I am seeing an incredible number of bogus tertiary domain queries on my master and slave nameservers, but exclusively just for one specific domain, for which I have the SOA. These queries come from commercial ISP nameservers as well as they appear to also be coming from residential DSL and cable modem IP assignments. Granted, they aren't really hurting anything by making these bogus queries, but I'm just exceedingly curious as to what this is all about, is there some new microsoft exploit being probed that nobody is as yet aware of? Googling for the answer gave me no results. Take a look at this and tell me what you guys think (sorted by IP and filtered to show only one unique query per IP involved, but I assure you, they make these same queries over and over non-stop, going on now for weeks).
Now before anyone tells me to just DROP rule them in iptables, remember that many of these appear to be large commercial ISPs, so dropping them from both my master AND slave would prevent any legitimate queries from these ISPs as well. Mostly I just want to know what this is and/or make people aware of this, if it is an emerging exploit issue. Thanks! By the way, below is a sorted resolve for the IPs in the above list that actually have PTR records.
ns5a.townisp.com.
ns6.townisp.com.
ns7.townisp.com.
ns8.townisp.com.
town119.shrewsbury-ma.gov.
pxy06jcsntn.jcsn.tn.charter.com.
pxy07jcsntn.jcsn.tn.charter.com.
pxy05jcsntn.jcsn.tn.charter.com.
pxy01jcsntn.jcsn.tn.charter.com.
pxy02jcsntn.jcsn.tn.charter.com.
pxy03jcsntn.jcsn.tn.charter.com.
pxy04jcsntn.jcsn.tn.charter.com.
pxy01bycymi.bycy.mi.charter.com.
pxy03bycymi.bycy.mi.charter.com.
pxy02bycymi.bycy.mi.charter.com.
pxy04bycymi.bycy.mi.charter.com.
pxy01oxfrma.oxfr.ma.charter.com.
pxy02oxfrma.oxfr.ma.charter.com.
pxy03oxfrma.oxfr.ma.charter.com.
pxy04oxfrma.oxfr.ma.charter.com.
pxy05oxfrma.oxfr.ma.charter.com.
chlm-nrcns01.chelmsfdrdc2.ma.boston.comcast.net.
chlm-nrcns02.chelmsfdrdc2.ma.boston.comcast.net.
chlm-cns02.chelmsfdrdc2.ma.boston.comcast.net.
chlm-cns03.chelmsfdrdc2.ma.boston.comcast.net.
chlm-cns04.chelmsfdrdc2.ma.boston.comcast.net.
Code:
216.195.0.140 VHS18.MYDOMAIN.COM
216.195.0.140 _ldap._tcp.dc._msdcs.MYDOMAIN.COM
216.195.0.140 _ldap._tcp.e3ad7dba-7dab-4536-b71e-6636157e0cda.domains._msdcs.MYDOMAIN.COM
216.195.0.161 VHS18.MYDOMAIN.COM
216.195.0.161 _kerberos._tcp.dc._msdcs.MYDOMAIN.COM
216.195.0.161 _ldap._tcp.dc._msdcs.MYDOMAIN.COM
