
ABUSE.MOM — BEHAVE OR GET EXPOSED
| Signature | Description | Points | Severity |
|---|---|---|---|
| Directory Scan | Behavioral anomaly detected by automated analysis | +0 |
Reconstructed HTTP requests from server access logs. Target domains redacted for security.
* Typical request patterns for detected signatures. Actual target domains are redacted.
Block 220.167.233.157 at the network perimeter. Implement defense-in-depth combining IP blocking with application-layer protections.
Other blocked IPs from the same /24 subnet — indicates systematic abuse from this network range.
This IP was checked against major DNS-based blacklists used by mail servers and firewalls worldwide.
Checked: Spamhaus, SpamCop, Barracuda, SORBS, CBL, UCEProtect. Results may change over time.
220.167.233.157 has been assigned a threat score of 60/100 (High). The IP is rated as a high-level threat. Network administrators should implement blocking rules and monitor for any connections from this address.
The address 220.167.233.157 originates from Xining, China, operating on the network of China Telecom. It was identified through automated analysis of incoming network traffic across monitored endpoints. Over a period of 16 days, this IP generated 245 malicious requests, averaging approximately 15.3 requests per day. China currently accounts for 114 blocked IPs in our database, making it a significant source of malicious traffic. At 60/100, this IP presents a meaningful threat. Implement rate limiting with escalation to blocking.
Mobile malware reaches devices through unofficial app stores, malicious links, and even occasionally through official stores using obfuscation techniques. Banking trojans, spyware, and ransomware variants specifically designed for mobile platforms continue to proliferate.
BEC attacks use compromised or spoofed executive email accounts to request fraudulent wire transfers or sensitive data. These attacks cause billions in annual losses and rely on social engineering rather than technical exploitation.