← Threat Pulse
Pulse #29

Threat Pulse W41 — Oracle-Sourced Scan Surge & Critical RCE Blitz

A single Oracle Corporation netblock in the Netherlands dominated this week's traffic, accounting for 73% of all events. Despite a 61% volume drop overall, critical RCE campaigns remained fully active and broadly distributed across all facades.
Week of 05 Oct 2026

Executive Summary

Week 41 (2026-10-02 to 2026-10-05) recorded 76,606 inbound probes, a significant 60.9% decrease from the prior week. However, this reduction is largely a statistical artifact driven by one dominant scanning source rather than a genuine decline in threat activity. Five critical-severity RCE campaigns remained fully active, targeting widespread vulnerabilities in Hikvision, PHPUnit, Apache, GeoServer, and Microsoft Exchange. The overall threat posture remains elevated.


Attack Volume & Trends

Metric Value vs. Prior Week
Total Probes 76,606 -60.9%
Recon 48,134 —
Scan 15,009 —
Exploit 10,733 —
Bruteforce 2,103 —
RCE 462 —
Auth 171 —

Facade breakdown:

Facade Hits
fake-http 29,784
fake-https 29,254
fake-ssh 9,702
fake-telnet 5,741
fake-postgres 1,048
fake-redis 532
fake-mysql 371
fake-mongodb 174

HTTP and HTTPS facades together absorbed 77% of all traffic, consistent with attacker focus on web-facing infrastructure. SSH and Telnet remain persistently targeted, reflecting ongoing credential-stuffing and IoT exploitation activity. Database facades (PostgreSQL, Redis, MySQL, MongoDB) collectively received 2,125 hits, a lower share but indicative of automated service discovery sweeps.

The volume drop from the prior week should be interpreted cautiously. A single source IP contributed 55,583 events — approximately 72.6% of all weekly traffic. Stripping that single actor, underlying baseline activity remains broadly consistent with previous weeks.


Top Threat Actors

Rank ASN / Org Country Events Dominant Behavior
1 Oracle Corporation NL 55,583 Scan
2 Amarutu Technology Ltd DE 1,637 Scan
3 Oracle Corporation NL 762 Scan
4 ZORNTECH WEB SOLUTIONS TR 620 Scan
5 ZORNTECH WEB SOLUTIONS TR 616 Scan

Key observations:

  • Oracle Corporation (NL) netblocks contributed two entries in the top five, collectively accounting for 56,345 events (73.6% of total weekly volume). This is consistent with scanner infrastructure — whether commercial, research, or abused cloud compute — hosted on Oracle Cloud's Amsterdam region. The volume and behavioral signature (dominant scan type) suggest an automated, wide-spectrum reconnaissance sweep rather than a targeted intrusion campaign.
  • Amarutu Technology Ltd (DE) is a frequently observed hosting provider associated with bulk-scanner and proxy infrastructure. Its presence as second-highest source is consistent with prior weeks.
  • ZORNTECH WEB SOLUTIONS (TR) contributed two closely numbered source IPs with nearly identical event counts (620 and 616), strongly suggesting coordinated or paired scanning from the same operator.

Active Campaigns

All five tracked campaigns reported 61,603 hits each this week — a figure that precisely matches the dominant Oracle scanner's activity, suggesting these campaign detections are largely attributable to that single scanning source probing for vulnerable endpoints at scale.

Campaign Severity Type Hits
Hikvision ISAPI RCE Critical RCE 61,603
PHPUnit eval-stdin RCE Critical RCE 61,603
Apache Path Traversal / RCE Critical Path Traversal 61,603
GeoServer OGC Filter RCE Critical RCE 61,603
Exchange ProxyLogon Critical RCE 61,603

Campaign analysis:

  • Hikvision ISAPI RCE: Targets unpatched IP cameras and NVR systems via the ISAPI interface. Exploitation grants unauthenticated remote code execution. Widely exploited by botnet operators for DDoS recruitment.
  • PHPUnit eval-stdin RCE (CVE-2017-9841): A legacy vulnerability in PHPUnit that exposed a test utility to unauthenticated code execution via POST to /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php. Despite its age, it remains a high-yield target due to abandoned or unaudited web applications.
  • Apache Path Traversal / RCE: Likely encompasses CVE-2021-41773 / CVE-2021-42013 or similar Apache HTTP Server traversal chains enabling file disclosure and command execution.
  • GeoServer OGC Filter RCE (CVE-2024-36401): A critical vulnerability disclosed in mid-2024 allowing unauthenticated RCE via OGC filter evaluation. Continued presence confirms this remains an actively exploited, unpatched attack surface across internet-facing GIS deployments.
  • Exchange ProxyLogon (CVE-2021-26855 et al.): A multi-year-old but persistently targeted Exchange exploitation chain. Continued high-volume probing indicates a large population of unpatched Exchange servers remains reachable.

