
9/22/2023 · João Tomé
What this post added
This post analyzes traffic patterns to `exmaple.com`, a domain intentionally registered to capture typos of the reserved `example.com` domain. It details the volume and nature of traffic, identifying it as predominantly bot-related (99.99%) and often unencrypted HTTP. The analysis highlights specific Autonomous Systems (ASNs), such as Bouygues Telecom (AS5410), as major sources of this traffic, suggesting potential misconfigurations. It also notes the increasing use of IPv6 and generic user agents in this bot traffic, and touches upon the low percentage of traffic categorized as DDoS attacks. The post emphasizes the importance of identifying and resolving such misconfigurations for efficient and secure network operations.