Navigating the Digital Storm

  • INTERNET WEATHER REPORT ☁️☀️

    AS219502, also known as STORMCLOUD-AS and registered to Storm Industries LLC, has just been added to the ASN watchlist.

    This autonomous system currently originates one IPv4 prefix:

    • 94.154.43.0/24

    That sole prefix is already lighting up abuse reporting. AbuseIPDB currently shows 90 reported IPs inside 94.154.43.0/24, with more than 6,300 total reports across the /24.

    This is not just reputation noise. One host inside the block, 94.154.43.58, was observed directly in my own firewall data performing a slow, randomized TCP port sweep against a monitored endpoint.

    Observed scanning from 94.154.43.58

    In the reviewed traffic sample, 94.154.43.58 generated:

    • 5,632 TCP connection attempts
    • one monitored destination
    • 5,587 unique destination ports
    • scan window: 30 Jun 2026 from 02:44:30 PT to 19:59:16 PT
    • source ports repeatedly clustered at 49152 through 49159

    The destination-port pattern does not look like a single-service brute-force attempt. It looks like a slow randomized vertical port sweep across one target. The scan touched a broad mix of well-known, registered, and high ephemeral ports, including examples such as:

    • 135
    • 443
    • 587
    • 1433
    • 6379
    • 9300
    • 9418
    • 10000
    • 27018

    The operational takeaway is simple: this was unsolicited reconnaissance from inside 94.154.43.0/24.

    Public abuse reputation

    The same source IP, 94.154.43.58, is also publicly reported on AbuseIPDB with 100% abuse confidence and recent reports describing port scanning, RDP probing, and blocked TCP SYN traffic using the same low source-port range seen in the local logs.

    Other hosts in the same /24 are also heavily reported. For example, 94.154.43.181 shows more than 1,000 AbuseIPDB reports and recent SSH brute-force activity. That matters because the case against this block does not rest on one noisy host. The whole /24 shows a pattern of active abuse.

    Routing and infrastructure context

    AS219502 is a very new ASN. The RIPE aut-num object for AS219502 was created on 9 Jun 2026 and uses the as-name STORMCLOUD-AS.

    BGP data reviewed for this report shows AS219502 currently originating 94.154.43.0/24. The route is valid from a routing-policy perspective, but “valid route” does not mean “safe network.” It only means the route is authorized within the routing system.

    The StormCloud public website markets offshore VPS, web hosting, proxy services, LIR services, IPv4 subnet allocation, BGP announcements, no mandatory identity verification, cryptocurrency payments, and high network usage. That combination is not proof of abuse by itself, but it is exactly the kind of hosting posture that attracts scanners, botnet operators, proxy abuse, phishing infrastructure, and disposable criminal workloads.

    The AS214472 / xlabs_v1 connection

    There is also relevant history around related Storm/Offshore infrastructure.

    Storm Industries’ own public site identifies Storm Industries LLC as the backend infrastructure and network operations entity behind StormCloud and lists AS214472 as part of that infrastructure. Public BGP data for AS214472 identifies it as Offshore LC with the as-name STORMINDUSTRIES.

    That matters because Hunt.io published research in April 2026 on the xlabs_v1 DDoS-for-hire IoT botnet. In that report, operator-controlled infrastructure was tied to 176.65.139.0/24, announced by AS214472. The botnet was described as a Mirai-derived DDoS-for-hire operation targeting game servers and Minecraft hosts.

    There is now also a RIPE route object for 176.65.139.0/24 with origin AS219502, created on 25 Jun 2026. That does not prove the same activity is currently operating from AS219502, and it does not prove that 94.154.43.0/24 was used in the xlabs_v1 operation. But it does create a clear routing and infrastructure relationship between the newer AS219502 and the older AS214472/StormCloud infrastructure family.

    Why AS219502 should be treated as hostile

    The case against AS219502 is not based on a single packet, a single report, or one random firewall hit.

    The evidence chain is broader:

    • AS219502 is a newly created StormCloud/Storm Industries ASN
    • it currently originates only one visible IPv4 /24
    • that /24 already has 90 reported IPs and thousands of AbuseIPDB reports
    • one IP inside the /24 was directly observed performing a randomized TCP port sweep
    • the observed source-port behavior matches public reports for the same IP
    • other hosts in the /24 show heavy abuse reporting, including SSH brute-force activity
    • related Storm/Offshore infrastructure has prior public reporting tied to DDoS-for-hire botnet infrastructure
    • StormCloud publicly advertises no-KYC, crypto-only, high-network-usage-friendly offshore hosting

    Taken together, this is enough to classify AS219502 and 94.154.43.0/24 as hostile scanner infrastructure.

    Indicators

    ASN

    • AS219502
    • STORMCLOUD-AS
    • Storm Industries LLC

    Prefix

    • 94.154.43.0/24

    Observed scanner IP

    • 94.154.43.58

    Related infrastructure context

    • AS214472
    • 176.65.139.0/24
    • StormCloud
    • Storm Industries / Offshore LC infrastructure

    Observed behavior

    • unsolicited TCP port scanning
    • randomized vertical port sweep
    • source ports clustered at 49152 through 49159
    • public reports of port scanning, RDP probing, SSH brute-force, and abusive network activity

    Bottom line

    AS219502 is a newly created StormCloud/Storm Industries ASN currently originating 94.154.43.0/24. That prefix is already heavily represented in public abuse reporting, and at least one host inside the block was directly observed performing a slow randomized TCP port sweep.

    Whether the best label is abusive customer infrastructure, abuse-tolerant hosting, disposable scanner infrastructure, or a newly stood-up successor to earlier Storm/Offshore activity, the operational conclusion is the same:

    Traffic from 94.154.43.0/24 should be treated as hostile.

    Drop It Like It’s Hot.

    Latest updates to the ASN watchlist posted on the ASN Watchlist page.

     

     

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • INTERNET WEATHER REPORT ☁️☀️

    AS399979 (49.3 Networking LLC) has just been added to ASN watchlist.

    This autonomous system currently originates one IPv4 prefix:

    45.139.104.0/24

    That sole prefix, 45.139.104.0/24, currently shows 95 reported IPs and 18,639 total reports on
    AbuseIPDB.

    A review of passive DNS tied to this /24 suggests what appears to be large-scale phishing-themed infrastructure spanning financial accounts, streaming subscriptions, health portals, tolling, government services, and parcel/logistics impersonation.

    After filtering out obvious Plesk placeholder hostnames, wildcard junk, duplicate www variants, and generic filler entries, the following 100 domains stood out as the strongest phishing-related examples visible in passive DNS for this block:

    Financial / account access / identity

    • luxtrust-dossieroppo.com
    • icloud-user-support.com
    • banka-365.com
    • ucet-365.com
    • paypai.websapps.de
    • paypai-sicheren.de
    • paypai.validierung.me
    • paypal.de-helfen.me
    • pay-pal-myapp.com
    • connect-payment.net
    • servicecustomerbilling.com
    • mycns-account.com
    • myfiix-bill.com
    • pay.pal-nachrichten.com
    • mypay.pal-nachrichten.com

    Streaming / subscription / Netflix-themed

    • noreply-neftlixaccount.com
    • ntlfixaccntservice.com
    • ntfxregis.com
    • pay-netflx.com
    • netflxpay.com
    • netflix-cancelled.com
    • netflix-update-account.com
    • netflixrenouvellement.com
    • netflixrenouvellement.fr
    • netflix-subskriptions.de
    • netflix-subskription.net
    • netflix-helfen.net
    • netflix-hilfe.de
    • monthlyntflx.com
    • ntfxmonthly.com

    Health / social services / Vitale / Ameli / Doctolib-themed

    • macartesante-vitalefrance.com
    • cartevitalefrance.com
    • macartevitale-sante.com
    • nouvelle-carte-vitale.com
    • carte-santevitale.com
    • assurance-maladie-cpam.com
    • support-cpam.com
    • ameli-compte.info
    • info-ameli-assurance.com
    • info-ameli-vitale.com
    • renouvellement-sante-maladie.com
    • mes-demarches-vitale.com
    • carte-vitale-suivi.com
    • mon-espace-ameli.com
    • mon-espace-sante-ameli.com
    • renouvellementameli2025.com
    • ameli-service-public.com
    • vitale-support.com
    • doctolib-mise-a-jour.info
    • doctolib-app.com

