
ABUSE.MOM — BEHAVE OR GET EXPOSED
| Signature | Description | Points | Severity |
|---|---|---|---|
| UA suspicious (short/empty) | Behavioral anomaly detected by automated analysis | +15 | |
| Danger strong hits: 2 | High-risk paths: shells, RCE vectors, exploits | +50 | |
| Danger medium hits: 2 | Medium-risk: admin panels, config files | +20 |
Reconstructed HTTP requests from server access logs. Target domains redacted for security.
* Typical request patterns for detected signatures. Actual target domains are redacted.
Address UA spoofing from 209.97.189.148: maintain blocklist of known malicious UA strings, require consistent UA across sessions, implement TLS fingerprinting.
Network reconnaissance data from Shodan. Open ports may indicate running services, misconfigurations, or potential attack surfaces.
| Port | Service | Risk | Description |
|---|---|---|---|
| 22 | SSH | Low | Secure Shell — common brute force target for remote access |
| 23 | Telnet | Critical | Telnet — unencrypted remote access, extremely dangerous if exposed |
| 26 | Unknown | Low | Service on port 26 |
| 66 | Unknown | Low | Service on port 66 |
| 79 | Unknown | Low | Service on port 79 |
| 80 | HTTP | Low | HTTP web server — standard web traffic |
| 104 | Unknown | Low | Service on port 104 |
| 110 | POP3 | Low | Service on port 110 |
| 340 | Unknown | Low | Service on port 340 |
| 400 | Unknown | Low | Service on port 400 |
| 443 | HTTPS | Low | HTTPS web server — encrypted web traffic |
| 1022 | Unknown | Low | Service on port 1022 |
| 1028 | Unknown | Low | Service on port 1028 |
| 1443 | Unknown | Low | Service on port 1443 |
| 1833 | Unknown | Low | Service on port 1833 |
| 2232 | Unknown | Low | Service on port 2232 |
| 2443 | Unknown | Low | Service on port 2443 |
| 4433 | Unknown | Low | Service on port 4433 |
| 4840 | Unknown | Low | Service on port 4840 |
| 5010 | Unknown | Low | Service on port 5010 |
| 5100 | Unknown | Low | Service on port 5100 |
| 5229 | Unknown | Low | Service on port 5229 |
| 5242 | Unknown | Low | Service on port 5242 |
| 5609 | Unknown | Low | Service on port 5609 |
| 6440 | Unknown | Low | Service on port 6440 |
| 6633 | Unknown | Low | Service on port 6633 |
| 8008 | Unknown | Low | Service on port 8008 |
| 8080 | HTTP-Alt | Low | HTTP alternative port — often used for admin panels or proxies |
| 8121 | Unknown | Low | Service on port 8121 |
| 8142 | Unknown | Low | Service on port 8142 |
| 8800 | Unknown | Low | Service on port 8800 |
| 9242 | Unknown | Low | Service on port 9242 |
| 9930 | Unknown | Low | Service on port 9930 |
| 9999 | Unknown | Low | Service on port 9999 |
| 45000 | Unknown | Low | Service on port 45000 |
⚠️ Network scanning reveals 1 dangerous service exposed on 209.97.189.148. Telnet (23) transmits credentials in plaintext — likely a compromised IoT device. These services should not be publicly accessible without strict firewall rules.
Data source: Shodan InternetDB. Scanned independently of abuse.mom.
This IP was checked against major DNS-based blacklists used by mail servers and firewalls worldwide.
Checked: Spamhaus, SpamCop, Barracuda, SORBS, CBL, UCEProtect. Results may change over time.
209.97.189.148 has been assigned a threat score of 85/100 (Critical). With this rating, the IP falls into the critical severity bracket — among the most dangerous addresses in our monitoring database.
The following attack categories were identified:
Our monitoring infrastructure has identified 209.97.189.148, geolocated to Slough, United Kingdom, operating on the network of DigitalOcean, LLC, as a source of suspicious network activity. Over a period of 1 days, this IP generated 1 malicious requests, averaging approximately 1 requests per day. This address belongs to a datacenter or cloud hosting provider. Hosting IPs are frequently leveraged by threat actors who rent cheap VPS instances specifically for conducting attacks. The IP exhibits User-Agent manipulation, switching between different browser identities or sending empty headers. Our records show 103 malicious IPs originating from United Kingdom, positioning it as a significant contributor to global threat activity. The score of 85/100 indicates a confirmed malicious actor. Network-level blocking is appropriate.
This IP belongs to a hosting or data center provider. Malicious traffic from hosting infrastructure often originates from compromised VPS instances, rented servers used for scanning campaigns, or abused free-tier cloud accounts. Hosting providers typically respond to abuse reports within 24-72 hours.
Analyzing User-Agent strings reveals automated tools masquerading as legitimate browsers. Inconsistencies between claimed browser capabilities and actual behavior, impossible version combinations, and known scanner signatures help identify malicious clients.
Hacktivism combines hacking skills with political or social motivations. DDoS campaigns, website defacements, and data leaks target organizations based on ideological disagreements, adding unpredictable threat actors to the landscape.