New indicators; geofencing; standards update

This commit is contained in:
2025-12-18 09:36:21 -06:00
parent 7e836a4f69
commit e5ace2441c
3 changed files with 45 additions and 44 deletions

View File

@@ -4,13 +4,46 @@
<logo>https://foundation.aninix.net/assets/img/AniNIX.png</logo>
<link rel="self" href="https://aninix.net/AniNIX/Wiki/raw/branch/main/rss/osint.xml" />
<link href="https://aninix.net/" />
<updated>2022-09-26T02:16:20Z</updated>
<updated>2025-08-21T12:09:04Z</updated>
<author>
<name>AniNIX</name>
</author>
<id>https://aninix.net/</id>
<entry>
<title>193.142.147.0/24</title>
<link href="https://pulsedive.com/indicator/?iid=74597502"></link>
<updated>2025-12-18T15:28:00Z</updated>
<id>https://pulsedive.com/indicator/?iid=74597502</id>
<author><name>DarkFeather</name></author>
<summary>
193.142.147.209 was observed attempting CVE 2025-55182 "React2Shell" against our web front. Total event count was three. Entire /24 has been blocked.
</summary>
</entry>
<entry>
<title>147.182.128.0/17</title>
<link href="https://pulsedive.com/indicator/?iid=71233732"></link>
<updated>2025-12-18T15:28:00Z</updated>
<id>https://pulsedive.com/indicator/?iid=71233732</id>
<author><name>DarkFeather</name></author>
<summary>
This DigitalOcean IP was observed running an extensive SSH brute-force from California. We are blocking the related /17 subnet as the provider is in poor reputation. Total event count was 112.
</summary>
</entry>
<entry>
<title>93.123.109.245</title>
<link href="https://pulsedive.com/ioc/93.123.109.245"></link>
<updated>2025-08-21T12:09:04Z</updated>
<id>https://pulsedive.com/ioc/93.123.109.245</id>
<author><name>DarkFeather</name></author>
<summary>
A Bulgarian IP was observed using a suspicious user agent (l9explore) and has been classified as known bad traffic. The related /24 was blocked. Total event count is 127.
</summary>
</entry>
<entry>
<title>200.28.54.71 and 186.107.199.1</title>
<link href="https://aninix.net/AniNIX/Wiki/raw/branch/main/rss/osint.xml#200.28.54.71"></link>