Forum Moderators: open

Message Too Old, No Replies

Is this some type of proxy activity?

         

Wmff

7:56 pm on Oct 29, 2023 (gmt 0)

Top Contributors Of The Month



Any idea what's going on here? Is it just a regular visitor using a proxy service to disguise himself? Or is it something malicious, trying to hide itself? As you can see these are requests are for a single web page, apparently from the same user agent, but from, not just different IP's, but from different service providers.
This started very suddenly about 48-72 hours ago. Commonly they also come from Ireland, Australia/New Zeeland.

2023-10-29
08:10:47
69.131.199.18
GET /index.php/about-us/9-uncategorised/892-western-bracken-fern-pteridium-aquilinum HTTP/1.1
Mozilla/5.0 (Linux; Android 8.0; Pixel 2 Build/OPD3.170816.012) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.5178.1524 Mobile Safari/537.36
United States
9212
385923
2023-10-29
08:10:49
107.146.236.62
GET /templates/beez_20/css/position.css HTTP/1.1
Mozilla/5.0 (Linux; Android 8.0; Pixel 2 Build/OPD3.170816.012) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.5178.1524 Mobile Safari/537.36
United States
1705
829
2023-10-29
08:10:49
174.45.174.218
GET /media/com_finder/css/finder.css?30337867b1da17a0510112b9ef0c9a29 HTTP/1.1
Mozilla/5.0 (Linux; Android 8.0; Pixel 2 Build/OPD3.170816.012) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.5178.1524 Mobile Safari/537.36
United States
887
1877
2023-10-29
08:10:51
47.17.49.115
GET /media/jui/js/jquery-migrate.min.js?30337867b1da17a0510112b9ef0c9a29 HTTP/1.1
Mozilla/5.0 (Linux; Android 8.0; Pixel 2 Build/OPD3.170816.012) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.5178.1524 Mobile Safari/537.36
United States
4034
732
2023-10-29
08:10:51
68.173.53.42
GET /media/jui/css/chosen.css?30337867b1da17a0510112b9ef0c9a29 HTTP/1.1
Mozilla/5.0 (Linux; Android 8.0; Pixel 2 Build/OPD3.170816.012) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.5178.1524 Mobile Safari/537.36
United States
2454
771
2023-10-29
08:10:51
97.114.187.63
GET /media/jui/js/bootstrap.min.js?30337867b1da17a0510112b9ef0c9a29 HTTP/1.1
Mozilla/5.0 (Linux; Android 8.0; Pixel 2 Build/OPD3.170816.012) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.5178.1524 Mobile Safari/537.36
United States
7736
1080
2023-10-29
08:10:51
71.85.134.225
GET /media/system/css/system.css HTTP/1.1
Mozilla/5.0 (Linux; Android 8.0; Pixel 2 Build/OPD3.170816.012) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.5178.1524 Mobile Safari/537.36
United States
550
1803
2023-10-29
08:10:52
216.218.64.66
GET /media/system/js/caption.js?30337867b1da17a0510112b9ef0c9a29 HTTP/1.1
Mozilla/5.0 (Linux; Android 8.0; Pixel 2 Build/OPD3.170816.012) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.5178.1524 Mobile Safari/537.36
United States
334
676
2023-10-29
08:10:53
71.178.178.115
GET /media/jui/js/chosen.jquery.min.js?30337867b1da17a0510112b9ef0c9a29 HTTP/1.1
Mozilla/5.0 (Linux; Android 8.0; Pixel 2 Build/OPD3.170816.012) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.5178.1524 Mobile Safari/537.36
United States
7710
3779
2023-10-29
08:10:53
76.37.111.139
GET /media/system/js/mootools-core.js?30337867b1da17a0510112b9ef0c9a29 HTTP/1.1
Mozilla/5.0 (Linux; Android 8.0; Pixel 2 Build/OPD3.170816.012) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.5178.1524 Mobile Safari/537.36
United States
26988
4394
2023-10-29
08:10:54
134.16.114.112
GET /templates/beez_20/images/system/arrow.png HTTP/1.1
Mozilla/5.0 (Linux; Android 8.0; Pixel 2 Build/OPD3.170816.012) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.5178.1524 Mobile Safari/537.36
United States
159
705
2023-10-29
08:10:56
174.61.102.178
GET /images/joomgallery/thumbnails/other_plants_127/western_bracken_fern_1154/bracken_fern_1_20150730_1280063662.jpg HTTP/1.1
Mozilla/5.0 (Linux; Android 8.0; Pixel 2 Build/OPD3.170816.012) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.5178.1524 Mobile Safari/537.36
United States
15591
1872
2023-10-29
08:10:56
99.145.0.236
GET /templates/beez_20/images/personal/bg2.png HTTP/1.1
Mozilla/5.0 (Linux; Android 8.0; Pixel 2 Build/OPD3.170816.012) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.5178.1524 Mobile Safari/537.36
United States
2629
643
2023-10-29
08:10:57
136.50.248.242
GET /templates/beez_20/images/personal/personal2.png HTTP/1.1
Mozilla/5.0 (Linux; Android 8.0; Pixel 2 Build/OPD3.170816.012) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.5178.1524 Mobile Safari/537.36
United States
699
900
2023-10-29
08:10:57
96.231.139.128
GET /templates/beez_20/images/personal/ecke.gif HTTP/1.1
Mozilla/5.0 (Linux; Android 8.0; Pixel 2 Build/OPD3.170816.012) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.5178.1524 Mobile Safari/537.36
United States
826
493
2023-10-29
08:10:58
76.50.218.195
GET /templates/beez_20/images/personal/navi_active.png HTTP/1.1
Mozilla/5.0 (Linux; Android 8.0; Pixel 2 Build/OPD3.170816.012) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.5178.1524 Mobile Safari/537.36
United States
95
1808

