Preventing malicious traffic from bc.googleusercontent.com

Remco00

Verified User
Joined
Feb 22, 2006
Messages
268
Lately I have seen an increasing number of malicious traffic from bc.googleusercontent.com in the log files. Almost always starting with the IP4 addresses 34.* and 35.*. That's why I went looking for an overview of IP addresses managed by Google. I found this one here:

https://www.gstatic.com/ipranges/goog.json

After stripping unnecessary text, I copied this list of Google IP-ranges to csf.deny:

Code:
# Google IP ranges
tcp|in|d=80,443|s=34.0.0.0/15
tcp|in|d=80,443|s=34.2.0.0/16
tcp|in|d=80,443|s=34.3.0.0/23
tcp|in|d=80,443|s=34.3.3.0/24
tcp|in|d=80,443|s=34.3.4.0/24
tcp|in|d=80,443|s=34.3.8.0/21
tcp|in|d=80,443|s=34.3.16.0/20
tcp|in|d=80,443|s=34.3.32.0/19
tcp|in|d=80,443|s=34.3.64.0/18
tcp|in|d=80,443|s=34.4.0.0/14
tcp|in|d=80,443|s=34.8.0.0/13
tcp|in|d=80,443|s=34.16.0.0/12
tcp|in|d=80,443|s=34.32.0.0/11
tcp|in|d=80,443|s=34.64.0.0/10
tcp|in|d=80,443|s=34.128.0.0/10
tcp|in|d=80,443|s=35.184.0.0/13
tcp|in|d=80,443|s=35.192.0.0/14
tcp|in|d=80,443|s=35.196.0.0/15
tcp|in|d=80,443|s=35.198.0.0/16
tcp|in|d=80,443|s=35.199.0.0/17
tcp|in|d=80,443|s=35.199.128.0/18
tcp|in|d=80,443|s=35.200.0.0/13
tcp|in|d=80,443|s=35.208.0.0/12
tcp|in|d=80,443|s=35.224.0.0/12
tcp|in|d=80,443|s=35.240.0.0/13
tcp|in|d=80,443|s=35.252.0.0/14

Now, after a few days, no more malicious traffic entries (e.g. mod_security) from bc.googleusercontent.com are visible in the log files. In the coming period I will monitor the Google Json file for the frequency of mutations in the file. If necessary, I will supplement my findings here.

List edited with advanced port filtering and specialized pipe-separated rules
 
Last edited:
I've been seeing the same, and was contemplating the exact same action.

Unfortunately I am a little worried about blocking legitimate traffic, so I was hoping GCP would figure out who's churning through their addresses.
 
You might want to have a look at this thread. It's set as solved but was a bit ongoing.
I also experiencing again spam via Google and Outlook.
 
You might want to have a look at this thread. It's set as solved but was a bit ongoing.
I also experiencing again spam via Google and Outlook.
Thanks Richard, but this has nothing to do with receiving spam. The malicious traffic we receive from bc.googleusercontent.com triggers certain mod_security rules we want to get rid of. Meanwhile I edited my first post to include port filtering and specialized pipe-separated rules in the list with Google IP-ranges so only ports 80 and 443 are blocked.
 
Back
Top