Firefox 6 is WAY out of date and probably a bot of some kind.
keyplyr
11:09 pm on Jul 1, 2013 (gmt 0)
@ dstiles re: ISPpro
Looks like broadband mixed in with web servers (much like Comcast.) Are you pinging for ports to tell the difference or just blocking categorically?
dstiles
6:59 pm on Jul 2, 2013 (gmt 0)
You could be right but there are several open-port IPs in the random tests I made. Ports I've seen include HTTP/HTTPS, POP3 and SMTP, FTP and others. Those ports say to me server.
If it's a mixed range then tough on the DSL users: they should find a better-split provider. Even if the ranges are static IPs, there is not enough separation between hard-core users who send out bots and "genuine" DSL users.
I dislike and distrust ALL comcast hits but I have to leave them open for one of my customers. In the past 2 years I've logged over 1200 comcast "idiotic hits". On the other hand my customer has received some orders from those ranges. :(
dstiles
7:01 pm on Jul 2, 2013 (gmt 0)
Another Rackspace range hit me today, a Cloud based at:
162.13.0.0 - 162.13.15.255
wilderness
12:11 pm on Jul 3, 2013 (gmt 0)
Servepath/GoGrid
There are mentions in two threads (one recent and one old):
173.1.0.0 - 173.1.255.255 173.1.0.0/16 I have as GoGrid
wilderness
9:11 pm on Jul 3, 2013 (gmt 0)
From their website FAQ:
"Is ServePath being acquired?
Absolutely not, ServePath and GoGrid have always been the same company; we are just changing our name." end of quote
Thanks for the heads up guys. Looking further, located these North American ranges that cover both names: GOGRID-BLK3 173.204.0.0 - 173.204.255.255 173.204.0.0/16 GOGRID-BLK3 173.244.64.0 - 173.244.79.255 173.244.64.0/20 GOGRID-BLK1 74.3.192.0 - 74.3.255.255 74.3.192.0/18
dstiles
7:55 pm on Jul 4, 2013 (gmt 0)
So gogrid is a new name for servepath or the other way around? Either way, I'm not really concerned: they are both blocked. :)
wilderness
1:28 am on Jul 7, 2013 (gmt 0)
There's multiple references to this, and even comes up in the search results advertising ;)
For ages I'd had 91.201.64.0/22 ("bulletproof-web", Russia) blocked on grounds of general robotitude.
Guess it wasn't as bulletproof as they thought; the range currently seems to be unassigned. RIPE being RIPE, you would expect this situation to last five or ten minutes, tops. But they may have closed up shop as long as six months ago.
I've had bad hits coming from this range in the past.
dstiles
7:45 pm on Jul 10, 2013 (gmt 0)
Lucy - I had that range listed as MHost but yes, not currently allocated, it seems. It's possible it fell to the latest round of exploiter shut-downs - there has been a fair amount of activity in recent months, causing a flurry of new bot activity from those attempting to create more robust botnets.
Following up through ixquick and entering the starting IP brings up a result from nanog which states the range was hijacked last August from DonEkoService (which they say was dodgy anyway). Maybe it was just reclaimed by RIPE.
not2easy
6:20 am on Jul 12, 2013 (gmt 0)
A new (for me anyway) DataShack just showed up July 7: 74.91.16.0 - 74.91.31.255 74.91.16.0/20 74.91.18.224 - 74.91.18.231 74.91.18.224/29
UA: -
keyplyr
8:55 am on Jul 12, 2013 (gmt 0)
@not2easy Thanls for the DataShack
Amernet cloud & VoIP 209.21.64.0 - 209.21.95.255 209.21.64.0/19
not2easy
4:37 pm on Jul 12, 2013 (gmt 0)
Another one: GO-DADDY-NETHERLANDS-BV 146.255.32.0 - 146.255.35.255 I blocked the whole 146.255.0.0/16 because this is a sub-range in NetRange: 146.255.0.0 - 146.255.255.255 and found on a non public site and they were trying very hard to do sql injections. UA: "T34m 0x68583052" another scan from this IP had UA: "-"
From WIRESIX: 98.142.208.0 - 98.142.223.255 98.142.208.0/20 UA: "Mozilla/5.0 (X11; U; Linux x86_64; en-GB; rv:1.9.0.2) Gecko/2008092213 Ubuntu/8.04 (hardy) Firefox/3.0.2"
From TEDE-LLU: 95.112.0.0 - 95.115.255.255 95.112.0.0/13 UA: "Java/1.7.0_07"
From SOFTLAYER-4-3: 75.126.0.0 - 75.126.255.255 75.126.0.0/16 UA: "Python-urllib/1.17"
From AFOCELCA (Portugal):213.58.195.224 - 213.58.195.231 213.58.192.0/21 "GET /w00tw00t.at.ISC.SANS.Win32:) HTTP/1.1" 400 289 "-" "-" No UA, the requested file is not on this server but I get a lot of requests for it, it must be popular...and vulnerable.
keyplyr
5:47 pm on Jul 12, 2013 (gmt 0)
Another one: GO-DADDY-NETHERLANDS-BV 146.255.32.0 - 146.255.35.255 I blocked the whole 146.255.0.0/16 because this is a sub-range in NetRange: 146.255.0.0 - 146.255.255.255
Thanks for the GDaddy range. However, I would reconsider blocking the /16. There *are* public areas in there. For example: Surebroadband 146.255.0.0 - 146.255.0.127