Good find although I always hate blocking Linode. I don't get many bad agents from their ranges, but I block a great number of company employees.
dstiles
4:12 pm on Jun 12, 2015 (gmt 0)
keyplr - I understand what you're saying. However, "carriers" is not the same as IP usage and the few /23 ranges I have for them are not extensive enough to accommodate all of those ISPs. If they identified their IP range usage I would be more likely to let certain services in, but until they do colo trumps broadband. :(
blend27 - io is a new TLD to me. Turns out it's "IO Top Level Domain Registry Cable and Wireless". Thanks for the IP range.
Thanks Don, didn't have several of those. Others are inside larger ranges & some of course can be combined. Too bad these tools don't do that for us :)
As far as "similar request" are concerned, I see those and other WP vulnerability probes easily 50x each and every day. I'm pretty sure there are a lot of WP installs at my host, possibly attracting the attention.
wilderness
2:51 pm on Jun 22, 2015 (gmt 0)
I added the following rather that continuing IP's for this same pest (saem UA from aforementioned SingleHop).
I got these from several domains today - in traps 104.236.0.0 - 104.236.255.255 104.236.0.0/16 DIGITALOCEAN-10 Simple Cloud Hosting
Registered about 6 months ago, but I did not have them on record.
keyplyr
7:22 am on Jun 23, 2015 (gmt 0)
In my experience WP vulnerability probes come from many UAs, not just the one you blocked. These UAs are all spoofed since it is a script (bot) that is actually probing your server for a open window, not a browser.
keyplyr
9:00 am on Jun 23, 2015 (gmt 0)
ods.vn mobile & servers 112.78.0.0/20 112.78.0.0 - 112.78.15.255