
ABUSE.MOM — BEHAVE OR GET EXPOSED
| Signature | Description | Points | Severity |
|---|---|---|---|
| 404 ratio 40-60% | Majority of requests returned 404 — enumeration | +15 | |
| Burst 101/10s | Abnormally fast request rate — automated scanning | +35 | |
| Burst 102/10s | Abnormally fast request rate — automated scanning | +35 | |
| Burst 105/10s | Abnormally fast request rate — automated scanning | +35 | |
| Burst 106/10s | Abnormally fast request rate — automated scanning | +35 | |
| Burst 108/10s | Abnormally fast request rate — automated scanning | +35 | |
| Burst 109/10s | Abnormally fast request rate — automated scanning | +35 | |
| Burst 111/10s | Abnormally fast request rate — automated scanning | +35 | |
| Burst 112/10s | Abnormally fast request rate — automated scanning | +35 | |
| Burst 113/10s | Abnormally fast request rate — automated scanning | +35 | |
| Burst 12/10s | Abnormally fast request rate — automated scanning | +35 | |
| Burst 12/2s | Abnormally fast request rate — automated scanning | +35 | |
| Burst 124/10s | Abnormally fast request rate — automated scanning | +35 | |
| Burst 129/10s | Abnormally fast request rate — automated scanning | +35 | |
| Burst 28/2s | Abnormally fast request rate — automated scanning | +35 | |
| Burst 29/2s | Abnormally fast request rate — automated scanning | +35 | |
| Burst 30/2s | Abnormally fast request rate — automated scanning | +35 | |
| Burst 32/2s | Abnormally fast request rate — automated scanning | +35 | |
| Burst 33/2s | Abnormally fast request rate — automated scanning | +35 | |
| Burst 34/2s | Abnormally fast request rate — automated scanning | +35 | |
| Burst 35/2s | Abnormally fast request rate — automated scanning | +35 | |
| Burst 36/2s | Abnormally fast request rate — automated scanning | +35 | |
| Burst 37/2s | Abnormally fast request rate — automated scanning | +35 | |
| Burst 38/2s | Abnormally fast request rate — automated scanning | +35 | |
| Burst 39/2s | Abnormally fast request rate — automated scanning | +35 | |
| Burst 41/2s | Abnormally fast request rate — automated scanning | +35 | |
| Burst 42/10s | Abnormally fast request rate — automated scanning | +35 | |
| Burst 66/10s | Abnormally fast request rate — automated scanning | +35 | |
| Burst 77/10s | Abnormally fast request rate — automated scanning | +35 | |
| Burst 78/10s | Abnormally fast request rate — automated scanning | +35 | |
| Burst 83/10s | Abnormally fast request rate — automated scanning | +35 | |
| Burst 86/10s | Abnormally fast request rate — automated scanning | +35 | |
| Burst 89/10s | Abnormally fast request rate — automated scanning | +35 | |
| Burst 96/10s | Abnormally fast request rate — automated scanning | +35 | |
| Danger medium hits: 1 | Medium-risk: admin panels, config files | +10 | |
| Danger medium hits: 105 | Medium-risk: admin panels, config files | +60 | |
| Danger medium hits: 108 | Medium-risk: admin panels, config files | +60 | |
| Danger medium hits: 11 | Medium-risk: admin panels, config files | +60 | |
| Danger medium hits: 156 | Medium-risk: admin panels, config files | +60 | |
| Danger medium hits: 158 | Medium-risk: admin panels, config files | +60 | |
| Danger medium hits: 167 | Medium-risk: admin panels, config files | +60 | |
| Danger medium hits: 2 | Medium-risk: admin panels, config files | +20 | |
| Danger medium hits: 201 | Medium-risk: admin panels, config files | +60 | |
| Danger medium hits: 202 | Medium-risk: admin panels, config files | +60 | |
| Danger medium hits: 204 | Medium-risk: admin panels, config files | +60 | |
| Danger medium hits: 205 | Medium-risk: admin panels, config files | +60 | |
| Danger medium hits: 28 | Medium-risk: admin panels, config files | +60 | |
| Danger medium hits: 30 | Medium-risk: admin panels, config files | +60 | |
| Danger medium hits: 431 | Medium-risk: admin panels, config files | +60 | |
| Danger medium hits: 50 | Medium-risk: admin panels, config files | +60 | |
| Danger medium hits: 63 | Medium-risk: admin panels, config files | +60 | |
| Danger medium hits: 81 | Medium-risk: admin panels, config files | +60 | |
