does anyone have all netblocks from recyber.net ?
because if u block the whois recyber.net network 89.248.165.0/24 , nothing happens.
so i guess they use fake ip's and have more networks in use.
i like to block them because i also dont like the massive port scans and malware from thier networks.
Thanks for that link, Wolfgang!
I don't think they're a malicious port scanner. If I did, I would add 89.248.165.0/24 to my "All Portscanners" Network Group. I have an Intrusion Prevention Exception that skips Anti-Portscan for that group. I also have a firewall rule that Rejects all traffic from that Network Group. Virtually all of the malicious port scans come from Russia and China.
Cheers - Bob
Yes very annoying. i can access my ISP Cisco and Block traffic before it reaches the firewall. but i still get port scanns from that net block.
so i guess they fake IP adresses. if the net block would like the one in the whois, it would be impossible to get thru the cisco deny list.
so yeah, time to block them.