free-109-108.mediaworksit.net has tried to crack my security so I thought it appropriate to track them down.
The host name only provides the third and fourth octet, leading one to gues the first two. As they have not repeated the third octet you will need to ban larger ranges.
Observation:
free-109-108.mediaworksit.net
Research:
free-112-5.mediaworksit.net 95.140.112.5 95.140.112.0 – 95.140.127.255 140.112.0/20
free-114-1.mediaworksit.net 95.140.114.0
free-124-110.mediaworksit.net 95.140.124.110
free-125-37.mediaworksit.net 95.140.125.37
free-125-62.mediaworksit.net 95.140.125.62
free-234-154.mediaworksit.net 109.111.234.154 109.111.234.0 – 109.111.237.255 109.111.234.0/22
free-235-194.mediaworksit.net 109.111.235.194
free-144-214.mediaworksit.net 178.254.144.214 178.254.128.0 – 178.254.191.255 178.254.128.0/18
free-148-194.mediaworksit.net 178.254.148.194
free-164-196.mediaworksit.net 178.254.164.196
free-167-14.mediaworksit.net 178.254.167.14
free-246-89.mediaworksit.net 178.253.246.89
free-249-30.mediaworksit.net 178.253.249.30
bot , Tech
ban , ban IP , internet security , ip address , mediaworksit , mediaworksit.net , research , spam , strategy , vpn
hoor.nullvpn.com was trying to crack my security, so I thought it good to research and ban them. They are using a VPN, but there are not many IP addresses.
Observed:
hoor.nullvpn.com 128.199.170.45
paladin.nullvpn.com
kodi.nullvpn.com 128.199.103.2
hermod.nullvpn.com 188.166.188.219
cooper.nullvpn.com 128.199.127.59
Research:
Nullvpn.com 104.24.114.17
game.nullvpn.com 116.251.210.113
loki.nullvpn.com 128.199.80.0 128.199.0.0 – 128.199.255.255 DigitalOcean
necro.nullvpn.com 128.199.86.38
aegis.nullvpn.com 128.199.124.10
ra.nullvpn.com 128.199.176.180
tios.nullvpn.com 128.199.194.237
nyx.nullvpn.com 128.199.225.142
kodi.nullvpn.com 128.199.103.2
eros.nullvpn.com 139.59.234.213
free-02.nullvpn.com 149.202.60.72
poseidon.nullvpn.com 188.166.178.67 188.166.0.0 – 188.166.255.255 EU-DIGITALOCEAN
zeus.nullvpn.com 188.166.178.103
demeter.nullvpn.com 188.166.184.105
tyr.nullvpn.com 188.166.184.163
hermod.nullvpn.com 188.166.188.219
float.nullvpn.com 188.166.189.38
dev.nullvpn.com 188.166.190.144
Permanent link to this post (85 words, 0 images, estimated 20 secs reading time)
bot , Tech
ban , ban IP , hoor.nullvpn.com , internet security , ip address , nullvpn.com , research , spam , strategy , vpn
h-65-167.a416.corp.bahnhof.se has content spammed by site, so I am looking to remove it. bahnhof.se and bahnhof.no are from Sweden.
Observed:
h-65-167.a416.corp.bahnhof.se 79.136.65.167
h-42-226.a357.priv.bahnhof.se 79.136.42.226
h-46-23.a165.priv.bahnhof.se 46.59.46.23
Research:
h-130-176.a2.corp.bahnhof.no 37.123.130.176 a2 = 162 37.123.128.0 – 37.123.191.255 37.123.128.0/18
h-253-21.a139.corp.bahnhof.se 5.150.253.21 5.150.192.0 – 5.150.255.255 5.150.192.0/18
h-130-176.a2.corp.bahnhof.no 37.123.130.176 37.123.128.0 – 37.123.191.255 37.123.128.0/18
h-62-152.a213.priv.bahnhof.se 46.59.62.152 46.59.0.0 – 46.59.128.255 46.59.0.0/17
h-42-226.a357.priv.bahnhof.se 79.136.42.226 79.136.0.0 – 79.136.128.255 79.136.0.0/17
h-53-173.a157.priv.bahnhof.se 79.136.53.173
h-65-174.a416.corp.bahnhof.se 79.136.65.174
h-184-90.a322.priv.bahnhof.se 81.170.184.90 81.170.128.0 – 81.170.255.255 81.170.128.0/17
h-234-136.a189.priv.bahnhof.se 81.170.234.136
h-236-56.a193.priv.bahnhof.se 81.170.236.56
H-249-146.a175.corp.bahnhof.se 81.170.249.146
h-129-203.a328.priv.bahnhof.se 85.24.129.203 85.24.128.0 – 85.24.255.255 85.24.128.0/17
h-129-14.a209.priv.bahnhof.se 85.24.129.14
A218.cust.bahnhof.se 85.24.240.1
h-2-71.a322.priv.bahnhof.se 94.254.2.71 163.34 94.254.0.0 – 94.254.128.255 94.254.0.0/17
h-2-71.a322.priv.bahnhof.se 94.254.2.71
h-2-51.A322.priv.bahnhof.se 94.254.2.51
h-50-216.a240.priv.bahnhof.se 94.254.50.216
bot , Tech
bahnhof , bahnhof.no , bahnhof.se , ban , ban IP , internet security , ip address , key , research , spam , strategy
tor-exit-node.7by7.de spammed me today, so I decided to track them down. There is not much on him, but he is a tor exit server.
It is too bad that tor exit servers are used for spamming, as many sites will ban them. Banning due to spamming really defeats the purpose of tor. The best intentions result in misuse.
tor-exit-node.7by7.de 72.52.91.19
tor-exit-node.7by7.de 72.52.91.30
tor-exit-node.7by7.de 96.44.189.101
tor-exit-node.7by7.de 213.61.149.100
7by7.de 91.236.122.1
Permanent link to this post (69 words, 0 images, estimated 17 secs reading time)
bot , Tech
7by7 , ban , ban IP , bot , dangerous , internet security , ip address , mbahrain , pattern , research , spam , strategy , tor
mbahrain.mbahrain.net is using the Zend_Http_Client user agent, so they get banned. They are small, only 2 IPs.
mbahrain.mbahrain.net 198.57.181.97 198.57.128.0 – 198.57.255.255 198.57.128.0/17 UNIFIEDLAYER
mbahrain.mbahrain.net 198.57.168.229
Permanent link to this post (27 words, 0 images, estimated 6 secs reading time)
bot , Tech
ban , ban IP , bot , dangerous , internet security , ip address , mbahrain , mbahrain.net , pattern , research , spam , strategy , Zend , Zend_Http_Client
boostgram.com tried to crack my site security. I need him disabled. Boostgram is hosted by Digital Ocean, which hosts a lot of spamming sites.
Observation:
production.ap.3393bc.boostgram.com 159.203.202.54
51.147.188
Research:
production.ap.9612d3.boostgram.com 104.131.9.204 104.131.0.0 – 104.131.255.255 104.131.0.0/16
150.18.211.
production.ap.90c84e.boostgram.com 104.131.156.149 144.200.78.
production.ap.970190.boostgram.com 104.131.192.0/19
production.ap.831aab.boostgram.com 104.236.7.133 104.236.0.0 – 104.236.255.255 104.236.0.0/16
131.26.171.
production.ap.9b51e1.boostgram.com 104.236.9.104 155.81.225.
production.ap.ecaad3.boostgram.com 104.236.88.116 236.170.211.
production.ap.3880c0.boostgram.com 104.236.94.135
production.ap.777b50.boostgram.com 104.236.199.226
production.ap.136571.boostgram.com 104.236.254.46
production.ap.e06883.boostgram.com 107.170.4.120 107.170.0.0 – 107.170.255.255 107.170.0.0/16
production.ap.73d069.boostgram.com 107.170.36.72
production.ap.67b6b3.boostgram.com 107.170.115.31
production.ap.f9906e.boostgram.com 107.170.219.111
production.ap.3393bc.boostgram.com 159.203.202.54 159.203.0.0 – 159.203.255.255 159.203.0.0/16
production.ap.c648f2.boostgram.com 159.203.218.94
production.ap.08ccaf.boostgram.com 159.203.245.132
production.ap.9d13a2.boostgram.com 159.203.207.1
bot , Tech
ban , ban IP , boostgram , bot , content spammer , internet security , ip address , pattern , research , spam , strategy
sl-reverse.com is a content spammer that is creeping into my site and I want it stopped. I’ll hunt them down and ban them. Sl-reverse also uses servers in Canada, Germany, Singapore, Japan and Italy, to name a few.
If they botnet my butt I will get more aggressive on them.
Observations:
fa.f7.a86c.ip4.static.sl-reverse.com 108.168.247.250
6.1f.5177.ip4.static.sl-reverse.com 119.81.31.6 119.81.31.0/24 SOFTLAYER
6.1f.5177.ip4.static.sl-reverse.com 119.81.31.6
59.7c.5177.ip4.static.sl-reverse.com 119.81.124.89
12.87.5177.ip4.static.sl-reverse.com 119.81.135.18
93.fa.5177.ip4.static.sl-reverse.com 119.81.250.147
39.f8.5177.ip4.static.sl-reverse.com 119.81.248.57
8b.f9.5177.ip4.static.sl-reverse.com 119.81.249.139
d6.fd.5177.ip4.static.sl-reverse.com 119.81.253.214
e6.96.089f.ip4.static.sl-reverse.com 159.8.150.230
d7.85.7a9f.ip4.static.sl-reverse.com 159.122.133.215 159.122.133.0/24 SOFTLAYER
d7.85.7a9f.ip4.static.sl-reverse.com 159.122.133.215
a6.48.caa1.ip4.static.sl-reverse.com 161.202.72.166
a.06.01a8.ip4.static.sl-reverse.com 168.1.6.10
d6.35.01a8.ip4.static.sl-reverse.com 168.1.53.214
70.17.01a8.ip4.static.sl-reverse.com 168.1.23.112
34.4b.01a8.ip4.static.sl-reverse.com 168.1.75.52
db.63.01a8.ip4.static.sl-reverse.com 168.1.99.219
fa.f7.a86c.ip4.static.sl-reverse.com 168.108.247.250
d8.00.39a9.ip4.static.sl-reverse.com 169.57.0.216
a0.67.b9d8.ip4.static.sl-reverse.com 216.185.103.160
bot , Tech
ban , ban IP , bot , content spammer , internet security , ip address , pattern , research , Shanghai , spam , strategy
hn.kd.dhcp is spamming my site, so I need to remove it. This guy has been around for quote a while and has a long list of IPs, but not so long a list of IP ranges. This spammer runs out of Henan Province, China, but has used Jilin, Chongqing, Guangdong, and Shanghai
These may be related: hn.kd.ny.adsl ; hn.ly.kd.adsl; hn.kd.dhcp
Observation:
61.52.253.116 hn.kd.dhcp 2017-jan-04
61.54.208.158 hn.kd.dhcp
61.54.208.235 hn.kd.dhcp 2016-oct-06
61.54.209.51 hn.kd.dhcp
Research:
61.52.9.239 61.52.0.0 – 61.53.255.255 61.52.0.0/15 China Unicom Henan
61.52.28.157
61.52.53.10
61.52.74.18
61.52.100.71
61.52.168.1
61.52.198.139
61.52.207.172
61.52.232.29
61.53.1.241
61.53.5.165
61.53.25.9
61.53.65.52
61.53.64.37
61.53.64.37
61.53.65.54
61.53.65.54
61.53.65.54
61.53.67.14
61.53.73.0
61.53.86.244
61.53.92.65
61.53.143.179
61.53.143.179
61.53.143.179
61.53.152.179
61.53.153.90
61.53.153.90
61.53.160.28
61.53.185.170
61.53.193.169
61.53.194.0
61.53.203.0
61.53.235.197
bot , Tech
ban , ban IP , bot , China Unicom Henan , Chongqing , dangerous , Guangdong , hn.kd.dhcp , hn.kd.ny.adsl , hn.ly.kd.adsl , internet security , ip address , Jilin , pattern , research , Shanghai , spam , strategy , 上海 , 中国 , 吉林 , 广东 , 河南 , 重庆
unassigned.calpop.com is a comment spammer, small yes, but still needs removal. They change this hostname’s IP a lot and move between different companies such as Calpop, CoreExpress, AirlineReservations.Com, and ATMLINK. They are out of Los Angeles. I am unsure if calpop.com is still in business, as Yelp postings suggest they are now closed . Their bot is still somehow finding electricity and connectivity to spam me, so the company and store die but the bot lives on…
Observations:
unassigned.calpop.com 64.27.17.140 2016-sept-14 referrer spam
bot , Tech
AirlineReservations.Com , ATMLINK , ban , ban IP , bot , Calpop , calpop.com , CoreExpress , internet security , ip address , pattern , research , spam , strategy
no-reverse-dns-configured.com is a content spammer, and I need to eliminate him from hitting my site. Here are the details required to ban him. If these strict IPs are not sufficient then ban the range.
I did not ban the AWS ranges because IPs usually come up with AWS host names, and I ban them already.
Observation:
80.82.65.82 no-reverse-dns-configured.com
89.248.166.157 no-reverse-dns-configured.com 2016-oct-10
93.174.93.133 no-reverse-dns-configured.com
Research:
89.248.163.0 – 89.248.175.255 89.248.163.0/20 Quasi SEYCHELLES
no-reverse-dns-configured.com 89.248.163.117
no-reverse-dns-configured.com 89.248.164.157
no-reverse-dns-configured.com 89.248.164.166
no-reverse-dns-configured.com 89.248.166.131
no-reverse-dns-configured.com 89.248.166.136
no-reverse-dns-configured.com 89.248.168.135
no-reverse-dns-configured.com 89.248.168.128
no-reverse-dns-configured.com 89.248.168.219
no-reverse-dns-configured.com 89.248.169.61
no-reverse-dns-configured.com 89.248.171.131
no-reverse-dns-configured.com 89.248.172.91
no-reverse-dns-configured.com 89.248.172.14
bot , Tech
ban , ban IP , bot , internet security , ip address , no-reverse-dns-configured.com , pattern , Quasi , research , SEYCHELLES , spam , strategy