Skip to content

47 Networks, 68 Seconds

47 different chunks of the internet, each a full /24 block of up to 256 addresses, started scanning my infrastructure within 68 seconds of each other. 47 entire networks, most of them belonging to a single hosting provider. 6 months of logs turned up more than a dozen of these synchronized waves, and at least 3 of them weren't one-time events. The same operators came back days later and ran the exact same target list again, like clockwork.

Every synchronized wave in order, from June to August, with the 3 repeat operators connected by a dashed line and bubble size showing how many networks were hit in each pass

Campaign overview

Time window checked March 8 to September 4, 2026
Events that qualified 13
Biggest single wave 51 networks, all starting within 38 seconds of each other (July 18, a one-off, see below)
Confirmed repeat target lists 3, each reused 2 or 3 times, 6 to 35 hours apart
Networks (ASNs) involved 25, across 6 countries, usually 1 clear leader per event
What's confirmed tight timing, repeated target lists, near-full coverage of each /24
What's not confirmed whether each one is a botnet or a legitimate research scanner

The main case: 47 networks in 68 seconds

On July 24, this pass touched between 220 and 254 of each network's 256 addresses, ran for almost the same length of time everywhere (5 hours, 5 to 16 minutes), at almost the same intensity (1.69 to 1.85 events per address per hour). 11,938 addresses, 125,761 events. 1 pass.

47 different /24 networks started their scan within 68 seconds of each other, plotted as seconds elapsed since the first one began

Almost all of it, 11,364 addresses, comes from 1 Turkish hosting network, NETFACTOR-ASN. 2 much smaller groups, 254 and 66 addresses, come from 2 other networks, small enough to probably be address space the same operator controls too, not a second attacker. The ranges aren't random: 31.169.64.0 through 31.169.95.0, 178.210.160.0 through 178.210.180.0, 131.222.216.0 through 131.222.228.0, back-to-back /24 blocks inside a few bigger ranges 1 provider owns. This looks like 1 operator working through almost an entire provider's address space, 1 /24 at a time, in under a minute.

The same scanning pattern came back 6 hours later

On July 25, the same 47 networks lit up again, minus 2, plus 6 new ones, 51 total. Still mostly NETFACTOR-ASN, 11,618 addresses this time, still near-full coverage everywhere, just slower: 140 seconds instead of 68.

45 of the original 47 came back unchanged. 2 didn't. 6 new /24s got added, including 1 Microsoft-registered block and 2 Hong Kong hosting providers, each a tiny handful of addresses next to NETFACTOR's share. Whatever builds this operator's target list isn't fixed. It gets reused roughly every 6 hours, with small edits each time.

Address share of every network that appeared in either the Jul 24 or Jul 25 NETFACTOR pass, log scale because the gap between the dominant player and everyone else is enormous

Not always one provider

2 earlier events look different in an important way. On June 27, 16 /24 networks started within 16 seconds of each other, and the ones I could identify belong to 7 genuinely different hosting brands. Address counts are close enough across 5 of the 7 that no single brand dominates the way NETFACTOR does above.

Then on June 29, the exact same 16 networks lit up again, same 7 brands, same address counts down to the last digit. 2 confirmed passes, about 28 hours apart, against a list spanning 7 unrelated companies instead of 1 provider's own block.

A third case beats both on repetition. The same 21 /24 networks, all belonging to a Turkish operator called ONEMBILISIM, got hit 3 times across July 17 to 19, close to 35 hours apart every time. That's too consistent for coincidence, and not quite a clean 24-hour cycle either. Each pass starts within 9 to 18 seconds across all 21 networks, hitting the exact same list every time.

How long between repeat passes against the identical target list, for the 3 confirmed repeat operators

Every synchronized wave found across 6 months, with the 3 repeating target lists connected by a dashed line

Walking through 1 provider's own block in order is one kind of automation, a scanner working a list step by step. Hitting 7 unrelated companies' scattered ranges within 16 seconds, then doing it again 28 hours later with the same list, is different. That list has to already exist, saved and reused rather than rebuilt. Whatever made it had done its research well before the first pass I can see, and kept the results.

Hosting infrastructure, cross-checked against Cloudflare Radar

Beyond timing, I checked how much traffic each network has sent me over the full 6 months, not just during the burst, to see whether its whole presence here is this one repeating behavior or a small part of something bigger. I also looked the same ASNs up on Cloudflare Radar to see who's actually registered behind each one and how big it really is. Then I grabbed what share of each network's overall traffic, over the last 7 days, Radar classifies as bot versus human. That last part isn't traffic to my infrastructure. It's each network's general footprint across the wider internet, but a useful independent check on what kind of network each one is.

