Ok so all of this happened on March 8 2022 when I got a person
trying to break into my mail server from IP 5.34.205.54 (AS15828)
Mar 8 19:01:20 server1 postfix/smtps/smtpd[151411]: warning: unknown[5.34.205.54]: SASL LOGIN authentication failed: Invalid
authentication mechanism
Mar 8 19:01:20 server1 postfix/smtps/smtpd[151411]: disconnect from unknown[5.34.205.54] ehlo=1 auth=0/1 rset=1 quit=1 commands=3/4
Mar 8 19:04:41 server1 postfix/anvil[151414]: statistics: max
connection rate 1/60s for (smtps:5.34.205.54) at Mar 8 19:01:19
Mar 8 19:04:41 server1 postfix/anvil[151414]: statistics: max
connection count 1 for (smtps:5.34.205.54) at Mar 8 19:01:19
Mar 8 19:04:41 server1 postfix/anvil[151414]: statistics: max cache
size 1 at Mar 8 19:01:19
Mar 8 19:22:15 server1 postfix/smtps/smtpd[151551]: connect from unknown[5.34.205.54]
Mar 8 19:22:16 server1 postfix/smtps/smtpd[151551]: warning: unknown[5.34.205.54]: SASL LOGIN authentication failed: Invalid
authentication mechanism
Mar 8 19:22:16 server1 postfix/smtps/smtpd[151551]: disconnect from unknown[5.34.205.54] ehlo=1 auth=0/1 rset=1 quit=1 commands=3/4
Mar 8 19:25:36 server1 postfix/anvil[151554]: statistics: max
connection rate 1/60s for (smtps:5.34.205.54) at Mar 8 19:22:15
Mar 8 19:25:36 server1 postfix/anvil[151554]: statistics: max
connection count 1 for (smtps:5.34.205.54) at Mar 8 19:22:15
Mar 8 19:25:36 server1 postfix/anvil[151554]: statistics: max cache
size 1 at Mar 8 19:22:15
Mar 8 19:43:05 server1 postfix/smtps/smtpd[151689]: connect from unknown[5.34.205.54]
Mar 8 19:43:06 server1 postfix/smtps/smtpd[151689]: warning: unknown[5.34.205.54]: SASL LOGIN authentication failed: Invalid
authentication mechanism
Mar 8 19:43:07 server1 postfix/smtps/smtpd[151689]: disconnect from unknown[5.34.205.54] ehlo=1 auth=0/1 rset=1 quit=1 commands=3/4
Mar 8 19:46:27 server1 postfix/anvil[151692]: statistics: max
connection rate 1/60s for (smtps:5.34.205.54) at Mar 8 19:43:06
Mar 8 19:46:27 server1 postfix/anvil[151692]: statistics: max
connection count 1 for (smtps:5.34.205.54) at Mar 8 19:43:06
So I believe that the person responsible for this break in attempt was
the one that I was contacting is the one responsible for the spam.
The person is using a free yandex.com email address as their contact
email address and doesn't appear to be any kind of legit website
for this ISP. The person is using the email address of
[email protected] the whole thing looks fishy to me.
I did contact the person on the ripe record first and got no where
with them before contacting the one providing connectivity to them.
https://apps.db.ripe.net/db-web-ui/query?searchtext=5.34.205.54
https://www.cidr-report.org/cgi-bin/as-report?as=AS15828
15828 WCD-AS, IR
Adjacency: 1 Upstream: 1 Downstream: 0
Upstream Adjacent AS list
AS133398 TELE-AS Tele Asia Limited, HK
whois: 401308
IANA has recorded AS15828 as originally allocated by
/usr/bin/whois -h jwhois.apnic.netr "AS15828\n % This is the
RIPE Database query service.
% The objects are in RPSL format.
%
% The RIPE Database is subject to Terms and Conditions.
% See
http://www.ripe.net/db/support/db-terms-conditions.pdf
% Note: this output has been filtered.
% Information related to 'AS15826 - AS15833'
as-block: AS15826 - AS15833
descr: RIPE NCC ASN block
remarks: These AS Numbers are assigned to network operators in the RIPE NCC service region.
mnt-by: RIPE-NCC-HM-MNT
created: 2018-11-22T15:27:25Z
last-modified: 2018-11-22T15:27:25Z
source: RIPE
% Information related to 'AS15828'
% Abuse contact for 'AS15828' is
'
[email protected]'
aut-num: AS15828
as-name: WCD-AS
export: to AS59721 announce as15828
export: to AS43754 announce as15828
export: to AS48011 announce as15828
export: to AS47350 announce as15828
export: to AS133398 announce as15828
import: From AS43754 accept any
import: From AS48011 accept any
import: From AS47350 accept any
import: From AS59721 accept any
import: From AS133398 accept any
org: ORG-BDNC3-RIPE
admin-c: MK17520-RIPE
tech-c: MK17520-RIPE
abuse-c: ACRO45411-RIPE
status: ASSIGNED
mnt-by: RIPE-NCC-END-MNT
mnt-by: wcd
created: 2015-08-31T13:46:05Z
last-modified: 2021-12-22T17:59:44Z
source: RIPE
sponsoring-org: ORG-RNB1-RIPE
organisation: ORG-BDNC3-RIPE
org-name: Blue Diamond Network Co., Ltd.
