Description
Describe the bug
This ticket is informational, there probably is no solution to fixing it.
2 months ago, my site site was white listed/removed from this DB. About 2 weeks, maybe a month later after removal. The botnet that was doing 10K-75K/day, max 250K/req per day to my site, vanished. Currently, as intended, some days I have 0 requests (weekends), and peaks at 5 requests a day that are not my IPs/ASNs, (Tor IPs), after being removed from this list.
This public phishing list, itself, is used by bad actors. If I wanted to DDOS a site, esp a pay per minute/hour/gig hosted site, just maliciously add a URL to this list, and watch the botnet traffic from 100s/1000s of VPNs, proxies, and cloud VPSes attack the site trying to find the .csv or .zip with collected phished logins or php/wordpress/shell injection attacks roll in. The bots DO NOT know what cookies are, and can't store cookies between requests, and the bots never learn, there is no content for them, no matter how much error 404 pages you return to them.
If someone could game this public list, and maliciously add an arbitrary false positive domain, and victim's domain's hosting, is pay per minute/hour/gig, it would quickly be knocked off or a huge cloud bill delivered at the end of the month.
After collecting a month of the the DDOS source IPs, and removing legitimate regional to me, ASNs, local LTE mobile and residential fixed ISPs, I came up with this list of ASNs. Except for Orange SA, all were non-residential. M247 hosting also popped into the list but from the wrong country on a tracepath, but I didn't include it here, since its the hosting provider of the VPN I personally use.
Hope this list helps someone.
559
1101
2514
3209
3215
3216
3352
4224
7489
7979
8075
8304
8359
8402
9605
11595
12093
12355
12389
12695
12816
12876
13043
13213
13238
13737
13768
13926
14061
14259
14315
14618
15085
15169
16276
16509
17506
18345
18403
18747
19237
20473
20860
21263
21887
22773
24940
26388
26548
27176
28855
29319
29405
29713
29802
30277
30860
32097
32475
32613
32780
32934
33083
33302
35526
35908
36236
36351
36352
36459
36873
36937
37100
37611
38364
39351
40021
42708
43289
43350
45671
45899
46562
46664
47583
49447
49825
50058
50304
51167
51395
53667
54203
54455
54538
55103
55286
55836
59425
60068
60404
60721
60729
60754
62651
62838
62904
63949
135377
135905
197422
197540
200651
202425
203833
205100
206092
206804
208169
208323
209366
209604
210630
211298
212238
394625
395111
396507
396982
397373
397423
398324
398355
398722
Metadata
Metadata
Assignees
Labels
Type
Projects
Status