178.211.139.240
Case file
First seen on 2026-09-29T22:27:22Z, most recently active on 2026-10-04T22:00:18Z.
Recorded 6 attack-shaped requests across 2 separate days.
Its traffic fuzzed a short, random filename looking for a forgotten script that responds.
Seen on our web sensor.
Scored into the "Script Kiddie" level, carrying the badges Regular, Campaign member.
Routed via AS201814 (MEVSPACE sp. z o.o.), an ASN we classify as residential.
Recorded internally; has not yet crossed the bar for a public listing.
Correlated with other addresses sharing the same signature under campaign "e3fd96970aa3c34a".
Enrichment
| rDNS | none |
|---|---|
| ASN | AS201814 — MEVSPACE sp. z o.o. |
| ASN type | residential |
| Country | Poland (PL) |
| Flags | none observed |
Timeline
- 2026-09-293
- 2026-10-043
Evidence (newest first, up to 50)
| Time (UTC) | Vantage | Site | Class | Status | Evidence |
|---|---|---|---|---|---|
| 2026-10-04T21:59:49Z – 2026-10-04T22:00:18Z | web | zmey.eu | 3 × fuzzed a short, random filename looking for a forgotten script that responds | 404 | GET /postnews.php -> 404 (3 distinct paths) |
| 2026-09-29T22:27:22Z – 2026-09-29T22:27:51Z | web | schetio.com | 3 × fuzzed a short, random filename looking for a forgotten script that responds | 404 | GET /postnews.php -> 404 (3 distinct paths) |
Campaign membership: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36|/filefuns.php (3 addresses correlated) — no standalone campaign page yet.
Dispute or removal: [email protected] — reference 178.211.139.240. See /threats/about for the method and the 7-day review window.
card.svg (used as this page's og:image)