Do they comeback? If so then they detect it and avoid it. If not then they crashed and mission accomplished.
Secondly, I know that most of these bots do not come back. The attacks do not reuse addresses against the same server in order to evade almost any conceivable filter rule that is predicated on a prior visit.
> as soon as an IP address is logged as having visited the trap URL (honeypot, or zipbomb or whatever), a log monitoring script bans that client.
Is this not why they aren’t getting the full file?
124.243.178.242 - - [29/Apr/2025:00:16:52 -0700] "GET /cgit/[...]
94.74.94.113 - - [29/Apr/2025:00:07:01 -0700] "GET /honeypot/[...]
Notice the second timestamp is almost ten minutes earlier.