
ABUSE.MOM — BEHAVE OR GET EXPOSED
| Signature | Description | Points | Severity |
|---|---|---|---|
| 404 ratio 40-60% | Majority of requests returned 404 — enumeration | +15 | |
| Danger medium hits: 4 | Medium-risk: admin panels, config files | +40 | |
| Directory Scan | Behavioral anomaly detected by automated analysis | +0 | |
| Foreign referer | Referer from unrelated external domain | +10 |
Reconstructed HTTP requests from server access logs. Target domains redacted for security.
* Typical request patterns for detected signatures. Actual target domains are redacted.
IP 107.173.185.208 is enumerating directories. Configure fail2ban apache-404 jail after 10+ 404 errors. Disable directory listings. Normalize all 404 responses.
Other blocked IPs from the same /24 subnet — indicates systematic abuse from this network range.
This IP was checked against major DNS-based blacklists used by mail servers and firewalls worldwide.
Checked: Spamhaus, SpamCop, Barracuda, SORBS, CBL, UCEProtect. Results may change over time.
107.173.185.208 has been assigned a threat score of 130/100 (Critical). This places it in the critical threat category. Immediate blocking is strongly advised across all network perimeters.
The following attack categories were identified:
107.173.185.208 is registered in Buffalo, United States, operating on the network of ColoCrossing. This IP first appeared in our threat feeds after triggering multiple behavioral detection signatures. During its 17-day observation window, we recorded 1,049 hostile requests from this IP — roughly 61.7 per day on average. Active path scanning has been detected — this IP probes for hundreds of common file and directory names. With 104 flagged addresses, United States represents a significant presence in our threat database. A score of 130/100 places this address in the top tier of severity. Block and investigate any historical connections.
Credential stuffing uses stolen username-password pairs from data breaches to attempt logins across many websites. Since users frequently reuse passwords, these automated attacks achieve success rates of 0.1-2%, which translates to thousands of compromised accounts from millions of attempts.
IPs originating from data centers and hosting providers account for a disproportionate amount of malicious traffic. Compromised VPS instances, bulletproof hosting, and abused trial accounts create persistent attack infrastructure that can be difficult to shut down.