Skip to content

Tons of Stretchoid IP ranges missing? #251

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
that-ben opened this issue May 17, 2025 · 8 comments
Open

Tons of Stretchoid IP ranges missing? #251

that-ben opened this issue May 17, 2025 · 8 comments
Assignees
Labels
data-update Updates the data

Comments

@that-ben
Copy link

Hi, just posting this to try to help the security community. You are missing lots of Stretchoid IP ranges in https://security.wdes.eu/scanners/stretchoid.txt

I stopped comparing with my list very early on at the 4.0.0.0/16 range, but here are a few examples of what you're missing and I'm sure there are thousands more...

4.236.187.0/24 # 2025-03-15 - Microsoft (stretchoid.com)
4.236.188.0/24 # 2025-03-15 - Microsoft (stretchoid.com)
4.236.189.0/24 # 2025-03-15 - Microsoft (stretchoid.com)
4.236.190.0/24 # 2025-03-05 - Microsoft (stretchoid.com)
4.236.191.0/24 # 2025-04-04 - Microsoft (stretchoid.com)
4.246.227.0/24 # 2025-03-15 - Microsoft (stretchoid.com)
4.246.228.0/24 # 2025-03-15 - Microsoft (stretchoid.com)

I'm not posting this to blame you. Stretchoid is a real Internet cancer and I hope that the more they get blocked, the more their mysterious and anonymous "research project" ends.

@williamdes
Copy link
Member

Hi!
I requested a scan of the /16 on https://security.wdes.eu
You can also post a full list of IPs using /32 on each line, and fill an username of your choice.

Yes they are a real cancer, and more it goes more I think that I need to build bash reporters.
each reporter would send new hits from logs to this project

while read log
  if grep stretchoid
    push to queue
while 1hour passes
 send results to security.wdes.eu
 purge results

Would you adhere to such a reporting system?

@williamdes williamdes self-assigned this May 17, 2025
@williamdes williamdes added the data-update Updates the data label May 17, 2025
@that-ben
Copy link
Author

that-ben commented May 17, 2025

FYI, I currently use AbuseIPDB and this is how I obtained my IP list so far. I just discovered your project and I had a look at your Stretchoid IP list and this is what made me post this thread, just to point out that there are a lot more Stretchoid IP address ranges than what you have gathered so far. Maybe we should merge our lists together.

I also have a huge list of other Internet "cancers" such as 3xK Tech GmbH scanners, Digital Ocean scanners, Alibaba Cloud scanners and many, many more.

@williamdes
Copy link
Member

I would be very glad to have your help!

for vendors not changing too often you can add lists here https://github.com/wdes/security/tree/main/data/collections
For other ones, some code needs to be done
but I can add them
And then I need to make a new release, with a new Deb file and install it on the server.

I have to push my recent work on modernizing the code for different detections

@that-ben
Copy link
Author

that-ben commented May 17, 2025

This is what I have so far that is 100% labelled as Stretchoid, but I have a lot more from Microsoft IP addresses that I suspect are Stretchoid, but are not officially labelled Stretchoid just yet (but maybe they will over the next few weeks, not sure).

