Area: Reputation and impersonation
IPs attacking others
Whether any of your public IPs (up to 30) is in a network marked as hijacked or used for crime (DROP list), on the CINS list of addresses that have attacked other systems, or is a Tor exit node. The lists are downloaded every day and matched on our servers.
What it can report
Open each one to see what it means and how to fix it.
Address in a hijacked network (DROP)
What it means
What could happen
How an attacker would use it
How to fix it
- Ask your hosting or internet provider whether that address range was hijacked or recently reassigned.
- Ask for an address from another network and move your website or mail server to it.
- If your email is the problem, send it through a reputable mail service instead of from that address.
- Check that no computer of yours is infected, just in case.
- Until it is fixed, expect some of your email and web traffic to be blocked, and warn customers who report problems.
How to check it's fixed
Who usually fixes it
Example with sample data. In your dashboard, the explanation uses your own domain and details.
Address seen attacking other systems
What it means
What could happen
How an attacker would use it
How to fix it
- Find out which computer or server uses that address.In an office it's usually the router's public address, so look at the computers and devices behind it.
- Ask your IT person to check it: unknown software, odd processes, strange connections.
- Change the administration passwords and update the system. If in doubt, reinstall it.
- Check routers, cameras and other connected devices: they are often the ones infected.
- If you are on shared hosting, tell your provider: another customer may be the cause.
How to check it's fixed
Who usually fixes it
Example with sample data. In your dashboard, the explanation uses your own domain and details.
Address is a Tor exit node
What it means
What could happen
How an attacker would use it
How to fix it
- Ask whoever manages that server whether it runs a Tor relay on purpose.
- If it doesn't, find out who installed it and remove it.
- Review the server's security: users, installed software and passwords. Change the passwords.
- If it's intentional, move your website and email to other addresses, so the Tor traffic doesn't affect them.
How to check it's fixed
Who usually fixes it
Example with sample data. In your dashboard, the explanation uses your own domain and details.
Abuse reports against the address
What it means
What could happen
How an attacker would use it
How to fix it
- Find out which server or computer uses that address.
- Ask your IT person to check it for unknown software, unusual connections and new accounts.
- Change the passwords, update the system and, if in doubt, reinstall it.
- If you are on shared hosting, ask your provider to check the server and to change you to another address if needed.
- Once it's fixed, ask AbuseIPDB to review the reports and let them age out.
How to check it's fixed
Who usually fixes it
Example with sample data. In your dashboard, the explanation uses your own domain and details.
Address seen scanning the internet
What it means
What could happen
How an attacker would use it
How to fix it
- Find out which computer or server uses that address.In an office it's usually the router's public address, so look at the computers and devices behind it.
- Ask your IT person to check it: unknown software, odd processes, strange connections.
- Change the administration passwords and update the system. If in doubt, reinstall it.
- Check routers, cameras and other connected devices: they are often the ones infected.
- If you are on shared hosting, tell your provider: another customer may be the cause.
How to check it's fixed
Who usually fixes it
Example with sample data. In your dashboard, the explanation uses your own domain and details.