# Binteca Threat Map: night ending 2026-10-03

Window: 2026-10-02T18:00:00+02:00 to 2026-10-03T06:00:00+02:00 (UTC+02:00). Target point: Johannesburg, ZA.

## Totals

| Metric | Overnight |
|---|---:|
| Attacks at the edge | 2,254 |
| New bans at the edge | 46 |
| Attacks (all sensors) | 2,584 |
| New bans (all sensors) | 76 |
| Requests seen | 71,871 |
| Blocked at the edge | 584 |
| Active bans at report time | 19 |
| Sensors reporting | 4 |

| Sensor | Kind | Attacks | New bans | Active bans |
|---|---|---:|---:|---:|
| edge | edge | 2,254 | 46 | 16 |
| web-1 | web | 130 | 13 | 1 |
| web-2 | web | 75 | 7 | 0 |
| web-3 | web | 125 | 10 | 2 |

## Attack categories

| Category | Attacks |
|---|---:|
| cms-probe | 1,866 |
| secret-probe | 612 |
| protocol | 35 |
| code-injection | 33 |
| scanner | 18 |
| traversal | 17 |

## Banned identifiers

- IP addresses banned: **71** (76 ban actions)
- E-mail addresses banned: 0
- Other identifiers banned: 0
- The WAF bans network addresses only; no e-mail or account identifiers appear in the source.

