153.0.158.115

recordedScanner

Case file

First seen on 2026-10-04T17:48:35Z, most recently active on 2026-10-04T18:36:36Z.

Recorded 8 attack-shaped requests across 1 separate day.

Its traffic requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot; it also requested an AWS credentials file left in a web-accessible path by mistake; it also requested docker-compose.yml, which often contains embedded passwords and connection strings.

Seen from 1 of our sensors: s19-web.

Scored into the "Scanner" level.

Routed via AS4837 (CHINA UNICOM China169 Backbone), an ASN we classify as residential.

Recorded internally; has not yet crossed the bar for a public listing.

Enrichment

rDNSnone
ASNAS4837 — CHINA UNICOM China169 Backbone
ASN typeresidential
CountryChina (CN)
Flagsnone observed

External references: GreyNoise, Shodan, AbuseIPDB

Timeline

Evidence (newest first, up to 50)

Time (UTC)VantageSiteClassStatusEvidence
2026-10-04T18:36:36Zs19-webhaived.commatched a catalogue rule404153.0.158.115 - - [04/Oct/2026:18:36:36 +0000] "GET /deployment-config.json HTTP/1.1" 404 94 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0 Safari/537.36" rt=0.002 cf=<redacted>-LAX
2026-10-04T18:35:16Zs19-webhaived.comrequested an AWS credentials file left in a web-accessible path by mistake404153.0.158.115 - - [04/Oct/2026:18:35:16 +0000] "GET /.aws/credentials HTTP/1.1" 404 88 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0 Safari/537.36" rt=0.001 cf=<redacted>-LAX
2026-10-04T18:34:21Zs19-webhaived.comrequested docker-compose.yml, which often contains embedded passwords and connection strings404153.0.158.115 - - [04/Oct/2026:18:34:21 +0000] "GET /docker-compose.yml HTTP/1.1" 404 90 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0 Safari/537.36" rt=0.001 cf=<redacted>-LAX
2026-10-04T18:11:51Z – 2026-10-04T18:30:20Z ×4s19-webhaived.com4 × requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot404153.0.158.115 - - [04/Oct/2026:18:30:20 +0000] "GET /static/config.js HTTP/1.1" 404 88 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0 Safari/537.36" rt=0.000 cf=<redacted>-LAX (4 distinct paths)
2026-10-04T18:11:10Zs19-webhaived.commatched a catalogue rule404153.0.158.115 - - [04/Oct/2026:18:11:10 +0000] "GET /scripts/secrets.js HTTP/1.1" 404 90 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0 Safari/537.36" rt=0.001 cf=<redacted>-LAX
2026-10-04T18:04:56Zs19-webhaived.comrequested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot404153.0.158.115 - - [04/Oct/2026:18:04:56 +0000] "GET /credentials.js HTTP/1.1" 404 86 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0 Safari/537.36" rt=0.001 cf=<redacted>-LAX
2026-10-04T18:02:33Zs19-webhaived.commatched a catalogue rule404153.0.158.115 - - [04/Oct/2026:18:02:33 +0000] "GET /secrets.js HTTP/1.1" 404 82 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0 Safari/537.36" rt=0.001 cf=<redacted>-LAX
2026-10-04T17:59:36Zs19-webhaived.comrequested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot404153.0.158.115 - - [04/Oct/2026:17:59:36 +0000] "GET /config.js HTTP/1.1" 404 81 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0 Safari/537.36" rt=0.001 cf=<redacted>-LAX
2026-10-04T17:48:35Zs19-webhaived.commatched a catalogue rule404153.0.158.115 - - [04/Oct/2026:17:48:35 +0000] "GET /sftp-config.json HTTP/1.1" 404 88 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0 Safari/537.36" rt=0.001 cf=<redacted>-LAX

Report history

No abuse report sent for this address yet.

Not currently correlated with any campaign.

Dispute or removal: [email protected] — reference 153.0.158.115 (mailbox goes live with phase 3). See /threats/about for the method and the 7-day review window.

card.svg (used as this page's og:image)