probable DDOS to 195.238.3.33

We're seeing packets with spoofed source addresses destined to
195.238.3.33 getting dropped on firewalls at several locations going
outbound. Googling has turned up nothing relating to that destination
IP address. Is anyone else seeing this? Anyone know what it is?

Thanks,
Tim

Went to Nic.com and got this:
OrgName: RIPE Network Coordination Centre
OrgID: RIPE
Address: Singel 258
Address: 1016 AB
City: Amsterdam
StateProv:
PostalCode:
Country: NL

NetRange: 195.0.0.0 - 195.255.255.255
CIDR: 195.0.0.0/8
NetName: RIPE-CBLK3
NetHandle: NET-195-0-0-0-1
Parent:
NetType: Allocated to RIPE NCC
NameServer: NS.RIPE.NET
NameServer: AUTH03.NS.UU.NET
NameServer: NS2.NIC.FR
NameServer: SUNIC.SUNET.SE
NameServer: MUNNARI.OZ.AU
NameServer: NS.APNIC.NET
Comment: These addresses have been further assigned to users in
Comment: the RIPE NCC region. Contact information can be found in
Comment: the RIPE database at whois.ripe.net
Comment:
RegDate: 1996-03-25
Updated: 1998-10-16

TechHandle: RIPE-NCC-ARIN
TechName: RIPE NCC Hostmaster
TechPhone: +31 20 535 4444
TechEmail: nicdb@ripe.net

OrgTechHandle: RIPE-NCC-ARIN
OrgTechName: RIPE NCC Hostmaster
OrgTechPhone: +31 20 535 4444
OrgTechEmail: nicdb@ripe.net

# ARIN WHOIS database, last updated 2003-02-09 20:00
# Enter ? for additional hints on searching ARIN's WHOIS database.

inetnum: 195.238.0.0 - 195.238.31.255
netname: SKYNET-B
descr: Belgacom Skynet SA/NV
descr: Internet access provider
descr: A subsidiary of BELGACOM SA/NV
country: BE

route: 195.238.0.0/19
descr: Belgacom Skynet SA/NV
origin: AS5432
notify: noc@skynet.be

$ host irc.skynet.be
irc.skynet.be. is an alias for chick.skynet.be.
chick.skynet.be. has address 195.238.0.13

Well, close... :stuck_out_tongue:

You might want to contact noc@skynet.be...

Regards,
Daniel

We're seeing packets with spoofed source addresses destined to
195.238.3.33 getting dropped on firewalls at several locations going
outbound. Googling has turned up nothing relating to that destination
IP address. Is anyone else seeing this? Anyone know what it is?

Thanks,
Tim

This should help

server ns1.skynet.be

Default Server: ns1.skynet.be
Address: 195.238.3.17

195.238.3.33

Server: ns1.skynet.be
Address: 195.238.3.17

Name: userspool1.skynet.be
Address: 195.238.3.33