
ABUSE.MOM — 规矩点,否则你将被曝光
| 签名 | 描述 | 分数 | 严重性 |
|---|---|---|---|
| Danger strong hits: 1 | 高风险路径:Webshell、RCE、漏洞利用 | +25 | |
| Danger medium hits: 1 | 中等风险:管理面板、配置文件 | +10 | |
| 404 ratio >= 60% | 大多数请求返回404——目录枚举 | +25 | |
| POST requests present | 自动分析检测到行为异常 | +8 | |
| Danger strong hits: 3 | 高风险路径:Webshell、RCE、漏洞利用 | +75 | |
| Danger medium hits: 2 | 中等风险:管理面板、配置文件 | +20 |
从服务器访问日志重建的HTTP请求。出于安全考虑,目标域名已隐藏。
* Typical request patterns for detected signatures. Actual target domains are redacted.
IP 176.241.66.87正在枚举目录。在10次以上404错误后配置fail2ban apache-404 jail。禁用目录列表。
来自Shodan的网络侦察数据。开放端口可能表示正在运行的服务、错误配置或潜在的攻击面。
| Port | Service | Risk | Description |
|---|---|---|---|
| 11 | Unknown | Low | Service on port 11 |
| 13 | Unknown | Low | Service on port 13 |
| 37 | Unknown | Low | Service on port 37 |
| 49 | Unknown | Low | Service on port 49 |
| 80 | HTTP | Low | HTTP web server — standard web traffic |
| 81 | Unknown | Low | Service on port 81 |
| 83 | Unknown | Low | Service on port 83 |
| 102 | Unknown | Low | Service on port 102 |
| 113 | Unknown | Low | Service on port 113 |
| 122 | Unknown | Low | Service on port 122 |
| 143 | IMAP | Low | Service on port 143 |
| 264 | Unknown | Low | Service on port 264 |
| 427 | Unknown | Low | Service on port 427 |
| 440 | Unknown | Low | Service on port 440 |
| 480 | Unknown | Low | Service on port 480 |
| 541 | Unknown | Low | Service on port 541 |
| 548 | Unknown | Low | Service on port 548 |
| 554 | Unknown | Low | Service on port 554 |
| 636 | Unknown | Low | Service on port 636 |
| 789 | Unknown | Low | Service on port 789 |
| 902 | Unknown | Low | Service on port 902 |
| 992 | Unknown | Low | Service on port 992 |
| 993 | IMAPS | Low | Service on port 993 |
| 1027 | Unknown | Low | Service on port 1027 |
| 1177 | Unknown | Low | Service on port 1177 |
| 1234 | Unknown | Low | Service on port 1234 |
| 1235 | Unknown | Low | Service on port 1235 |
| 1311 | Unknown | Low | Service on port 1311 |
| 1337 | Unknown | Low | Service on port 1337 |
| 1414 | Unknown | Low | Service on port 1414 |
| 1433 | MSSQL | High | Service on port 1433 |
| 1440 | Unknown | Low | Service on port 1440 |
| 1471 | Unknown | Low | Service on port 1471 |
| 1515 | Unknown | Low | Service on port 1515 |
| 1800 | Unknown | Low | Service on port 1800 |
| 1801 | Unknown | Low | Service on port 1801 |
| 1820 | Unknown | Low | Service on port 1820 |
| 1830 | Unknown | Low | Service on port 1830 |
| 1911 | Unknown | Low | Service on port 1911 |
| 1935 | Unknown | Low | Service on port 1935 |
| 1962 | Unknown | Low | Service on port 1962 |
| 1972 | Unknown | Low | Service on port 1972 |
| 1980 | Unknown | Low | Service on port 1980 |
| 2002 | Unknown | Low | Service on port 2002 |
| 2008 | Unknown | Low | Service on port 2008 |
| 2051 | Unknown | Low | Service on port 2051 |
| 2082 | Unknown | Low | Service on port 2082 |
| 2086 | Unknown | Low | Service on port 2086 |
| 2095 | Unknown | Low | Service on port 2095 |
| 2109 | Unknown | Low | Service on port 2109 |
| 2121 | Unknown | Low | Service on port 2121 |
| 2154 | Unknown | Low | Service on port 2154 |
| 2181 | Unknown | Low | Service on port 2181 |
| 2196 | Unknown | Low | Service on port 2196 |
| 2222 | Unknown | Low | Service on port 2222 |
