
ABUSE.MOM — BEHAVE OR GET EXPOSED
| Signature | Description | Points | Severity |
|---|---|---|---|
| Burst 13/2s | Abnormally fast request rate — automated scanning | +35 | |
| Burst 15/2s | Abnormally fast request rate — automated scanning | +35 | |
| Burst 34/10s | Abnormally fast request rate — automated scanning | +35 | |
| Burst 48/10s | Abnormally fast request rate — automated scanning | +35 | |
| Danger medium hits: 31 | Medium-risk: admin panels, config files | +60 | |
| Danger medium hits: 40 | Medium-risk: admin panels, config files | +60 | |
| Danger medium hits: 71 | Medium-risk: admin panels, config files | +60 | |
| Danger strong hits: 11 | High-risk paths: shells, RCE vectors, exploits | +100 | |
| Danger strong hits: 19 | High-risk paths: shells, RCE vectors, exploits | +100 | |
| Danger strong hits: 8 | High-risk paths: shells, RCE vectors, exploits | +100 |
Reconstructed HTTP requests from server access logs. Target domains redacted for security.
* Typical request patterns for detected signatures. Actual target domains are redacted.
Implement limit_req_zone in nginx. Deploy CDN with DDoS protection. Configure SYN cookies and connection tracking to throttle 104.215.156.39.
This IP was checked against major DNS-based blacklists used by mail servers and firewalls worldwide.
Checked: Spamhaus, SpamCop, Barracuda, SORBS, CBL, UCEProtect. Results may change over time.
104.215.156.39 has been assigned a threat score of 230/100 (Critical). With this rating, the IP falls into the critical severity bracket — among the most dangerous addresses in our monitoring database.
The following attack categories were identified:
104.215.156.39 is registered in Singapore, Singapore, operating on the network of Microsoft Corporation. This IP first appeared in our threat feeds after triggering multiple behavioral detection signatures. The address has been active for 2 days in our monitoring system, producing 241 flagged requests at a rate of ~120.5/day. Operating from datacenter infrastructure, this IP is typical of addresses used in organized attack operations. Cloud and VPS providers are commonly exploited as launching platforms for automated scanning. Rate-based attacks from this IP aim to overwhelm server resources through high-volume request flooding. Singapore currently accounts for 101 blocked IPs in our database, making it a significant source of malicious traffic. A score of 230/100 places this address in the top tier of severity. Block and investigate any historical connections.
This IP belongs to a hosting or data center provider. Malicious traffic from hosting infrastructure often originates from compromised VPS instances, rented servers used for scanning campaigns, or abused free-tier cloud accounts. Hosting providers typically respond to abuse reports within 24-72 hours.
Distributed denial of service attacks overwhelm infrastructure with traffic volume. Effective mitigation combines always-on traffic scrubbing, anycast network distribution, rate limiting, and the ability to quickly scale absorption capacity during attacks.
Processing IP addresses for security purposes under GDPR requires balancing legitimate interest in network protection with data minimization principles. Threat intelligence platforms must implement appropriate retention policies and provide mechanisms for data subject rights.