
ABUSE.MOM — BEHAVE OR GET EXPOSED
| Signature | Description | Points | Severity |
|---|---|---|---|
| Directory Scan | Behavioral anomaly detected by automated analysis | +0 |
Reconstructed HTTP requests from server access logs. Target domains redacted for security.
* Typical request patterns for detected signatures. Actual target domains are redacted.
Add 157.0.147.175 to your firewall blocklist. Review logs for successful connections. Enable comprehensive logging on all public-facing services.
Other blocked IPs from the same /24 subnet — indicates systematic abuse from this network range.
This IP was checked against major DNS-based blacklists used by mail servers and firewalls worldwide.
Checked: Spamhaus, SpamCop, Barracuda, SORBS, CBL, UCEProtect. Results may change over time.
157.0.147.175 has been assigned a threat score of 80/100 (Critical). This places it in the critical threat category. Immediate blocking is strongly advised across all network perimeters.
Network traffic from 157.0.147.175, located in Suzhou, China, operating on the network of China Unicom Jiangsu Province Network, has been classified as malicious by our automated threat scoring engine. The address has been active for 20 days in our monitoring system, producing 1,315 flagged requests at a rate of ~65.8/day. China currently accounts for 110 blocked IPs in our database, making it a significant source of malicious traffic. At 80/100, this IP warrants immediate defensive action.
Modern phishing operations use sophisticated infrastructure including lookalike domains, valid TLS certificates, and evasion techniques like cloaking and geofencing. Analyzing this infrastructure reveals campaigns before they reach their targets.
Subdomain takeover occurs when DNS records point to decommissioned services. Attackers claim the abandoned resource and serve content under the trusted domain, enabling cookie theft, phishing, and reputation damage.