Realtime Prefix Hijacking Alarms

  • Home/
  • Hijackings/
  • About/
NEWS: (2020-09-04) We now switch to RIPE RIS for BGP live data access, for BGPmon.io is now unavailable!

Hijacking Alarm Information

Time (UTC) IP Prefix CC Suspicious Origin AS Alarm Delay (s) Alarm Lasts (s) Avg Fing. [.6, 1]
11-12-27 03:43:43 166.111.111.0/24 +1 CN Origin changes from AS4538 to AS23910 0 11 0.76

BGP UPDATEs of 166.111.111.0/24 (from BGPmon)

Δ t Timestamp Time (UTC) Monitor IP AS Path
0 1324957423 11-12-27 03:43:43 129.82.2.2 12145 14041 11537 23911 23910
1 1324957424 11-12-27 03:43:44 187.16.216.20 28571 1916 11537 23911 23910
2 1324957425 11-12-27 03:43:45 205.167.76.241 10876 4600 11537 23911 23910
8 1324957431 11-12-27 03:43:51 129.82.2.2 12145 14041 19401 23911 23910
22 1324957445 11-12-27 03:44:05 202.167.228.81 24436 7575 11537 23911 23910
25 1324957448 11-12-27 03:44:08 202.167.228.46 7575 11537 23911 23910
28 1324957451 11-12-27 03:44:11 187.16.216.20 28571 1916 27750 11537 23911 23910

Geographical Plot (Full Screen)

Other anomalous prefixes in this BGP update

IP Prefix Country Code Country Name Origin Change
166.111.32.0/24 CN China AS4538 -> AS23910
Being hijacked? ROA and BGPSEC can $ecure your prefixes. You may also be interested in our FSBGP [ietf-draft] [papers].

© Copyright 2011- THU CNPT Lab. All Rights Reserved.