Our platforms were recently targeted by a large-scale web scraping operation originating from devices that are apparently participating in residential proxy networks 🏘️ 🖥️ . The vast majority of these requests were successfully blocked by our existing mitigations 🛑 . However, the sheer volume of traffic caused temporary disruptions to both the MalwareBazaar and URLhaus platforms ⚠️
To put the scale into perspective, our web platforms typically handle approximately 1,500 requests per second (excluding traffic to our community API and commercial APIs). During this incident, the scraping operation leveraged more than 135,000 unique IP addresses, most of which could be identified as nodes in residential proxy networks 🔍
The offender attempted to remain undetected by sending very few requests (less than 5) per IP address to the platforms 🕵
Below are the top networks sourcing this traffic (by unique IPs):
2,961 AS25019 SAUDINETSTC 🇸🇦
1,995 AS206206 KNET 🇮🇶
1,984 AS9121 TTNet 🇹🇷
1,954 AS3215 Orange 🇫🇷
1,871 AS12322 PROXAD 🇫🇷
1,550 AS5410 BOUYGTEL-ISP 🇫🇷
1,531 AS37705 TOPNET 🇹🇳
1,413 AS8193 BRM-AS 🇺🇿
We are sharing details of the involved IPs, along with the relevant timestamps, here for your awareness ⤵️
https://raw.githubusercontent.com/abusech/misc/refs/heads/main/2026-06-22_Residential-Proxy-Scraping-IPs.csv