From: Peter Müller Date: Tue, 14 Jun 2022 15:51:13 +0000 (+0000) Subject: override-{other,xd}: Regular batch of various overrides X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=aa84b59830c4e44209a12d7604b42211d31bac24;p=location%2Flocation-database.git override-{other,xd}: Regular batch of various overrides Signed-off-by: Peter Müller --- diff --git a/overrides/override-other.txt b/overrides/override-other.txt index 877710b..50621a8 100644 --- a/overrides/override-other.txt +++ b/overrides/override-other.txt @@ -139,6 +139,11 @@ descr: Leaseweb USA, Inc. remarks: ISP located in US, but some RIR data for announced prefixes contain garbage country: US +aut-num: AS8283 +descr: Netwerkvereniging Coloclue +remarks: ISP located in NL, but some RIR data for announced prefixes contain garbage +country: NL + aut-num: AS8359 descr: MTS PJSC remarks: ISP located in RU, but some RIR data for announced prefixes contain garbage @@ -258,6 +263,11 @@ descr: ITL LLC remarks: ISP headquatered in BG and/or UA, physically located in NL, some RIR data for announced prefixes contain inaccurate data country: NL +aut-num: AS21700 +descr: Neptune Networks, LLC +remarks: ISP located in US, but RIR data for announced prefixes contain garbage +country: US + aut-num: AS23470 descr: ReliableSite.Net LLC remarks: ISP located in US, but RIR data for announced prefixes contain garbage @@ -883,6 +893,11 @@ descr: vServer.site LTD remarks: ISP located in DE, but some RIR data for announced prefixes contain garbage country: DE +aut-num: AS56690 +descr: VNET LLC +remarks: ISP located in RU, but some RIR data for announced prefixes contain garbage +country: RU + aut-num: AS56703 descr: MEHR AVA GOSTAR PARSIAN INFORMATION ENGINEERING CO.,LTD remarks: ISP located in IR, but some RIR data for announced prefixes contain garbage @@ -1308,11 +1323,6 @@ descr: White-Sand Cloud Computing(HK) Co., LIMITED remarks: part of the "Asline" IP hijacking gang, tampers with RIR data, traces back to AP region country: AP -aut-num: AS140227 -descr: Hong Kong Communications International Co., Limited -remarks: part of the "Asline" IP hijacking gang, tampers with RIR data, traces back to AP region -country: AP - aut-num: AS140641 descr: YOTTA NETWORK SERVICES PRIVATE LIMITED remarks: ISP located in IN, some RIR data for announced prefixes contain garbage @@ -1588,11 +1598,6 @@ descr: Alviva Holding Limited remarks: ISP located in BG, but RIR data for announced prefixes contain garbage country: BG -aut-num: AS209160 -descr: Miti 2000 EOOD -remarks: another shady customer of "Tamatiya EOOD / 4Vendeta", located in BG, tampers with RIR data -country: BG - aut-num: AS209366 descr: SEMrush CY LTD remarks: claims CY for announced prefixes, but they are all hosted in NL @@ -1878,6 +1883,11 @@ descr: Serverion LLC remarks: ISP located in NL, some RIR data contain garbage country: NL +net: 15.235.128.0/17 +descr: OVH Singapore PTE. LTD +remarks: Accurate country code missing due to ARIN DB situation +country: SG + net: 31.220.0.0/22 descr: Amarutu Technology Ltd. / KoDDoS / ESecurity remarks: fake offshore location (BZ), traces back to NL @@ -2143,6 +2153,11 @@ descr: xTom Limited remarks: fake offshore locations (AQ / PN / SS), traces back to US country: US +net: 172.107.241.0/24 +descr: Psychz Networks +remarks: Country code missing due to ARIN DB situation +country: ES + net: 178.239.20.0/24 descr: Anthony Marshall / Game Hosting Net / FlokiNET Ltd. remarks: fake location (BA), traces back to RO @@ -2303,6 +2318,11 @@ descr: NewMedia Express on behalf of Datacamp remarks: traces back to JP country: JP +net: 216.73.159.0/24 +descr: Zappie Host LLC +remarks: Accurate country code missing due to ARIN DB situation +country: CL + net: 2404:f4c0:fd04::/48 descr: LSHIY Group remarks: Quirk in RIR data, GR != DE diff --git a/overrides/override-xd.txt b/overrides/override-xd.txt index d103e4b..85b506b 100644 --- a/overrides/override-xd.txt +++ b/overrides/override-xd.txt @@ -206,6 +206,11 @@ descr: EDGENAP LTD remarks: IP hijacking? Rogue ISP? drop: yes +aut-num: AS61432 +descr: TOV VAIZ PARTNER +remarks: Rogue ISP +drop: yes + aut-num: AS62068 descr: SpectraIP B.V. remarks: bulletproof ISP (linked to AS202425 et al.) located in NL @@ -272,6 +277,12 @@ remarks: part of the "Asline" IP hijacking gang, tampers with RIR data country: AP drop: yes +aut-num: AS140227 +descr: Hong Kong Communications International Co., Limited +remarks: part of the "Asline" IP hijacking gang, tampers with RIR data, traces back to AP region +country: AP +drop: yes + aut-num: AS141159 descr: Incomparable(HK)Network Co., Limited remarks: ISP and IP hijacker located in HK, tampers with RIR data @@ -296,6 +307,11 @@ remarks: IP hijacker in RU and dirty suballocations, not a safe place to go country: RU drop: yes +aut-num: AS200313 +descr: WEB_GroupInternet INC +remarks: All bulletproof/cybercrime hosting, all the time, not a safe AS to connect to +drop: yes + aut-num: AS200391 descr: KREZ 999 EOOD remarks: another shady customer of "Tamatiya EOOD / 4Vendeta", located in BG, tampers with RIR data @@ -356,6 +372,12 @@ remarks: bulletproof ISP, see: https://krebsonsecurity.com/2019/07/meet-the-worl country: RU drop: yes +aut-num: AS209160 +descr: Miti 2000 EOOD +remarks: another shady customer of "Tamatiya EOOD / 4Vendeta", located in BG, tampers with RIR data +country: BG +drop: yes + aut-num: AS209272 descr: Alviva Holding Limited remarks: bulletproof ISP operating from a war zone in eastern UA @@ -363,7 +385,7 @@ country: UA drop: yes aut-num: AS209559 -descr: Truenetwork IDC (?) +descr: XHOST INTERNET SOLUTIONS LP remarks: Rogue ISP (linked to AS202425) located in NL country: NL drop: yes @@ -376,8 +398,8 @@ drop: yes aut-num: AS210848 descr: Telkom Internet LTD -remarks: Rogue ISP (linked to AS202425) located in NL -country: NL +remarks: Rogue ISP (linked to AS202425) located in NL and RO +country: EU drop: yes aut-num: AS211193 @@ -416,12 +438,6 @@ remarks: Rogue ISP (linked to AS57717) located in NL country: NL drop: yes -aut-num: AS267712 -descr: EL ALAMO S.R.L -remarks: Hijacked AS being announced out of RU -country: RU -drop: yes - aut-num: AS328543 descr: Sun Network Company Limited remarks: IP hijacker, traces back to AP region @@ -463,6 +479,11 @@ remarks: Shady ISP located in US, solely announcing "Cloud Innovation Ltd." spac country: US drop: yes +net: 185.196.220.0/24 +descr: Makut Investments +remarks: Long-running brute-force attack network +drop: yes + net: 195.133.20.0/24 descr: Tribeka Web Advisors S.A. remarks: Tampers with RIR data, traces back to NL, not a safe place to route traffic to