Report for IP: 20.205.46.33

Threat LevelHIGH64/1001 rule type
10 incidents · active attack detected · 10 attacks/day · last seen 23d ago
PTR N/A
Org / ASN Microsoft Azure Cloud (eastasia)
Country 🇭🇰 Hong Kong
City Hong Kong, Central and Western District
Timezone Asia/Hong_Kong

Attack Analysis

🇭🇰 Hong Kong · Hong Kong · 8075 · Microsoft Corporation
Webshell Upload Scan
This IP rapidly probed multiple non-existent PHP paths in under 60 seconds — a hallmark of automated webshell scanning tools hunting for previously uploaded backdoors or vulnerable file-upload endpoints. If successful, a webshell grants the attacker full remote code execution on the server.

Reports (10)

Date Severity Description
9 Jul 2026 - 02:21 high Web: Webshell scan — 3+ unknown PHP probes in 60s
9 Jul 2026 - 02:20 high Web: Webshell scan — 3+ unknown PHP probes in 60s
9 Jul 2026 - 02:19 high Web: Webshell scan — 3+ unknown PHP probes in 60s
8 Jul 2026 - 20:13 high Web: Webshell scan — 3+ unknown PHP probes in 60s
8 Jul 2026 - 20:11 high Web: Webshell scan — 3+ unknown PHP probes in 60s
8 Jul 2026 - 20:10 high Web: Webshell scan — 3+ unknown PHP probes in 60s
8 Jul 2026 - 18:32 high Web: Webshell scan — 3+ unknown PHP probes in 60s
8 Jul 2026 - 18:31 high Web: Webshell scan — 3+ unknown PHP probes in 60s
8 Jul 2026 - 17:09 high Web: Webshell scan — 3+ unknown PHP probes in 60s
8 Jul 2026 - 17:08 high Web: Webshell scan — 3+ unknown PHP probes in 60s