E
E
Eugene2014-10-15 17:36:33
DDoS Protection
Eugene, 2014-10-15 17:36:33

DDOS - random referrer (botnet)?

Hello! DDOSYAT sites, switched to VDS + CloudFlare (PRO), please help, how can I repel such attacks?

108.162.254.65 - - [15/Oct/2014:17:23:15 +0300] "GET / HTTP/1.1" 499 0 "http://203g96q6e93.ua/" "Opera/9.80 (Windows NT 6.1; U; Edition Grenada Local; ru) Presto/2.10.289 Version/9.06"

108.162.254.65 - - [15/Oct/2014:17:23:15 +0300] "GET / HTTP/1.1" 499 0 "http://4du9f.net/" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.014982; .NET CLR 3.5.014982; .NET CLR 3.0.014982"

141.101.80.49 - - [15/Oct/2014:17:23:15 +0300] "GET / HTTP/1.1" 499 0 "http://l9q904vb20.net/" "Opera/9.80 (Windows NT 6.1; WOW64; U; Edition France Local; ru) Presto/2.10.289 Version/11.08"

108.162.212.48 - - [15/Oct/2014:17:23:15 +0300] "GET / HTTP/1.1" 504 182 "http://891f25944drj0.ua/" "Mozilla/5.0 (Windows NT 5.1; rv:13.0) Gecko/20100101 Firefox/13.0"

141.101.98.213 - - [15/Oct/2014:17:23:15 +0300] "GET / HTTP/1.1" 499 0 "http://bg61dar789x.org/" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Trident/4.0; SLCC2; .NET CLR 2.0.537976; .NET CLR 3.5.537976; .NET CLR 3.0.537976"

141.101.98.213 - - [15/Oct/2014:17:23:15 +0300] "GET / HTTP/1.1" 499 0 "http://85rh4er9k3.net/" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Trident/4.0; SLCC2; .NET CLR 2.0.033922; .NET CLR 3.5.033922; .NET CLR 3.0.033922"

141.101.80.49 - - [15/Oct/2014:17:23:15 +0300] "GET / HTTP/1.1" 499 0 "http://v410e78grgrki9.net/" "Opera/9.80 (Windows NT 5.1; U; Edition Grenada Local; ru) Presto/2.10.289 Version/5.08"

141.101.80.49 - - [15/Oct/2014:17:23:15 +0300] "GET / HTTP/1.1" 499 0 "http://0z8n634c.org/" "Mozilla/5.0 (Windows NT 6.1; rv:12.0) Gecko/20100101 Firefox/12.0"

141.101.80.49 - - [15/Oct/2014:17:23:15 +0300] "GET / HTTP/1.1" 499 0 "http://98l3j47grimx.com/" "Mozilla/5.0 (Windows NT 6.1; rv:15.0) Gecko/20100101 Firefox/15.0"

173.245.62.188 - - [15/Oct/2014:17:23:15 +0300] "GET / HTTP/1.1" 499 0 "http://fsl4y5zt79.org/" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; SLCC2; .NET CLR 2.0.989772; .NET CLR 3.5.989772; .NET CLR 3.0.989772"

108.162.212.16 - - [15/Oct/2014:17:23:16 +0300] "GET / HTTP/1.1" 499 0 "http://960culf1sqsu.ua/" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Trident/4.0; SLCC2; .NET CLR 2.0.029777; .NET CLR 3.5.029777; .NET CLR 3.0.029777"

108.162.254.65 - - [15/Oct/2014:17:23:16 +0300] "GET / HTTP/1.1" 499 0 "http://8gen0pguofs19.net/" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Trident/4.0; SLCC2; .NET CLR 2.0.498375; .NET CLR 3.5.498375; .NET CLR 3.0.498375"

108.162.223.131 - - [15/Oct/2014:17:23:16 +0300] "GET / HTTP/1.1" 499 0 "http://72ihk.net/" "Mozilla/5.0 (Windows NT 6.1; rv:17.0) Gecko/20100101 Firefox/17.0"

108.162.254.65 - - [15/Oct/2014:17:23:16 +0300] "GET / HTTP/1.1" 499 0 "http://953qu3w4v0r7.org/" "Mozilla/5.0 (Windows NT 5.1; WOW64; rv:11.0) Gecko/20100101 Firefox/11.0"

103.22.200.180 - - [15/Oct/2014:17:23:16 +0300] "GET / HTTP/1.1" 499 0 "http://648z620t6f.net/" "Opera/9.80 (Windows NT 6.1; WOW64; U; Edition Romania Local; ru) Presto/2.10.289 Version/7.05"

141.101.80.49 - - [15/Oct/2014:17:23:16 +0300] "GET / HTTP/1.1" 499 0 "http://34yupy175a3587.org/" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Trident/4.0; SLCC2; .NET CLR 2.0.349828; .NET CLR 3.5.349828; .NET CLR 3.0.349828"

108.162.254.65 - - [15/Oct/2014:17:23:16 +0300] "GET / HTTP/1.1" 499 0 "http://zi22jg4j00.net/" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.029356; .NET CLR 3.5.029356; .NET CLR 3.0.029356"

108.162.223.131 - - [15/Oct/2014:17:23:16 +0300] "GET / HTTP/1.1" 499 0 "http://lsu7849.ua/" "Opera/9.80 (Windows NT 5.1; WOW64; U; Edition Egypt Local; ru) Presto/2.10.289 Version/12.09"

141.101.75.95 - - [15/Oct/2014:17:23:16 +0300] "GET / HTTP/1.1" 499 0 "http://2x9rgrr69lr.net/" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.045441; .NET CLR 3.5.045441; .NET CLR 3.0.045441"

Answer the question

In order to leave comments, you need to log in

2 answer(s)
_
_ _, 2014-10-15
@AMar4enko

IP addresses are repeated. Make request throttling, when the number of requests per unit of time is exceeded, write the ip-address to a separate log, set fail2ban on this log.

P
Puma Thailand, 2014-10-15
@opium

Yes, the most banal ddos

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question