WOW thank you for the above!!!
I've been doing my own research on AP2P spybot networks.
I've had genuine interactions with FOUR different AntiP2P botnets which are snooping from these networks:
1) AWS Global
2) Contabo Germany
3) SoftLayer 'DTEC' USA
4) Fasthosts UK
This is NOT extensive but JUST ones I have personally experienced. This is why I need Tixati IP FILTER to match to torrents and specific banned IP's.
At the moment Tixati does not do this so difficult to maintain precise lists.
I've been using other tools to log interaction data but its killing my computer resources.
Anyway if anyone is interested... these Anti-P2P botnets are set up listening on the following /24's
AWS
Still under investigation - just block the entire lot.
EC2's have PATHETIC bandwidth allowances so useless for torrenting so presuming they're all fake clients.
Contabo AntiP2P Germany:
AntiP2P SNOOPING BOXES 'identifying' as MonoTorrent - this setup is utterly laughable. Poor understanding of P2P.
A=MONOTORRENT FAKED CLIENT
B=DIFFERENT AP2P NETWORK
CONTABO_A:167.86.70.0-167.86.70.255 # 90% ADULT CONTENT 10% RUBBISH MOVIES
CONTABO_A:173.249.44.0-173.249.44.255 # 80% ADULT CONTENT 20% RUBBISH MOVIES
CONTABO_B:213.136.79.0-213.136.79.255 # ENGLISH SPEAKING MOVIES AND TV
DTEC/SoftLayer AntiP2P: (American TV)
AntiP2P SNOOPING BOXES 'identifying' as libtorrent/1.1.9.0
This bizarre AP2P is constantly interfering with my setup. They write extremely bad code.
SoftLayer:169.60.48.0/24 # EXTENSIVE USA MUSIC, GAMES, WRESTLING
SoftLayer:169.61.218.0/24 # EXTENSIVE USA MUSIC, GAMES, MOVIES
SoftLayer:169.63.200.0/24 # EXTENSIVE USA MUSIC, GAMES, MOVIES
FASTHOSTS UK AntiP2P SNOOPING BOXES 'identifying' as Deluge 1.3.6
FH:77.68.37.0/24 # GENERIC MONITORING (EXTENSIVE AMERICAN ONLY CONTENT)
FH:77.68.40.0/24 # GENERIC MONITORING (LOW TRAFFIC AMERICAN SPORT PPV KICKBOXING)
FH:77.68.41.0/24 # GENERIC MONITORING (EXTENSIVE AMERICAN ONLY CONTENT)
FH:77.68.42.0/24 # PRECISION MONITORING SPECIFIC TITLE
FH:77.68.43.0/24 # PRECISION MONITORING SPECIFIC TITLE
FH:77.68.51.0/24 # PRECISION MONITORING SPECIFIC TITLE
FH:88.208.201.0/24 # EXTREMELY ACTIVE AMERICAN TV+MOVIES
FH:88.208.218.0/24 # EXTREMELY ACTIVE AMERICAN TV+MOVIES
FH:88.208.228.0/24 # EXTREMELY ACTIVE AMERICAN TV+MOVIES
FH:88.208.202.0/24 # EXTREMELY ACTIVE AMERICAN TV BOX SETS
FH:88.208.203.0/24 # EXTREMELY ACTIVE AMERICAN TV BOX SETS
FH:88.208.205.0/24 # QUIET FOREIGN LANGUAGE AND CRACKED APPS
FH:88.208.206.0/24 # QUIET FOREIGN LANGUAGE
FH:88.208.208.0/24 # EXTREMELY ACTIVE AMERICAN TV+MOVIES
FH:88.208.209.0/24 # GENERIC MONITORING (LOW TRAFFIC AMERICAN SPORT PPV KICKBOXING)
FH:88.208.217.0/24 # EXTREMELY ACTIVE AMERICAN TV+MOVIES
FH:88.208.221.0/24 # QUIET FOREIGN LANGUAGE AND CRACKED APPS
FH:88.208.229.0/24 # GENERIC MONITORING (EXTENSIVE AMERICAN ONLY CONTENT)
FH:88.208.244.0/24 # VERY LOW TRAFFIC UNKNOWN TV
FH:88.208.245.0/24 # EXTREMELY ACTIVE AMERICAN TV+MOVIES
FH:88.208.246.0/24 # EXTREMELY ACTIVE AMERICAN TV+MOVIES
These are only P2P bots that I have 'caught' using my current setup.
I could spend more time on this but these are so BAD they are screaming to be identified.