4.151.38.0/24 # 2024-12-29 - Microsoft (stretchoid.com)
4.151.219.0/24 # 2024-12-25 - Microsoft (stretchoid.com)
4.151.220.0/24 # 2024-12-13 - Microsoft (stretchoid.com)
4.151.228.0/24 # 2025-02-01 - Microsoft (stretchoid.com)
4.151.230.0/24 # 2024-12-27 - Microsoft (stretchoid.com)
4.156.21.0/24 # 2024-12-13 - Microsoft (stretchoid.com)
4.156.237.0/24 # 2024-12-13 - Microsoft (stretchoid.com)
4.227.178.0/24 # 2025-05-14 - Microsoft (stretchoid.com)
4.236.187.0/24 # 2025-03-15 - Microsoft (stretchoid.com)
4.236.188.0/24 # 2025-03-15 - Microsoft (stretchoid.com)
4.236.189.0/24 # 2025-03-15 - Microsoft (stretchoid.com)
4.236.190.0/24 # 2025-03-05 - Microsoft (stretchoid.com)
4.236.191.0/24 # 2025-04-04 - Microsoft (stretchoid.com)
4.246.227.0/24 # 2025-03-15 - Microsoft (stretchoid.com)
4.246.228.0/24 # 2025-03-15 - Microsoft (stretchoid.com)
4.246.231.0/24 # 2025-03-08 - Microsoft (stretchoid.com)
4.246.247.0/24 # 2024-12-25 - Microsoft (stretchoid.com)
4.255.100.0/24 # 2025-01-01 - Microsoft (stretchoid.com)
4.255.101.0/24 # 2024-12-13 - Microsoft (stretchoid.com)
9.234.8.0/24 # 2025-05-10 - Microsoft (stretchoid.com)
13.64.108.0/24 # 2024-12-25 - Microsoft (stretchoid.com)
13.64.111.0/24 # 2024-12-25 - Microsoft (stretchoid.com)
13.64.192.0/24 # 2024-12-24 - Microsoft (stretchoid.com)
13.64.193.0/24 # 2024-12-25 - Microsoft (stretchoid.com)
13.64.194.0/24 # 2025-01-03 - Microsoft (stretchoid.com)
13.83.41.0/24 # 2025-01-01 - Microsoft (stretchoid.com)
13.86.104.0/24 # 2025-05-15 - Microsoft (stretchoid.com)
13.87.132.0/24 # 2024-12-24 - Microsoft (stretchoid.com)
13.89.124.0/24 # 2025-03-15 - Microsoft (stretchoid.com)
13.89.125.0/24 # 2025-03-06 - Microsoft (stretchoid.com)
13.91.41.0/24 # 2025-01-01 - Microsoft (stretchoid.com)
13.91.165.0/24 # 2025-01-02 - Microsoft (stretchoid.com)
13.91.180.0/24 # 2024-12-25 - Microsoft (stretchoid.com)
13.91.181.0/24 # 2024-12-25 - Microsoft (stretchoid.com)
13.91.241.0/24 # 2025-01-18 - Microsoft (stretchoid.com)
20.29.21.0/24 # 2025-03-08 - Microsoft (stretchoid.com)
20.29.22.0/24 # 2025-03-08 - Microsoft (stretchoid.com)
20.29.23.0/24 # 2025-03-15 - Microsoft (stretchoid.com)
20.29.33.0/24 # 2025-03-15 - Microsoft (stretchoid.com)
20.29.35.0/24 # 2025-03-15 - Microsoft (stretchoid.com)
20.29.36.0/24 # 2025-03-08 - Microsoft (stretchoid.com)
20.29.57.0/24 # 2025-05-14 - Microsoft (stretchoid.com)
20.29.58.0/24 # 2025-05-17 - Microsoft (stretchoid.com)
20.40.216.0/24 # 2025-05-10 - Microsoft (stretchoid.com)
20.55.35.0/24 # 2025-05-10 - Microsoft (stretchoid.com)
20.55.88.0/24 # 2025-05-17 - Microsoft (stretchoid.com)
20.64.97.0/24 # 2025-04-05 - Microsoft (stretchoid.com)
20.64.104.0/24 # 2025-04-02 - Microsoft (stretchoid.com)