| IP | Country | City | ASN / org | Attack types | Bans | Max offence | State | Tags | Suspected actor (confidence) |
|---|---|---|---|---|---:|---:|---|---|---|
| `20.210.186.186` | JP | Osaka | AS8075 Microsoft Corporation | php-probe | 1 | 1 | expired | hosting-provider | Suspected CMS exploitation bot (low) |
| `20.198.74.230` | IN | Pune | AS8075 Microsoft Corporation | cms-probe | 1 | 1 | expired | hosting-provider | Suspected CMS exploitation bot (low) |
| `45.138.12.25` | HK | Sheung Wan | AS218785 TC DATACENTER LIMITED | secret-probe, credential-probe, php-probe | 1 | 1 | expired | abuse-prone-hosting, cluster:45.138.12.0/24 | Suspected credential/secret-harvesting campaign (medium) |
| `91.148.244.131` | NL | Haarlem (Oude Stad) | AS34343 Eweka Internet Services B.V. | credential-probe | 1 | 1 | expired |  | Suspected credential/secret-harvesting campaign (low) |
| `209.99.185.60` | US | San Francisco | AS402253 SKN Subnet & Telecom Ltd | secret-probe, credential-probe | 2 | 1 | expired | spamhaus-drop, firehol-level1 | Suspected credential/secret-harvesting campaign (medium) |
| `45.156.87.186` | NL | Amsterdam | AS197170 TechTies Inc. | credential-probe, secret-probe | 2 | 2 | expired | spamhaus-drop, firehol-level1, repeat-offender | Suspected credential/secret-harvesting campaign (medium) |
| `45.138.12.53` | HK | Sheung Wan | AS218785 TC DATACENTER LIMITED | secret-probe | 1 | 1 | expired | abuse-prone-hosting, cluster:45.138.12.0/24 | Suspected credential/secret-harvesting campaign (medium) |
| `27.102.121.33` | KR | Seongnam-si (Geumto-ro) | AS45996 DAOU TECHNOLOGY | php-probe | 1 | 1 | expired |  | Suspected CMS exploitation bot (low) |
| `45.138.12.45` | HK | Sheung Wan | AS218785 TC DATACENTER LIMITED | cms-probe | 1 | 1 | expired | abuse-prone-hosting, cluster:45.138.12.0/24 | Known-bad scanning infrastructure (medium) |
| `170.64.182.167` | AU | Alexandria | AS14061 DigitalOcean, LLC | secret-probe, rce-payload | 2 | 1 | expired | hosting-provider | Suspected Androxgh0st-style Laravel/PHPUnit exploitation (low) |
| `170.64.196.141` | AU | Alexandria | AS14061 DigitalOcean, LLC | secret-probe, rce-payload, cms-probe | 2 | 2 | expired | hosting-provider, repeat-offender | Suspected Androxgh0st-style Laravel/PHPUnit exploitation (low) |
| `170.64.197.162` | AU | Alexandria | AS14061 DigitalOcean, LLC | secret-probe | 2 | 1 | expired | hosting-provider | Suspected credential/secret-harvesting campaign (low) |
| `103.216.170.129` | IN | Mumbai (Navjeevan Society) | AS135198 Bombay Bullion Commmunication | rce-payload | 1 | 1 | expired |  | Suspected Mirai-style IoT botnet (medium) |
| `104.23.223.154` | SE | Stockholm | AS13335 Cloudflare, Inc. | secret-probe | 1 | 1 | expired | cdn-edge | CDN edge relaying an attack (true origin hidden) (high) |
| `104.23.223.8` | SE | Stockholm | AS13335 Cloudflare, Inc. | secret-probe | 1 | 1 | expired | cdn-edge | CDN edge relaying an attack (true origin hidden) (high) |
| `104.23.239.80` | DE | Frankfurt am Main | AS13335 Cloudflare, Inc. | secret-probe | 1 | 1 | expired | cdn-edge | CDN edge relaying an attack (true origin hidden) (high) |
| `104.28.245.161` | EG | Shubrā al Khaymah | AS13335 Cloudflare, Inc. | secret-probe | 1 | 1 | expired | cdn-edge | CDN edge relaying an attack (true origin hidden) (high) |
| `128.199.182.152` | SG | Singapore (Pioneer) | AS14061 DigitalOcean, LLC | secret-probe | 1 | 1 | expired | research-scanner | Internet research scanner (benign) (high) |
| `134.199.157.29` | AU | Alexandria | AS14061 DigitalOcean, LLC | secret-probe | 1 | 1 | expired | hosting-provider | Suspected credential/secret-harvesting campaign (low) |
| `134.199.164.71` | AU | Alexandria | AS14061 DigitalOcean, LLC | secret-probe | 1 | 1 | expired | hosting-provider | Suspected credential/secret-harvesting campaign (low) |
| `134.199.175.94` | AU | Alexandria | AS14061 DigitalOcean, LLC | cms-probe | 1 | 1 | expired | hosting-provider | Suspected CMS exploitation bot (low) |
| `138.201.135.150` | DE | Falkenstein | AS24940 Hetzner Online GmbH | rce-payload | 1 | 1 | expired | hosting-provider | Suspected exploit/RCE bot (low) |
| `14.117.192.81` | CN | Guangzhou | AS136199 CHINANET Guangdong province Yuedong MAN network | rce-payload | 1 | 1 | expired |  | Suspected Mirai-style IoT botnet (medium) |
