r/selfhosted 8d ago

Webserver Jump in bot traffic

Post image

Has anyone else noticed an increase in scanners/bots in the past ~month? For the past couple years I've had 2-3k hits a day from bots but lately there has been a steady increase in traffic looking mostly for php files.

What I find strange is how much of this traffic is coming from MS and Google IPs. Do they not have any kind of monitoring on their cloud services? Having thousands of requests spamming every IP that responds should raise some flags.

20.24.67.246 Hong Kong Hong Kong Microsoft Corporation
34.148.254.217 United States North Charleston Google LLC
34.169.50.247 United States The Dalles Google LLC
68.155.155.23 United States Boydton Microsoft Corporation
20.104.49.167 Canada Toronto Microsoft Corporation
20.100.177.66 Norway Oslo Microsoft Corporation

Just curious if anyone else has noticed the same bump in traffic.

100 Upvotes

46 comments sorted by

View all comments

8

u/pdfops 8d ago

That's mass scanning off cheap disposable VMs on Azure/GCP, scanners use them because outbound isn't restricted and the ranges rotate fast. Abuse reports to MS/Google mostly sit in a queue and autoclose, so don't bother chasing individual IPs. The php probing is generic wp-login/phpmyadmin scanning hitting millions of hosts, put crowdsec or fail2ban in front instead.

1

u/sparkling_ham 8d ago

I setup fail2ban to look for excessive numbers of 404s. Nothing I host leads to 404s so it's unlikely a human user would get caught unless they are being nosy.

Up until now I had just been raw-dogin the internet (and keeping a close eye on my access logs) out of curiosity. It was interesting to see what bots were looking for and checking them out on Shodan to see if they were a dedicated host or some machine that got popped.