From: Peter Müller Date: Wed, 25 May 2022 11:36:31 +0000 (+0000) Subject: override-{other,xd}: Regular batch of various overrides X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=d2612b28e0775eafc6af75080ba341780fc522ad;p=location%2Flocation-database.git override-{other,xd}: Regular batch of various overrides Signed-off-by: Peter Müller --- diff --git a/overrides/override-other.txt b/overrides/override-other.txt index a6a0282..c89fcda 100644 --- a/overrides/override-other.txt +++ b/overrides/override-other.txt @@ -1298,6 +1298,11 @@ descr: Hong Kong Communications International Co., Limited remarks: part of the "Asline" IP hijacking gang, tampers with RIR data, traces back to AP region country: AP +aut-num: AS140641 +descr: YOTTA NETWORK SERVICES PRIVATE LIMITED +remarks: ISP located in IN, some RIR data for announced prefixes contain garbage +country: IN + aut-num: AS140733 descr: Wujidun Network Limited remarks: part of the "Asline" IP hijacking gang, tampers with RIR data, traces back to AP region @@ -1328,6 +1333,11 @@ descr: YISU CLOUD LTD remarks: ... located in HK country: HK +aut-num: AS142578 +descr: E-Large (HongKong) +remarks: traceroutes dead-end in US, and measurements could not proof that this AS is being located elsewhere +country: US + aut-num: AS196682 descr: FLP Kochenov Aleksej Vladislavovich remarks: ISP located in UA, but RIR data for announced prefixes all say EU @@ -1553,6 +1563,11 @@ descr: Nese Mala / Moon DC remarks: shady ISP located in TR, but many RIR data for announced prefixes contain garbage country: TR +aut-num: AS208911 +descr: Alsycon BV +remarks: Shady ISP located in NL, but some RIR data for announced prefixes contain garbage +country: NL + aut-num: AS209132 descr: Alviva Holding Limited remarks: ISP located in BG, but RIR data for announced prefixes contain garbage @@ -1958,6 +1973,11 @@ descr: OVH Australia PTY LTD remarks: Accurate country code missing due to ARIN DB situation country: AU +net: 77.81.142.0/24 +descr: M247 Ltd. +remarks: Both /25 have MX allocated, but supernet seems to lack precise country information +country: MX + net: 85.202.80.0/24 descr: Amarutu Technology Ltd. / KoDDoS / ESecurity remarks: fake offshore location (BZ), traces back to US @@ -1968,11 +1988,6 @@ descr: netcup GmbH remarks: https://lists.ipfire.org/pipermail/location/2022-January/000519.html country: AT -net: 91.90.120.0/24 -descr: M247 LTD, Greenland Infrastructure -remarks: ... traces back to CA -country: CA - net: 91.149.194.0/24 descr: IP Volume Ltd. / Epik remarks: fake location (CH), traces back to SE diff --git a/overrides/override-xd.txt b/overrides/override-xd.txt index 0c600dd..d103e4b 100644 --- a/overrides/override-xd.txt +++ b/overrides/override-xd.txt @@ -79,6 +79,12 @@ remarks: bulletproof ISP (related to AS202425 and AS57717) located in NL country: NL drop: yes +aut-num: AS47154 +descr: HUSAM A. H. HIJAZI +remarks: Rogue ISP located in NL +country: NL +drop: yes + aut-num: AS48090 descr: PPTECHNOLOGY LIMITED remarks: bulletproof ISP (related to AS204655) located in NL @@ -173,6 +179,12 @@ remarks: Autonomous System registered to offshore company, abuse contact is a fr country: AP drop: yes +aut-num: AS59753 +descr: Vault Dweller OU +remarks: bulletproof ISP (related to AS57717) located in NL +country: NL +drop: yes + aut-num: AS60424 descr: 1337TEAM LIMITED / eliteteam[.]to remarks: Owned by an offshore letterbox company, suspected rogue ISP @@ -272,6 +284,12 @@ remarks: IP hijacker located somewhere in AP area (JP?) country: AP drop: yes +aut-num: AS141759 +descr: HONGKONG XING TONG HUI TECHNOLOGY CO.,LIMITED +remarks: Dirty ISP located in NL +country: NL +drop: yes + aut-num: AS196691 descr: Get-Net LLC remarks: IP hijacker in RU and dirty suballocations, not a safe place to go @@ -344,6 +362,12 @@ remarks: bulletproof ISP operating from a war zone in eastern UA country: UA drop: yes +aut-num: AS209559 +descr: Truenetwork IDC (?) +remarks: Rogue ISP (linked to AS202425) located in NL +country: NL +drop: yes + aut-num: AS209654 descr: Delis LLC remarks: Shary Serverion customer and IP hijacker in NL, many RIR data for announced prefixes contain garbage @@ -386,6 +410,12 @@ remarks: bulletproof ISP located in RU country: RU drop: yes +aut-num: AS213194 +descr: Alfa Web Solutions Ltd +remarks: Rogue ISP (linked to AS57717) located in NL +country: NL +drop: yes + aut-num: AS267712 descr: EL ALAMO S.R.L remarks: Hijacked AS being announced out of RU