AIT Security Center V11

Real Threat Intelligence Platform

Real cyber threat intelligence generated from AIT NODE SECURITY AI history, firewall detections, GeoLite2 GEO cache and ASN provider intelligence.

LIVE THREAT INTELLIGENCE METRICS

Unique threat IPs35 342
Total attack events370 610
Critical IPs16 874
High risk IPs4 471
Public Safe Feed Intelligence

Feed Consumer & External Reputation Pulse

Public dashboard mode shows aggregated intelligence only. Raw IP addresses, full User-Agent strings, referrers and internal scoring rules are intentionally not exposed.

Safe public mode
Monitored feed consumers202behavior signals
Critical behavior signals20publicly anonymized
External reputation matches6314 high-confidence
Clean reputation checks138201 total checked

Protected Signals

10User-agent rotationBrowser/bot identity changes without exposing raw strings.
194Sensitive feed accessAccess to protected white-feed intelligence summarized only.
27Bot identity claimsSearch/AI crawler claims summarized without publishing raw claims.
14Multi-list reputation hitsIP ranges seen on more than one external reputation list.

Reputation Sources

S5H43
Spamhaus ZEN21
UCEPROTECT L214
SpamCop SCBL7
UCEPROTECT L12
Anonymized sourceRiskExternal reputationPrimary signalObserved
199.47.82.xxxCriticalListed 25External reputation matchlast 30 days
104.28.247.xxxCriticalListed 25External reputation matcholder signal
34.29.245.xxxCriticalListed 40External reputation matcholder signal
34.42.56.xxxCriticalListed 40External reputation matcholder signal
34.46.116.xxxCriticalListed 40External reputation matcholder signal
136.67.191.xxxHighListed 75Multi-list external reputationlast 30 days
117.132.188.xxxHighListed 75Multi-list external reputationlast 30 days
36.140.220.xxxHighListed 35Multi-list external reputationolder signal
Security-first publication policy: public output is aggregated and anonymized. Full IPs, raw User-Agent strings, referrers, exact timestamps and enforcement logic remain available only in the protected WordPress admin area.
Real IP / Domain Intelligence Lookup

Investigate IP Address or Domain

Search the real AIT threat database by IP address or safely resolve a domain to its public IP address before analysis. Domains are resolved through DNS only; the target website is not opened.

Exploit Probe Intelligence

What AIT Security Center Detects

Detection signatures are based on real hostile traffic observed against hosted WordPress, WooCommerce and application domains. WordPress renders the intelligence only; the server-side protection engine performs the actual blocking.

🔐

Secrets & Config Exposure Probes

Detects scanners looking for leaked environment files, package credentials and API configuration paths.

/.env/.env.backup/api/.env/.pypirccredentialssecrets.jsonapi_keys.json
📦

Backup & Source Discovery

Detects reconnaissance against backup folders, source repositories and development artifacts.

/backup//.git/config.sql.bak.olddumpconfig.json
🕳️

WordPress Backdoor & Webshell Probes

Detects requests for common malicious PHP filenames and fake WordPress plugin/core backdoor paths.

/inputs.php/ioxi-o.php/wp-conf.php/adminfuns.php/wp-good.php/chosen.php?p=/WordPressCore/
💉

SQL Injection Fingerprints

Detects payloads attempting database enumeration, blind SQL injection and command/file extraction.

UNION SELECTinformation_schemasleep(benchmark(extractvalue(updatexml(into outfile
Trusted Network Intelligence

Trusted Networks White List

The white list protects verified search engines, AI answer engines and trusted network sources from accidental overblocking, while the strongest exploit-detection layers still run before the allow rule.

Current trusted ranges516

Verified Sources

The list is built from controlled and official sources instead of broad cloud-provider ranges.

GoogleCloudflareBingbotYandexDuckDuckGoOAI-SearchBotChatGPT-UserPerplexityBotPerplexity-User
🧱

Correct Firewall Priority

The recommended order keeps the white list useful without turning it into a bypass for malicious behavior.

  1. High-confidence DROP layers
    hackerscan, SQLi, root PHP scan and bad-bot protection.
  2. Trusted Networks White List
    verified crawlers and AI/search services are allowed only after dangerous probes are rejected.
  3. General blocklists and service rules
    SANATABLOCK, abuse lists and normal port allow rules continue below.
🛡️

Why Not First?

The firewall rule engine stops at the first matching rule. If the white list is first, trusted ranges can bypass later automated drop rules. Placing exploit-detection layers first means even a trusted network is blocked if it requests paths such as:

/.env/.git/config/wp-config.phpSQLiroot .php scans
🔎

Clean White List Policy

The white list should prefer specific crawler feeds such as Bingbot JSON instead of entire Microsoft/Azure ServiceTags. GPTBot and AdsBot can stay optional depending on the site policy.