| 2224 | Unknown | Low | Service on port 2224 |
| 2266 | Unknown | Low | Service on port 2266 |
| 2332 | Unknown | Low | Service on port 2332 |
| 2375 | Unknown | Low | Service on port 2375 |
| 2455 | Unknown | Low | Service on port 2455 |
| 2553 | Unknown | Low | Service on port 2553 |
| 2568 | Unknown | Low | Service on port 2568 |
| 2628 | Unknown | Low | Service on port 2628 |
| 2762 | Unknown | Low | Service on port 2762 |
| 3001 | Unknown | Low | Service on port 3001 |
| 3011 | Unknown | Low | Service on port 3011 |
| 3058 | Unknown | Low | Service on port 3058 |
| 3061 | Unknown | Low | Service on port 3061 |
| 3065 | Unknown | Low | Service on port 3065 |
| 3110 | Unknown | Low | Service on port 3110 |
| 3134 | Unknown | Low | Service on port 3134 |
| 3137 | Unknown | Low | Service on port 3137 |
| 3144 | Unknown | Low | Service on port 3144 |
| 3164 | Unknown | Low | Service on port 3164 |
| 3174 | Unknown | Low | Service on port 3174 |
| 3333 | Unknown | Low | Service on port 3333 |
| 3352 | Unknown | Low | Service on port 3352 |
| 3388 | Unknown | Low | Service on port 3388 |
| 3524 | Unknown | Low | Service on port 3524 |
| 3541 | Unknown | Low | Service on port 3541 |
| 3551 | Unknown | Low | Service on port 3551 |
| 3689 | Unknown | Low | Service on port 3689 |
| 3749 | Unknown | Low | Service on port 3749 |
| 3790 | Unknown | Low | Service on port 3790 |
| 3792 | Unknown | Low | Service on port 3792 |
| 4022 | Unknown | Low | Service on port 4022 |
| 4042 | Unknown | Low | Service on port 4042 |
| 4064 | Unknown | Low | Service on port 4064 |
| 4104 | Unknown | Low | Service on port 4104 |
| 4150 | Unknown | Low | Service on port 4150 |
| 4157 | Unknown | Low | Service on port 4157 |
| 4282 | Unknown | Low | Service on port 4282 |
| 4369 | Unknown | Low | Service on port 4369 |
| 4433 | Unknown | Low | Service on port 4433 |
| 4435 | Unknown | Low | Service on port 4435 |
| 4443 | Unknown | Low | Service on port 4443 |
| 4444 | Unknown | Low | Service on port 4444 |
| 4506 | Unknown | Low | Service on port 4506 |
| 4524 | Unknown | Low | Service on port 4524 |
| 4543 | Unknown | Low | Service on port 4543 |
| 4786 | Unknown | Low | Service on port 4786 |
| 4840 | Unknown | Low | Service on port 4840 |
| 4886 | Unknown | Low | Service on port 4886 |
| 4949 | Unknown | Low | Service on port 4949 |
| 5001 | Unknown | Low | Service on port 5001 |
| 5007 | Unknown | Low | Service on port 5007 |
| 5010 | Unknown | Low | Service on port 5010 |
| 5025 | Unknown | Low | Service on port 5025 |
| 5070 | Unknown | Low | Service on port 5070 |
| 5150 | Unknown | Low | Service on port 5150 |
| 5224 | Unknown | Low | Service on port 5224 |
| 5257 | Unknown | Low | Service on port 5257 |
| 5269 | Unknown | Low | Service on port 5269 |
| 5432 | PostgreSQL | High | PostgreSQL database — direct database access risk |
| 5542 | Unknown | Low | Service on port 5542 |
| 5569 | Unknown | Low | Service on port 5569 |
| 5601 | Unknown | Low | Service on port 5601 |
| 5603 | Unknown | Low | Service on port 5603 |
| 5609 | Unknown | Low | Service on port 5609 |
| 5800 | Unknown | Low | Service on port 5800 |
| 5801 | Unknown | Low | Service on port 5801 |
| 5986 | Unknown | Low | Service on port 5986 |
| 5987 | Unknown | Low | Service on port 5987 |
