@BCOVertigo@lemmy.world avatar

BCOVertigo

@BCOVertigo@lemmy.world

This profile is from a federated server and may be incomplete. Browse more on the original instance.

BCOVertigo,
@BCOVertigo@lemmy.world avatar

Low effort speculation:

That’s a vodaphone portugal IP, but this is likely traffic routing though their customer cellular network and not their corporate. It’s possible that someone in PT has a similar username for this service and is fat fingering it. It’s also possible that you’re seeing a tiny sliver of a larger attack.

Spur.us tracks that IP as an egress point for openproxy and windscribe ResIP networks so it’s worth considering that the origin of the authentications you’re seeing may not be Portuguese cellphone but someone hiding behind those services.

Here’s a paper describing the difficulties such a service creates for folks trying to secure accounts with traditional IP reputation based rules. “Resident Evil: Understanding Residential IP Proxy as a Dark Service” ieeexplore.ieee.org/document/8835239

Shooting in the dark for how a bad actor would monetize account takeover for this service if this is in fact an attack… They could try to sell your invitation to that private tracker. They could also look to scoop up a bunch of folks to try and blackmail based on what victims are download/seeding. Other more creative options I’m not thinking of might be on the table.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • localhost
  • All magazines
  • 200 @ user_overview
    HTTP status 200 OK
    Route name user_overview
    Has session yes
    Stateless Check no
    Time 350 ms
    Total time 350 ms
    Initialization time 73 ms
    Memory 12.0 MiB
    Peak memory usage 12.0 MiB
    PHP memory limit 128 MiB
    Logger 87
    Errors 0
    Warnings 0
    Deprecations 87
    Cache 26 in 28.71 ms
    Cache Calls 26
    Total time 28.71 ms
    Cache hits 33 / 38 (86.84%)
    Cache writes 3
    2
    Default locale en
    Missing messages 2
    Fallback messages 0
    Defined messages 132
    Security n/a
    Authenticated No
    Firewall name main
    Twig 113 ms
    Render Time 113 ms
    Template Calls 74
    Block Calls 16
    Macro Calls 0
    46 in 52 ms
    settings_row_switch 15
    user_settings_row_switch 4
    date 3
    user_avatar 2
    user_inline 2
    date_edited 2
    vote 2
    boost 2
    settings_row_enum 2
    user_box 1
    user_actions 1
    entry 1
    magazine_inline 1
    entry_comment 1
    related_magazines 1
    active_users 1
    related_categories 1
    related_posts 1
    related_entries 1
    support_us_block 1
    featured_magazines 1
    16 in 36.02 ms
    Database Queries 16
    Different statements 16
    Query time 36.02 ms
    Invalid entities 0
    Cache hits 22
    Cache misses 1
    Cache puts 1
    6.4.0
    Profiler token e4bb29
    Environment dev
    Debug enabled
    PHP version 8.2.26   View phpinfo()
    PHP Extensions Xdebug ✗ APCu ✓ OPcache ✓
    PHP SAPI apache2handler