Curious recon(?) or testing against downloads.

Unusual one.. Several IPs have been requesting a small download from my website every 30 minutes since 2018-10-01. The first ever request from that group of IPs was 2017-12-14 and then nothing until 2018-10-01! The requests appear to have stopped 2018-10-08.
All associated IPs:

87.114.193.121 initial request, plusnet broadband IP in the UK
46.101.119.24 digitalocean
46.101.94.163 digitalocean
162.243.187.126 digitalocean
52.67.133.136 amazon brazil
18.228.7.191 amazon brazil
18.231.121.157 amazon brazil
18.231.36.254 amazon brazil
18.228.42.156 amazon brazil
18.228.152.45
169.57.65.164 softlayer
119.81.129.142 softlayer
54.202.225.77 amazon
34.220.151.96 amazon
18.231.116.211 amazon

Unusual and curious. Speed testing? Attempting to use my bandwidth allowance? Broken av / malware checking system? Can’t find anything about it in the request information or google searches. Some of the IPs appear to be associated with other “bad internet practice” (scans, botnets etc.).

This entry was posted in Uncategorized. Bookmark the permalink.

Comment on this topic

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out /  Change )

Twitter picture

You are commenting using your Twitter account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )

Connecting to %s