47 Networks, 68 Seconds
47 different chunks of the internet, each a full /24 block of up to 256 addresses, started scanning my infrastructure within 68 seconds of each other. 47 entire networks, most of them belonging to a single hosting provider. 6 months of logs turned up more than a dozen of these synchronized waves, and at least 3 of them weren't one-time events. The same operators came back days later and ran the exact same target list again, like clockwork.
Campaign overview
| Time window checked | March 8 to September 4, 2026 |
| Events that qualified | 13 |
| Biggest single wave | 51 networks, all starting within 38 seconds of each other (July 18, a one-off, see below) |
| Confirmed repeat target lists | 3, each reused 2 or 3 times, 6 to 35 hours apart |
| Networks (ASNs) involved | 25, across 6 countries, usually 1 clear leader per event |
| What's confirmed | tight timing, repeated target lists, near-full coverage of each /24 |
| What's not confirmed | whether each one is a botnet or a legitimate research scanner |
The main case: 47 networks in 68 seconds
On July 24, this pass touched between 220 and 254 of each network's 256 addresses, ran for almost the same length of time everywhere (5 hours, 5 to 16 minutes), at almost the same intensity (1.69 to 1.85 events per address per hour). 11,938 addresses, 125,761 events. 1 pass.
Almost all of it, 11,364 addresses, comes from 1 Turkish hosting network, NETFACTOR-ASN. 2 much smaller groups, 254 and 66 addresses, come from 2 other networks, small enough to probably be address space the same operator controls too, not a second attacker. The ranges aren't random: 31.169.64.0 through 31.169.95.0, 178.210.160.0 through 178.210.180.0, 131.222.216.0 through 131.222.228.0, back-to-back /24 blocks inside a few bigger ranges 1 provider owns. This looks like 1 operator working through almost an entire provider's address space, 1 /24 at a time, in under a minute.
The same scanning pattern came back 6 hours later
On July 25, the same 47 networks lit up again, minus 2, plus 6 new ones, 51 total. Still mostly NETFACTOR-ASN, 11,618 addresses this time, still near-full coverage everywhere, just slower: 140 seconds instead of 68.
45 of the original 47 came back unchanged. 2 didn't. 6 new /24s got added, including 1 Microsoft-registered block and 2 Hong Kong hosting providers, each a tiny handful of addresses next to NETFACTOR's share. Whatever builds this operator's target list isn't fixed. It gets reused roughly every 6 hours, with small edits each time.
Not always one provider
2 earlier events look different in an important way. On June 27, 16 /24 networks started within 16 seconds of each other, and the ones I could identify belong to 7 genuinely different hosting brands. Address counts are close enough across 5 of the 7 that no single brand dominates the way NETFACTOR does above.
Then on June 29, the exact same 16 networks lit up again, same 7 brands, same address counts down to the last digit. 2 confirmed passes, about 28 hours apart, against a list spanning 7 unrelated companies instead of 1 provider's own block.
A third case beats both on repetition. The same 21 /24 networks, all belonging to a Turkish operator called ONEMBILISIM, got hit 3 times across July 17 to 19, close to 35 hours apart every time. That's too consistent for coincidence, and not quite a clean 24-hour cycle either. Each pass starts within 9 to 18 seconds across all 21 networks, hitting the exact same list every time.
Walking through 1 provider's own block in order is one kind of automation, a scanner working a list step by step. Hitting 7 unrelated companies' scattered ranges within 16 seconds, then doing it again 28 hours later with the same list, is different. That list has to already exist, saved and reused rather than rebuilt. Whatever made it had done its research well before the first pass I can see, and kept the results.
Hosting infrastructure, cross-checked against Cloudflare Radar
Beyond timing, I checked how much traffic each network has sent me over the full 6 months, not just during the burst, to see whether its whole presence here is this one repeating behavior or a small part of something bigger. I also looked the same ASNs up on Cloudflare Radar to see who's actually registered behind each one and how big it really is. Then I grabbed what share of each network's overall traffic, over the last 7 days, Radar classifies as bot versus human. That last part isn't traffic to my infrastructure. It's each network's general footprint across the wider internet, but a useful independent check on what kind of network each one is.
