maynard
(Maynard)
September 9, 2026, 1:12am
1
or, Why is it attempting to connect, by massive swarm, to my server which doesn’t use their services?
You don’t have to read or respond of course, but here it is.
I suppose I could always ask ‘them’.
I do have some related perspective/data which I’ll append as a reply.
Here is a continuous log fragment of time[hh:mm] and quantity(uniq IPs) of incoming new tcp connections which hit my rate limiting:
23:06 (1)
23:07
23:13 (2)
23:14
23:15 (2)
23:16 (18)
23:17 (27)
23:18 (68)
23:19 (102)
23:20 (108)
23:21 (119)
23:22 (102)
23:23 (97)
23:24 (42)
23:25 (17)
23:26 (1)
23:27
23:30 (1)
and my processing …
└─# tail -30 drop.log |awk ‘$2 ~ /23:/ && $5 ~ /[0-9 .]+/’ |tr " " “\n” |sed -nE ‘/{8,}/p’ |sort -Vu |cut -d’.’ -f1-3 |sed -E ‘s/$/.0/24/g’ |aggregate |while read p; do asn $p; done |tee /tmp/swarm-asns
to reveal the source sof this swarm:
└─# awk '{print $3,$13}' </tmp/swarm-asns |sort |uniq -c |sort -n
1 16509 AMAZON-02
1 197540 netcup-AS
1 269843 AS269843
1 37693 OOREDOO
1 395747 CLOUDFLARENET-SFO05
146 14789 CLOUDFLARENET
378 13335 CLOUDFLARENET
count ASN owner
Triggering the rate limit puts the IP into a set which drops further connections for the next two minutes. … which could explain why every logged IP was unique
How did those blocks aggregate?
1 21
24 22
96 23
408 24
count \prefix
How many Class-B’s were involved?
└─# cut -d'.' -f1-2 </tmp/swarm-asns |sort |uniq -c |awk '$1 > 31'
52 104.22
36 104.23
77 162.158
91 172.68
100 172.69
57 172.70
70 172.71
maynard
(Maynard)
September 9, 2026, 2:02am
2
Relatedly, … if an IP hits the ratelimit, it gets inserted into set which drops future new connections for 2 minutes; if while in that set, it attempts further new connections at a slightly lower rate limit, I add the IP’s entire prefix (reported by cymru/pwhois) to a semi-permanent blocklist, from which we currently glean …
└─# cut -d’ ’ -f1 <dump.list |sort -u |aggregate |wc -l
304 total prefixes in the list
└─# cut -d’ ’ -f1 <dump.list |sort -u |aggregate |awk -F"/" ‘$2 <= 20’ |wc -l
229 larger than a /21
└─# cut -d’ ’ -f1 <dump.list |sort -u |aggregate |awk -F"/" ‘$2 <= 16’ |wc -l
53 larger than a /17
… of which from the latter …
30 396982 GOOGLE-CLOUD-PLATFORM
13 16509 AMAZON-02
# ASN
By far the most connect abusive operator I see is from IPs whose PTR is within
bc.googleusercontent.com
Just beneath that, and below my current trigger for semi-permanent blocklist, is
from the .compute*.amazonaws.com space
maynard
(Maynard)
September 9, 2026, 2:05am
3
maynard
(Maynard)
September 9, 2026, 3:04am
4
Here’s a 24hr. snapshot of related firewall activity (packet counting)
[wide screen formatted]
60:minutes 76:http-new 0:hrated-dropped 0:http-rated 35:dumplist 2:ossec-blocked 0:orated-dropped 0:ossec-rated
60:minutes 45:http-new 0:hrated-dropped 0:http-rated 18:dumplist 7:ossec-blocked 10:orated-dropped 1:ossec-rated
60:minutes 60:http-new 0:hrated-dropped 0:http-rated 131:dumplist 13:ossec-blocked 2129:orated-dropped 3:ossec-rated
