We have gotten a few emails from these folks in the past day. They indicate the following IPs are problematic:
- 208.80.155.143
- 208.80.155.178
Some views of this reports:
https://www.webiron.com/abuse_feed/abuse@wmflabs.org
https://www.webiron.com/iplookup/208.80.155.178
https://www.webiron.com/abuse_feed/208.80.155.143
Unwanted and or Abusive Web Requests: Offending/Source IP: 208.80.155.143 - Issue: Source has attempted the following botnet activity: Orphan Malware Scanner - Block Type: New Ban - Time: 2017-01-23 13:02:12-07:00 - Port: 80 - Service: http - Report ID: 3142fba8-e198-41a2-a99f-023d2d3cc5a6 - Bot Fingerprint: 1332903b7e59e47342fcd6c65b8b7858 - Bot Information: https://www.webiron.com/bot_lookup/1332903b7e59e47342fcd6c65b8b7858 - Bot Node Feed: https://www.webiron.com/bot_feed/1332903b7e59e47342fcd6c65b8b7858 - Abused Range: 45.79.136.0/24 - Requested URI: /about/ - User-Agent: COIParser/2.0
- Time: 2017-01-23 14:16:59-07:00 - Port: 80 - Service: http - Report ID: cfa4e4db-a20a-49e8-93f9-e745dcbc6bef - Bot Fingerprint: 1332903b7e59e47342fcd6c65b8b7858 - Bot Information: https://www.webiron.com/bot_lookup/1332903b7e59e47342fcd6c65b8b7858 - Bot Node Feed: https://www.webiron.com/bot_feed/1332903b7e59e47342fcd6c65b8b7858 - Abused Range: 50.116.5.0/24 - Requested URI: / - User-Agent: COIParser/2.0
- Time: 2017-01-23 14:16:59-07:00 - Port: 80 - Service: http - Report ID: cfa4e4db-a20a-49e8-93f9-e745dcbc6bef - Bot Fingerprint: 1332903b7e59e47342fcd6c65b8b7858 - Bot Information: https://www.webiron.com/bot_lookup/1332903b7e59e47342fcd6c65b8b7858 - Bot Node Feed: https://www.webiron.com/bot_feed/1332903b7e59e47342fcd6c65b8b7858 - Abused Range: 50.116.5.0/24 - Requested URI: / - User-Agent: COIParser/2.0
All the activity I see them reporting I can track back to coibot and linkwatcher https://wikitech.wikimedia.org/wiki/Nova_Resource:Tools/Access_Request/Beetstra that is run by @Beetstra.
The nodes in question (each exec node in Tools has it's own external IP):
79a41ff1-de61-4061-a4b0-7cd1d25d658f tools-exec-1403 ACTIVE public=10.68.17.239, 208.80.155.143 f284b92f-3e86-4127-bdd1-d7e32bb65809 tools-exec-1411 ACTIVE public=10.68.17.209, 208.80.155.178
I can see the expected bots running:
557434 0.35652 coibot tools.coibot r 12/01/2016 05:03:23 continuous MASTER
I see where the user is setting an appropriate (and reported user-agent):
/data/project/coibot
data/project/coibot# grep -Ri COIParser *
Parser.pl:$diffFetcher->agent("COIParser/2.0");
/data/project/linkwatcher
linkwatcher.pm: my $agent = shift || 'LinkWatcher'; #user-specified agent or default to 'LinkWatcher'
My thought at the moment is these reports are not identifying whatever Orphan Malware Scanner is.