Mozilla/5.0 (compatible; Thinkbot/0.5.8; +In_the_test_phase,_if_the_Thinkbot_brings_you_trouble,_please_block_its_IP_address._Thank_you.)
😂🙈
Mozilla/5.0 (compatible; Thinkbot/0.5.8; +In_the_test_phase,_if_the_Thinkbot_brings_you_trouble,_please_block_its_IP_address._Thank_you.)
😂🙈
Ban me at the IP level if you don't like me | Hacker News
LinkBro, ban me at the IP level if you don't like me!All has gone very quiet on the #botnet front. But that has exposed a new botnet, stealthily crawling away.
I've started giving them names - is this a bad sign? Am I getting too attached?!!
Anyway, more analysis, stats, graphs here:
https://evilgeniusrobot.uk/botnet-reports/all-quiet-for-now-and-a-new-player-20250815.html
Let's test my theory about the bots harvesting links from here on Mastodon.
These links have not been seen anywhere so far, they're unique to this post.
https://another.evilgeniusrobot.uk/test-on-mastodon-only
https://an.evilgeniusrobot.uk/test-on-mastodon-exclusive
I suspect these will start to show up in the logs at some point. I exclude the #MastoDDoS effect from the stats, that doesn't count.
#Thinkbot has been pretty fast on the uptake but it could be that those posts got boosted widely, I dunno.
[Hmm.. "clever hand sparrow", indeed :) ]
Some other preliminary analysis makes me think that both botnets, and also my old friend #Thinkbot, got the initial links from this Mastodon account.
All crawls seem to start from the /bonk-wave and /not-bonk-wave URLs I posted here when I first launched the site, rather than the root of the home page which I've posted elsewhere. I haven't posted those links anywhere but here.
Thinkbot also found my "uncooked" releases very quickly which backs up that theory.
#Thinkbot does seem to space out requests to roughly one per minute or so - I'm not seeing great bursts of activity - just a constant trickle.
But as it will download anything it finds, that could include big zip files (e.g. on #Faircamp sites it will find and download any FLAC archives).
This could easily rack up quite a lot of bandwidth on bigger sites, which might cost someone money.
It's a particularly antisocial bot. Just rude, I would say, rather than actively malicious.
#Thinkbot's user-agent says:
"if_the_Thinkbot_brings_you_trouble,_please_block_its_IP_address._Thank_you."
In the last 24 hours or so, I've seen 1700+ requests from Thinkbot to my robot, from 74 different IP addresses. They're not in an easily blockable CIDR range.
I'll keep track of the IPs and publish them somewhere in case it's useful but they're coming from all over the place.
The few I looked up are at least all linked to Tencent in some way, but spread across the globe.
I got a little bit annoyed at a bot hoovering up all the large zip files of lossless music from various websites I run. I may have slightly overreacted...
https://evilgeniusrobot.uk/posts/an-evil-genius-robot.html
Still it's finally a good use of that domain name I've had for a few years now!