Page 1 of 1

Avast corporate IP SPAMMER

Posted: 2020-01-13 03:38
by palinka
Funny... Experimenting with click-to-see-PTR in my firewall ban project and I ran across a very curious ban:

Timestamp: 20/01/12 05:14.42
IP: 5.62.47.69
HELO: ADMIN
PTR: r-69-47-62-5.ff.avast.com

Banned for invalid HELO, but dang... looks like a corporate machine at AVAST was compromised by VIRUS?????? :lol:

Re: Avast corporate IP SPAMMER

Posted: 2020-01-13 11:54
by RvdH
Or maybe it is just a isolated test box in their corporate network to monitor, study and learn malware/virus behavior

Re: Avast corporate IP SPAMMER

Posted: 2020-01-13 14:43
by palinka
Possibly, but I just looked in my log db and found 7 instances of HELO = "ADMIN" from all around the world.

Eh... I give it 50/50 chance it was a spambot. :mrgreen: