http://lpoaj774fddyczsopqwpecbqanp243yjaz36bukhzqgafkmwlxrhhuqd.onion/posts/2024/07/zipbombing.html
Previously, what we had done was redirect things that looked like such bots (specifically, things requesting PHP or ASPX paths) onto one'a Hetzner's 10GB downloads on their speedtests sites. But, this seems even more effective, since we can make them download sth that unpacks into much more than 10GB (while having an innocuous content size at first).