
miltonningis@hushmail.com wrote:
Anyone know why AS 8143: $ whois -h whois.arin.net 8143
OrgName: Publicom Corp. OrgID: PUBLIC-35 Address: 1450 Coral Way #10 City: Miami StateProv: FL PostalCode: 33145 Country: US RegDate: 1997-04-25
Is announcing the following blocks?
$ whois -h whois.arin.net 155.73.0.0 OrgName: Borealis AS
$ whois -h whois.arin.net 134.33.0.0
OrgName: Codex Corporation
In that case, the hijacker setup a fake webhost that It's impossible to signup for at http://www.codexcorp.net [134.33.0.7] to make them look legitimate.
$ whois -h whois.arin.net 196.4.167.0
OrgName: Juta Information Network
$ whois -h whois.arin.net 144.2.0.0
OrgName: Publico B.V.
$ whois -h whois.arin.net 143.49.160.0 OrgName: Inform, Ltd.
$ whois -h whois.arin.net 160.116.160.0 OrgName: Affiliated Computing Services (Pty) Ltd
$ whois -h whois.arin.net 162.73.128.0 OrgName: Information Technology
$ whois -h whois.arin.net 198.204.0.0 OrgName: GHR Services Inc.
Thier all hijacked netblocks.
Also, Perhaps someone from AS16631 (Cogent) can explain this one:
Why is AS27255: $ whois -h whois.arin.net 27255
OrgName: VMX Inc
Announcing this?
$ whois -h whois.arin.net 157.156.0.0
OrgName: VMX Inc RegDate: 1992-01-13
Another hijacked one.
Had a /16 for 11 years, just recently decided to get an ASN? Seems like someone just registered a new company to have the same name as a company that had a /16, and then got a new ASN....
No. Thier just hijacked netblocks. Tower Group who had thier unused netblocks been announced by AS8143 confirmed that it was hijacked.