Sunday, October 15, 2017

Networks Sending Bad Traffic

As explained in my Secplicity blog posts I set up some rules to auto-block hosts hitting unexpected ports on a test network. For more information how to do that and about IPs and Internet Registries in general refer to these posts:




Why I Am Seeing This Traffic...

After setting up these rules according to the above I was able to capture hosts that are connecting to ports on my network that have absolutely no business doing so. I may have caught a few legitimate connections in the following and a few fat-fingered requests but no way all of this can be explained away by that.

The most likely solution is that the networks listed below are hosting malicious software on some device and it is reaching out on the Internet looking for other devices to attack.

Another possibility is that the hosts are part of a proxy network or VPN service that is hiding the identity of the person who is actually making the request - and why would someone need to hide their true identity to contact a test network to which it has no business accessing? Additionally, I wonder if all the hosts involved in these proxy and VPN networks have consented to share their Internet access or if they too are hosting malware. I also wonder if the devices given away with Internet service are actually part of the problem and hosting the malware.

If you can think of other reasons why this may be happening, let me know. But if my one small test network is getting hit this many times a day, multiply that by all the hosts on the Internet ...that's a lot of bad traffic. It is also a lot of noise hiding truly malicious traffic.

If You Are Seeing Blocked Outbound Requests on Your Network...Please Investigate!

If you know someone who works for one of these networks could you please ask them to inspect their traffic to see if they are getting outbound requests blocked by the firewall at the other network? In that case that particular host may be hosting malware that is trying to reach out to the other network.

Auto-Blocked Network List

I turned my auto-block list into a blocked-sites list that can be used on a WatchGuard Firebox (Security Appliance) and it is available on github which you can use at your own risk and with the noted caveats - I will maybe update this over time as I discover more:


As noted in the readme above I'm focusing on ARIN for details and disregarding individual networks on the other registries at this time (too much...)

Networks Sending Rogue Traffic

23.91.64.0-23.91.79.255|A Small Orange LLC
208.67.248.56-208.67.248.63|ABP Technology
49.204.0.0/24|ACTFIBERNET-Secundrabad
104.37.96.0-104.37.103.255|ALTIUS Broadband, LLC
108.64.0.0-108.95.255.255|AT+T
172.0.0.0-172.15.255.255|AT+T Internet Services
99.0.0.0-99.127.255.255|AT+T Internet Services
172.124.0.0-172.127.255.255|AT+T Internet Services
107.192.0.0-107.223.255.255|AT+T Internet Services
104.48.0.0-104.63.255.255|AT+T Internet Services
64.20.64.0-64.20.79.255|Adamswells Internet
209.153.192.0-209.153.255.25|Allstream Corp.
18.219.0.0-18.228.255.255|Amazon Technologies Inc
34.192.0.0-34.255.255.255|Amazon Technologies Inc
52.32.0.0-52.63.255.255|Amazon Technologies Inc
52.0.0.0-52.31.255.255|Amazon Technologies Inc.
64.33.163.0-64.33.163.127|Amery Telephone Company
24.49.32.0-24.49.35.255|Antietam Cable Television, Inc
125.0.0.0/8|Apnic
24.112.184.0-24.112.184.255|Armstrong Cable Services
24.144.246.0-24.144.246.255|Armstrong Cable Services
207.32.0.0-207.32.63.255|Aureon Network Services
12.219.122.0-12.219.122.255|BAY CITY ISD, TX
97.68.0.0-97.68.255.255|BRIGHT HOUSE NETWORKS, LLC
49.205.0.0/16|Beam Telecom Pvt Ltd
216.229.0.0/19|Binary Net LLC
208.157.185.0-208.157.185.255|Bloomer Telephone Compan
104.192.162.0-104.192.162.255|Bloomer Telephone Company
67.209.70.0-67.209.70.255|Bloomer Telephone Company
24.56.192.0-24.56.255.255|Broadstripe
24.35.0.0-24.35.127.255|Broadstripe
24.119.0.0-24.119.255.255|CABLE ONE, INC
160.3.0.0-160.3.255.255|CABLE ONE, INC.
24.121.182.0-24.121.183.255|CABLEVISION OF LAKE HAVASU
173.220.134.176-173.220.134.183|CARESOFT INC
192.198.63.40-192.198.63.47|CITY OF CONNERSVILLE TV3
173.214.144.0-173.214.159.255|CNS Internet
172.87.0.0-172.87.15.255|CONSOLIDATED TELEPHONE CO
96.47.96.0-96.47.111.255|COZAD TELEPHONE COMPANY
104.245.228.0/22|CVALINK-BROADBAND
24.51.64.0-24.51.127.255|Cable Bahamas
72.27.0.0-72.27.223.255|Cable and Wireless Jamaica
208.163.32.0-208.163.63.255|Cable and Wireless Jamaica
71.6.142.64-71.6.142.127|CariNet
66.240.192.128-66.240.192.191|CariNet, Inc.
96.32.0.0-96.42.255.255|Charter Commnications
24.176.176.0-24.176.191.255|Charter Communications
66.191.0.0-66.191.255.255|Charter Communications
66.168.112.0-66.168.119.255|Charter Communications
68.188.160.0-68.188.191.255|Charter Communications
24.205.32.0-24.205.75.255|Charter Communications
66.227.164.0-66.227.165.255|Charter Communications
66.214.96.0-66.214.111.255|Charter Communications
68.188.128.0-68.188.159.255|Charter Communications
24.241.112.0-24.241.127.255|Charter Communications
68.119.64.0-68.119.95.255|Charter Communications
68.186.32.0-68.186.63.255|Charter Communications
71.83.80.0-71.83.95.255|Charter Communications
47.32.0.0-47.51.255.255|Charter Communications
24.181.144.0-24.181.159.255|Charter Communications
184.166.0.0-184.167.255.255|Charter Communications
24.226.224.0-24.226.239.255|Cogeco Cable Holdings Inc
192.3.0.0-192.3.255.255|ColoCrossing
98.218.0.0-98.218.255.255|Comcast
24.126.128.0-24.126.255.255|Comcast
68.61.0.0-68.61.255.255|Comcast
75.147.128.0-75.147.143.255|Comcast Business Communications, LLC
66.208.250.0-66.208.251.255|Comcast Business Communications, LLC
24.118.0.0-24.118.127.255|Comcast Cable Communications Holdings, Inc
24.30.96.0-24.30.127.255|Comcast Cable Communications Holdings, Inc
66.229.128.0-66.229.255.255|Comcast Cable Communications Holdings, Inc
98.194.0.0-98.195.255.255|Comcast Cable Communications, Inc
67.180.128.0-67.180.255.255|Comcast Cable Communications, Inc
174.49.64.0-174.49.127.255|Comcast Cable Communications, Inc.
68.35.0.0-68.35.127.255|Comcast Cable Communications, Inc.
67.182.0.0-67.182.63.255|Comcast Cable Communications, Inc.
67.183.0.0-67.183.255.255|Comcast Cable Communications, Inc.
98.216.0.0-98.217.255.255|Comcast Cable Communications, Inc.
98.202.0.0-98.202.255.255|Comcast Cable Communications, Inc.
174.54.0.0-174.55.255.255|Comcast Cable Communications, LLC
50.128.0.0-50.255.255.255|Comcast Cable Communications, LLC
24.0.0.0-24.15.255.255|Comcast Cable Communications, LLC
24.248.224.0-24.248.231.255|Cox Communications
174.77.64.0-174.77.71.255|Cox Communications
174.74.0.0-174.74.127.255|Cox Communications
68.228.192.0-68.228.255.255|Cox Communications
98.183.128.0-98.183.255.255|Cox Communications
98.165.0.0-98.165.255.255|Cox Communications
24.234.0.0-24.234.255.255|Cox Communications Inc
68.104.128.0-68.104.255.255|Cox Communications Inc.
68.4.0.0-68.5.255.255|Cox Communications Inc.
68.108.0.0-68.108.127.255|Cox Communications Inc.
192.198.60.0-192.198.61.255|DHCP Pool - Cinergy MetroNet (
209.195.110.0-209.195.111.255|DISTRIBUTEL COMMUNICATIONS LTD.
66.163.144.0-66.163.159.255|Dakota Central Telecommunications Cooperative
104.237.224.0-104.237.255.255|DedFiberCo
63.143.64.0-63.143.127.255|Digicel Jamaica
45.55.0.0-45.55.255.255|Digital Ocean
165.227.0.0-165.227.73.21|Digital Ocean
205.0.0.0-205.55.255.255|DoD Network Information Center
209.27.48.0-209.27.51.255|EASTERN OREGON TELECOM
216.172.96.0-216.172.111.255|EBL Global Networks, Inc.
47.23.70.8-47.23.70.15|EIHAV HU MAN SERVICES
68.169.189.0-68.169.189.255|EPB Telecom
24.40.128.0-24.40.143.255|Earthlink
66.243.232.0-66.243.239.255|FAIRPOINT COMMUNICATIONS, INC.
209.141.32.0-209.141.63.255|FranTech Solutions
198.251.80.0-198.251.95.255|FranTech Solutions
198.98.48.0-198.98.63.255|FranTech Solutions
47.136.0.0-47.181.255.255|Frontier Communications
47.191.0.0-47.207.255.255|Frontier Communications Corporation
50.102.0.0-50.111.255.255|Frontier Communications of America, Inc
50.120.0.0-50.127.255.255|Frontier Communications of America, Inc.
24.237.0.0-24.237.255.255|GENERAL COMMUNICATION, INC.
206.174.0.0-206.174.127.255|GENERAL COMMUNICATION, INC.
12.189.100.56-12.189.100.59|GEOVANNI TEON
206.71.48.0-206.71.63.255|Galaxyvisions Inc
65.50.0.0-65.50.191.255|GigaMonster
64.145.108.0-64.145.111.255|Global Capacity
207.168.186.0-207.168.187.255|Global Capacity
64.145.128.0-64.145.131.255|Global Capacity
136.32.0.0-136.63.255.255|Google Fiber
35.192.0.0-35.207.255.255|Google Inc.
65.36.116.0-65.36.116.255|Grande Communications Austin Hub 3
67.198.110.0-67.198.111.255|Grande Communications Waco
96.63.248.0-96.63.251.255|Grove Norman
64.251.30.0-64.251.31.255|HA Servers, LLC
23.239.192.0-23.239.223.255|Handy Networks, LLC
216.248.81.128-216.248.81.159|Heart of Iowa Communications Cooperative
104.193.253.0-104.193.253.255|Hosting Solution Ltd / King Servers
23.254.128.0-23.254.255.255|Hostwinds LLC
74.82.0.0-74.82.255.255|Hurricane Electric
216.218.128.0-216.218.255.255|Hurricane Electric
184.104.0.0-184.105.255.255|Hurricane Electric
64.62.128.0-64.62.255.255|Hurricane Electric, Inc.
173.233.160.0-173.233.175.255|Infobahn Outfitters, Inc.
65.101.54.88-65.101.54.95|Inter-Tel.Net
47.23.23.104-47.23.23.111|Karvers Grille
66.165.192.0-66.165.223.255|Keewaytinook Okimakanak
209.33.126.0-209.33.126.255|Kingwood, Tx Customers
216.158.240.0-216.158.255.255|Kit Carson Electric Cooperative, Inc
64.184.32.0-64.184.47.255|LIGTEL COMMUNICATIONS, INC
216.244.74.184-216.244.74.191|Lee Benson
45.56.64.0-45.56.127.255|Linode
45.79.0.0-45.79.255.255|Linode
67.227.128.0-67.227.255.255|Liquid Web, L.L.C
23.24.24.192-23.24.24.207|MATTIONI LTD
100.0.0.0-100.41.255.255|MCI Communications Services, Inc. d/b/a Verizon Business
173.48.0.0-173.63.255.255|MCI Communications Services, Inc. d/b/a Verizon Business
98.108.0.0-98.119.255.255|MCI Communications Services, Inc. d/b/a Verizon Business
96.57.181.144-96.57.181.151|MRI IMAG OF ROCHELLE
173.16.0.0-173.31.255.255|Mediacom Communications Corp
47.23.4.48-47.23.4.55|Mercedes Benz
104.254.48.0-104.254.51.255|Metro Loop
13.64.0.0-13.107.255.255|Microsoft
52.224.0.0-52.255.255.255|Microsoft
23.96.0.0-23.103.255.255|Microsoft
24.220.148.0-24.220.149.255|Midcontinent Communications
96.3.64.0-96.3.65.255|Midcontinent Communications
24.230.162.0-24.230.163.255|Midcontinent Communications
67.20.32.0-67.20.47.255|NEW FRONTIERS INTERNET SERVICES
209.249.85.0-209.249.85.255|NOVA Wireless
204.42.0.0-204.42.255.255|NTT America, Inc.
173.209.160.0-173.209.167.255|NWI CC Fiber
206.81.96.0-206.81.103.255|NapaNet
209.123.0.0-209.123.255.255|Net Access Corporation
199.48.160.0-199.48.167.255|Nodes Direct
96.46.28.0-96.46.32.0|Northwest Internet
66.172.104.64-66.172.104.127|Northwest Internet
158.69.0.0-158.69.255.255|OVH Hosting
198.50.201.0-198.50.201.63|OVH Hosting, Inc
12.22.5.152-12.22.5.159|OXBORROW TRUCKING N LANDSCAPE MA
69.122.8.0-69.122.11.255|Optimum Online
24.185.16.0-24.185.31.255|Optimum Online (Cablevision Systems)
24.228.96.0-24.228.111.255|Optimum Online (Cablevision Systems)
68.192.48.0-68.192.63.255|Optimum Online (Cablevision Systems)
38.0.0.0-38.255.255.255|PSINet, Inc.
24.115.101.0-24.115.101.255|PenTeleData Account
24.115.125.0-24.115.125.255|PenTeleData House Account
24.38.128.0-24.38.143.255|Phenix Cable
24.224.0.0/19|Pioneer Long Distance -Asia
216.254.234.0-216.254.234.255|PrairieWave Cable Modem DHCP
24.149.64.0-24.149.79.255|Private Customer - HELICON CABLE - Redwood
66.35.51.195-66.35.51.207|Prosperent Inc. / FORTRUST LLC
209.126.136.0/27|Quad Data
216.160.0.0-216.161.255.255|Qwest Communications Company, LLC
64.121.0.0-64.121.255.255|RCN
24.148.0.0-24.148.95.255|RCN
184.106.76.0-184.106.79.255|Rackspace
198.11.120.0-198.11.127.255|Radiolink
107.161.16.0-107.161.31.255|Ram Node
216.98.153.224-216.98.153.255|Rapid7
71.6.216.32/27|Rapid7
162.250.188.0-162.250.191.255|Rica Web Services
91.0.0.0/8|Ripe
99.226.216.0-99.226.217.255|Rogers Cable
172.86.120.0-172.86.127.255|Router Hosting
209.64.57.0-209.64.57.7|SOUTHERN PINE PLANTATIONS
104.156.16.0-104.156.31.255|Salina Spavinaw Telephone Company, Inc.
216.174.154.64-216.174.154.71|SaskTel Wide Area Network Engineering Center
216.107.176.0-216.107.191.255|Sentco.net, LLC
65.111.164.0-65.111.175.255|Server Pronto
184.64.0.0-184.71.255.255|Shaw Communications Inc.
24.64.0.0-24.71.255.255|Shaw Communications Inc.
24.76.0.0-24.79.255.255|Shaw Communications Inc.
108.178.0.0-108.178.63.255|SingleHop, Inc
65.181.118.0-65.181.118.255|Solar VPS
64.130.128.0-64.130.191.255|South Central Rural Telecommunications Cooperative Inc.
66.207.224.0-66.207.255.255|Star Wireless, Inc.
108.170.128.0-108.170.191.255|Start Communications
24.156.176.0-24.156.191.255|Start Communications
24.54.64.0-24.54.95.255|Start Communications
67.213.84.0-67.213.84.255|Stratonexus Technologies Corporation O/A aeonex.ca
208.180.0.0-208.180.255.255|Suddenlink Communications
173.216.0.0-173.219.255.255|Suddenlink Communications
205.204.20.0-205.204.23.255|Summit Broadband
216.239.188.0-216.239.189.255|Summit Broadband
172.32.0.0-172.63.255.255|T-mobile
42.217.0.0-42.217.255.255|TELEBECNET
108.172.0.0-108.173.255.255|TELUS
172.218.0.0-172.219.255.255|TELUS Communications Inc.
207.243.195.112-207.243.195.127|TKT ENTERPRISES INC
142.217.0.0-142.217.255.255|TelebecNET
67.78.0.0-67.79.0.0|Time Warner Cable
104.172.0.0-104.175.255.255|Time Warner Cable
173.168.0.0-173.175.255.255|Time Warner Cable
172.112.0.0-172.119.255.255|Time Warner Cable
108.184.0.0-108.185.255.255|Time Warner Cable
104.32.0.0-104.32.255.255|Time Warner Cable
67.240.0.0-67.255.255.255|Time Warner Cable Internet LLC
65.28.0.0-65.31.255.255|Time Warner Cable Internet LLC
173.196.0.0-173.198.159.255|Time Warner Cable Internet LLC
172.88.0.0-172.91.255.255|Time Warner Cable Internet LLC
66.8.128.0-66.8.255.255|Time Warner Cable Internet LLC
74.64.0.0-74.79.255.255|Time Warner Cable Internet LLC
23.240.0.0-23.243.255.255|Time Warner Cable Internet LLC
24.208.0.0-24.211.255.255|Time Warner Cable Internet LLC
72.176.0.0-72.191.255.255|Time Warner Cable Internet LLC
45.48.0.0-45.51.255.255|Time Warner Cable Internet LLC
68.172.0.0-68.175.255.255|Time Warner Cable Internet LLC
72.128.0.0-72.135.255.255|Time Warner Cable Internet LLC
24.106.128.0-24.106.255.255|Time Warner Cable Internet LLC
184.152.0.0-184.153.255.255|Time Warner Cable Internet LLC
24.92.160.0-24.95.255.255|Time Warner Cable Internet LLC
172.100.0.0-172.101.255.255|Time Warner Cable Internet LLC
24.198.0.0-24.198.255.255|Time Warner Cable Internet LLC
98.144.0.0-98.157.255.255|Time Warner Cable Internet LLC
24.123.128.0-24.123.255.255|Time Warner Cable Internet LLC
98.0.0.0-98.15.255.255|Time Warner Cable Internet LLC
24.24.0.0-24.29.255.255|Time Warner Cable Internet LLC
74.128.0.0-74.141.255.255|Time Warner Cable Internet LLC
66.108.0.0-66.108.255.255|Time Warner Cable Internet LLC
68.200.0.0-68.207.255.255|Time Warner Cable Internet LLC
174.96.0.0-174.111.255.255|Tune Warner Cable
174.141.192.0-174.141.207.255|US Internet Corp
192.163.192.0-192.163.255.255|Unified Layer
64.203.112.0-64.203.127.255|Unwired Broadband, Inc.
173.9.203.96-173.9.203.103|VELASQUEZ MUFFLER  and BRAKES
151.204.224.0-151.204.255.255|Verizon Internet Services
96.22.224.90-96.22.224.255|Videotron Ltee
173.178.105.0-173.178.105.255|Videotron Ltee
43.228.92.0/24|Viswaroopa Info Services India Private Ltd
162.213.24.0-162.213.31.255|Volume Drive
45.63.18.0-45.63.19.255|Vultr Holdings, LLC
45.32.136.0-45.32.137.255|Vultr Holdings, LLC
45.77.152.0-45.77.153.255|Vultr Holdings, LLC
65.60.240.0-65.60.243.255|WIDEOPENWEST OHIO
104.37.212.64-104.37.212.95|Wang Hui
208.66.24.0-208.66.31.255|Webpass
23.28.0.0-23.28.255.255|WideOpenWest Finance LLC
98.16.0.0-98.23.255.255|Windstream Communications LLC
196.0.0.0-196.255.255.25|actinic
169.0.0.0/8|actinic
132.0.0.0-132.0.255.255|actinic
137.0.0.0-137.255.255.255|afrinic
113.0.0.0/8|apnic
118.0.0.0/8|apnic
117.0.0.0/8|apnic
106.0.0.0/8|apnic
223.0.0.0/8|apnic
202.0.0.0/8|apnic
58.0.0.0-58.255.255.255|apnic
59.0.0.0-59.255.255.255|apnic
27.0.0.0/8|apnic
110.0.0.0/8|apnic
60.0.0.0/8|apnic
111.0.0.0/8|apnic
116.0.0.0/8|apnic
14.0.0.0/8|apnic
123.0.0.0/8|apnic
220.0.0.0/8|apnic
122.0.0.0/8|apnic
219.0.0.0/8|apnic
112.0.0.0/8|apnic
171.0.0.0/8|apnic
119.0.0.0/8|apnic
105.0.0.0/8|apnic
115.0.0.0/8|apnic
1.0.0.0/8|apnic
139.0.0.0-139.255.255.255|apnic
101.0.0.0-101.255.255.255|apnic
221.0.0.0-221.255.255.255|apnic
203.0.0.0/8|apnic
222.0.0.0/8|apnic
182.0.0.0/8|apnic
218.0.0.0-218.255.255.255|apnic
183.0.0.0/8|apnic
120.0.0.0-120.255.255.255|apnic
114.0.0.0/8|apnic
124.0.0.0/8|apnic
61.0.0.0/8|apnic
108.192.0.0/10|at+t
97.80.0.0-97.95.255.255|charter
104.238.188.0/23|choopa / vultr holdings
104.156.244.0/22|choopa vultr holdings
67.55.200.0-67.55.203.255|citizens Mutual Telephone Company
67.165.192.0-67.165.255.255|comcast
70.184.96.0-70.184.127.255|cox communications
70.166.96.0-70.166.127.255|cox communications
159.203.0.0-159.203.255.255|digital ocean
104.131.0.0-104.131.255.255|digital ocean
104.236.0.0/16|digital ocean - Cloud Hosting
159.89.0.0-159.89.255.255|digital ocean - Cloud Hosting
67.158.0.0-67.158.31.255|knowology inc
189.0.0.0/8|lacnic
191.0.0.0/8|lacnic
179.0.0.0/8|lacnic
181.0.0.0/8|lacnic
200.0.0.0/8|lacnic
180.0.0.0/8|lacnic
186.0.0.0/8|lacnic
187.0.0.0/8|lacnic
177.0.0.0/8|lacnic
190.0.0.0/8|lacnic
201.0.0.0/8|lacnic
216.241.0.0-216.241.31.255|lacnic
188.0.0.0/8|lacnic
148.0.0.0-148.255.255.255|lactic
138.0.0.0-138.255.255.255|lactic
131.0.0.0-131.255.255.255|lactic
108.0.0.0/10|mci + small cos on 108.58 + twang.sa 59 + in2network 60 + random 61 +  knobs 62
94.0.0.0/8|ripe
62.0.0.0/8|ripe
88.0.0.0/8|ripe
195.0.0.0/8|ripe
217.0.0.0/8|ripe
213.0.0.0-213.255.255.25|ripe
46.0.0.0/8|ripe
31.0.0.0/8|ripe
79.0.0.0/8|ripe
85.0.0.0/8|ripe
80.0.0.0/8|ripe
185.0.0.0/8|ripe
5.0.0.0/8|ripe
109.0.0.0/8|ripe
77.0.0.0/8|ripe
95.0.0.0/8|ripe
168.1.0.0-168.1.255.255|ripe
89.0.0.0/8|ripe
78.0.0.0/8|ripe
141.0.0.0-141.255.255.255|ripe
198.20.64.0-198.20.127.255|singlehop
158.85.81.112-158.85.81.127|soft layer
104.138.0.0/15|time warner
68.52.192.0-68.52.255.255|Comcast Cable Communications, Inc.
68.80.0.0-68.81.255.255|Comcast Cable Communications, Inc
66.190.120.0-66.190.127.255|Charter Communications
173.167.255.240-173.167.255.247|MEYERS MANAGEMENT
70.112.0.0-70.127.255.255|Time Warner Cable Internet LLC
70.160.0.0-70.161.255.255|Cox Communications
70.176.0.0-70.176.255.255|Cox Communications
70.177.128.0-70.177.159.255|Cox Communications
70.191.112.0-70.191.127.255|Cox Communications
70.25.77.0-70.25.77.255|Sympatico HSE
70.44.5.0-70.44.5.255|PenTeleData House Account
70.64.0.0-70.79.255.255|Shaw Communications Inc.
70.89.64.56-70.89.64.63|CURTIS H STOUT INC
70.92.0.0-70.95.255.255|Time Warner Cable Internet LLC
69.113.96.0-69.113.111.255|Optimum Online (Cablevision Systems)
69.116.144.0-69.116.147.255|Optimum Online (Cablevision Systems)
69.118.208.0-69.118.215.255|Optimum Online (Cablevision Systems)
69.123.120.0-69.123.127.255|Optimum Online (Cablevision Systems)
69.124.212.0-69.124.215.255|Optimum Online (Cablevision Systems)
69.126.156.0-69.126.159.255|Optimum Online (Cablevision Systems)
69.138.96.0-69.138.111.255|Comcast Cable Communications, Inc.
69.16.192.0-69.16.255.255|Liquid Web, L.L.C
69.176.64.0-69.176.79.255|Telesphere Networks Ltd
69.18.228.0-69.18.228.255|Eagle Communications, Inc.
69.200.0.0-69.207.255.255|Time Warner Cable Internet LLC
69.254.128.0-69.254.159.255|Comcast Cable Communications, Inc.
69.26.128.0-69.26.159.255|Aerioconnect
69.161.88.0-69.161.88.255|Metrocast Communications
71.0.0.0-71.3.255.255|Embarq Corporation
71.10.208.0-71.10.215.255|Charter Communications
71.128.0.0-71.159.255.255|AT+T Internet Services
71.13.225.110-71.13.239.255|Charter Communications
71.169.192.0-71.173.63.255|MCI Communications Services, Inc. d/b/a Verizon Business
71.173.96.0-71.180.255.255|MCI Communications Services, Inc. d/b/a Verizon Business
71.195.0.0-71.195.63.255|Comcast Cable Communications, IP Services
71.204.0.0-71.204.127.255|Comcast Cable Communications, IP Services
71.224.0.0-71.239.255.255|Comcast Cable Communications, LLC
71.241.224.0-71.253.255.255|MCI Communications Services, Inc. d/b/a Verizon Business
71.28.192.0-71.28.207.255|WINDSTREAM-COMMUNICATIONS
71.40.0.0-71.43.255.255|Time Warner Cable Internet LLC
71.6.146.128-71.6.146.191|CariNet, Inc.
71.64.0.0-71.79.255.255|Time Warner Cable Internet LLC
71.84.224.0-71.84.239.255|Charter Communications
71.91.136.0-71.91.143.255|Charter Communications
71.92.0.0-71.92.15.255|Charter Communications
72.0.156.96-72.0.156.103|GI Associates
72.136.0.0-72.143.255.255|Rogers Communications Canada Inc.
72.198.0.0-72.198.127.255|Cox Communications
72.201.0.0-72.201.255.255|Cox Communications
72.211.64.0-72.211.127.255|Cox Communications Inc.
72.218.0.0-72.218.255.255|Cox Communications
72.220.0.0-72.220.255.255|Cox Communications
72.224.0.0-72.231.255.255|Time Warner Cable Internet LLC
72.4.128.0-72.4.175.255|Affinity Internet, Inc
72.43.0.0-72.43.255.255|Time Warner Cable Internet LLC
72.46.200.0-72.46.202.255|ETS-TELEPHONE-BLOCK-3
72.73.128.0-72.87.47.255|MCI Communications Services, Inc. d/b/a Verizon Business
81.0.0.0-81.255.255.255|ripe
75.108.0.0-75.111.255.255|Suddenlink Communications
107.170.0.0-107.170.255.255|DigitalOcean, LLC
136.24.128.0-136.24.191.255|webpass
173.15.128.0-173.15.191.255|Comcast Business Communications, LLC
173.246.0.0-173.246.31.255|EBOX
199.36.117.0-199.36.117.255|AFFORDABLE COMPUTING and
205.144.208.0-205.144.223.255|Dalton Utilities
24.173.0.0-24.173.255.255|Time Warner Cable Internet LLC
50.113.0.0-50.113.255.255|Time Warner Cable Internet LLC
68.233.224.0-68.233.255.255|NOC4Hosts Inc.
68.50.0.0-68.50.255.255|Comcast Cable Communications, Inc.
70.184.152.0-70.184.159.255|Cox Communications
73.0.0.0-73.255.255.255|Comcast Cable Communications, LLC
74.116.56.0-74.116.59.255|Island Networks Ltd
74.120.4.0-74.120.7.255|Commstream Communications Inc
74.192.0.0-74.197.255.255|Suddenlink Communications
74.208.0.0-74.208.255.255|1+1 Internet Inc.
74.62.0.0-74.62.255.255|Time Warner Cable Internet LLC
74.93.88.224-74.93.88.231|VILLAGE OF WESTCHESTER
75.102.160.0-75.102.191.255|INTERSTATE TELECOMMUNICATIONS COOPERATIVE, INC.
75.103.128.0-75.103.223.255|Endeavor Communications
75.112.160.0-75.112.191.255|Bright House Networks
75.127.208.0-75.127.223.255|Static IP Services
75.129.32.0-75.129.47.255|Charter Communications
75.132.0.0-75.132.255.255|Charter Communications
75.152.0.0-75.159.255.255|TELUS
75.160.0.0-75.175.255.255|Qwest Communications Company, LLC
75.176.0.0-75.191.255.255|Time Warner Cable Internet LLC
75.0.0.0-75.63.255.255|AT+T Internet Services
75.99.91.32-75.99.91.39|GORLITZ CONGREGATION
75.99.96.224-75.99.96.231|MORTGAGE LIBERTY
98.173.144.0-98.173.159.255|Cox Communications Inc.
96.70.32.0-96.70.63.255|Comcast Cable Communications, LLC
96.46.24.0-96.46.27.255|Northwest Internet
149.255.0.0-149.255.255.255|ripe
76.11.216.0-76.11.223.255|New Wave Communications / Time Warner
76.121.0.0-76.121.255.255|Comcast Cable Communications, Inc.
76.16.0.0-76.31.255.255|Comcast Cable Communications, LLC
76.168.0.0-76.175.255.255|Time Warner Cable Internet LLC
76.183.0.0-76.183.255.255|Time Warner Cable Internet LLC
76.191.33.192-76.191.33.255|DSCI Engineering
76.220.58.160-76.255.255.255|AT+T Internet Services
76.72.0.0-76.72.127.255|Lafayette Consolidated Government
76.80.0.0-76.95.255.255|Time Warner Cable Internet LLC
76.97.0.0-76.97.255.255|Comcast Cable Communications, Inc


Wednesday, October 11, 2017

Today's Misbehaving IP addresses

I recently cleared out my list of auto-blocked IPs. Then I created a bunch of rules to permanently block some of the worst offending networks.

Here are the IPs that are still popping up in other ranges and trying to hit blocked ports on my test network. I believe that in most cases, whatever devices is running on these particular IP addresses, has been compromised. If anyone has a better explanation would love to hear it.

For more information how I got this list see:

https://www.secplicity.org/2017/08/11/using-firewall-policies-auto-block-rogue-hosts-external-networks/

https://www.secplicity.org/2017/10/03/world-network-traffic/

100.32.170.186 device blocked port
100.37.229.113 device blocked port
104.131.109.149 device blocked port
104.131.127.75 device blocked port
104.131.146.198 device blocked port
104.131.156.165 device blocked port
104.193.253.47 device blocked port
104.254.49.94 device blocked port
104.33.73.241 device blocked port
104.37.212.67 device blocked port
107.161.18.140 device blocked port
107.219.88.23 device blocked port
108.170.146.80 device blocked port
108.172.241.7 device blocked port
108.178.61.59 device blocked port
108.84.185.160 device blocked port
12.189.100.57 device blocked port
12.219.42.47 device blocked port
13.85.18.90 device blocked port
131.161.54.42 device blocked port
131.191.74.198 device blocked port
132.248.214.228 device blocked port
137.175.250.84 device blocked port
137.175.66.108 device blocked port
138.197.148.142 device blocked port
138.68.250.203 device blocked port
139.216.133.94 device blocked port
141.126.46.248 device blocked port
141.212.122.201 device blocked port
141.212.122.202 device blocked port
141.212.122.70 device blocked port
141.212.122.71 device blocked port
142.217.113.217 device blocked port
144.217.15.152 device blocked port
148.231.246.4 device blocked port
151.204.230.56 device blocked port
158.85.81.120 device blocked port
158.85.81.125 device blocked port
159.203.242.0 device blocked port
159.203.242.39 device blocked port
159.203.248.108 device blocked port
159.203.255.128 device blocked port
160.3.241.179 device blocked port
162.196.237.28 device blocked port
162.202.59.133 device blocked port
162.210.149.92 device blocked port
162.213.26.246 device blocked port
162.213.26.249 device blocked port
162.243.157.23 device blocked port
162.245.19.155 device blocked port
162.250.190.182 device blocked port
165.227.179.45 device blocked port
165.227.73.21 device blocked port
165.228.118.217 device blocked port
168.1.128.34 device blocked port
172.101.190.147 device blocked port
172.124.233.205 device blocked port
172.2.175.52 device blocked port
172.218.238.166 device blocked port
172.56.20.123 device blocked port
172.86.121.100 device blocked port
172.87.2.178 device blocked port
172.89.154.178 device blocked port
173.16.121.119 device blocked port
173.169.57.124 device blocked port
173.174.211.193 device blocked port
173.19.109.71 device blocked port
173.197.38.82 device blocked port
173.20.18.37 device blocked port
173.209.163.167 device blocked port
173.214.158.51 device blocked port
173.220.134.182 device blocked port
173.233.163.41 device blocked port
173.27.73.120 device blocked port
173.29.115.71 device blocked port
173.56.231.51 device blocked port
173.9.203.102 device blocked port
174.100.174.152 device blocked port
174.109.147.151 device blocked port
174.111.234.153 device blocked port
174.113.97.208 device blocked port
174.49.86.177 device blocked port
174.54.252.80 device blocked port
174.55.116.211 device blocked port
174.74.17.90 device blocked port
174.77.67.202 device blocked port
184.105.139.116 device blocked port
184.105.139.121 device blocked port
184.105.139.124 device blocked port
184.105.247.207 device blocked port
184.105.247.219 device blocked port
184.105.247.223 device blocked port
184.105.247.228 device blocked port
184.105.247.251 device blocked port
184.69.141.22 device blocked port
192.163.250.146 device blocked port
192.198.60.144 device blocked port
196.52.43.54 device blocked port
196.52.43.55 device blocked port
196.52.43.57 device blocked port
196.52.43.60 device blocked port
196.52.43.63 device blocked port
196.52.43.64 device blocked port
198.11.121.243 device blocked port
198.20.69.74 device blocked port
198.50.201.21 device blocked port
198.98.54.142 device blocked port
199.48.164.224 device blocked port
204.42.253.137 device blocked port
206.174.56.28 device blocked port
206.71.63.4 device blocked port
206.81.101.89 device blocked port
207.243.195.114 device blocked port
208.157.185.191 device blocked port
208.163.45.0 device blocked port
208.180.17.79 device blocked port
208.66.25.98 device blocked port
208.67.248.59 device blocked port
209.123.234.81 device blocked port
209.123.234.82 device blocked port
209.141.54.89 device blocked port
209.195.111.78 device blocked port
209.249.85.201 device blocked port
209.27.49.169 device blocked port
209.33.126.177 device blocked port
209.64.57.3 device blocked port
210.7.9.64 device blocked port
213.108.78.56 device blocked port
213.109.13.197 device blocked port
213.126.18.146 device blocked port
213.155.238.189 device blocked port
213.45.72.124 device blocked port
213.55.115.106 device blocked port
213.66.62.153 device blocked port
216.107.184.175 device blocked port
216.107.185.18 device blocked port
216.160.182.58 device blocked port
216.172.100.146 device blocked port
216.174.154.68 device blocked port
216.218.206.107 device blocked port
216.218.206.110 device blocked port
216.218.206.112 device blocked port
216.218.206.123 device blocked port
216.218.206.66 device blocked port
216.218.206.67 device blocked port
216.218.206.69 device blocked port
216.218.206.82 device blocked port
216.218.206.87 device blocked port
216.218.206.91 device blocked port
216.239.189.156 device blocked port
216.241.25.34 device blocked port
216.244.74.186 device blocked port
216.254.234.41 device blocked port
216.79.145.170 device blocked port
216.98.153.253 device blocked port
218.106.246.138 device blocked port
218.156.85.17 device blocked port
218.161.106.171 device blocked port
218.161.108.120 device blocked port
