Category: Tech

clientshostname.com Content Scraper: Research, Ban

customer.clientshostname.com scraped me, and the name is very generic, so I thought to research it. clientshostname.com has a lot of customer names prepended to it, so this excludes all their names. Three IP ranges should do you.

Observed:
customer.clientshostname.com

Research:
93.170.13.233 93.170.13.0/24
93.170.13.212
93.170.13.205
104.193.252.10 104.193.252.0/24
104.193.252.1
104.193.252.0
185.104.8.50 185.104.8.0 – 185.104.11.255 UK-KSERVERS
185.104.8.56
185.104.8.52
185.104.8.52
185.104.8.50
185.104.8.126
185.104.9.38
185.104.9.38
185.104.9.37
185.104.9.37
185.104.9.246
185.104.9.236
185.104.9.236
185.104.9.230
185.104.9.228
185.104.10.80
185.104.10.6
185.104.10.17
185.104.10.11
185.104.11.255
185.104.11.195
185.104.11.195
185.104.11.195
185.104.11.143
185.104.11.130
185.104.11.130
185.130.104.134
204.155.31.255
213.180.204.213

blizoo.bg Content Scraper: Research, Ban

c8fb265ea92a.softphone.blizoo.bg scraped me, but this one is tough.

Observation:
c8fb265ea92a.softphone.blizoo.bg

Research:
0024d19b1333.softphone.blizoo.bg 84.252.31.0 0.36.209.155.19.51 84.252.0.0 – 84.252.63.255 84.252.0.0/18 Blizoo BG
001e6beed8e8.softphone.blizoo.bg 84.252.53.172
0024d1956637.Softphone.Blizoo.Bg 85.130.17.48 85.130.0.0 – 85.130.128.255 85.130.0.0/17

c8fb265ea1a7.softphone.blizoo.bg 130.204.57.130 130.204.0.0 – 130.204.255.255 130.204.0.0/16 BLIZOO Bg
002624ab99a0.softphone.blizoo.bg 130.204.81.53
38c85cd6f4bc.softphone.blizoo.bg 130.204.85.1
00252e5ee5e4.softphone.blizoo.bg 130.204.103.4
a4a24a37efd3.softphone.blizoo.bg 130.204.116.226
00252ea84d9b.softphone.blizoo.bg 130.204.143.1 0.37.46.168.77.155
602ad0d8f8b1.softphone.blizoo.bg 130.204.169.1
a4a24a394b91.softphone.blizoo.bg 130.204.243.142

direcway.com Content Scraper: Research, Ban

host671420043112.direcway.com is a whisper bot that content scraped me. They are unique in that their hostname is somewhat ambiguous, making machine reading more difficult. All octets can be 2 or 3 digits long, allowing for much ambiguity.

whisper is a very much hated botnet that continues to attack my site, one ip at a time, small but relentless.

Observation:
host671420043112.direcway.com predicted IP is 67.142.112.43

Pattern:
The host name has all of the IP digits but is ambiguous. The first octet can be either 2 or 3 digits, so look at their IP ranges. The third and fourth octets are reversed. The third octet has a prepended “00”.

secured-by.zenmate.com: Research, Ban

secured-by.zenmate.com did nothing suspcious, but it did pique my interest, so I did the research.

Observations:
37.58.52.47
37.58.52.107
46.165.234.134
91.109.30.104
91.109.30.91
108.59.8.208 108.59.0.0 – 108.59.15.255 108.59.0.0/20 LEASEWEB
108.59.8.210
108.59.8.218
108.59.10.153
178.162.199.130
178.162.208.142
178.162.216.34
179.43.147.123
179.43.147.205
179.43.147.219
179.43.159.89
179.43.169.28
192.96.205.133
199.115.118.81
199.115.118.83
207.244.72.200
207.244.72.222
207.244.72.228
207.244.77.1
207.244.77.10
207.244.77.4
207.244.77.9
207.244.77.45
207.244.78.12
207.244.79.129
207.244.79.131 linked with referrer kwpublisher
207.244.83.102
207.244.83.206
de51.node.zenmate.io 46.165.208.228
207.244.79.153 secured-by.zenmate.com

network-consulting.fr Content Spammer: Research, Ban

network-consulting.fr had content spammed me, so I looked them up. They are interesting with its host name usage. if they spam me again i will be ready.

79.98.16.0 – 79.98.23.255 Network Consulting Fr

Observation:
f79.ip.network-consulting.fr My educated guess is 79.98.21.79

Pattern:
network-consulting.fr starts its “A” group from 79.98.16.0. Incrementing up the alphabet adds one number to the third octet, or third octet+. The first number of the host name is the fourth octet.

