interset.ru seems to be managed by a company named netup.ru who hosts at digitalocean.com GB.
blend27
8:46 am on Sep 5, 2016 (gmt 0)
halocolocation.com 206.41.160.0 - 206.41.191.255 206.41.160.0/19 one more for the equal sign in UA attempt:
=Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16
keyplyr
11:50 pm on Sep 5, 2016 (gmt 0)
New ovh.com 91.134.0.0 - 91.134.255.255 91.134.0.0/16
dstiles
6:49 pm on Sep 6, 2016 (gmt 0)
91.134.0.0/16 - nasty: used to be bulgarian cable!
not2easy
6:12 am on Sep 8, 2016 (gmt 0)
Snagged a new (for me) Hetzner today (formerly ARIN, now RIPE) I've seen this block just once in the past, but for whatever reason it wasn't identified in my main file. HETZNER-RZ-BLK-ERX4 138.201.0.0 - 138.201.255.255 138.201.0.0/16
blend27
10:29 am on Sep 8, 2016 (gmt 0)
I thought I had all GB covered, but then...
Mozilla/4.0 (compatible; MSIE 5.0; Windows NT; DigExt; DTS Agent
Who does things like that anymore?..
UK Dedicated Servers Limited UK-UKSERVERS-20120626 5.101.168.0 - 5.101.175.255 5.101.168.0/21
keyplyr
11:50 am on Sep 8, 2016 (gmt 0)
"Who does things like that anymore?"
Likely someone running a very old script they bought at the bargin store on the dark web.
blend27
12:03 pm on Sep 8, 2016 (gmt 0)
Someone crawls into a dark web store.
Sayz I got almost no money, Give me a script!
Reply: did you read robots.txt?
:)
blend27
12:15 pm on Sep 8, 2016 (gmt 0)
re:last HETZNER @not2easy
There were some really nasty activity that started on 2016-02-25 at 18:31:32 GMT from that range.
static.NN.16.201.138.clients.your-server.de was simply toxic, many of them.
IT_SERVICES(Latvia). Homepage says - Under Construction. /24 has only a few sites with very questionable content(P*lz&P*orn) 185.129.148.0 - 185.129.148.255 185.129.148.0/24
dstiles
8:03 pm on Oct 1, 2016 (gmt 0)
I have 185.129.148.0/22 for this one (Latvia)
keyplyr
8:37 pm on Oct 1, 2016 (gmt 0)
I have 185.129.148.0/22 for this one (Latvia)
While the /22 appears to all be Latvia servers, it looks like there are several companies leasing those ranges. For example: 185.129.151.0/24 is 2cloud.eu.