What is this strange traffic?

I've started seeing some strange traffic hitting my server for the past few days and I'm at a loss as to what it could be. None of the domains they're requesting in the Host field belong to me. I have configured nginx to return a 444 for all requests to the "default" server:

server {
listen 80 default_server;

server_name _;
server_tokens off;

return 444;
}

Has anybody else seen traffic like this before?

122.193.148.55 - "glassellparknc.com" [28/Dec/2019:02:36:40 -0700] "GET HTTP://glassellparknc.com:80/ HTTP/1.1" 444 0 "http://glassellparknc.com/" "Mozilla/5.0(compatible;MSIE9.0;WindowsNT6.1;Trident/5.0)"

180.126.50.81 - "realhouse.co.jp" [28/Dec/2019:03:28:58 -0700] "GET HTTP://realhouse.co.jp:80/ HTTP/1.1" 444 0 "http://realhouse.co.jp/" "Mozilla/5.0(compatible;MSIE9.0;WindowsNT6.1;Trident/5.0)"

183.199.86.195 - "www.2cto.com" [28/Dec/2019:03:32:46 -0700] "GET HTTP://www.2cto.com:80/kf/201408/324874.html HTTP/1.1" 444 0 "http://www.2cto.com/kf/201408/324874.html" "Mozilla/5.0(compatible;MSIE9.0;WindowsNT6.1;Trident/5.0)"

113.93.126.19 - "2.110.106.231" [28/Dec/2019:03:34:27 -0700] "GET HTTP://2.110.106.231:80/ HTTP/1.1" 444 0 "http://2.110.106.231/" "Mozilla/5.0(compatible;MSIE9.0;WindowsNT6.1;Trident/5.0)"

211.138.139.106 - "www.jiemian.com" [28/Dec/2019:03:36:05 -0700] "GET HTTP://www.jiemian.com:80/article/1251687.html HTTP/1.1" 444 0 "http://www.jiemian.com/article/1251687.html" "Mozilla/5.0(compatible;MSIE9.0;WindowsNT6.1;Trident/5.0)"

39.154.5.8 - "www.vengstunet.no" [28/Dec/2019:03:37:17 -0700] "GET HTTP://www.vengstunet.no:80/ HTTP/1.1" 444 0 "http://www.vengstunet.no/" "Mozilla/5.0(compatible;MSIE9.0;WindowsNT6.1;Trident/5.0)"

120.242.61.252 - "www.conexx-video.de" [28/Dec/2019:04:30:12 -0700] "GET HTTP://www.conexx-video.de:80/ HTTP/1.1" 444 0 "http://www.conexx-video.de/" "Mozilla/5.0(compatible;MSIE9.0;WindowsNT6.1;Trident/5.0)"

27.216.236.155 - "hi.tobacco.com.cn" [28/Dec/2019:04:31:22 -0700] "GET HTTP://hi.tobacco.com.cn:80/ HTTP/1.1" 444 0 "http://hi.tobacco.com.cn/" "Mozilla/5.0(compatible;MSIE9.0;WindowsNT6.1;Trident/5.0)"

183.199.195.222 - "www.byronjwu.com" [28/Dec/2019:04:34:18 -0700] "GET HTTP://www.byronjwu.com:80/ HTTP/1.1" 444 0 "http://www.byronjwu.com/" "Mozilla/5.0(compatible;MSIE9.0;WindowsNT6.1;Trident/5.0)"

114.217.96.197 - "www.szczyrk.info.pl" [28/Dec/2019:04:35:33 -0700] "GET HTTP://www.szczyrk.info.pl:80/ HTTP/1.1" 444 0 "http://www.szczyrk.info.pl/" "Mozilla/5.0(compatible;MSIE9.0;WindowsNT6.1;Trident/5.0)"

101.69.200.13 - "minimals.jp" [28/Dec/2019:04:37:03 -0700] "GET HTTP://minimals.jp:80/ HTTP/1.1" 444 0 "http://minimals.jp/" "Mozilla/5.0(compatible;MSIE9.0;WindowsNT6.1;Trident/5.0)"

