Kompromitovan AltusHost B.V. datacentar
#1
Izgleda da je kompromitovan data centar AltusHost B.V. (altushost.com) u Srbiji. Na njihovom veb sajtu (https://archive.ph/J0nZq) stoji speed test IP adresa: 37.46.115.115, i ako ovu adresu/opseg proverimo na AbuseIPDB: https://www.abuseipdb.com/check-block/37.46.115.115/24, dobijemo ogromnu listu kompromitovanih hostova koji sprovode napade od skeniranja portova, preko brute force napada do skeniranja za ranjivim aplikacijama.

[Image: attachment.php?aid=768]


Attached Files Image(s)
   
“If you think you are too small to make a difference, try sleeping with a mosquito.” - Dalai Lama XIV
Reply
#2
Ako odemo na Shodan i krenemo da kucamo gore spomenute adrese, videćemo da je zapravo dobar deo adresa zapravo VPN servis, koji se očigledno zloupotrebljava.

https://www.shodan.io/host/37.46.115.48

[Image: attachment.php?aid=769]


[Image: attachment.php?aid=770]

https://www.shodan.io/host/37.46.115.17

[Image: attachment.php?aid=771]

[Image: attachment.php?aid=772]


Attached Files Image(s)
               
“If you think you are too small to make a difference, try sleeping with a mosquito.” - Dalai Lama XIV
Reply
#3
Napadi sa ovih resursa još uvek traju:

[Image: attachment.php?aid=891]


Attached Files Image(s)
   
“If you think you are too small to make a difference, try sleeping with a mosquito.” - Dalai Lama XIV
Reply
#4
Ove servere koristi (ili je u posedu) zapravo NordVPN.
“If you think you are too small to make a difference, try sleeping with a mosquito.” - Dalai Lama XIV
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)