Author Topic: Known crawler that probes for Word Press vulnerabilities or innocent party?  (Read 995 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33925
  • malware fighter
This address was reported several times: -static.130.62.9.5.clients.your-server
a.o. by hxtp://www.DivineRevelations.info, quite a secure site, but also with some issues: https://observatory.mozilla.org/analyze.html?host=www.divinerevelations.info  especially with sri-hashes on external script links: https://sritest.io/#report/a450bc03-a1a2-4135-a42c-cc8d4e3cb7c7

This particular Hetzner Crawler abuse is not alerted here: http://urlquery.net/report.php?id=1497093416843
as all connection attempts are refused.
When we check with ID serve -
it appears to runs on OpenSSH 7.3p1 Ubuntu 1 (Ubuntu Linux; protocol 2.0) ; cpe:/o:linux:linux_kernel on 5.9.62.130.

The controversy really starts, when we see this address being tracked by -91.209.51.22, a spammer:
Re: https://cleantalk.org/blacklists/91.209.51.22 

Now question is, who is the crawler, who is the spammer, who: the good guy, the bad and/or the ugly un?

Just some interesting interactions we see here, but I personally rather like to block both of these flagged addresses.

polonus (volunteer website security analyst and website error-hunter)
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!