20.64.106.0/24 # 2025-03-19 - Microsoft (stretchoid.com)
20.64.107.0/24 # 2025-03-26 - Microsoft (stretchoid.com)
20.81.46.0/24 # 2025-05-10 - Microsoft (stretchoid.com)
20.83.51.0/24 # 2025-03-08 - Microsoft (stretchoid.com)
20.83.52.0/24 # 2025-03-08 - Microsoft (stretchoid.com)
20.83.53.0/24 # 2025-03-15 - Microsoft (stretchoid.com)
20.83.167.0/24 # 2025-05-14 - Microsoft (stretchoid.com)
20.84.144.0/24 # 2025-03-15 - Microsoft (stretchoid.com)
20.84.145.0/24 # 2025-03-08 - Microsoft (stretchoid.com)
20.84.146.0/24 # 2025-03-08 - Microsoft (stretchoid.com)
20.84.147.0/24 # 2025-03-08 - Microsoft (stretchoid.com)
20.84.152.0/24 # 2025-05-15 - Microsoft (stretchoid.com)
20.84.153.0/24 # 2025-05-17 - Microsoft (stretchoid.com)
20.98.140.0/24 # 2025-03-15 - Microsoft (stretchoid.com)
20.98.141.0/24 # 2025-03-15 - Microsoft (stretchoid.com)
20.98.142.0/24 # 2025-03-15 - Microsoft (stretchoid.com)
20.98.164.0/24 # 2025-05-15 - Microsoft (stretchoid.com)
20.102.40.0/24 # 2025-05-17 - Microsoft (stretchoid.com)
20.102.89.0/24 # 2025-05-14 - Microsoft (stretchoid.com)
20.102.105.0/24 # 2025-05-16 - Microsoft (stretchoid.com)
20.106.56.0/24 # 2025-05-16 - Microsoft (stretchoid.com)
20.106.57.0/24 # 2025-05-09 - Microsoft (stretchoid.com)
20.106.168.0/24 # 2025-05-17 - Microsoft (stretchoid.com)
20.106.206.0/24 # 2025-05-17 - Microsoft (stretchoid.com)
20.106.236.0/24 # 2025-03-08 - Microsoft (stretchoid.com)
20.115.83.0/24 # 2025-05-16 - Microsoft (stretchoid.com)
20.118.32.0/24 # 2025-05-17 - Microsoft (stretchoid.com)
20.118.64.0/24 # 2025-01-02 - Microsoft (stretchoid.com)
20.118.68.0/24 # 2024-12-25 - Microsoft (stretchoid.com)
20.118.69.0/24 # 2024-12-24 - Microsoft (stretchoid.com)
20.118.202.0/24 # 2025-05-10 - Microsoft (stretchoid.com)
20.118.209.0/24 # 2025-05-09 - Microsoft (stretchoid.com)
20.118.232.0/24 # 2025-05-10 - Microsoft (stretchoid.com)
20.119.99.0/24 # 2025-05-17 - Microsoft (stretchoid.com)
20.121.143.0/24 # 2025-04-08 - Microsoft (stretchoid.com)
20.124.93.0/24 # 2025-05-17 - Microsoft (stretchoid.com)
20.127.157.0/24 # 2025-05-17 - Microsoft (stretchoid.com)
20.127.201.0/24 # 2025-05-17 - Microsoft (stretchoid.com)
20.127.220.0/24 # 2025-05-16 - Microsoft (stretchoid.com)
20.150.194.0/24 # 2025-05-17 - Microsoft (stretchoid.com)
20.150.200.0/24 # 2025-03-27 - Microsoft (stretchoid.com)
20.150.201.0/24 # 2025-03-08 - Microsoft (stretchoid.com)
20.150.202.0/24 # 2025-03-01 - Microsoft (stretchoid.com)
20.150.203.0/24 # 2025-03-14 - Microsoft (stretchoid.com)
20.150.204.0/24 # 2025-03-15 - Microsoft (stretchoid.com)
20.150.206.0/24 # 2025-03-10 - Microsoft (stretchoid.com)
20.169.53.0/24 # 2025-05-17 - Microsoft (stretchoid.com)
20.169.83.0/24 # 2025-05-15 - Microsoft (stretchoid.com)
