<span id="hs_cos_wrapper_post_body" class="hs_cos_wrapper hs_cos_wrapper_meta_field hs_cos_wrapper_type_rich_text" style="" data-hs-cos-general-type="meta_field" data-hs-cos-type="rich_text" ><p><span>ChinaNet (AS 4134) is not just another autonomous system. It's China’s national internet backbone, and has the most users and widest coverage of any public internet network in the country. The telecommunications operator is also known for "facilitating communications between Western and Chinese subscribers" (China Telecom Americas). Well, for such a big and important chunk of the internet, the amount of abuse on there is just too large.</span><span></span></p> <p><span><!--more-->Based on <a href="https://cleantalk.org/blacklists/as4134" rel="noopener" target="_blank">CleanTalk's reputation data</a>, almost 30% of IPs on the ChinaNet AS are spam sources:</span></p> <p><span><img src="https://www.threatstop.com/hubfs/as4134_spam.png" alt="as4134_spam" width="1138" loading="lazy" style="width: 1138px;"></span></p> <p>Specifically, the IP 14.135.120[.]19 is a star in our log monitoring sensors. It has been continuously blocked by ThreatSTOP while trying to communicate with our customers' networks. A quick <a href="https://check-ioc.threatstop.com/ioc/14.135.120.19" rel="noopener" target="_blank">CheckIOC </a>search shows that this IP has been a plethora of targets over the last 3 years!</p> <p><img src="https://www.threatstop.com/hubfs/chinanet_ip_targets.png" alt="chinanet_ip_targets" width="1104" loading="lazy" style="width: 1104px;"></p> <p>This list shows everything from SSH and IMAP attacks, to botnets, to broader "these IPs are the worst" lists. Currently, 14.135.120[.]19 is in our CINS Army and Dataplane threat targets, as well as our China Geo target (full target descriptions are at the bottom of this post). Its neighboring IPs, 14.135.120[.]18, 14.135.120[.]20, and 14.135.120[.]21 are also in on the cyber attack business, boasting a malicious reputation on <a href="https://www.virustotal.com/gui/home/upload" rel="noopener" target="_blank">VirusTotal</a>.</p> <p><img src="https://www.threatstop.com/hubfs/virustotal_chinanet.png" alt="virustotal_chinanet" width="1679" loading="lazy" style="width: 1679px;"></p> <p style="direction: ltr;">Our team highly recommends blocking traffic to and from the malicious IPs listed in this post. ThreatSTOP's security solutions are being updated every minute with the most up to date threat intelligence, including bad areas of the internet such as this one, to protect our users from cyber attacks across the whole threat landscape.</p> <p style="direction: ltr;">&nbsp;</p> <div> <div> <div> <div> <p><em>Ready to try ThreatSTOP in your network? Want an expert-led demo to see how it works?</em></p> </div> </div> </div> </div> <aside> <div></div> <div></div> </aside></span>