  • Use official JSON feeds where possible.
  • Avoid huge generic cloud ranges as trusted sources.
  • Keep high-confidence attack layers above the white list.
  • Review entry counts after every update.
🌍

Top Countries

Real distribution by country from GeoLite2 City cache.

United States11 893
France2 100
Singapore1 925
India1 707
Germany1 409
United Kingdom1 383
The Netherlands1 346
Brazil1 028
🏢

Top Network Providers

ASN provider intelligence from GeoLite2 ASN cache.

Google LLC10 224
Cloudflare, Inc.6 274
OVH SAS1 713
Microsoft Corporation1 272
F.n.s. Holdings Limited853
Amazon.com, Inc.798
DigitalOcean, LLC755
GSL Networks Pty LTD449
🛡️

Top Detection Modules

Threat activity grouped by AIT protection module.

Hacker Scan Intelligence225 890
WordPress Protection49 982
XML-RPC Protection41 088
Bad Bots35 456
SSH Protection22 541
No User-Agent Protection12 638
Page Click Protection4 083
Root PHP Scanner2 288
Risk Engine

Threat Severity Distribution

Risk is calculated from event count, security module type and repeated detection across modules.

CRITICAL16 87447.7%
HIGH4 47112.7%
MEDIUM9 69927.4%
LOW4 29812.2%
Threat Timeline

Last 30 Days Activity

Historical activity calculated from the real last_seen timestamps in threat-feed.json.

08-26
08-27
08-28
08-29
08-30
08-31
09-01
09-02
09-03
09-04
09-05
09-06
09-07
09-08
09-09
09-10
09-11
09-12
09-13
09-14
09-15
09-16
09-17
09-18
09-19
09-20
09-21
09-22
09-23
09-24
World Threat Map

Global Attack Origin Map

Approximate geographic source points based on GeoLite2 latitude and longitude from geo-cache.json.

Live Threat Feed

Latest Recorded Threat Activity

2026-09-24 01:12:10LOW · Canada · OVH SAS
2026-09-24 01:11:24LOW · Singapore · Amazon.com, Inc.
2026-09-24 01:09:31LOW · Singapore · HUAWEI CLOUDS
2026-09-24 01:04:51MEDIUM · Greece · Medianet Invest Ae
2026-09-24 01:04:51HIGH · Bulgaria · Omniline Investment s.r.o.
2026-09-24 01:04:51MEDIUM · Romania · Orange Romania S.A.
2026-09-24 01:04:51MEDIUM · Moldova · Moldtelecom SA
2026-09-24 01:04:51MEDIUM · Croatia · Hrvatski Telekom d.d.
2026-09-24 01:04:51MEDIUM · The Netherlands · Dedik Services Limited
2026-09-24 01:04:50MEDIUM · Poland · Eweka Internet Services B.V.
2026-09-24 01:04:50MEDIUM · Bulgaria · VIPNET PRIM Ltd
2026-09-24 01:04:50MEDIUM · Serbia · Optel Telekom Tim d.o.o.
2026-09-24 01:04:50MEDIUM · India · Eweka Internet Services B.V.
2026-09-24 01:04:49MEDIUM · Estonia · Telia Eesti AS
2026-09-24 01:04:49MEDIUM · United Kingdom · Hyperoptic Ltd
Threat Leaderboard

Top Dangerous IPs

IPRiskEventsSeverityCountryProviderLast Seen
100/10040CRITICALSwedenMicrosoft Corporation2026-08-26 11:37:01
100/10039CRITICALPolandMicrosoft Corporation2026-08-26 11:36:26
100/10039CRITICALGermanyMicrosoft Corporation2026-08-26 11:36:25
100/10036CRITICALSingaporeF.n.s. Holdings Limited2026-08-26 11:37:10
100/10036CRITICALSingaporeF.n.s. Holdings Limited2026-08-26 11:37:10
100/10036CRITICALSingaporeF.n.s. Holdings Limited2026-08-26 11:37:10
100/10035CRITICALMexicoMicrosoft Corporation2026-08-26 11:37:08
100/10035CRITICALCanadaMicrosoft Corporation2026-08-26 11:37:05
100/10035CRITICALCanadaMicrosoft Corporation2026-08-26 11:36:25
100/10035CRITICALCanadaMicrosoft Corporation2026-08-26 11:37:01
100/10035CRITICALItalyMicrosoft Corporation2026-08-26 11:36:13
100/10035CRITICALCanadaMicrosoft Corporation2026-08-26 11:36:25
Threat Sources Distribution

Attack Source Distribution

Real-world distribution of detected attacks across AIT NODE SECURITY AI protection modules.

