Seeing some strange hits today.
First, several dozen hits from this bot:
Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; spider-feedback@bytedance.com)
operating from 156.59.198.135 (Zenlayer, Singapore). It grabbed several dozen pdf files, it knew the path to get them. Did not grab any html files, did not request robots.txt. I had been blocking some Zenlayer IP's, but now the entire AS21859 is blocked.
Also today, about 53 hits from these User-Agents:
Mozilla/5.0 (iPhone; CPU iPhone OS 11_0 like Mac OS X) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.9279.1304 Mobile Safari/537.36
Mozilla/5.0 (Linux; Android 5.0; SM-G900P Build/LRX21T) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/40.0.3165.1420 Mobile Safari/537.36
Mozilla/5.0 (Linux; Android 6.0; Nexus 5 Build/MRA58N) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.3566.1039 Mobile Safari/537.36
Mozilla/5.0 (Linux; Android 8.0; Pixel 2 Build/OPD3.170816.012) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/43.0.1095.1898 Mobile Safari/537.36
About a dozen hits from each one, but the chrome version changed to various versions from 39 to 59, otherwise the UA's were identical.
I am going to scan my logs for those UA's, results in a few days.
These hits were also getting PDF files almost exclusively, sometimes an HTML file (but not the accessory files that a human browser would be requesting to render the page). No referrer.
The countries these hits came from were Australia, Canada, Ireland, New Zealand, UK and US (about 8 to 10 for each). I'm blocking a lot of the third world (in the router) so it makes these hits from western countries stand out. The IP's belonged to what looks like residential/commercial ISP's (ACCESS-SK, ATT, Bell Canada, BT (UK), BT (Ireland), Comcast, Eir Broadband, Foxtel, Mercury NZ, Microplex, One New Zealand Group, Rogers, SASKTEL, Sky UK Limited, SPACEX-STARLINK, Spark New Zealand Trading, Telstra, Vodafone Australia, Vodafone Ireland).
I have never seen anything like this. I think this is related to the Bytedance hits. Bytedance, aka TikTok.
I think Bytedance is using the TikTok app on people's phones to access files that perhaps they (China) is having problems reaching. For the past few years I've been blocking every Chinese /16 net-block that I see hitting my router / webserver / mailserver.
The only alternate explanation is that there is a new bot or malware operating on people's cell phones. Or at least made to look like the hits are coming from cell phones, from residential / commercial IP's.