216.195.0.161 _ldap._tcp.e3ad7dba-7dab-4536-b71e-6636157e0cda.domains._msdcs.MYDOMAIN.COM
216.195.0.161 _ldap._tcp.pdc._msdcs.MYDOMAIN.COM
216.195.0.161 data.MYDOMAIN.COM
216.195.0.161 wpad.MYDOMAIN.COM
216.195.0.163 VHS18.MYDOMAIN.COM
216.195.0.163 _ldap._tcp.dc._msdcs.MYDOMAIN.COM
216.195.0.163 _ldap._tcp.e3ad7dba-7dab-4536-b71e-6636157e0cda.domains._msdcs.MYDOMAIN.COM
216.195.0.165 VHS18.MYDOMAIN.COM
216.195.0.165 _kerberos._tcp.dc._msdcs.MYDOMAIN.COM
216.195.0.165 _ldap._tcp.dc._msdcs.MYDOMAIN.COM
216.195.0.165 _ldap._tcp.e3ad7dba-7dab-4536-b71e-6636157e0cda.domains._msdcs.MYDOMAIN.COM
216.195.0.165 _ldap._tcp.pdc._msdcs.MYDOMAIN.COM
216.195.0.165 data.MYDOMAIN.COM
216.195.0.165 ghm.static.zmh.zope.net.MYDOMAIN.COM
216.195.0.165 wpad.MYDOMAIN.COM
216.195.12.119 VHS18.MYDOMAIN.COM
216.195.12.119 _ldap._tcp.dc._msdcs.MYDOMAIN.COM
216.195.12.119 _ldap._tcp.e3ad7dba-7dab-4536-b71e-6636157e0cda.domains._msdcs.MYDOMAIN.COM
216.195.12.119 _ldap._tcp.pdc._msdcs.MYDOMAIN.COM
216.195.12.119 data.MYDOMAIN.COM
216.195.12.119 wpad.MYDOMAIN.COM
24.159.64.15 MY2003.MYDOMAIN.COM
24.159.64.15 STAFF02.MYDOMAIN.COM
24.159.64.15 _ldap._tcp.Default-First-Site-Name._sites.MYDOMAIN.COM
24.159.64.15 _ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.MYDOMAIN.COM
24.159.64.15 staff02.MYDOMAIN.COM
24.159.64.16 MY2003.MYDOMAIN.COM
24.159.64.17 _ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.MYDOMAIN.COM
24.159.64.17 _ldap._tcp.dc._msdcs.STUDENT.MYDOMAIN.COM
24.159.64.19 MY2003.MYDOMAIN.COM
24.159.64.19 STAFF02.MYDOMAIN.COM
24.159.64.19 _ldap._tcp.Default-First-Site-Name._sites.MYDOMAIN.COM
24.159.64.19 _ldap._tcp.Default-First-Site-Name._sites.STAFF01.MYDOMAIN.COM
24.159.64.20 _ldap._tcp.Default-First-Site-Name._sites.MYDOMAIN.COM
24.159.64.20 _ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.MYDOMAIN.COM
24.159.64.20 isatap.MYDOMAIN.COM
24.159.64.21 MY2003.MYDOMAIN.COM
24.159.64.21 SPEDLAP13.MYDOMAIN.COM
24.159.64.21 STAFF02.MYDOMAIN.COM
24.159.64.21 _ldap._tcp.Default-First-Site-Name._sites.MYDOMAIN.COM
24.159.64.21 _ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.MYDOMAIN.COM
24.159.64.21 _ldap._tcp.pdc._msdcs.STUDENT.MYDOMAIN.COM
24.159.64.21 isatap.MYDOMAIN.COM
24.159.64.22 BRW_C63BFE.MYDOMAIN.COM
24.159.64.22 MY2003.MYDOMAIN.COM
24.159.64.22 VHS21.STUDENT.MYDOMAIN.COM
24.159.64.22 _ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.MYDOMAIN.COM
24.159.64.22 isatap.MYDOMAIN.COM