    Government / fines / tolls / transport-themed

    • peageauto-regularisation.com
    • ulysfrance.com
    • service-ulys.com
    • ulys-autoroutes.com
    • ulys-autoroutes.net
    • telepeage-facture.com
    • paybadge-relance.com
    • impaye-ulys.com
    • peage-ulys.org
    • contravention-regularisation.com
    • info-amendesgouv.com
    • amendes-regulariser-paiement.com
    • dossier-infraction.com
    • antai.antsdemarches.com
    • ants-demarches.com

    Parcel / logistics / delivery-themed

    • mydhl-kw-t.com
    • mydhl-kuwait.com
    • trackship-dhl.com
    • dhl-infos.de
    • delivery-upsworld.com
    • upstrackpackages.com
    • globaldelivery-connect.com
    • auspost-packageonhold.com
    • auspost-customsprccs.com
    • assistance-package-delivery.info
    • hometrack-assistance-package.info
    • track-pakpost.com
    • infosuivicolissimo.com
    • mon-suivi-colissimo.com
    • info-suivi-laposte.com
    • suivi-colis-colissimo.com
    • colissimo-info-colis.com
    • relay-colis-retour.info
    • livraisoncolis-mondialrelay.com
    • mondialrelay-statutcolis.com
    • track-my-mondialrelay.com
    • colis-mondialrelay-suivi.com
    • clients-mondialrelay.com
    • mondialrelay-livraisoncolis.com
    • mondialrelay-maj-colis.com
    • retour-mondialrelay.com
    • reprogramme-mon-colis.com
    • service-mondiaireiay.com
    • infocolis-suivi.com
    • suivicolissimo-info.com
    • locker-mondialrelayy.com
    • mondial-points-relais.info
    • mrelay-distri.com
    • livraison-mon-relay.info
    • monrelay-suivi.com

    Drop It Like It’s Hot.

    Latest updates to the ASN watchlist posted here:
    https://internetweather.net/asn-watchlist/

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • 77.90.141.0/24 is a suspected stolen or misappropriated BGP prefix currently being used for QuickBooks callback phishing and abusive email delivery. In the phishing samples reviewed for this report, three separate emails were sent directly from hosts inside 77.90.141.0/24. Those messages impersonated Intuit and QuickBooks, used the same callback phishing template, and were still active as of 13 Mar 2026 PT.

    This post focuses only on direct evidence tied to 77.90.141.0/24. Nine phishing emails were reviewed in total. Three were directly linked to this prefix. Six others were sent from different IP space and are not attributed here to 77.90.141.0/24.

    77.90.141.0/24 routing and RIPE data

    The RIPE data reviewed for this report identifies the prefix as:

    • inetnum: 77.90.141.0 – 77.90.141.255
    • netname: SUBALLOC-CONTRUST
    • country: DE
    • status: SUB-ALLOCATED PA
    • responsible organisation: K&K Kommunikationssysteme GmbH
    • abuse contact: alex.kontrast.eu@gmail.com

    The same RIPE data shows a route object for 77.90.141.0/24 with origin AS396073. The route object was created on 11 Oct 2025 UTC. The inetnum object for the current /24 record was created on 12 Oct 2025 UTC.

    The routing-history view reviewed for this prefix shows older visibility, a long quiet period after 2019, and later reappearance under multiple origin ASNs, including AS62425, AS208485, and AS396073. That is not what normal, stable, long-term stewardship of a customer prefix looks like. It looks like a questionable custody trail followed by active abuse.

    For that reason, the most accurate description here is not a classic short-lived BGP hijack. The better description is a suspected stolen prefix, a likely misappropriated prefix, or a quietly taken-over netblock that is now being used for phishing operations.

    Direct phishing evidence from 77.90.141.0/24

    Three QuickBooks phishing emails in the reviewed set were sent directly from IPs inside 77.90.141.0/24.