218.161.126.75 device blocked port
218.17.199.76 device blocked port
218.18.152.89 device blocked port
218.2.0.103 device blocked port
218.20.190.10 device blocked port
218.200.14.30 device blocked port
218.201.67.78 device blocked port
218.203.108.16 device blocked port
218.206.227.194 device blocked port
218.23.124.99 device blocked port
218.23.234.118 device blocked port
218.235.219.62 device blocked port
218.241.157.27 device blocked port
218.26.172.50 device blocked port
218.26.176.3 device blocked port
218.28.39.147 device blocked port
218.28.39.151 device blocked port
218.29.211.166 device blocked port
218.31.102.93 device blocked port
218.38.12.19 device blocked port
218.4.213.198 device blocked port
218.4.213.230 device blocked port
218.42.8.242 device blocked port
218.5.138.235 device blocked port
218.56.37.114 device blocked port
218.60.145.19 device blocked port
218.60.56.143 device blocked port
218.64.151.211 device blocked port
218.64.216.72 device blocked port
218.64.66.50 device blocked port
218.64.77.6 device blocked port
218.64.91.95 device blocked port
218.66.109.89 device blocked port
218.69.8.30 device blocked port
218.71.140.224 device blocked port
218.73.127.93 device blocked port
218.76.143.245 device blocked port
218.76.167.24 device blocked port
218.77.192.239 device blocked port
218.79.14.243 device blocked port
218.86.103.27 device blocked port
218.87.109.155 device blocked port
218.88.21.59 device blocked port
218.92.160.190 device blocked port
218.92.181.206 device blocked port
218.92.240.38 device blocked port
218.93.126.105 device blocked port
218.94.117.106 device blocked port
221.0.194.20 device blocked port
221.1.59.133 device blocked port
221.11.163.27 device blocked port
221.122.101.21 device blocked port
221.135.170.138 device blocked port
221.144.180.24 device blocked port
221.149.132.49 device blocked port
221.176.165.243 device blocked port
221.182.236.8 device blocked port
221.194.2.159 device blocked port
221.195.128.26 device blocked port
221.195.60.38 device blocked port
221.2.101.235 device blocked port
221.203.78.182 device blocked port
221.203.80.70 device blocked port
221.208.168.150 device blocked port
221.213.33.10 device blocked port
221.215.74.187 device blocked port
221.219.76.251 device blocked port
221.222.158.132 device blocked port
221.224.16.162 device blocked port
221.225.255.163 device blocked port
221.226.15.78 device blocked port
221.226.226.157 device blocked port
221.229.177.43 device blocked port
221.229.204.177 device blocked port
221.229.204.182 device blocked port
221.231.112.11 device blocked port
221.231.2.94 device blocked port
221.237.227.148 device blocked port
221.4.182.104 device blocked port
221.9.144.45 device blocked port
23.239.217.58 device blocked port
23.24.24.194 device blocked port
23.241.136.40 device blocked port
23.28.251.68 device blocked port
24.1.145.78 device blocked port
24.115.101.172 device blocked port
24.115.125.199 device blocked port
24.118.73.66 device blocked port
24.119.170.230 device blocked port
24.12.118.171 device blocked port
24.121.183.166 device blocked port
24.123.198.214 device blocked port
24.126.168.65 device blocked port
24.126.70.166 device blocked port
24.144.246.42 device blocked port
24.148.24.170 device blocked port
24.148.85.13 device blocked port
24.149.71.34 device blocked port
24.176.181.33 device blocked port
24.179.215.218 device blocked port
24.181.157.170 device blocked port
24.198.112.204 device blocked port
24.205.58.43 device blocked port
24.220.149.119 device blocked port
24.226.227.49 device blocked port
24.230.162.6 device blocked port
24.234.160.117 device blocked port
24.237.89.83 device blocked port
24.248.230.210 device blocked port
24.29.244.130 device blocked port
24.30.123.85 device blocked port
24.35.76.2 device blocked port
24.38.140.251 device blocked port
24.40.136.85 device blocked port
24.49.35.147 device blocked port
24.51.122.53 device blocked port
24.54.68.5 device blocked port
24.56.254.247 device blocked port
24.6.216.103 device blocked port
24.76.172.86 device blocked port
34.197.134.17 device blocked port
35.194.150.190 device blocked port
38.104.1.186 device blocked port
38.78.199.162 device blocked port
45.32.136.54 device blocked port
45.49.38.55 device blocked port
45.55.10.94 device blocked port
45.55.11.57 device blocked port
45.55.13.94 device blocked port
45.55.20.78 device blocked port
45.55.31.248 device blocked port
45.56.91.118 device blocked port
45.63.19.215 device blocked port
45.77.152.129 device blocked port
45.79.106.170 device blocked port
45.79.223.204 device blocked port
47.145.139.63 device blocked port
47.147.16.202 device blocked port
47.154.248.97 device blocked port
47.197.176.139 device blocked port
47.23.23.109 device blocked port
47.42.71.182 device blocked port
47.44.167.210 device blocked port
47.50.220.230 device blocked port
50.103.98.2 device blocked port
50.198.116.253 device blocked port
50.199.164.182 device blocked port
50.199.188.197 device blocked port
50.24.14.192 device blocked port
50.243.180.218 device blocked port
50.247.155.1 device blocked port
50.29.180.145 device blocked port
50.5.232.64 device blocked port
50.61.239.72 device blocked port
50.77.124.242 device blocked port
52.227.175.53 device blocked port
52.43.235.21 device blocked port
58.96.85.14 device blocked port
59.100.14.9 device blocked port
59.102.100.202 device blocked port
63.143.69.72 device blocked port
64.121.119.66 device blocked port
64.130.135.198 device blocked port
64.145.111.26 device blocked port
64.184.42.88 device blocked port
64.187.217.234 device blocked port
64.20.76.175 device blocked port
64.203.116.102 device blocked port
65.101.54.88 device blocked port
65.111.164.93 device blocked port
65.181.118.96 device blocked port
65.36.116.181 device blocked port
65.60.242.150 device blocked port
66.108.109.39 device blocked port
66.163.146.64 device blocked port
66.165.223.206 device blocked port
66.168.112.165 device blocked port
66.172.104.100 device blocked port
66.191.7.121 device blocked port
66.208.250.189 device blocked port
66.214.111.42 device blocked port
66.229.131.46 device blocked port
67.158.15.153 device blocked port
67.161.204.192 device blocked port
