From: Peter Müller Date: Tue, 7 May 2024 10:36:45 +0000 (+0000) Subject: override-{other,xd}: Regular batch of various overrides X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=bc21506673c6a6b5b25a333ae6a228177c070adc;p=location%2Flocation-database.git override-{other,xd}: Regular batch of various overrides Signed-off-by: Peter Müller --- diff --git a/overrides/override-other.txt b/overrides/override-other.txt index a62c046..f5f7343 100644 --- a/overrides/override-other.txt +++ b/overrides/override-other.txt @@ -978,6 +978,11 @@ descr: Dreamtorrent Corp remarks: traceroutes dead-end somewhere in or near RU country: RU +aut-num: AS47154 +descr: HUSAM A. H. HIJAZI +remarks: ISP located in NL +country: NL + aut-num: AS47482 descr: Spectre Operations BV remarks: ISP located in NL, but some RIR data for suballocations of announced prefixes contain garbage @@ -1156,7 +1161,7 @@ country: FI aut-num: AS51852 descr: Private Layer INC remarks: Physically located in CH -countr: CH +country: CH aut-num: AS51999 descr: WhiteHat Inc. @@ -1427,6 +1432,11 @@ descr: LeaseWeb Netherlands B.V. remarks: ISP located in Amsterdam, NL, but many RIR data for announced prefixes contain garbage country: NL +aut-num: AS61125 +descr: SABOTAGE LLC +remarks: traces back to NL +country: NL + aut-num: AS61218 descr: 4b42 UG (haftungsbeschränkt) remarks: ... who thinks messing with countries is funny :-/ @@ -2402,6 +2412,11 @@ descr: IP Connect Inc. remarks: fake offshore location (SC), traces back to NL country: NL +aut-num: AS215127 +descr: 410 Teapot Limited +remarks: Traces back to NL +country: NL + aut-num: AS262287 descr: Maxihost LTDA remarks: Many if not all prefixes announced by this AS trace back to BR, yet their RIR data contain mostly garbage. Also, Maxihost LTDA does not seem to be able to prevent cyber criminals from abusing it's services - tomorrows bulletproof ISP? diff --git a/overrides/override-xd.txt b/overrides/override-xd.txt index bae1ac7..9aafd82 100644 --- a/overrides/override-xd.txt +++ b/overrides/override-xd.txt @@ -55,23 +55,11 @@ remarks: all cybercrime hosting, all the time country: RU drop: yes -aut-num: AS44446 -descr: OOO SibirInvest -remarks: bulletproof ISP (related to AS202425 and AS57717) located in NL -country: NL -drop: yes - aut-num: AS44477 descr: STARK INDUSTRIES SOLUTIONS LTD remarks: Rogue ISP in multiple locations, some RIR data contain garbage drop: yes -aut-num: AS47154 -descr: HUSAM A. H. HIJAZI -remarks: Rogue ISP located in NL -country: NL -drop: yes - aut-num: AS48090 descr: PPTECHNOLOGY LIMITED remarks: bulletproof ISP (related to AS204655) located in NL @@ -84,11 +72,6 @@ remarks: Part of the "Fiber Grid" IP hijacking / dirty hosting operation, RIR da country: EU drop: yes -aut-num: AS49447 -descr: Nice IT Services Group Inc. -remarks: Rogue ISP -drop: yes - aut-num: AS49870 descr: Alsycon BV remarks: Shady ISP (related to AS204655 et al., same postal address) located in NL, but some RIR data for announced prefixes contain garbage @@ -101,24 +84,12 @@ remarks: part of the "Asline" IP hijacking gang, traces back to San Jose, CR country: CR drop: yes -aut-num: AS49943 -descr: IT Resheniya LLC -remarks: Rogue ISP -country: RU -drop: yes - aut-num: AS51381 descr: 1337TEAM LIMITED / eliteteam[.]to remarks: Bulletproof ISP country: RU drop: yes -aut-num: AS53727 -descr: Netsys Global Telecom Limited (?) -remarks: Hijacked AS announced out of some location in AP, possibly HK -country: AP -drop: yes - aut-num: AS54600 descr: PEG TECH INC remarks: ISP and IP hijacker located in US this time, tampers with RIR data @@ -138,7 +109,7 @@ country: AP drop: yes aut-num: AS55933 -descr: Cloudie Limited +descr: Cloudie Limited / Worria remarks: part of the "Asline" IP hijacking gang, tampers with RIR data, traces back to HK country: HK drop: yes