Malicious bot attack?
-
Several of our websites have experienced a major direct load traffic spike in the last 30 days - roughly 40K new visitors for each site. The bots are emulating IE9 and appear to be hitting our home page and bouncing 100% of the time. The traffic is double our usual volume, or more. Our bounce rates, conversion rate, page views, etc have suffered accordingly. The volume hasn't affected site performance, yet.
Since the traffic is direct load, I can't see this being a negative SEO attack. Plus, our search visibility for everything but our brands is abysmal - there aren't any real rankings to tank.
Our engineers are saying that the IP addresses are diverse, and they aren't seeing any pattern. I also checked GA for traffic locations, and we aren't seeing anything unusual from overseas.It appears that the attack is US based.
Has anyone seen this before?
-
I have been experiencing this on my site as well. Just curious if you were still receiving this kind of traffic since it has been a few months?
Recently there have been one or two times throughout the day where I see a huge spike in direct traffic. As you mentioned, the GA numbers seem to suffer but as long as this does not impact my rankings or site performance I'm not too worried. I too am concerned that this is more than just an annoyance and possibly reason for concern.
I've had other sites show up on GA as sending tons of referral traffic and figured it was just spam, but not sure of the benefit to a spammer of sending ghost direct traffic unless it is some kind of negative SEO attack. Would love to find out.
-
try
http://sucuri.net/website-firewall/
or
Stop bot attack resulting in a more secure website. Stop bots
-
Google analytics has issue with ghost referrals and find out what the referral name is parking in the block it in GA
UA numbers ending in two and three are not effected for some reason
You're hosting company can update software in order to make this stop
hope this helps
Tom
-
I would strongly recommend Cloudflare to address this type of problem. They have massive data on malicious sources and offer tools to mitigate attacks like you're facing.
-
Have you tried digging deeper into the type of browser and OS they're emulating? Chances are you could get a pretty precise block on just their activity if you match up their browser, screen dimension, OS, versions, etc without affecting any other users.
Got a burning SEO question?
Subscribe to Moz Pro to gain full access to Q&A, answer questions, and ask your own.
Browse Questions
Explore more categories
-
Moz Tools
Chat with the community about the Moz tools.
-
SEO Tactics
Discuss the SEO process with fellow marketers
-
Community
Discuss industry events, jobs, and news!
-
Digital Marketing
Chat about tactics outside of SEO
-
Research & Trends
Dive into research and trends in the search industry.
-
Support
Connect on product support and feature requests.
Related Questions
-
Inbound links to internal search with pharma spam anchor text. Negative seo attack
Suddenly in October I had a spike on inbound links from forums and spams sites. Each one had setup hundreds of links. The links goes to WordPress internal search. Example: mysite.com/es/?s=⚄
White Hat / Black Hat SEO | | Arlinaite470 -
Malicious backlinks
Hello to everyone! We have identified some weird links that are pointing to our site and we are not sure if they are considered malicious backlinks and we should disavow them. Most of them are directories of websites, the most common one is called "Top million domains by alexa" (you can see an example here: www.besafe.in/domain-list-237). Have you ever seen these kind of links before? Are they causing harm to our site? Thank you so much!
White Hat / Black Hat SEO | | xaviplabor0 -
Massive Spam attack against my domain - automate disvow of tld?
We've been getting hundreds of new links from unique domains every day - all the domains follow a pattern like this: www.someword-1f4163e1.space/wiki/Someterm Hundreds... every day. What techniques exist to deal with a prolonged negative seo attack of this type. By the time we can detect and disvow, the damage is done.
White Hat / Black Hat SEO | | sonar0 -
Correct way to block search bots momentarily... HTTP 503?
Hi, What is the best way to block googlebot etc momentarily? For example, if I am implementing a programming update to our magento ecommerce platform and am unsure of the results and potential layout/ file changes that may impact SEO (Googlebot continuously spiders our site) How can you block the bots for like 30 mins or so? Thanks
White Hat / Black Hat SEO | | bjs20100 -
Negative SEO attack working amazingly on Google.ca
We have a client www.atvandtrailersales.com who recently (March) fell out of the rankings. We checked their backlink file and found over 100 spam links pointing at their website with terms like "uggboots" and "headwear" etc. etc. I submitted a disavow link file, as this was obviously an attack on the website. Since the recent Panda update, the client is back out of the rankings for a majority of keyword phrases. The disavow link file that was submitted back in march has 90% of the same links that are still spamming the website now. I've sent a spam report to Google and nothing has happened. I could submit a new disavow link file, but I'm not sure if this is worth the time. '.'< --Thanks!
