ABUSE.MOM
THREAT REPORT

IP Threat Report
196.242.20.201

ABUSE.MOM — BEHAVE OR GET EXPOSED

Generated: 2026-05-22 14:06:18
First seen: 2026-03-13 05:00:05
Last seen: 2026-03-17 13:00:05
65

⛔ Verdict: BLOCK

This IP address has been classified as a source of malicious automated activity. Threat score: 65/100. Total malicious requests observed: 16.

DANGER_PATHRATIO_404REDIRECT_PROBEREFERER
01

Geolocation & Classification

IP Address
196.242.20.201
Type
Residential
Country
🇿🇦 South Africa
City
Pretoria
ISP
Orion Network Limited
Organization
Fiber Grid
Autonomous System
AS41564 Orion Network Limited
Hit Count
16
02

Detection Signatures

SignatureDescriptionPointsSeverity
Danger medium hits: 2Medium-risk: admin panels, config files+20
404 ratio 40-60%Majority of requests returned 404 — enumeration+15
Probe pattern 302->404 same pathBehavioral anomaly detected by automated analysis+20
Foreign referer seenReferer from unrelated external domain+10
Σ = 65
03

Observed Activity

Reconstructed HTTP requests from server access logs. Target domains redacted for security.

[redacted]
GET
/
200
Requests shown: 1 · HTTP 404: 0 · Dangerous patterns: 0

* Typical request patterns for detected signatures. Actual target domains are redacted.

04

Timeline

2026-03-13 05:00:05
First malicious request detected
IP entered monitoring from server access logs
During observation
Multiple detection signatures triggered
Danger medium hits: 2 (+20), 404 ratio 40-60% (+15), Probe pattern 302->404 same path (+20)
2026-03-17 13:00:05
Last malicious request observed
Total score reached: 65/100
Next cycle
IP blocked — all subsequent requests denied (HTTP 403)
Added to blocklist automatically
05

Network Provider

Orion Network Limited
AS41564 · 🇿🇦 South Africa
06

Recommendations

Actions taken & recommended

  • IP 196.242.20.201 is blocked at application level (HTTP 403)
  • Consider blocking at firewall level (iptables/CSF) to reduce server load
  • Other malicious IPs detected in the same /24 subnet — consider blocking 196.242.20.0/24
  • Report abuse to the network provider via their abuse contact
  • Ensure sensitive files (.env, .git, backups) are not accessible from the web

🔎 Path Enumeration Protection

Block scanning from 196.242.20.201: rate-limit 404 responses per IP, deploy a honeypot 404 page, ensure no backup files are web-accessible.

07

Neighbors in 196.242.20.0/24

Other blocked IPs from the same /24 subnet — indicates systematic abuse from this network range.

08

Open Ports & Services

Network reconnaissance data from Shodan. Open ports may indicate running services, misconfigurations, or potential attack surfaces.

OPEN PORTS (3)
PortServiceRiskDescription
80HTTPLowHTTP web server — standard web traffic
7777UnknownLowService on port 7777
55555UnknownLowService on port 55555

Data source: Shodan InternetDB. Scanned independently of abuse.mom.

09

Blacklist Status (DNSBL)

This IP was checked against major DNS-based blacklists used by mail servers and firewalls worldwide.

✓ Clean
Spamhaus ZEN

Checked: Spamhaus, SpamCop, Barracuda, SORBS, CBL, UCEProtect. Results may change over time.

10

Threat Analysis

196.242.20.201 has been assigned a threat score of 65/100 (High). This score indicates high threat severity. The IP has shown clear patterns of malicious behavior that warrant immediate defensive measures.

The following attack categories were identified:

Path Enumeration

📊 Threat Analysis

IP address 196.242.20.201 has been traced to Pretoria, South Africa, operating on the network of Orion Network Limited. Our threat detection systems have flagged this address based on observed malicious behavior patterns. Our sensors captured 16 malicious requests from this address across a 4-day span, reflecting a sustained attack cadence of ~4 requests per day. This is a residential IP address, suggesting a compromised home device such as a router, smart appliance, or infected workstation participating in a botnet. The IP exhibits directory enumeration behavior, systematically requesting non-existent paths to discover hidden files and misconfigured resources. Our records show 101 malicious IPs originating from South Africa, positioning it as a significant contributor to global threat activity. The score of 65/100 warrants active monitoring and rate-limiting. Full blocking is advisable for sensitive systems.

This IP is classified as residential, suggesting it may belong to a compromised home device, IoT botnet member, or an infected personal computer. Residential IPs involved in attacks often indicate malware infection without the owner's knowledge.

11

Related Threats

🇿🇦 Top threats from South Africa

94.156.152.43 (340)94.156.152.15 (305)34.35.89.136 (245)185.203.122.106 (210)34.35.135.91 (195)View all →

🏢 Same network: AS41564

89.251.0.24 (295)89.251.0.128 (295)89.251.0.26 (280)89.251.0.123 (270)89.251.0.110 (255)View all →
12

Security Intelligence

💡 HTTP Request Smuggling

Request smuggling exploits differences in how front-end and back-end servers parse HTTP requests. This technique can bypass security controls, poison web caches, and hijack other users sessions by desynchronizing request boundaries.

💡 Data Center IP Reputation

IPs originating from data centers and hosting providers account for a disproportionate amount of malicious traffic. Compromised VPS instances, bulletproof hosting, and abused trial accounts create persistent attack infrastructure that can be difficult to shut down.

🔍 Check Any IP Address

Share this report: