AIT Security Center V11

Real Threat Intelligence Platform

Real cyber threat intelligence generated from AIT NODE SECURITY AI history, firewall detections, GeoLite2 GEO cache and ASN provider intelligence.

LIVE THREAT INTELLIGENCE METRICS

Unique threat IPs18 285
Total attack events106 558
Critical IPs907
High risk IPs4 442
Public Safe Feed Intelligence

Feed Consumer & External Reputation Pulse

Public dashboard mode shows aggregated intelligence only. Raw IP addresses, full User-Agent strings, referrers and internal scoring rules are intentionally not exposed.

Safe public mode
Monitored feed consumers132behavior signals
Critical behavior signals16publicly anonymized
External reputation matches5630 high-confidence
Clean reputation checks75131 total checked

Protected Signals

10User-agent rotationBrowser/bot identity changes without exposing raw strings.
126Sensitive feed accessAccess to protected white-feed intelligence summarized only.
20Bot identity claimsSearch/AI crawler claims summarized without publishing raw claims.
30Multi-list reputation hitsIP ranges seen on more than one external reputation list.

Reputation Sources

S5H35
Spamhaus ZEN34
UCEPROTECT L216
UCEPROTECT L15
SpamCop SCBL4
Anonymized sourceRiskExternal reputationPrimary signalObserved
104.28.247.xxxCriticalListed 45Multi-list external reputationolder signal
199.47.82.xxxCriticalListed 65Multi-list external reputationlast 7 days
34.46.116.xxxCriticalListed 40External reputation matcholder signal
36.140.220.xxxHighListed 35Multi-list external reputationolder signal
104.28.215.xxxHighListed 45Multi-list external reputationolder signal
34.27.189.xxxCriticalListed 40External reputation matcholder signal
84.16.224.xxxHighListed 65Multi-list external reputationolder signal
192.42.116.xxxHighListed 85Multi-list external reputationolder signal
Security-first publication policy: public output is aggregated and anonymized. Full IPs, raw User-Agent strings, referrers, exact timestamps and enforcement logic remain available only in the protected WordPress admin area.
Real IP / Domain Intelligence Lookup

Investigate IP Address or Domain

Search the real AIT threat database by IP address or safely resolve a domain to its public IP address before analysis. Domains are resolved through DNS only; the target website is not opened.

Exploit Probe Intelligence

What AIT Security Center Detects

Detection signatures are based on real hostile traffic observed against hosted WordPress, WooCommerce and application domains. WordPress renders the intelligence only; the server-side protection engine performs the actual blocking.

🔐

Secrets & Config Exposure Probes

Detects scanners looking for leaked environment files, package credentials and API configuration paths.

/.env/.env.backup/api/.env/.pypirccredentialssecrets.jsonapi_keys.json
📦

Backup & Source Discovery

Detects reconnaissance against backup folders, source repositories and development artifacts.

/backup//.git/config.sql.bak.olddumpconfig.json
🕳️

WordPress Backdoor & Webshell Probes

Detects requests for common malicious PHP filenames and fake WordPress plugin/core backdoor paths.

/inputs.php/ioxi-o.php/wp-conf.php/adminfuns.php/wp-good.php/chosen.php?p=/WordPressCore/
💉

SQL Injection Fingerprints

Detects payloads attempting database enumeration, blind SQL injection and command/file extraction.

UNION SELECTinformation_schemasleep(benchmark(extractvalue(updatexml(into outfile
Trusted Network Intelligence

Trusted Networks White List

The white list protects verified search engines, AI answer engines and trusted network sources from accidental overblocking, while the strongest exploit-detection layers still run before the allow rule.

Current trusted ranges516

Verified Sources

The list is built from controlled and official sources instead of broad cloud-provider ranges.

GoogleCloudflareBingbotYandexDuckDuckGoOAI-SearchBotChatGPT-UserPerplexityBotPerplexity-User
🧱

Correct Firewall Priority

The recommended order keeps the white list useful without turning it into a bypass for malicious behavior.

  1. High-confidence DROP layers
    hackerscan, SQLi, root PHP scan and bad-bot protection.
  2. Trusted Networks White List
    verified crawlers and AI/search services are allowed only after dangerous probes are rejected.
  3. General blocklists and service rules
    SANATABLOCK, abuse lists and normal port allow rules continue below.
🛡️

Why Not First?

