AWS has acted upon similar reports in the past, Azure may have but the lack of comms and delays in seeing any action (if any) hasn't inspired confidence.
I would hope they did investigate too otherwise it’s too easy to DoS a valid customer with fake complaints.
A couple provides I sent abuse complaints to based on whois lookups responded with automated emails requesting the info in X-ARF format. It’s hard to get some cloud providers to respond to a random residential user.
A couple IPs were repeated “scans” by supposed security researchers with IPs out of Hawaii and France.
If I find the sketchy Hawaii and French IPs I will post something.
Edit: Here you go:
https://academyforinternetresearch.org
IP Location United States United States Honolulu Academy Of Internet Research Limited Liability Company
ASN United States AS400161 (registered Oct 22, 2021)
Whois Server whois.arin.net
IP Address 104.156.155.3
NetRange: 104.156.155.0 - 104.156.155.255
CIDR: 104.156.155.0/24
NetName: ACDRESEARCH
NetHandle: NET-104-156-155-0-1
Parent: NET104 (NET-104-0-0-0-0)
NetType: Direct Allocation
OriginAS:
Organization: Academy of Internet Research Limited Liability Company (AIRLL)
RegDate: 2022-01-07
Updated: 2022-01-07
Ref: https://rdap.arin.net/registry/ip/104.156.155.0
OrgName: Academy of Internet Research Limited Liability Company
OrgId: AIRLL
Address: #A1- 5436
Address: 1110 Nuuanu Ave
City: Honolulu
StateProv: HI
PostalCode: 96817
Country: US
RegDate: 2021-10-15
Updated: 2022-11-06
Ref: https://rdap.arin.net/registry/entity/AIRLLIt seems they are running on Hivelocity a bare metal hosting provider.
Snort is something I have looked at installing and playing with on a PFSense box.
You could also check if the remote IP has any open ports (ex. SSH) and block based on that as most regular visitors probably won't be exposing those types of services to the Internet.
If I had a dollar for every person who has turned loose such a tool to shit up my abuse@ispname.com inbox...
I seriously doubt the Las Vegas “located” IP with Hong Kong addresses on their registration or Shanghai UCloud Information Technology Company IPs are scanning me for good reasons.
What do you think would happen if I run an older version of plex with a known vulnerability?
The automated emails are usually in the same formats making them easy to filter and parse too.