Investigating suspicious inbound IPs using AbuseIPDB
AbuseIPDB is a platform that allows cyber defenders to report any abuse of IPs toward their network’s IPs, specifically targeting inbound IPs, including port-scanning IPs, vulnerability-scanning IPs, and malicious SMTP servers.
By accessing the AbuseIPDB website (https://www.abuseipdb.com/), you will be able to either report IP addresses that engage in hacking attempts or any other malicious behavior, or check the report history of any IP address to see whether there have been any other reports of malicious activities from the same IP. See Figure 14.20:
Figure 14.20 – The AbuseIPDB main webpage
Assuming that during your monitoring activities, you find several brute-forcing attempts from the 223.113.73.226
IP address. To investigate this IP’s reputation, you can enter it into the IP Check form in AbuseIPDB. See Figure 14.21:
Figure 14.21 – Investigating...