
ABUSE.MOM — 规矩点,否则你将被曝光
| 签名 | 描述 | 分数 | 严重性 |
|---|---|---|---|
| Danger medium hits: 4 | 中等风险:管理面板、配置文件 | +40 | |
| Probe pattern 302->404 same path | 自动分析检测到行为异常 | +20 | |
| Foreign referer seen | 来自无关外部域名的Referer | +10 |
从服务器访问日志重建的HTTP请求。出于安全考虑,目标域名已隐藏。
* Typical request patterns for detected signatures. Actual target domains are redacted.
IP 163.172.31.86正在枚举目录。在10次以上404错误后配置fail2ban apache-404 jail。禁用目录列表。
来自Shodan的网络侦察数据。开放端口可能表示正在运行的服务、错误配置或潜在的攻击面。
| Port | Service | Risk | Description |
|---|---|---|---|
| 53 | DNS | Low | DNS server — potential for DNS amplification attacks |
| 80 | HTTP | Low | HTTP web server — standard web traffic |
| 111 | Unknown | Low | Service on port 111 |
| 143 | IMAP | Low | Service on port 143 |
| 443 | HTTPS | Low | HTTPS web server — encrypted web traffic |
| 465 | Unknown | Low | Service on port 465 |
| 993 | IMAPS | Low | Service on port 993 |
| 2082 | Unknown | Low | Service on port 2082 |
| 2086 | Unknown | Low | Service on port 2086 |
| 2087 | Unknown | Low | Service on port 2087 |
| 4190 | Unknown | Low | Service on port 4190 |
| 8443 | HTTPS-Alt | Low | Service on port 8443 |
数据来源:Shodan InternetDB。独立于abuse.mom进行扫描。
该IP已通过全球邮件服务器和防火墙使用的主要DNS黑名单进行检查。
已检查:Spamhaus、SpamCop、Barracuda、SORBS、CBL、UCEProtect。
163.172.31.86 has been assigned a threat score of 70/100 (High). 这将其归类为高严重性威胁。建议对敏感基础设施进行主动封锁。
The following attack categories were identified:
威胁情报分析将163.172.31.86与来自Paris, France,运营在Scaleway SAS的网络中的恶意活动相关联。该地址自首次检测以来一直处于观察状态。 该地址在我们的监控系统中活跃了1天,产生了1次标记请求,速率约为每天1次。 该IP从数据中心基础设施运营,是有组织攻击行动中使用的典型地址。 该IP表现出目录枚举行为,系统地请求不存在的路径以发现隐藏文件和配置错误的资源。 我们的记录显示来自France的119个恶意IP,使其成为全球威胁活动的重要贡献者。 评分70/100表明这是一个已确认的恶意行为者。网络级别封锁是适当的。
This IP belongs to a hosting or data center provider. Malicious traffic from hosting infrastructure often originates from compromised VPS instances, rented servers used for scanning campaigns, or abused free-tier cloud accounts. Hosting providers typically respond to abuse reports within 24-72 hours.
SSRF attacks trick servers into making requests to internal resources that should not be publicly accessible. This can expose cloud metadata endpoints, internal APIs, and private network services, potentially leading to full infrastructure compromise.
Passive DNS databases record historical DNS resolution data, enabling analysts to track domain changes, identify related infrastructure, and discover malicious domains sharing hosting with known threats. This historical context is invaluable for threat investigation.