If you have log records or packets for traffic from this particular subnet. If you have anything you can share I'd appreciate it.
Likely what you will have is DNS open resolver checks, as well as SSH bruteforce pwd guessing attacks. I'm interested in those as well as anything else from this subnet.
Regards
Mark H - markh.isc (at) gmail.com
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.