
ABUSE.MOM — BEHAVE OR GET EXPOSED
| Signature | Description | Points | Severity |
|---|---|---|---|
| Directory Scan | Behavioral anomaly detected by automated analysis | +0 |
Reconstructed HTTP requests from server access logs. Target domains redacted for security.
* Typical request patterns for detected signatures. Actual target domains are redacted.
Block 64.137.37.205 at the network perimeter. Implement defense-in-depth combining IP blocking with application-layer protections.
This IP was checked against major DNS-based blacklists used by mail servers and firewalls worldwide.
Checked: Spamhaus, SpamCop, Barracuda, SORBS, CBL, UCEProtect. Results may change over time.
64.137.37.205 has been assigned a threat score of 60/100 (High). At this threat level, the IP is considered high risk. Firewall rules should be updated to deny traffic from this source.
Threat intelligence analysis has linked 64.137.37.205 to malicious activity originating from Santiago, CL, operating on the network of Latitude.sh. The address has been under observation since its initial detection. The address has been active for 14 days in our monitoring system, producing 202 flagged requests at a rate of ~14.4/day. Our records show 86 malicious IPs originating from CL, positioning it as a notable contributor to global threat activity. The score of 60/100 warrants active monitoring and rate-limiting. Full blocking is advisable for sensitive systems.
GraphQL APIs introduce specific vulnerabilities including introspection information disclosure, query complexity attacks, batching abuse, and authorization bypass through nested queries. Depth limiting, cost analysis, and field-level authorization address these GraphQL-specific threats.
Blocking traffic from specific countries reduces attack surface but impacts legitimate international users. Effective geo-based policies use tiered approaches — blocking, rate limiting, or requiring additional verification based on risk assessment.