Author Archives: dontai

vnpt.vn Content Scraper: Research, Ban

static.vnpt.vn does not resolve as a host name, and as they scraped me I will track them down. They are pretty tricky. One of their tactics is that they use the host name “localhost”, which looks odd in the access log. Tech staff cannot find the actual IP address.

As I work with these IP ranges it is clear that this content scraper is doing a real detriment to Viet Nam. The use of his IPs would force me to pretty much ban the whole country. As an emerging country this would be very bad for Viet Nam, all for the greed and selfishness of a single bot maker. I know that there are no morals with stealing content, as with thieves, but at this stage of Viet Nam’s development this bot maker could easily damage the country.

dps.gov.co Content Scraper: Research, Ban

lyncdiscover.dps.gov.co has nothing to do with the Government of Columbia, and a good thing, because it is a content scraper bot.

dps.gov.co is the Departamento para la Prosperidad Social, part of the Columbian Government. I am unsure how a content scraper got hold of a Columbian Government extent, legally.

As this is a Government site I have contacted their tech contact, but they do not look too sophisticated. At least I have done my part to try to stop this abuse of the dps.gv.co host name.

Research:
186.170.31.134 186.170.0.0 /15 COLOMBIA TEL
186.170.31.134
186.170.31.134

hdesknet.com.br Content Scraper: Research, Ban

pool.hdesknet.com.br is part of the fix-website-errors.com by Semalt SEO content scraper campaign, huge and very annoying. I wish they would just stop scraping my site. This botnet is huge and does not seem to want to end. It started with keywords-monitoring-success and free-video-tool.com, which then involved Virtua and megared.net.mx. The vast majority of these content scraper bots reside in Brazil and South America, but there are others from Italy and the US.

Thankfully, only one ip range kills this.

Observed:
pool.hdesknet.com.br

Research:
177.67.176.0 177.67.176.0 – 177.67.183.255 177.67.176.0/21 HELP DESK Br
177.67.176.129
177.67.176.131
177.67.177.192
177.67.177.0
177.67.177.228
177.67.178.1
177.67.178.88
177.67.178.158
177.67.178.158
177.67.179.126
177.67.179.167
177.67.179.181

boostgram.com security risk: Research, Ban

boostgram.com tried to crack my site security. I need him disabled. Boostgram is hosted by Digital Ocean, which hosts a lot of spamming sites.

Observation:
production.ap.3393bc.boostgram.com 159.203.202.54

51.147.188

Research:
production.ap.9612d3.boostgram.com 104.131.9.204 104.131.0.0 – 104.131.255.255 104.131.0.0/16
150.18.211.
production.ap.90c84e.boostgram.com 104.131.156.149 144.200.78.
production.ap.970190.boostgram.com 104.131.192.0/19

production.ap.831aab.boostgram.com 104.236.7.133 104.236.0.0 – 104.236.255.255 104.236.0.0/16
131.26.171.
production.ap.9b51e1.boostgram.com 104.236.9.104 155.81.225.
production.ap.ecaad3.boostgram.com 104.236.88.116 236.170.211.
production.ap.3880c0.boostgram.com 104.236.94.135
production.ap.777b50.boostgram.com 104.236.199.226
production.ap.136571.boostgram.com 104.236.254.46

production.ap.e06883.boostgram.com 107.170.4.120 107.170.0.0 – 107.170.255.255 107.170.0.0/16
production.ap.73d069.boostgram.com 107.170.36.72
production.ap.67b6b3.boostgram.com 107.170.115.31
production.ap.f9906e.boostgram.com 107.170.219.111

production.ap.3393bc.boostgram.com 159.203.202.54 159.203.0.0 – 159.203.255.255 159.203.0.0/16
production.ap.c648f2.boostgram.com 159.203.218.94
production.ap.08ccaf.boostgram.com 159.203.245.132
production.ap.9d13a2.boostgram.com 159.203.207.1

sl-reverse.com Content Scraper: Research, Ban

sl-reverse.com is a content spammer that is creeping into my site and I want it stopped. I’ll hunt them down and ban them. Sl-reverse also uses servers in Canada, Germany, Singapore, Japan and Italy, to name a few.

If they botnet my butt I will get more aggressive on them.

Observations:
fa.f7.a86c.ip4.static.sl-reverse.com 108.168.247.250

6.1f.5177.ip4.static.sl-reverse.com 119.81.31.6 119.81.31.0/24 SOFTLAYER
6.1f.5177.ip4.static.sl-reverse.com 119.81.31.6
59.7c.5177.ip4.static.sl-reverse.com 119.81.124.89
12.87.5177.ip4.static.sl-reverse.com 119.81.135.18
93.fa.5177.ip4.static.sl-reverse.com 119.81.250.147
39.f8.5177.ip4.static.sl-reverse.com 119.81.248.57
8b.f9.5177.ip4.static.sl-reverse.com 119.81.249.139
d6.fd.5177.ip4.static.sl-reverse.com 119.81.253.214

e6.96.089f.ip4.static.sl-reverse.com 159.8.150.230
d7.85.7a9f.ip4.static.sl-reverse.com 159.122.133.215 159.122.133.0/24 SOFTLAYER
d7.85.7a9f.ip4.static.sl-reverse.com 159.122.133.215
a6.48.caa1.ip4.static.sl-reverse.com 161.202.72.166
a.06.01a8.ip4.static.sl-reverse.com 168.1.6.10
d6.35.01a8.ip4.static.sl-reverse.com 168.1.53.214
70.17.01a8.ip4.static.sl-reverse.com 168.1.23.112
34.4b.01a8.ip4.static.sl-reverse.com 168.1.75.52
db.63.01a8.ip4.static.sl-reverse.com 168.1.99.219
fa.f7.a86c.ip4.static.sl-reverse.com 168.108.247.250
d8.00.39a9.ip4.static.sl-reverse.com 169.57.0.216
a0.67.b9d8.ip4.static.sl-reverse.com 216.185.103.160

hn.kd.dhcp Content Spammer: Research, Ban

hn.kd.dhcp is spamming my site, so I need to remove it. This guy has been around for quote a while and has a long list of IPs, but not so long a list of IP ranges. This spammer runs out of Henan Province, China, but has used Jilin, Chongqing, Guangdong, and Shanghai

These may be related: hn.kd.ny.adsl; hn.ly.kd.adsl; hn.kd.dhcp

Observation:
61.52.253.116 hn.kd.dhcp 2017-jan-04
61.54.208.158 hn.kd.dhcp
61.54.208.235 hn.kd.dhcp 2016-oct-06
61.54.209.51 hn.kd.dhcp

Research:
61.52.9.239 61.52.0.0 – 61.53.255.255 61.52.0.0/15 China Unicom Henan
61.52.28.157
61.52.53.10
61.52.74.18
61.52.100.71
61.52.168.1
61.52.198.139
61.52.207.172
61.52.232.29
61.53.1.241
61.53.5.165
61.53.25.9
61.53.65.52
61.53.64.37
61.53.64.37
61.53.65.54
61.53.65.54
61.53.65.54
61.53.67.14
61.53.73.0
61.53.86.244
61.53.92.65
61.53.143.179
61.53.143.179
61.53.143.179
61.53.152.179
61.53.153.90
61.53.153.90
61.53.160.28
61.53.185.170
61.53.193.169
61.53.194.0
61.53.203.0
61.53.235.197

Bamboozled by Spoons

Seven bamboo utensils, 3 spatulas, 3 spoons and maybe a pasta scooper, purchased in Toronto, Canada. What are their purposes and why so many? I will think about them. Photo by Don Tai

Seven bamboo utensils, 3 spatulas, 3 spoons and maybe a pasta scooper, purchased in Toronto, Canada. What are their purposes and why so many? I will think about them. Photo by Don Tai

Mum offered me some spoons, which I did not really think about. After all, what is there to now about spoons. As with all simple things in life, they are not so simple once you dig into them. How many types of spoons can there be? Lots. What the purpose of the spoon with the round hole in it?

unassigned.calpop.com: Research, Ban

unassigned.calpop.com is a comment spammer, small yes, but still needs removal. They change this hostname’s IP a lot and move between different companies such as Calpop, CoreExpress, AirlineReservations.Com, and ATMLINK. They are out of Los Angeles. I am unsure if calpop.com is still in business, as Yelp postings suggest they are now closed. Their bot is still somehow finding electricity and connectivity to spam me, so the company and store die but the bot lives on…

Observations:
unassigned.calpop.com 64.27.17.140 2016-sept-14 referrer spam

no-reverse-dns-configured.com: Research, Ban

no-reverse-dns-configured.com is a content spammer, and I need to eliminate him from hitting my site. Here are the details required to ban him. If these strict IPs are not sufficient then ban the range.

I did not ban the AWS ranges because IPs usually come up with AWS host names, and I ban them already.

Observation:
80.82.65.82 no-reverse-dns-configured.com
89.248.166.157 no-reverse-dns-configured.com 2016-oct-10
93.174.93.133 no-reverse-dns-configured.com

Research:
89.248.163.0 – 89.248.175.255 89.248.163.0/20 Quasi SEYCHELLES
no-reverse-dns-configured.com 89.248.163.117
no-reverse-dns-configured.com 89.248.164.157
no-reverse-dns-configured.com 89.248.164.166
no-reverse-dns-configured.com 89.248.166.131
no-reverse-dns-configured.com 89.248.166.136
no-reverse-dns-configured.com 89.248.168.135
no-reverse-dns-configured.com 89.248.168.128
no-reverse-dns-configured.com 89.248.168.219
no-reverse-dns-configured.com 89.248.169.61
no-reverse-dns-configured.com 89.248.171.131
no-reverse-dns-configured.com 89.248.172.91
no-reverse-dns-configured.com 89.248.172.14

hn.kd.ny.adsl: Research, Ban

This guy hn.kd.ny.adsl seems innocent enough, until I tried to look him up, only to find no positive IP address. Others have posted that they, too, cannot find his IP address in order to ban him. Hmmm, let me track him down.

This hacker is prolific in that he rarely repeats the third octet, making it harder to ban by a narrower range. You’ll need to go up to the second octet to cover his IP ranges. He uses predominantly China Unicom Henan. Only once did he go to China Unicon Fujian, which might just be an outlier data point.