The firewall rule engine stops at the first matching rule. If the white list is first, trusted ranges can bypass later automated drop rules. Placing exploit-detection layers first means even a trusted network is blocked if it requests paths such as:

/.env/.git/config/wp-config.phpSQLiroot .php scans
🔎

Clean White List Policy

The white list should prefer specific crawler feeds such as Bingbot JSON instead of entire Microsoft/Azure ServiceTags. GPTBot and AdsBot can stay optional depending on the site policy.

  • Use official JSON feeds where possible.
  • Avoid huge generic cloud ranges as trusted sources.
  • Keep high-confidence attack layers above the white list.
  • Review entry counts after every update.
🌍

Top Countries

Real distribution by country from GeoLite2 City cache.

United States6 061
India1 140
Germany905
Singapore795
The Netherlands731
China611
Brazil565
United Kingdom556
🏢

Top Network Providers

ASN provider intelligence from GeoLite2 ASN cache.

Google LLC4 965
Microsoft Corporation1 724
F.n.s. Holdings Limited859
Amazon.com, Inc.515
GSL Networks Pty LTD417
Fastly, Inc.379
DigitalOcean, LLC370
Cloudflare, Inc.354
🛡️

Top Detection Modules

Threat activity grouped by AIT protection module.

Hacker Scan Intelligence42 998
WordPress Protection26 824
XML-RPC Protection15 931
Bad Bots12 835
No User-Agent Protection9 763
SSH Protection8 846
Page Click Protection3 233
Root PHP Scanner1 534
Risk Engine

Threat Severity Distribution

Risk is calculated from event count, security module type and repeated detection across modules.

CRITICAL9075%
HIGH4 44224.3%
MEDIUM9 31951%
LOW3 61719.8%
Threat Timeline

Last 30 Days Activity

Historical activity calculated from the real last_seen timestamps in threat-feed.json.

07-12
07-13
07-14
07-15
07-16
07-17
07-18
07-19
07-20
07-21
07-22
07-23
07-24
07-25
07-26
07-27
07-28
07-29
07-30
07-31
08-01
08-02
08-03
08-04
08-05
08-06
08-07
08-08
08-09
World Threat Map

Global Attack Origin Map

Approximate geographic source points based on GeoLite2 latitude and longitude from geo-cache.json.

Live Threat Feed

Latest Recorded Threat Activity

2026-08-09 08:18:33LOW · Pakistan · FIBERISH (PVT) LTD
2026-08-09 07:50:32MEDIUM · United States · Google LLC
2026-08-09 07:49:45MEDIUM · Japan · Google LLC
2026-08-09 07:44:31MEDIUM · India · Hostinger International Limited
2026-08-09 07:29:04LOW · Philippines · Converge ICT Solutions Inc.
2026-08-09 07:25:49LOW · United States · Amazon.com, Inc.
2026-08-09 07:16:34LOW · Nepal · WorldLink Communications Pvt Ltd
2026-08-09 07:04:24LOW · India · Bharti Airtel Ltd., Telemedia Services
2026-08-09 06:36:01MEDIUM · United States · Google LLC
2026-08-09 06:30:53LOW · United States · Zenlayer Inc
2026-08-09 06:30:43MEDIUM · United States · Google LLC
2026-08-09 06:09:52MEDIUM · United States · Google LLC
2026-08-09 06:07:01LOW · China · CHINA UNICOM China169 Backbone
2026-08-09 05:59:26LOW · United States · Amazon.com, Inc.
2026-08-09 05:48:24LOW · The Netherlands · Turunc Smart Bilgisayar Teknoloji Ve Dis Ticaret Limited Sirketi
Threat Leaderboard

Top Dangerous IPs

IPRiskEventsSeverityCountryProviderLast Seen
100/10022CRITICALSingaporeMicrosoft Corporation2026-07-18 00:18:18
100/10022CRITICALIndiaMicrosoft Corporation2026-07-18 00:18:18
100/10022CRITICALUnited StatesMicrosoft Corporation2026-07-18 00:16:45
100/10022CRITICALJapanMicrosoft Corporation2026-07-18 00:18:26
100/10022CRITICALHong KongMicrosoft Corporation2026-07-18 00:16:31
100/10022CRITICALUnited StatesMicrosoft Corporation2026-07-18 00:16:45
100/10022CRITICALSouth KoreaMicrosoft Corporation2026-07-18 00:17:41
100/10018CRITICALUnited StatesGoogle LLC2026-07-18 00:18:38
100/10018CRITICALUnited StatesGoogle LLC2026-07-18 00:18:08
100/10018CRITICALBelgiumGoogle LLC2026-07-18 00:18:35
100/10018CRITICALCanadaMicrosoft Corporation2026-07-18 00:17:40
100/10018CRITICALUnited StatesGoogle LLC2026-07-18 00:18:15
Threat Sources Distribution

Attack Source Distribution

Real-world distribution of detected attacks across AIT NODE SECURITY AI protection modules.

