Spambot passing through anti-ddos protection

What is the name of the domain?

exammmmple.com

What is the issue you’re encountering

spambots logging into user forum accounts

What steps have you taken to resolve the issue?

despite anti-ddos nonstop, today a spambot managed to log into a forum user account to post spam related to criminal activities
IP : 195.206.110.166
AS134351 - Leaseweb Japan K.K. (hosting)

Steps taken priorly
I have enabled ddos mode nonstop
I have enabled “Bot Fight Mode” and “Block AI Bots”
I have a huge block list of hosting ASN in WAF
I have enabled captcha for known bots except my allowlist in WAF

Steps taken after spam
added the hosting ASN to blocklist in WAF

furthermore cloudflare logs show a recent and suspicious surge of traffic which might be related

Screenshot of the error

This topic was automatically closed after 15 days. New replies are no longer allowed.