| 5992 | Unknown | Low | Service on port 5992 |
| 6008 | Unknown | Low | Service on port 6008 |
| 6262 | Unknown | Low | Service on port 6262 |
| 6379 | Redis | Critical | Redis in-memory database — frequently misconfigured without auth |
| 6556 | Unknown | Low | Service on port 6556 |
| 6653 | Unknown | Low | Service on port 6653 |
| 6666 | Unknown | Low | Service on port 6666 |
| 7001 | Unknown | Low | Service on port 7001 |
| 7071 | Unknown | Low | Service on port 7071 |
| 7082 | Unknown | Low | Service on port 7082 |
| 7415 | Unknown | Low | Service on port 7415 |
| 7433 | Unknown | Low | Service on port 7433 |
| 7443 | Unknown | Low | Service on port 7443 |
| 7510 | Unknown | Low | Service on port 7510 |
| 7548 | Unknown | Low | Service on port 7548 |
| 7700 | Unknown | Low | Service on port 7700 |
| 7775 | Unknown | Low | Service on port 7775 |
| 7778 | Unknown | Low | Service on port 7778 |
| 7782 | Unknown | Low | Service on port 7782 |
| 7878 | Unknown | Low | Service on port 7878 |
| 7980 | Unknown | Low | Service on port 7980 |
| 8001 | Unknown | Low | Service on port 8001 |
| 8018 | Unknown | Low | Service on port 8018 |
| 8020 | Unknown | Low | Service on port 8020 |
| 8025 | Unknown | Low | Service on port 8025 |
| 8036 | Unknown | Low | Service on port 8036 |
| 8049 | Unknown | Low | Service on port 8049 |
| 8060 | Unknown | Low | Service on port 8060 |
| 8069 | Unknown | Low | Service on port 8069 |
| 8079 | Unknown | Low | Service on port 8079 |
| 8083 | Unknown | Low | Service on port 8083 |
| 8086 | Unknown | Low | Service on port 8086 |
| 8090 | Unknown | Low | Service on port 8090 |
| 8097 | Unknown | Low | Service on port 8097 |
| 8098 | Unknown | Low | Service on port 8098 |
| 8112 | Unknown | Low | Service on port 8112 |
| 8133 | Unknown | Low | Service on port 8133 |
| 8140 | Unknown | Low | Service on port 8140 |
| 8181 | Unknown | Low | Service on port 8181 |
| 8200 | Unknown | Low | Service on port 8200 |
| 8238 | Unknown | Low | Service on port 8238 |
| 8280 | Unknown | Low | Service on port 8280 |
| 8291 | MikroTik | High | MikroTik Winbox — router management, targeted by VPNFilter malware |
| 8333 | Unknown | Low | Service on port 8333 |
| 8385 | Unknown | Low | Service on port 8385 |
| 8417 | Unknown | Low | Service on port 8417 |
| 8421 | Unknown | Low | Service on port 8421 |
| 8430 | Unknown | Low | Service on port 8430 |
| 8443 | HTTPS-Alt | Low | Service on port 8443 |
| 8450 | Unknown | Low | Service on port 8450 |
| 8563 | Unknown | Low | Service on port 8563 |
| 8586 | Unknown | Low | Service on port 8586 |
| 8587 | Unknown | Low | Service on port 8587 |
| 8728 | Unknown | Low | Service on port 8728 |
| 8771 | Unknown | Low | Service on port 8771 |
| 8809 | Unknown | Low | Service on port 8809 |
| 8835 | Unknown | Low | Service on port 8835 |
| 8849 | Unknown | Low | Service on port 8849 |
| 8857 | Unknown | Low | Service on port 8857 |
| 8883 | Unknown | Low | Service on port 8883 |
| 8888 | HTTP-Alt | Low | Service on port 8888 |
| 8916 | Unknown | Low | Service on port 8916 |
| 9000 | Unknown | Low | Service on port 9000 |
| 9001 | Unknown | Low | Service on port 9001 |
| 9002 | Unknown | Low | Service on port 9002 |
| 9042 | Unknown | Low | Service on port 9042 |
| 9046 | Unknown | Low | Service on port 9046 |