20.169.85.114 # 2025-04-04 - Microsoft (stretchoid.com)
20.169.104.0/24 # 2025-03-06 - Microsoft (stretchoid.com)
20.169.105.0/24 # 2025-03-03 - Microsoft (stretchoid.com)
20.169.106.0/24 # 2025-03-08 - Microsoft (stretchoid.com)
20.169.107.0/24 # 2025-03-08 - Microsoft (stretchoid.com)
20.171.24.0/24 # 2025-03-08 - Microsoft (stretchoid.com)
20.171.25.0/24 # 2025-03-08 - Microsoft (stretchoid.com)
20.171.26.0/24 # 2025-03-08 - Microsoft (stretchoid.com)
20.171.27.0/24 # 2025-03-08 - Microsoft (stretchoid.com)
20.171.28.0/24 # 2025-03-15 - Microsoft (stretchoid.com)
20.171.29.0/24 # 2025-03-01 - Microsoft (stretchoid.com)
20.171.30.0/24 # 2025-03-08 - Microsoft (stretchoid.com)
20.171.31.0/24 # 2025-03-20 - Microsoft (stretchoid.com)
20.172.67.0/24 # 2025-05-04 - Microsoft (stretchoid.com)
20.225.3.0/24 # 2024-12-13 - Microsoft (stretchoid.com)
40.74.208.0/24 # 2025-04-04 - Microsoft (stretchoid.com)
40.76.116.0/24 # 2025-05-17 - Microsoft (stretchoid.com)
40.76.125.0/24 # 2025-05-16 - Microsoft (stretchoid.com)
40.76.137.0/24 # 2025-05-15 - Microsoft (stretchoid.com)
40.76.225.0/24 # 2025-05-16 - Microsoft (stretchoid.com)
40.78.88.0/24 # 2024-12-25 - Microsoft (stretchoid.com)
40.78.95.0/24 # 2024-12-25 - Microsoft (stretchoid.com)
40.78.127.0/24 # 2025-02-01 - Microsoft (stretchoid.com)
40.80.204.0/24 # 2025-04-04 - Microsoft (stretchoid.com)
40.80.206.0/24 # 2025-04-04 - Microsoft (stretchoid.com)
40.118.208.0/24 # 2025-01-01 - Microsoft (stretchoid.com)
40.118.214.0/24 # 2025-01-22 - Microsoft (stretchoid.com)
40.119.43.0/24 # 2025-04-11 - Microsoft (stretchoid.com)
48.216.196.0/24 # 2024-12-25 - Microsoft (stretchoid.com)
48.216.197.0/24 # 2024-12-25 - Microsoft (stretchoid.com)
48.216.242.0/24 # 2025-05-10 - Microsoft (stretchoid.com)
48.216.248.0/24 # 2025-03-15 - Microsoft (stretchoid.com)
48.217.211.0/24 # 2025-01-03 - Microsoft (stretchoid.com)
48.217.212.0/24 # 2025-01-14 - Microsoft (stretchoid.com)
48.217.233.0/24 # 2025-05-17 - Microsoft (stretchoid.com)
52.157.3.0/24 # 2025-01-21 - Microsoft (stretchoid.com)
52.160.37.0/24 # 2024-12-25 - Microsoft (stretchoid.com)
52.165.81.0/24 # 2025-05-15 - Microsoft (stretchoid.com)
52.165.88.0/24 # 2025-05-16 - Microsoft (stretchoid.com)
52.180.137.0/24 # 2025-05-09 - Microsoft (stretchoid.com)
52.180.157.0/24 # 2025-05-16 - Microsoft (stretchoid.com)
52.183.224.0/24 # 2024-12-25 - Microsoft (stretchoid.com)
52.186.170.0/24 # 2025-05-16 - Microsoft (stretchoid.com)
52.186.171.0/24 # 2025-05-16 - Microsoft (stretchoid.com)
52.186.178.0/24 # 2025-05-16 - Microsoft (stretchoid.com)
52.186.182.0/24 # 2025-05-14 - Microsoft (stretchoid.com)
52.188.189.0/24 # 2025-05-17 - Microsoft (stretchoid.com)
