Author Topic: Has this IP been flagged?  (Read 710 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Has this IP been flagged?
« on: May 08, 2020, 06:04:56 PM »
See: https://urlhaus.abuse.ch/url/360155/  (malware download found);
Services: PORT   STATE SERVICE VERSION
22/tcp open  ssh     OpenSSH 5.3 (protocol 2.0)
80/tcp open  http    Apache httpd 2.2.15 ((CentOS))
| http-methods:
|_  Potentially risky methods: TRACE
|_http-server-header: Apache/2.2.15 (CentOS)
|_http-title: Apache HTTP Server Test Page powered by CentOS

Brute force attacker: https://www.abuseipdb.com/check/45.95.168.81

Has it already gone?
Quote
Content that was returned by your fileviewer request for the URL: htxp://45.95.168.81/sbidiot/zte

1:  < !DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
2:  < html> < head>
3:  < title> 404 Not Found< /title>
4:  < /head> < body>
5:  < h1> Not Found< /h1>
6:  < p> The requested URL /SBidioT/zte was not found on this server.< /p>
7:  < hr>
8:  < address> Apache/2.2.15 (CentOS) Server at 45.95.168.81 Port 80< /address>
9:  < /body> < /html>

See vulnerabilities there: https://www.shodan.io/host/45.95.168.81

polonus (volunteer 3rd party cold recon website security-analyst and website error-hunter)
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!