Tag: ban

no-reverse-dns-configured.com: Research, Ban

no-reverse-dns-configured.com is a content spammer, and I need to eliminate him from hitting my site. Here are the details required to ban him. If these strict IPs are not sufficient then ban the range.

I did not ban the AWS ranges because IPs usually come up with AWS host names, and I ban them already.

Observation:
80.82.65.82 no-reverse-dns-configured.com
89.248.166.157 no-reverse-dns-configured.com 2016-oct-10
93.174.93.133 no-reverse-dns-configured.com

Research:
89.248.163.0 – 89.248.175.255 89.248.163.0/20 Quasi SEYCHELLES
no-reverse-dns-configured.com 89.248.163.117
no-reverse-dns-configured.com 89.248.164.157
no-reverse-dns-configured.com 89.248.164.166
no-reverse-dns-configured.com 89.248.166.131
no-reverse-dns-configured.com 89.248.166.136
no-reverse-dns-configured.com 89.248.168.135
no-reverse-dns-configured.com 89.248.168.128
no-reverse-dns-configured.com 89.248.168.219
no-reverse-dns-configured.com 89.248.169.61
no-reverse-dns-configured.com 89.248.171.131
no-reverse-dns-configured.com 89.248.172.91
no-reverse-dns-configured.com 89.248.172.14

hn.kd.ny.adsl: Research, Ban

This guy hn.kd.ny.adsl seems innocent enough, until I tried to look him up, only to find no positive IP address. Others have posted that they, too, cannot find his IP address in order to ban him. Hmmm, let me track him down.

This hacker is prolific in that he rarely repeats the third octet, making it harder to ban by a narrower range. You’ll need to go up to the second octet to cover his IP ranges. He uses predominantly China Unicom Henan. Only once did he go to China Unicon Fujian, which might just be an outlier data point.

zomro.com Content Scraper: Research, Ban

midex.zomro.com scrapes my site for awstat tags. I do not know why, and they do it multiple times. It is very annoying.

There is a ransomware listing for crasher121.zomro.com 93.170.169.52. There are other comments such as “109.248.33.212 is involved in malware incidents, spamming activity, ssh attacks, ddos” so caution is required. I did not research zomro.net, as I do not know if the .com and .net sites are related.

Observation:
midex.zomro.com
178.159.39.142 anconsul.ru 2016-nov-06 zomro

Research:
midex.zomro.com 93.171.158.189 93.171.158.0 – 93.171.159.255 93.171.158.0/23
elk91.zomro.com 93.171.158.47

midex.zomro.com 93.170.141.97 93.170.141.0/24

zuahbbazek1.zomro.com 93.170.253.11 93.170.253.0/24

ipredator.se: Research, Ban

ipredator.se is a Swedish VPN service that is comment spamming my site.

Observation:
anon-48-125.vpn.ipredator.se 46.246.32.0 – 46.246.63.255 PrivActually
host anon-44-42.vpn.ipredator.se 46.246.44.42
exit1.ipredator.se 197.231.221.211 CYBERDYNE Monrovia I did not realize that I had banned this before. If this changes I will hunt it down again. There are a few IPs that have used this host name. They continue to content scrape me.
anon-45-30.vpn.ipredator.se 46.246.45.30
anon-47-29.vpn.ipredator.se 46.246.47.29

Pattern:
Add 46.246. to the two octets in the host name.

Research
anon-39-1.vpn.ipredator.se 46.246.39.1
anon-42-1.vpn.ipredator.se 46.246.42.1
anon-37-1.vpn.ipredator.se 46.246.37.1
anon-55-1.vpn.ipredator.se 46.246.55.1
Anon-53-30.vpn.ipredator.se 46.246.53.30
anon-40-38.vpn.ipredator.se 46.246.40.38
anon-47-246.vpn.ipredator.se 46.246.47.246
anon-172-19.vpn.ipredator.se 93.182.172.19

fix-website-errors.com by Semalt: Research, Ban

fix-website-errors.com is a new content scraper campaign from Semalt. It follows from the keywords-monitoring-your-success.com and free-video-tool.com campaign, which I have already banned. That botnet was huge. They involved virtua in Brazil as well. Damn them.

Anyway, they hit your site, you track them down, ban them, rinse and repeat.

bb.sky.com Content Scraper: Research, Ban

bb.sky.com is a regular content scraper on my site, so I have decided to track them down. I finally figured out their hex IP address, so I can target ranges better.

Sky is a very large TV and internet provider in the Uk. They have a huge range of IPs.

Site hits:
5ad4e517.bb.sky.com 90.212.229.12 90.212.0.0 – 90.213.255.255
027e2f4c.bb.sky.com 2.126.47.76 2.126.0.0 – 2.126.255.255
5ad00af4.bb.sky.com 90.208.10.244 90.208.0.0 – 90.209.255.255
b0fb523c.bb.sky.com 176.251.82.60 176.248.0.0 – 176.251.255.255

megared.net.mx: Research, Ban

This is part of the keywords-monitoring-your-success.com, free-video-tool.com Semalt Botnet that spread to other South American hosts, but they have changed the referrer name slightly to keywords-monitoring-success.com. This host is tricky because they only provide the last 2 octets of the IP address, leaving me to guess the first two.

Here is my clue: customer-qro-199-67.megared.net.mx

There are clues to the same pattern used by megared.net.mx, using a variety of new 2 initial octets combined with the last 2 from the host name. While I only have this one IP as a content scraper, their reputation is one of an email spammer. I guess they moved into a newer but related business model.