Aller directement au contenu principalAller directement au pied de page

Catégories de menaces

ReportedIP uses 30 predefined threat categories to classify malicious activity. Each category has a severity level from 1 (low) to 10 (critical) that influences the confidence score calculation. When reporting an IP, you specify one or more category IDs to describe the type of attack observed.

All Categories

1 Élevé
DNS Compromise
Compromised or hijacked DNS servers
10
2 Critique
DNS Poisoning
DNS cache poisoning attempts
10
3 Moyen
Fraud Orders
Fraudulent orders in online shops
10
4 Critique
DDoS Attack
Distributed denial-of-service attacks
10
5 Élevé
FTP Brute-Force
Brute-force attacks against FTP services
10
6 Élevé
Ping of Death
Oversized-ping (Ping of Death) attacks
10
7 Critique
Phishing
Hosting or distributing phishing sites
10
8 Moyen
Fraud VoIP
VoIP fraud and toll abuse
10
9 Moyen
Open Proxy
Open proxy servers used to relay abuse
10
10 Moyen
Web Spam
Spam posted to websites and forums
10
11 Moyen
Email Spam
Unsolicited bulk email (spam) sources
10
#12 Low
Blog Spam
Spam comments on blogs
10
#13 Low
VPN IP
VPN exit nodes (low direct threat)
10
14 Moyen
Port Scan
Port scanning and service probing
10
15 Élevé
Hacking
General hacking activity
10
16 Critique
Injection SQL
SQL injection attack attempts
10
17 Élevé
Spoofing
IP or email spoofing
10
18 Élevé
Brute-Force
Credential brute-force attacks
10
19 Moyen
Bad Web Bot
Malicious or abusive web bots
10
20 Élevé
Exploited Host
Compromised hosts under attacker control
10
21 Élevé
Web App Attack
Attacks against web applications
10
22 Élevé
SSH
SSH brute-force and abuse
10
23 Élevé
IoT Targeted
Attacks targeting IoT devices
10
24 Moyen
Cryptocurrency Mining
Unauthorised cryptocurrency mining
10
25 Critique
Ransomware C&C
Ransomware command-and-control infrastructure
10
26 Critique
Banking Trojan
Banking trojan distribution or control
10
27 Élevé
Mobile Malware
Mobile malware distribution
10
28 Critique
Supply Chain Attack
Software supply-chain attacks
10
29 Critique
Zero-Day Exploit
Exploitation of unpatched zero-day vulnerabilities
10
30 Critique
Nation State
State-sponsored attack activity
10
31 Élevé
WP Login Brute Force
Brute force attacks on wp-login.php
10
32 Élevé
WP Admin Brute Force
Attacks on WordPress admin area
10
33 Élevé
WP XML-RPC Brute Force
Abuse of XML-RPC interface
10
34 Élevé
WP REST API Abuse
Abuse of WordPress REST API
10
35 Élevé
WP Plugin Exploit
Exploitation of plugin vulnerabilities
10
36 Élevé
WP Theme Exploit
Exploitation of theme vulnerabilities
10
37 Critique
WP Core Exploit
Attacks on WordPress core vulnerabilities
10
38 Critique
WP Zero-Day Exploit
Unknown WordPress exploits
10
#39 Low
WP Comment Spam
Spam in WordPress comments
10
40 Moyen
WP Contact Form Spam
Spam via contact forms
10
41 Moyen
WP Registration Spam
Fake user registrations
10
42 Moyen
WP Trackback Spam
Trackback/Pingback spam
10
43 Critique
WP File Upload Malware
Malware upload via WordPress
10
44 Critique
WP Code Injection
PHP/JavaScript code injection
10
45 Critique
WP Database Injection
SQL injection in WordPress
10
46 Critique
WP Backdoor Installation
Installation of backdoors
10
47 Moyen
WP SEO Spam
SEO spam and link injection
10
48 Moyen
WP Content Scraping
Automated content scraping
10
49 Moyen
WP Fake SEO Bot
Malicious SEO crawlers
10
50 Élevé
WP Redirect Hijacking
Manipulation of redirects
10
51 Élevé
WP Resource Exhaustion
DoS through resource consumption
10
52 Moyen
WP Media Library Abuse
Abuse of media library
10
53 Moyen
WP Search Abuse
Overload of search function
10
54 Moyen
WP Cron Abuse
Abuse of WP-Cron
10
55 Moyen
WP User Enumeration
Enumeration of WordPress users
10
56 Élevé
WP Version Scanning
Scanning for WordPress versions
10
57 Élevé
WP Plugin Scanning
Detection of installed plugins
10
58 Élevé
WP Config Exposure
Access to wp-config.php
10

Using Categories in the API

When reporting an IP via the /report endpoint, include the category ID in your request to classify the type of threat observed. The category severity directly influences the confidence score. Full endpoint documentation lives in the Référence de l'API; the Page « Liste noire » shows how to build category-filtered, service-specific block lists.

Report with Category

boucle
curl -X POST \
     -H "X-Key: YOUR_API_KEY" \
     -H "Content-Type: application/json" \
     -d '{"ip": "1.2.3.4", "categories": [4, 15], "comment": "Brute force SSH + port scan"}' \
     "https://reportedip.de/wp-json/reportedip/v2/report"
200 OK
json
{
  "data": {
    "ipAddress": "1.2.3.4",
    "abuseConfidencePercentage": 42,
    "reportId": "12345"
  }
}

Retrieve All Categories

You can fetch the full list of categories programmatically:

boucle
curl "https://reportedip.de/wp-json/reportedip/v2/categories"
Tip: Higher severity categories have a greater impact on the confidence score. Always choose the most accurate category for your report — it helps the community make better blocking decisions.

Severity Scale

The severity scale ranges from 1 to 10 and maps to four threat levels:

Level Severity Description Example
Low 1 – 3 Minor or informational threats Web scraping, comment spam
Medium 4 – 6 Moderate threats requiring attention Brute force login, credential stuffing
High 7 – 8 Serious threats with potential damage SQL injection, XSS attacks
Critical 9 – 10 Severe threats requiring immediate action DDoS, ransomware, zero-day exploits

Dernière mise à jour : · Géré par ReportedIP

Axé sur la sécurité
Conforme au RGPD
Fabriqué en Allemagne
Retour à Docs