New ASN to block. But again, the firewall vendors don't give a fuck about your feature requests so you'll have to block the networks instead.

Silent Push reports that there has been a migration from the OFAC sanctioned Aeza Group's AS210644 to AS211522 which is listed as operated by Hypercore, Ltd.

https://www.silentpush.com/news/iofa-detects-aeza-group-infrastructure/

Here are the networks in AS211522 that you may want to block:

83.147.216.0/24
91.186.216.0/22
91.186.212.0/23
83.147.222.0/24
83.147.192.0/24
83.147.254.0/24
83.147.252.0/23
150.241.64.0/19
178.253.55.0/24

#threatIntel

Silent Push IOFA™ Feed Detects Aeza Group Infrastructure Shift Following OFAC Sanctions

On July 1, 2025, the U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC) designated Aeza Group, two affiliated companies, and four individuals for providing bulletproof hosting services that enabled global cybercriminal activity — including ransomware operations, data theft, and darknet drug trafficking. Bulletproof hosting (BPH) refers to resilient server infrastructure used by […]

Silent Push
@cR0w @neurovagrant ipsetmgr —command asnsetentry —asn 210644 —setname asnblock—apply 211522
@QuatermassTools @neurovagrant Not available in most enterprise firewalls, I'm afraid. But yeah, that's the idea.

@cR0w @neurovagrant i don’t actually have any enterprise firewalls fortunately, just tin in a data centre with my own tools to keep things under control. Ipsetmgr is just the tool I was driven to write this year to help me deal with the additional load of the malware ai crawler shite.

https://code.quatermass.co.uk/toolsmith/perl-App-IPSetMgr

Next up, writing a new consumer module to integrate with a brand new user-space library/tool for live application lookups, https://code.quatermass.co.uk/jgh/nmh

perl-App-IPSetMgr

General IP Set Manager

Code From The Pit
@QuatermassTools @neurovagrant Oh nice. Right one. That sounds like a cool project.
@cR0w And the upstreams are... Aeza! wow, such move
@astraleureka "Don't block us, we're technically not sanctioned."