Total Attacks218 858
Top ThreatPage Click Protection
Largest Share94.6%
Security Modules10
🏆

Dominant Threat Source

Page Click Protection
206 956 attack events detected
94.6% of all recorded attacks
Root PHP Scanner236 events · 0.1%
Hacker Scan Intelligence5 024 events · 2.3%
SQL Injection Scanner10 events · 0%
Bad Bots1 093 events · 0.5%
Page Click Protection206 956 events · 94.6%
No User-Agent Protection510 events · 0.2%
XML-RPC Protection152 events · 0.1%
WordPress Protection4 035 events · 1.8%
SSH Protection217 events · 0.1%
Mail Protection625 events · 0.3%
Security Modules

Protection Modules & Detection Logic

The original AIT Security Center module explanations are preserved and connected to the real threat intelligence data.

Blocks IP addresses searching for suspicious PHP files in website root directories, commonly associated with web shells, malware and WordPress exploit scanners.

Failed events236
Currently banned31
Listed IPs31

Why Are These IP Addresses Listed?

  1. Requests targeting PHP files that legitimate visitors normally never access.
  2. Large numbers of requests to root PHP files within a short period.
  3. Typical web shell filenames such as shell.php, x.php, fileXX.php and wp-load.php probes.
  4. Often originates from VPS or cloud infrastructure.
  5. After reaching the threshold the IP is added to the dynamic firewall layer and blocked at network level.

Matched Patterns

/inputs.php/ioxi-o.php/rip.php/wp-conf.php/adminfuns.php/wp-good.php/autoload_classmap.php/chosen.php?p=/classwithtostring.php/wp-content/plugins/WordPressCore//wp-content/themes/hideo/network.php

Observed Behavior

  • Known webshell and fake WordPress core filenames are requested directly.
  • The scanner looks for backdoors left by previous compromises.
  • Requests often arrive in bursts against the same domain.
  • Any 200/500 response for these paths should be investigated on the server.

Example IPs

+ 11 more IPs hidden from the HTML preview to keep the page fast.

Blocks IP addresses probing for exposed configuration files, secrets, backup folders, development artifacts, API metadata and known attacker discovery paths.

Failed events5 024
Currently banned6 619
Listed IPs6 619

Why Are These IP Addresses Listed?

  1. Requests for sensitive files such as .env, .env.backup, .pypirc, credentials, secrets.json and api_keys.json.
  2. Probing for exposed project files, .git directories, config files, SQL dumps, backups and old copies.
  3. Requests to discovery endpoints such as /backup/, /cgi-bin/, /phpinfo.php, /actuator, /graphql, swagger.json and openapi.json.
  4. Behavior matches automated reconnaissance before exploitation, credential theft or data exposure attempts.
  5. After the configured threshold is reached the IP is added to the dynamic firewall layer and blocked at network level.

Matched Patterns

/.env/.env.backup/api/.env/.pypirc/.git/config/backup//cgi-bin//phpinfo.php/info.php/actuator/graphql/swagger.json/openapi.jsonsecrets.jsonapi_keys.jsoncredentials

Observed Behavior

  • Secrets hunting: attempts to access .env, .env.backup, /api/.env and .pypirc files.
  • Backup discovery: HEAD/GET requests to /backup/ and old archive locations.
  • Scanner camouflage: suspicious requests may use fake or misleading browser, AI crawler or search-engine User-Agent strings.
  • Multi-site behavior: the same source network may probe many hosted domains with the same signature.

Example IPs

+ 6 599 more IPs hidden from the HTML preview to keep the page fast.

Blocks IP addresses attempting SQL injection, database enumeration, time-based SQLi and file extraction payloads against web applications.

Failed events10
Currently banned0
Listed IPs0

Why Are These IP Addresses Listed?

  1. Requests include SQL injection signatures such as UNION SELECT and information_schema.
  2. Attempts may target WordPress AJAX endpoints, plugin parameters or vulnerable query arguments.
  3. Time-based SQL injection probes such as sleep(), benchmark() or waitfor delay indicate exploit automation.
  4. Database extraction payloads such as load_file() or into outfile are high-risk compromise indicators.
  5. The IP is blocked before repeated SQLi attempts can continue against hosted websites.