| `159.223.180.252` | US | North Bergen | AS14061 DigitalOcean, LLC | secret-probe | 1 | 1 | expired | hosting-provider | Suspected credential/secret-harvesting campaign (low) |
| `159.89.98.12` | DE | Freiburg im Breisgau | AS14061 DigitalOcean, LLC | secret-probe | 1 | 1 | expired | hosting-provider | Suspected credential/secret-harvesting campaign (low) |
| `162.158.110.254` | DE | Frankfurt am Main | AS13335 Cloudflare, Inc. | secret-probe | 1 | 1 | expired | cdn-edge | CDN edge relaying an attack (true origin hidden) (high) |
| `164.90.228.79` | DE | Frankfurt am Main | AS14061 DigitalOcean, LLC | secret-probe | 1 | 1 | expired | research-scanner | Internet research scanner (benign) (high) |
| `170.64.131.170` | AU | Alexandria | AS14061 DigitalOcean, LLC | secret-probe | 1 | 1 | expired | hosting-provider | Suspected credential/secret-harvesting campaign (low) |
| `170.64.214.139` | AU | Alexandria | AS14061 DigitalOcean, LLC | secret-probe | 1 | 1 | expired | hosting-provider | Suspected credential/secret-harvesting campaign (low) |
| `172.68.194.182` | DE | Frankfurt am Main | AS13335 Cloudflare, Inc. | secret-probe | 1 | 1 | expired | cdn-edge | CDN edge relaying an attack (true origin hidden) (high) |
| `172.68.213.54` | CZ | Prague | AS13335 Cloudflare, Inc. | secret-probe | 1 | 1 | expired | cdn-edge | CDN edge relaying an attack (true origin hidden) (high) |
| `172.69.150.71` | DE | Frankfurt am Main | AS13335 Cloudflare, Inc. | secret-probe | 1 | 1 | expired | cdn-edge | CDN edge relaying an attack (true origin hidden) (high) |
| `172.70.240.180` | DE | Frankfurt am Main | AS13335 Cloudflare, Inc. | secret-probe | 1 | 1 | expired | cdn-edge | CDN edge relaying an attack (true origin hidden) (high) |
| `172.70.247.113` | DE | Frankfurt am Main | AS13335 Cloudflare, Inc. | secret-probe | 1 | 1 | expired | cdn-edge | CDN edge relaying an attack (true origin hidden) (high) |
| `172.70.250.57` | DE | Frankfurt am Main | AS13335 Cloudflare, Inc. | secret-probe | 1 | 1 | expired | cdn-edge | CDN edge relaying an attack (true origin hidden) (high) |
| `172.71.15.24` | CZ | Prague | AS13335 Cloudflare, Inc. | secret-probe | 1 | 1 | expired | cdn-edge | CDN edge relaying an attack (true origin hidden) (high) |
| `172.86.81.110` | SG | Singapore | AS14956 RouterHosting LLC | secret-probe | 1 | 3 | active | hosting-provider, repeat-offender | Suspected credential/secret-harvesting campaign (low) |
| `184.105.139.69` | US | Chicago | AS6939 Hurricane Electric LLC | secret-probe | 1 | 1 | expired | research-scanner | Internet research scanner (benign) (high) |
| `185.19.40.62` | DE | Frankfurt am Main | AS210558 1337 Services GmbH | cms-probe | 1 | 2 | expired | spamhaus-drop, firehol-level1, repeat-offender | Known-bad scanning infrastructure (medium) |
| `193.36.224.218` | US | Ormond Beach | AS206092 F.N.S. HOLDINGS LIMITED | cms-probe | 1 | 1 | expired | cluster:193.36.224.0/24 | Suspected CMS exploitation bot (medium) |
| `193.36.224.245` | US | Ormond Beach | AS206092 F.N.S. HOLDINGS LIMITED | cms-probe | 1 | 1 | expired | cluster:193.36.224.0/24 | Suspected CMS exploitation bot (medium) |
| `193.36.224.249` | US | Ormond Beach | AS206092 F.N.S. HOLDINGS LIMITED | cms-probe | 1 | 1 | expired | cluster:193.36.224.0/24 | Suspected CMS exploitation bot (medium) |
| `194.61.40.98` | IN | New Delhi | AS137409 GSL Networks Pty LTD | cms-probe | 1 | 1 | expired |  | Suspected CMS exploitation bot (low) |
| `195.178.110.106` | AD | Andorra la Vella | AS48090 TECHOFF SRV LIMITED | secret-probe | 1 | 1 | expired | spamhaus-drop, firehol-level1, abuse-prone-hosting, cluster:195.178.110.0/24 | Suspected credential/secret-harvesting campaign (medium) |
| `195.178.110.28` | AD | Andorra la Vella | AS48090 TECHOFF SRV LIMITED | secret-probe | 1 | 1 | expired | spamhaus-drop, firehol-level1, abuse-prone-hosting, cluster:195.178.110.0/24 | Suspected credential/secret-harvesting campaign (medium) |
| `20.65.202.209` | US | San Antonio | AS8075 Microsoft Corporation | attack-tool | 1 | 1 | expired | hosting-provider | Automated attack tool (low) |
| `203.159.90.72` | NL | Lelystad | AS210558 1337 Services GmbH | cms-probe | 1 | 3 | active | spamhaus-drop, firehol-level1, repeat-offender | Known-bad scanning infrastructure (medium) |