67.165.212.69 device blocked port
67.166.134.229 device blocked port
67.180.128.240 device blocked port
67.182.49.39 device blocked port
67.183.70.186 device blocked port
67.198.111.176 device blocked port
67.20.43.20 device blocked port
67.209.70.122 device blocked port
67.213.84.198 device blocked port
67.55.200.181 device blocked port
67.55.201.198 device blocked port
67.55.202.125 device blocked port
67.55.202.203 device blocked port
67.55.202.252 device blocked port
67.79.180.130 device blocked port
67.8.110.71 device blocked port
68.104.231.105 device blocked port
68.108.44.178 device blocked port
68.168.101.171 device blocked port
68.174.199.115 device blocked port
68.186.42.195 device blocked port
68.188.150.174 device blocked port
68.188.169.171 device blocked port
68.192.57.220 device blocked port
68.228.217.225 device blocked port
68.35.102.69 device blocked port
68.4.130.103 device blocked port
68.4.89.77 device blocked port
68.50.59.50 device blocked port
68.80.6.106 device blocked port
69.113.99.154 device blocked port
69.116.147.145 device blocked port
69.122.9.14 device blocked port
69.123.122.191 device blocked port
69.138.106.158 device blocked port
69.16.251.248 device blocked port
69.161.88.7 device blocked port
69.176.74.166 device blocked port
69.18.228.34 device blocked port
69.203.76.27 device blocked port
69.206.174.41 device blocked port
69.254.150.144 device blocked port
70.119.240.177 device blocked port
70.126.98.47 device blocked port
70.161.89.46 device blocked port
70.166.121.105 device blocked port
70.166.81.119 device blocked port
70.176.246.56 device blocked port
70.184.114.70 device blocked port
70.184.154.78 device blocked port
70.184.90.187 device blocked port
70.191.114.103 device blocked port
70.25.77.58 device blocked port
70.78.101.15 device blocked port
70.89.64.58 device blocked port
70.95.53.98 device blocked port
71.10.213.244 device blocked port
71.13.225.110 device blocked port
71.170.243.94 device blocked port
71.171.45.51 device blocked port
71.202.78.113 device blocked port
71.204.126.95 device blocked port
71.236.24.184 device blocked port
71.251.20.67 device blocked port
71.6.142.85 device blocked port
71.69.232.229 device blocked port
71.76.176.239 device blocked port
71.83.83.186 device blocked port
71.84.231.250 device blocked port
71.92.0.147 device blocked port
72.0.156.102 device blocked port
72.130.18.195 device blocked port
72.141.79.40 device blocked port
72.177.33.246 device blocked port
72.177.83.134 device blocked port
72.181.214.179 device blocked port
72.198.52.144 device blocked port
72.201.130.228 device blocked port
72.218.42.62 device blocked port
72.220.20.40 device blocked port
72.228.2.52 device blocked port
72.27.212.206 device blocked port
72.27.87.143 device blocked port
72.4.145.14 device blocked port
72.46.201.40 device blocked port
72.80.117.44 device blocked port
73.100.3.7 device blocked port
73.118.244.207 device blocked port
73.137.125.195 device blocked port
73.140.155.36 device blocked port
73.159.93.59 device blocked port
73.162.23.176 device blocked port
73.188.15.55 device blocked port
73.193.229.136 device blocked port
73.211.84.4 device blocked port
73.214.56.55 device blocked port
73.219.75.26 device blocked port
73.222.199.144 device blocked port
73.224.64.224 device blocked port
73.233.62.176 device blocked port
73.247.222.172 device blocked port
73.252.247.79 device blocked port
73.254.23.194 device blocked port
73.91.183.170 device blocked port
73.97.168.109 device blocked port
74.116.56.14 device blocked port
74.120.4.107 device blocked port
74.133.129.195 device blocked port
74.138.131.140 device blocked port
74.192.61.227 device blocked port
74.194.5.67 device blocked port
74.64.92.117 device blocked port
74.78.212.15 device blocked port
74.82.47.3 device blocked port
74.82.47.31 device blocked port
74.82.47.36 device blocked port
74.82.47.43 device blocked port
74.82.47.45 device blocked port
74.82.47.53 device blocked port
74.82.47.54 device blocked port
74.93.88.225 device blocked port
75.103.190.115 device blocked port
75.109.210.24 device blocked port
75.127.221.34 device blocked port
75.129.39.147 device blocked port
75.132.10.38 device blocked port
75.132.237.221 device blocked port
75.138.54.130 device blocked port
75.147.135.78 device blocked port
75.152.9.252 device blocked port
75.168.71.203 device blocked port
75.170.161.22 device blocked port
75.177.87.57 device blocked port
75.178.28.200 device blocked port
75.185.92.50 device blocked port
75.19.8.189 device blocked port
76.121.228.171 device blocked port
76.16.220.145 device blocked port
76.169.192.66 device blocked port
76.17.62.2 device blocked port
76.179.132.56 device blocked port
76.183.182.163 device blocked port
76.191.33.197 device blocked port
76.24.216.32 device blocked port
76.72.12.237 device blocked port
76.95.1.8 device blocked port
76.97.158.179 device blocked port
8.29.87.4 device blocked port
81.248.2.209 device blocked port
96.22.224.90 device blocked port
96.3.64.105 device blocked port
96.35.229.125 device blocked port
96.36.98.42 device blocked port
96.40.157.189 device blocked port
96.47.99.173 device blocked port
96.57.181.148 device blocked port
96.63.249.203 device blocked port
96.64.233.163 device blocked port
96.70.205.225 device blocked port
96.70.74.69 device blocked port
96.80.19.70 device blocked port
96.83.245.146 device blocked port
96.84.146.230 device blocked port
97.68.31.130 device blocked port
97.86.153.179 device blocked port
97.89.32.202 device blocked port
97.89.33.69 device blocked port
97.94.246.72 device blocked port
98.113.20.31 device blocked port
98.116.71.21 device blocked port
98.121.89.70 device blocked port
98.14.132.114 device blocked port
98.151.126.126 device blocked port
98.165.144.22 device blocked port
98.183.172.158 device blocked port
98.19.30.174 device blocked port
98.195.87.135 device blocked port
98.202.99.22 device blocked port
98.217.37.130 device blocked port
98.218.162.97 device blocked port
99.112.224.152 device blocked port
99.113.149.34 device blocked port
99.224.113.107 device blocked port
99.51.162.176 device blocked port
99.68.146.9 device blocked port
99.7.196.106 device blocked port