Matched Patterns

UNION SELECTinformation_schemaextractvalue(updatexml(benchmark(sleep(load_fileinto outfilexp_cmdshellwaitfor delay

Observed Behavior

  • Database enumeration payloads attempting to read table and user information.
  • Blind/time-based probes designed to detect injectable parameters.
  • Plugin or endpoint probing where the scanner does not know whether the target software exists.
  • High-risk SQL payloads that have no normal visitor use case.

Example IPs

Blocks aggressive bots, scrapers and crawlers that generate unnecessary traffic or behave like automated scanners.

Failed events1 093
Currently banned455
Listed IPs455

Why Are These IP Addresses Listed?

  1. Suspicious or unwanted User-Agent.
  2. Behavior typical of scraping or mass crawling activity.
  3. Unnecessary load on Apache, PHP-FPM, Redis and databases.
  4. May crawl large portions of websites without real user value.
  5. Blocking preserves resources for legitimate visitors.

Example IPs

+ 435 more IPs hidden from the HTML preview to keep the page fast.

Detects excessive request rates, click floods, crawler storms and resource abuse.

Failed events206 956
Currently banned385
Listed IPs385

Why Are These IP Addresses Listed?

  1. Large numbers of HTTP requests within a short period of time.
  2. Behavior that can exhaust Apache and PHP worker resources.
  3. Commonly observed with aggressive crawlers and automated tools.
  4. Protects WooCommerce and WordPress websites from unnecessary load.
  5. The IP address is blocked before it can create a prolonged load spike.

Example IPs

+ 365 more IPs hidden from the HTML preview to keep the page fast.

Blocks requests without a User-Agent header. Legitimate browsers almost always send one, while many scanners and scripts do not.

Failed events510
Currently banned734
Listed IPs734

Why Are These IP Addresses Listed?

  1. The request does not contain a User-Agent header.
  2. This is often a sign of a curl/wget script, scanner or bot.
  3. Legitimate browsers almost always send a User-Agent header.
  4. These requests are often an early stage of probing or automated reconnaissance.
  5. Blocking reduces background noise and unwanted traffic to websites.

Example IPs

+ 714 more IPs hidden from the HTML preview to keep the page fast.

Protects WordPress xmlrpc.php from brute-force attempts, abuse and automated attacks.

Failed events152
Currently banned1 459
Listed IPs1 459

Why Are These IP Addresses Listed?

  1. Repeated requests targeting xmlrpc.php.
  2. Often used for brute-force attacks and credential stuffing.
  3. Can be used for amplification attacks and resource abuse.
  4. It is not normal for a single external IP to aggressively target XML-RPC.
  5. Blocking protects login systems and PHP-FPM processes.

Example IPs

+ 1 439 more IPs hidden from the HTML preview to keep the page fast.

Blocks suspicious WordPress requests, login attacks, plugin probing and other common attack patterns.

Failed events4 035
Currently banned2 687
Listed IPs2 687

Why Are These IP Addresses Listed?

  1. Suspicious WordPress endpoints or login patterns.
  2. Attempts to probe plugins and themes.
  3. Requests typical of automated WordPress attack kits.
  4. Behavior that does not resemble a legitimate visitor.
  5. Blocking reduces the risk of brute-force attacks and vulnerability scanning.

Example IPs

+ 2 667 more IPs hidden from the HTML preview to keep the page fast.

Blocks IP addresses responsible for failed SSH logins and brute-force attacks.

Failed events217
Currently banned1 007
Listed IPs1 007

Why Are These IP Addresses Listed?

  1. Repeated failed SSH login attempts.
  2. Brute-force attempts against system accounts.
  3. Often originates from botnets or cloud VPS infrastructure.
  4. SSH is a critical administrative access point to the server.
  5. Blocking reduces the risk of root or server access compromise.

Example IPs

+ 987 more IPs hidden from the HTML preview to keep the page fast.

Blocks abuse against the mail server including SMTP authentication attacks, relay probing and mail abuse.

Failed events625
Currently banned2
Listed IPs2

Why Are These IP Addresses Listed?

  1. Failed SMTP authentication attempts.
  2. Attempts at relay probing or mail abuse.
  3. Behavior typical of mail brute-force tools.
  4. Protects the reputation of the mail server.
  5. Blocking protects domains from spam and abuse risks.

