ABUSE.MOM
威胁报告

IP威胁报告
185.244.104.205

ABUSE.MOM — 规矩点,否则你将被曝光

生成时间: 2026-05-22 08:27:34
首次发现: 2026-03-01 16:00:11
最后发现: 2026-03-01 16:00:11
110

⛔ 判定:封锁

该IP地址已被归类为自动化恶意活动的来源。 威胁评分: 110/100. 已观察到的恶意请求总数: 1.

BOT_UAUA_CHANGEDBURSTREFERER
01

地理位置与分类

IP地址
185.244.104.205
类型
Hosting
国家
🇩🇪 Germany
城市
Frankfurt
ISP
Ferdinand Zink trading as Tube-Hosting
组织
Xantho UAB
自治系统
AS213200 Ferdinand Zink trading as Tube-Hosting
请求次数
1
02

检测签名

签名描述分数严重性
UA bot: Go-http-client检测到已知机器人/爬虫的User-Agent+40
UA changed for same IP多个User-Agent——机器人轮换技术+25
Burst: 9 req / 2s请求频率异常——自动扫描+35
Foreign referer seen来自无关外部域名的Referer+10
Σ = 110
03

观察到的活动

从服务器访问日志重建的HTTP请求。出于安全考虑,目标域名已隐藏。

[redacted]
GET
/
200
[redacted]
GET
/page
200
显示请求: 2 · HTTP 404: 0 · 危险模式: 0

* Typical request patterns for detected signatures. Actual target domains are redacted.

04

时间线

2026-03-01 16:00:11
检测到首次恶意请求
IP已从服务器日志进入监控
观察期间
触发了多个检测签名
UA bot: Go-http-client (+40), UA changed for same IP (+25), Burst: 9 req / 2s (+35)
2026-03-01 16:00:11
观察到最后一次恶意请求
总分达到: 110/100
下一周期
IP已封锁——所有后续请求被拒绝(HTTP 403)
自动添加到封锁列表
05

网络供应商

Ferdinand Zink trading as Tube-Hosting
AS213200 · 🇩🇪 Germany
06

建议

已采取和建议的措施

  • IP 185.244.104.205 已在应用层封锁(HTTP 403)
  • 建议在防火墙层(iptables/CSF)进行封锁
  • 通过abuse联系方式向网络供应商举报
  • 确保敏感文件(.env、.git、备份)无法从网络访问

🤖 User-Agent异常防御

IP 185.244.104.205显示可疑的UA行为。阻止空User-Agent请求。为敏感端点实施基于JavaScript的机器人检测。

🌊 洪水/DDoS缓解

在nginx中实施limit_req_zone。部署具有DDoS防护的CDN。配置SYN cookies和连接跟踪以限制185.244.104.205。

08

开放端口和服务

来自Shodan的网络侦察数据。开放端口可能表示正在运行的服务、错误配置或潜在的攻击面。

开放端口 (28)
PortServiceRiskDescription
111UnknownLowService on port 111
1024UnknownLowService on port 1024
1080UnknownLowService on port 1080
1181UnknownLowService on port 1181
1200UnknownLowService on port 1200
1234UnknownLowService on port 1234
1292UnknownLowService on port 1292
1337UnknownLowService on port 1337
1370UnknownLowService on port 1370
1400UnknownLowService on port 1400
1414UnknownLowService on port 1414
1433MSSQLHighService on port 1433
1443UnknownLowService on port 1443
1457UnknownLowService on port 1457
1459UnknownLowService on port 1459
1471UnknownLowService on port 1471
1521UnknownLowService on port 1521
1599UnknownLowService on port 1599
1800UnknownLowService on port 1800
1801UnknownLowService on port 1801
1883UnknownLowService on port 1883
1911UnknownLowService on port 1911
1925UnknownLowService on port 1925
1953UnknownLowService on port 1953
1958UnknownLowService on port 1958
1969UnknownLowService on port 1969
1971UnknownLowService on port 1971
3128UnknownLowService on port 3128

数据来源:Shodan InternetDB。独立于abuse.mom进行扫描。

09

黑名单状态 (DNSBL)

该IP已通过全球邮件服务器和防火墙使用的主要DNS黑名单进行检查。

✓ 清洁
Spamhaus ZEN

已检查:Spamhaus、SpamCop、Barracuda、SORBS、CBL、UCEProtect。

10

Threat Analysis

185.244.104.205 has been assigned a threat score of 110/100 (Critical). 这代表着极高风险等级。我们的检测系统已从该地址标记出多个高置信度的恶意意图指标。

The following attack categories were identified:

User-Agent AnomalyRequest Flooding

📊 Threat Analysis

185.244.104.205注册在Frankfurt, Germany,运营在Ferdinand Zink trading as Tube-Hosting的网络中。该IP在触发多个行为检测签名后首次出现在我们的威胁源中。 在其1天的观察窗口期间,我们记录了来自此IP的1次敌对请求——平均每天约1次。 被归类为托管IP,此地址可能运行在租用的服务器或云实例上。攻击者偏好数据中心IP因其高带宽和一次性特点。 识别出两种攻击模式(User-Agent Anomaly和Request Flooding),表明这是一个针对多个漏洞的半自动化攻击活动。 Germany目前在我们的数据库中占101个被封锁IP,使其成为恶意流量的重要来源。 威胁评分110/100,此IP属于我们数据库中最危险的地址之一。强烈建议立即完全封锁。

This IP belongs to a hosting or data center provider. Malicious traffic from hosting infrastructure often originates from compromised VPS instances, rented servers used for scanning campaigns, or abused free-tier cloud accounts. Hosting providers typically respond to abuse reports within 24-72 hours.

11

Related Threats

🇩🇪 Top threats from Germany

15.220.152.241 (320)77.81.65.244 (313)185.168.29.98 (313)91.217.249.222 (305)212.30.36.219 (305)View all →

🏢 Same network: AS213200

View all →
12

Security Intelligence

💡 HTTP Header Analysis for Threat Detection

Examining HTTP headers beyond User-Agent reveals attack tools and automated scripts. Missing standard headers, unusual ordering, non-standard values, and inconsistencies with claimed client identity all serve as reliable detection signals.

💡 Critical Infrastructure Targeting

Attacks on power grids, water systems, and transportation networks have moved from theoretical to practical threats. Industrial control systems often lack modern security features, making them vulnerable to both targeted and opportunistic attacks.

🔍 Check Any IP Address

Share this report: