banned IP
- Time: 2017-07-15 10:31:40-07:00
- Port: 80
- Service: http
- Report ID: ffcfeaae-ce3b-4e0d-94a8-262dce3f67c4
- Bot Fingerprint: 78c5e7c8e2bf89b015688ee6cb512412
- Bot Information:
https://www.webiron.com/bot_lookup/78c5e7c8e2bf89b015688ee6cb512412
- Bot Node Feed:
https://www.webiron.com/bot_feed/78c5e7c8e2bf89b015688ee6cb512412
- Abused Range: 5.133.182.0/24
- Requested URI: /wp-login.php
- User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:40.0) Gecko/20100101 Firefox/40.1
- GET/POST Arguments Sent: pwd, wp-submit, testcookie, log
- Issue: Source has attempted the following botnet activity: WordPress Login Brute Force
- Block Type: Banned IP
- Time: 2017-07-15 10:31:40-07:00
- Port: 80
- Service: http
- Report ID: 9302eb23-1e38-499f-a299-7580dcfbd2b6
- Bot Fingerprint: 78c5e7c8e2bf89b015688ee6cb512412
- Bot Information:
https://www.webiron.com/bot_lookup/78c5e7c8e2bf89b015688ee6cb512412
- Bot Node Feed:
https://www.webiron.com/bot_feed/78c5e7c8e2bf89b015688ee6cb512412
- Abused Range: 5.133.182.0/24
- Requested URI: /wp-login.php
- User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:40.0) Gecko/20100101 Firefox/40.1
- GET/POST Arguments Sent: pwd, wp-submit, testcookie, log
Hope it helps anyone else.
I have checked with TalkTalk and thy were looking into it.