115.60.175.227 - "chria.com.br" [28/Dec/2019:04:37:43 -0700] "GET HTTP://chria.com.br:80/ HTTP/1.1" 444 0 "http://chria.com.br/" "Mozilla/5.0(compatible;MSIE9.0;WindowsNT6.1;Trident/5.0)"

219.129.181.237 - "reseaupiscine.com" [28/Dec/2019:05:45:51 -0700] "GET HTTP://reseaupiscine.com:80/ HTTP/1.1" 444 0 "http://reseaupiscine.com/" "Mozilla/5.0(compatible;MSIE9.0;WindowsNT6.1;Trident/5.0)"

122.192.151.41 - "www.zeffire.com" [28/Dec/2019:05:50:47 -0700] "GET HTTP://www.zeffire.com:80/ HTTP/1.1" 444 0 "http://www.zeffire.com/" "Mozilla/5.0(compatible;MSIE9.0;WindowsNT6.1;Trident/5.0)"

49.88.211.61 - "www.bangboer.net" [28/Dec/2019:05:52:03 -0700] "GET HTTP://www.bangboer.net:80/news/show29548.html HTTP/1.1" 444 0 "http://www.bangboer.net/news/show29548.html" "Mozilla/5.0(compatible;MSIE9.0;WindowsNT6.1;Trident/5.0)"

112.111.184.16 - "www.checkwebhosting.com" [28/Dec/2019:05:56:48 -0700] "GET HTTP://www.checkwebhosting.com:80/ HTTP/1.1" 444 0 "http://www.checkwebhosting.com/" "Mozilla/5.0(compatible;MSIE9.0;WindowsNT6.1;Trident/5.0)"

101.30.26.36 - "lncy.com" [28/Dec/2019:05:58:51 -0700] "GET HTTP://lncy.com:80/ HTTP/1.1" 444 0 "http://lncy.com/" "Mozilla/5.0(compatible;MSIE9.0;WindowsNT6.1;Trident/5.0)"

112.3.39.189 - "www.latimers.com" [28/Dec/2019:06:15:32 -0700] "GET HTTP://www.latimers.com:80/ HTTP/1.1" 444 0 "http://www.latimers.com/" "Mozilla/5.0(compatible;MSIE9.0;WindowsNT6.1;Trident/5.0)"

116.26.8.139 - "www.chenxingprinting.com" [28/Dec/2019:07:04:10 -0700] "GET HTTP://www.chenxingprinting.com:80/ HTTP/1.1" 444 0 "http://www.chenxingprinting.com/" "Mozilla/5.0(compatible;MSIE9.0;WindowsNT6.1;Trident/5.0)"

117.31.178.14 - "wiggiesdolls.com" [28/Dec/2019:07:07:54 -0700] "GET HTTP://wiggiesdolls.com:80/ HTTP/1.1" 444 0 "http://wiggiesdolls.com/" "Mozilla/5.0(compatible;MSIE9.0;WindowsNT6.1;Trident/5.0)"

180.103.216.156 - "www.shdrq.com" [28/Dec/2019:08:00:48 -0700] "GET HTTP://www.shdrq.com:80/ HTTP/1.1" 444 0 "http://www.shdrq.com/" "Mozilla/5.0(compatible;MSIE9.0;WindowsNT6.1;Trident/5.0)"

112.111.185.12 - "glasscockinc.com" [28/Dec/2019:08:06:14 -0700] "GET HTTP://glasscockinc.com:80/ HTTP/1.1" 444 0 "http://glasscockinc.com/" "Mozilla/5.0(compatible;MSIE9.0;WindowsNT6.1;Trident/5.0)"

117.94.195.187 - "www.80p.net" [28/Dec/2019:08:08:52 -0700] "GET HTTP://www.80p.net:80/ HTTP/1.1" 444 0 "http://www.80p.net/" "Mozilla/5.0(compatible;MSIE9.0;WindowsNT6.1;Trident/5.0)"

113.58.239.173 - "123.125.114.144" [28/Dec/2019:08:47:10 -0700] "HEAD http://123.125.114.144/ HTTP/1.1" 444 0 "-" "Mozilla/5.01682558 Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US) AppleWebKit/537.36(KHTML, like Gecko) Chrome/40.0.2214.89 Safari/537.36"

112.0.15.70 - "www.gdpsj.cn" [28/Dec/2019:09:00:18 -0700] "GET HTTP://www.gdpsj.cn:80/ HTTP/1.1" 444 0 "http://www.gdpsj.cn/" "Mozilla/5.0(compatible;MSIE9.0;WindowsNT6.1;Trident/5.0)"

140.237.112.117 - "www.jamiekay.co.uk" [28/Dec/2019:10:08:12 -0700] "GET HTTP://www.jamiekay.co.uk:80/ HTTP/1.1" 444 0 "http://www.jamiekay.co.uk/" "Mozilla/5.0(compatible;MSIE9.0;WindowsNT6.1;Trident/5.0)"

36.40.234.115 - "stevelam.org" [28/Dec/2019:10:12:40 -0700] "GET HTTP://stevelam.org:80/ HTTP/1.1" 444 0 "http://stevelam.org/" "Mozilla/5.0(compatible;MSIE9.0;WindowsNT6.1;Trident/5.0)"

110.246.8.164 - "ordoszx.gov.cn" [28/Dec/2019:10:14:42 -0700] "GET HTTP://ordoszx.gov.cn:80/zxyw/201410/t20141017_1238354.html HTTP/1.1" 444 0 "http://ordoszx.gov.cn/zxyw/201410/t20141017_1238354.html" "Mozilla/5.0(compatible;MSIE9.0;WindowsNT6.1;Trident/5.0)"

119.134.46.200 - "scottsternthal.com" [28/Dec/2019:10:16:59 -0700] "GET HTTP://scottsternthal.com:80/ HTTP/1.1" 444 0 "http://scottsternthal.com/" "Mozilla/5.0(compatible;MSIE9.0;WindowsNT6.1;Trident/5.0)"

124.67.17.23 - "www.select-holding.com" [28/Dec/2019:10:21:39 -0700] "GET HTTP://www.select-holding.com:80/index.html HTTP/1.1" 444 0 "http://www.select-holding.com/index.html" "Mozilla/5.0(compatible;MSIE9.0;WindowsNT6.1;Trident/5.0)"

112.32.80.121 - "wowot.com" [28/Dec/2019:10:21:49 -0700] "GET HTTP://wowot.com:80/ HTTP/1.1" 444 0 "http://wowot.com/" "Mozilla/5.0(compatible;MSIE9.0;WindowsNT6.1;Trident/5.0)"

119.114.50.254 - "www.paul-andrew.com" [28/Dec/2019:10:23:58 -0700] "GET HTTP://www.paul-andrew.com:80/ HTTP/1.1" 444 0 "http://www.paul-andrew.com/" "Mozilla/5.0(compatible;MSIE9.0;WindowsNT6.1;Trident/5.0)"

183.251.115.17 - "3171100.com" [28/Dec/2019:10:26:37 -0700] "GET HTTP://3171100.com:80/ HTTP/1.1" 444 0 "http://3171100.com/" "Mozilla/5.0(compatible;MSIE9.0;WindowsNT6.1;Trident/5.0)"

113.58.239.119 - "123.125.114.144" [28/Dec/2019:10:55:04 -0700] "HEAD http://123.125.114.144/ HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:45.0) Gecko/20100101 Firefox/45.0"

183.2.115.190 - "www.countrygrindquarterly.com" [28/Dec/2019:11:31:29 -0700] "GET HTTP://www.countrygrindquarterly.com:80/ HTTP/1.1" 444 0 "http://www.countrygrindquarterly.com/" "Mozilla/5.0(compatible;MSIE9.0;WindowsNT6.1;Trident/5.0)"

1 Reply

That looks like traffic designed to see how your web server will respond to spurious or invalid requests. Misconfigured servers can give up information about how they're configured in such cases, which can be the start of an attack.

Reply

Please enter an answer
Tips:

You can mention users to notify them: @username

You can use Markdown to format your question. For more examples see the Markdown Cheatsheet.

> I’m a blockquote.

I’m a blockquote.

[I'm a link] (https://www.google.com)

I'm a link

**I am bold** I am bold

*I am italicized* I am italicized

Community Code of Conduct