Total Attacks132 673
Top ThreatPage Click Protection
Largest Share93.9%
Security Modules10
🏆

Dominant Threat Source

Page Click Protection
124 541 attack events detected
93.9% of all recorded attacks
Root PHP Scanner381 events · 0.3%
Hacker Scan Intelligence3 453 events · 2.6%
SQL Injection Scanner35 events · 0%
Bad Bots993 events · 0.7%
Page Click Protection124 541 events · 93.9%
No User-Agent Protection782 events · 0.6%
XML-RPC Protection84 events · 0.1%
WordPress Protection2 166 events · 1.6%
SSH Protection37 events · 0%
Mail Protection201 events · 0.2%
Security Modules

Protection Modules & Detection Logic

The original AIT Security Center module explanations are preserved and connected to the real threat intelligence data.

Blocks IP addresses searching for suspicious PHP files in website root directories, commonly associated with web shells, malware and WordPress exploit scanners.

Failed events381
Currently banned39
Listed IPs39

Why Are These IP Addresses Listed?

  1. Requests targeting PHP files that legitimate visitors normally never access.
  2. Large numbers of requests to root PHP files within a short period.
  3. Typical web shell filenames such as shell.php, x.php, fileXX.php and wp-load.php probes.
  4. Often originates from VPS or cloud infrastructure.
  5. After reaching the threshold the IP is added to the dynamic firewall layer and blocked at network level.

Matched Patterns

/inputs.php/ioxi-o.php/rip.php/wp-conf.php/adminfuns.php/wp-good.php/autoload_classmap.php/chosen.php?p=/classwithtostring.php/wp-content/plugins/WordPressCore//wp-content/themes/hideo/network.php

Observed Behavior

  • Known webshell and fake WordPress core filenames are requested directly.
  • The scanner looks for backdoors left by previous compromises.
  • Requests often arrive in bursts against the same domain.
  • Any 200/500 response for these paths should be investigated on the server.

Example IPs

+ 19 more IPs hidden from the HTML preview to keep the page fast.

Blocks IP addresses probing for exposed configuration files, secrets, backup folders, development artifacts, API metadata and known attacker discovery paths.

Failed events3 453
Currently banned18 556
Listed IPs18 556

Why Are These IP Addresses Listed?

  1. Requests for sensitive files such as .env, .env.backup, .pypirc, credentials, secrets.json and api_keys.json.
  2. Probing for exposed project files, .git directories, config files, SQL dumps, backups and old copies.
  3. Requests to discovery endpoints such as /backup/, /cgi-bin/, /phpinfo.php, /actuator, /graphql, swagger.json and openapi.json.
  4. Behavior matches automated reconnaissance before exploitation, credential theft or data exposure attempts.
  5. After the configured threshold is reached the IP is added to the dynamic firewall layer and blocked at network level.

Matched Patterns

/.env/.env.backup/api/.env/.pypirc/.git/config/backup//cgi-bin//phpinfo.php/info.php/actuator/graphql/swagger.json/openapi.jsonsecrets.jsonapi_keys.jsoncredentials

Observed Behavior

  • Secrets hunting: attempts to access .env, .env.backup, /api/.env and .pypirc files.
  • Backup discovery: HEAD/GET requests to /backup/ and old archive locations.
  • Scanner camouflage: suspicious requests may use fake or misleading browser, AI crawler or search-engine User-Agent strings.
  • Multi-site behavior: the same source network may probe many hosted domains with the same signature.

Example IPs

+ 18 536 more IPs hidden from the HTML preview to keep the page fast.

Blocks IP addresses attempting SQL injection, database enumeration, time-based SQLi and file extraction payloads against web applications.

Failed events35
Currently banned0
Listed IPs0

Why Are These IP Addresses Listed?

  1. Requests include SQL injection signatures such as UNION SELECT and information_schema.
  2. Attempts may target WordPress AJAX endpoints, plugin parameters or vulnerable query arguments.
  3. Time-based SQL injection probes such as sleep(), benchmark() or waitfor delay indicate exploit automation.
  4. Database extraction payloads such as load_file() or into outfile are high-risk compromise indicators.
  5. The IP is blocked before repeated SQLi attempts can continue against hosted websites.

Matched Patterns

UNION SELECTinformation_schemaextractvalue(updatexml(benchmark(sleep(load_fileinto outfilexp_cmdshellwaitfor delay

Observed Behavior

  • Database enumeration payloads attempting to read table and user information.
  • Blind/time-based probes designed to detect injectable parameters.
  • Plugin or endpoint probing where the scanner does not know whether the target software exists.
  • High-risk SQL payloads that have no normal visitor use case.