24.159.64.22 wpad.STUDENT.MYDOMAIN.COM
24.247.24.39 SPEDLAP13.MYDOMAIN.COM
24.247.24.39 STAFF02.MYDOMAIN.COM
24.247.24.39 _ldap._tcp.Default-First-Site-Name._sites.MYDOMAIN.COM
24.247.24.39 _ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.MYDOMAIN.COM
24.247.24.39 isatap.MYDOMAIN.COM
24.247.24.41 BRW_C63BFE.MYDOMAIN.COM
24.247.24.41 MY2003.MYDOMAIN.COM
24.247.24.41 STAFF02.MYDOMAIN.COM
24.247.24.41 _ldap._tcp.Default-First-Site-Name._sites.MYDOMAIN.COM
24.247.24.41 _ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.MYDOMAIN.COM
24.247.24.41 isatap.MYDOMAIN.COM
24.247.24.55 BRW_C63BFE.MYDOMAIN.COM
24.247.24.55 MY2003.MYDOMAIN.COM
24.247.24.55 _ldap._tcp.Default-First-Site-Name._sites.MYDOMAIN.COM
24.247.24.61 STAFF02.MYDOMAIN.COM
24.247.24.61 _ldap._tcp.Default-First-Site-Name._sites.MYDOMAIN.COM
24.247.24.61 _ldap._tcp.Default-First-Site-Name._sites.STAFF01.MYDOMAIN.COM
24.247.24.61 _ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.MYDOMAIN.COM
66.189.0.101 BRW_C63BFE.MYDOMAIN.COM
66.189.0.101 MY2003.MYDOMAIN.COM
66.189.0.101 SPEDLAP13.MYDOMAIN.COM
66.189.0.101 STAFF01.MYDOMAIN.COM
66.189.0.101 STAFF02.MYDOMAIN.COM
66.189.0.101 VHS27.STUDENT.MYDOMAIN.COM
66.189.0.101 _kerberos._tcp.Default-First-Site-Name._sites.dc._msdcs.MYDOMAIN.COM
66.189.0.101 _kerberos._tcp.dc._msdcs.STUDENT.MYDOMAIN.COM
66.189.0.101 _ldap._tcp.33c5e987-35cd-49b4-a8f8-73c47f609a58.domains._msdcs.MYDOMAIN.COM
66.189.0.101 _ldap._tcp.Default-First-Site-Name._sites.MYDOMAIN.COM
66.189.0.101 _ldap._tcp.Default-First-Site-Name._sites.STAFF01.MYDOMAIN.COM
66.189.0.101 _ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.MYDOMAIN.COM
66.189.0.101 _ldap._tcp.MYDOMAIN.COM
66.189.0.101 _ldap._tcp.STAFF01.MYDOMAIN.COM
66.189.0.101 _ldap._tcp.dc._msdcs.MYDOMAIN.COM
66.189.0.101 _ldap._tcp.dc._msdcs.STUDENT.MYDOMAIN.COM
66.189.0.101 _ldap._tcp.e3ad7dba-7dab-4536-b71e-6636157e0cda.domains._msdcs.MYDOMAIN.COM
66.189.0.101 _ldap._tcp.pdc._msdcs.MYDOMAIN.COM
66.189.0.101 isatap.MYDOMAIN.COM
66.189.0.101 technas.MYDOMAIN.COM
66.189.0.101 wpad.MYDOMAIN.COM
66.189.0.102 BRW_C63BFE.MYDOMAIN.COM
66.189.0.102 MY2003.MYDOMAIN.COM
66.189.0.102 SPEDLAP13.MYDOMAIN.COM
66.189.0.102 STAFF01.MYDOMAIN.COM
66.189.0.102 STAFF02.MYDOMAIN.COM
66.189.0.102 VHS21.STUDENT.MYDOMAIN.COM
66.189.0.102 VHS27.STUDENT.MYDOMAIN.COM
66.189.0.102 _kerberos._tcp.Default-First-Site-Name._sites.dc._msdcs.MYDOMAIN.COM
66.189.0.102 _kerberos._tcp.dc._msdcs.MYDOMAIN.COM