    1) 26 Feb 2026 PT

    • Subject: Your QuickBooks Subscription is due for renewal [redacted]
    • Display identity: notification@quickbooks.intuit.com
    • Return-path: info@qbmarketpro.biz
    • Source host: server7.hgranticsy.com
    • Source IP: 77.90.141.39

    2) 6 Mar 2026 PT

    • Subject: Your QuickBooks subscription is due for renewal [redacted]
    • Display identity: Intuit inc
    • Return-path: info@freshledas.com
    • Source host: server6.freshledas.com
    • Source IP: 77.90.141.9

    3) 13 Mar 2026 PT

    • Subject: Your QuickBooks subscription is due for renewal. [redacted]
    • Display identity: notification@intuit.com
    • Return-path: info@enlito.info
    • Source host: server4.enlito.info
    • Source IP: 77.90.141.11

    These were not random lookalike spam messages. These were structured Intuit and QuickBooks impersonation emails delivered from three separate IPs inside the same /24 over a short time period.

    This was callback phishing, not ordinary click phishing

    The QuickBooks lure in these emails was designed to push the recipient into a phone-based scam workflow. The messages claimed there was a QuickBooks subscription renewal problem, payment issue, or billing failure and instructed the recipient to call a toll-free number for assistance.

    The repeated callback number in the three emails was:

    +1 (803) 210-4380

    That makes this a callback phishing campaign. The goal is not just to get a click. The goal is to get the target on the phone with the operator.

    That matters because callback phishing often targets businesses, accounting staff, finance personnel, and users who are more likely to trust a billing problem than a generic credential theft page.

    Shared fingerprints across the three emails

    The three emails sent from 77.90.141.0/24 shared multiple technical fingerprints that tie them together as one operation or one reusable phishing kit.

    Observed shared traits:

    • same QuickBooks subscription renewal lure
    • same callback number: +1 (803) 210-4380
    • same mailer fingerprint: X-Mailer: Smart_Send_4_4_2
    • same Message-ID host pattern: @WIN-KEJVO9CLD80
    • same pair of inline image attachments: 1.png and 2.png
    • same overall wording and structure, with only minor date changes

    This is a strong cluster, not three unrelated messages.

    Why these messages are more dangerous than average junk spam

    These messages were built to look polished and familiar. They used Intuit and QuickBooks branding, billing language, renewal language, and a support-style phone workflow. The text was cleaner than low-grade commodity phishing. The senders also rotated throwaway domains while keeping the same lure, the same phone number, and the same mailer artifacts.

    Two of the three messages authenticated cleanly for the attacker-controlled sender domains using SPF, DKIM, and DMARC. The third soft-failed SPF but still passed DKIM and DMARC. That does not make the emails legitimate. It means the phishing operator controlled the sender domains well enough to pass basic email checks for its own infrastructure.

    That is a higher-effort operation than the usual low-quality phish.

    Why 77.90.141.0/24 should be treated as hostile

    The case against 77.90.141.0/24 does not rest on one bad domain or one isolated email. The evidence chain is broader:

    • questionable routing and custody history for the BGP prefix
    • new RIPE route and inetnum records appearing in Oct 2025
    • later visibility under multiple origin ASNs
    • active QuickBooks callback phishing sent directly from multiple IPs in the /24
    • shared infrastructure fingerprints across the phishing emails

    Taken together, the observed behavior is consistent with abuse-tolerant infrastructure and phishing delivery. Whether the best label is suspected stolen prefix, misappropriated prefix, or quietly taken-over netblock, the operational conclusion is the same: traffic originating from 77.90.141.0/24 should be treated as high risk.

    Indicators

    Prefix and ASN

    • 77.90.141.0/24
    • AS396073
    • historical origins observed in supplied routing history: AS62425, AS208485, AS396073

    Observed phishing source IPs

    • 77.90.141.39
    • 77.90.141.9
    • 77.90.141.11

    Observed source hosts

    • server7.hgranticsy.com
    • server6.freshledas.com
    • server4.enlito.info

    Observed sender domains

    • qbmarketpro.biz
    • freshledas.com
    • enlito.info

    Phishing theme

    • QuickBooks subscription renewal
    • QuickBooks billing problem
    • Intuit impersonation
    • callback phishing

    Reused callback number

    • +1 (803) 210-4380

    Shared mailer artifact

    • Smart_Send_4_4_2

    Bottom line

    77.90.141.0/24 is a suspected stolen or misappropriated prefix that is actively being used for QuickBooks callback phishing. Based on the phishing samples reviewed for this report, this was not a one-off event. The same infrastructure delivered multiple near-identical Intuit and QuickBooks lures from multiple IPs inside the same /24 between 26 Feb 2026 PT and 13 Mar 2026 PT.

