ufwで不審なアクセスをブロック

Nid: 917

piwik にて USの204.79.180.* からIPアドレスを変えながら多数のページアクセスを確認。誰なの?

$ whois 204.79.180.0 | grep -v '^#' | grep .
NetRange:       204.79.180.0 - 204.79.180.255
CIDR:           204.79.180.0/24
NetName:        DRAKE-HOLDINGS
NetHandle:      NET-204-79-180-0-1
Parent:         NET204 (NET-204-0-0-0-0)
NetType:        Direct Assignment
OriginAS:
Organization:   Drake Holdings LLC (MC-938)
RegDate:        1994-12-14
Updated:        2015-10-28
Ref:            https://whois.arin.net/rest/net/NET-204-79-180-0-1
OrgName:        Drake Holdings LLC
OrgId:          MC-938
Address:        2215-B Renaissance Drive
City:           Las Vegas
StateProv:      NV
PostalCode:     89119
Country:        US
RegDate:        2014-12-15
Updated:        2017-01-28
Ref:            https://whois.arin.net/rest/org/MC-938
OrgTechHandle: ADMIN5512-ARIN
OrgTechName:   Administrator
OrgTechPhone:  +1-702-605-0237
OrgTechEmail:  drakeholdings@cyberservices.com
OrgTechRef:    https://whois.arin.net/rest/poc/ADMIN5512-ARIN
OrgAbuseHandle: ADMIN5512-ARIN
OrgAbuseName:   Administrator
OrgAbusePhone:  +1-702-605-0237
OrgAbuseEmail:  drakeholdings@cyberservices.com
OrgAbuseRef:    https://whois.arin.net/rest/poc/ADMIN5512-ARIN

ググって情報確認。https://www.webmasterworld.com/search_engine_spiders/4777875-2-30.htm

ネットワークごとBlockします。

$ sudo ufw deny from 204.79.180.0/24 comment 'block Drake Holdings LLC'
$ sudo ufw status verbose