Looking at my router logs (not my web server logs) this morning. These logs show packets dropped by my router for one reason or another. The reason usually being some sort of probe or hack attempt.
One thing stands out - 213 pings (ICMP packets, type 8, code 0) from 216.73.216.58. This IP is part of AS16509 (Amazon) - but the prefix 216.73.216.0/22 is registered to -> Anthropic, PBC.
There are no DNS host names listed for this prefix. I need to check to see if indeed I have gotten Claudebot hits from this CIDR.
AbusedIPDB has 20 reports of abuse from this IP, they also list it as belonging to Anthropic.
This might be the "ping of death" attack, which is common to see from data center IP's. This is the first notable search engine (if you call AI bots search engines) that I've seen using AWS. My own experience with AWS is that it's garbage and highly hacked / vulnerable, so I wonder if these servers have been hacked - I never see ping probes from Bing or Google searchbot IP's.
An alternative theory is that the source IP for these ICMP packets is spoofed, meaning that they are not really coming from Anthropic servers. It's not clear to me if this would be a DDos method, and if so, against who? Me, or Anthropic?