66.189.0.102 _kerberos._tcp.dc._msdcs.STUDENT.MYDOMAIN.COM
66.189.0.102 _ldap._tcp.33c5e987-35cd-49b4-a8f8-73c47f609a58.domains._msdcs.MYDOMAIN.COM
66.189.0.102 _ldap._tcp.Default-First-Site-Name._sites.MYDOMAIN.COM
66.189.0.102 _ldap._tcp.Default-First-Site-Name._sites.STAFF01.MYDOMAIN.COM
66.189.0.102 _ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.MYDOMAIN.COM
66.189.0.102 _ldap._tcp.MYDOMAIN.COM
66.189.0.102 _ldap._tcp.STAFF01.MYDOMAIN.COM
66.189.0.102 _ldap._tcp.dc._msdcs.MYDOMAIN.COM
66.189.0.102 _ldap._tcp.dc._msdcs.STUDENT.MYDOMAIN.COM
66.189.0.102 _ldap._tcp.e3ad7dba-7dab-4536-b71e-6636157e0cda.domains._msdcs.MYDOMAIN.COM
66.189.0.102 _ldap._tcp.pdc._msdcs.MYDOMAIN.COM
66.189.0.102 isatap.MYDOMAIN.COM
66.189.0.102 staff02.MYDOMAIN.COM
66.189.0.102 std2.MYDOMAIN.COM
66.189.0.102 wpad.MYDOMAIN.COM
66.189.0.103 BRW_C63BFE.MYDOMAIN.COM
66.189.0.103 SPEDLAP13.MYDOMAIN.COM
66.189.0.103 STAFF01.MYDOMAIN.COM
66.189.0.103 STAFF02.MYDOMAIN.COM
66.189.0.103 _kerberos._tcp.dc._msdcs.STUDENT.MYDOMAIN.COM
66.189.0.103 _ldap._tcp.33c5e987-35cd-49b4-a8f8-73c47f609a58.domains._msdcs.MYDOMAIN.COM
66.189.0.103 _ldap._tcp.Default-First-Site-Name._sites.MYDOMAIN.COM
66.189.0.103 _ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.MYDOMAIN.COM
66.189.0.103 _ldap._tcp.MYDOMAIN.COM
66.189.0.103 _ldap._tcp.dc._msdcs.MYDOMAIN.COM
66.189.0.103 _ldap._tcp.dc._msdcs.STUDENT.MYDOMAIN.COM
66.189.0.103 _ldap._tcp.e3ad7dba-7dab-4536-b71e-6636157e0cda.domains._msdcs.MYDOMAIN.COM
66.189.0.103 _ldap._tcp.pdc._msdcs.MYDOMAIN.COM
66.189.0.103 isatap.MYDOMAIN.COM
66.189.0.103 staff02.STUDENT.MYDOMAIN.COM
66.189.0.103 std1.STUDENT.MYDOMAIN.COM
66.189.0.103 technas.MYDOMAIN.COM
66.189.0.103 wpad.MYDOMAIN.COM
66.189.0.104 BRW_C63BFE.MYDOMAIN.COM
66.189.0.104 MY2003.MYDOMAIN.COM
66.189.0.104 SPEDLAP13.MYDOMAIN.COM
66.189.0.104 STAFF01.MYDOMAIN.COM
66.189.0.104 STAFF02.MYDOMAIN.COM
66.189.0.104 _kerberos._tcp.Default-First-Site-Name._sites.dc._msdcs.MYDOMAIN.COM
66.189.0.104 _kerberos._tcp.dc._msdcs.MYDOMAIN.COM
66.189.0.104 _kerberos._tcp.dc._msdcs.STUDENT.MYDOMAIN.COM
66.189.0.104 _ldap._tcp.33c5e987-35cd-49b4-a8f8-73c47f609a58.domains._msdcs.MYDOMAIN.COM
66.189.0.104 _ldap._tcp.Default-First-Site-Name._sites.MYDOMAIN.COM
66.189.0.104 _ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.MYDOMAIN.COM
66.189.0.104 _ldap._tcp.MYDOMAIN.COM
66.189.0.104 _ldap._tcp.dc._msdcs.MYDOMAIN.COM
66.189.0.104 _ldap._tcp.dc._msdcs.STUDENT.MYDOMAIN.COM
