
ABUSE.MOM — BEHAVE OR GET EXPOSED
| Signature | Description | Points | Severity |
|---|---|---|---|
| Directory Scan | Behavioral anomaly detected by automated analysis | +0 |
Reconstructed HTTP requests from server access logs. Target domains redacted for security.
* Typical request patterns for detected signatures. Actual target domains are redacted.
Add 89.221.204.71 to your firewall blocklist. Review logs for successful connections. Enable comprehensive logging on all public-facing services.
Other blocked IPs from the same /24 subnet — indicates systematic abuse from this network range.
This IP was checked against major DNS-based blacklists used by mail servers and firewalls worldwide.
Checked: Spamhaus, SpamCop, Barracuda, SORBS, CBL, UCEProtect. Results may change over time.
89.221.204.71 has been assigned a threat score of 65/100 (High). This classifies it as a high-severity threat. Proactive blocking is recommended for sensitive infrastructure.
89.221.204.71 is registered in Moscow, Russia, operating on the network of Time-host LTD. This IP first appeared in our threat feeds after triggering multiple behavioral detection signatures. During its 4-day observation window, we recorded 648 hostile requests from this IP — roughly 162 per day on average. The address operates as a VPN/proxy exit node. Attackers route traffic through anonymizing services to obscure their real location and evade IP-based security controls. Our records show 113 malicious IPs originating from Russia, positioning it as a significant contributor to global threat activity. The score of 65/100 warrants active monitoring and rate-limiting. Full blocking is advisable for sensitive systems.
This IP is associated with a VPN or proxy service. Attackers frequently route their traffic through anonymizing services to obscure their true location. This makes attribution more challenging but the malicious behavior patterns remain detectable.
Machine learning models analyze vast amounts of network traffic to identify attack patterns invisible to rule-based systems. Supervised models classify known attack types while unsupervised models detect anomalies that may indicate novel threats.
Network telescopes monitor large blocks of unused IP address space. Since no legitimate traffic should reach these addresses, all observed traffic represents scanning, backscatter from spoofed attacks, or misconfiguration — providing pure signal for threat analysis.