Forum Moderators: open

Web hit from Residential ISP or international VPN?

         

SumGuy

2:28 am on Jul 29, 2025 (gmt 0)

5+ Year Member Top Contributors Of The Month



Had a hit recently from 82.23.125.61. The user-agent was

Mozilla/5.0 (Linux; Android 5.0; SM-G900P Build/LRX21T) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.4127.1908 Mobile Safari/537.36

This was flagged as robot / VPN (for at least a couple of reasons). The IP is ASN 812 - Rogers (huge cable-TV and cellular provider in Canada, equivalent to Comcast in the US). Spur ID's the IP as VPN, but calls it a data-center. This is interesting. BGP lookup comes back with a prefix 82.23.125.0/24, registrant is "private customer". I throw the IP into scamalytics, it says the IP is operated by "private customer". Geographical location Canada (Toronto). It also flags it as a VPN.

I do a trace-route to it.

The second last hop is 66.220.47.65. I do BGP lookup on that. It's still a Rogers IP, but the prefix registrant (66.220.47.0/24) is - Eleven Holdings Limited.

WHOIS Record for 66.220.47.0

Created Jan 22, 2025
Updated Jan 22, 2025
Registrant Organization ELEVEN HOLDINGS LIMITED
Registrant Country or Region Hong Kong S.A.R. of China
Registrar Name ORG-EHL10-RIPE

So here's an example of a residential ISP (Rogers) renting some of their IP's for use by international (Chinese) VPN operators. Unsuspecting webmasters would think traffic from this IP was organic and originated in Toronto.

haramamba

10:00 am on Jul 29, 2025 (gmt 0)

Top Contributors Of The Month



I don't trust these "private customer" IP ranges. I have blocked some of them from AT&T and Microsoft ASNs. They are typically sending some xmlrpc-like sh*t or trying to ddos the smtp server with fake login attempts.
The "SM-G900P" in the user agent string is a 100% red flag in my anti-bot stript.
The last time I saw this user agent was a year ago.

haramamba

10:15 am on Jul 29, 2025 (gmt 0)

Top Contributors Of The Month



Just tried "whois 82.23.125.61" and what I see:

geofeed: https://geofeed.ipxo.com/geofeed.txt
mnt-ref: IPXO-MNT
abuse-mailbox: report@abuseradar.com

All 3 lines don't look good, especially this "IPXO-MNT". For me, it means ban on sight.

SumGuy

12:54 pm on Jul 29, 2025 (gmt 0)

5+ Year Member Top Contributors Of The Month



Thanks @haramamba for the whois tip. I'm not in the habit of checking whois info, but I have downloaded the ipxo geofeed list in the past, but not recently. That's another bit of useful info that ipxo is involved in this - they are Roger's "private customer" in this scheme.

I'm going to download the geofeed list again today, and see how many new CIDR's there are that aren't in my router's current IP blocking list, and add them.

lucy24

7:26 pm on Jul 29, 2025 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Chrome/41.0.4127.1908
That, at least, makes it easy :)

I looked up Chrome/41 in logs. Within this calendar year, all of mine have been Chrome/41.0.222[78].various--all, of course, blocked. Lazy botrunners are certainly a boon to the rest of us.

Brett_Tabke

8:28 pm on Sep 28, 2025 (gmt 0)

WebmasterWorld Administrator 10+ Year Member Top Contributors Of The Month



Why couldn't this just be an open proxy? someone got hacked and all they did was put a proxy on the ip.

SumGuy

12:25 pm on Oct 1, 2025 (gmt 0)

5+ Year Member Top Contributors Of The Month



> Why couldn't this just be an open proxy? someone got hacked and all they did was put a proxy on the ip.

If the IP is tied to IPXO (as indicated a few posts up) then it's not hacked, its part of a VPN by design.

Spur identifies the IP as being OXYLABS_PROXY.

=======
Oxylabs - High Quality Proxy Service to Gather Data at Scale

The best proxy service platform with 175M+ Residential and 2M Datacenter IP proxies. Extract public data from any website with ease!

lucy24

4:46 pm on Oct 1, 2025 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



to Gather Data at Scale ... Extract public data from any website with ease!
Well. That certainly clears up any qualms one might have about potentially barring an honest, law-abiding human.