org-type: OTHER
address: AlmaseAbi Building - Mosalla blv -
RobatKarim - Tehran - Iran
abuse-c: AR33223-RIPE
mnt-ref: MNT-ALMAS
mnt-by: MNT-ALMAS
created: 2015-08-17T07:55:22Z
last-modified: 2015-08-17T08:19:44Z
source: RIPE # Filtered
person: DWCI NET
address: 1110 Palms Airport Drive 89119 Las Vegas, NV
phone: +971525729284
nic-hdl: MK17520-RIPE
mnt-by: wcd
created: 2015-01-27T10:15:09Z
last-modified: 2022-03-12T22:46:25Z
source: RIPE
So I decided to contact the person who it appears is providing ISP
providing connectivity to them Who is Tele Asia Limited, HK
Lovely another provider in Hong Hong. But this one is a special kind
of stupid he has been insulting and rude towards me every since the
start when I asked him to block all traffic to the /24 5.34.205.0/24
I have been dealing with Clive Rand
[email protected] and he
has been rude and ignorant and cursing at me and insulting me constantly.
So then I started to do a bit more digging and find out who exact
is tele-asia.net is.
I came across this
https://www.spamhaus.org/sbl/listings/tele-asia.net
Found 6 SBL listings for IPs under the responsibility of tele-asia.net
SBL545218
185.36.81.177/32 tele-asia.net
17-Mar-2022 10:49 GMT
Spamvertised website
SBL543599
45.125.67.0/24 tele-asia.net
23-Feb-2022 23:29 GMT
Suspected Snowshoe Spam IP Range
SBL543598
45.125.67.77/32 tele-asia.net
23-Feb-2022 23:28 GMT
spam source
SBL543473
45.125.67.75/32 tele-asia.net
22-Feb-2022 17:39 GMT
spam source
SBL543230
45.125.67.74/32 tele-asia.net
18-Feb-2022 22:22 GMT
spam source
SBL543112
45.125.67.73/32 tele-asia.net
17-Feb-2022 15:32 GMT
spam source
Oh looks like they are quite spam friendly too
it makes sense now why they are willing to provide
connectivity to some one who is trying to break into mail
servers.
Then I did a bit more digging on abuseipdb.com
https://www.abuseipdb.com/check/5.34.205.54
There has been 656 reports of abuse coming from this IP at
the time of writing this post from 44 different sources.
and the last report was just 48 minutes ago at the time of writing
this post. So the abuse is very active.
So it isn't just me seeing abuse coming from this IP
https://www.abuseipdb.com/check/5.34.205.54
Anyone else seeing these break in attempts it appears to be a spammer
trying to break into mail servers to gain access to to the mail
server to send out spam emails.
I would also be very careful contacting tele-asia.net as they appear to
either being paid a large sum of money to turn a blind eye to this abuse
or are working in conjunction with this abuser.
http://www.tele-asia.net/eng/index.php
They also don't even have a working abuse mailbox at tele-asia.net
either. If you email
[email protected] it bounces back saying the
mailbox is full.
They must be getting a lot of abuse complaints or something.
You can report abuse here as well and open a ticket but it appears
tickets fall on deaf ears with these guys when it comes to abuse
at tele-asia.net
https://www.tele-asia.net/billing/submitticket.php?step=2&deptid=5
This is the bounce back that I get. If you email
[email protected] it works.
This message was created automatically by mail delivery software.
A message that you sent could not be delivered to one or more of its recipients. This is a permanent error. The following address(es) failed:
[email protected]
LMTP error after RCPT TO:<
[email protected]>:
552 5.2.2 <
[email protected]> Quota exceeded (mailbox for user is
full)
Reporting-MTA: dns; main.hosthongkong.net
Action: failed
Final-Recipient: rfc822;
[email protected]
Status: 5.0.0
Has anyone else seen anything coming from 5.34.205.54?
I would definitely block 5.34.205.0/24 and possibly all of tele-asia.net
as well.
Anyone else seeing these attempts coming from this spammer rats nest.
I would be very careful dealing with "Spaceship Networks" or
tele-asia.net in this case. They appear to be a big spam nest.
--- SoupGate-Win32 v1.05
* Origin: fsxNet Usenet Gateway (21:1/5)