Example IPs

Blocks aggressive bots, scrapers and crawlers that generate unnecessary traffic or behave like automated scanners.

Failed events993
Currently banned944
Listed IPs944

Why Are These IP Addresses Listed?

  1. Suspicious or unwanted User-Agent.
  2. Behavior typical of scraping or mass crawling activity.
  3. Unnecessary load on Apache, PHP-FPM, Redis and databases.
  4. May crawl large portions of websites without real user value.
  5. Blocking preserves resources for legitimate visitors.

Example IPs

+ 924 more IPs hidden from the HTML preview to keep the page fast.

Detects excessive request rates, click floods, crawler storms and resource abuse.

Failed events124 541
Currently banned128
Listed IPs128

Why Are These IP Addresses Listed?

  1. Large numbers of HTTP requests within a short period of time.
  2. Behavior that can exhaust Apache and PHP worker resources.
  3. Commonly observed with aggressive crawlers and automated tools.
  4. Protects WooCommerce and WordPress websites from unnecessary load.
  5. The IP address is blocked before it can create a prolonged load spike.

Example IPs

+ 108 more IPs hidden from the HTML preview to keep the page fast.

Blocks requests without a User-Agent header. Legitimate browsers almost always send one, while many scanners and scripts do not.

Failed events782
Currently banned611
Listed IPs611

Why Are These IP Addresses Listed?

  1. The request does not contain a User-Agent header.
  2. This is often a sign of a curl/wget script, scanner or bot.
  3. Legitimate browsers almost always send a User-Agent header.
  4. These requests are often an early stage of probing or automated reconnaissance.
  5. Blocking reduces background noise and unwanted traffic to websites.

Example IPs

+ 591 more IPs hidden from the HTML preview to keep the page fast.

Protects WordPress xmlrpc.php from brute-force attempts, abuse and automated attacks.

Failed events84
Currently banned2 555
Listed IPs2 555

Why Are These IP Addresses Listed?

  1. Repeated requests targeting xmlrpc.php.
  2. Often used for brute-force attacks and credential stuffing.
  3. Can be used for amplification attacks and resource abuse.
  4. It is not normal for a single external IP to aggressively target XML-RPC.
  5. Blocking protects login systems and PHP-FPM processes.

Example IPs

+ 2 535 more IPs hidden from the HTML preview to keep the page fast.

Blocks suspicious WordPress requests, login attacks, plugin probing and other common attack patterns.

Failed events2 166
Currently banned2 879
Listed IPs2 879

Why Are These IP Addresses Listed?

  1. Suspicious WordPress endpoints or login patterns.
  2. Attempts to probe plugins and themes.
  3. Requests typical of automated WordPress attack kits.
  4. Behavior that does not resemble a legitimate visitor.
  5. Blocking reduces the risk of brute-force attacks and vulnerability scanning.

Example IPs

+ 2 859 more IPs hidden from the HTML preview to keep the page fast.

Blocks IP addresses responsible for failed SSH logins and brute-force attacks.

Failed events37
Currently banned1 258
Listed IPs1 258

Why Are These IP Addresses Listed?

  1. Repeated failed SSH login attempts.
  2. Brute-force attempts against system accounts.
  3. Often originates from botnets or cloud VPS infrastructure.
  4. SSH is a critical administrative access point to the server.
  5. Blocking reduces the risk of root or server access compromise.

Example IPs

+ 1 238 more IPs hidden from the HTML preview to keep the page fast.

Blocks abuse against the mail server including SMTP authentication attacks, relay probing and mail abuse.

Failed events201
Currently banned3
Listed IPs3

Why Are These IP Addresses Listed?

  1. Failed SMTP authentication attempts.
  2. Attempts at relay probing or mail abuse.
  3. Behavior typical of mail brute-force tools.
  4. Protects the reputation of the mail server.
  5. Blocking protects domains from spam and abuse risks.

Example IPs

AI & Enterprise Intelligence Network

AI Systems Tracking This Threat Intelligence Feed

Automated AI crawlers, search engines and enterprise research platforms detected from real download activity across the Daily, Full and Trusted Networks firewall feeds.

