Jump to content

Recommended Posts

Posted

Hi guys

 

Strange one here and I'm not sure where this post should live...

 

One of my schools has asked me to trace an email previously and when I have done it for them this time the Originating IP is registered to the MoD.

I thought it was an error so did it again and got the same result.

 

Anyone seen anything like this before, and no, the email account the email was sent from does not belong to a MoD employee (that we know of anyways).

 

Email Header (possible identifying details removed):

Received: from he1pr01cu001.internal.outlook.com by

HE1PR02MB1068.eurprd02.prod.outlook.com with HTTP via

HE1PR01CA0006.EURPRD01.PROD.EXCHANGELABS.COM; Thu, 24 Mar 2016 20:06:26 +0000

Received: from HE1PR02MB1116.eurprd02.prod.outlook.com ([10.163.173.26]) by

HE1PR02MB1116.eurprd02.prod.outlook.com ([10.163.173.26]) with mapi id

15.01.0447.017; Thu, 24 Mar 2016 20:06:26 +0000

Content-Type: application/ms-tnef; name="winmail.dat"

Content-Transfer-Encoding: binary

From: [email protected]x

To: [email protected]x

Subject: Re: Tomorrow

Thread-Topic: Tomorrow

Thread-Index: AdGFI7NHVhYfeITVQSSHBVQ/mVB+UAA49+JJ

Date: Day, date Month Year Time

Message-ID:

References:

In-Reply-To:

Accept-Language: en-US

Content-Language: en-US

X-MS-Has-Attach:

X-MS-Exchange-Organization-SCL: -1

X-MS-TNEF-Correlator:

MIME-Version: 1.0

X-MS-Exchange-Organization-MessageDirectionality: Originating

X-MS-Exchange-Organization-AuthSource: HE1PR02MB1116.eurprd02.prod.outlook.com

X-MS-Exchange-Organization-AuthAs: Internal

X-MS-Exchange-Organization-AuthMechanism: 04

X-Originating-IP: [25.163.2.132]

X-MS-Exchange-Organization-Network-Message-Id: 88da2345-67c2-4cc2-d8b9-08d3541fc7f7

X-MS-Exchange-Organization-Antispam-Report: SFV:SKI;SCL:-1

X-Forefront-Antispam-Report: SFV:SKI;SCL:-1

Return-Path: [email protected]

X-MS-Exchange-Transport-EndToEndLatency: 00:00:01.3141764

 

Report from who.is on the Orginating IP:

[Querying whois.arin.net]

[Redirected to whois.ripe.net]

[Querying whois.ripe.net]

[whois.ripe.net]

% This is the RIPE Database query service.

% The objects are in RPSL format.

%

% The RIPE Database is subject to Terms and Conditions.

% See http://www.ripe.net/db/support/db-terms-conditions.pdf

 

% Note: this output has been filtered.

% To receive output for a database update, use the "-B" flag.

 

% Information related to '25.0.0.0 - 25.255.255.255'

 

% Abuse contact for '25.0.0.0 - 25.255.255.255' is '[email protected]'

 

inetnum: 25.0.0.0 - 25.255.255.255

netname: UK-MOD-19850128

country: GB

org: ORG-DMoD1-RIPE

admin-c: MN1891-RIPE

tech-c: MN1891-RIPE

status: LEGACY

mnt-by: UK-MOD-MNT

mnt-domains: UK-MOD-MNT

mnt-routes: UK-MOD-MNT

mnt-by: RIPE-NCC-LEGACY-MNT

created: 2005-08-23T10:27:23Z

last-modified: 2015-07-24T14:31:16Z

source: RIPE # Filtered

 

organisation: ORG-DMoD1-RIPE

org-name: UK Ministry of Defence

org-type: LIR

address: Not Published

address: Not Published

address: Not Published

address: UNITED KINGDOM

phone: +443067700816

admin-c: MN1891-RIPE

mnt-ref: UK-MOD-MNT

mnt-ref: RIPE-NCC-HM-MNT

mnt-by: RIPE-NCC-HM-MNT

abuse-c: MH12763-RIPE

created: 2004-04-17T12:18:23Z

last-modified: 2015-04-16T11:23:42Z

source: RIPE # Filtered

 

person: Mathew Newton

address: Network Technical Authority

address: UK Ministry of Defence

phone: +44 (0)30 677 00816

abuse-mailbox: [email protected]

nic-hdl: MN1891-RIPE

created: 2005-03-18T10:42:04Z

last-modified: 2014-01-17T14:55:29Z

source: RIPE # Filtered

mnt-by: UK-MOD-MNT

 

% Information related to '25.160.0.0/11AS203665'

 

route: 25.160.0.0/11

descr: UK Ministry of Defence

origin: AS203665

mnt-by: UK-MOD-MNT

created: 2015-11-25T11:02:00Z

last-modified: 2015-11-25T11:02:00Z

source: RIPE

 

% This query was served by the RIPE Database Query Service version 1.86 (DB-2)

 

I'm puzzled by this one, I really am. There is no obvious reason for this to be the source of this email.

Posted
The MoD used to own large IP address ranges. It could simply be that WHOIS or whatever hasn't been updated to show the new owner information for that address.
Posted
The MoD used to own large IP address ranges. It could simply be that WHOIS or whatever hasn't been updated to show the new owner information for that address.

 

Record is less than 6 months old, so doubt it.

 

Looks to me like they are using an MOD internet connection!

Posted
Record is less than 6 months old, so doubt it.

 

Looks to me like they are using an MOD internet connection!

 

I thought the same thing but I have no idea why. It's all very strange and I can't work it out.

Posted
I thought the same thing but I have no idea why. It's all very strange and I can't work it out.

 

Long shot, but partner/spouse serving and they live on barracks?

Posted
Yeah like JordanT91 said, it's a legacy IPv4 prefix that is/was owned by the UK MoD a lot of large companies and government organisations owned complete prefixes but have had to return them back to the pool as more IPv4 address are required by the ever increasing number of ISPs around the world. it may be that the MoD still owns it and leases segments out to ISPs but I think it's more likely that records of who owns it now haven't been updated.
Posted
LOL!!! You'd hope they don't set their reserve dns whois record - it would be like updating your LinkedIn with your promotion to double agent.
  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...