Wikipedia:WikiProject on open proxies/Requests/Archives/42

NordVPN
closed



New unblocked NordVPN addresses. Some possible UPE activity there too. MarioGom (talk) 21:34, 10 May 2021 (UTC)
 * Blocked. GeneralNotability (talk) 23:08, 20 May 2021 (UTC)

Majestic Hosting Ranges
close

Webhost range with edits coming out of it. Can't find much about the ISP (not sure if hosting only or also colo), everything else in the ASN has been globally hardblocked by until 2025, so hardblocks seem warranted. – please hardblock the range for two years. Thanks. --Blablubbs&#124;talk 08:48, 21 May 2021 (UTC)
 * ✅ --Malcolmxl5 (talk) 11:54, 24 May 2021 (UTC)
 * Thanks. Closing. --Blablubbs&#124;talk 13:09, 24 May 2021 (UTC)

192.42.116.0/27
close

Per whois, the range is a Tor exit node (TOR-EXIT-HVIV network name). Most IPs are individually blocked, 192.42.116.18 is not. Verified tor exit on Shodan. MarioGom (talk) 15:14, 22 May 2021 (UTC)
 * ✅, obviously. Hosted by this group. The ASN is an education network, so not good to block. : Please block the /27 above for two years, hard. --Blablubbs&#124;talk 10:10, 23 May 2021 (UTC)
 * ✅ --Malcolmxl5 (talk) 14:53, 24 May 2021 (UTC)
 * Thanks, closing. --Blablubbs&#124;talk 15:36, 24 May 2021 (UTC)

67.53.214.86
close

Reason: (This user violates wikipedia rules by using proxy. The IP address is already blocked in several bases for using proxy. For example here https://www.rbls.org/) 77.37.160.57 (talk) 12:58, 24 May 2021 (UTC)
 * IP is ❌. Closing. --Blablubbs&#124;talk 15:27, 24 May 2021 (UTC)

TunnelBear (III)
close
 * au.lazerpenguin.com
 * au.lazerpenguin.com
 * au.lazerpenguin.com
 * au.lazerpenguin.com
 * au.lazerpenguin.com
 * au.lazerpenguin.com
 * au.lazerpenguin.com

The /24 is M247-LTD-Sydney, so probably good to hardblock:

--MarioGom (talk) 20:36, 24 May 2021 (UTC)
 * Yep. – please hardblock the /24 for two years. Thanks. --Blablubbs&#124;talk 21:09, 24 May 2021 (UTC)
 * ✅ --Malcolmxl5 (talk) 21:29, 24 May 2021 (UTC)
 * Thanks! Closing. --Blablubbs&#124;talk 21:42, 24 May 2021 (UTC)

2a07:23c0:9:1::9:312
closed

Reason: Owned by Hosting Services Inc. who provides web hosting services apparently running servers, public proxies and anonymizing VPNs. Malcolmxl5 (talk) 11:43, 24 May 2021 (UTC)
 * ✅ webhost plus on the same ASN (the subrange 209.126.88.0/24 is already globally hardblocked, as is the rest of the ASN). These providers technically also offer colocation and I don't see any clear VPN fingerprints, but everything else on the range is hardblocked, so I'd recommend matching that.  – please block the /48 and the /22, hard, two years. No strong objections to a soft block if preferred by the closing admin. Thanks. --Blablubbs&#124;talk 15:35, 24 May 2021 (UTC)
 * ✅ --Malcolmxl5 (talk) 16:26, 25 May 2021 (UTC)

HideMyAss (II)
closed
 * ma.us.hma.rocks

--MarioGom (talk) 20:51, 24 May 2021 (UTC)
 * ✅. This is part of that huge Cogent /8, I don't see a possible rangeblock here. – please hardblock the single IP for a year. I usually recommend two-year blocks, but given the range, I think going for a shorter one and revisiting when it expires makes more sense. Thanks. --Blablubbs&#124;talk 21:40, 24 May 2021 (UTC)
 * ✅ --Malcolmxl5 (talk) 16:17, 25 May 2021 (UTC)

119.8.115.183
close

Reason: Appears to be a sock behind a VPS/VPN. No edit history until today; edit summary shows extensive knowledge of WP. Normchou  💬 18:31, 12 May 2021 (UTC)


