157.245.113.227

In feed.txt Persistent Regular Toolkit

Blocked on our servers, including web requests through Cloudflare, since UTC, through UTC, and in feed.txt.

Record

Score
33/100each request counts half as much after 30 days
Worst level
Persistent
Attack-shaped requests
33all time
Active days
2UTC days
First seen
Last seen
Servers hit
2
Targets
2sites
Times blocked
1by the evidence rules

Its traffic was scanned by LeakIX, an internet-wide exposure-mapping service; it also probed the WordPress REST API batch endpoint, often used to fingerprint or chain other WordPress vulnerabilities; it also requested the .git directory itself, hoping it is exposed and browsable.

Surfaces: web-app. Attack types: scanning, scanning tools, hunting for secrets. Seen by: edge, web.

Activity, last 90 days

Active on 2 of the last 90 UTC days. Current block: to .

Daily counts
Attack requests per UTC day, days with activity only
Day (UTC)Requests
4
29
  • At least 29 requests a minute at its peak ( UTC; identical requests in the same second are stored once).
  • Methods: GET 22, POST 9, OPTIONS 1.
  • Our servers answered: 404 24, 403 4, 200 1 (totals only, from our web servers).

Evidence

Newest first, the latest 50 stored requests grouped into runs. Times are UTC. The user agent is shown as its family only.

Evidence, newest first, grouped by UTC day
TimeSiteWhat happenedRequestUser agentSeen by
4emx.comwas scanned by LeakIX, an internet-wide exposure-mapping serviceGET /debug/default/view?LeakIXweb
4emx.comwas scanned by LeakIX, an internet-wide exposure-mapping serviceOPTIONS /LeakIXweb
4emx.com3× was scanned by LeakIX, an internet-wide exposure-mapping service (3 distinct paths)GET /.vscode/sftp.jsonLeakIXweb
4emx.comprobed a Spring Boot actuator endpoint, which can leak environment variables and internal config if left openGET /actuator/envLeakIXweb
4emx.comwas scanned by LeakIX, an internet-wide exposure-mapping serviceGET /.well-known/security.txtLeakIXweb
4emx.comfuzzed a short, random filename looking for a forgotten script that respondsGET /info.phpLeakIXweb
4emx.com3× was scanned by LeakIX, an internet-wide exposure-mapping service (3 distinct paths)GET /telescope/requestsLeakIXweb
4emx.com5× was scanned by LeakIX, an internet-wide exposure-mapping service (5 distinct paths)POST /api/gqlLeakIXweb
4emx.comrequested the .git directory itself, hoping it is exposed and browsable/.gitnoneweb
4emx.comprobed for an exposed .git directory to download the site's source history and configGET /.git/configLeakIXweb
4emx.comwas scanned by LeakIX, an internet-wide exposure-mapping serviceGET /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.applicationLeakIXweb
4emx.comrequested a .env file, hoping to find API keys or database credentialsGET /.envLeakIXweb
4emx.com6× was scanned by LeakIX, an internet-wide exposure-mapping service (6 distinct paths)GET /.DS_StoreLeakIXweb
4emx.comwas scanned by LeakIX, an internet-wide exposure-mapping serviceGET /server-statusLeakIXweb
4emx.com2× was scanned by LeakIX, an internet-wide exposure-mapping service (2 distinct paths)GET /serverLeakIXweb
victorantonov.com2× probed the WordPress REST API batch endpoint, often used to fingerprint or chain other WordPress vulnerabilitiesPOST /wp-json/batch/v1LeakIXedge
victorantonov.com2× was scanned by LeakIX, an internet-wide exposure-mapping servicePOST /LeakIXedge

Network

ASN
AS14061 DigitalOcean, LLC
Network type
hosting
Reverse DNS
dc16f0d67a.scan.leakix.org
Country
United States US
City
Clifton (registry location of a hosting network)
Flags
none observed
Abuse contact
not found
Checked

Elsewhere: GreyNoise, Shodan, AbuseIPDB.