The uniform hit count across all campaigns strongly implies a single automated toolset cycling through a comprehensive exploit checklist per target, rather than five independent campaign operators.


Notable Paths & Techniques

The following paths received significant unsolicited traffic outside of tracked campaigns:

Path / Probe Hits Assessment
/ 2,027 Root enumeration; fingerprinting server type and response behavior
/login 1,254 Generic login panel discovery; precursor to credential attacks
/login/ 919 Trailing-slash variant; bypasses naive path-based filtering
/cgi-bin/ 900 CGI directory enumeration; targets legacy CGI scripts and shellshock-style payloads
/phpmyadmin/ 875 phpMyAdmin discovery; common target for default/weak credential attacks
/manager/ 874 Tomcat Manager interface probe; targets default Tomcat credentials
/cgi-bin-sdb/ 874 Vendor-specific CGI path; associated with embedded device firmware (routers, NAS)
database=postgres 347 PostgreSQL service fingerprinting; likely automated DB discovery
UNSTABLE 192 Malformed or protocol-violation probe; may be fuzzer or misconfigured scanner artifact
/robots.txt 184 Standard reconnaissance step; attackers mine disallowed paths for sensitive endpoints

Notable technique observations:

  • The /login and /login/ split (1,254 + 919 = 2,173 combined hits) highlights that attackers routinely probe both normalized and trailing-slash variants to defeat simple string-match defenses.
  • /cgi-bin-sdb/ is particularly associated with embedded device interfaces (notably some QNAP and Synology NAS paths), indicating IoT/NAS-targeting alongside traditional web server exploitation.
  • The UNSTABLE probe string is anomalous and warrants monitoring — it may reflect a fuzzing framework probing for parser errors, or a misconfigured tool leaking internal state labels.
  • database=postgres appearing as a notable probe outside the fake-postgres facade suggests HTTP-level parameter injection scanning, where attackers embed database identifiers in web request parameters to probe for backend exposure.

Geographic Distribution

Country Events % of Total Notes
Netherlands (NL) 57,455 75.0% Dominated by Oracle Cloud scanner infrastructure
United States (US) 2,420 3.2% Mixed commercial hosting; diverse tooling
China (CN) 2,417 3.2% Consistent presence; broad recon and exploit activity
Germany (DE) 2,175 2.8% Includes Amarutu bulk-scanner traffic
France (FR) 1,533 2.0% Hosting and VPS infrastructure
Turkey (TR) 1,443 1.9% Includes ZORNTECH coordinated scanning
Pakistan (PK) 1,082 1.4% Elevated vs. baseline; monitor for trend continuation
Romania (RO) 1,010 1.3% Common proxy/VPS abuse origin

Excluding the dominant NL scanner, the remaining 19,151 events distribute more evenly across US, CN, DE, FR, TR, PK, and RO — a distribution consistent with prior weeks and reflecting the standard global attacker ecosystem. Pakistan's share at 1,082 events merits continued observation to determine whether it represents a sustained increase or a transient spike.


Recommendations

  1. Prioritize patching for active RCE targets. All five active campaigns target known, CVE-assigned vulnerabilities. Organizations running Hikvision cameras, internet-facing GeoServer, Exchange, Apache HTTP Server, or legacy PHP applications with PHPUnit in vendor paths should verify patch status immediately.
  1. Remove or restrict PHPUnit from production environments. CVE-2017-9841 affects a development dependency that should never be deployed to production. Audit vendor/ directories in all web-accessible document roots.
  1. Block or rate-limit probes to high-value administrative paths. Paths such as /manager/, /phpmyadmin/, and /cgi-bin/ should either be blocked at the perimeter for non-administrative source ranges or served a non-responsive stub to reduce attacker signal.
  1. Investigate Oracle Cloud ingress. If your environment is receiving large volumes of scan traffic originating from Oracle Cloud (AS136907 / AS31898 NL ranges), evaluate whether geo-based or ASN-based rate limiting is appropriate for your threat model. Consider reporting abusive scanning to Oracle's abuse contact.
  1. Monitor the UNSTABLE probe signature. This anomalous string should be logged and cross-correlated with any application-layer errors in production systems. It may indicate a fuzzing framework probing for unstable parser behavior.
  1. Watch Pakistan-origin traffic trends. At 1,082 events this week, PK-origin probes are worth tracking over the next 2–3 weeks to determine if this represents a new campaign origin or isolated activity.
  1. Ensure database services are not internet-exposed. PostgreSQL, Redis, MySQL, and MongoDB facades all received unsolicited traffic. No database service should be bound to a public interface without a documented operational requirement and enforced authentication.