
ABUSE.MOM — 规矩点,否则你将被曝光
| 签名 | 描述 | 分数 | 严重性 |
|---|---|---|---|
| Danger strong hits: 3 | 高风险路径:Webshell、RCE、漏洞利用 | +75 | |
| Danger medium hits: 2 | 中等风险:管理面板、配置文件 | +20 |
从服务器访问日志重建的HTTP请求。出于安全考虑,目标域名已隐藏。
* Typical request patterns for detected signatures. Actual target domains are redacted.
将37.235.105.210添加到防火墙封锁列表。检查日志中的成功连接。在所有面向公众的服务上启用全面日志记录。
来自Shodan的网络侦察数据。开放端口可能表示正在运行的服务、错误配置或潜在的攻击面。
| Port | Service | Risk | Description |
|---|---|---|---|
| 21 | FTP | Medium | File Transfer Protocol — often targeted for anonymous login attacks |
| 25 | SMTP | Medium | SMTP mail server — can be abused for spam relay |
| 80 | HTTP | Low | HTTP web server — standard web traffic |
| 110 | POP3 | Low | Service on port 110 |
| 143 | IMAP | Low | Service on port 143 |
| 465 | Unknown | Low | Service on port 465 |
| 587 | Unknown | Low | Service on port 587 |
| 993 | IMAPS | Low | Service on port 993 |
| 995 | POP3S | Low | Service on port 995 |
| 8080 | HTTP-Alt | Low | HTTP alternative port — often used for admin panels or proxies |
| 8081 | Unknown | Low | Service on port 8081 |
| 8888 | HTTP-Alt | Low | Service on port 8888 |
⚠️ 在37.235.105.210上检测到1个高风险端口。 这些服务在没有严格防火墙规则的情况下不应公开访问。
| CVE ID | Link |
|---|---|
| CVE-2025-13837 | NVD → |
| CVE-2021-28861 | NVD → |
| CVE-2024-9287 | NVD → |
| CVE-2022-42919 | NVD → |
| CVE-2023-24329 | NVD → |
| CVE-2021-3737 | NVD → |
| CVE-2009-3720 | NVD → |
| CVE-2016-3189 | NVD → |
| CVE-2023-36632 | NVD → |
| CVE-2007-4559 | NVD → |
| CVE-2023-40217 | NVD → |
| CVE-2021-3733 | NVD → |
| CVE-2024-6232 | NVD → |
| CVE-2025-13836 | NVD → |
| CVE-2022-0391 | NVD → |
| CVE-2013-0340 | NVD → |
| CVE-2015-20107 | NVD → |
| CVE-2022-37454 | NVD → |
| CVE-2021-29921 | NVD → |
| CVE-2022-26488 | NVD → |
| CVE-2009-2940 | NVD → |
| CVE-2018-25032 | NVD → |
| CVE-2021-3426 | NVD → |
| CVE-2025-12781 | NVD → |
| CVE-2020-29396 | NVD → |
🔴 此主机有32个已知CVE与其暴露的服务相关联。如此大量的漏洞强烈表明软件严重过时。 请在NVD数据库中查看每个CVE的详细信息。
数据来源:Shodan InternetDB。独立于abuse.mom进行扫描。
该IP已通过全球邮件服务器和防火墙使用的主要DNS黑名单进行检查。
已检查:Spamhaus、SpamCop、Barracuda、SORBS、CBL、UCEProtect。
37.235.105.210 has been assigned a threat score of 95/100 (Critical). 这是一个严重级别的威胁。系统管理员应将此IP视为敌对地址,无例外地阻止所有入站连接。
我们的监控基础设施已将37.235.105.210(地理位置为Prague, Czech Republic,运营在SH.cz s.r.o.的网络中)识别为可疑网络活动的来源。 该地址在我们的监控系统中活跃了1天,产生了1次标记请求,速率约为每天1次。 该IP从数据中心基础设施运营,是有组织攻击行动中使用的典型地址。 Czech Republic目前在我们的数据库中占90个被封锁IP,使其成为恶意流量的值得注意的来源。 威胁评分95/100,此IP属于我们数据库中最危险的地址之一。强烈建议立即完全封锁。
This IP belongs to a hosting or data center provider. Malicious traffic from hosting infrastructure often originates from compromised VPS instances, rented servers used for scanning campaigns, or abused free-tier cloud accounts. Hosting providers typically respond to abuse reports within 24-72 hours.
WordPress sites face constant automated attacks targeting xmlrpc.php for brute force amplification, wp-login.php for credential theft, and vulnerable plugins for remote code execution. Over 90% of CMS-based attacks specifically target WordPress installations.
Certificate Transparency logs record all publicly trusted TLS certificates. Monitoring these logs reveals unauthorized certificate issuance, phishing domain preparation, and shadow IT — providing early warning of attacks targeting an organizations domain.