| 9068 | Unknown | Low | Service on port 9068 |
| 9070 | Unknown | Low | Service on port 9070 |
| 9082 | Unknown | Low | Service on port 9082 |
| 9091 | Unknown | Low | Service on port 9091 |
| 9092 | Unknown | Low | Service on port 9092 |
| 9099 | Unknown | Low | Service on port 9099 |
| 9148 | Unknown | Low | Service on port 9148 |
| 9160 | Unknown | Low | Service on port 9160 |
| 9190 | Unknown | Low | Service on port 9190 |
| 9191 | Unknown | Low | Service on port 9191 |
| 9200 | Elasticsearch | High | Elasticsearch — can leak sensitive data if unauthenticated |
| 9203 | Unknown | Low | Service on port 9203 |
| 9215 | Unknown | Low | Service on port 9215 |
| 9218 | Unknown | Low | Service on port 9218 |
| 9230 | Unknown | Low | Service on port 9230 |
| 9251 | Unknown | Low | Service on port 9251 |
| 9300 | Unknown | Low | Service on port 9300 |
| 9306 | Unknown | Low | Service on port 9306 |
| 9398 | Unknown | Low | Service on port 9398 |
| 9400 | Unknown | Low | Service on port 9400 |
| 9447 | Unknown | Low | Service on port 9447 |
| 9505 | Unknown | Low | Service on port 9505 |
| 9595 | Unknown | Low | Service on port 9595 |
| 9770 | Unknown | Low | Service on port 9770 |
| 9800 | Unknown | Low | Service on port 9800 |
| 9898 | Unknown | Low | Service on port 9898 |
| 9918 | Unknown | Low | Service on port 9918 |
| 9944 | Unknown | Low | Service on port 9944 |
| 9994 | Unknown | Low | Service on port 9994 |
| 9999 | Unknown | Low | Service on port 9999 |
| 10000 | Unknown | Low | Service on port 10000 |
| 10003 | Unknown | Low | Service on port 10003 |
| 10134 | Unknown | Low | Service on port 10134 |
| 10283 | Unknown | Low | Service on port 10283 |
| 10380 | Unknown | Low | Service on port 10380 |
| 10480 | Unknown | Low | Service on port 10480 |
| 10554 | Unknown | Low | Service on port 10554 |
| 10909 | Unknown | Low | Service on port 10909 |
| 11027 | Unknown | Low | Service on port 11027 |
| 11084 | Unknown | Low | Service on port 11084 |
| 11300 | Unknown | Low | Service on port 11300 |
| 11434 | Unknown | Low | Service on port 11434 |
| 12126 | Unknown | Low | Service on port 12126 |
| 12129 | Unknown | Low | Service on port 12129 |
| 12135 | Unknown | Low | Service on port 12135 |
| 12153 | Unknown | Low | Service on port 12153 |
| 12154 | Unknown | Low | Service on port 12154 |
| 12163 | Unknown | Low | Service on port 12163 |
| 12192 | Unknown | Low | Service on port 12192 |
| 12194 | Unknown | Low | Service on port 12194 |
| 12208 | Unknown | Low | Service on port 12208 |
| 12223 | Unknown | Low | Service on port 12223 |
| 12245 | Unknown | Low | Service on port 12245 |
| 12253 | Unknown | Low | Service on port 12253 |
| 12261 | Unknown | Low | Service on port 12261 |
| 12262 | Unknown | Low | Service on port 12262 |
| 12272 | Unknown | Low | Service on port 12272 |
| 12277 | Unknown | Low | Service on port 12277 |
| 12309 | Unknown | Low | Service on port 12309 |
| 12312 | Unknown | Low | Service on port 12312 |
| 12319 | Unknown | Low | Service on port 12319 |
| 12327 | Unknown | Low | Service on port 12327 |
| 12338 | Unknown | Low | Service on port 12338 |
| 12345 | Unknown | Low | Service on port 12345 |
| 12349 | Unknown | Low | Service on port 12349 |
| 12377 | Unknown | Low | Service on port 12377 |
