Reason: I’m not sure which LTA has used this IP but as they also use apparently legit Australian IPs, there’s a good chance that this one geolocating to Benin is a proxy. Spur suggests it’s a residential proxy. Robtex says it is "hosted by This is a DiViNetworks customer route-object which is being exported under this origin AS37090". Also according to Robtex, 41.222.192.0/22 is a "proxy-registered route object". --Malcolmxl5 (talk) 04:25, 15 May 2021 (UTC)
@Malcolmxl5:Confirmed residential proxy, meaning that it will behave like any normal device on that range (which is very unlikely to be a webhost) – because of that, long blocks won't help here. You could probably extend it to a week or two, but I wouldn't suggest anything longer than that and the effectiveness will be limited. No details per BEANS, but I can shoot you an email if you want to eat those. --Blablubbs|talk08:57, 15 May 2021 (UTC)
I’ll leave the block as it is, Blablubbs, if these are only blocked for a short time. If you could email me BEANS, I’ll be grateful. --Malcolmxl5 (talk) 15:49, 15 May 2021 (UTC)
AlthusHost range, everything I can see on it is IPVanish VPN. Awaiting administrative action – please hardblock it for two years. Thanks. --Blablubbs|talk13:56, 11 May 2021 (UTC)
Here's a large report on Urban VPN that Blablubbs and me prepared last month. The first collapsed section contains all unblocked individual IPs. The rest of the sections include all IPs plus information about parent ranges. MarioGom (talk) 16:40, 5 April 2021 (UTC)
MarioGom, slowly making my way through these. 93.94.109.157 (be2) is not coming up as a proxy for me - Spur says no, and I'm not seeing the characteristic fingerprint on Shodan. Think it moved/disappeared, or is that a typo? GeneralNotability (talk) 01:05, 18 May 2021 (UTC)
Finished A-E, anything unblocked in there did not come up on Shodan as a match. I'm trying to coax a useful report out of Shodan now to see where those nodes went. GeneralNotability (talk) 01:41, 18 May 2021 (UTC)
GeneralNotability, the IP for be2 did not change, but indeed, it does not present the same fingerprint. It's the same case for cn3, es2, es3, sg3, tw2, us7 and za3. I only checked unblocked IPs. Here's an updated enumeration of the unblocked individual addresses:
Thanks for the updated list. I've blocked everything in the unblocked list (and most of the globally-blocked ones for good measure). All IPs were confirmed - most via Shodan showing the fingerprint, the rest via lookup of the hostnames. GeneralNotability (talk) 01:31, 19 May 2021 (UTC)
There are other Fishnet ranges, but I'd have to take a deeper dive. Can't say much about the webhost for the Thai IP. Awaiting administrative action: Please hardblock the ranges above and 202.129.16.155 for 2 years each. Thanks. --Blablubbs|talk11:56, 7 May 2021 (UTC)