| Danger medium hits: 82 | Medium-risk: admin panels, config files | +60 | |
| Danger medium hits: 84 | Medium-risk: admin panels, config files | +60 | |
| Danger strong hits: 1 | High-risk paths: shells, RCE vectors, exploits | +25 | |
| Danger strong hits: 10 | High-risk paths: shells, RCE vectors, exploits | +100 | |
| Danger strong hits: 12 | High-risk paths: shells, RCE vectors, exploits | +100 | |
| Danger strong hits: 15 | High-risk paths: shells, RCE vectors, exploits | +100 | |
| Danger strong hits: 16 | High-risk paths: shells, RCE vectors, exploits | +100 | |
| Danger strong hits: 18 | High-risk paths: shells, RCE vectors, exploits | +100 | |
| Danger strong hits: 2 | High-risk paths: shells, RCE vectors, exploits | +50 | |
| Danger strong hits: 24 | High-risk paths: shells, RCE vectors, exploits | +100 | |
| Danger strong hits: 28 | High-risk paths: shells, RCE vectors, exploits | +100 | |
| Danger strong hits: 3 | High-risk paths: shells, RCE vectors, exploits | +75 | |
| Danger strong hits: 4 | High-risk paths: shells, RCE vectors, exploits | +100 | |
| Danger strong hits: 6 | High-risk paths: shells, RCE vectors, exploits | +100 | |
| Danger strong hits: 8 | High-risk paths: shells, RCE vectors, exploits | +100 | |
| Danger strong hits: 9 | High-risk paths: shells, RCE vectors, exploits | +100 | |
| Probe 302→404 | Behavioral anomaly detected by automated analysis | +20 | |
| UA suspicious | Behavioral anomaly detected by automated analysis | +15 |
Reconstructed HTTP requests from server access logs. Target domains redacted for security.
* Typical request patterns for detected signatures. Actual target domains are redacted.
IP 158.158.76.106 is enumerating directories. Configure fail2ban apache-404 jail after 10+ 404 errors. Disable directory listings. Normalize all 404 responses.
Implement limit_req_zone in nginx. Deploy CDN with DDoS protection. Configure SYN cookies and connection tracking to throttle 158.158.76.106.
Address UA spoofing from 158.158.76.106: maintain blocklist of known malicious UA strings, require consistent UA across sessions, implement TLS fingerprinting.
This IP was checked against major DNS-based blacklists used by mail servers and firewalls worldwide.
Checked: Spamhaus, SpamCop, Barracuda, SORBS, CBL, UCEProtect. Results may change over time.
158.158.76.106 has been assigned a threat score of 280/100 (Critical). This is a critical-level threat. Systems administrators should treat this IP as hostile and block all inbound connections without exception.
The following attack categories were identified:
The address 158.158.76.106 originates from Madrid, Spain, operating on the network of Microsoft Corporation. It was identified through automated analysis of incoming network traffic across monitored endpoints. During its 4-day observation window, we recorded 2,985 hostile requests from this IP — roughly 746.3 per day on average. Classified as a hosting IP, this address likely runs on a rented server or cloud instance. Attackers prefer datacenter IPs for their high bandwidth and disposable nature. With 3 different attack patterns detected, this IP exhibits behavior characteristic of advanced automated scanning frameworks. At 280/100, this is an extremely high-risk address. All traffic should be considered hostile.
This IP belongs to a hosting or data center provider. Malicious traffic from hosting infrastructure often originates from compromised VPS instances, rented servers used for scanning campaigns, or abused free-tier cloud accounts. Hosting providers typically respond to abuse reports within 24-72 hours.
Distributed denial of service attacks overwhelm infrastructure with traffic volume. Effective mitigation combines always-on traffic scrubbing, anycast network distribution, rate limiting, and the ability to quickly scale absorption capacity during attacks.
CAPTCHAs remain a primary bot defense but face increasing bypass rates from AI-powered solvers. Modern alternatives include invisible behavioral analysis, proof-of-work challenges, and device fingerprinting that detect bots without impacting user experience.