178.211.139.240

recordedScript KiddieRegularCampaign member

Case file

First seen on 2026-09-29T22:27:22Z, most recently active on 2026-10-04T22:00:18Z.

Recorded 6 attack-shaped requests across 2 separate days.

Its traffic fuzzed a short, random filename looking for a forgotten script that responds.

Seen on our web sensor.

Scored into the "Script Kiddie" level, carrying the badges Regular, Campaign member.

Routed via AS201814 (MEVSPACE sp. z o.o.), an ASN we classify as residential.

Recorded internally; has not yet crossed the bar for a public listing.

Correlated with other addresses sharing the same signature under campaign "e3fd96970aa3c34a".

Enrichment

rDNSnone
ASNAS201814 — MEVSPACE sp. z o.o.
ASN typeresidential
CountryPoland (PL)
Flagsnone observed

External references: GreyNoise, Shodan, AbuseIPDB

Timeline

Evidence (newest first, up to 50)

Time (UTC)VantageSiteClassStatusEvidence
2026-10-04T21:59:49Z – 2026-10-04T22:00:18Zwebzmey.eu3 × fuzzed a short, random filename looking for a forgotten script that responds404GET /postnews.php -> 404 (3 distinct paths)
2026-09-29T22:27:22Z – 2026-09-29T22:27:51Zwebschetio.com3 × fuzzed a short, random filename looking for a forgotten script that responds404GET /postnews.php -> 404 (3 distinct paths)

Campaign membership: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36|/filefuns.php (3 addresses correlated) — no standalone campaign page yet.

Dispute or removal: [email protected] — reference 178.211.139.240. See /threats/about for the method and the 7-day review window.

card.svg (used as this page's og:image)