I'm apparently IP-blocking some or all of 110.249/16 (China Unicom Hebei province network) - I noticed today some port-80 dropped packets from:
bytespider-110-249-X-Y.crawl.bytedance.com
where X is either 201 or 202.
Looking back at the logs, I see similar attempts on a couple of days each back last july and december, then one day in January and now today. Perhaps a pattern emerging of once a month now, 12 attempts before it gives up.
For anyone looking for bytedance / bytespider IP's, the 2 most recent being
110.249.201.92
110.249.202.158
12 different IP's in total so far.