52.189.75.0/24 # 2024-12-24 - Microsoft (stretchoid.com)
52.189.76.0/24 # 2024-12-13 - Microsoft (stretchoid.com)
52.189.78.0/24 # 2024-12-24 - Microsoft (stretchoid.com)
52.224.242.0/24 # 2025-05-15 - Microsoft (stretchoid.com)
52.228.152.0/24 # 2024-12-25 - Microsoft (stretchoid.com)
52.228.153.0/24 # 2024-12-25 - Microsoft (stretchoid.com)
52.228.154.0/24 # 2024-12-24 - Microsoft (stretchoid.com)
52.228.161.0/24 # 2024-12-25 - Microsoft (stretchoid.com)
52.228.167.0/24 # 2024-12-24 - Microsoft (stretchoid.com)
52.249.38.0/24 # 2024-12-13 - Microsoft (stretchoid.com)
52.249.219.0/24 # 2025-05-15 - Microsoft (stretchoid.com)
57.151.48.0/24 # 2025-01-03 - Microsoft (stretchoid.com)
57.151.68.0/24 # 2024-12-25 - Microsoft (stretchoid.com)
57.151.70.0/24 # 2025-01-01 - Microsoft (stretchoid.com)
57.151.97.0/24 # 2025-05-17 - Microsoft (stretchoid.com)
57.152.56.0/24 # 2024-12-25 - Microsoft (stretchoid.com)
57.152.77.0/24 # 2025-01-03 - Microsoft (stretchoid.com)
57.152.78.0/24 # 2024-12-24 - Microsoft (stretchoid.com)
74.235.100.0/24 # 2025-05-16 - Microsoft (stretchoid.com)
74.235.205.0/24 # 2025-05-16 - Microsoft (stretchoid.com)
74.249.128.0/24 # 2025-05-17 - Microsoft (stretchoid.com)
74.249.178.0/24 # 2025-05-15 - Microsoft (stretchoid.com)
104.40.0.0/16 # 2025-03-13 - Microsoft (stretchoid.com)
104.45.224.0/24 # 2024-12-25 - Microsoft (stretchoid.com)
104.209.34.0/24 # 2024-12-25 - Microsoft (stretchoid.com)
104.209.35.0/24 # 2024-12-24 - Microsoft (stretchoid.com)
128.203.200.0/24 # 2025-03-15 - Microsoft (stretchoid.com)
128.203.201.0/24 # 2025-03-10 - Microsoft (stretchoid.com)
128.203.202.0/24 # 2025-03-15 - Microsoft (stretchoid.com)
128.203.203.0/24 # 2024-03-10 - Microsoft (stretchoid.com)
128.203.204.0/24 # 2025-03-10 - Microsoft (stretchoid.com)
130.131.162.0/24 # 2025-05-14 - Microsoft (stretchoid.com)
135.119.96.0/24 # 2025-05-15 - Microsoft (stretchoid.com)
135.222.40.0/24 # 2025-05-09 - Microsoft (stretchoid.com)
135.237.120.0/24 # 2025-05-16 - Microsoft (stretchoid.com)
135.237.124.0/24 # 2025-05-08 - Microsoft (stretchoid.com)
138.91.109.0/24 # 2025-05-17 - Microsoft (stretchoid.com)
172.168.40.0/24 # 2024-12-13 - Microsoft (stretchoid.com)
172.168.152.0/24 # 2024-12-25 - Microsoft (stretchoid.com)
172.168.155.0/24 # 2024-12-25 - Microsoft (stretchoid.com)
172.168.157.0/24 # 2024-12-25 - Microsoft (stretchoid.com)
172.168.158.0/24 # 2024-12-13 - Microsoft (stretchoid.com)
172.168.159.0/24 # 2025-01-04 - Microsoft (stretchoid.com)
172.169.2.0/24 # 2024-12-25 - Microsoft (stretchoid.com)
172.169.3.0/24 # 2025-01-03 - Microsoft (stretchoid.com)
172.169.6.0/24 # 2025-01-03 - Microsoft (stretchoid.com)
172.169.105.0/24 # 2024-12-25 - Microsoft (stretchoid.com)
172.169.108.0/24 # 2025-01-03 - Microsoft (stretchoid.com)
