
ABUSE.MOM — 规矩点,否则你将被曝光
| 签名 | 描述 | 分数 | 严重性 |
|---|---|---|---|
| Danger strong hits: 3 | 高风险路径:Webshell、RCE、漏洞利用 | +75 | |
| Danger medium hits: 2 | 中等风险:管理面板、配置文件 | +20 |
从服务器访问日志重建的HTTP请求。出于安全考虑,目标域名已隐藏。
* Typical request patterns for detected signatures. Actual target domains are redacted.
将212.32.49.171添加到防火墙封锁列表。检查日志中的成功连接。在所有面向公众的服务上启用全面日志记录。
来自同一/24子网的其他被封锁IP——表明该网络范围存在系统性滥用。
来自Shodan的网络侦察数据。开放端口可能表示正在运行的服务、错误配置或潜在的攻击面。
| Port | Service | Risk | Description |
|---|---|---|---|
| 80 | HTTP | Low | HTTP web server — standard web traffic |
| 443 | HTTPS | Low | HTTPS web server — encrypted web traffic |
| 502 | Unknown | Low | Service on port 502 |
| 853 | Unknown | Low | Service on port 853 |
| 1337 | Unknown | Low | Service on port 1337 |
| 8443 | HTTPS-Alt | Low | Service on port 8443 |
数据来源:Shodan InternetDB。独立于abuse.mom进行扫描。
该IP已通过全球邮件服务器和防火墙使用的主要DNS黑名单进行检查。
已检查:Spamhaus、SpamCop、Barracuda、SORBS、CBL、UCEProtect。
212.32.49.171 has been assigned a threat score of 95/100 (Critical). 这将其归入严重威胁类别。强烈建议在所有网络边界立即进行封锁。
我们的监控基础设施已将212.32.49.171(地理位置为Atlanta, United States,运营在Zayo Bandwidth的网络中)识别为可疑网络活动的来源。 该地址在我们的监控系统中活跃了1天,产生了1次标记请求,速率约为每天1次。 该地址作为VPN/代理出口节点运营。攻击者通过匿名化服务路由流量以隐藏真实位置。 United States目前在我们的数据库中占106个被封锁IP,使其成为恶意流量的重要来源。 评分95/100将此地址置于最高严重性级别。应封锁并调查任何历史连接。
This IP is associated with a VPN or proxy service. Attackers frequently route their traffic through anonymizing services to obscure their true location. This makes attribution more challenging but the malicious behavior patterns remain detectable.
Command injection occurs when attackers insert operating system commands through application inputs. Successful exploitation grants direct server access, enabling data theft, malware installation, and lateral movement across networks.
Watering hole attacks compromise websites frequently visited by target organizations. Rather than attacking targets directly, adversaries infect trusted resources, exploiting the inherent trust users place in regularly visited sites.