Webmasters who removed large-scale spam infections from their website may sometimes have been subjected to a DDoS attack by Google's search engine crawling bot, also known as Googlebot.
This out-of-the-ordinary scenario has been discussed by researchers at Sucuri, who are warning webmasters and urging them to properly configure Google Search Console (formerly known as Webmasters Tools) before removing spam HTML files from their web host.
Sucuri staff noticed a recent spam campaign that compromised websites and left behind many HTML spam files. These files are harmless and do nothing more than redirect users to more dangerous websites.
Attackers drop tens or hundreds of thousands of such files in multiple directories of compromised websites. These HTML pages link to other insecure websites, creating an autonomous network of malicious websites that link to each other, with the sole purpose of gaining better SEO and climbing up Google search results.
The tactic is ancient, but Google is an automated system and some spam campaigns can influence search results using such outdated tricks.
In cases where webmasters notice the infections, Sucuri, a website security vendor, warns that removing all files at once without going through a specific sequence of steps can lead to two negative results.
One is a rapid drop in Google's PageRank, due to the high number of 404 errors that will appear from incorrectly removing unwanted HTML files.
The second is more dangerous and only occurs in certain cases, where it can accidentally lead to a DDoS attack from Googlebot if the appropriate settings are not made in Google Search Console.
In both cases, Sucuri has issued a series of steps that should be followed so that webmasters do not suffer further damage when cleaning their websites.

