For the past few days my Aliyun CDN has been alerting constantly — traffic and request counts suddenly spike, triggering automatic shutdown. After analyzing the access logs, I found the requests mainly came from IPs in the following areas, all hammering a single image on my CDN:
- Laishan District, Yantai, Shandong
- Zhifu District, Yantai, Shandong
- Hanjiang District, Yangzhou, Jiangsu
Massive concurrent requests for one image in an instant — very much like a CC or DDoS attack. I routed traffic to Cloudflare via DNS, but no use! Yes — this attack traffic doesn’t go through DNS resolution at all; it keeps hammering the Aliyun CDN directly. It looks very much like a targeted attack, but DDoSing or CC-ing my CDN makes no sense — if they were attacking my website, I’d at least understand. So I concluded this isn’t a vendetta: my download traffic is being scraped by PCDN nodes.
PCDN enforcement has gotten strict lately. Previously, PCDN was flagged by the upload/download traffic ratio — people running PCDN had to inflate their download numbers after uploading too much, and plenty of webmasters got caught in the crossfire. Nowadays it seems they only look at upload traffic, not the ratio, so I don’t know why [Yantai] and [Yangzhou] Telecom lines are still scraping like this.
The only fix is banning the IP ranges. Based on my CDN access logs, here are the offending ranges. List last updated: 2025-06-15.
43.254.192.0/22
49.71.66.0/24
49.86.114.0/24
49.86.201.0/24
49.86.208.0/24
58.220.4.0/24
58.220.40.0/24
114.230.5.0/24
114.230.138.0/24
117.91.119.0/24
117.91.214.0/24
121.233.152.0/22
121.233.221.0/24
121.233.227.0/24
123.169.44.0/22
140.75.192.0/23
180.103.51.0/24
180.119.10.0/24
180.119.194.0/24
182.34.2.0/22
182.34.108.0/22
218.90.199.0/24
218.91.18.0/24
218.91.77.0/24
218.91.112.0/24
240e:00e9:b00c:0001:0000:0000:0000:0000/64