 * The IP is a web server hosted at Huawei Cloud. Possibly a VPN node. And on top of that Spur flags it as a residential proxy. 119.8.96.0/19 should be good to block. Someone may want to block all other ranges from . MarioGom (talk) 19:23, 12 May 2021 (UTC)
 * While Huawei Cloud doesn't appear to offer colocation, this specific IP doesn't really look like a conventional anonymiser to me. Given the region, I think it's likely that Huawei ranges are going to have a good number of corporate gateways on them, used by Chinese companies who need access to a less filtered internet for business purposes; I'm not comfortable hardblocking the lot. However, softblocks seem warranted. The ranges are a little unwieldy here, but I think the below should cover everything. – please block the following, soft, two years each:
 * Thanks. --Blablubbs&#124;talk 09:57, 13 May 2021 (UTC)
 * ✅ Softblocks only. --Malcolmxl5 (talk) 15:59, 26 May 2021 (UTC)
 * Thanks! Closing. --Blablubbs&#124;talk 16:52, 26 May 2021 (UTC)
 * Thanks. --Blablubbs&#124;talk 09:57, 13 May 2021 (UTC)
 * ✅ Softblocks only. --Malcolmxl5 (talk) 15:59, 26 May 2021 (UTC)
 * Thanks! Closing. --Blablubbs&#124;talk 16:52, 26 May 2021 (UTC)
 * ✅ Softblocks only. --Malcolmxl5 (talk) 15:59, 26 May 2021 (UTC)
 * Thanks! Closing. --Blablubbs&#124;talk 16:52, 26 May 2021 (UTC)

AirVPN
close
 * (whois: KUSTBANDET-AIRVPN-NETWORK)
 * (hostname: airvpn.dserver.softronics.ch)

The invidial IP is probably only an entry IP and not exit IP, but it can't hurt to block it. --MarioGom (talk) 21:24, 24 May 2021 (UTC)
 * ✅. – please hardblock  and  (softronics per WHOIS) for two years each. The ASN for the former also deserves a look, but I don't have the time right now. Thanks. --Blablubbs&#124;talk 09:09, 26 May 2021 (UTC)
 * ✅ --Malcolmxl5 (talk) 16:05, 26 May 2021 (UTC)
 * Thanks! Closing. --Blablubbs&#124;talk 16:52, 26 May 2021 (UTC)

IVPN
close
 * it.gw.ivpn.net

Per DNS and Spur. Responds to IKE handshake. MarioGom (talk) 20:41, 24 May 2021 (UTC)
 * . Big ASN, checking for blockable ranges. --Blablubbs&#124;talk 09:17, 25 May 2021 (UTC)
 * There's a lot here. : Please block the following, hard, two years each:
 * (Secured Servers LLC)
 * (Bigbox Infosoft LLC)
 * (Fastserv)
 * (Bigbox)
 * (Bigbox)
 * (Fastserv)
 * (SeFlow.it Dedicated Servers - wf2 - Milan)
 * (CloudFlow Virtual Datacenter
 * (Seflow dedicated servers)
 * (Seflow VPS)
 * (Breezle)
 * (Oneprovider
 * (zoneidc, google translate at )
 * (Breezle)
 * (Breezle)
 * (Seflow)
 * (Ranxplorer)
 * (Ranxplorer)
 * (Ranxplorer)
 * There are a number of other ranges named with the pattern italy_network – they all belong to Seflow (the entire ASN does), but I'm not sure what they're doing. Someone braver than me may want to just block those as well, but I'll leave that up to you. Thanks. --Blablubbs&#124;talk 09:34, 25 May 2021 (UTC)
 * ✅ --Malcolmxl5 (talk) 11:56, 29 May 2021 (UTC)
 * Many thanks, closing. --Blablubbs&#124;talk 11:58, 29 May 2021 (UTC)

Celo VPN
closed

jp1.celo.net SSL cert on port 999. MarioGom (talk) 21:34, 24 May 2021 (UTC)
 * ✅. This is Enzu, a webhost that also does colocation, but seems to host proxies fairly frequently., please hardblock for two years. Thanks. --Blablubbs&#124;talk 08:18, 31 May 2021 (UTC)
 * ✅ --Malcolmxl5 (talk) 12:16, 31 May 2021 (UTC)

96.9.192.0/18
close

Nexeon range with a very high amount of VPN servers (NordVPN, WorldVPN).