| `206.81.12.187` | US | North Bergen | AS14061 DigitalOcean, LLC | secret-probe | 1 | 1 | expired | research-scanner | Internet research scanner (benign) (high) |
| `209.141.51.90` | US | Las Vegas | AS53667 FranTech Solutions | rce-payload | 1 | 1 | expired |  | Suspected exploit/RCE bot (low) |
| `31.171.130.110` | GB | London | AS206092 F.N.S. HOLDINGS LIMITED | cms-probe | 1 | 1 | expired | cluster:31.171.130.0/24 | Suspected CMS exploitation bot (medium) |
| `31.171.130.154` | GB | London | AS206092 F.N.S. HOLDINGS LIMITED | cms-probe | 1 | 1 | expired | cluster:31.171.130.0/24 | Suspected CMS exploitation bot (medium) |
| `31.171.130.160` | GB | London | AS206092 F.N.S. HOLDINGS LIMITED | cms-probe | 1 | 1 | expired | cluster:31.171.130.0/24 | Suspected CMS exploitation bot (medium) |
| `34.12.94.35` | NL | Groningen | AS396982 Google LLC | secret-probe | 1 | 1 | expired | hosting-provider | Suspected credential/secret-harvesting campaign (low) |
| `34.178.138.173` | NL | Groningen | AS396982 Google LLC | secret-probe | 1 | 1 | expired | hosting-provider | Suspected credential/secret-harvesting campaign (low) |
| `34.21.135.165` | SG | Singapore | AS396982 Google LLC | secret-probe | 1 | 1 | expired | hosting-provider | Suspected credential/secret-harvesting campaign (low) |
| `34.23.78.56` | US | North Charleston | AS396982 Google LLC | secret-probe | 1 | 1 | expired | hosting-provider | Suspected credential/secret-harvesting campaign (low) |
| `35.185.17.194` | US | North Charleston | AS396982 Google LLC | secret-probe | 1 | 1 | expired | hosting-provider | Suspected credential/secret-harvesting campaign (low) |
| `35.222.122.52` | US | Council Bluffs | AS396982 Google LLC | secret-probe | 1 | 1 | expired | hosting-provider | Suspected credential/secret-harvesting campaign (low) |
| `35.225.6.63` | US | Council Bluffs | AS396982 Google LLC | secret-probe | 1 | 1 | expired | hosting-provider | Suspected credential/secret-harvesting campaign (low) |
| `37.120.213.13` | CH | Zurich | AS9009 M247 Europe SRL | rce-payload | 1 | 1 | expired | hosting-provider | Suspected exploit/RCE bot (low) |
| `43.136.79.172` | CN | Guangzhou | AS45090 Shenzhen Tencent Computer Systems Company Limited | rce-payload | 1 | 1 | expired | hosting-provider | Suspected exploit/RCE bot (low) |
| `43.157.211.165` | ID | Jakarta | AS132203 Shenzhen Tencent Computer Systems Company Limited | rce-payload | 1 | 1 | expired | hosting-provider | Suspected exploit/RCE bot (low) |
| `45.138.12.10` | HK | Sheung Wan | AS218785 TC DATACENTER LIMITED | secret-probe | 1 | 2 | expired | abuse-prone-hosting, repeat-offender, cluster:45.138.12.0/24 | Suspected credential/secret-harvesting campaign (medium) |
| `45.138.12.6` | HK | Sheung Wan | AS218785 TC DATACENTER LIMITED | secret-probe | 1 | 1 | expired | abuse-prone-hosting, cluster:45.138.12.0/24 | Suspected credential/secret-harvesting campaign (medium) |
| `45.138.12.9` | HK | Sheung Wan | AS218785 TC DATACENTER LIMITED | secret-probe | 1 | 1 | expired | abuse-prone-hosting, cluster:45.138.12.0/24 | Suspected credential/secret-harvesting campaign (medium) |
| `45.148.10.8` | AD | Andorra la Vella | AS48090 TECHOFF SRV LIMITED | secret-probe | 1 | 1 | expired | spamhaus-drop, firehol-level1, abuse-prone-hosting | Suspected credential/secret-harvesting campaign (medium) |
| `54.94.85.181` | BR | São Paulo | AS16509 Amazon.com, Inc. | secret-probe | 1 | 2 | expired | hosting-provider, repeat-offender | Suspected credential/secret-harvesting campaign (low) |
| `68.69.177.112` | US | Hollis | AS402226 OnlyScans LLC | attack-tool | 1 | 1 | expired | research-scanner | Internet research scanner (benign) (medium) |
| `71.62.11.39` | US | Charlottesville | AS7922 Comcast Cable Communications, LLC | secret-probe | 1 | 1 | expired |  | Suspected credential/secret-harvesting campaign (low) |
| `81.171.72.135` | NL | Haarlem (Oude Stad) | AS34343 Eweka Internet Services B.V. | credential-probe | 1 | 1 | expired |  | Suspected credential/secret-harvesting campaign (low) |
| `91.92.241.196` | NL | Amsterdam | AS202412 Omegatech LTD | secret-probe | 1 | 1 | expired | spamhaus-drop, firehol-level1 | Suspected credential/secret-harvesting campaign (medium) |

## Top sources by request count

| IP | Requests | Country | ASN / org | Status |
|---|---:|---|---|---|
| `20.210.186.186` | 184 | JP | AS8075 Microsoft Corporation | banned until Sat 22:26 |
| `20.198.74.230` | 183 | IN | AS8075 Microsoft Corporation | ban expired Sat 06:42 |
| `35.229.36.226` | 152 | US | AS396982 Google LLC | spared: shared address |
| `45.138.12.25` | 74 | HK | AS218785 TC DATACENTER LIMITED | spared: shared address |
| `45.138.12.43` | 42 | HK | AS218785 TC DATACENTER LIMITED | spared: shared address |
| `91.148.244.131` | 23 | NL | AS34343 Eweka Internet Services B.V. | ban expired 01:31 |
| `209.99.185.60` | 20 | US | AS402253 SKN Subnet & Telecom Ltd | ban expired 02:10 |
| `45.156.87.186` | 12 | NL | AS197170 TechTies Inc. | ban expired 22:53 |
| `45.138.12.53` | 8 | HK | AS218785 TC DATACENTER LIMITED | spared: shared address |
| `27.102.121.33` | 7 | KR | AS45996 DAOU TECHNOLOGY | ban expired 03:37; not banned |
| `45.138.12.45` | 5 | HK | AS218785 TC DATACENTER LIMITED | ban expired 23:11 |
| `167.250.224.25` | 4 | BR | AS265210 OSCAR M DE CARVALHO - ME | not banned |
| `152.42.141.52` | 2 | NL | AS14061 DigitalOcean, LLC | not banned |
| `167.71.105.201` | 2 | US | AS14061 DigitalOcean, LLC | not banned |

## Most severe findings

| Severity | Rule | Requests | Addresses | First | Example source | Example request |
|---|---|---:|---:|---|---|---|
| critical | Secret or VCS file probe (BW-SEC-01) | 409 | 40 | 18:02 | `96.126.130.210` | `GET /.env` |
| critical | Credential, state or dump file probe (BW-SEC-02) | 49 | 6 | 19:09 | `45.156.87.186` | `GET /wp-config.php` |
| critical | PHP or shell payload (BW-RCE-03) | 22 | 7 | 19:22 | `170.64.182.167` | `POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php` |
| critical | Traversal to a system file (BW-TRV-01) | 13 | 2 | 00:01 | `34.19.75.177` | `GET /[@]fs/proc/self/environ?import&raw??` |
| critical | Secret or VCS file probe (BW-SEC-01) | 35 | 8 | 18:54 | `170.64.196.141` | `GET /.env` |
| critical | PHP or shell payload (BW-RCE-03) | 6 | 2 | 20:41 | `170.64.196.141` | `POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php` |
| critical | Credential, state or dump file probe (BW-SEC-02) | 2 | 1 | 21:53 | `45.156.87.186` | `GET /wp-config.php` |
| critical | Secret or VCS file probe (BW-SEC-01) | 21 | 4 | 19:23 | `170.64.182.167` | `GET /.env` |
| critical | PHP or shell payload (BW-RCE-03) | 3 | 2 | 23:43 | `14.117.192.81` | `POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh` |
| critical | Credential, state or dump file probe (BW-SEC-02) | 1 | 1 | 01:10 | `209.99.185.60` | `GET /id_rsa` |
| critical | Secret or VCS file probe (BW-SEC-01) | 81 | 8 | 19:02 | `104.23.239.80` | `GET /.git/config` |
| critical | Credential, state or dump file probe (BW-SEC-02) | 14 | 2 | 19:19 | `45.138.12.25` | `GET /wp-config.php.bak` |
| critical | PHP or shell payload (BW-RCE-03) | 2 | 2 | 22:54 | `103.216.170.129` | `POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh` |
| high | Deep directory traversal (BW-TRV-02) | 4 | 2 | 00:01 | `34.19.75.177` | `GET /_image?href=/../../../.env` |
| high | Attack tool user agent (BW-UA-01) | 5 | 4 | 20:10 | `20.65.202.209` | `GET /` |
| high | Attack tool user agent (BW-UA-01) | 5 | 5 | 20:16 | `20.80.111.73` | `GET /` |
| high | Attack tool user agent (BW-UA-01) | 8 | 7 | 19:19 | `172.202.106.156` | `GET /owa/auth/logon.aspx` |
| medium | CMS, admin or appliance probe (BW-CMS-01) | 54 | 5 | 20:41 | `170.64.196.141` | `GET /_ignition/execute-solution` |
| medium | CMS, admin or appliance probe (BW-CMS-01) | 26 | 4 | 18:23 | `203.159.90.72` | `GET //wp-includes/wlwmanifest.xml` |
| medium | PHP script probe (BW-PHP-01) | 10 | 4 | 19:19 | `45.138.12.25` | `GET /phpinfo.php` |

## Suspected actors and campaigns

Labels are heuristic groupings of infrastructure and behaviour, **not attribution**. See the README.

| Suspected actor / campaign | Confidence | Addresses | Top countries | Evidence |
|---|---|---:|---|---|
| Suspected credential/secret-harvesting campaign | medium | 32 | US 8, NL 6, HK 5, AU 5, AD 3 | hunts for .env, VCS or credential files; listed on Spamhaus DROP; listed on FireHOL level 1; AS218785 TC DATACENTER (abuse-prone hosting) |
| CDN edge relaying an attack (true origin hidden) | high | 12 | DE 7, SE 2, CZ 2, EG 1 | AS13335 Cloudflare is a CDN; the real client is behind it |
| Suspected CMS exploitation bot | medium | 11 | US 3, GB 3, IN 2, JP 1, KR 1 | CMS, admin panel or PHP script probing; 3 addresses from 193.36.224.0/24 (AS206092) attacked the same night; 3 addresses from 31.171.130.0/24 (AS206092) attacked the same night |
| Internet research scanner (benign) | high | 5 | US 3, SG 1, DE 1 | reverse DNS cdffb2c5b1.scan.leakix.org; reverse DNS fee8d5bfdc.scan.leakix.org; reverse DNS scan-03.shadowserver.io; reverse DNS bf99e5305e.scan.leakix.org |
| Suspected exploit/RCE bot | low | 5 | DE 1, US 1, CH 1, CN 1, ID 1 | sent a shell or PHP payload |
| Unattributed automated probe | low | 4 | US 2, BR 1, NL 1 |  |
| Known-bad scanning infrastructure | medium | 4 | HK 2, DE 1, NL 1 | AS218785 TC DATACENTER (abuse-prone hosting); 7 addresses from 45.138.12.0/24 (AS218785) attacked the same night; listed on Spamhaus DROP; listed on FireHOL level 1 |
| Automated attack tool | low | 3 | US 3 | request carried a known attack-tool user agent |
| Suspected Androxgh0st-style Laravel/PHPUnit exploitation | low | 2 | AU 2 | probes PHPUnit eval-stdin.php (CVE-2017-9841), a technique documented in CISA AA24-016A; no request bodies are logged, so the malware family cannot be confirmed |
| Suspected Mirai-style IoT botnet | medium | 2 | IN 1, CN 1 | IoT/router exploit path with a downloader typical of Mirai-family loaders |

_Binteca Threat Map (https://cybermap.binteca.io), generated 2026-10-07T11:35:12Z from the overnight WAF summary. Geolocation: DB-IP Lite (CC BY 4.0)._