Example IPs

AI & Enterprise Intelligence Network

AI Systems Tracking This Threat Intelligence Feed

Automated AI crawlers, search engines and enterprise research platforms detected from real download activity across the Daily, Full and Trusted Networks firewall feeds.

Total AI feed hits48
Most active consumer🌐 Google
Last seenпреди 3 дни
🌐Google
10feed hits
Unique IPs: 5Last: преди 3 дни
🤖OpenAI
9feed hits
Unique IPs: 6Last: преди 1 мес.
🧠Anthropic Claude
7feed hits
Unique IPs: 2Last: преди 7 дни
☁️Amazon
7feed hits
Unique IPs: 7Last: преди 15 дни
🎓Turnitin
6feed hits
Unique IPs: 1Last: преди 2 дни
📘Meta
3feed hits
Unique IPs: 3Last: преди 1 мес.
🍎Apple
3feed hits
Unique IPs: 3Last: преди 1 мес.
🔎Perplexity
3feed hits
Unique IPs: 3Last: преди 1 мес.

Recent AI Activity

Latest recognized feed consumers
TimeAI / OrganizationFeedIP
🎓 TurnitinWhite199.47.82.21
🎓 TurnitinFull199.47.82.21
🎓 TurnitinDaily199.47.82.21
🌐 GoogleWhite163.245.210.197
🌐 GoogleFull163.245.210.197
🌐 GoogleDaily163.245.210.197
🌐 GoogleWhite66.249.75.44
🧠 Anthropic ClaudeFull216.73.216.114
🧠 Anthropic ClaudeFull216.73.216.114
🧠 Anthropic ClaudeWhite216.73.216.114
🧠 Anthropic ClaudeDaily216.73.216.114
☁️ AmazonWhite107.20.181.148
Bot Identity Verification

Verified bots, pending checks and fake identities

Generated from cached DNS/bot intelligence. No live DNS checks are performed on page load.

Verified Bots26
Pending Verification0
Fake Identities1
These crawlers passed cached identity verification and are treated as trusted feed consumers.
IPOrganizationBotStatusConfidenceNext check
AnthropicClaudeBotVerified100%след 6 дни
MetaMeta / Facebook CrawlerVerified100%след 3 дни
MetaMeta / Facebook CrawlerVerified100%след 3 дни
MetaMeta / Facebook CrawlerVerified100%след 3 дни
OpenAIOAI-SearchBotVerified100%след 3 дни
OpenAIOAI-SearchBotVerified100%след 3 дни
OpenAIOAI-SearchBotVerified100%след 3 дни
PerplexityPerplexityBotVerified100%след 3 дни
PerplexityPerplexityBotVerified100%след 3 дни
PerplexityPerplexityBotVerified100%след 3 дни
OpenAIOAI-SearchBotVerified100%след 3 дни
OpenAIOAI-SearchBotVerified100%след 3 дни
TurnitinTurnitinBotVerified100%след 3 дни
OpenAIOAI-SearchBotVerified100%след 3 дни
AnthropicClaudeBotVerified100%след 3 дни
GoogleGooglebotVerified100%след 25 дни
MicrosoftBingbotVerified100%след 16 дни
MicrosoftBingbotVerified100%след 9 дни
MicrosoftBingbotVerified100%след 8 дни
MicrosoftBingbotVerified100%след 3 дни
MicrosoftBingbotVerified100%след 11 мес.
AppleApplebotVerified100%след 11 мес.
AppleApplebotVerified100%след 11 мес.
AppleApplebotVerified100%след 11 мес.
GoogleGooglebotVerified100%след 11 мес.
GoogleGooglebotVerified100%след 11 мес.
These IPs use a known crawler User-Agent, but reverse DNS / forward DNS verification is still pending or incomplete. They are allowed, monitored and rechecked automatically.
No pending crawler verification claims in the cache yet.
These IPs claim a known crawler identity but failed verification or were classified as abusive. They should not receive trusted feed access.
IPClaimed botActual networkVerdictConfidenceReason
GooglebotUnknownFake identity98%Claimed Google crawler identity failed repeated verification by reverse + forward DNS.

Download Firewall Feeds

Download public AIT NODE SECURITY AI feeds. The Daily Firewall Feed contains active protections, the Full Server Firewall Feed contains published firewall intelligence, and the Trusted Networks White Feed contains verified network ranges.

НАГОРЕ