    That is enough to classify 77.90.141.0/24 as phishing infrastructure.

  • On 12/17/2025, I received a “Verify your email address” message that appeared to be a legitimate Fedora Accounts verification email. The sender authenticated cleanly (SPF pass, DKIM pass, DMARC pass) and originated from Fedora infrastructure (fas@fedoraproject.org, via bastion.fedoraproject.org).

    But the HTML body contained a cryptocurrency-themed phishing payload that had nothing to do with Fedora.

    What the email looked like (the tell)

    The plain-text part was normal Fedora account verification copy:

    • “This email address has been used to sign up for a Fedora Account…”

    • An activation link on accounts.fedoraproject.org

    • A 60-minute validity window

    The HTML part, however, opened with attacker-controlled content:

    • “✅ We have partnered with BINANCE… you have won a mining account with 1.3465 BTC…”

    • A link out to graph.org (phish landing page)

    • Instructions to “send proof” to “BINANCE online chat”

    Then the email continued with the legitimate Fedora activation link and boilerplate.

    That split (clean text/plain + poisoned text/html) is a classic way to slip past both automated scanning and a user’s quick glance, especially when the sender domain is reputable and authentication passes.

    Why this is a problem

    This is not “just another scam email.”

    • The message was sent from a legitimate Fedora Project mail path and passed authentication checks.

    • That gives the phish credibility and significantly increases the chance a recipient trusts it.

    • It also means mailbox providers and filters are more likely to deliver it instead of quarantining it.

    In other words: the threat actors didn’t spoof Fedora – they appear to have used Fedora Accounts as a delivery mechanism.

    Likely abuse path (best inference from the artifact)

    I don’t have Fedora’s backend logs, but based on the content structure, the most plausible scenario is:

    • An attacker automated account registrations against the Fedora Accounts signup flow, inserting victim email addresses.

    • During registration, they populated some user-controlled field that gets rendered into the HTML template (for example: “full name”, “display name”, or another profile/registration field).

    • That field was either:

      • Rendered without proper output encoding, or

      • Allowed HTML/markup that was not sanitized, or

      • Passed through a formatter that produced HTML with unsafe content.

    Result: Fedora’s mailer generated a verification email where the HTML portion contained attacker content, while the plain-text portion remained “normal,” increasing deliverability and deception.

    That is consistent with the greeting line in the HTML being replaced with the phishing message, while the rest of the template remains intact.

    What I did

    • I reported the issue to Red Hat/Fedora security contacts (including Red Hat security).

    • As of 12/18/2025, I did not receive a response.

    • I also forwarded it to a Fedora contact address I could find (including Code of Conduct-related routing) as a “someone needs to see this” escalation, even if it’s not the perfect intake channel.

    What Fedora should do (quick, practical fixes)

    If you run a community identity/signup system, this is the defensive checklist I’d start with:

    • Remove user-controlled fields from verification emails entirely, or strictly escape/encode them (no HTML allowed, ever).

    • Ensure the HTML template uses safe output encoding for every variable.

    • Make text/plain and text/html content-identical in meaning, so one can’t be “clean” while the other is weaponized.

    • Add rate limiting, bot detection, and/or CAPTCHA on registration attempts.

    • Add abuse detection for high-volume signups and unusual field content (URLs, crypto keywords, excessive Unicode symbols).

    • Consider suppressing outbound verification email if the display-name/full-name contains suspicious patterns until reviewed.

    What recipients should do

    If you get a “verify your email” message you didn’t initiate:

    • Do not click anything, even if SPF/DKIM/DMARC pass.

    • Treat it as hostile when it contains:

      • crypto giveaways, “you won” language, or external links unrelated to the service

    • If you want to be extra safe, go directly to the site by typing it manually (not via the email) and check whether an account exists or request password reset only if needed.