Wmff

4:03 am on Nov 2, 2023 (gmt 0)

Top Contributors Of The Month



Here is another example from 110123, trimmed down.
Each of these IP Addresses opened/requested an element of a web page. They all resolved to Canada but there are almost as many different IP Addresses as there are different ISP/Organizations. They all showed the same user agent but there was no referer displayed in my server logs. The entire visit happened between 14:58:21 - 14:58:38. I have seen similar activity come from Ireland, Australia, and USA.

user agent: Mozilla/5.0 (iPhone; CPU iPhone OS 11_0 like Mac OS X) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/54.0.5848.1080 Mobile Safari/537.36

IP Addresses: 70.26.204.92, 142.112.201.20, 142.116.152.210, 170.203.221.247, 166.48.216.174, 99.233.175.187
76.69.143.147, 192.214.239.90, 24.235.135.103, 70.24.120.153, 129.222.187.117, 50.93.95.108, 76.11.79.106
216.211.127.27, 142.113.188.121, 76.67.135.146, 99.211.210.93, 66.183.113.179, 99.248.8.32, 99.247.65.169
99.234.123.45, 174.116.60.35, 134.41.131.131, 174.138.210.121, 148.64.82.195, 135.23.241.6, 142.118.81.92

Wmff

8:27 am on Nov 4, 2023 (gmt 0)

Top Contributors Of The Month



Here is another twist to this subject. The following visit/page hit was reported as 35.145.156.153 by my tracking service. However, my server logs reports all of the following IP's for the same hits on various elements of the same page:
71.205.239.64, 68.198.176.120, 172.3.59.126, 100.33.36.169, 108.29.207.77, 174.71.52.251

- my tracking service reported Android / Google Pixel 2, Chrome for Android
- server logs reported Android 8.0; Pixel 2 Build/OPD3.170816.012) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.7745.1779 Mobile Safari/537.36

What's going on - anybody?

not2easy

1:31 pm on Nov 4, 2023 (gmt 0)

WebmasterWorld Administrator 10+ Year Member Top Contributors Of The Month



Since these appear to be residential carrier IPs and the main UA common among them seems to be Google Pixel 2 variations, I'd guess these are related to a wireless mobile user of Pixel 2 on cloud wi-fi. Perhaps they are using a privacy related app that shuffles the IP - ? If they are using the page normally except for the IP changes, I'd say it is unlikely to be something nefarious. It is not impossible they are traveling and if by air, it might mean a string of carriers.

