
ABUSE.MOM — BEHAVE OR GET EXPOSED
| Signature | Description | Points | Severity |
|---|---|---|---|
| 404 ratio 40-60% | Majority of requests returned 404 — enumeration | +15 | |
| Burst: 5 req / 2s | Abnormally fast request rate — automated scanning | +35 | |
| Foreign referer seen | Referer from unrelated external domain | +10 |
Reconstructed HTTP requests from server access logs. Target domains redacted for security.
* Typical request patterns for detected signatures. Actual target domains are redacted.
Block scanning from 149.88.27.85: rate-limit 404 responses per IP, deploy a honeypot 404 page, ensure no backup files are web-accessible.
Implement limit_req_zone in nginx. Deploy CDN with DDoS protection. Configure SYN cookies and connection tracking to throttle 149.88.27.85.
Network reconnaissance data from Shodan. Open ports may indicate running services, misconfigurations, or potential attack surfaces.
| Port | Service | Risk | Description |
|---|---|---|---|
| 443 | HTTPS | Low | HTTPS web server — encrypted web traffic |
| 444 | Unknown | Low | Service on port 444 |
| 3000 | Unknown | Low | Service on port 3000 |
| 3001 | Unknown | Low | Service on port 3001 |
| 3009 | Unknown | Low | Service on port 3009 |
| 3011 | Unknown | Low | Service on port 3011 |
| 3012 | Unknown | Low | Service on port 3012 |
| 3015 | Unknown | Low | Service on port 3015 |
| 3016 | Unknown | Low | Service on port 3016 |
| 3021 | Unknown | Low | Service on port 3021 |
| 3030 | Unknown | Low | Service on port 3030 |
| 3047 | Unknown | Low | Service on port 3047 |
| 3048 | Unknown | Low | Service on port 3048 |
| 3049 | Unknown | Low | Service on port 3049 |
| 3050 | Unknown | Low | Service on port 3050 |
| 3051 | Unknown | Low | Service on port 3051 |
| 3053 | Unknown | Low | Service on port 3053 |
| 3054 | Unknown | Low | Service on port 3054 |
| 3055 | Unknown | Low | Service on port 3055 |
| 3056 | Unknown | Low | Service on port 3056 |
| 3063 | Unknown | Low | Service on port 3063 |
| 3065 | Unknown | Low | Service on port 3065 |
| 3066 | Unknown | Low | Service on port 3066 |
| 3067 | Unknown | Low | Service on port 3067 |
| 3076 | Unknown | Low | Service on port 3076 |
| 3077 | Unknown | Low | Service on port 3077 |
| 3078 | Unknown | Low | Service on port 3078 |
| 3081 | Unknown | Low | Service on port 3081 |
| 3089 | Unknown | Low | Service on port 3089 |
| 3092 | Unknown | Low | Service on port 3092 |
| 3093 | Unknown | Low | Service on port 3093 |
| 3095 | Unknown | Low | Service on port 3095 |
| 3098 | Unknown | Low | Service on port 3098 |
| 3099 | Unknown | Low | Service on port 3099 |
| 3100 | Unknown | Low | Service on port 3100 |
| 3221 | Unknown | Low | Service on port 3221 |
| 3260 | Unknown | Low | Service on port 3260 |
| 3268 | Unknown | Low | Service on port 3268 |
| 3269 | Unknown | Low | Service on port 3269 |
| 3299 | Unknown | Low | Service on port 3299 |
| 4000 | Unknown | Low | Service on port 4000 |
| 4001 | Unknown | Low | Service on port 4001 |
| 4002 | Unknown | Low | Service on port 4002 |
| 4021 | Unknown | Low | Service on port 4021 |
| 4022 | Unknown | Low | Service on port 4022 |
| 4040 | Unknown | Low | Service on port 4040 |
| 4042 | Unknown | Low | Service on port 4042 |
| 4064 | Unknown | Low | Service on port 4064 |
| 4095 | Unknown | Low | Service on port 4095 |
| 4100 | Unknown | Low | Service on port 4100 |
Data source: Shodan InternetDB. Scanned independently of abuse.mom.
This IP was checked against major DNS-based blacklists used by mail servers and firewalls worldwide.
Checked: Spamhaus, SpamCop, Barracuda, SORBS, CBL, UCEProtect. Results may change over time.
149.88.27.85 has been assigned a threat score of 60/100 (High). This classifies it as a high-severity threat. Proactive blocking is recommended for sensitive infrastructure.
The following attack categories were identified:
Network traffic from 149.88.27.85, located in Zurich, Switzerland, operating on the network of Datacamp Limited, has been classified as malicious by our automated threat scoring engine. Our sensors captured 1 malicious requests from this address across a 1-day span, reflecting a sustained attack cadence of ~1 requests per day. Operating from a residential network, this IP may represent a compromised home gateway or IoT device that has been drafted into a larger attack infrastructure. Two attack patterns were identified (Path Enumeration and Request Flooding), suggesting a semi-automated campaign that targets multiple vulnerabilities. With 101 flagged addresses, Switzerland represents a significant presence in our threat database. At 60/100, this IP presents a meaningful threat. Implement rate limiting with escalation to blocking.
This IP is classified as residential, suggesting it may belong to a compromised home device, IoT botnet member, or an infected personal computer. Residential IPs involved in attacks often indicate malware infection without the owner's knowledge.
Distributed denial of service attacks overwhelm infrastructure with traffic volume. Effective mitigation combines always-on traffic scrubbing, anycast network distribution, rate limiting, and the ability to quickly scale absorption capacity during attacks.
Border Gateway Protocol hijacking allows attackers to redirect internet traffic through their infrastructure. While less common than application-level attacks, BGP hijacks can intercept sensitive data, inject malware, or cause widespread service disruption.