Got some strange hits today from 31.105.x.x - quite spread out across that /16. Here are some of the user-agents:
Mozilla/5.0 (iPhone; CPU iPhone OS 18_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Mobile/15E148 Instagram 365.0.0.24.109 (iPhone14,2; iOS 18.6.1; en_AU; en-AU; scale=3.00; 1170x2532; 732485445)
Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; https:// zhanzhang.toutiao. com/)
MistralBot/1.0
Mozilla/5.0 (Linux; Android 13; TFY-LX2 Build/HONORTFY-L32CQ; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/124.0.6367.123 Mobile Safari/537.36 Instagram 329.0.0.41.93 Android (33/13; 480dpi; 1080x2289; HONOR; TFY-LX2; HNTFY-Q; qcom; en_GB; 593717597)
Plus a few stale UA's. BTW, I never see a screen resolution in the UA or any of the request headers that my software logs, so I don't know what's up with that.
Also strange were some of the requests:
/our-story
/company
/about
/contact-us
/aboutus
/contactus
All those are asking for a path. Some of those (like "our-story" or "company") I've never even had as an html file.
At the top level, all those IP's just map to AS6079 (RCN / Astound). A little digging turns up something called wookra, and plugging that into HE's bgp gives me about 40 CIDR's (including 31.105.0.0/16). So yea the entire /16 is garbage.
I was already blocking a good chunk of 31.98 and 31.105 but now it's complete.