Total AI feed hits65
Most active consumer🌐 Google
Last seenпреди 23 дни
🌐Google
17feed hits
Unique IPs: 11Last: преди 23 дни
☁️Amazon
11feed hits
Unique IPs: 11Last: преди 15 дни
🧠Anthropic Claude
10feed hits
Unique IPs: 3Last: преди 7 дни
🎓Turnitin
9feed hits
Unique IPs: 1Last: преди 23 дни
🤖OpenAI
9feed hits
Unique IPs: 6Last: преди 2 мес.
📘Meta
3feed hits
Unique IPs: 3Last: преди 2 мес.
🍎Apple
3feed hits
Unique IPs: 3Last: преди 3 мес.
🔎Perplexity
3feed hits
Unique IPs: 3Last: преди 3 мес.

Recent AI Activity

Latest recognized feed consumers
TimeAI / OrganizationFeedIP
🧠 Anthropic ClaudeFull216.73.217.36
🧠 Anthropic ClaudeDaily216.73.217.36
🧠 Anthropic ClaudeWhite216.73.217.36
☁️ AmazonFull52.54.249.218
🎓 TurnitinWhite199.47.82.21
🎓 TurnitinFull199.47.82.21
🎓 TurnitinDaily199.47.82.21
🌐 GoogleFull66.249.70.174
☁️ AmazonWhite35.153.86.200
🌐 GoogleDaily66.249.70.174
🌐 GoogleWhite66.249.76.163
☁️ AmazonFull34.203.111.15
Bot Identity Verification

Verified bots, pending checks and fake identities

Generated from cached DNS/bot intelligence. No live DNS checks are performed on page load.

Verified Bots34
Pending Verification0
Fake Identities4
These crawlers passed cached identity verification and are treated as trusted feed consumers.
IPOrganizationBotStatusConfidenceNext check
AnthropicClaudeBotVerified100%след 6 дни
AnthropicClaudeBotVerified100%след 3 дни
MicrosoftBingbotVerified100%след 23 дни
MetaMeta / Facebook CrawlerVerified100%след 8 ч.
MetaMeta / Facebook CrawlerVerified100%след 8 ч.
MetaMeta / Facebook CrawlerVerified100%след 8 ч.
OpenAIOAI-SearchBotVerified100%след 8 ч.
OpenAIOAI-SearchBotVerified100%след 8 ч.
OpenAIOAI-SearchBotVerified100%след 8 ч.
PerplexityPerplexityBotVerified100%след 6 ч.
PerplexityPerplexityBotVerified100%след 6 ч.
PerplexityPerplexityBotVerified100%след 6 ч.
OpenAIOAI-SearchBotVerified100%след 6 ч.
OpenAIOAI-SearchBotVerified100%след 6 ч.
OpenAIOAI-SearchBotVerified100%след 6 ч.
AnthropicClaudeBotVerified100%след 6 ч.
TurnitinTurnitinBotVerified100%след 5 ч.
MicrosoftBingbotVerified100%след 23 дни
MicrosoftBingbotVerified100%след 18 дни
MicrosoftBingbotVerified100%след 17 дни
MicrosoftBingbotVerified100%след 17 дни
MicrosoftBingbotVerified100%след 17 дни
MicrosoftBingbotVerified100%след 17 дни
GoogleGooglebotVerified100%след 16 дни
GoogleGooglebotVerified100%след 9 дни
GoogleGooglebotVerified100%след 3 дни
GoogleGooglebotVerified100%след 2 дни
MicrosoftBingbotVerified100%след 19 ч.
MicrosoftBingbotVerified100%след 9 мес.
AppleApplebotVerified100%след 9 мес.
AppleApplebotVerified100%след 9 мес.
AppleApplebotVerified100%след 9 мес.
GoogleGooglebotVerified100%след 9 мес.
GoogleGooglebotVerified100%след 9 мес.
These IPs use a known crawler User-Agent, but reverse DNS / forward DNS verification is still pending or incomplete. They are allowed, monitored and rechecked automatically.
No pending crawler verification claims in the cache yet.
These IPs claim a known crawler identity but failed verification or were classified as abusive. They should not receive trusted feed access.
IPClaimed botActual networkVerdictConfidenceReason
GooglebotUnknownFake identity98%Claimed Google crawler identity failed repeated verification by reverse + forward DNS.
GooglebotUnknownFake identity98%Claimed Google crawler identity failed repeated verification by reverse + forward DNS.
GooglebotUnknownFake identity98%Claimed Google crawler identity failed repeated verification by reverse + forward DNS.
GooglebotUnknownFake identity98%Claimed Google crawler identity failed repeated verification by reverse + forward DNS.

Download Firewall Feeds

Download public AIT NODE SECURITY AI feeds. The Daily Firewall Feed contains active protections, the Full Server Firewall Feed contains published firewall intelligence, and the Trusted Networks White Feed contains verified network ranges.

НАГОРЕ