The following ASes are now blocked from my home network.
- 208077 COMPASTELECOM LLP (KZ)
- 41039 Timer, LLC (RU)
- 8717 A1 Bulgaria EAD (BG)
- 39927 E-Light-Telecom Ltd. (RU)
- 17557 Pakistan Telecommunication Company Limited (PK)
- 12997 OJSC Kyrgyztelecom (KG)
- 24921 Latvijas Mobilais Telefons SIA (LV)
- 133278 Dehradun Enet Solutions Private Ltd (IN)
- 45536 Readylink Internet Services Limited (IN)
- 37061 Safaricom (KE)
- 36947 ALGTEL-AS (DZ)
- 9260 Multinet Pakistan Pvt. Ltd. (PK)
- 141334 Skynet Digital Services Pvt. Ltd. (IN)
- 36994 Vodacom-VB (ZA)
- 48004 PE Tsibrankov Konstantin Igorevich (UA)
- 3326 Datagroup PRIVATE JOINT STOCK COMPANY (UA)
- 134032 INFONET COMM ENTERPRISES (IN)
This was triggered by the following log entries.
212.46.56.169 - - [22/Apr/2024:04:43:14 -0400] "GET /wp-login.php HTTP/1.1" 301 239 195.184.214.82 - - [22/Apr/2024:04:44:16 -0400] "GET /wp-login.php HTTP/1.1" 301 239 195.24.40.178 - - [22/Apr/2024:04:45:41 -0400] "GET /wp-login.php HTTP/1.1" 301 239 176.196.46.109 - - [22/Apr/2024:04:46:04 -0400] "GET /admin/ HTTP/1.1" 301 233 182.180.35.167 - - [22/Apr/2024:04:46:30 -0400] "GET /admin/ HTTP/1.1" 301 233 212.97.4.143 - - [22/Apr/2024:04:47:21 -0400] "GET /admin/ HTTP/1.1" 301 233 80.89.79.165 - - [22/Apr/2024:04:48:07 -0400] "GET /admin/ HTTP/1.1" 301 233 103.230.153.134 - - [22/Apr/2024:04:49:27 -0400] "GET /downloader/ HTTP/1.1" 301 238 103.230.153.134 - - [22/Apr/2024:04:49:29 -0400] "GET /downloader/ HTTP/1.1" 404 196 103.230.153.134 - - [22/Apr/2024:04:49:33 -0400] "GET /admin.php HTTP/1.1" 301 236 103.21.79.131 - - [22/Apr/2024:04:49:56 -0400] "GET /admin.php HTTP/1.1" 301 236 41.139.174.67 - - [22/Apr/2024:04:50:20 -0400] "GET /admin.php HTTP/1.1" 301 236 41.104.30.47 - - [22/Apr/2024:04:50:32 -0400] "GET /admin.php HTTP/1.1" 301 236 125.209.67.210 - - [22/Apr/2024:04:51:40 -0400] "GET /Backoffice/ HTTP/1.1" 301 238 125.209.67.210 - - [22/Apr/2024:04:51:41 -0400] "GET /Backoffice/ HTTP/1.1" 404 196 103.159.107.172 - - [22/Apr/2024:04:51:44 -0400] "GET /administrator/ HTTP/1.1" 301 241 105.246.210.136 - - [22/Apr/2024:04:52:08 -0400] "GET /administrator/ HTTP/1.1" 301 241 195.18.19.81 - - [22/Apr/2024:04:53:04 -0400] "GET /administrator/ HTTP/1.1" 301 241 93.183.203.243 - - [22/Apr/2024:04:53:25 -0400] "GET /administrator/ HTTP/1.1" 301 241 103.58.115.60 - - [22/Apr/2024:04:53:39 -0400] "GET /administrator/ HTTP/1.1" 301 241
Note that all of the probes seen in the log above occurred within about 10 minutes. Also note that almost none of them handled 301. This is the signature of a poorly implemented botnet. Also note that they’re all from continents other than my own.
I’m still working on the automation for this, but the scheme is working. For a given nefarious query, I look up the route in the global BGP routing table to find the origin AS (in my local copy, using my Ipv4Routes class). I then look up the country for the origin AS, and based on my configured policy, block the entire AS for up to 2 years. For example, Russian (RU) ASes are always blocked for 2 years.
Later I saw similar activity that triggered the blocking of the following ASes.
- 35816 SEVSTAR Lancom Ltd. (RU)
- 53754 SYSTEMA Ltd (RU)
- 58310 TELEPORT LLC (RU)
- 208142 LLC Rocket Telecom (RU)
- 7303 Telecom Argentina S.A. (AR)
- 28075 ARLINK S.A. (AR)
- 5384 EMIRATES TELECOMMUNICATIONS GROUP COMPANY (ETISALAT GROUP) PJSC (AE)
- 7418 TELEFONICA CHILE S.A. (CL)
- 9541 Cyber Internet Services Pvt Ltd. (PK)
- 12735 TurkNet Iletisim Hizmetleri A.S. (TR)
- 13489 EPM Telecomunicaciones S.A. E.S.P. (CO)
- 17858 LG POWERCOMM (KR)
- 25553 TRK Gluhov Ltd. (UA)
- 28458 IENTC S DE RL DE CV (MX)
- 35457 Etisalcom Bahrain Company W.L.L. (BH)
- 62240 Clouvider Limited (GB)










