More DigitalOcean 159.223.0.0 - 159.223.255.255 159.223.0.0/16 AS14061
martinibuster
4:29 am on Jan 3, 2022 (gmt 0)
That's interesting. The sites I use for research don't show that entire IP range assigned to AS14061.
A whois search for 159.223.255.255 shows that there is no Origin AS assigned to that IP address.
But the whois search result shows that 159.223.0.0 - 159.223.255.255 correspond to Digital Ocean.
And when I search what's assigned to AS14061 the IP range stops at 159.223.191.255 which usually means that it's assigned to a different AS.
Strange!
not2easy
4:35 am on Jan 3, 2022 (gmt 0)
That is strange, you're right. I got a weird result the first time I clicked on the 'whois' button in Network Tools but when I re-clicked, it spit out the complete listing and says it was last updated in May 2021 but I had never seen anything from that range before. Scraper today.
dstiles
9:14 am on Jan 3, 2022 (gmt 0)
I blocked that range last October following a bot or similar hit. A check with Network Tools this morning (from UK) shows no problem. Maybe a DNS routing problem?
blend27
9:37 pm on Mar 29, 2022 (gmt 0)
Amsterdam Servers - AS25369 - part of HYDRA 89.46.223.0 - 89.46.223.255 89.46.223.0/24
thetrasher
2:16 am on Aug 19, 2022 (gmt 0)
OVH (AS16276)
57.128.0.0 - 57.131.255.255 57.128.0.0/14 Created 2022-01-25
141.227.128.0 - 141.227.255.255 141.227.128.0/17 Created 2022-02-03
162.19.0.0 - 162.19.255.255 162.19.0.0/16 Created 2021-05-19
198.244.128.0 - 198.244.255.255 198.244.128.0/17 Created 2021-02-22
GTS Telecom Romania 128.140.0.0 - 128.140.255.255 128.140.0.0/16
martinibuster
5:37 am on Oct 2, 2022 (gmt 0)
I got attacked last month by a bot on Tencent but on a different AS# than the one you listed, not2easy. So I went down the list and blocked the biggest blocks from the AS that attacked my site. I make a list of everything I block, ordered by AS# so I can reference check. I use blank spaces between the ranges to make it easy to scan the list.
TENCENT AS45090
Deny from 1.12.0.0/14
Deny from 1.116.0.0/15
Deny from 42.192.0.0/15
Deny from 43.128.0.0/15
Deny from 81.68.0.0/14
Deny from 82.156.0.0/15
Deny from 101.34.0.0/15
Deny from 101.42.0.0/15
Deny from 106.52.0.0/14
Deny from 111.230.0.0/15
Deny from 115.159.0.0/16
Deny from 118.24.0.0/15
Deny from 121.4.0.0/15
Deny from 123.206.0.0/15
Deny from 139.155.0.0/16 Deny from 139.186.0.0/16 Deny from 159.75.0.0/16 Deny from 170.106.0.0/16 Deny from 175.27.0.0/16
not2easy
6:42 pm on Dec 7, 2022 (gmt 0)
New to me today - weird for the RIPE listing using a US address Dedipath as35913 45.15.128.0 - 45.15.129.255 45.15.128.0/22
martinibuster
1:12 am on Dec 8, 2022 (gmt 0)
I think you can ban a much larger group of numbers there with one line, starting with at least 45.15.124.0 and going as far as 45.15.187.255
I didn't check in detail because I'm about to do something but will check it out later.
not2easy
3:23 am on Dec 8, 2022 (gmt 0)
Yes, I have records of a bunch of 45.8.n.n. - 45.15.n.n. from around April 2015 that haven't been seen for a while. These weren't in that list, though more isn't surprising. :(