Jump to content


Photo

X-Barracuda-Apparent-Source-IP: is a very long list of Russian and Ukrainian IPs and ports


This topic has been archived. This means that you cannot reply to this topic.
1 reply to this topic

#1 Alan Brewer

Alan Brewer
  • Members
  • 12 posts

Posted 17 January 2020 - 03:51 PM

We got several emails today with their X-Barracuda-Apparent-Source-IP: being a very long list of Russian and Ukrainian IPs and ports.  My Barracuda blocked them as spam, but this looks very scary.  Has anyone seen similar?  The list below is just a small snip of the actual email.  The IP list is MUCH larger than this....

X-Barracuda-Envelope-From: Pen@uspsninall.site
X-Barracuda-Effective-Source-IP: uspsninall.site[5.44.45.249]
X-Barracuda-Apparent-Source-IP: 5.44.45.249
193.201.224.17:57452
193.201.224.17:55609
5.101.65.69:56883
193.201.224.17:55152
193.201.224.17:55379
5.101.65.69:57419
5.101.65.69:55146
193.201.224.17:55569
193.201.224.17:56798
193.201.224.17:57023
193.201.224.17:56272
5.101.65.69:56313
193.201.224.17:56059
193.201.224.17:57261
5.101.65.69:57552
5.101.65.69:56298
5.101.65.69:55160
5.101.65.69:55236
193.201.224.17:55808
193.201.224.17:57304
193.201.224.17:56172
5.101.65.69:56664
193.201.224.17:56966
193.201.224.17:56236
193.201.224.17:57474
5.101.65.69:57068
193.201.224.17:57352
193.201.224.17:55394
5.101.65.69:56445
5.101.65.69:55919
5.101.65.69:57576
193.201.224.17:55258
5.101.65.69:56982
193.201.224.17:56663
193.201.224.17:57380
5.101.65.69:56635
5.101.65.69:56110
5.101.65.69:55525
193.201.224.17:55383
193.201.224.17:55769
5.101.65.69:55128
5.101.65.69:56798
5.101.65.69:5596


#2 Michael Manning

Michael Manning
  • Members
  • 270 posts

Posted 20 January 2020 - 09:55 AM

What is your thinking here? Are they a huge number of hops from sending IP to recipient? As an attempt to obfuscate the source?