66.189.0.104 _ldap._tcp.e3ad7dba-7dab-4536-b71e-6636157e0cda.domains._msdcs.MYDOMAIN.COM
66.189.0.104 _ldap._tcp.pdc._msdcs.MYDOMAIN.COM
66.189.0.104 _ldap._tcp.pdc._msdcs.STUDENT.MYDOMAIN.COM
66.189.0.104 isatap.MYDOMAIN.COM
66.189.0.104 staff02.STUDENT.MYDOMAIN.COM
66.189.0.104 std2.MYDOMAIN.COM
66.189.0.104 technas.MYDOMAIN.COM
66.189.0.105 BRW_C63BFE.MYDOMAIN.COM
66.189.0.105 MY2003.MYDOMAIN.COM
66.189.0.105 STAFF01.MYDOMAIN.COM
66.189.0.105 STAFF02.MYDOMAIN.COM
66.189.0.105 VHS27.STUDENT.MYDOMAIN.COM
66.189.0.105 _kerberos._tcp.dc._msdcs.MYDOMAIN.COM
66.189.0.105 _ldap._tcp.33c5e987-35cd-49b4-a8f8-73c47f609a58.domains._msdcs.MYDOMAIN.COM
66.189.0.105 _ldap._tcp.Default-First-Site-Name._sites.MYDOMAIN.COM
66.189.0.105 _ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.MYDOMAIN.COM
66.189.0.105 _ldap._tcp.MYDOMAIN.COM
66.189.0.105 _ldap._tcp.dc._msdcs.MYDOMAIN.COM
66.189.0.105 _ldap._tcp.dc._msdcs.STUDENT.MYDOMAIN.COM
66.189.0.105 _ldap._tcp.e3ad7dba-7dab-4536-b71e-6636157e0cda.domains._msdcs.MYDOMAIN.COM
66.189.0.105 isatap.MYDOMAIN.COM
66.189.0.105 staff02.MYDOMAIN.COM
66.189.0.105 staff02.STUDENT.MYDOMAIN.COM
66.189.0.105 std1.MYDOMAIN.COM
66.189.0.105 std1.STUDENT.MYDOMAIN.COM
66.189.0.105 std2.MYDOMAIN.COM
66.189.0.105 technas.MYDOMAIN.COM
66.189.0.105 wpad.MYDOMAIN.COM
68.237.161.36 _ldap._tcp.33c5e987-35cd-49b4-a8f8-73c47f609a58.domains._msdcs.MYDOMAIN.COM
68.237.161.36 _ldap._tcp.dc._msdcs.STUDENT.MYDOMAIN.COM
68.237.161.36 _ldap._tcp.pdc._msdcs.STUDENT.MYDOMAIN.COM
68.237.161.36 isatap.MYDOMAIN.COM
68.237.161.36 pltwlap10.STUDENT.MYDOMAIN.COM
68.237.161.37 %5e%5estore_domain%5e%5e.STUDENT.MYDOMAIN.COM
68.237.161.37 _ldap._tcp.33c5e987-35cd-49b4-a8f8-73c47f609a58.domains._msdcs.MYDOMAIN.COM
68.237.161.37 _ldap._tcp.dc._msdcs.STUDENT.MYDOMAIN.COM
68.237.161.37 isatap.MYDOMAIN.COM
68.237.161.37 pltwlap10.STUDENT.MYDOMAIN.COM
68.237.161.38 %5e%5estore_domain%5e%5e.MYDOMAIN.COM
68.237.161.38 _ldap._tcp.33c5e987-35cd-49b4-a8f8-73c47f609a58.domains._msdcs.MYDOMAIN.COM
68.237.161.38 _ldap._tcp.dc._msdcs.STUDENT.MYDOMAIN.COM
68.237.161.38 isatap.MYDOMAIN.COM
68.237.161.38 pltwlap10.STUDENT.MYDOMAIN.COM
68.237.161.39 _ldap._tcp.33c5e987-35cd-49b4-a8f8-73c47f609a58.domains._msdcs.MYDOMAIN.COM
68.237.161.39 _ldap._tcp.dc._msdcs.STUDENT.MYDOMAIN.COM
68.237.161.39 _ldap._tcp.pdc._msdcs.STUDENT.MYDOMAIN.COM
68.237.161.40 _kerberos._tcp.dc._msdcs.STUDENT.MYDOMAIN.COM
