Today I checked the traffic analysis system and found that a certain webpage link on the blog website has been subjected to a large number of malicious accesses.
After filtering, all the IP addresses that accessed the webpage link belong to Huawei Cloud IP addresses (this may only be a portion of the total IP addresses).
According to the metric analysis from Tencent Cloud EdgeOne, the webpage link was accessed over 3500 times within 35 hours.
Below are the malicious IP segments:
1.92.193.0/24
1.92.196.0/24
1.92.198.0/24
1.92.200.0/24
1.92.201.0/24
1.92.207.0/24
116.204.1.0/24
116.204.4.0/24
116.204.13.0/24
116.204.16.0/24
116.204.17.0/24
116.204.19.0/24
116.204.2.0/24
116.204.27.0/24
116.204.31.0/24
116.204.32.0/24
116.204.38.0/24
116.204.39.0/24
116.204.40.0/24
116.204.42.0/24
116.204.44.0/24
116.204.47.0/24
116.204.64.0/24
116.204.71.0/24
116.204.74.0/24
116.204.76.0/24
116.204.79.0/24
116.204.96.0/24
116.204.97.0/24
116.204.100.0/24
116.204.103.0/24
116.204.106.0/24
116.204.108.0/24
116.204.109.0/24
121.37.96.0/24
121.37.98.0/24
121.37.106.0/24
121.37.107.0/24




