Weekly Report for 2026-04-24 to 2026-05-01

STIX2 Threat Intelligence Feeds (109,673 indicators this week)

Weekly Intelligence Summary

88.0KAttacking IPs This Week
182Source Countries
2.1KPhishing Domains
27.1KProxy/Anon IPs
4.0KWeb Exploit Events
12CVEs Exploited
55OpenCLAW Events

Weekly Comparison

Attacks by Destination

Attacks By Country & ASN

Attacks By Protocol

SSH (60,827 IPs)

FTP (111 IPs)

SIP (130 IPs)

TELNET (2,753 IPs)

MSSQL (398 IPs)

MYSQL (120 IPs)

REDIS (389 IPs)

Cloud Provider Abuse

Phishing Domains by Category

Top SSH Bruteforce Usernames

Infrastructure Analysis

Tor Exit Nodes (2,305 total)

Infrastructure Type

Anonymous Proxy Hosts (27,115 total)

Emerging Threats (Last 24h)

IP AddressThreat ScoreCountryTags
107.189.8.65100Luxembourgattack Bruteforce Brute-Force cowrie cve202229266 cyber security
185.94.111.1100RussiaAlaska cowrie ddos denial of service IPs Attacking Alaskan Hosts malicious
193.107.216.228100Hong Kongbruteforce cyber security digital ocean Energy ICS ioc
193.46.255.60100Romaniaawsau awsbah awsindia awsjap blacklist botnet
92.63.196.25100Russiaadmin blacklist botnet brute force Energy green
92.63.196.61100Russiaadmin blacklist botnet brute force Energy green
89.248.165.202100NetherlandsAlaska auto-generated security botnet green IPs Attacking Alaskan Hosts kfsensor
5.61.11.123100Russiablacklist botnet cyber security Energy green ICS
154.89.5.86100Hong Kongcyber security ioc malicious Nextray phishing Scanner
183.136.226.3100Chinabrute force cyber security Energy green ICS ioc
183.136.226.4100Chinabruteforce cyber security digital ocean Energy green ICS
176.192.99.26100Russiaattack awsau bruteforce cyber security Energy green
144.172.118.37100United Statesattack cve202229266 cyber security description description ip indicator
209.141.34.39100United StatesBruteforce Brute-Force cowrie cyber security ioc LokiBot
45.146.165.165100RussiaBot Exploit IOC Malware Nextray Scanner
45.143.203.3100Ukraineadmin blacklist botnet green Malicious IP mirai
89.248.163.140100United Kingdomauto-generated security Brute force count cyber security ioc kfsensor
104.16.18.941000 report 10357 aaaa abuse contact accept access ta0001
45.143.200.50100Russiaadmin Alaska alienvault blacklist botnet cyber security
80.254.126.75100Russiacyber security green ioc kfsensor malicious Nextray

Web Exploit Detection Summary

4.0KExploit Events
1.1KUnique Attacker IPs
45Rules Triggered
12CVEs Observed
SourceRuleEventsUnique IPsCVEs
ETET WEB_SERVER Suspected FOXSHELL Variant Webshell Activity1,880783
ETET WEB_SERVER Suspected FOXSHELL Variant Webshell Activity1,880783
ETET WEB_SERVER WEB-PHP phpinfo access72534CVE-2002-1149
ETET SCAN WordPress Scanner Performing Multiple Requests to Windows Live Writer XML62870
ETET WEB_SERVER Possible DROP SQL Injection Attempt151103
LOCALLOCAL PHP Source Backup File Grab Attempt10911
LOCALLOCAL AWS Credentials File Grab Attempt9948
ETGPL WEB_SERVER 403 Forbidden6545
ETET SCAN Google Webcrawler User-Agent (Mediapartners-Google)5555
ETET WEB_SERVER /bin/sh In URI Possible Shell Command Execution Attempt5325
ETET WEB_SPECIFIC_APPS Rails Arbitrary File Disclosure Attempt5225CVE-2019-5418
ETET EXPLOIT Vulnerable Microsoft Exchange Server Response (CVE-2021-31207)4924CVE-2021-31207
ETGPL WEB_SERVER .htpasswd access3014
ETET WEB_SERVER Possible SQL Injection Obfuscated by REVERSE function in HTTP Request Body295
ETET WEB_SERVER Possible SQL injection obfuscated via REVERSE function in HTTP URI295
ETET EXPLOIT Apache HTTP Server 2.4.49 - Path Traversal Attempt (CVE-2021-41773) M22725CVE-2021-41773
ETET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M22624CVE-2021-42013
ETET WEB_SERVER Possible CREATE SQL Injection Attempt in URI2523
LOCALLOCAL Spring Boot Actuator Sensitive Endpoint Probe235
ETET WEB_SPECIFIC_APPS SonicWall SonicOS Unauthenticated Stack-Based Buffer Overflow (CVE-2022-22274) M1167CVE-2022-22274 CVE-2023-0656

CVE Exploitation Activity

CVE-2002-1149 CVE-2019-5418 CVE-2021-31207 CVE-2021-41773 CVE-2021-42013 CVE-2022-22274 CVE-2023-0656 CVE-2023-1389 CVE-2021-26855 CVE-2019-0193 CVE-2021-22005 CVE-2010-0738

OpenCLAW Dashboard Intelligence

55Total Events
13Unique Attackers
8Days Active

Attack Types

TypeCountShare
generic-probe60100.0%

Severity Distribution

SeverityCountPercentage
low60100.0%
Share on: