Weekly Report for 2026-05-01 to 2026-05-08

STIX2 Threat Intelligence Feeds (82,577 indicators this week)

Weekly Intelligence Summary

67.2KAttacking IPs This Week
182Source Countries
1.6KPhishing Domains
27.1KProxy/Anon IPs
3.8KWeb Exploit Events
19CVEs Exploited
62OpenCLAW Events

Weekly Comparison

Threat Score Distribution

Average threat score across all tracked IPs: 18.3/100

Attacks by Destination

Attacks By Country & ASN

Attacks By Protocol

SSH (39,681 IPs)

FTP (31 IPs)

SIP (100 IPs)

TELNET (1,444 IPs)

MSSQL (171 IPs)

MYSQL (42 IPs)

REDIS (91 IPs)

MITRE ATT&CK Techniques

Cloud Provider Abuse

Top Attacking Networks

Attack Classification Tags

Phishing Domains by Category

Top SSH Bruteforce Usernames

Infrastructure Analysis

Tor Exit Nodes (2,315 total)

Infrastructure Type

Anonymous Proxy Hosts (27,061 total)

Highest Risk Networks

NetworkRisk ScoreIPsRisk Level
AS60729 zwiebelfreunde e.v.8516
AS210731 forening for dotsrc8411
AS4224 the calyx institute8121
AS208294 cia triad security llc69116
AS396507 emerald onion6234
AS1101 surfnet bv5938
AS57724 ddos guard ltd5320
AS15736 mobile business solution mbs llp4911
AS138740 citylink broadbnad services pvt ltd4813
AS137280 kingsoft cloud corporation limited48102
AS38345 internet domain name system beijing engineering resrarch center ltd.4714
AS206264 amarutu technology ltd4611
AS39351 31173 services ab4515
AS58541 qingdao 26600045176
AS263333 vipturbo comrcio & servios de informtica ltda4532

Web Exploit Detection Summary

3.8KExploit Events
1.1KUnique Attacker IPs
57Rules Triggered
19CVEs Observed
SourceRuleEventsUnique IPsCVEs
ETET WEB_SERVER Suspected FOXSHELL Variant Webshell Activity1,723697
ETET WEB_SERVER Suspected FOXSHELL Variant Webshell Activity1,723697
ETET SCAN WordPress Scanner Performing Multiple Requests to Windows Live Writer XML57547
ETET WEB_SERVER WEB-PHP phpinfo access33538CVE-2002-1149
ETGPL WEB_SERVER 403 Forbidden16952
ETET WEB_SERVER Possible DROP SQL Injection Attempt14072
ETET EXPLOIT Vulnerable Microsoft Exchange Server Response (CVE-2021-31207)13431CVE-2021-31207
LOCALLOCAL Spring Boot Actuator Sensitive Endpoint Probe13131
ETET WEB_SPECIFIC_APPS Rails Arbitrary File Disclosure Attempt9430CVE-2019-5418
ETET SCAN Google Webcrawler User-Agent (Mediapartners-Google)7575
LOCALLOCAL AWS Credentials File Grab Attempt6348
ETET EXPLOIT [FIREEYE] Suspicious Pulse Secure HTTP Request (CVE-2021-22893) M1632CVE-2021-22893
ETET WEB_SERVER /bin/sh In URI Possible Shell Command Execution Attempt4421
ETET WEB_SERVER PHP Possible https Local File Inclusion Attempt3836CVE-2002-0953
ETET WEB_SERVER PHP Generic Remote File Include Attempt (HTTPS)3836
LOCALLOCAL Microsoft Exchange ECP Admin Probe (ProxyShell/ProxyLogon)3110CVE-2021-26855
ETET WEB_SERVER Possible SQL Injection Obfuscated by REVERSE function in HTTP Request Body294
ETET WEB_SERVER Possible SQL injection obfuscated via REVERSE function in HTTP URI294
ETGPL WEB_SERVER DELETE attempt251
ETET EXPLOIT Apache HTTP Server 2.4.49 - Path Traversal Attempt (CVE-2021-41773) M22221CVE-2021-41773

CVE Exploitation Activity

CVE-2002-1149 CVE-2021-31207 CVE-2019-5418 CVE-2021-22893 CVE-2002-0953 CVE-2021-26855 CVE-2021-41773 CVE-2021-42013 CVE-2024-21887 CVE-2022-22274 CVE-2023-0656 CVE-2023-1389 CVE-2020-5902 CVE-2021-22005 CVE-2000-0778 CVE-2016-0061 CVE-2024-3400 CVE-2000-0868 CVE-2024-4577

OpenCLAW Dashboard Intelligence

62Total Events
19Unique Attackers
8Days Active

Attack Types

TypeCountShare
generic-probe8698.9%
admin-scan11.1%

Severity Distribution

SeverityCountPercentage
medium11.1%
low8698.9%
Share on: