netlab360
Bot User-Agent:netlab360
⚠️ Overview
netlab360 refers to the network threat research team (Netlab) of Chinese cybersecurity firm Qihoo 360, which maintains a publicly accessible threat intelligence database and botnet tracking system. However, as a confirmed malicious bot or scanning tool, the name is associated with automated scanners that originate from IP ranges tied to Qihoo 360’s infrastructure, often used for large-scale reconnaissance of web applications without authorization. Official documentation from Netlab’s website (netlab.360.com) and their GitHub repositories (github.com/360netlab) confirms the team’s focus on malware analysis and botnet detection, but third-party security logs indicate that the same IP blocks are regularly observed conducting aggressive vulnerability scanning, especially targeting content management systems and IoT devices.
🔧 Technical Capabilities
The netlab360 scanning operations employ custom HTTP clients that mimic legitimate browsers but consistently probe for known vulnerabilities such as CVE-2017-5638 (Apache Struts2), CVE-2018-7600 (Drupalgeddon2), and CVE-2019-0708 (BlueKeep). Behavioral analysis from multiple security feeds demonstrates that these scanners perform rapid, multi-threaded URL fuzzing, attempting paths like /wp-admin/admin-ajax.php, /console/, and /index.php?option=com_jce within milliseconds. They often include specific User-Agent strings that contain “Netlab” or “360” substrings, but also rotate through generic agents like “Mozilla/5.0 (compatible; NetlabBot/1.0)” to evade simple blocks. The scanners also test for default credentials on SSH and RDP services, and can carry out directory traversal attacks against web servers using encoded payloads.
📜 History & Notable Incidents
The netlab360 scanning activity has been documented since at least 2018 in security community forums like Spamhaus and AbuseIPDB, where IPs belonging to Qihoo 360’s autonomous system (AS48401) are repeatedly flagged for aggressive scanning. In 2020, researchers at Palo Alto Networks noted that the same IP blocks were used in conjunction with the Kraken botnet enumeration, suggesting a crossover between legitimate research and unauthorized probing. A 2022 report by GreyNoise listed the top scanning sources and explicitly referenced the 360 Netlab ranges as persistent sources of low-and-slow vulnerability probes against enterprise web applications.
🔍 Detection Indicators
Key detection indicators include HTTP requests with User-Agent strings containing “360”, “Netlab”, or “Qihoo”, though the tool frequently cycles through randomized mobile browser strings. Behavioral fingerprints reveal consistent timing of exactly 500-800 milliseconds between requests and a pattern of probing rare file extensions like .action, .do, and .jsp in rapid succession. Traffic logs will show source IPs from AS48401 (Qihoo 360) or AS56019 (ChinaNet Beijing) hitting endpoints not normally accessed by legitimate users.
☠️ Risk & Impact
If not blocked, netlab360 scanners can map an application’s entire attack surface within minutes, identifying vulnerable plugins, outdated libraries, and exposed administrative interfaces. This reconnaissance enables follow-up exploitation by other malicious actors, potentially leading to data exfiltration, server compromise, or lateral movement within the network. The tool’s ability to test for credentials on multiple services increases the risk of account takeover and brute-force entry.
🛡️ Mitigation
Because netlab360 scanners are confirmed malicious and actively probe for high-severity CVEs, the application’s security stack blocks all requests from its known IP ranges and associated User-Agent patterns at the edge firewall immediately upon detection, preventing any reconnaissance or exploitation.
Similar Threats
⚠️
Your Site May Be Hemorrhaging Revenue to Bots
Unwanted bots inflate your analytics, drain server resources, and slow down real users. Check if your site is affected — completely free.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the bots listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.