60:minutes 53:http-new 0:hrated-dropped 0:http-rated 264:dumplist 5:ossec-blocked 8:orated-dropped 1:ossec-rated
60:minutes 73:http-new 0:hrated-dropped 0:http-rated 144:dumplist 13:ossec-blocked 72:orated-dropped 3:ossec-rated
60:minutes 79:http-new 0:hrated-dropped 0:http-rated 21:dumplist 5:ossec-blocked 11:orated-dropped 1:ossec-rated
59:minutes 72:http-new 0:hrated-dropped 0:http-rated 80:dumplist 5:ossec-blocked 64:orated-dropped 1:ossec-rated
60:minutes 65:http-new 26:hrated-dropped 2:http-rated 76:dumplist 5:ossec-blocked 5:orated-dropped 1:ossec-rated
60:minutes 79:http-new 19:hrated-dropped 1:http-rated 22:dumplist 5:ossec-blocked 29:orated-dropped 2:ossec-rated
60:minutes 324:http-new 2077:hrated-dropped 55:http-rated 1952:dumplist 12:ossec-blocked 274:orated-dropped 6:ossec-rated
60:minutes 65:http-new 0:hrated-dropped 0:http-rated 124:dumplist 10:ossec-blocked 83:orated-dropped 2:ossec-rated
60:minutes 70:http-new 0:hrated-dropped 0:http-rated 39:dumplist 0:ossec-blocked 0:orated-dropped 0:ossec-rated
60:minutes 78:http-new 0:hrated-dropped 0:http-rated 128:dumplist 4:ossec-blocked 0:orated-dropped 0:ossec-rated
60:minutes 88:http-new 52:hrated-dropped 11:http-rated 39:dumplist 11:ossec-blocked 2139:orated-dropped 2:ossec-rated
60:minutes 140:http-new 157:hrated-dropped 8:http-rated 29:dumplist 16:ossec-blocked 328:orated-dropped 12:ossec-rated
60:minutes 80:http-new 71:hrated-dropped 1:http-rated 165:dumplist 4:ossec-blocked 6:orated-dropped 0:ossec-rated
60:minutes 35:http-new 0:hrated-dropped 0:http-rated 118:dumplist 5:ossec-blocked 54:orated-dropped 1:ossec-rated
60:minutes 71:http-new 18:hrated-dropped 1:http-rated 140:dumplist 10:ossec-blocked 43:orated-dropped 2:ossec-rated
60:minutes 60:http-new 24:hrated-dropped 1:http-rated 91:dumplist 0:ossec-blocked 0:orated-dropped 0:ossec-rated
60:minutes 53:http-new 0:hrated-dropped 0:http-rated 76:dumplist 1:ossec-blocked 0:orated-dropped 0:ossec-rated
60:minutes 204:http-new 2907:hrated-dropped 10:http-rated 135:dumplist 0:ossec-blocked 0:orated-dropped 0:ossec-rated
60:minutes 1786:http-new 5669:hrated-dropped 710:http-rated 53:dumplist 1:ossec-blocked 0:orated-dropped 0:ossec-rated
60:minutes 78:http-new 0:hrated-dropped 0:http-rated 90:dumplist 15:ossec-blocked 126:orated-dropped 3:ossec-rated
60:minutes 38:http-new 0:hrated-dropped 0:http-rated 69:dumplist 7:ossec-blocked 231:orated-dropped 1:ossec-rated
43:minutes 55:http-new 0:hrated-dropped 0:http-rated 29:dumplist 14:ossec-blocked 279:orated-dropped 2:ossec-rated
the http/hrated counters are for port 443; the orated/ossec counters are for the Ossec HIDS response system, which utilizes an escalating timeout for its dropset. Extreme values get my attention however.
None of these, or the amazonaws or cloudflare traffic, are likely to be pernicious; but it is surely, and apparently poorly, automated; in service of suspicious ends.
The Net is becoming as unusable as the planet unlivable; both victims of misguided capital.
Meanwhile, …