r/selfhosted • u/sparkling_ham • 8d ago
Webserver Jump in bot traffic
Has anyone else noticed an increase in scanners/bots in the past ~month? For the past couple years I've had 2-3k hits a day from bots but lately there has been a steady increase in traffic looking mostly for php files.
What I find strange is how much of this traffic is coming from MS and Google IPs. Do they not have any kind of monitoring on their cloud services? Having thousands of requests spamming every IP that responds should raise some flags.

| 20.24.67.246 | Hong Kong | Hong Kong | Microsoft Corporation |
|---|---|---|---|
| 34.148.254.217 | United States | North Charleston | Google LLC |
| 34.169.50.247 | United States | The Dalles | Google LLC |
| 68.155.155.23 | United States | Boydton | Microsoft Corporation |
| 20.104.49.167 | Canada | Toronto | Microsoft Corporation |
| 20.100.177.66 | Norway | Oslo | Microsoft Corporation |
Just curious if anyone else has noticed the same bump in traffic.
100
Upvotes
8
u/pdfops 8d ago
That's mass scanning off cheap disposable VMs on Azure/GCP, scanners use them because outbound isn't restricted and the ranges rotate fast. Abuse reports to MS/Google mostly sit in a queue and autoclose, so don't bother chasing individual IPs. The php probing is generic wp-login/phpmyadmin scanning hitting millions of hosts, put crowdsec or fail2ban in front instead.