2

The other day my server started getting slow and the logs showed it was being heavily spammed with strange requests like for BingBar,

218.94.73.210 - - [22/Apr/2015:13:25:37 +1200] "GET /BingBar/signed/SeaPort.cab HTTP/1.1" 404 13315 "-" "SeaPort/3.1"

And many requests from different IPs for:

221.174.220.44 - - [21/Apr/2015:18:26:40 +1200] "POST /R/A10KIDg2YTU3MjA2YTczODRhNTliYzE5ZmRjNjMwNjBjZGU1EgQAJwIVGHgiAQAqBwgEEMrTxi844o-ASEIgQrOBZPRm7QvL7xHK09_W6HZUB9NNHDQINI6TlOsbHqk= HTTP/1.1" 404 13315 "-" "-"

and for "BitTorrent"

120.84.145.107 - - [22/Apr/2015:17:36:54 +1200] "GET /announce.php?info_hash=J%CCV%1E%1E%87%17H%2A%E6U%B5%F6%E6%A9%60%AF%DE%26%1B&peer_id=%2DSD0100%2D%00%FAsp%B3%EF%0A%D9A%CB%3D%7B&ip=192.168.18.150&port=13296&uploaded=35075634&downloaded=35075634&left=2241210207&numwant=200&key=9018&compact=1 HTTP/1.0" 404 0 "-" "Bittorrent"

and things like

119.4.95.7 - - [21/Apr/2015:19:32:16 +1200] "GET /img/169563854/2958521e/dlink__2Fdownload_2F169563854_2F2958521e_3Ftsid_3D20100512-223441-fd64b17d/preview.mp3 HTTP/1.1" 404 13315 "http://dc181.4shared.com/" "Mozilla/4.0 (compatible; MSIE 5.50; Windows NT 6.1; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729)"

123.64.9.60 - - [22/Apr/2015:05:07:27 +1200] "GET /images/models/samples-120x90/1901671.jpg HTTP/1.1" 404 13330 "http://ads.vs.com/_special/iframe/?sitekey=flirt4free&mp_code=b3gd&service=guys&shape=custom&width=1200&height=640&image_type=samples-120x90&scrolling=0&fontcolor=000000&bgcolor=ffffff&bordercolor=AC840C&show_all=Y" "Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chr$

None of these pages exist on my server. Does any one know what these requests are and why they sometimes come in so heavily to my server IP?

  • The general consensus is that this traffic is being misdirected to random Internet addresses by the Great Firewall of China. There's not that much you can do, unless you own a few nuclear weapons or something... – Michael Hampton Apr 23 '15 at 01:17

0 Answers0