68.237.161.40 _ldap._tcp.33c5e987-35cd-49b4-a8f8-73c47f609a58.domains._msdcs.MYDOMAIN.COM
68.237.161.40 _ldap._tcp.dc._msdcs.STUDENT.MYDOMAIN.COM
68.237.161.40 isatap.MYDOMAIN.COM
68.237.161.40 pltwlap10.STUDENT.MYDOMAIN.COM
68.87.71.227 STAFF02.MYDOMAIN.COM
68.87.71.228 STAFF02.MYDOMAIN.COM
68.87.71.232 STAFF02.MYDOMAIN.COM
68.87.71.232 isatap.MYDOMAIN.COM
68.87.71.232 wpad.MYDOMAIN.COM
71.243.0.36 %5e%5estore_domain%5e%5e.MYDOMAIN.COM
71.243.0.36 Grant1.MYDOMAIN.COM
71.243.0.36 OWNER-PC.MYDOMAIN.COM
71.243.0.36 SPEDLT11.MYDOMAIN.COM
71.243.0.36 STAFF02.MYDOMAIN.COM
71.243.0.36 _kerberos._tcp.dc._msdcs.MYDOMAIN.COM
71.243.0.36 _ldap._tcp.33c5e987-35cd-49b4-a8f8-73c47f609a58.domains._msdcs.MYDOMAIN.COM
71.243.0.36 _ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.MYDOMAIN.COM
71.243.0.36 _ldap._tcp.MYDOMAIN.COM
71.243.0.36 _ldap._tcp.dc._msdcs.MYDOMAIN.COM
71.243.0.36 _ldap._tcp.dc._msdcs.STUDENT.MYDOMAIN.COM
71.243.0.36 _ldap._tcp.e3ad7dba-7dab-4536-b71e-6636157e0cda.domains._msdcs.MYDOMAIN.COM
71.243.0.36 _ldap._tcp.pdc._msdcs.MYDOMAIN.COM
71.243.0.36 facebook.MYDOMAIN.COM
71.243.0.36 isatap.MYDOMAIN.COM
71.243.0.36 staffgpo.MYDOMAIN.COM
71.243.0.36 technas.MYDOMAIN.COM
71.243.0.36 wpad.MYDOMAIN.COM
71.243.0.37 Grant1.MYDOMAIN.COM
71.243.0.37 Grant6.MYDOMAIN.COM
71.243.0.37 SPEDLT11.MYDOMAIN.COM
71.243.0.37 _kerberos._tcp.dc._msdcs.STUDENT.MYDOMAIN.COM
71.243.0.37 _ldap._tcp.33c5e987-35cd-49b4-a8f8-73c47f609a58.domains._msdcs.MYDOMAIN.COM
71.243.0.37 _ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.MYDOMAIN.COM
71.243.0.37 _ldap._tcp.MYDOMAIN.COM
71.243.0.37 _ldap._tcp.dc._msdcs.MYDOMAIN.COM
71.243.0.37 _ldap._tcp.dc._msdcs.STUDENT.MYDOMAIN.COM
71.243.0.37 _ldap._tcp.e3ad7dba-7dab-4536-b71e-6636157e0cda.domains._msdcs.MYDOMAIN.COM
71.243.0.37 _ldap._tcp.pdc._msdcs.STUDENT.MYDOMAIN.COM
71.243.0.37 isatap.MYDOMAIN.COM
71.243.0.37 mms.MYDOMAIN.COM
71.243.0.37 pltwlap10.STUDENT.MYDOMAIN.COM
71.243.0.37 staffgpo.MYDOMAIN.COM
71.243.0.37 wpad.MYDOMAIN.COM
71.243.0.38 %5e%5estore_domain%5e%5e.STUDENT.MYDOMAIN.COM
71.243.0.38 Grant1.MYDOMAIN.COM
71.243.0.38 Grant6.MYDOMAIN.COM
71.243.0.38 OWNER-PC.MYDOMAIN.COM
71.243.0.38 SPEDLT11.MYDOMAIN.COM
71.243.0.38 STAFF02.MYDOMAIN.COM
71.243.0.38 _ldap._tcp.33c5e987-35cd-49b4-a8f8-73c47f609a58.domains._msdcs.MYDOMAIN.COM
71.243.0.38 _ldap._tcp.Default-First-Site-Name._sites.MYDOMAIN.COM
71.243.0.38 _ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.MYDOMAIN.COM