OTOH that iPhone OS is seriously out of date. The Pixel2 default OS is Android 8 Oreo but that would also be outdated. Because scripts can use any UA they find lying around, that points to a likelihood of a scripted bot. It would be hard to block it via UA without additional conditions.

In other words, from the information here, your guess is as good as mine. There are a lot of users more gifted in UA analyses than I am, so I hope you will get better responses.

Wmff

5:44 pm on Nov 4, 2023 (gmt 0)

Top Contributors Of The Month



not2easy thanks for the input.
To complicate things even further: A single page visit are sometimes now being reported from IP addresses from all over the world and most are on common black lists or being reported with a bad "Reputation Score", "Abusive IP".

Mozilla/5.0 (Linux; Android 6.0; Nexus 5 Build/MRA58N) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/47.0.2904.1868 Mobile Safari/537.36

start time: 2023-11-03 15:24:35 - 138.94.121.92 Honduras, 69.118.221.133 United States, 144.64.173.205 Portugal, 154.124.66.202 Senegal, 81.233.56.114 Sweden, 73.86.137.164 United States, 84.65.122.166 United Kingdom, 191.126.172.152 Chile, 38.25.30.26 Peru, 45.24.13.217 United States, 122.162.144.151 India, 92.13.66.4 United Kingdom, 90.212.88.48 United Kingdom, 190.48.253.172 Argentina

not2easy

7:06 pm on Nov 4, 2023 (gmt 0)

WebmasterWorld Administrator 10+ Year Member Top Contributors Of The Month



It is not impossible that these are botnets - strings of infected residential computers' IPs used remotely in service to people or organizations for payment. When the IPs are from carriers like "Cablevision Systems Corp" it does not indicate mobile use, more like infected machines or routers. If you block the IP ranges you would likely be blocking visitors you would welcome. They would be unaware of their part in your unwanted traffic. I know of nothing here that indicates that is the case, these are just hypothetical situations that could produce the effect. The IPs are not part of a proxy themselves, but may be used as part of a proxy unrelated to those IPs.

I'm guessing here.

SumGuy

3:11 am on Nov 6, 2023 (gmt 0)

10+ Year Member Top Contributors Of The Month



I've checked about a dozen IP's in this thread at spur.us, it says they do or likely do belong to a call-back proxy network.

Wmff

4:43 am on Nov 6, 2023 (gmt 0)

Top Contributors Of The Month



I had to look that up, "call-back proxy network", and see that this is what "not2easy" was speculating.
Thanks for checking, I have been using https://www.ipqualityscore.com and found similar results, although not as detailed, showing many are proxies and or most, if not all, end up on various black lists.
As my site is strictly educational, I don't sell anything, have no subscriber lists, so the only thing to "steal" is my content and thousands of photos.
So, I guess what is happening is that these are not "regular" visitors using a proxy but some kind of malicious bot probing for something to "steal". Not good news, but I guess there isn't much that can be done once you become a target.
Thanks again to all who replied.




[edited by: not2easy at 11:10 am (utc) on Nov 6, 2023]
[edit reason] ToS/Charter [/edit]

SumGuy

12:56 pm on Nov 6, 2023 (gmt 0)

10+ Year Member Top Contributors Of The Month



Note that I mentioned this UA (among a few others)

Mozilla/5.0 (Linux; Android 8.0; Pixel 2 Build/OPD3.170816.012) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/43.0.1095.1898 Mobile Safari/537.36

in the first post of this thread: [webmasterworld.com...]

Since then I'm rejecting webhits from some of those user-agents - or more specifically in this case any UA that contains OPD3.170816.(because the Chrome version is variable).

I think it's obvious that would be a very efficient way to deal with this phenomena.