44.206.93.215、50.16.72.185等IP冒充Amazonbot爬虫流量攻击
近期发现很多流量攻击,来自3.209.174.110、3.210.29.96、3.213.106.226、3.224.215.150、18.213.102.186、18.232.12.157、34.205.170.13、34.231.45.47、34.236.185.101、35.173.38.202、40.77.167.7、44.193.102.198、44.194.134.53、44.205.180.155、44.205.192.249、44.209.35.147、44.212.131.50、50.16.72.185、52.0.105.244、52.4.238.8、52.45.15.233、52.201.155.215、52.204.71.8、54.164.106.236、54.209.100.30、98.82.66.172、100.29.34.97、100.29.160.53等ip,看似很分散的ip实际是IDC机房的ip。
经过百度智能云查询:
归属地:美国 弗吉尼亚州 阿什本
运营商:亚马逊
应用场景:IDC
IPV4:52.0.105.244
风控标签:爬虫、异常操作行为、可疑用途IP、攻击威胁IP
这些ip均是亚马逊云服务器的,也就是说,是别人租用亚马逊云服务器然后冒充Amazonbot爬虫,从事流量攻击行为。(These IP addresses are all associated with Amazon Web Services (AWS). In other words, someone rents AWS servers and then impersonates Amazonbot crawlers to engage in traffic attack activities.)
访问日志如下(摘):
2026-06-07 04:11:26 GET /*/*.html keyword=%E5%A1%91%E8%83%B6&last_id_000043=0f32a4c7f3994ec58f4338c853b896df&last_id_000054=729b79af0346226d7cababc707426200&prev_id_000054=65f7f0e930e920145aabf86c60dabd24 80 - 52.0.105.244 Mozilla/5.0+AppleWebKit/537.36+(KHTML,+like+Gecko;+compatible;+Amazonbot/0.1;++https //developer amazon com/support/amazonbot)+Chrome/119.0.6045.214+Safari/537.36 - 200 0 0

浙公网安备 33010602011771号