Just blocked 141.138.130.0/24 and 141.138.131/24 on my firewall because suspicious port scanning @WillHillBet
Posted by jpluimers on 2016/11/02
I just blocked these IP subnets on my routers:
- 141.138.130.0/24
- 141.138.131.0/24
Within a day they managed to get 80+ IP addresses from these subnets into my port-scanner blacklists because of suspicious port scanning activities.
They all belong to William Hill Organization Ltd, United Kingdom.
- [WayBack] 141.138.130.0 – 141.138.130.63 – IP Whois | Myip.ms
- [WayBack] 141.138.130.64 – 141.138.130.255 – Ip Address Lookup Location – William Hill Organization Ltd
- [WayBack] 141.138.131.0 – 141.138.131.255 Whois
If the situation continues I’m going to block the superblock as well:
–jeroen






Pete said
We’ve seen this too and have blocked the entire /21. It is part of a DDoS against William Hill: http://www.theregister.co.uk/2016/11/02/william_hill_ddos/
jpluimers said
Thanks!
–jeroen
Just blocked 95.131.[184|185|186|190|191].0/24 on my firewall because suspicious port scanning @WillHillBet « The Wiert Corner – irregular stream of stuff said
[…] IL on Just blocked 141.138.130.0/24… […]
IL said
Actually whole block is 141.138.128.0/21 ( 141.138.128.0 – 141.138.135.255 )
https://myip.ms/view/ip_owners/556769/William_Hill_Organization_Ltd.html
jpluimers said
The rest of the block didn’t post-scan yet.