From this pattern they can go up to “H”

Research:
a20.ip.network-consulting.fr 79.98.16.20
a81.ip.network-consulting.fr 79.98.16.81
b248.ip.network-consulting.fr 79.98.17.248
c4.ip.network-consulting.fr 79.98.18.4
c17.ip.network-consulting.fr 79.98.18.17
c51.ip.network-consulting.fr 79.98.18.51
c61.ip.network-consulting.fr 79.98.18.61
c80.ip.network-consulting.fr 79.98.18.80
c165.ip.network-consulting.fr 79.98.18.165
d49.ip.network-consulting.fr 79.98.19.49

Wifi Off, Android Phone App Head Soccer Still able to Connect to Internet

Suspicious, we were, that Little Weed was burning through our internet bandwidth quota very quickly. Even with wifi off, how could this happen? Some Android apps have the ability to turn on wifi by themselves and communicate.

Little Weed noticed that one of his apps, Head Soccer, updated without his knowledge, so he asked to take the phone off our wifi network. This app, Head Soccer, has following permissions:

ztomy.com Content Spammer: Research, Ban

ns1648.ztomy.com has spammed me, but it has been difficult to track down and ban. The ips jump around like mexican jumping beans.

Observations:
I finally got a positive spam hit from 5.231.42.24. and then from 5.231.40.52.
5.41.178.9 ns1648.ztomy.com
5.62.21.221 ns1648.ztomy.com
23.27.250.179 ns1648.ztomy.com 2016-nov-17
104.144.22.219 ns1648.ztomy.com 2016-nov-08
104.144.28.122 ns1648.ztomy.com 2016-oct-12
104.144.28.155 ns1648.ztomy.com 2016-nov-20
184.83.3.154 ns1648.ztomy.com 2016-oct-25
193.169.144.179 ns1648.ztomy.com 2016-nov-20
193.169.144.221 ns1648.ztomy.com 2016-nov-17
193.169.144.230 ns1648.ztomy.com 2016-nov-20
193.169.144.241 ns1648.ztomy.com 2016-nov-20
193.169.144.243 ns1648.ztomy.com 2016-nov-20
193.169.144.247 ns1648.ztomy.com 2016-nov-20
202.51.195.38 ns1648.ztomy.com 2016-nov-16
204.188.238.39 ns1648.ztomy.com 2017-mar-13
205.211.138.134 ns1648.ztomy.com 2016-nov-04

Android Studio 2.1.2: Downgrading Gradle Versions

Damn, that was hard. Android Studio 2.1.2 is really a bitch to tame. I had not used AS for a while, so when I opened it I needed to upgrade, which I did. That is when the pain started. If you are using an older phone than Android v21 Lollipop then you will need add a lower version of gradle 2.10 to work.

The different versions of Android require different versions of gradle. Upgrade your android version and your gradle version will correspond. Upgrade Android Studio and you support and older version of Android spells trouble.

cable.net.co Content Scraper: Research, Ban

You never know what you will find in your travels. dynamic-ip-181500198200.cable.net.co was content scraping me, so I decided to target it. It is part of the large Semalt botnet that started with keywords-monitoring-your-success.com and free-video-tool.comand then continued with fix-website-errors, with a sprinkling of buttons-for-websites thrown in.

Its host name is unique in that it is numerically very long. I could see remnants of a decimal IP address, but there was something odd.

Their pattern is not as predictable as required by a computer but that is precisely the point: They want to fool anti-bot software, but allow their admin staff to figure it out. If staff have a couple of errors it is no problem.

unassigned.psychz.net Comment Spammer: Research, Ban

unassigned.psychz.net spammed me, so I tracked them down. They use a lot of various IP ranges.

They have a hostname lookup of host 199.15.112.8 199.15.112.0 – 199.15.119.255 199.15.112.0/21 but this hostname has been used for so many more IPs.

Research:
23.91.13.35
23.228.228.142

45.35.1.10 45.34.0.0 – 45.35.255.255 45.34.0.0/15
45.34.0.0 – 45.35.105.255 45.35.0.0/18 45.35.64.0/19 45.35.96.0/21 45.35.104.0/23
45.35.71.119
45.35.75.57
45.35.90.36
45.35.90.36
45.35.105.172

66.249.75.140
66.249.75.231

74.117.56.250 74.117.56.0 – 74.117.63.255 74.117.56.0/21
74.117.58.193
74.117.62.54
74.117.62.54

107.160.192.167

108.171.240.170 108.171.240.0 – 108.171.255.255 108.171.240.0/20
108.171.240.86
108.171.240.86
108.171.255.189

173.224.209.59 173.224.208.0 – 173.224.223.255 173.224.208.0/20
173.224.211.52
173.224.218.223
173.224.218.223
173.224.218.83

174.132.240.146

192.168.10.202 192.168.0.0 – 192.168.255.255 192.168.0.0/16