Forum Moderators: open

Hits from 31.105.x.x (Mistralbot ?)

         

SumGuy

12:12 am on Jul 19, 2026 (gmt 0)

5+ Year Member Top Contributors Of The Month



Got some strange hits today from 31.105.x.x - quite spread out across that /16. Here are some of the user-agents:

Mozilla/5.0 (iPhone; CPU iPhone OS 18_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Mobile/15E148 Instagram 365.0.0.24.109 (iPhone14,2; iOS 18.6.1; en_AU; en-AU; scale=3.00; 1170x2532; 732485445)

Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; https:// zhanzhang.toutiao. com/)

MistralBot/1.0

Mozilla/5.0 (Linux; Android 13; TFY-LX2 Build/HONORTFY-L32CQ; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/124.0.6367.123 Mobile Safari/537.36 Instagram 329.0.0.41.93 Android (33/13; 480dpi; 1080x2289; HONOR; TFY-LX2; HNTFY-Q; qcom; en_GB; 593717597)

Plus a few stale UA's. BTW, I never see a screen resolution in the UA or any of the request headers that my software logs, so I don't know what's up with that.

Also strange were some of the requests:

/our-story
/company
/about
/contact-us
/aboutus
/contactus

All those are asking for a path. Some of those (like "our-story" or "company") I've never even had as an html file.

At the top level, all those IP's just map to AS6079 (RCN / Astound). A little digging turns up something called wookra, and plugging that into HE's bgp gives me about 40 CIDR's (including 31.105.0.0/16). So yea the entire /16 is garbage.

I was already blocking a good chunk of 31.98 and 31.105 but now it's complete.