 * Previous blocks: 96.9.243.171, 96.9.245.99, 96.9.245.107, 96.9.246.123, 96.9.246.124, 96.9.246.163, 96.9.246.179, 96.9.246.180, 96.9.247.11, 96.9.247.43, 96.9.247.51, 96.9.247.59, 96.9.247.171, 96.9.247.187, 96.9.247.188, 96.9.247.200/29, 96.9.247.243, 96.9.249.131, 96.9.250.147, 96.9.250.155, 96.9.250.200/29, 96.9.255.19
 * 96.9.243.5 · whois · spur · shodan · WorldVPN · us40.ocservvpn.com
 * 96.9.243.8 · whois · spur · shodan · WorldVPN · us51.ocservvpn.com
 * 96.9.244.23 · whois · spur · shodan · WorldVPN · us45.ocservvpn.com
 * 96.9.244.33 · whois · spur · shodan · WorldVPN · us41.ocservvpn.com
 * 96.9.244.34 · whois · spur · shodan · WorldVPN · us76.ocservvpn.com
 * 96.9.244.35 · whois · spur · shodan · WorldVPN · us70.ocservvpn.com
 * 96.9.244.150 · whois · spur · shodan · WorldVPN · us100.ocservvpn.com
 * 96.9.244.175 · whois · spur · shodan · WorldVPN · us4.ocservvpn.com
 * 96.9.244.179 · whois · spur · shodan · WorldVPN · us6.ocservvpn.com
 * 96.9.244.201 · whois · spur · shodan · WorldVPN · us99.ocservvpn.com
 * 96.9.244.204 · whois · spur · shodan · WorldVPN · us46.ocservvpn.com
 * 96.9.244.208 · whois · spur · shodan · WorldVPN · us87.ocservvpn.com
 * 96.9.244.210 · whois · spur · shodan · WorldVPN · us50.ocservvpn.com
 * 96.9.244.211 · whois · spur · shodan · WorldVPN · us88.ocservvpn.com
 * 96.9.244.212 · whois · spur · shodan · WorldVPN · us47.ocservvpn.com
 * 96.9.244.213 · whois · spur · shodan · WorldVPN · us48.ocservvpn.com
 * 96.9.244.214 · whois · spur · shodan · WorldVPN · us49.ocservvpn.com
 * 96.9.244.215 · whois · spur · shodan · WorldVPN · us78.ocservvpn.com
 * 96.9.244.216 · whois · spur · shodan · WorldVPN · us79.ocservvpn.com
 * 96.9.244.217 · whois · spur · shodan · WorldVPN · us80.ocservvpn.com
 * 96.9.244.218 · whois · spur · shodan · WorldVPN · us81.ocservvpn.com
 * 96.9.244.219 · whois · spur · shodan · WorldVPN · us5.ocservvpn.com
 * 96.9.244.220 · whois · spur · shodan · WorldVPN · us82.ocservvpn.com
 * 96.9.244.221 · whois · spur · shodan · WorldVPN · us42.ocservvpn.com
 * 96.9.244.229 · whois · spur · shodan · WorldVPN · us27.ocservvpn.com
 * 96.9.244.230 · whois · spur · shodan · WorldVPN · us21.ocservvpn.com
 * 96.9.244.231 · whois · spur · shodan · WorldVPN · us33.ocservvpn.com
 * 96.9.244.232 · whois · spur · shodan · WorldVPN · us89.ocservvpn.com
 * 96.9.244.235 · whois · spur · shodan · WorldVPN · us92.ocservvpn.com
 * 96.9.244.236 · whois · spur · shodan · WorldVPN · us93.ocservvpn.com
 * 96.9.244.237 · whois · spur · shodan · WorldVPN · us94.ocservvpn.com
 * 96.9.244.243 · whois · spur · shodan · WorldVPN · us95.ocservvpn.com
 * 96.9.244.244 · whois · spur · shodan · WorldVPN · us96.ocservvpn.com
 * 96.9.244.245 · whois · spur · shodan · WorldVPN · us26.ocservvpn.com