71.243.0.38 _ldap._tcp.MYDOMAIN.COM
71.243.0.38 _ldap._tcp.dc._msdcs.MYDOMAIN.COM
71.243.0.38 _ldap._tcp.dc._msdcs.STUDENT.MYDOMAIN.COM
71.243.0.38 _ldap._tcp.e3ad7dba-7dab-4536-b71e-6636157e0cda.domains._msdcs.MYDOMAIN.COM
71.243.0.38 _ldap._tcp.pdc._msdcs.MYDOMAIN.COM
71.243.0.38 _ldap._tcp.pdc._msdcs.STUDENT.MYDOMAIN.COM
71.243.0.38 isatap.MYDOMAIN.COM
71.243.0.38 pltwlap10.STUDENT.MYDOMAIN.COM
71.243.0.38 staffgpo.MYDOMAIN.COM
71.243.0.38 wpad.MYDOMAIN.COM
71.243.0.39 Grant1.MYDOMAIN.COM
71.243.0.39 MYdata.MYDOMAIN.COM
71.243.0.39 OWNER-PC.MYDOMAIN.COM
71.243.0.39 SPEDLT11.MYDOMAIN.COM
71.243.0.39 _kerberos._tcp.dc._msdcs.MYDOMAIN.COM
71.243.0.39 _kerberos._tcp.dc._msdcs.STUDENT.MYDOMAIN.COM
71.243.0.39 _ldap._tcp.33c5e987-35cd-49b4-a8f8-73c47f609a58.domains._msdcs.MYDOMAIN.COM
71.243.0.39 _ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.MYDOMAIN.COM
71.243.0.39 _ldap._tcp.MYDOMAIN.COM
71.243.0.39 _ldap._tcp.dc._msdcs.MYDOMAIN.COM
71.243.0.39 _ldap._tcp.dc._msdcs.STUDENT.MYDOMAIN.COM
71.243.0.39 _ldap._tcp.e3ad7dba-7dab-4536-b71e-6636157e0cda.domains._msdcs.MYDOMAIN.COM
71.243.0.39 _ldap._tcp.pdc._msdcs.MYDOMAIN.COM
71.243.0.39 isatap.MYDOMAIN.COM
71.243.0.39 mms.STUDENT.MYDOMAIN.COM
71.243.0.39 pltwlap10.STUDENT.MYDOMAIN.COM
71.243.0.39 staffgpo.MYDOMAIN.COM
71.243.0.39 wpad.MYDOMAIN.COM
71.250.0.36 Grant1.MYDOMAIN.COM
71.250.0.36 Grant6.MYDOMAIN.COM
71.250.0.36 OWNER-PC.MYDOMAIN.COM
71.250.0.36 SPEDLT11.MYDOMAIN.COM
71.250.0.36 _ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.MYDOMAIN.COM
71.250.0.36 _ldap._tcp.MYDOMAIN.COM
71.250.0.36 _ldap._tcp.dc._msdcs.MYDOMAIN.COM
71.250.0.36 _ldap._tcp.e3ad7dba-7dab-4536-b71e-6636157e0cda.domains._msdcs.MYDOMAIN.COM
71.250.0.36 _ldap._tcp.pdc._msdcs.MYDOMAIN.COM
71.250.0.36 isatap.MYDOMAIN.COM
71.250.0.36 staffgpo.MYDOMAIN.COM
71.250.0.36 wpad.MYDOMAIN.COM
71.250.0.37 Grant1.MYDOMAIN.COM
71.250.0.37 SPEDLT11.MYDOMAIN.COM
71.250.0.37 _kerberos._tcp.dc._msdcs.MYDOMAIN.COM
71.250.0.37 _ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.MYDOMAIN.COM
71.250.0.37 _ldap._tcp.MYDOMAIN.COM
71.250.0.37 _ldap._tcp.dc._msdcs.MYDOMAIN.COM
71.250.0.37 _ldap._tcp.e3ad7dba-7dab-4536-b71e-6636157e0cda.domains._msdcs.MYDOMAIN.COM
71.250.0.37 _ldap._tcp.pdc._msdcs.MYDOMAIN.COM
71.250.0.37 facebook.MYDOMAIN.COM
71.250.0.37 isatap.MYDOMAIN.COM
71.250.0.37 staffgpo.MYDOMAIN.COM
71.250.0.37 technas.MYDOMAIN.COM
71.250.0.37 wpad.MYDOMAIN.COM