| 12396 | Unknown | Low | Service on port 12396 |
| 12414 | Unknown | Low | Service on port 12414 |
| 12418 | Unknown | Low | Service on port 12418 |
| 12423 | Unknown | Low | Service on port 12423 |
| 12432 | Unknown | Low | Service on port 12432 |
| 12460 | Unknown | Low | Service on port 12460 |
| 12465 | Unknown | Low | Service on port 12465 |
| 12507 | Unknown | Low | Service on port 12507 |
| 12522 | Unknown | Low | Service on port 12522 |
| 12587 | Unknown | Low | Service on port 12587 |
| 13000 | Unknown | Low | Service on port 13000 |
| 13333 | Unknown | Low | Service on port 13333 |
| 14344 | Unknown | Low | Service on port 14344 |
| 14403 | Unknown | Low | Service on port 14403 |
| 14825 | Unknown | Low | Service on port 14825 |
| 14875 | Unknown | Low | Service on port 14875 |
| 15672 | Unknown | Low | Service on port 15672 |
| 16023 | Unknown | Low | Service on port 16023 |
| 16026 | Unknown | Low | Service on port 16026 |
| 16035 | Unknown | Low | Service on port 16035 |
| 16071 | Unknown | Low | Service on port 16071 |
| 16094 | Unknown | Low | Service on port 16094 |
| 16667 | Unknown | Low | Service on port 16667 |
| 16992 | Unknown | Low | Service on port 16992 |
| 16993 | Unknown | Low | Service on port 16993 |
| 17775 | Unknown | Low | Service on port 17775 |
| 18019 | Unknown | Low | Service on port 18019 |
| 18022 | Unknown | Low | Service on port 18022 |
| 18037 | Unknown | Low | Service on port 18037 |
| 18039 | Unknown | Low | Service on port 18039 |
| 18050 | Unknown | Low | Service on port 18050 |
| 18067 | Unknown | Low | Service on port 18067 |
| 18074 | Unknown | Low | Service on port 18074 |
| 18245 | Unknown | Low | Service on port 18245 |
| 19065 | Unknown | Low | Service on port 19065 |
| 19091 | Unknown | Low | Service on port 19091 |
| 19100 | Unknown | Low | Service on port 19100 |
| 19222 | Unknown | Low | Service on port 19222 |
| 21025 | Unknown | Low | Service on port 21025 |
| 21100 | Unknown | Low | Service on port 21100 |
| 21102 | Unknown | Low | Service on port 21102 |
| 21239 | Unknown | Low | Service on port 21239 |
| 21246 | Unknown | Low | Service on port 21246 |
| 21309 | Unknown | Low | Service on port 21309 |
| 21323 | Unknown | Low | Service on port 21323 |
| 22222 | Unknown | Low | Service on port 22222 |
| 23023 | Unknown | Low | Service on port 23023 |
| 23424 | Unknown | Low | Service on port 23424 |
| 25001 | Unknown | Low | Service on port 25001 |
| 25006 | Unknown | Low | Service on port 25006 |
| 25010 | Unknown | Low | Service on port 25010 |
| 25105 | Unknown | Low | Service on port 25105 |
| 26460 | Unknown | Low | Service on port 26460 |
| 28015 | Unknown | Low | Service on port 28015 |
| 28017 | Unknown | Low | Service on port 28017 |
| 29840 | Unknown | Low | Service on port 29840 |
| 30003 | Unknown | Low | Service on port 30003 |
| 30007 | Unknown | Low | Service on port 30007 |
| 30023 | Unknown | Low | Service on port 30023 |
| 30104 | Unknown | Low | Service on port 30104 |
| 31337 | Unknown | Low | Service on port 31337 |
| 32400 | Unknown | Low | Service on port 32400 |
| 35100 | Unknown | Low | Service on port 35100 |
| 35250 | Unknown | Low | Service on port 35250 |
| 35554 | Unknown | Low | Service on port 35554 |
| 35975 | Unknown | Low | Service on port 35975 |
