
ABUSE.MOM — BEHAVE OR GET EXPOSED
| Signature | Description | Points | Severity |
|---|---|---|---|
| UA bot: python | Known bot/crawler User-Agent detected | +40 | |
| Danger strong hits: 1 | High-risk paths: shells, RCE vectors, exploits | +25 | |
| Danger medium hits: 1 | Medium-risk: admin panels, config files | +10 | |
| POST requests present | Behavioral anomaly detected by automated analysis | +8 |
Reconstructed HTTP requests from server access logs. Target domains redacted for security.
* Typical request patterns for detected signatures. Actual target domains are redacted.
IP 171.225.157.57 shows suspicious UA behavior. Block empty User-Agent requests. Implement JavaScript-based bot detection for sensitive endpoints.
Network reconnaissance data from Shodan. Open ports may indicate running services, misconfigurations, or potential attack surfaces.
| Port | Service | Risk | Description |
|---|---|---|---|
| 80 | HTTP | Low | HTTP web server — standard web traffic |
| 2000 | Unknown | Low | Service on port 2000 |
| 8291 | MikroTik | High | MikroTik Winbox — router management, targeted by VPNFilter malware |
| 8545 | Unknown | Low | Service on port 8545 |
| 8563 | Unknown | Low | Service on port 8563 |
| 8568 | Unknown | Low | Service on port 8568 |
| 8570 | Unknown | Low | Service on port 8570 |
| 8575 | Unknown | Low | Service on port 8575 |
| 8580 | Unknown | Low | Service on port 8580 |
| 8582 | Unknown | Low | Service on port 8582 |
| 8587 | Unknown | Low | Service on port 8587 |
| 8593 | Unknown | Low | Service on port 8593 |
| 8594 | Unknown | Low | Service on port 8594 |
| 8630 | Unknown | Low | Service on port 8630 |
| 8649 | Unknown | Low | Service on port 8649 |
| 8707 | Unknown | Low | Service on port 8707 |
| 8728 | Unknown | Low | Service on port 8728 |
| 8732 | Unknown | Low | Service on port 8732 |
| 8743 | Unknown | Low | Service on port 8743 |
| 8745 | Unknown | Low | Service on port 8745 |
| 9595 | Unknown | Low | Service on port 9595 |
| 9600 | Unknown | Low | Service on port 9600 |
| 9611 | Unknown | Low | Service on port 9611 |
| 9674 | Unknown | Low | Service on port 9674 |
| 9696 | Unknown | Low | Service on port 9696 |
| 9704 | Unknown | Low | Service on port 9704 |
⚠️ 1 high-risk port detected on 171.225.157.57. These services should not be publicly accessible without strict firewall rules.
Data source: Shodan InternetDB. Scanned independently of abuse.mom.
This IP was checked against major DNS-based blacklists used by mail servers and firewalls worldwide.
Checked: Spamhaus, SpamCop, Barracuda, SORBS, CBL, UCEProtect. Results may change over time.
171.225.157.57 has been assigned a threat score of 83/100 (Critical). This represents a critical risk level. Our detection systems have flagged multiple high-confidence indicators of malicious intent from this address.
The following attack categories were identified:
Network traffic from 171.225.157.57, located in Da Nang, Vietnam, operating on the network of Viettel Corporation, has been classified as malicious by our automated threat scoring engine. Our sensors captured 1 malicious requests from this address across a 1-day span, reflecting a sustained attack cadence of ~1 requests per day. This residential IP is likely a compromised consumer device. Home routers and IoT equipment with default credentials are prime targets for botnet operators. Detected suspicious User-Agent anomalies including empty, forged, or rapidly rotating UA strings — characteristic of automated scanning tools. Vietnam currently accounts for 154 blocked IPs in our database, making it a significant source of malicious traffic. A threat score of 83/100 places this IP in the high-risk category. Blocking at the firewall level is recommended.
This IP is classified as residential, suggesting it may belong to a compromised home device, IoT botnet member, or an infected personal computer. Residential IPs involved in attacks often indicate malware infection without the owner's knowledge.
Analyzing User-Agent strings reveals automated tools masquerading as legitimate browsers. Inconsistencies between claimed browser capabilities and actual behavior, impossible version combinations, and known scanner signatures help identify malicious clients.
Residential proxies route traffic through real home internet connections, making malicious traffic appear to come from legitimate users. Some networks install proxy software bundled with free applications, unknowingly conscripting millions of devices.