157.245.113.227
In feed.txt Persistent Regular Toolkit
Blocked on our servers, including web requests through Cloudflare, since UTC, through UTC, and in feed.txt.
Record
- Score
- 33/100each request counts half as much after 30 days
- Worst level
- Persistent
- Attack-shaped requests
- 33all time
- Active days
- 2UTC days
- First seen
- Last seen
- Servers hit
- 2
- Targets
- 2sites
- Times blocked
- 1by the evidence rules
Its traffic was scanned by LeakIX, an internet-wide exposure-mapping service; it also probed the WordPress REST API batch endpoint, often used to fingerprint or chain other WordPress vulnerabilities; it also requested the .git directory itself, hoping it is exposed and browsable.
Surfaces: web-app. Attack types: scanning, scanning tools, hunting for secrets. Seen by: edge, web.
Activity, last 90 days
Active on 2 of the last 90 UTC days. Current block: to .
Daily counts
| Day (UTC) | Requests |
|---|---|
| 4 | |
| 29 |
- At least 29 requests a minute at its peak ( UTC; identical requests in the same second are stored once).
- Methods: GET 22, POST 9, OPTIONS 1.
- Our servers answered: 404 24, 403 4, 200 1 (totals only, from our web servers).
Evidence
Newest first, the latest 50 stored requests grouped into runs. Times are UTC. The user agent is shown as its family only.
| Time | Site | What happened | Request | User agent | Seen by |
|---|---|---|---|---|---|
| 4emx.com | was scanned by LeakIX, an internet-wide exposure-mapping service | GET /debug/default/view? | LeakIX | web | |
| 4emx.com | was scanned by LeakIX, an internet-wide exposure-mapping service | OPTIONS / | LeakIX | web | |
| 4emx.com | 3× was scanned by LeakIX, an internet-wide exposure-mapping service (3 distinct paths) | GET /.vscode/sftp.json | LeakIX | web | |
| 4emx.com | probed a Spring Boot actuator endpoint, which can leak environment variables and internal config if left open | GET /actuator/env | LeakIX | web | |
| 4emx.com | was scanned by LeakIX, an internet-wide exposure-mapping service | GET /.well-known/security.txt | LeakIX | web | |
| 4emx.com | fuzzed a short, random filename looking for a forgotten script that responds | GET /info.php | LeakIX | web | |
| 4emx.com | 3× was scanned by LeakIX, an internet-wide exposure-mapping service (3 distinct paths) | GET /telescope/requests | LeakIX | web | |
| 4emx.com | 5× was scanned by LeakIX, an internet-wide exposure-mapping service (5 distinct paths) | POST /api/gql | LeakIX | web | |
| 4emx.com | requested the .git directory itself, hoping it is exposed and browsable | /.git | none | web | |
| 4emx.com | probed for an exposed .git directory to download the site's source history and config | GET /.git/config | LeakIX | web | |
| 4emx.com | was scanned by LeakIX, an internet-wide exposure-mapping service | GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application | LeakIX | web | |
| 4emx.com | requested a .env file, hoping to find API keys or database credentials | GET /.env | LeakIX | web | |
| 4emx.com | 6× was scanned by LeakIX, an internet-wide exposure-mapping service (6 distinct paths) | GET /.DS_Store | LeakIX | web | |
| 4emx.com | was scanned by LeakIX, an internet-wide exposure-mapping service | GET /server-status | LeakIX | web | |
| 4emx.com | 2× was scanned by LeakIX, an internet-wide exposure-mapping service (2 distinct paths) | GET /server | LeakIX | web | |
| victorantonov.com | 2× probed the WordPress REST API batch endpoint, often used to fingerprint or chain other WordPress vulnerabilities | POST /wp-json/batch/v1 | LeakIX | edge | |
| victorantonov.com | 2× was scanned by LeakIX, an internet-wide exposure-mapping service | POST / | LeakIX | edge | |
Network
- ASN
- AS14061 DigitalOcean, LLC
- Network type
- hosting
- Reverse DNS
dc16f0d67a.scan.leakix.org- Country
- United States US
- City
- Clifton (registry location of a hosting network)
- Flags
- none observed
- Abuse contact
- not found
- Checked