Skip to main contentSkip to footer

Threat Categories

ReportedIP verwendet 30 vordefinierte Threat Categories zur Klassifizierung böswilliger Aktivitäten. Jede Kategorie verfügt über eine Schweregradstufe von 1 (gering) bis 10 (kritisch), die die Berechnung des Confidence Score beeinflusst. Bei der Meldung einer IP-Adresse geben Sie eine oder mehrere Kategorie-IDs an, um die Art des beobachteten Angriffs zu beschreiben.

Alle Kategorien

#1 High
DNS Compromise
Compromised or hijacked DNS servers
8/10
#2 Critical
DNS Poisoning
DNS cache poisoning attempts
9/10
#3 Medium
Fraud Orders
Fraudulent orders in online shops
6/10
#4 Critical
DDoS Attack
Distributed denial-of-service attacks
9/10
#5 High
FTP Brute-Force
Brute-force attacks against FTP services
7/10
#6 High
Ping of Death
Oversized-ping (Ping of Death) attacks
8/10
#7 Critical
Phishing
Hosting or distributing phishing sites
9/10
#8 Medium
Fraud VoIP
VoIP fraud and toll abuse
6/10
#9 Medium
Open Proxy
Open proxy servers used to relay abuse
5/10
#10 Medium
Web Spam
Spam posted to websites and forums
4/10
#11 Medium
Email Spam
Unsolicited bulk email (spam) sources
4/10
#12 Low
Blog Spam
Spam comments on blogs
3/10
#13 Low
VPN IP
VPN exit nodes (low direct threat)
2/10
#14 Medium
Port Scan
Port scanning and service probing
6/10
#15 High
Hacking
General hacking activity
8/10
#16 Critical
SQL Injection
SQL injection attack attempts
9/10
#17 High
Spoofing
IP or email spoofing
7/10
#18 High
Brute-Force
Credential brute-force attacks
7/10
#19 Medium
Bad Web Bot
Malicious or abusive web bots
5/10
#20 High
Exploited Host
Compromised hosts under attacker control
8/10
#21 High
Web App Attack
Attacks against web applications
8/10
#22 High
SSH
SSH brute-force and abuse
7/10
#23 High
IoT Targeted
Attacks targeting IoT devices
8/10
#24 Medium
Cryptocurrency Mining
Unauthorised cryptocurrency mining
6/10
#25 Critical
Ransomware C&C
Ransomware command-and-control infrastructure
10/10
#26 Critical
Banking Trojan
Banking trojan distribution or control
10/10
#27 High
Mobile Malware
Mobile malware distribution
8/10
#28 Critical
Supply Chain Attack
Software supply-chain attacks
10/10
#29 Critical
Zero-Day Exploit
Exploitation of unpatched zero-day vulnerabilities
10/10
#30 Critical
Nation State
State-sponsored attack activity
10/10
#31 High
WP Login Brute Force
Brute force attacks on wp-login.php
7/10
#32 High
WP Admin Brute Force
Attacks on WordPress admin area
8/10
#33 High
WP XML-RPC Brute Force
Abuse of XML-RPC interface
8/10
#34 High
WP REST API Abuse
Abuse of WordPress REST API
7/10
#35 High
WP Plugin Exploit
Exploitation of plugin vulnerabilities
8/10
#36 High
WP Theme Exploit
Exploitation of theme vulnerabilities
8/10
#37 Critical
WP Core Exploit
Attacks on WordPress core vulnerabilities
9/10
#38 Critical
WP Zero-Day Exploit
Unknown WordPress exploits
10/10
#39 Low
WP Comment Spam
Spam in WordPress comments
3/10
#40 Medium
WP Contact Form Spam
Spam via contact forms
4/10
#41 Medium
WP Registration Spam
Fake user registrations
5/10
#42 Medium
WP Trackback Spam
Trackback/Pingback spam
6/10
#43 Critical
WP File Upload Malware
Malware upload via WordPress
9/10
#44 Critical
WP Code Injection
PHP/JavaScript code injection
9/10
#45 Critical
WP Database Injection
SQL injection in WordPress
10/10
#46 Critical
WP Backdoor Installation
Installation of backdoors
10/10
#47 Medium
WP SEO Spam
SEO spam and link injection
6/10
#48 Medium
WP Content Scraping
Automated content scraping
5/10
#49 Medium
WP Fake SEO Bot
Malicious SEO crawlers
6/10
#50 High
WP Redirect Hijacking
Manipulation of redirects
7/10
#51 High
WP Resource Exhaustion
DoS through resource consumption
7/10
#52 Medium
WP Media Library Abuse
Abuse of media library
5/10
#53 Medium
WP Search Abuse
Overload of search function
4/10
#54 Medium
WP Cron Abuse
Abuse of WP-Cron
6/10
#55 Medium
WP User Enumeration
Enumeration of WordPress users
6/10
#56 High
WP Version Scanning
Scanning for WordPress versions
7/10
#57 High
WP Plugin Scanning
Detection of installed plugins
7/10
#58 High
WP Config Exposure
Access to wp-config.php
8/10

Verwendung von Kategorien in der API

Wenn Sie eine IP-Adresse über den /report Endpoints melden, fügen Sie die Kategorie-ID in Ihre Anfrage ein, um die Art der beobachteten Bedrohung zu klassifizieren. Der Schweregrad der Kategorie hat direkten Einfluss auf den Confidence Score. Die vollständige Dokumentation zum Endpoint finden Sie in der API Reference; auf der Seite „Blacklist“ wird gezeigt, wie Sie nach Kategorien gefilterte, dienstspezifische Blacklists erstellen können.

Report with Category

curl
curl -X POST \
     -H "X-Key: YOUR_API_KEY" \
     -H "Content-Type: application/json" \
     -d '{"ip": "1.2.3.4", "categories": [4, 15], "comment": "Brute force SSH + port scan"}' \
     "https://reportedip.com/wp-json/reportedip/v2/report"
200 OK
json
{
  "data": {
    "ipAddress": "1.2.3.4",
    "abuseConfidencePercentage": 42,
    "reportId": "12345"
  }
}

Alle Kategorien abrufen

Sie können die vollständige Liste der Kategorien programmgesteuert abrufen:

curl
curl "https://reportedip.com/wp-json/reportedip/v2/categories"
Tipp: Kategorien mit höherem Schweregrad haben einen größeren Einfluss auf den Confidence Score. Wählen Sie für Ihre Reports stets die zutreffendste Kategorie aus – dies hilft der Community, bessere Entscheidungen bezüglich der Sperrung zu treffen.

Schweregradskala

Die Schweregradskala reicht von 1 bis 10 und ist vier Bedrohungsstufen zugeordnet:

Stufe Schweregrad Beschreibung Beispiel
Gering 1 – 3 Geringfügige oder rein informative Bedrohungen Web-Scraping, Kommentar-Spam
Mittel 4 – 6 Mäßige Bedrohungen, die Aufmerksamkeit erfordern Brute Force-Angriffe auf Login-Daten, Credential Stuffing
Hoch 7 – 8 Schwerwiegende Bedrohungen mit potenziellem Schaden SQL Injection, XSS-Angriffe
Kritisch 9 – 10 Schwerwiegende Bedrohungen, die sofortiges Handeln erfordern DDoS, Ransomware, Zero-Day Exploits

Zuletzt aktualisiert: · Betreut vom reportedIP-Team

Security Focused
GDPR Compliant
Made in Germany
Zurück zu den Docs