--MarioGom (talk) 13:14, 29 May 2021 (UTC)
 * Yep, that's a lot of proxies. : Please hardblock given the proxies, and place a softblock on the underlying range,, both for two years. Thanks. --Blablubbs&#124;talk 08:34, 31 May 2021 (UTC)
 * ✅ Hardblock for the /20; softblock for the /18.--Malcolmxl5 (talk) 12:14, 31 May 2021 (UTC)

91.90.44.0/26
close

Mullvad range. 91.90.44.18 can be verified by DNS no-osl-008.mullvad.net, or do some spot checks in the contributions list to Spur. Alternatively, the full Blix /21 at 91.90.40.0/21 can be blocked. A few other ranges from this AS are already blocked, see. MarioGom (talk) 15:35, 30 May 2021 (UTC)
 * ✅, considering that I'm on it right now and not currently in Norway. 91.90.44.28 (talk) 08:38, 31 May 2021 (UTC)
 * – per my logged-out editing above, please hardblock for two years. The entire ASN needs a look, but I don't have the time right now ( is indeed fine to hard- or softblock depending on your preference as well). --Blablubbs&#124;talk 08:41, 31 May 2021 (UTC)
 * We probably do want to hardblock the /21 Blix range, see User:MarioGom/sandbox/ProxyReport. MarioGom (talk) 10:55, 4 June 2021 (UTC)
 * ✅ Hardblocked the /21. --Malcolmxl5 (talk) 15:57, 4 June 2021 (UTC)
 * Thanks, closing. --Blablubbs&#124;talk 18:01, 4 June 2021 (UTC)

Windscribe (III)
close
 * ee.windscribe.com
 * ee.windscribe.com

--MarioGom (talk) 20:53, 24 May 2021 (UTC)
 * ✅. This is fairyhosting – there are some additional ranges involved. The provider also does colocation. : Please block for two years. Recommend hardblock given the presence of VPN nodes; soft + single IP blocks for the two above is an option too. In addition, please block the following two fairyhosting ranges, either soft or hard, as you prefer:
 * Thanks. --Blablubbs&#124;talk 08:11, 31 May 2021 (UTC)
 * ✅ --Malcolmxl5 (talk) 12:41, 6 June 2021 (UTC)
 * Thanks, closing. Feel free to close requests yourself if you want (just change  to ). --Blablubbs&#124;talk 12:44, 6 June 2021 (UTC)
 * ✅ --Malcolmxl5 (talk) 12:41, 6 June 2021 (UTC)
 * Thanks, closing. Feel free to close requests yourself if you want (just change  to ). --Blablubbs&#124;talk 12:44, 6 June 2021 (UTC)

82.103.181.179
close

Reason: Spur says 82.103.181.179 is part of Mullvad VPN. ISP is ASERGO, which appears to be a web host; Scamalytics says "They operate 16,121 IP addresses, almost all of which are running anonymizing VPNs, servers, Tor exit nodes, and public proxies." Malcolmxl5 (talk) 00:09, 6 June 2021 (UTC)
 * ✅, and there's more on the /18 (my current IP is 82.103.140.213, for example). – please block  and  (both ASERGO) hard, two years. Thanks. --Blablubbs&#124;talk 08:01, 6 June 2021 (UTC)
 * ✅ --Malcolmxl5 (talk) 12:35, 6 June 2021 (UTC)
 * Thanks, closing. --Blablubbs&#124;talk 12:36, 6 June 2021 (UTC)

ProtonVPN (II)
close



Unblocked ProtonVPN nodes. MarioGom (talk) 18:11, 6 May 2021 (UTC)
 * , looking for blockable ranges. --Blablubbs&#124;talk 16:00, 7 May 2021 (UTC)
 * This is a bit of a rabbit hole, bear with me. The IPs above are ✅ and there's a bunch of different webhosts involved.
 * The first lot is in, which is Doratelekom, a Turkish webhost. There's a lot more in the ASN, but I'm hesitant to action it without reading up some more, as a previous CU-block on a dora range indicates that there are also legitimate residential ranges here.
 * The second group is on a range that has normal residential IPs on it, so the following will have to be blocked individually:
 * The 162. group is this DS provider and covered by . Looking at the ASN here turned up some other ranges that are good to block:
 * The 162. group is this DS provider and covered by . Looking at the ASN here turned up some other ranges that are good to block:
 * The 162. group is this DS provider and covered by . Looking at the ASN here turned up some other ranges that are good to block:
 * The 162. group is this DS provider and covered by . Looking at the ASN here turned up some other ranges that are good to block:
 * The 162. group is this DS provider and covered by . Looking at the ASN here turned up some other ranges that are good to block:


 * (Kriener hosting)
 * (turkbil)
 * (Heficed, which also offers colocation)
 * (also Heficed)
 * (Fasthosting)
 * (dedipath, also offers colocation)
 * (dedipath)
 * (Heficed)
 * (dedipath}}
 * (Heficed)
 * (dedipath)
 * (Heficed)
 * (dedipath}}
 * (Heficed)
 * (dedipath)


 * The 185. ones are in, which belongs to ICME, a webhost that also offers colocation (given the VPN IPs, this one should probably be hardblocked, or soft with individual blocks on the VPN IPs). Other ranges belonging to that provider are:


 * (Datasolutions SA, can't quite figure out what that is but [https://data-solutions.net data-solutions.net seems to be a mail server)
 * (black.host, seems to be dedicated only)
 * (black.host, seems to be dedicated only)


 * The 194. group is also serverion and covered by
 * , please Hardblock the IPs I linked here for 2 years each. I'll leave it up to you whether you want to soft- or hardblock the ones where I noted colocation (or just leave the additional ranges alone entirely). --Blablubbs&#124;talk 16:44, 7 May 2021 (UTC)
 * I've addressed all of these, I believe and added some of these ISP's to ASNBlock, which should clean up some others too. !ɘM γɿɘυϘ ⅃ϘƧ  00:38, 7 June 2021 (UTC)
 * , please Hardblock the IPs I linked here for 2 years each. I'll leave it up to you whether you want to soft- or hardblock the ones where I noted colocation (or just leave the additional ranges alone entirely). --Blablubbs&#124;talk 16:44, 7 May 2021 (UTC)
 * I've addressed all of these, I believe and added some of these ISP's to ASNBlock, which should clean up some others too. !ɘM γɿɘυϘ ⅃ϘƧ  00:38, 7 June 2021 (UTC)

FastestVPN
close
 * usmia.jumptoserver.com
 * tr-iz-pptp-01.jumptoserver.com
 * br.jumptoserver.com
 * jp-tk-pptp-01.jumptoserver.com
 * pl2.jumptoserver.com
 * ro.jumptoserver.com

Unblocked IPs from this shady VPN company. All of them verified with DNS, Spur and Shodan (see SSL cert), except 45.179.88.31 which has no HTTP service as the others, but Spur flags, seems a webhost and responds to IKEv2 (UDP). MarioGom (talk) 09:18, 22 May 2021 (UTC)
 * , checking for blockable ranges. --Blablubbs&#124;talk 10:11, 23 May 2021 (UTC)
 * The above IPs are all ✅ VPNs. : See below
 * The first IP belongs to Netrouting/Colohost. If someone wants to go through: Most ranges in the ASN should be good to softblock, but there is at least one sublet residential range.
 * The second belongs to Bilrom Dedicated Server Network - 4, which is sublet from alastyr, a Turkish webhost. The entire ASN should be good for two-year hardblocks – the ranges in questions are
 * (will probably have to stick with the /32 there)
 * The third is Hostzone Brazil. Can't find much about the ISP, but I'm going to go out on a limb and say it's a webhost; please block for two years, either soft + single IP hardblock or hard for the range.
 * The fourth has a pretty convoluted WHOIS. The ASN belongs to IDC Frontier data centres, no ranges are blocked. Might merit further investigation – I can say that  is ehost idc and should probably be hardblocked given the VPN on it – alternatively, you can softblock the range and hardblock the VPN IP.
 * The fifth is BrainStorm Network aka oneprovider, which doesn't appear to do colocation, so is good for a hardblock. The ASN is "Artnet" and has some of the most nondescript WHOIS outputs I've ever seen. Can't find much about this provider, but looking at this, the ranges are probably at least good for softblocks if someone wants to hand those out.
 * The last one is netrouting again, see above. Recommend either hardblock for, or single IP hardblock + soft for the range(s).
 * Best, --Blablubbs&#124;talk 10:31, 23 May 2021 (UTC)
 * I've addressed all of these directly, and added a couple to ASNBlock. !ɘM γɿɘυϘ ⅃ϘƧ  00:49, 7 June 2021 (UTC)
 * The fourth has a pretty convoluted WHOIS. The ASN belongs to IDC Frontier data centres, no ranges are blocked. Might merit further investigation – I can say that  is ehost idc and should probably be hardblocked given the VPN on it – alternatively, you can softblock the range and hardblock the VPN IP.
 * The fifth is BrainStorm Network aka oneprovider, which doesn't appear to do colocation, so is good for a hardblock. The ASN is "Artnet" and has some of the most nondescript WHOIS outputs I've ever seen. Can't find much about this provider, but looking at this, the ranges are probably at least good for softblocks if someone wants to hand those out.
 * The last one is netrouting again, see above. Recommend either hardblock for, or single IP hardblock + soft for the range(s).
 * Best, --Blablubbs&#124;talk 10:31, 23 May 2021 (UTC)
 * I've addressed all of these directly, and added a couple to ASNBlock. !ɘM γɿɘυϘ ⅃ϘƧ  00:49, 7 June 2021 (UTC)