172.169.110.0/24 # 2024-12-13 - Microsoft (stretchoid.com)
172.169.111.0/24 # 2024-12-25 - Microsoft (stretchoid.com)
172.169.190.0/24 # 2025-01-18 - Microsoft (stretchoid.com)
172.169.191.0/24 # 2024-12-24 - Microsoft (stretchoid.com)
172.169.205.0/24 # 2024-12-24 - Microsoft (stretchoid.com)
172.169.206.0/24 # 2024-12-29 - Microsoft (stretchoid.com)
172.169.207.0/24 # 2024-12-25 - Microsoft (stretchoid.com)
172.170.167.0/24 # 2025-01-28 - Microsoft (stretchoid.com)
172.171.245.0/24 # 2025-03-08 - Microsoft (stretchoid.com)
172.171.246.0/24 # 2025-03-08 - Microsoft (stretchoid.com)
172.174.200.0/24 # 2025-05-17 - Microsoft (stretchoid.com)
172.174.253.0/24 # 2025-04-04 - Microsoft (stretchoid.com)
172.174.254.0/24 # 2025-04-04 - Microsoft (stretchoid.com)
172.174.255.0/24 # 2025-04-04 - Microsoft (stretchoid.com)
172.178.73.0/24 # 2025-04-05 - Microsoft (stretchoid.com)
172.178.74.0/24 # 2025-04-04 - Microsoft (stretchoid.com)
172.178.115.0/24 # 2025-05-16 - Microsoft (stretchoid.com)
172.178.123.0/24 # 2025-04-05 - Microsoft (stretchoid.com)
172.178.124.0/24 # 2025-04-01 - Microsoft (stretchoid.com)
172.178.126.0/24 # 2025-04-04 - Microsoft (stretchoid.com)
172.178.127.0/24 # 2025-04-05 - Microsoft (stretchoid.com)
172.202.49.0/24 # 2025-05-17 - Microsoft (stretchoid.com)
172.202.113.0/24 # 2025-05-17 - Microsoft (stretchoid.com)
172.202.117.0/24 # 2025-03-08 - Microsoft (stretchoid.com)
172.202.118.0/24 # 2025-03-08 - Microsoft (stretchoid.com)
172.202.250.0/24 # 2025-03-08 - Microsoft (stretchoid.com)
172.202.251.0/24 # 2024-12-25 - Microsoft (stretchoid.com)
172.202.252.0/24 # 2025-01-06 - Microsoft (stretchoid.com)
172.202.253.0/24 # 2025-01-01 - Microsoft (stretchoid.com)
172.206.141.0/24 # 2024-12-24 - Microsoft (stretchoid.com)
172.206.143.0/24 # 2024-12-25 - Microsoft (stretchoid.com)
172.206.145.0/24 # 2024-12-25 - Microsoft (stretchoid.com)
172.206.147.0/24 # 2024-12-24 - Microsoft (stretchoid.com)
172.206.148.0/24 # 2024-12-13 - Microsoft (stretchoid.com)
172.206.224.0/24 # 2025-05-10 - Microsoft (stretchoid.com)
172.206.226.0/24 # 2025-05-17 - Microsoft (stretchoid.com)
172.208.25.0/24 # 2025-05-16 - Microsoft (stretchoid.com)
172.210.68.0/24 # 2025-05-16 - Microsoft (stretchoid.com)
172.212.59.0/24 # 2024-12-24 - Microsoft (stretchoid.com)
172.212.60.0/24 # 2025-01-18 - Microsoft (stretchoid.com)
172.212.61.0/24 # 2024-12-31 - Microsoft (stretchoid.com)
172.212.102.0/24 # 2025-03-06 - Microsoft (stretchoid.com)
172.212.103.0/24 # 2025-03-06 - Microsoft (stretchoid.com)
172.214.113.0/24 # 2025-03-16 - Microsoft (stretchoid.com)
172.214.114.0/24 # 2025-01-17 - Microsoft (stretchoid.com)
172.215.145.0/24 # 2025-05-17 - Microsoft (stretchoid.com)

