AV battle ground Attacks

#0 - April 5, 2010, 7:35 p.m.
Blizzard Post
I played several BG's this Sunday and in the AV battle grounds I played on this character and my 52 rogue on this realm/faction I got scanned for open ports by some website in China.
I don't do porn, was not on any other sites and am Very security conscious
I use;
Ad-Aware
Spy bot Search & Destroy
Anti viral software
anti Root-kit software
Brows on Private browsing settings
and clean my browser's Everything, (cookies, history, etc.) after each use.

So with that in mind it becomes likely that these two sites latched on to me While I was In the AV BG.
IF you can make use of this info to get these people to stop attacking us players,
Here is their particulars starting with the log entries of my firewall showing their predatory behavior;
Q u o t e:

-------------------------------------------------
4/5/2010 3:26:56 AM Intruder address: 221.192.199.35, subnet blocked Blocked by IDS
4/5/2010 3:26:56 AM Detected 16415, 11292, 14340, 36895, 14348, 20480 port(s) scanning from 221.192.199.35 SCAN

4/4/2010 6:18:36 PM Intruder address: 125.45.109.196, subnet blocked Blocked by IDS
4/4/2010 6:18:36 PM Detected 38175, 14340, 44556, 36895, 50980, 14348 port(s) scanning from 125.45.109.196 SCAN

4/4/2010 3:05:41 PM Intruder address: 221.192.199.35, subnet blocked Blocked by IDS
4/4/2010 3:05:41 PM Detected 16415, 11292, 14340, 36895, 14348, 20480 port(s) scanning from 221.192.199.35 SCAN

4/4/2010 2:00:44 PM Intruder address: 125.45.109.196, subnet blocked Blocked by IDS
4/4/2010 2:00:44 PM Detected 38175, 14340, 44556, 36895, 50980, 14348 port(s) scanning from 125.45.109.196 SCAN

=======================================================================================
Using, (for 'whois' info);
https://dns.l4x.org/
=============================

Using server whois.apnic.net.
Query string: "-V Md4.7 221.192.199.35"

% APNIC found the following authoritative answer from: whois.apnic.net

inetnum: 221.192.0.0 - 221.195.255.255
netname: UNICOM-HE
descr: China Unicom Hebei Province Network
descr: China Unicom
country: CN
admin-c: CH1302-AP
tech-c: KL984-AP
remarks: service provider
mnt-by: APNIC-HM
mnt-lower: MAINT-CNCGROUP-HE
mnt-routes: MAINT-CNCGROUP-RR
status: ALLOCATED PORTABLE
remarks: -+-+-+-+-+-+-+-+-+-+-+-++-+-+-+-+-+-+-+-+-+-+-+-+-+-+
remarks: This object can only be updated by APNIC hostmasters.
remarks: To update this object, please contact APNIC
remarks: hostmasters and include your organisation's account
remarks: name in the subject line.
remarks: -+-+-+-+-+-+-+-+-+-+-+-++-+-+-+-+-+-+-+-+-+-+-+-+-+-+
changed: [email protected] 20040329
changed: [email protected] 20060124
changed: [email protected] 20060125
changed: [email protected] 20080314
changed: [email protected] 20090508
source: APNIC

route: 221.192.0.0/14
descr: CNC Group CHINA169 Hebei Province Network
country: CN
origin: AS4837
mnt-by: MAINT-CNCGROUP-RR
changed: [email protected] 20060118
source: APNIC

person: ChinaUnicom Hostmaster
nic-hdl: CH1302-AP
e-mail: abuse@chinaunic#%#*%@#@@%#@%**!#%@#!#%@!!
address: No.21,Jin-Rong Street
address: Beijing,100140
address: P.R.China
phone: +86-10-66259940
fax-no: +86-10-66259764
country: CN
changed: abuse@chinaunic#%#*%@#@@%#@%**!#%@#!#%@!! 20090408
mnt-by: MAINT-CNCGROUP
source: APNIC

person: Kong Lingfei
nic-hdl: KL984-AP
e-mail: konglf5@chinaunic#%#*%@#@@%#@%**!#%@#!#%@!!
address: 45, Guang An Street, Shi Jiazhuang City, HeBei Province,050011,CN
phone: +86-311-86681601
fax-no: +86-311-86689210
country: cn
changed: konglf5@chinaunic#%#*%@#@@%#@%**!#%@#!#%@!! 20090206
mnt-by: MAINT-CNCGROUP-HE
source: APNIC
-----------------------------------------------------------------
HTTP Port 80 Reply

Content-length: 1193
Content-location: http://221.192.199.35/iisstart.htm
X-powered-by: ASP.NET
Accept-ranges: bytes
Server: Microsoft-IIS/6.0
Last-modified: Fri, 21 Feb 2003 12:15:52 GMT
Connection: close
Etag: "0ce1f9a2d9c21:a4f"
Date: Mon, 05 Apr 2010 18:10:06 GMT
Content-type: text/html
=======================================================================================


Whois for 125.45.109.196

From server whois.ripe.net 0 minutes ago:

Using server whois.apnic.net.
Query string: "-V Md4.7 125.45.109.196"

% APNIC found the following authoritative answer from: whois.apnic.net

inetnum: 125.40.0.0 - 125.47.255.255
netname: UNICOM-HA
descr: China Unicom Henan province network
descr: China Unicom
country: CN
admin-c: CH1302-AP
tech-c: WW444-AP
mnt-by: APNIC-HM
mnt-lower: MAINT-CNCGROUP-HA
mnt-routes: MAINT-CNCGROUP-RR
status: ALLOCATED PORTABLE
remarks: -+-+-+-+-+-+-+-+-+-+-+-++-+-+-+-+-+-+-+-+-+-+-+-+-+-+
remarks: This object can only be updated by APNIC hostmasters.
remarks: To update this object, please contact APNIC
remarks: hostmasters and include your organisation's account
remarks: name in the subject line.
remarks: -+-+-+-+-+-+-+-+-+-+-+-++-+-+-+-+-+-+-+-+-+-+-+-+-+-+
changed: [email protected] 20051011
changed: [email protected] 20051020
changed: [email protected] 20090507
changed: [email protected] 20090508
source: APNIC

route: 125.40.0.0/13
descr: CNC Group CHINA169 Henan Province Network
country: CN
origin: AS4837
mnt-by: MAINT-CNCGROUP-RR
changed: [email protected] 20060118
source: APNIC

person: ChinaUnicom Hostmaster
nic-hdl: CH1302-AP
e-mail: abuse@chinaunic#%#*%@#@@%#@%**!#%@#!#%@!!
address: No.21,Jin-Rong Street
address: Beijing,100140
address: P.R.China
phone: +86-10-66259940
fax-no: +86-10-66259764
country: CN
changed: abuse@chinaunic#%#*%@#@@%#@%**!#%@#!#%@!! 20090408
mnt-by: MAINT-CNCGROUP
source: APNIC

person: Wei Wang
nic-hdl: WW444-AP
e-mail: [email protected].#%#*%@#@@%#@%**!#%@#!#%@!!
address: #55 San Quan Road, Zhengzhou, Henan Provice
phone: +86-371-65952358
fax-no: +86-371-65968952
country: CN
changed: [email protected] 20100305
mnt-by: MAINT-CNCGROUP-HA
source: APNIC

#2 - April 5, 2010, 7:45 p.m.
Blizzard Post
It's likely a coincidence that you were in Alterac Valley when this occurred, Iradiatic; however, I encourage you to forward this information on to our Hacks team at [email protected].

Thanks for the report!