
ABUSE.MOM — BEHAVE OR GET EXPOSED
| Signature | Description | Points | Severity |
|---|---|---|---|
| UA changed for same IP | Multiple User-Agents — bot rotation technique | +25 | |
| Danger strong hits: 167 | High-risk paths: shells, RCE vectors, exploits | +100 | |
| Danger medium hits: 217 | Medium-risk: admin panels, config files | +60 | |
| Burst: 35 req / 2s | Abnormally fast request rate — automated scanning | +35 | |
| Burst: 128 req / 10s | Abnormally fast request rate — automated scanning | +35 | |
| Danger strong hits: 144 | High-risk paths: shells, RCE vectors, exploits | +100 | |
| Danger medium hits: 422 | Medium-risk: admin panels, config files | +60 | |
| Burst: 36 req / 2s | Abnormally fast request rate — automated scanning | +35 | |
| Burst: 132 req / 10s | Abnormally fast request rate — automated scanning | +35 | |
| Danger strong hits: 232 | High-risk paths: shells, RCE vectors, exploits | +100 | |
| Danger medium hits: 336 | Medium-risk: admin panels, config files | +60 | |
| Burst: 34 req / 2s | Abnormally fast request rate — automated scanning | +35 | |
| Burst: 124 req / 10s | Abnormally fast request rate — automated scanning | +35 | |
| Danger strong hits: 98 | High-risk paths: shells, RCE vectors, exploits | +100 | |
| Burst: 127 req / 10s | Abnormally fast request rate — automated scanning | +35 | |
| Danger strong hits: 231 | High-risk paths: shells, RCE vectors, exploits | +100 | |
| Danger strong hits: 102 | High-risk paths: shells, RCE vectors, exploits | +100 | |
| Danger medium hits: 335 | Medium-risk: admin panels, config files | +60 | |
| Danger strong hits: 78 | High-risk paths: shells, RCE vectors, exploits | +100 | |
| Danger medium hits: 293 | Medium-risk: admin panels, config files | +60 | |
| Danger strong hits: 10 | High-risk paths: shells, RCE vectors, exploits | +100 | |
| Danger medium hits: 153 | Medium-risk: admin panels, config files | +60 | |
| Danger strong hits: 9 | High-risk paths: shells, RCE vectors, exploits | +100 | |
| Danger medium hits: 152 | Medium-risk: admin panels, config files | +60 | |
| Burst: 129 req / 10s | Abnormally fast request rate — automated scanning | +35 |
Reconstructed HTTP requests from server access logs. Target domains redacted for security.
* Typical request patterns for detected signatures. Actual target domains are redacted.
Address UA spoofing from 151.245.116.148: maintain blocklist of known malicious UA strings, require consistent UA across sessions, implement TLS fingerprinting.
Implement limit_req_zone in nginx. Deploy CDN with DDoS protection. Configure SYN cookies and connection tracking to throttle 151.245.116.148.
Other blocked IPs from the same /24 subnet — indicates systematic abuse from this network range.
Network reconnaissance data from Shodan. Open ports may indicate running services, misconfigurations, or potential attack surfaces.
| Port | Service | Risk | Description |
|---|---|---|---|
| 1443 | Unknown | Low | Service on port 1443 |
| 4000 | Unknown | Low | Service on port 4000 |
| 7443 | Unknown | Low | Service on port 7443 |
Data source: Shodan InternetDB. Scanned independently of abuse.mom.
This IP was checked against major DNS-based blacklists used by mail servers and firewalls worldwide.
Checked: Spamhaus, SpamCop, Barracuda, SORBS, CBL, UCEProtect. Results may change over time.
151.245.116.148 has been assigned a threat score of 255/100 (Critical). This represents a critical risk level. Our detection systems have flagged multiple high-confidence indicators of malicious intent from this address.
The following attack categories were identified:
The address 151.245.116.148 originates from Tirana, AL, operating on the network of Cyberzone S.A.. It was identified through automated analysis of incoming network traffic across monitored endpoints. The address has been active for 1 days in our monitoring system, producing 10 flagged requests at a rate of ~10/day. The address is classified as residential, meaning it likely belongs to an end-user ISP connection. Malicious activity from residential IPs typically indicates device compromise or botnet membership. The dual attack vectors of User-Agent Anomaly combined with Request Flooding indicate a coordinated assault rather than opportunistic scanning. AL currently accounts for 61 blocked IPs in our database, making it a notable source of malicious traffic. A score of 255/100 places this address in the top tier of severity. Block and investigate any historical connections.
This IP is classified as residential, suggesting it may belong to a compromised home device, IoT botnet member, or an infected personal computer. Residential IPs involved in attacks often indicate malware infection without the owner's knowledge.
Examining HTTP headers beyond User-Agent reveals attack tools and automated scripts. Missing standard headers, unusual ordering, non-standard values, and inconsistencies with claimed client identity all serve as reliable detection signals.
Correlating logs across web servers, firewalls, DNS, and authentication systems reveals attack patterns invisible in individual log sources. Modern SIEM platforms use statistical analysis to connect related events across time and systems.