| ASN | Provider (registered organization, per Radar) | Country | 6 months here | Bot share (Radar, 7 days) | Share that's this burst |
|---|---|---|---|---|---|
| AS56582 | NETFACTOR-ASN (Netfactor Telekomunikasyon ve Teknoloji Hizmetleri San. ve Tic. A.S.) | Turkey | 176,096 events, 11,659 IPs | 42.8% | Nearly all of it. Both passes together are close to every IP this network has ever sent me |
| AS207326 | HOSTLAB (HostLAB Bilisim Teknolojileri A.S.) | Turkey | 1,604,252 events, 1,524 IPs | 93.6% | Small slice. This operator sends far more traffic than just the June wave |
| AS47585 | YIGITHOSTING (Yigit Hosting Bilisim E-Ticaret Gida Sanayi Ticaret Limited Sirketi) | Turkey | 778,669 events, 1,016 IPs | 94.4% | Same pattern, most of its activity is unrelated to the wave |
| AS135377 | UCLOUD-HK (UCloud Information Technology, HK Limited) | Hong Kong | 605,220 events, 1,507 IPs | 93.1% | Small slice, 1 address showed up in the Jul 25 NETFACTOR pass |
| AS203114 | ETKINHOST (Eray Maden, trading as Etkin Host Bilisim ve Internet Hizmetleri) | Turkey | 268,535 events, 254 IPs | 84.5% | The 254 IPs from the June wave look like this operator's entire presence here |
| AS206668 | GAMINGVDS (Bayram Coskun, individual registration) | Turkey | 274,462 events, 508 IPs | 87.2% | The June wave's 254 addresses are about half this operator's total |
| AS200010 | VISLOM per my own lookup (Olfe Veri Merkezi Anonim Sirketi per Radar) | Turkey | 268,078 events, 255 IPs | 58.1% | Same shape, close to this operator's whole presence here |
| AS213407 | UZMANSOFT (Adem Celik, trading as Uzmansoft Bilisim Web Yazilim Hizmetleri) | Turkey | 205,511 events, 508 IPs | 55.6% | About half this operator's total |
| AS57844 | SPD-NET (SPDNet Telekomunikasyon Hizmetleri Bilgi Teknolojileri Taahhut Sanayi Ve Ticaret A.S.) | Turkey | 141,418 events, 6,858 IPs | 89.8% | The Jul 29 wave, 27 networks, is a small part of a much bigger, ongoing presence |
| AS213488 | INOXWEB (Mustafa Gunes, trading as Inoxweb Datacenter ve Hosting Bilisim Teknolojileri) | Turkey | 13,969 events, 254 IPs | 28.7% | Close to this operator's entire presence here |
| AS203545 | NERZEN-BILISIM-TEKNOLOJILERI (Savas Anac, individual registration) | Turkey | 4,962 events, 241 IPs | 75.0% | Most of this operator's activity is the Jul 18 wave |
| AS215238 | ONEMBILISIM (no company name on file) | Turkey | 2,134 events, 1,046 IPs | 57.0% | The 3 repeat passes make up most of this small presence |
| AS210529 | C2BILISIM (CE2 Bilgi Teknolojileri Ticaret Limited Sirketi) | Turkey | 1 event, 1 IP | 77.4% | The single address in the Jul 18 wave is the only time this network has ever shown up |
| AS43420 | ELTRONIK-AS (Eltronik Brodnica) | Poland | 1,776 events, 723 IPs | 11.6% | Most of this operator's activity is the Aug 27 wave |
| AS206991 | IXIR (Iksir Internet Hizmetleri A.S.) | Turkey | 7,752 events, 817 IPs | 54.2% | Most of this operator's activity is the Aug 26 wave |
| AS51540 | DALNET-ASN (Dal Bilgi Teknolojileri ve Bil Sis Tic A.S.) | Turkey | 3,242 events, 521 IPs | 76.5% | Most of this operator's activity is the Aug 26 wave |
| AS50467 | BESKID-MEDIA-AS (Beskid Media Sp. z o.o.) | Poland | 3,892 events, 1,163 IPs | 10.7% | The Aug 24 wave is a small part of a much bigger, ongoing presence |
| AS8075 | MICROSOFT-CORP-MSN-AS-BLOCK (Microsoft Corporation) | United States | 590,025 events, 5,132 IPs | 96.0% | 1 /24 in the Jul 25 NETFACTOR pass, tiny next to this ASN's total |
I used radar.cloudflare.com to get information about bot share percentages.
2 things stand out from the 6-month footprint side of this table. For operators like NETFACTOR, ETKINHOST, VISLOM, and C2BILISIM, the wave here is basically everything that network has ever done to my infrastructure, close to their whole personality. For HOSTLAB, YIGITHOSTING, UCLOUD-HK, SPD-NET, and BESKID-MEDIA-AS, though, it's a small, deliberate slice cut from a much bigger flow of normal traffic, pointing away from "this whole network is built for 1 scanning tool" and toward "someone with a much bigger fleet occasionally points part of it at a coordinated wave." The log type behind the biggest event counts here (HOSTLAB, NETFACTOR, GAMINGVDS) is almost all firewall-level connection logging, not full interactive sessions. Connection attempts, not completed logins.
