wrote:
> I am Fred from Paris in France
And you are also GG googlegroup replying to a thread which is about a
week old. Some of the people who actually use newsreaders instead of
web based archives may have already had the reference posts spool off
their provider's newsservers.
> I would like to know who is this "61.156.238.238"
The 'who' in terms of meatspace identity is not available. We only know
about the provider for the IP address and the 'records' of the IP
address's activity amassed by those who report firewall logs to DShield
[and also MyNetWatchman] which aggregates them. DShield has amassed
about 400,000 reports, so there are very very many people who have had
this IP appear in their logs.
This is not the only thread asking questions about it. There is another
thread in an .it ng it.comp.sicurezza.windows also discussing. There
are also about 5000 reports in MNW, so you can get a 'picture' of the
type of activity coming from the IP at its report ID 175981779 or see it
at this link
http://www.mynetwatchman.com/LID.asp?IID=175981779 It
shows a 'wealth' of apparent malware agents generating reports.
If you could get your hands on the logs for the provider for the IP then
you could determine the meatspace person or account 'attached' to the IP
address.
The provider for the IP's netblock is
CNCGROUP Shandong province network
The contact person for the netblock is
XIAOFENG ZHANG
Jinan, Shandong P.R China
+86-531-6666666 (doubtful)
The CNC group main address is in Beijing
No.156, Fu-Xing-Men-Nei Street,
Beijing, 100031, P.R.China
+86-10-82993155 (probably true)
The cnc group is extremely unresponsive to problems with spam, viral
propagations or associated portscans.
In comparison, if we wanted to know who was the meatspace persona of
your IP address for the time frame of your posting here, we would
contact the ProXad provider and if we had sufficient justification, the
provider would 'relinquish' the records on your account.
Free SAS / ProXad
8, rue de la Ville L'Eveque
75008 Paris
+33 1 73 50 20 00
--
Mike Easter