
ABUSE.MOM — 规矩点,否则你将被曝光
| 签名 | 描述 | 分数 | 严重性 |
|---|---|---|---|
| Danger medium hits: 8 | 中等风险:管理面板、配置文件 | +60 | |
| 404 ratio 40-60% | 大多数请求返回404——目录枚举 | +15 | |
| Probe pattern 302->404 same path | 自动分析检测到行为异常 | +20 | |
| Foreign referer seen | 来自无关外部域名的Referer | +10 | |
| Danger medium hits: 6 | 中等风险:管理面板、配置文件 | +60 |
从服务器访问日志重建的HTTP请求。出于安全考虑,目标域名已隐藏。
* Typical request patterns for detected signatures. Actual target domains are redacted.
IP 107.172.55.124正在枚举目录。在10次以上404错误后配置fail2ban apache-404 jail。禁用目录列表。
来自同一/24子网的其他被封锁IP——表明该网络范围存在系统性滥用。
来自Shodan的网络侦察数据。开放端口可能表示正在运行的服务、错误配置或潜在的攻击面。
| Port | Service | Risk | Description |
|---|---|---|---|
| 80 | HTTP | Low | HTTP web server — standard web traffic |
| 1344 | Unknown | Low | Service on port 1344 |
| 3128 | Unknown | Low | Service on port 3128 |
| 8000 | Unknown | Low | Service on port 8000 |
| 8080 | HTTP-Alt | Low | HTTP alternative port — often used for admin panels or proxies |
| 8800 | Unknown | Low | Service on port 8800 |
| 21242 | Unknown | Low | Service on port 21242 |
| 52951 | Unknown | Low | Service on port 52951 |
| CVE ID | Link |
|---|---|
| CVE-2026-33515 | NVD → |
| CVE-2021-31806 | NVD → |
| CVE-2018-19131 | NVD → |
| CVE-2020-15049 | NVD → |
| CVE-2023-46728 | NVD → |
| CVE-2019-12522 | NVD → |
| CVE-2021-28116 | NVD → |
| CVE-2020-15810 | NVD → |
| CVE-2020-11945 | NVD → |
| CVE-2022-41318 | NVD → |
| CVE-2020-24606 | NVD → |
| CVE-2019-12520 | NVD → |
| CVE-2019-12519 | NVD → |
| CVE-2020-8449 | NVD → |
| CVE-2019-12523 | NVD → |
| CVE-2020-25097 | NVD → |
| CVE-2018-1000024 | NVD → |
| CVE-2023-46846 | NVD → |
| CVE-2021-31807 | NVD → |
| CVE-2019-12521 | NVD → |
| CVE-2020-8517 | NVD → |
| CVE-2016-10003 | NVD → |
| CVE-2016-10002 | NVD → |
| CVE-2018-1000027 | NVD → |
| CVE-2025-59362 | NVD → |
🔴 此主机有59个已知CVE与其暴露的服务相关联。如此大量的漏洞强烈表明软件严重过时。 请在NVD数据库中查看每个CVE的详细信息。
数据来源:Shodan InternetDB。独立于abuse.mom进行扫描。
该IP已通过全球邮件服务器和防火墙使用的主要DNS黑名单进行检查。
已检查:Spamhaus、SpamCop、Barracuda、SORBS、CBL、UCEProtect。
107.172.55.124 has been assigned a threat score of 105/100 (Critical). 这代表着极高风险等级。我们的检测系统已从该地址标记出多个高置信度的恶意意图指标。
The following attack categories were identified:
IP地址107.172.55.124已追溯至Los Angeles, United States,运营在HostPapa的网络中。我们的威胁检测系统根据观察到的恶意行为模式标记了此地址。 在12天的时间内,此IP产生了5次恶意请求,平均每天约0.4次请求。 该地址被归类为住宅,意味着它可能属于终端用户ISP连接。来自住宅IP的恶意活动通常表明设备已被入侵或属于僵尸网络。 该IP表现出目录枚举行为,系统地请求不存在的路径以发现隐藏文件和配置错误的资源。 我们的记录显示来自United States的201个恶意IP,使其成为全球威胁活动的重要贡献者。 评分105/100将此地址置于最高严重性级别。应封锁并调查任何历史连接。
This IP is classified as residential, suggesting it may belong to a compromised home device, IoT botnet member, or an infected personal computer. Residential IPs involved in attacks often indicate malware infection without the owner's knowledge.
Credential stuffing uses stolen username-password pairs from data breaches to attempt logins across many websites. Since users frequently reuse passwords, these automated attacks achieve success rates of 0.1-2%, which translates to thousands of compromised accounts from millions of attempts.
Deepfake audio and video enable convincing impersonation of executives and trusted individuals. Real-time voice cloning has been used in successful fraud campaigns, adding a new dimension to social engineering that traditional security training does not address.