    Indicators from this sample (sanitized)

    • Legit sender: fas@fedoraproject.org

    • Legit infra in headers: bastion02.fedoraproject.org / internal worker

    • Payload link domain in HTML: graph.org

    • Activation URL domain: accounts.fedoraproject.org (token redacted)


    If you’re running an identity system: please assume attackers will use your reputation to deliver their scams. Email authentication tells you the message is really from the domain – it does not tell you the message is safe.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • INTERNET WEATHER REPORT 🌧☁️☀️

     

    AS215476 (Inside Network LTD) has just been added to ASN watchlist. This autonomous system announces only one BGP prefixes:

    • 77.90.185.0/24

     

    High concentration of phishing websites targeting government and banking entities – and a metric shit-ton of unsolicited port scanning detected.

     

    Drop It Like It’s Hot. 🔥

     

    Latest updates to the ASN watchlist posted here: https://internetweather.net/asn-watchlist/

     

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • INTERNET WEATHER REPORT 🌧☁️☀️

     

    AS211736 (FOP Dmytro Nedilskyi) has just been added to ASN watchlist. This autonomous system announces three BGP prefixes:

    • 88.210.63.0/24
    • 92.63.197.0/24
    • 185.156.73.0/24

     

    High concentration of brute-force attack (large scale) and some phishing sites – plus a few bonus illegal marketplace sites. Check out this corroborating report as well:  https://thehackernews.com/2025/09/ukrainian-network-fdn3-launches-massive.html

     

    Drop It Like It’s Hot. 🔥

     

    Latest updates to the ASN watchlist posted here: https://internetweather.net/asn-watchlist/

     

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • So I was researching a rarely seen threat vector of ESP (IP protocol 50) packets and stumbled upon VMISS Inc. (AS967) – a boy what a surprise this was!

     

    A quick look a their announced IP space (BGP prefixes) was a big red flag by itself, then I discovered their “our team” page: https://www.vmiss.com/our-team/

     

    None of the people shown on the page exist, and the images themselves are stolen.

    This “Max Gray” guy is an image stolen (or reused) from other sources, as revealed by a reverse image search:

     

    Anyway, definitely stay away from this one. My best guess is this is a Chinese organization, operating in Canada, and it’s fraudulent to the core.

     

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • INTERNET WEATHER REPORT 🌧☁️☀️

     

    AS215925 (VPSVAULT.HOST LTD) has just been added to ASN watchlist. This autonomous system announces two BGP prefixes:

    • 108.165.153.0/24
    • 87.121.84.0/24

     

    High concentration of malware hosting (infostealer, DDoS, etc.) and other illegal content.

     

    Drop It Like It’s Hot. 🔥

     

    Latest updates to the ASN watchlist posted here: https://internetweather.net/asn-watchlist/

     

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • INTERNET WEATHER REPORT 🌧☁️☀️

     

    AS42624 (Global-Data System IT Corporation) has just been added to ASN watchlist. This autonomous system announces nine BGP prefixes:

    • 185.196.8.0/24
    • 185.196.9.0/24
    • 185.196.10.0/24
    • 185.196.11.0/24
    • 185.208.156.0/24
    • 185.208.157.0/24
    • 185.208.158.0/24
    • 185.208.159.0/24

     

    Nothing but phishing sites, various malware hosting (infostealer, DDoS, etc.) and other illegal content. Global-Data System IT Corporation (nice-sounding generic bullshit name) was previously registered in the Seychelles as AS34888 – but has not been seen in the global routing table using that ASN since February 1, 2022.

     

    Drop It Like It’s Hot. 🔥

     

    Latest updates to the ASN watchlist posted here: https://internetweather.net/asn-watchlist/

     

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • INTERNET WEATHER REPORT 🌧☁️☀️

     

    AS214295 (SKYNET NETWORK LTD) has just been added to ASN watchlist. This autonomous system announces only three BGP prefixes:

    • 45.142.193.0/24
    • 87.120.93.0/24
    • 194.0.234.0/24

     

    Abuse reports sent to murraycharles988@gmail.com go unanswered. AbuseIPDB has logged nearly 250,000 abuse reports for the first netblock alone.

     

    Drop It Like It’s Hot.

     

    Latest updates to the ASN watchlist posted here: https://internetweather.net/asn-watchlist/

     

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