ExpressVPN (III)
close
 * usa-losangeles-1-ca-version-2.expressnetw.com
 * usa-losangeles-1-ca-version-2.expressnetw.com
 * usa-losangeles-1-ca-version-2.expressnetw.com

Got the 2 individual IPs from DNS enumeration, but the whole /24 seems to be ExpressVPN per whois (PANQ-VPN) and random Spur spot checks. MarioGom (talk) 20:49, 24 May 2021 (UTC)
 * ✅, plus a bunch of webnx ranges., please hardblock the following for two years:
 * (see above)
 * (HostUS VPS)
 * (Corgitech VPS
 * The following are other webnx ranges; the provider also offers colocation – I'd go with softblocks, but hard is fine too, as you prefer:
 * Thanks. --Blablubbs&#124;talk 15:46, 30 May 2021 (UTC)
 * I've blocked the 3 Symbol confirmed.svg Confirmed ranges directly, and added a lot of the rest (plus a BIG haul on AS1239) to ASNBlock. !ɘM γɿɘυϘ ⅃ϘƧ  01:02, 7 June 2021 (UTC)
 * Thanks for all your work. :) --Blablubbs&#124;talk 08:43, 7 June 2021 (UTC)
 * Thanks. --Blablubbs&#124;talk 15:46, 30 May 2021 (UTC)
 * I've blocked the 3 Symbol confirmed.svg Confirmed ranges directly, and added a lot of the rest (plus a BIG haul on AS1239) to ASNBlock. !ɘM γɿɘυϘ ⅃ϘƧ  01:02, 7 June 2021 (UTC)
 * Thanks for all your work. :) --Blablubbs&#124;talk 08:43, 7 June 2021 (UTC)
 * Thanks. --Blablubbs&#124;talk 15:46, 30 May 2021 (UTC)
 * I've blocked the 3 Symbol confirmed.svg Confirmed ranges directly, and added a lot of the rest (plus a BIG haul on AS1239) to ASNBlock. !ɘM γɿɘυϘ ⅃ϘƧ  01:02, 7 June 2021 (UTC)
 * Thanks for all your work. :) --Blablubbs&#124;talk 08:43, 7 June 2021 (UTC)
 * Thanks for all your work. :) --Blablubbs&#124;talk 08:43, 7 June 2021 (UTC)

92.38.175.0/24
closed

G-Core Labs, see whois. This ASN has many ranges blocked already. 92.38.175.0/27 is PureVPN (pointtoserver, see whois). MarioGom (talk) 11:51, 30 May 2021 (UTC)
 * Blocked the range. GeneralNotability (talk) 19:51, 6 June 2021 (UTC)

193.228.99.5
close
 * https://www.ipqualityscore.com/free-ip-lookup-proxy-vpn-test/lookup/193.228.99.5
 * https://www.ipqualityscore.com/free-ip-lookup-proxy-vpn-test/lookup/213.162.73.160
 * https://www.ipqualityscore.com/free-ip-lookup-proxy-vpn-test/lookup/213.162.80.225

I want to report proxies vpn doing vandal on pages. 112.172.112.143 (talk) 08:35, 9 June 2021 (UTC)


 * I took the freedom to fix the formatting of your report. MarioGom (talk) 09:10, 9 June 2021 (UTC)
 * IPs are ❌, closing. 112.172.112.143, please note that suspicion that an IP is a proxy is not grounds for reversion on its own. --Blablubbs&#124;talk 10:40, 9 June 2021 (UTC)