@williamdes
Copy link
Member

How do you suspect an IP?
Also, you might like my tool to bulk&round robin reverse dns IPs
https://github.com/wdes/dns-ptr-resolver

@szepeviktor
Copy link
Contributor

szepeviktor commented May 18, 2025

Seems like stretchoid was kicked out of Digital Ocean and lives in AS8075.

You could get a list of stretchoid IP ranges from Alienvault.

# Get API KEY from https://otx.alienvault.com/settings
curl -H "X-OTX-API-KEY: $API_KEY" "https://otx.alienvault.com/api/v1/indicators/domain/stretchoid.com/passive_dns" > stretchoid.json
cat stretchoid.json | jq -r '."passive_dns"[]."address" | select(test("^\\d{1,3}(\\.\\d{1,3}){3}$")) | (split(".") | .[0:3] + ["0"] | join("."))' | sort -Vu

@that-ben
Copy link
Author

that-ben commented May 18, 2025

The way this botnet works is that it will send more probes (from new IP addresses) whenever it finds that you blocked the previous ones. It's a chain system where each probe is queued. They send them sparingly, little by little, in a trickling manner. But when you block an IP, they will send another probe from a new IP. The more you block Stretchoid, the more you will receive new IP addresses from it.

All one has to do is to run a website or any public facing server and have some kind of cron job that reads the logs and blacklists Stretchoid's IP addresses in CSF firewall (or any other programmable firewall). Whenever you blacklist a Stretchoid IP, then over the course of 12 hours, you will receive another Stretchoid IP and then another one and then another one... After 5 IP from the same 24-bit subnet (0/24) I blacklist the whole subnet to increase the chances of getting probed by IP addresses from new subnets I've never seen before.

I've been "collecting" Microsoft Stretchoid IP addresses for 6 months now. Before that, they were using Digital Ocean's datacentres, but since last year, Microsoft saw an opportunity to even further prostitute themselves by leasing their unsold Azure IP space to Stretchoid. That's why I marked them as Microsoft, because before, they were labelled as Digital Ocean. You can say a big thanks to Microsoft for letting this happen and cashing in on it too! If you think Microsoft is there to protect you or your interests, think again. The sole reason they're in business is to make money. I've stopped using Microsoft products and services years ago and would never trust them with my personal information either, especially given the horrific, disastrous security holes legacy that has followed in almost every version of Windows so far, but anyway, I digress.

To answer your question, Stretchoid will generally scan for open ports and this is how I generally catch them. I suspect that it's reselling or sharing this information with a bunch of Azure servers, because vulnerability scanners often come from Azure shortly after (the same day or the day after) and they scan for THOUSANDS of known PHP filenames and try to inject SQL in various, often inexistent, URL on our server.

Note that if you do not block Stretchoid IP addresses, they will try again to scan a new port number almost every day. They usually go very slowly (between 1 to 10 ports per day per IP) in the hope of not getting caught.

Also to note: If your server uses multiple WAN facing addresses, Stretchoid will try all of them, not just IP addresses tied to a particular website or service on your server.

