Forum Moderators: open

Message Too Old, No Replies

Domain Re-Animator Bot

Zombie apocalypse...

         

trintragula

8:26 pm on May 18, 2015 (gmt 0)

10+ Year Member Top Contributors Of The Month



I had a visit this evening from OVH (167.114.156.nnn) with this:
Domain Re-Animator Bot (http://domainreanimator.com) - support@domainreanimator.com
which sounds a bit scary.
A quick look at the website is as horrifying as it sounds.

It requested 1015 pages in 25 minutes.
Robots.txt? What's that again?

Stuff of nightmares.
Fortunately my pet monster swallowed it whole.

Pfui

11:40 pm on May 19, 2015 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



As seen on May 1st, from probably the same IP. Ditto no robots.txt, but only two hits (403'd) --

ns514167.ip-167-114-156.net
(167.114.156.198)
Domain Re-Animator Bot (http://domainreanimator.com) - support@domainreanimator.com

OVH France was bad enough. OVH Canada is catching up.

keyplyr

1:09 am on May 20, 2015 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Once again, there's no need to obscure the IP address from a public company by using "nnn." That is something we do here for privacy concerns only for humans using a ISP.

IMO all OVH ranges should be blocked:

OVH
167.114.0.0/16
167.114.0.0 - 167.114.255.255

lucy24

2:33 am on May 20, 2015 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



OVH Canada is catching up.

I've always glossed it as "Francophone robot" and have met quite as many offenders from Montreal as from the mother country.

The fourth piece of an IPv4 is pretty irrelevant, unless you're dealing with something so specialized that you have to block a <24 sub-range.

Pfui

10:24 pm on May 22, 2015 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Today, the same no-robots.txt UA from an entirely different OVH hosting server back in France...

ns514167.ip-167-114-156.net
(213.186.33.5; also reports as: redirect.ovh.net)
A whopping threat level 48 at PHP: [projecthoneypot.org...]

Host Range: 213.186.33.0 - 213.186.33.255
Host CIDR: 213.186.33.0/24

And one more for your blocking pleasure:

Host Range: 213.186.32.0 - 213.186.32.255
Host CIDR: 213.186.32.0/24

keyplyr

11:31 pm on May 22, 2015 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month




@Pfui, those OVH ranges are actually this one larger range:
213.186.32.0/19
213.186.32.0 - 213.186.63.255

Pfui

2:11 am on May 23, 2015 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Thanks. That saves a ton of htaccess and/or iptables entries.