164.92.107.174
In feed.txt Persistent Regular Toolkit
Blocked indefinitely since UTC on our servers, including web requests through Cloudflare, and in feed.txt. A hosting-network block has no end date; it ends only through the delisting path.
Record
- Score
- 35/100each request counts half as much after 30 days
- Worst level
- Persistent
- Attack-shaped requests
- 63all time
- Active days
- 2UTC days
- First seen
- Last seen
- Servers hit
- 2
- Targets
- 2sites
- Times blocked
- 1by the evidence rules
Its traffic was scanned by LeakIX, an internet-wide exposure-mapping service; it also probed a Spring Boot actuator endpoint, which can leak environment variables and internal config if left open; it also probed for an exposed .git directory to download the site's source history and config.
Surfaces: web-app. Attack types: scanning, scanning tools, hunting for secrets. Seen by: web.
Activity, last 90 days
Active on 2 of the last 90 UTC days. Current block: , with no end date.
Daily counts
| Day (UTC) | Requests |
|---|---|
| 32 | |
| 31 |
- At least 32 requests a minute at its peak ( UTC; identical requests in the same second are stored once).
- Methods: GET 50, POST 10, OPTIONS 2.
- The servers we watch answered: 301 32, 404 23, 403 4, 302 4 (totals only, from our web servers).
Evidence
Newest first, the latest 50 stored requests grouped into runs. Times are UTC. The user agent is shown as its family only.
| Time | Site | What happened | Request | User agent | Seen by |
|---|---|---|---|---|---|
| haived.com | 2× was scanned by LeakIX, an internet-wide exposure-mapping service (2 distinct paths) | GET /debug/default/view? | LeakIX | web | |
| haived.com | was scanned by LeakIX, an internet-wide exposure-mapping service | OPTIONS / | LeakIX | web | |
| haived.com | 3× was scanned by LeakIX, an internet-wide exposure-mapping service (3 distinct paths) | GET /.vscode/sftp.json | LeakIX | web | |
| haived.com | probed a Spring Boot actuator endpoint, which can leak environment variables and internal config if left open | GET /actuator/env | LeakIX | web | |
| haived.com | 5× was scanned by LeakIX, an internet-wide exposure-mapping service (5 distinct paths) | GET /.well-known/security.txt | LeakIX | web | |
| haived.com | 5× was scanned by LeakIX, an internet-wide exposure-mapping service (5 distinct paths) | POST /api/gql | LeakIX | web | |
| haived.com | probed for an exposed .git directory to download the site's source history and config | GET /.git/config | LeakIX | web | |
| haived.com | was scanned by LeakIX, an internet-wide exposure-mapping service | GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application | LeakIX | web | |
| haived.com | requested a .env file, hoping to find API keys or database credentials | GET /.env | LeakIX | web | |
| haived.com | 11× was scanned by LeakIX, an internet-wide exposure-mapping service (10 distinct paths) | GET /.DS_Store | LeakIX | web | |
| neutralizatori.com | was scanned by LeakIX, an internet-wide exposure-mapping service | GET /debug/default/view? | LeakIX | web | |
| neutralizatori.com | was scanned by LeakIX, an internet-wide exposure-mapping service | GET /? | LeakIX | web | |
| neutralizatori.com | was scanned by LeakIX, an internet-wide exposure-mapping service | OPTIONS / | LeakIX | web | |
| neutralizatori.com | 3× was scanned by LeakIX, an internet-wide exposure-mapping service (3 distinct paths) | GET /.vscode/sftp.json | LeakIX | web | |
| neutralizatori.com | probed a Spring Boot actuator endpoint, which can leak environment variables and internal config if left open | GET /actuator/env | LeakIX | web | |
| neutralizatori.com | was scanned by LeakIX, an internet-wide exposure-mapping service | GET /.well-known/security.txt | LeakIX | web | |
| neutralizatori.com | fuzzed a short, random filename looking for a forgotten script that responds | GET /info.php | LeakIX | web | |
| neutralizatori.com | 3× was scanned by LeakIX, an internet-wide exposure-mapping service (3 distinct paths) | GET /telescope/requests | LeakIX | web | |
| neutralizatori.com | 3× was scanned by LeakIX, an internet-wide exposure-mapping service (3 distinct paths) | POST /api/gql | LeakIX | web | |
| neutralizatori.com | was scanned by LeakIX, an internet-wide exposure-mapping service | POST /api | LeakIX | web | |
| neutralizatori.com | was scanned by LeakIX, an internet-wide exposure-mapping service | POST /graphql | LeakIX | web | |
| neutralizatori.com | requested the .git directory itself, hoping it is exposed and browsable | /.git | none | web | |
| neutralizatori.com | probed for an exposed .git directory to download the site's source history and config | GET /.git/config | LeakIX | web | |
Network
- ASN
- AS14061 DigitalOcean, LLC
- Network type
- hosting
- Reverse DNS
dd761bf4f4.scan.leakix.org- Country
- United States US
- City
- Santa Clara (registry location of a hosting network)
- Flags
- none observed
- Abuse contact
- found in the registry
- Checked
Delisting
This block has no end date. If the range now belongs to someone else, it can leave the list through the free delisting path; every decision is published on the delisting log.