Here's an example of 2 new Stretchoid IP addresses that did a port scan on our server this afternoon. I'm not showing our IP addresses, but each of those screenshot contain 3 of our 5 public IP addresses:

Image Image

Stretchoid will also very briefly scan Apache servers, but rarely more than 2 or 3 requests and then it will just go silent for a day or more and probably try again. I think that they mainly do that to see if port 443 is open and to see how your 404 errors look like so they can sniff what web platform your server is using (Apache, NGINX, etc...) but I usually block them before they can come back so I'm not sure to what extent they would scan. All their requests are always obvious 404 nonsense. Example of an Apache request made by a Stretchoid IP:

135.233.97.43 - - [24/May/2025:09:44:43 -0400] "GET /developmentserver/metadatauploader HTTP/1.1" 404 196

@that-ben
Copy link
Author

that-ben commented May 24, 2025

A couple more new ones for you guys. Stay safe out there.

20.15.163.0/24 # 2025-05-23 - Microsoft (stretchoid.com)
20.15.164.0/24 # 2025-05-23 - Microsoft (stretchoid.com)
20.29.8.0/24 # 2025-05-24 - Microsoft (stretchoid.com)
20.29.19.0/24 # 2025-05-23 - Microsoft (stretchoid.com)
20.29.49.0/24 # 2025-05-23 - Microsoft (stretchoid.com)
20.29.56.0/24 # 2025-05-24 - Microsoft (stretchoid.com)
20.40.218.0/24 # 2025-05-17 - Microsoft (stretchoid.com)
20.40.250.0/24 # 2025-05-23 - Microsoft (stretchoid.com)
20.46.228.0/24 # 2025-05-24 - Microsoft (stretchoid.com)
20.62.194.0/24 # 2025-05-23 - Microsoft (stretchoid.com)
20.62.248.0/24 # 2025-05-23 - Microsoft (stretchoid.com)
20.80.105.0/24 # 2025-05-24 - Microsoft (stretchoid.com)
20.83.150.0/24 # 2025-05-23 - Microsoft (stretchoid.com)
20.83.185.0/24 # 2025-05-23 - Microsoft (stretchoid.com)
20.102.88.0/24 # 2025-05-23 - Microsoft (stretchoid.com)
20.106.32.0/24 # 2025-05-24 - Microsoft (stretchoid.com)
20.118.225.0/24 # 2025-05-24 - Microsoft (stretchoid.com)
20.118.240.0/24 # 2025-05-23 - Microsoft (stretchoid.com)
20.118.241.0/24 # 2025-05-23 - Microsoft (stretchoid.com)
20.119.74.0/24 # 2025-05-24 - Microsoft (stretchoid.com)
20.121.123.0/24 # 2025-05-21 - Microsoft (stretchoid.com)
20.127.195.0/24 # 2025-05-24 - Microsoft (stretchoid.com)
40.76.248.0/24 # 2025-05-17 - Microsoft (stretchoid.com)
40.90.248.0/24 # 2025-05-23 - Microsoft (stretchoid.com)
40.119.29.0/24 # 2025-05-24 - Microsoft (stretchoid.com)
48.217.82.0/24 # 2025-05-23 - Microsoft (stretchoid.com)
52.146.89.0/24 # 2025-05-21 - Microsoft (stretchoid.com)
52.188.191.0/24 # 2025-05-23 - Microsoft (stretchoid.com)
52.188.224.0/24 # 2025-05-24 - Microsoft (stretchoid.com)
130.131.161.0/24 # 2025-05-24 - Microsoft (stretchoid.com)
135.119.112.0/24 # 2025-05-17 - Microsoft (stretchoid.com)
135.233.97.0/24 # 2025-05-24 - Microsoft (stretchoid.com)
135.237.122.0/24 # 2025-05-24 - Microsoft (stretchoid.com)
138.91.105.0/24 # 2025-05-23 - Microsoft (stretchoid.com)
172.208.49.0/24 # 2025-05-22 - Microsoft (stretchoid.com)

For those interested, I also literally just stumbled upon the following list, which seems to actively be kept up to date and it looks like they already have all the IP addresses that I have ever been scanned from, so this is legit: https://github.com/MDMCK10/internet-scanners/blob/main/strechoid.nft

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
data-update Updates the data
Projects
None yet
Development

No branches or pull requests

3 participants