-
You know the drill by now. Drop it like it’s hot! ASN Watchlist (it’s really a drop list)
·
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Interserver (AS19318) has been added to the ASN watchlist. In the last 24 hours, AS19318 has originated the most abusive network traffic, proportionate to the IP space announced – a single /24: 109.205.213.0/24 Outside of our internally collected data, we see a correlation with AbuseIPDB user reports for this netblock – a whopping total of 62,416 abuse reports, as of this writing. This is not an isolated incident for Interserver. They have demonstrated a repeated track record…
·
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
In the last six years, Internet Weather sensors have never detected unsolicited Encapsulating Security Payload (ESP) packets. This changed on 2023-11-09 14:52:12 when the first ever ESP packet was detected. ESP (IP protocol number 50) packets are normally used to encapsulate IPsec traffic between VPN endpoints. Outside of this, you would never expect to see this kind of activity traversing your network. Additionally, ESP packets may not be filtered by your edge or client-side (CPE) firewalls. Due to…
·
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Do you have legacy internet number resources at risk of hijack? We are currently reviewing every legacy autonomous system number (ASN) and IPv4 netblocks in the ARIN region and notifying resource holders who at risk. Affected parties will receive an email providing details on which specific resources are at risk and provide guidance on the action needed to secure them.
·
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
AS22769, formerly known as “DDOSING NETWORK” and “DDOSING-BGP-NETWORK” is now back in the global routing table as a legitimate organization: Valley Strong Credit Union. This is due to ARIN reclaiming the autonomous system number (ASN) and re-issuing it, per their Return and Revocation Process for internet number resources. Previously, AS22769 was a fraudulent autonomous system that originated thousands of IPv4 addresses between 2018 and 2022. Despite a fraud report being filed with ARIN in 2018, AS22769 was allowed to…
·
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Academy of Internet Research LLC (AS400161) has been added to the ASN watchlist. AS400161 is the autonomous system that originates the scanning traffic from “security researchers” that state on their website they “wish to make internet free, safe and accessible to all.” Strangely these guys can’t seem to get their own name right and use the following known aliases: Academy of Internet Research Limited Liability Company Academy for Internet Research LLC Department of Internet Services The Hawaii…
·
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Rethem Hosting LLC (AS14987) has been added to the ASN watchlist. AS14987 is the autonomous system that originates the scanning traffic of a now seemingly defunct “research project” known as InterneTTL. These scans originate from the 104.152.52.0/24 netblock and each IP has a reverse DNS (PTR) record of “internettl.org” – a website that stopped functioning sometime after September 2021, per data provided by the Internet Archive and urlscan.io. BGP.tools notes that 104.152.52.0/24 is originated by AS14987 and…
·
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Miti 2000 EOOD (AS209160) has been added to the ASN watchlist. In the last 24 hours, AS209160 has originated the most abusive network traffic, proportionate to the IP space announced – a single /24: 78.128.113.0/24 Outside of our internally collected data, we see a correlation with AbuseIPDB user reports for this netblock – an insane total of 383,680 abuse reports, as of this writing. It is advisable to not route any packets from this autonomous system.
·
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
XHOST INTERNET SOLUTIONS LP (AS209559) has been added to the ASN watchlist. In the last 24 hours, AS209559 has originated the most abusive network traffic, proportionate to the IP space announced – a single /24: 80.66.83.0/24 Outside of our internally collected data, we see a correlation with AbuseIPDB user reports for this netblock – a whopping total of 46,545 abuse reports, as of this writing. Additionally, you may note that XHOST INTERNET SOLUTIONS LP’s other autonomous system…
·
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
BtHoster LTD (AS198465) has been added to the ASN watchlist. In the last week, AS198465 has originated the most abusive network traffic, proportionate to the IP space announced – two /24’s: 45.129.14.0/24 77.90.185.0/24 Outside of our internally collected data, we see a correlation with AbuseIPDB user reports for these netblocks – a whopping combined total of 146,763 abuse reports, as of this writing. We recommend you examine your relationship with this AS and consider your options before routing…
·
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


