What's the deal with openportstats.com?
Over the last few months a few groups I am involved with have been discussing openportstats.com. They first came to my attention in May of 2020. At that time a number of ISPs indicated attempted DOS by IPs in Russia (ASN202425). The volume of traffic was not really big enough to do any harm, but in some cases the volume of network traffic was causing issues for some devices and causing congestion on some low speed links.
In July the traffic reappeared.
One firewall was showing 330,000 blocked port scan events an hour. With some free time for research, the path led to the website openportstats.com, a website hosted in France, and purporting to be IoT researchers. In fact in late July the ISC added openportstats to our list of known researchers.
Starting in September, the scans became almost continuous.
I recently attempted to contact them using the two email addresses listed on their website, and both emails were returned "server not available".
I am all for supporting security research, but none of the other various scanners and crawlers which contribute to the background noise of the Internet are causing the level of impact openportstats.com is. Their scans are clumsy and overly aggressive and given my lack of luck attempting to contact them I am having to question the legitimacy of these researchers and their research.
If you have also experienced impact from their scans, or know anyone associated with openportstats.com, I would love to hear about it via comments on this diary or through our contact page.
Update: A reader pointed out that the IPs are not actually in Russia, but rather in the Netherlands. Some of the IP ranges are registered to Russian IP addresses, but AS204655 and AS202425 are both hosted near Amsterdam by IP Volume Inc which is formerly known as Ecatel. Ecatel and its progeny have a somewhat notorious history.
-- Rick Wanner MSISE - rwanner at isc dot sans dot edu - http://namedeplume.blogspot.com/ - Twitter:namedeplume (Protected)
Comments
Anonymous
Dec 22nd 2020
3 years ago
Anonymous
Dec 22nd 2020
3 years ago
Unfortunately neither of those articles were big on details, so it was difficult to quantify if they are up to something or if this is just coincidence. Badness happens all the time on the Internet. I did want to call them out, but wasn't going to acuse them of malicious activity without quantifiable proof.
Anonymous
Dec 22nd 2020
3 years ago
185.216.140.0/23 - AS204655
80.82.64.0/24 - AS202425
80.82.65.0/24 - AS202425
80.82.70.0/24 - AS202425
80.82.77.0/24 - AS202425
80.82.78.0/24 - AS202425
89.248.160.0/24 - AS202425
89.248.162.0/24 - AS202425
89.248.167.0/24 - AS202425
89.248.168.0/24 - AS202425
89.248.169.0/24 - AS202425
89.248.170.0/24 - AS202425
89.248.171.0/24 - AS202425
89.248.172.0/24 - AS202425
89.248.174.0/24 - AS202425
93.174.93.0/24 - AS202425
93.174.95.0/24 - AS202425
94.102.49.0/24 - AS202425
94.102.50.0/24 - AS202425
94.102.51.0/24 - AS202425
94.102.52.0/24 - AS202425
94.102.53.0/24 - AS202425
94.102.56.0/24 - AS202425
94.102.57.0/24 - AS202425
Anonymous
Dec 22nd 2020
3 years ago