A high bot share on the Radar side doesn't mean a network is running attacks. Hosting and VPS providers naturally skew bot-heavy since most of their addresses run unattended servers, not people at browsers, so a high number reads more as "infrastructure, not a residential ISP" than "malicious." It does support that networks like PEROVATE and DATAFON-ASN look, in their general traffic, exactly like their role in this post suggests: automated infrastructure, not end users. NETFACTOR itself, behind the biggest and most repeated wave in this post, comes back lower than expected, 42.8 percent bot against 57.2 percent human.
source: radar.cloudflare.com
2 more things changed how I'd describe the June 27 event. 4 of the 7 "different hosting brands," GAMINGVDS, NERZEN-BILISIM, UZMANSOFT, and INOXWEB, aren't registered to companies at all, they're individual people running one-person hosting resale businesses. That doesn't prove anything by itself, plenty of small resellers really are one person, but it softens the "7 unrelated companies" framing to "7 unrelated registrations, several of them individuals rather than firms," still real and unusual, just less corporate than it first looked.
The other thing is a naming mismatch. My own address lookup labeled AS200010 as VISLOM. Radar shows the registered organization as Olfe Veri Merkezi Anonim Sirketi, no mention of VISLOM at all, maybe a customer or brand on Olfe's network, maybe my own data is just out of date. Either way, an ASN's short display name and its actual registered owner aren't always the same thing, worth checking both before treating a name as an identity.
Where it's coming from
10 of the 13 qualifying events trace back to Turkish-registered networks as the main operator. 2 trace to Poland instead (BESKID-MEDIA-AS in August, ELTRONIK-AS at the end), a different provider and country than any of the Turkish-hosted cases. The last one is entirely unresolved in my own address lookup, a gap in my data, not proof the traffic came from nowhere.
That lean toward Turkish hosting brands, across 10 operators that don't otherwise look alike in their normal traffic, is worth noting on its own. It might reflect where this kind of scanning infrastructure tends to live, or just that my own address lookup works better for some regions than others. I can't fully tell those apart from this data.
Networks involved, for reference
Here is the full list of /24s from the 2 biggest passes, July 24 and July 25, 53 networks in total, in case anyone wants to check their own logs against the same list. You can also download it as a plain text file.
31.169.64.0/24 31.169.65.0/24 31.169.66.0/24 31.169.67.0/24
31.169.69.0/24 31.169.70.0/24 31.169.71.0/24 31.169.72.0/24
31.169.74.0/24 31.169.76.0/24 31.169.77.0/24 31.169.78.0/24
31.169.79.0/24 31.169.80.0/24 31.169.81.0/24 31.169.82.0/24
31.169.84.0/24 31.169.85.0/24 31.169.87.0/24 31.169.90.0/24
31.169.92.0/24 31.169.93.0/24 31.169.94.0/24 31.169.95.0/24
45.74.176.0/24 46.235.14.0/24 46.247.61.0/24 64.62.156.0/24
80.245.47.0/24 91.102.161.0/24 131.222.216.0/24 131.222.217.0/24
131.222.218.0/24 131.222.219.0/24 131.222.227.0/24 131.222.228.0/24
135.237.126.0/24 165.154.163.0/24 178.210.160.0/24 178.210.170.0/24
178.210.171.0/24 178.210.172.0/24 178.210.173.0/24 178.210.174.0/24
178.210.175.0/24 178.210.176.0/24 178.210.177.0/24 178.210.178.0/24
178.210.180.0/24 185.33.63.0/24 193.46.0.0/24 212.87.196.0/24
217.70.11.0/24
Personal take-aways
This is where the wide view matters most. Looking at any single spike on its own, even a striking one, leaves room for doubt. 47 networks starting within a minute of each other could, in theory, be some coincidence in how a handful of unrelated operators happened to schedule their scans. That argument gets weaker every time the same shape shows up again, from a different operator, on a different date, with nothing obvious connecting it to the last one. NETFACTOR, ONEMBILISIM, 7 separate hosting brands, spread across 6 months and several countries. 1 spike like that might be coincidence. A dozen of them, from networks that share nothing else in common, stop looking like coincidence.
Comments
Reply on this Mastodon post to join the discussion.