ASN Provider (registered organization, per Radar) Country 6 months here Bot share (Radar, 7 days) Share that's this burst
AS56582 NETFACTOR-ASN (Netfactor Telekomunikasyon ve Teknoloji Hizmetleri San. ve Tic. A.S.) Turkey 176,096 events, 11,659 IPs 42.8% Nearly all of it. Both passes together are close to every IP this network has ever sent me
AS207326 HOSTLAB (HostLAB Bilisim Teknolojileri A.S.) Turkey 1,604,252 events, 1,524 IPs 93.6% Small slice. This operator sends far more traffic than just the June wave
AS47585 YIGITHOSTING (Yigit Hosting Bilisim E-Ticaret Gida Sanayi Ticaret Limited Sirketi) Turkey 778,669 events, 1,016 IPs 94.4% Same pattern, most of its activity is unrelated to the wave
AS135377 UCLOUD-HK (UCloud Information Technology, HK Limited) Hong Kong 605,220 events, 1,507 IPs 93.1% Small slice, 1 address showed up in the Jul 25 NETFACTOR pass
AS203114 ETKINHOST (Eray Maden, trading as Etkin Host Bilisim ve Internet Hizmetleri) Turkey 268,535 events, 254 IPs 84.5% The 254 IPs from the June wave look like this operator's entire presence here
AS206668 GAMINGVDS (Bayram Coskun, individual registration) Turkey 274,462 events, 508 IPs 87.2% The June wave's 254 addresses are about half this operator's total
AS200010 VISLOM per my own lookup (Olfe Veri Merkezi Anonim Sirketi per Radar) Turkey 268,078 events, 255 IPs 58.1% Same shape, close to this operator's whole presence here
AS213407 UZMANSOFT (Adem Celik, trading as Uzmansoft Bilisim Web Yazilim Hizmetleri) Turkey 205,511 events, 508 IPs 55.6% About half this operator's total
AS57844 SPD-NET (SPDNet Telekomunikasyon Hizmetleri Bilgi Teknolojileri Taahhut Sanayi Ve Ticaret A.S.) Turkey 141,418 events, 6,858 IPs 89.8% The Jul 29 wave, 27 networks, is a small part of a much bigger, ongoing presence
AS213488 INOXWEB (Mustafa Gunes, trading as Inoxweb Datacenter ve Hosting Bilisim Teknolojileri) Turkey 13,969 events, 254 IPs 28.7% Close to this operator's entire presence here
AS203545 NERZEN-BILISIM-TEKNOLOJILERI (Savas Anac, individual registration) Turkey 4,962 events, 241 IPs 75.0% Most of this operator's activity is the Jul 18 wave
AS215238 ONEMBILISIM (no company name on file) Turkey 2,134 events, 1,046 IPs 57.0% The 3 repeat passes make up most of this small presence
AS210529 C2BILISIM (CE2 Bilgi Teknolojileri Ticaret Limited Sirketi) Turkey 1 event, 1 IP 77.4% The single address in the Jul 18 wave is the only time this network has ever shown up
AS43420 ELTRONIK-AS (Eltronik Brodnica) Poland 1,776 events, 723 IPs 11.6% Most of this operator's activity is the Aug 27 wave
AS206991 IXIR (Iksir Internet Hizmetleri A.S.) Turkey 7,752 events, 817 IPs 54.2% Most of this operator's activity is the Aug 26 wave
AS51540 DALNET-ASN (Dal Bilgi Teknolojileri ve Bil Sis Tic A.S.) Turkey 3,242 events, 521 IPs 76.5% Most of this operator's activity is the Aug 26 wave
AS50467 BESKID-MEDIA-AS (Beskid Media Sp. z o.o.) Poland 3,892 events, 1,163 IPs 10.7% The Aug 24 wave is a small part of a much bigger, ongoing presence
AS8075 MICROSOFT-CORP-MSN-AS-BLOCK (Microsoft Corporation) United States 590,025 events, 5,132 IPs 96.0% 1 /24 in the Jul 25 NETFACTOR pass, tiny next to this ASN's total

I used radar.cloudflare.com to get information about bot share percentages.

2 things stand out from the 6-month footprint side of this table. For operators like NETFACTOR, ETKINHOST, VISLOM, and C2BILISIM, the wave here is basically everything that network has ever done to my infrastructure, close to their whole personality. For HOSTLAB, YIGITHOSTING, UCLOUD-HK, SPD-NET, and BESKID-MEDIA-AS, though, it's a small, deliberate slice cut from a much bigger flow of normal traffic, pointing away from "this whole network is built for 1 scanning tool" and toward "someone with a much bigger fleet occasionally points part of it at a coordinated wave." The log type behind the biggest event counts here (HOSTLAB, NETFACTOR, GAMINGVDS) is almost all firewall-level connection logging, not full interactive sessions. Connection attempts, not completed logins.