71.250.0.38 Grant1.MYDOMAIN.COM
71.250.0.38 OWNER-PC.MYDOMAIN.COM
71.250.0.38 SPEDLT11.MYDOMAIN.COM
71.250.0.38 STAFF02.MYDOMAIN.COM
71.250.0.38 _ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.MYDOMAIN.COM
71.250.0.38 _ldap._tcp.dc._msdcs.MYDOMAIN.COM
71.250.0.38 _ldap._tcp.e3ad7dba-7dab-4536-b71e-6636157e0cda.domains._msdcs.MYDOMAIN.COM
71.250.0.38 staffgpo.MYDOMAIN.COM
71.250.0.38 wpad.MYDOMAIN.COM
71.250.0.39 Grant1.MYDOMAIN.COM
71.250.0.39 Grant6.MYDOMAIN.COM
71.250.0.39 MYdata.MYDOMAIN.COM
71.250.0.39 OWNER-PC.MYDOMAIN.COM
71.250.0.39 SPEDLT11.MYDOMAIN.COM
71.250.0.39 STAFF02.MYDOMAIN.COM
71.250.0.39 _ldap._tcp.Default-First-Site-Name._sites.MYDOMAIN.COM
71.250.0.39 _ldap._tcp.MYDOMAIN.COM
71.250.0.39 _ldap._tcp.dc._msdcs.MYDOMAIN.COM
71.250.0.39 _ldap._tcp.e3ad7dba-7dab-4536-b71e-6636157e0cda.domains._msdcs.MYDOMAIN.COM
71.250.0.39 isatap.MYDOMAIN.COM
71.250.0.39 staffgpo.MYDOMAIN.COM
71.250.0.39 wpad.MYDOMAIN.COM
76.96.5.198 STAFF02.MYDOMAIN.COM
76.96.5.200 isatap.MYDOMAIN.COM
76.96.5.200 wpad.MYDOMAIN.COM
76.96.5.201 STAFF02.MYDOMAIN.COM
76.96.5.201 isatap.MYDOMAIN.COM
76.96.5.201 wpad.MYDOMAIN.COM
Now before anyone tells me to just DROP rule them in iptables, remember that many of these appear to be large commercial ISPs, so dropping them from both my master AND slave would prevent any legitimate queries from these ISPs as well. Mostly I just want to know what this is and/or make people aware of this, if it is an emerging exploit issue. Thanks! By the way, below is a sorted resolve for the IPs in the above list that actually have PTR records.
ns5a.townisp.com.
ns6.townisp.com.
ns7.townisp.com.
ns8.townisp.com.
town119.shrewsbury-ma.gov.
pxy06jcsntn.jcsn.tn.charter.com.
pxy07jcsntn.jcsn.tn.charter.com.
pxy05jcsntn.jcsn.tn.charter.com.
pxy01jcsntn.jcsn.tn.charter.com.
pxy02jcsntn.jcsn.tn.charter.com.
pxy03jcsntn.jcsn.tn.charter.com.
pxy04jcsntn.jcsn.tn.charter.com.
pxy01bycymi.bycy.mi.charter.com.
pxy03bycymi.bycy.mi.charter.com.
pxy02bycymi.bycy.mi.charter.com.
pxy04bycymi.bycy.mi.charter.com.
pxy01oxfrma.oxfr.ma.charter.com.
pxy02oxfrma.oxfr.ma.charter.com.
pxy03oxfrma.oxfr.ma.charter.com.
pxy04oxfrma.oxfr.ma.charter.com.
pxy05oxfrma.oxfr.ma.charter.com.
chlm-nrcns01.chelmsfdrdc2.ma.boston.comcast.net.
chlm-nrcns02.chelmsfdrdc2.ma.boston.comcast.net.
chlm-cns02.chelmsfdrdc2.ma.boston.comcast.net.
chlm-cns03.chelmsfdrdc2.ma.boston.comcast.net.
chlm-cns04.chelmsfdrdc2.ma.boston.comcast.net.