Possible DDoS from Ecxon/ASN 270764

Observable: Brazil Ecxon Datacenter DDoS
Observable Type: IP/ASN

Details: Reports of spikes in TCP_RECV from the following sources.

Subnet Country source ASN WHOIS
104.234.119.0/24 CA arin 270764 Ecxon Datacenter LTDA, BR
181.215.236.0/24 AE ripencc 270764 Ecxon Datacenter LTDA, BR
181.215.253.0/24 AE ripencc 270764 Ecxon Datacenter LTDA, BR
181.215.254.0/24 AE ripencc 270764 Ecxon Datacenter LTDA, BR
189.127.164.0/24 BR lacnic 270764 Ecxon Datacenter LTDA, BR
189.127.165.0/24 BR lacnic 270764 Ecxon Datacenter LTDA, BR

iris-pe-export-2026-03-04T09_03_25-05_00.csv (31.3 KB)

Looking at each /24 for DNS traffic seen in the last 30 days, I see multiple connected VPS hosting services (ie, run one until it gets too hot, shut it down, spin a new one up with a slightly different name, rinse and repeat). Also dominated by gaming server rentals, and what may be live TV pirating, with a chunk of dynamic DNS indicators.

Does not look like a good neighborhood. While risk scores are low-moderate, it looks like this is almost exclusively what this ASN does; a few hundred records per /24, rather than the thousands or tens of thousands I’d expect to see with a conventional host.

1 Like