A high bot share on the Radar side doesn't mean a network is running attacks. Hosting and VPS providers naturally skew bot-heavy since most of their addresses run unattended servers, not people at browsers, so a high number reads more as "infrastructure, not a residential ISP" than "malicious." It does support that networks like PEROVATE and DATAFON-ASN look, in their general traffic, exactly like their role in this post suggests: automated infrastructure, not end users. NETFACTOR itself, behind the biggest and most repeated wave in this post, comes back lower than expected, 42.8 percent bot against 57.2 percent human.

Bot versus human share of each ASN's overall HTTP traffic, per Cloudflare Radar, last 7 days

source: radar.cloudflare.com

2 more things changed how I'd describe the June 27 event. 4 of the 7 "different hosting brands," GAMINGVDS, NERZEN-BILISIM, UZMANSOFT, and INOXWEB, aren't registered to companies at all, they're individual people running one-person hosting resale businesses. That doesn't prove anything by itself, plenty of small resellers really are one person, but it softens the "7 unrelated companies" framing to "7 unrelated registrations, several of them individuals rather than firms," still real and unusual, just less corporate than it first looked.

The other thing is a naming mismatch. My own address lookup labeled AS200010 as VISLOM. Radar shows the registered organization as Olfe Veri Merkezi Anonim Sirketi, no mention of VISLOM at all, maybe a customer or brand on Olfe's network, maybe my own data is just out of date. Either way, an ASN's short display name and its actual registered owner aren't always the same thing, worth checking both before treating a name as an identity.

Where it's coming from

Where the synchronized waves trace back to, by dominant network operator, counted in networks hit and grouped by country

10 of the 13 qualifying events trace back to Turkish-registered networks as the main operator. 2 trace to Poland instead (BESKID-MEDIA-AS in August, ELTRONIK-AS at the end), a different provider and country than any of the Turkish-hosted cases. The last one is entirely unresolved in my own address lookup, a gap in my data, not proof the traffic came from nowhere.

That lean toward Turkish hosting brands, across 10 operators that don't otherwise look alike in their normal traffic, is worth noting on its own. It might reflect where this kind of scanning infrastructure tends to live, or just that my own address lookup works better for some regions than others. I can't fully tell those apart from this data.

Networks involved, for reference

Here is the full list of /24s from the 2 biggest passes, July 24 and July 25, 53 networks in total, in case anyone wants to check their own logs against the same list. You can also download it as a plain text file.

31.169.64.0/24   31.169.65.0/24   31.169.66.0/24   31.169.67.0/24
31.169.69.0/24   31.169.70.0/24   31.169.71.0/24   31.169.72.0/24
31.169.74.0/24   31.169.76.0/24   31.169.77.0/24   31.169.78.0/24
31.169.79.0/24   31.169.80.0/24   31.169.81.0/24   31.169.82.0/24
31.169.84.0/24   31.169.85.0/24   31.169.87.0/24   31.169.90.0/24
31.169.92.0/24   31.169.93.0/24   31.169.94.0/24   31.169.95.0/24
45.74.176.0/24   46.235.14.0/24   46.247.61.0/24   64.62.156.0/24
80.245.47.0/24   91.102.161.0/24  131.222.216.0/24 131.222.217.0/24
131.222.218.0/24 131.222.219.0/24 131.222.227.0/24 131.222.228.0/24
135.237.126.0/24 165.154.163.0/24 178.210.160.0/24 178.210.170.0/24
178.210.171.0/24 178.210.172.0/24 178.210.173.0/24 178.210.174.0/24
178.210.175.0/24 178.210.176.0/24 178.210.177.0/24 178.210.178.0/24
178.210.180.0/24 185.33.63.0/24   193.46.0.0/24    212.87.196.0/24
217.70.11.0/24

Personal take-aways

This is where the wide view matters most. Looking at any single spike on its own, even a striking one, leaves room for doubt. 47 networks starting within a minute of each other could, in theory, be some coincidence in how a handful of unrelated operators happened to schedule their scans. That argument gets weaker every time the same shape shows up again, from a different operator, on a different date, with nothing obvious connecting it to the last one. NETFACTOR, ONEMBILISIM, 7 separate hosting brands, spread across 6 months and several countries. 1 spike like that might be coincidence. A dozen of them, from networks that share nothing else in common, stop looking like coincidence.

Comments

Reply on this Mastodon post to join the discussion.