Y
Y
Yura01032020-04-02 11:04:22
Parsing
Yura0103, 2020-04-02 11:04:22

How to determine if the traffic to the site is malicious?

In October 2019, strange transitions to a site from another country appeared. The duration of the visits ranged from 1 second to 1 minute. At the current time (04/02/2020), the position of the site in the search results has fallen significantly... The process of worsening the position of the site began literally from November. Here are the current logs for 10 hours (exactly the visits that confuse me). Can someone tell me what's going on...
02.04.2020, 00:00 91.193.178.254 /?bxrand=1585774826050 Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.80 Safari/537.36
02.04. 2020, 00:06 83.220.237.53 /?bxrand=1585775175724 Mozilla/5.0 (Linux; Android 7.1.1; Coolpad COR-I0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.116 Mobile Safari/537.36
04/02/2020, 00:06 213.87.149.102 /?bxrand=1585774830614 Mozilla/5.0 (Linux; arm_64; Android 9; MI MAX 3) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 YaBrowser/20.2.2.2 00 Mobile Safari/537.36
02.04.2020, 00:28 176.59.49.52 /?bxrand=1585776480286 Mozilla/5.0 (Linux; Android 7.1.1; Coolpad COR-I0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.116 Mobile Safari/537.36
02.04.2020, 00:29 176.59.49.52 /?bxrand=1585776586942 Mozilla/5.0 (Linux; Android 7.1.1; Coolpad COR-I0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.116 Mobile Safari/537.36
02.04.2020 01:58 91.193.179.138 /?bxrand=1585781887044 Mozilla/5.0 (Windows NT 6.2; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.10836
04/02/2020 01:59 78.159.98.69 /?bxrand=1585781962504 Mozilla/5.0 (Windows NT 6.0; Win64; x64; rv:49.0) Gecko/20100101 Firefox/49.0
04/02/2020, 03:41 38.17.63 =1585788098996 Mozilla/5.0 (Linux; arm_64; Android 9; Redmi Note 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.122 YaBrowser/20.3.0.152.00 (alpha) Mobile SA/0 Safari/537.36
02.04. 2020, 03:44 83.220.237.53 /?bxrand=1585788289018 Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/73.0.3683.103 Safari/537.36
02.04.2020 2150 .151.17 /?bxrand=1585788810202 Mozilla/5.0 (Windows NT 6.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.142 Safari/537.36
2020-04-02 04:05 176.59.47.103 /?bxrand=1585789113578 Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.142 Safari/537.36
02.02,02 13 91.193.177.97 /?bxrand=1585790013408 Mozilla/5.0 (Windows NT 6.2; Win64; x64; rv:55.0
) Windows NT 6.2) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.120 Safari/537.36
02.04.2020, 04:16 31.173.30.147 /?bxrand=1585790191322 Mozilla/5.0 (Windows NT 6.1) AppleKit/53ML.WebKit/53ML.WebKit/53ML.36 like Gecko) Chrome/77.0.3865.120 Safari/537.36
04/02/2020, 04:39 31.173.87.163 /?bxrand=1585791542538 Mozilla/5.0 (Linux; Android 9; Redmi 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.94 Mobile Safari/537.36 Vivaldi/2.39.174
2020-04-02 04:51 213.87.129.227 /?bxrand=1585792269458 Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.80 Safari/537.36
02.05,02.05
24 213.87.161.158/ Android 6.0; Mobile; rv:54.0) Gecko/54.0 Firefox/54.0
04/02/2020, 06:18 31.173.27.243 /?bxrand=1585797513056 Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko ) Chrome/78.0.3904.108 Safari/537.36
04/02/2020 07:25 31.173.87.153 /?bxrand=1585801522012 Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36
02.04.2028.2028.2028 .159.39 /?bxrand=1585804553884 Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/59.0.3052.33 Safari/537.36
04/02/2020, 08:18 213.87.159.39 1585804670210 Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/59.0.3052.33 Safari/537.36
04/02/2020 09:31 87.252.225.143 /?bxrand=1585 NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.132 YaBrowser/20.3.1.197 Yowser/2.5 Safari/537.36
04/02/2020, 09:33 213.87.135.254 /?bxrand=1585809222972 Mozilla/5.0 (iPhone; CPU iPhone OS 11_4_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/11.1.2 Mobile/15E148 Safari /604.1
02.04.2020 09:45 213.87.162.66 /?bxrand=1585809949262 Mozilla/5.0 (Linux; Android 9; ZE620KL) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.162 Mobile
, Safari/532.046 09:54 31.173.25.166 /?bxrand=1585810454016 Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/56.0.2919.49 Safari/537.36

Answer the question

In order to leave comments, you need to log in

2 answer(s)
D
Dimonchik, 2020-04-02
@dimonchik2013

logs as logs
, well, a megaphone, so what? maybe everything with mobile
for SEO is getting deeper and you need to start with Yandex and Google Webmaster

Y
Yura0103, 2020-04-02
@Yura0103

it is at least strange that /?bxrand=**** is added to the domain name. The site is tied to the Republic of Belarus. And as practice shows, these fake entries start when everyone is usually asleep.

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question