I am working on an e-commerce website... there is a bot that keeps creating new users on our website... All the users belong to allmelbet.com and all of them have exactly the same first name and last name:
Williamemink WilliameminkQK
The signup process to the our website is quite standard... they can either create an account with Facebook/Google or they need to enter an email address and click on the confirmation link send to their email... all of these suspicious accounts are created using the latter option.
I don't understand why they are creating so many accounts... if they were interested in scraping the website data, they did not need to create an account... creating account is a requirement when someone wants to list (sell) something on the e-commerce website... these users have not created any listing (so far)...
Questions:
Has anyone experienced this? Is this a known attack? Or just a scrapping bot, who would create a new account before scraping?
How can I prevent this? Is there a built-in mechanism in AWS Shield to block this domain?