
ABUSE.MOM — BEHAVE OR GET EXPOSED
| Signature | Description | Points | Severity |
|---|---|---|---|
| 404 ratio 40-60% | Majority of requests returned 404 — enumeration | +15 | |
| Burst 18/2s | Abnormally fast request rate — automated scanning | +35 | |
| Burst 20/2s | Abnormally fast request rate — automated scanning | +35 | |
| Burst 21/2s | Abnormally fast request rate — automated scanning | +35 | |
| Burst 56/10s | Abnormally fast request rate — automated scanning | +35 | |
| Burst 62/10s | Abnormally fast request rate — automated scanning | +35 | |
| Burst 63/10s | Abnormally fast request rate — automated scanning | +35 | |
| Burst 64/10s | Abnormally fast request rate — automated scanning | +35 | |
| Burst 66/10s | Abnormally fast request rate — automated scanning | +35 | |
| Danger medium hits: 261 | Medium-risk: admin panels, config files | +60 | |
| Danger medium hits: 522 | Medium-risk: admin panels, config files | +60 | |
| Danger medium hits: 786 | Medium-risk: admin panels, config files | +60 | |
| Danger strong hits: 164 | High-risk paths: shells, RCE vectors, exploits | +100 | |
| Danger strong hits: 44 | High-risk paths: shells, RCE vectors, exploits | +100 | |
| Danger strong hits: 88 | High-risk paths: shells, RCE vectors, exploits | +100 | |
| Probe 302→404 | Behavioral anomaly detected by automated analysis | +20 | |
| UA suspicious | Behavioral anomaly detected by automated analysis | +15 |
Reconstructed HTTP requests from server access logs. Target domains redacted for security.
* Typical request patterns for detected signatures. Actual target domains are redacted.
IP 74.249.224.76 is enumerating directories. Configure fail2ban apache-404 jail after 10+ 404 errors. Disable directory listings. Normalize all 404 responses.
Implement limit_req_zone in nginx. Deploy CDN with DDoS protection. Configure SYN cookies and connection tracking to throttle 74.249.224.76.
IP 74.249.224.76 shows suspicious UA behavior. Block empty User-Agent requests. Implement JavaScript-based bot detection for sensitive endpoints.
This IP was checked against major DNS-based blacklists used by mail servers and firewalls worldwide.
Checked: Spamhaus, SpamCop, Barracuda, SORBS, CBL, UCEProtect. Results may change over time.
74.249.224.76 has been assigned a threat score of 280/100 (Critical). A score this high marks a critical threat actor. This address has demonstrated persistent, aggressive malicious behavior across multiple detection vectors.
The following attack categories were identified:
Network traffic from 74.249.224.76, located in Des Moines, United States, operating on the network of Microsoft Corporation, has been classified as malicious by our automated threat scoring engine. During its 7-day observation window, we recorded 754 hostile requests from this IP — roughly 107.7 per day on average. The IP is classified as hosting/datacenter infrastructure, commonly associated with rented servers used for automated attack campaigns, botnet command-and-control, or vulnerability scanning at scale. With 3 different attack patterns detected, this IP exhibits behavior characteristic of advanced automated scanning frameworks. With 108 flagged addresses, United States represents a significant presence in our threat database. A score of 280/100 places this address in the top tier of severity. Block and investigate any historical connections.
This IP belongs to a hosting or data center provider. Malicious traffic from hosting infrastructure often originates from compromised VPS instances, rented servers used for scanning campaigns, or abused free-tier cloud accounts. Hosting providers typically respond to abuse reports within 24-72 hours.
Distributed denial of service attacks overwhelm infrastructure with traffic volume. Effective mitigation combines always-on traffic scrubbing, anycast network distribution, rate limiting, and the ability to quickly scale absorption capacity during attacks.
Nation-state actors conduct sophisticated campaigns for espionage, sabotage, and influence operations. Their resources exceed typical criminal organizations, enabling zero-day exploitation, long-term persistent access, and attacks on critical infrastructure.