White Hat / Black Hat SEO | | SmartWebPros1 -
Attacked with spam links.
Our website was hit with the "Pharma hack", "Google Cloaking Hack", or "Blackhat SEO Spam". and Google showed in the results this website may be compromised. After cleaning out the hack from the website I chacked with the Seomoz tool Open Site Explorer and I found that they hacked 1000 of other websites and created links to my website. They were building a few 1000 links to the website with the clickable text "buy cheap online pharmacy". and more like that. This website www.washington23.com has been hacked and gives over 200 links to your website for pharmacy items. And Google considers this from your impotent links as i can see in webmasters. What can I do about it?
White Hat / Black Hat SEO | | Joseph-Green-SEO0 -
Is OSE data reliable and removal of malicious inbound links?
I ran a report on my site (www.rentscouter.com) using OSE and it is reporting some very strange inbound links like: anchor text = Megan http://www.newswire.ca/en/releases/mmnr/smr/Paul_Henderson_Interview_Full_Clip_REVISED.f4v?m=pc&a=bookmarkList.view&target_user_id=1&search_type=tag&keyword=蒲田・大森・羽田周辺 http://www.newswire.ca/en/releases/mmnr/smr/Paul_Henderson_Interview_Full_Clip_REVISED.f4v?m=pc&a=bookmarkList.view&target_user_id=1&search_type=tag&keyword=熱闘!甲子園%2F高校野球ゲーム http://www.hawkeyesports.com/photos/schools/stan/sport/m-baskbl/04-05action/Thumbs.db?pages10=10&size=9?pk=1 anchor text = Alexa's Mom http://www.lg.com/it/products/documents/LE8800.epk?action=view&pageId=214&start=69164 http://www.michigan.gov/documents/techtalk/SEM-0601_191695_7.dot?blogname=mahdid&sub=5&tpl=0 anchor text = http://fansofdavid.com/wp-content/uploads/2011/03/4v5sh3k1.htm?seccion=busqarag_s&busq=Huesos&?seccion=basearag_c&id=3&?seccion=busqarag_s&busq=Huesos&?seccion=basearag_c&id=3&_pagi_pg=596 However, none of these seem to show up in my Google Webmaster account. And generally when I go to some of these links I can't find any reference to my site - is the OSE data bad or are these really shady links someone is building to knock down my site? What is showing up in GWT are a bunch of growing crappy links that redirect to some advertising site - does anyone know of a way to get these removed by Google as I doubt I'm going have any luck trying to contact the owner(s) of these sites: | http://harleydavidsonjacket.org/article/252213-best_penis_enlargement_methods.htm |
White Hat / Black Hat SEO | | BoulderJoe
| http://harleydavidsonjacket.org/article/252426-plumbers_and_gasfitters_needed_urgently.htm |
| http://harleydavidsonjacket.org/article/252451-the_importance_of_plumbers_and_more.htm |
| http://harleydavidsonjacket.org/article/253039-football_betting_systems_can_they_be_profitable.htm |
| http://harleydavidsonjacket.org/article/253131-my_teen_wants_to_know_how_sex_was_and_is_for_me_what_do_i_say.htm |
| http://harleydavidsonjacket.org/article/254364-why_marriage_counseling_is_good_for_you.htm |
| http://harleydavidsonjacket.org/article/254449-herpes_dating_service_what_is_it.htm | Yes, I know Google will theoretically and maybe eventually "ignore" such links, but that will be on Google time 4 weeks or 4 years - who knows. Plus, with a younger site with a thinner link profile - anything like the links above can't be helping me...... I'm trying to figure out why my site keeps bouncing between #5 and #255 for specific keywords and determining if I have a google penalty which is being discussed in this thread: http://www.seomoz.org/q/help-with-diagnosing-google-penalty0 -
HELP! My client got a DDOS Attack! Need advice
Here the setup: Server is hosted inhouse. It got attacked using a DDOS from 20+ IP addresses spoofing in different counries. Our server overloaded and didn't work anymore. URL is registered at GoDaddy. Signed up at Dreamhost. We pointed DNS to Dreamhost successfully. Attacks kept coming and messed up other sites on the Dreamhost shared server. We didn't know we were being followed at first. We originally thought they were attacking the IP address on our inhouse server. Dreamhost noticed the attack and put us on a seperate IP and disabled our URL until the attacks 'stopped'. MY QUESTION IS: What do I do if they don't stop? Close shop? 99% of the business is internet driven. This has to be the blackest Blackhat SEO ever.
White Hat / Black Hat SEO | | Francisco_Meza0