Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. An individual, Zhenyun Sun (https://find-and-update.company-information.service.gov.uk/officers/svz68usL11Hfb5q2_65DDqlFd2Y/appointments), is registering UK "fibre ISPs" at Companies House at an unusual rate.

An individual, Zhenyun Sun (https://find-and-update.company-information.service.gov.uk/officers/svz68usL11Hfb5q2_65DDqlFd2Y/appointments), is registering UK "fibre ISPs" at Companies House at an unusual rate.

Scheduled Pinned Locked Moved Uncategorized
3 Posts 1 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • spamhaus@infosec.exchangeS This user is from outside of this forum
    spamhaus@infosec.exchangeS This user is from outside of this forum
    spamhaus@infosec.exchange
    wrote last edited by
    #1

    An individual, Zhenyun Sun (https://find-and-update.company-information.service.gov.uk/officers/svz68usL11Hfb5q2_65DDqlFd2Y/appointments), is registering UK "fibre ISPs" at Companies House at an unusual rate. On the surface, they could pass for legitimate broadband providers. But look closer, and the picture soon changes 🕵️ ...

    Some of these companies are assigned an ASN, sharing the same abuse contact: onesproxy[.]com. ⤵️

    spamhaus@infosec.exchangeS 1 Reply Last reply
    1
    0
    • spamhaus@infosec.exchangeS spamhaus@infosec.exchange

      This same company markets itself as a Chinese provider of "residential proxies." These ASNs are registered at RIPE (@ripencc) as assigned to ISPs delivering fibre to UK homes.

      One explanation is that this makes proxy traffic appear to originate from genuine residential broadband customers. But it may not necessarily be for malicious purposes. It could be targeting SEO and those who want to "cheat the system" by simulating traffic from a large pool of users for marketing. ⤵️

      spamhaus@infosec.exchangeS This user is from outside of this forum
      spamhaus@infosec.exchangeS This user is from outside of this forum
      spamhaus@infosec.exchange
      wrote last edited by
      #2

      For anyone actually trying to buy internet service from this list of providers? Good luck! We haven't observed abuse traffic emanating from these ASNs yet. But the infrastructure suggests this one is one to keep an eye on! 👀

      1 Reply Last reply
      1
      0
      • spamhaus@infosec.exchangeS spamhaus@infosec.exchange

        An individual, Zhenyun Sun (https://find-and-update.company-information.service.gov.uk/officers/svz68usL11Hfb5q2_65DDqlFd2Y/appointments), is registering UK "fibre ISPs" at Companies House at an unusual rate. On the surface, they could pass for legitimate broadband providers. But look closer, and the picture soon changes 🕵️ ...

        Some of these companies are assigned an ASN, sharing the same abuse contact: onesproxy[.]com. ⤵️

        spamhaus@infosec.exchangeS This user is from outside of this forum
        spamhaus@infosec.exchangeS This user is from outside of this forum
        spamhaus@infosec.exchange
        wrote last edited by
        #3

        This same company markets itself as a Chinese provider of "residential proxies." These ASNs are registered at RIPE (@ripencc) as assigned to ISPs delivering fibre to UK homes.

        One explanation is that this makes proxy traffic appear to originate from genuine residential broadband customers. But it may not necessarily be for malicious purposes. It could be targeting SEO and those who want to "cheat the system" by simulating traffic from a large pool of users for marketing. ⤵️

        spamhaus@infosec.exchangeS 1 Reply Last reply
        1
        0
        • R relay@relay.infosec.exchange shared this topic
        Reply
        • Reply as topic
        Log in to reply
        • Oldest to Newest
        • Newest to Oldest
        • Most Votes


        • Login

        • Login or register to search.
        • First post
          Last post
        0
        • Categories
        • Recent
        • Tags
        • Popular
        • World
        • Users
        • Groups