@BCOVertigo@lemmy.world avatar

BCOVertigo

@BCOVertigo@lemmy.world

This profile is from a federated server and may be incomplete. Browse more on the original instance.

BCOVertigo,
@BCOVertigo@lemmy.world avatar

Low effort speculation:

That’s a vodaphone portugal IP, but this is likely traffic routing though their customer cellular network and not their corporate. It’s possible that someone in PT has a similar username for this service and is fat fingering it. It’s also possible that you’re seeing a tiny sliver of a larger attack.

Spur.us tracks that IP as an egress point for openproxy and windscribe ResIP networks so it’s worth considering that the origin of the authentications you’re seeing may not be Portuguese cellphone but someone hiding behind those services.

Here’s a paper describing the difficulties such a service creates for folks trying to secure accounts with traditional IP reputation based rules. “Resident Evil: Understanding Residential IP Proxy as a Dark Service” ieeexplore.ieee.org/document/8835239

Shooting in the dark for how a bad actor would monetize account takeover for this service if this is in fact an attack… They could try to sell your invitation to that private tracker. They could also look to scoop up a bunch of folks to try and blackmail based on what victims are download/seeding. Other more creative options I’m not thinking of might be on the table.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • localhost
  • All magazines
  • 200 @ user_overview
    HTTP status 200 OK
    Route name user_overview
    Has session yes
    Stateless Check no
    Time 335 ms
    Total time 335 ms
    Initialization time 89 ms
    Memory 12.0 MiB
    Peak memory usage 12.0 MiB
    PHP memory limit 128 MiB
    Logger 88
    Errors 0
    Warnings 0
    Deprecations 88
    Cache 32 in 40.59 ms
    Cache Calls 32
    Total time 40.59 ms
    Cache hits 28 / 41 (68.29%)
    Cache writes 7
    2
    Default locale en
    Missing messages 2
    Fallback messages 0
    Defined messages 128
    Security n/a
    Authenticated No
    Firewall name main
    Twig 127 ms
    Render Time 127 ms
    Template Calls 74
    Block Calls 16
    Macro Calls 0
    46 in 50 ms
    settings_row_switch 15
    user_settings_row_switch 4
    date 3
    user_avatar 2
    user_inline 2
    date_edited 2
    vote 2
    boost 2
    settings_row_enum 2
    user_box 1
    user_actions 1
    entry 1
    magazine_inline 1
    entry_comment 1
    related_magazines 1
    active_users 1
    related_categories 1
    related_posts 1
    related_entries 1
    support_us_block 1
    featured_magazines 1
    20 in 59.53 ms
    Database Queries 20
    Different statements 20
    Query time 59.53 ms
    Invalid entities 0
    Cache hits 20
    Cache misses 3
    Cache puts 4
    6.4.0
    Profiler token 834aff
    Environment dev
    Debug enabled
    PHP version 8.2.26   View phpinfo()
    PHP Extensions Xdebug ✗ APCu ✓ OPcache ✓
    PHP SAPI apache2handler