ABUSE.MOM
THREAT REPORT

IP Threat Report
223.73.39.31

ABUSE.MOM — BEHAVE OR GET EXPOSED

Generated: 2026-05-30 08:54:42
First seen: 2026-03-07 06:00:05
Last seen: 2026-03-10 10:00:06
70

⛔ Verdict: BLOCK

This IP address has been classified as a source of malicious automated activity. Threat score: 70/100. Total malicious requests observed: 8.

DANGER_PATHREFERERREDIRECT_PROBE
01

Geolocation & Classification

IP Address
223.73.39.31
Type
Mobile
Country
🇨🇳 China
City
Dongguan
ISP
China Mobile communications corporation
Organization
China Mobile
Autonomous System
AS9808 China Mobile Communications Group Co., Ltd.
Hit Count
8
02

Detection Signatures

SignatureDescriptionPointsSeverity
Danger medium hits: 6Medium-risk: admin panels, config files+60
Foreign referer seenReferer from unrelated external domain+10
Danger medium hits: 2Medium-risk: admin panels, config files+20
Probe pattern 302->404 same pathBehavioral anomaly detected by automated analysis+20
Σ = 110
03

Observed Activity

Reconstructed HTTP requests from server access logs. Target domains redacted for security.

[redacted]
GET
/
200
Requests shown: 1 · HTTP 404: 0 · Dangerous patterns: 0

* Typical request patterns for detected signatures. Actual target domains are redacted.

04

Timeline

2026-03-07 06:00:05
First malicious request detected
IP entered monitoring from server access logs
During observation
Multiple detection signatures triggered
Danger medium hits: 6 (+60), Foreign referer seen (+10), Danger medium hits: 2 (+20)
2026-03-10 10:00:06
Last malicious request observed
Total score reached: 70/100
Next cycle
IP blocked — all subsequent requests denied (HTTP 403)
Added to blocklist automatically
05

Network Provider

China Mobile communications corporation
AS9808 · 🇨🇳 China
06

Recommendations

Actions taken & recommended

  • IP 223.73.39.31 is blocked at application level (HTTP 403)
  • Consider blocking at firewall level (iptables/CSF) to reduce server load
  • Report abuse to the network provider via their abuse contact
  • Ensure sensitive files (.env, .git, backups) are not accessible from the web

🔎 Path Enumeration Protection

Block scanning from 223.73.39.31: rate-limit 404 responses per IP, deploy a honeypot 404 page, ensure no backup files are web-accessible.

09

Blacklist Status (DNSBL)

This IP was checked against major DNS-based blacklists used by mail servers and firewalls worldwide.

⛔ LISTED
Spamhaus ZEN

Checked: Spamhaus, SpamCop, Barracuda, SORBS, CBL, UCEProtect. Results may change over time.

10

Threat Analysis

223.73.39.31 has been assigned a threat score of 70/100 (High). The IP is rated as a high-level threat. Network administrators should implement blocking rules and monitor for any connections from this address.

The following attack categories were identified:

Path Enumeration

📊 Threat Analysis

Our monitoring infrastructure has identified 223.73.39.31, geolocated to Dongguan, China, operating on the network of China Mobile communications corporation, as a source of suspicious network activity. The address has been active for 3 days in our monitoring system, producing 8 flagged requests at a rate of ~2.7/day. The address belongs to a mobile carrier network. The sustained pattern of malicious requests indicates either a compromised device or deliberate abuse. Active path scanning has been detected — this IP probes for hundreds of common file and directory names. China currently accounts for 166 blocked IPs in our database, making it a significant source of malicious traffic. At 70/100, this IP warrants immediate defensive action.

11

Related Threats

🇨🇳 Top threats from China

180.184.55.222 (340)117.50.120.215 (235)115.191.1.205 (235)123.58.16.244 (235)43.142.47.248 (230)View all →

🏢 Same network: AS9808

183.207.48.161 (230)36.212.132.184 (220)117.156.171.166 (200)112.51.229.143 (180)36.138.252.97 (170)View all →
12

Security Intelligence

💡 HTTP Request Smuggling

Request smuggling exploits differences in how front-end and back-end servers parse HTTP requests. This technique can bypass security controls, poison web caches, and hijack other users sessions by desynchronizing request boundaries.

💡 CAPTCHA and Bot Detection

CAPTCHAs remain a primary bot defense but face increasing bypass rates from AI-powered solvers. Modern alternatives include invisible behavioral analysis, proof-of-work challenges, and device fingerprinting that detect bots without impacting user experience.

🔍 Check Any IP Address

Share this report: