Weekly Report for 2026-09-01 to 2026-09-08
Sep 08, 2026
Weekly Reports
STIX2 Threat Intelligence Feeds (74,781 indicators this week)
Weekly Intelligence Summary
45.1KAttacking IPs This Week
160Source Countries
1.7KPhishing Domains
0Proxy/Anon IPs
1.8MTotal IPs in Database
21.2KNetworks Tracked
4.8KWeb Exploit Events
23CVEs Exploited
2.0KOpenCLAW Events
Weekly Comparison
Threat Score Distribution
Average threat score across all tracked IPs: 18.0/100
Attacks by Destination
Attacks By Country & ASN
Attacks By Protocol
SSH (44,914 IPs)
FTP (68 IPs)
SIP (141 IPs)
TELNET (978 IPs)
MSSQL (212 IPs)
MYSQL (76 IPs)
REDIS (247 IPs)
MITRE ATT&CK Techniques
Cloud Provider Abuse
Top Attacking Networks
Attack Classification Tags
Phishing Domains by Category
Top SSH Bruteforce Usernames
Infrastructure Analysis
Tor Exit Nodes (3,087 total)
Infrastructure Type
Anonymous Proxy Hosts
No proxy data available.
Emerging Threats (Last 24h)
| IP Address | Threat Score | Country | Tags |
|---|---|---|---|
| 107.189.8.65 | 100 | Luxembourg | attack Bruteforce Brute-Force cowrie cve202229266 cyber security |
| 185.94.111.1 | 100 | Russia | Alaska cowrie ddos denial of service IPs Attacking Alaskan Hosts malicious |
| 193.107.216.228 | 100 | Hong Kong | bruteforce cyber security digital ocean Energy ICS ioc |
| 193.46.255.60 | 100 | Romania | awsau awsbah awsindia awsjap blacklist botnet |
| 92.63.196.25 | 100 | Russia | admin blacklist botnet brute force Energy green |
| 92.63.196.61 | 100 | Russia | admin blacklist botnet brute force Energy green |
| 89.248.165.202 | 100 | Netherlands | Alaska auto-generated security botnet green IPs Attacking Alaskan Hosts kfsensor |
| 5.61.11.123 | 100 | Russia | blacklist botnet cyber security Energy green ICS |
| 154.89.5.86 | 100 | Hong Kong | cyber security ioc malicious Nextray phishing Scanner |
| 183.136.226.3 | 100 | China | brute force cyber security Energy green ICS ioc |
| 183.136.226.4 | 100 | China | bruteforce cyber security digital ocean Energy green ICS |
| 176.192.99.26 | 100 | Russia | attack awsau bruteforce cyber security Energy green |
| 144.172.118.37 | 100 | United States | attack cve202229266 cyber security description description ip indicator |
| 209.141.34.39 | 100 | United States | Bruteforce Brute-Force cowrie cyber security ioc LokiBot |
| 45.146.165.165 | 100 | Russia | Bot Exploit IOC Malware Nextray Scanner |
| 45.143.203.3 | 100 | Ukraine | admin blacklist botnet green Malicious IP mirai |
| 89.248.163.140 | 100 | United Kingdom | auto-generated security Brute force count cyber security ioc kfsensor |
| 104.16.18.94 | 100 | 0 report 10357 aaaa abuse contact accept access ta0001 | |
| 45.143.200.50 | 100 | Russia | admin Alaska alienvault blacklist botnet cyber security |
| 80.254.126.75 | 100 | Russia | cyber security green ioc kfsensor malicious Nextray |
Highest Risk Networks
| Network | Risk Score | IPs | Risk Level |
|---|---|---|---|
| AS60729 zwiebelfreunde e.v. | 85 | 16 | |
| AS210731 forening for dotsrc | 84 | 11 | |
| AS4224 the calyx institute | 81 | 21 | |
| AS208294 cia triad security llc | 69 | 116 | |
| AS396507 emerald onion | 62 | 34 | |
