Did your list contain:
173.209.211.144
173.209.211.145
173.209.211.146
173.209.211.148
173.209.211.193
173.209.211.214
173.209.211.215
173.209.211.221
173.209.211.225
173.209.211.235
173.209.211.242
173.209.212.148
173.209.212.215
173.209.212.218
173.209.212.235
173.209.212.238
We have all these flagged/banned as open proxies/botnet on Windows boxes, not mobile. Spikes in traffic* from this range on February 27th 2014, March 4th 2014, March 9th 2014, March 19th, March 18th, April 18th, April 28th 2014. If it is a business running a Cel/WiFi hotspot and their main box is compromised maybe anyone on their Windows laptop is being infected? But you mention mobile, so if the signup was made via mobile it could be something entirely different. Still, that entire IP range appears rooted and infected so it's banned/blocked.
*Could be more but only took a quick look at the stats.
|