
ABUSE.MOM — BEHAVE OR GET EXPOSED
| Signature | Description | Points | Severity |
|---|---|---|---|
| Directory Scan | Behavioral anomaly detected by automated analysis | +0 |
Reconstructed HTTP requests from server access logs. Target domains redacted for security.
* Typical request patterns for detected signatures. Actual target domains are redacted.
Add 89.22.230.26 to your firewall blocklist. Review logs for successful connections. Enable comprehensive logging on all public-facing services.
This IP was checked against major DNS-based blacklists used by mail servers and firewalls worldwide.
Checked: Spamhaus, SpamCop, Barracuda, SORBS, CBL, UCEProtect. Results may change over time.
89.22.230.26 has been assigned a threat score of 95/100 (Critical). This places it in the critical threat category. Immediate blocking is strongly advised across all network perimeters.
Our monitoring infrastructure has identified 89.22.230.26, geolocated to Stockholm, Sweden, operating on the network of xorek.cloud International LTD, as a source of suspicious network activity. Over a period of 21 days, this IP generated 1,132 malicious requests, averaging approximately 53.9 requests per day. Sweden currently accounts for 101 blocked IPs in our database, making it a significant source of malicious traffic. With a threat score of 95/100, this IP is among the most dangerous addresses in our database. Immediate and complete blocking is strongly recommended.
SSRF attacks trick servers into making requests to internal resources that should not be publicly accessible. This can expose cloud metadata endpoints, internal APIs, and private network services, potentially leading to full infrastructure compromise.
MFA dramatically reduces the effectiveness of credential-based attacks. Even when passwords are compromised through phishing or data breaches, the additional authentication factor prevents unauthorized access in the vast majority of cases.