| AS1101 surfnet bv | 59 | 38 | |
| AS57724 ddos guard ltd | 53 | 20 | |
| AS15736 mobile business solution mbs llp | 49 | 11 | |
| AS138740 citylink broadbnad services pvt ltd | 48 | 13 | |
| AS137280 kingsoft cloud corporation limited | 48 | 102 | |
| AS206264 amarutu technology ltd | 46 | 11 | |
| AS39351 31173 services ab | 45 | 15 | |
| AS202660 uzbektelekom joint stock company | 45 | 17 | |
| AS58541 qingdao 266000 | 45 | 176 | |
| AS263333 vipturbo comrcio & servios de informtica ltda | 45 | 32 |
Web Exploit Detection Summary
4.8KExploit Events
333Unique Attacker IPs
54Rules Triggered
23CVEs Observed
| Source | Rule | Events | Unique IPs | CVEs |
|---|---|---|---|---|
| ET | ET WEB_SERVER WEB-PHP phpinfo access | 1,857 | 86 | CVE-2002-1149 |
| ET | ET SCAN WordPress Scanner Performing Multiple Requests to Windows Live Writer XML | 938 | 68 | — |
| LOCAL | LOCAL AWS Credentials File Grab Attempt | 454 | 52 | — |
| ET | ET WEB_SPECIFIC_APPS Rails Arbitrary File Disclosure Attempt | 405 | 42 | CVE-2019-5418 |
| LOCAL | LOCAL PHP Source Backup File Grab Attempt | 365 | 99 | — |
| LOCAL | LOCAL Microsoft Exchange ECP Admin Probe (ProxyShell/ProxyLogon) | 260 | 12 | CVE-2021-26855 |
| LOCAL | LOCAL Spring Boot Actuator Sensitive Endpoint Probe | 189 | 95 | — |
| ET | ET WEB_SERVER Likely Malicious Request for /proc/self/environ | 106 | 17 | — |
| ET | ET WEB_SERVER /etc/passwd Detected in URI | 97 | 13 | — |
| ET | ET EXPLOIT [FIREEYE] Suspicious Pulse Secure HTTP Request (CVE-2021-22893) M1 | 81 | 2 | CVE-2021-22893 |
| ET | ET WEB_SPECIFIC_APPS SonicWall SonicOS Unauthenticated Stack-Based Buffer Overflow (CVE-2022-22274) M1 | 61 | 48 | CVE-2022-22274 CVE-2023-0656 |
| ET | ET SCAN Suspicious User-Agent Containing Web Scan/er Likely Web Scanner | 35 | 5 | — |
| LOCAL | LOCAL Ivanti Connect Secure Admin Interface Probe | 27 | 2 | CVE-2024-21887 |
| ET | ET WEB_SERVER /bin/sh In URI Possible Shell Command Execution Attempt | 25 | 13 | — |
| ET | ET SCAN SFTP/FTP Password Exposure via sftp-config.json | 22 | 11 | — |
| ET | ET SCAN ELF/Mirai Variant User-Agent (Inbound) | 14 | 9 | — |
| ET | ET EXPLOIT Apache HTTP Server 2.4.49 - Path Traversal Attempt (CVE-2021-41773) M2 | 13 | 13 | CVE-2021-41773 |
| ET | GPL WEB_SERVER .htpasswd access | 12 | 8 | — |
| ET | ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 | 12 | 12 | CVE-2021-42013 |
| ET | ET WEB_SERVER WebShell Generic - wget http - POST | 11 | 4 | — |
CVE Exploitation Activity
CVE-2002-1149 CVE-2019-5418 CVE-2021-26855 CVE-2021-22893 CVE-2022-22274 CVE-2023-0656 CVE-2024-21887 CVE-2021-41773 CVE-2021-42013 CVE-2023-1389 CVE-2002-0953 CVE-2019-0193 CVE-2021-22005 CVE-2024-4577 CVE-2020-5902 CVE-2023-35082 CVE-2023-49103 CVE-2024-32114 CVE-2000-0868 CVE-2024-3400
Web Exploit Attacker Countries (253 IPs)
OpenCLAW Dashboard Intelligence
2.0KTotal Events
59Unique Attackers
8Days Active
Attack Types
| Type | Count | Share | |
|---|---|---|---|
| generic-probe | 1,253 | 91.5% | |
| admin-scan | 112 | 8.2% | |
| oauth-probe | 4 | 0.3% |
Severity Distribution
| Severity | Count | Percentage |
|---|---|---|
| medium | 112 | 8.2% |
| low | 1,253 | 91.8% |