Fwd: Abuse Message [AbuseID:86FFBD:29]: AbuseNormalInfo: Your server 5.9.28.201 has been registered as an attack source

Dear Provider,

Im George Egri, the Co-Founder and CEO of BitNinja Server Security. Im writing to inform you that we have detected malicious requests from the IP 5.9.28.201 directed at our clients servers.

As a result of these attacks, we have added your IP to our greylist to prevent it from attacking our clients servers.

Servers are increasingly exposed as the targets of botnet attacks and you might not be aware that your server is being used as a bot to send malicious attacks over the Internet.

I’ve collected the 3 earliest logs below, and you can find the freshest 100, that may help you disinfect your server, under the link.
http://bitninja.io/incidentReport.php?details=4dcd2df5f5e6e2b275?utm_source=incident&utm_content=publicpage. The timezone is UTC +1:00.

{
    "PORT HIT": "5.9.28.201:61793->107.#.#.82:5000",
    "MESSAGES": "Array
		(
		    [14:39:38] => GET /v2/_catalog HTTP/1.1
		Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
		Accept-Encoding: gzip,deflate
		User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.3
		)
		"
}                 

Добавить комментарий

Ваш адрес email не будет опубликован. Обязательные поля помечены *