194.44.36.31
close

Reason: This proxy interfered with an SPI case during which a number of other proxies were blocked. This is possibly the same person who used other proxies. My very best wishes (talk) 03:38, 11 June 2021 (UTC)


 * Looking at it individually, I doubt this is currently a proxy. However, it might be worth to compare to other IPs in the SPI to have a clearer picture. MarioGom (talk) 07:59, 11 June 2021 (UTC)
 * I checked this one at the time; I agree that it's pretty, maybe if you really stretch it. Even if I could confirm, this is not a type of proxy where there's all that much use in blocking. Closing. --Blablubbs&#124;talk 11:12, 11 June 2021 (UTC)

146.70.38.0/24
close

M247-LTD-ARGENTINA range. PIA servers on 146.70.38.131, 146.70.38.132, 146.70.38.141, 146.70.38.142. MarioGom (talk) 19:23, 28 May 2021 (UTC)


 * I think the whole 146.70.0.0/16 is M247. MarioGom (talk) 12:38, 31 May 2021 (UTC)

Here's a list of some of the PIA and CyberGhost servers I found in the /16. You can find more by cross-checking xwiki contributions of 146.70.0.0/16 with spur.


 * 146.70.8.0/24
 * 146.70.8.2 · whois · spur · shodan · CyberGhost · ns.zagreb-rack401.nodes.gen4.ninja
 * 146.70.8.4 · whois · spur · shodan · CyberGhost · blade2.zagreb-rack401.nodes.gen4.ninja
 * 146.70.8.8 · whois · spur · shodan · CyberGhost · blade6.zagreb-rack401.nodes.gen4.ninja


 * 146.70.9.0/24
 * 146.70.9.14 · whois · spur · shodan · CyberGhost · blade12.bogota-rack402.nodes.gen4.ninja


 * 146.70.10.0/24
 * 146.70.10.3 · whois · spur · shodan · CyberGhost · blade1.sanjose-rack403.nodes.gen4.ninja
 * 146.70.10.5 · whois · spur · shodan · CyberGhost · blade3.sanjose-rack403.nodes.gen4.ninja
 * 146.70.10.9 · whois · spur · shodan · CyberGhost · blade7.sanjose-rack403.nodes.gen4.ninja
 * 146.70.10.12 · whois · spur · shodan · CyberGhost · blade10.sanjose-rack403.nodes.gen4.ninja


 * 146.70.11.0/24
 * 146.70.11.2 · whois · spur · shodan · CyberGhost · ns.santiago-rack402.nodes.gen4.ninja
 * 146.70.11.4 · whois · spur · shodan · CyberGhost · blade2.santiago-rack402.nodes.gen4.ninja
 * 146.70.11.6 · whois · spur · shodan · CyberGhost · blade4.santiago-rack402.nodes.gen4.ninja
 * 146.70.11.9 · whois · spur · shodan · CyberGhost · blade7.santiago-rack402.nodes.gen4.ninja
 * 146.70.11.11 · whois · spur · shodan · CyberGhost · blade9.santiago-rack402.nodes.gen4.ninja
 * 146.70.11.12 · whois · spur · shodan · CyberGhost · blade10.santiago-rack402.nodes.gen4.ninja
 * 146.70.11.14 · whois · spur · shodan · CyberGhost · blade12.santiago-rack402.nodes.gen4.ninja


 * 146.70.14.0/24
 * 146.70.14.2 · whois · spur · shodan · CyberGhost · ns.jakarta-rack402.nodes.gen4.ninja
 * 146.70.14.7 · whois · spur · shodan · CyberGhost · blade5.jakarta-rack402.nodes.gen4.ninja
 * 146.70.14.10 · whois · spur · shodan · CyberGhost · blade8.jakarta-rack402.nodes.gen4.ninja
 * 146.70.14.12 · whois · spur · shodan · CyberGhost · blade10.jakarta-rack402.nodes.gen4.ninja
 * 146.70.14.16 · whois · spur · shodan · CyberGhost · blade14.jakarta-rack402.nodes.gen4.ninja


 * 146.70.15.0/24
 * 146.70.15.4 · whois · spur · shodan · CyberGhost · blade2.kualalumpur-rack403.nodes.gen4.ninja
 * 146.70.15.5 · whois · spur · shodan · CyberGhost · blade3.kualalumpur-rack403.nodes.gen4.ninja
 * 146.70.15.9 · whois · spur · shodan · CyberGhost · blade7.kualalumpur-rack403.nodes.gen4.ninja


 * 146.70.38.0/24
 * 146.70.38.131 · whois · spur · shodan · PIA · ar.privacy.network
 * 146.70.38.132 · whois · spur · shodan · PIA · ar.privacy.network
 * 146.70.38.141 · whois · spur · shodan · PIA · ar.privacy.network
 * 146.70.38.142 · whois · spur · shodan · PIA · ar.privacy.network


 * 146.70.39.0/24
 * 146.70.39.2 · whois · spur · shodan · CyberGhost · ns.buenosaires-rack403.nodes.gen4.ninja
 * 146.70.39.4 · whois · spur · shodan · CyberGhost · blade2.buenosaires-rack403.nodes.gen4.ninja
 * 146.70.39.7 · whois · spur · shodan · CyberGhost · blade5.buenosaires-rack403.nodes.gen4.ninja
 * 146.70.39.10 · whois · spur · shodan · CyberGhost · blade8.buenosaires-rack403.nodes.gen4.ninja
 * 146.70.39.16 · whois · spur · shodan · CyberGhost · blade14.buenosaires-rack403.nodes.gen4.ninja
 * 146.70.39.130 · whois · spur · shodan · CyberGhost · ns.buenosaires-rack404.nodes.gen4.ninja
 * 146.70.39.131 · whois · spur · shodan · CyberGhost · blade1.buenosaires-rack404.nodes.gen4.ninja
 * 146.70.39.134 · whois · spur · shodan · CyberGhost · blade4.buenosaires-rack404.nodes.gen4.ninja
 * 146.70.39.135 · whois · spur · shodan · CyberGhost · blade5.buenosaires-rack404.nodes.gen4.ninja
 * 146.70.39.140 · whois · spur · shodan · CyberGhost · blade10.buenosaires-rack404.nodes.gen4.ninja

--MarioGom (talk) 18:17, 9 June 2021 (UTC)
 * I checked random IPs in the /16; it's almost certainly all M247. – please hardblock  for two years. Thanks. --Blablubbs&#124;talk 11:57, 11 June 2021 (UTC)
 * ✅ --Malcolmxl5 (talk) 08:13, 12 June 2021 (UTC)

176.67.85.0/24
close

The range belongs to Mudhook Marketing (IPVanish), see whois. There are many confirmed IPVanish nodes within the ranges. Also, hundreds of other VPN servers (already blocked) in the same ASN. MarioGom (talk) 11:34, 29 May 2021 (UTC)
 * ✅., please hardblock for two years. The rest of the ASN is already whacked. Thanks. --Blablubbs&#124;talk 11:45, 11 June 2021 (UTC)
 * ✅ --Malcolmxl5 (talk) 08:10, 12 June 2021 (UTC)

152.228.128.0/17
close

OVH, see whois. WorldVPN servers on 152.228.210.107 and 152.228.215.225. MarioGom (talk) 11:48, 30 May 2021 (UTC)
 * I've learnt today about OVH's mess mixing DSL and hosting ranges. The /17 is probably not the best option and sub-ranges should be checked instead. MarioGom (talk) 07:09, 7 June 2021 (UTC)


 * ✅ both individual IPs. Concur about the complicated ranges – the /17 is too wide. However, is VPS-SBG6, so very likely safe to block.  – please hardblock it for two years. Thanks. --Blablubbs&#124;talk 11:48, 11 June 2021 (UTC)
 * ✅ --Malcolmxl5 (talk) 08:03, 12 June 2021 (UTC)

94.64.198.226
close

Reason: the proxy is engaged in edit warring, possibly on behalf of a named account. My very best wishes (talk) 03:13, 11 June 2021 (UTC)
 * ✅, no details per BEANS., please block the individual IP for two weeks. Thanks. --Blablubbs&#124;talk 11:14, 11 June 2021 (UTC)
 * Since blocked 72h for edit warring. Should be enough for this one. Closing. --Blablubbs&#124;talk 17:22, 12 June 2021 (UTC)