| 39001 | Unknown | Low | Service on port 39001 |
| 40001 | Unknown | Low | Service on port 40001 |
| 41800 | Unknown | Low | Service on port 41800 |
| 42420 | Unknown | Low | Service on port 42420 |
| 44158 | Unknown | Low | Service on port 44158 |
| 44302 | Unknown | Low | Service on port 44302 |
| 44303 | Unknown | Low | Service on port 44303 |
| 44510 | Unknown | Low | Service on port 44510 |
| 45000 | Unknown | Low | Service on port 45000 |
| 46000 | Unknown | Low | Service on port 46000 |
| 46474 | Unknown | Low | Service on port 46474 |
| 49153 | Unknown | Low | Service on port 49153 |
| 49200 | Unknown | Low | Service on port 49200 |
| 49688 | Unknown | Low | Service on port 49688 |
| 50070 | Unknown | Low | Service on port 50070 |
| 50073 | Unknown | Low | Service on port 50073 |
| 50080 | Unknown | Low | Service on port 50080 |
| 50105 | Unknown | Low | Service on port 50105 |
| 50995 | Unknown | Low | Service on port 50995 |
| 50996 | Unknown | Low | Service on port 50996 |
| 51235 | Unknown | Low | Service on port 51235 |
| 52140 | Unknown | Low | Service on port 52140 |
| 54490 | Unknown | Low | Service on port 54490 |
| 55000 | Unknown | Low | Service on port 55000 |
| 55200 | Unknown | Low | Service on port 55200 |
| 55481 | Unknown | Low | Service on port 55481 |
| 55553 | Unknown | Low | Service on port 55553 |
| 58532 | Unknown | Low | Service on port 58532 |
| 60030 | Unknown | Low | Service on port 60030 |
| 60129 | Unknown | Low | Service on port 60129 |
| 61234 | Unknown | Low | Service on port 61234 |
| 61613 | Unknown | Low | Service on port 61613 |
| 61616 | Unknown | Low | Service on port 61616 |
| 63811 | Unknown | Low | Service on port 63811 |
| 64295 | Unknown | Low | Service on port 64295 |
| 64894 | Unknown | Low | Service on port 64894 |
| 65000 | Unknown | Low | Service on port 65000 |
⚠️ 在176.241.66.87上检测到4个高风险端口。开放的数据库端口表明可能存在数据泄露风险。 这些服务在没有严格防火墙规则的情况下不应公开访问。
数据来源:Shodan InternetDB。独立于abuse.mom进行扫描。
该IP已通过全球邮件服务器和防火墙使用的主要DNS黑名单进行检查。
已检查:Spamhaus、SpamCop、Barracuda、SORBS、CBL、UCEProtect。
176.241.66.87 has been assigned a threat score of 103/100 (Critical). 凭借此评分,该IP属于严重威胁级别——是我们监控数据库中最危险的地址之一。
The following attack categories were identified:
地址176.241.66.87来源于Amman, JO,运营在VTEL HOLDINGS LIMITED/JORDAN CO.的网络中。它是通过对受监控端点的入站网络流量进行自动分析而被识别的。 我们的传感器在11天内捕获了来自此地址的3次恶意请求,反映出每天约0.3次的持续攻击节奏。 从住宅网络运营,此IP可能代表一个被入侵的家庭网关或已被招募到更大攻击基础设施中的IoT设备。 该IP表现出目录枚举行为,系统地请求不存在的路径以发现隐藏文件和配置错误的资源。 我们的记录显示来自JO的78个恶意IP,使其成为全球威胁活动的值得注意的贡献者。 评分103/100将此地址置于最高严重性级别。应封锁并调查任何历史连接。
This IP is classified as residential, suggesting it may belong to a compromised home device, IoT botnet member, or an infected personal computer. Residential IPs involved in attacks often indicate malware infection without the owner's knowledge.
SQL injection remains one of the most common web attack vectors. Attackers inject malicious SQL code through input fields to extract database contents, modify data, or gain administrative access. Automated scanners test for SQLi vulnerabilities at massive scale.
The RaaS model allows technically unskilled criminals to deploy sophisticated ransomware through affiliate programs. Operators provide the malware, infrastructure, and negotiation services, taking a percentage of ransom payments from their affiliates.