188.166.99.91
In feed.txt Brute Regular Toolkit
Blocked indefinitely since UTC on our servers, including web requests through Cloudflare, and in feed.txt. A hosting-network block has no end date; it ends only through the delisting path.
Record
- Score
- 34/100each request counts half as much after 30 days
- Worst level
- Brute
- Attack-shaped requests
- 15all time
- Active days
- 2UTC days
- First seen
- Last seen
- Servers hit
- 2
- Targets
- 2sites
- Times blocked
- 1by the evidence rules
Its traffic requested a .env file, hoping to find API keys or database credentials; it also probed for an exposed GraphQL endpoint or its config file, often a precursor to an introspection query; it also swept a generic login/signup/account/dashboard route this site does not expose, consistent with an automated app-framework scanner.
Surfaces: web-app. Attack types: scanning, hunting for secrets. Seen by: web.
Activity, last 90 days
Active on 2 of the last 90 UTC days. Current block: , with no end date.
Daily counts
| Day (UTC) | Requests |
|---|---|
| 2 | |
| 13 |
- At least 13 requests a minute at its peak ( UTC; identical requests in the same second are stored once).
- Methods: GET 17.
- The servers we watch answered: 404 11, 301 5, 403 2 (totals only, from our web servers).
Evidence
Newest first, the latest 50 stored requests grouped into runs. Times are UTC. The user agent is shown as its family only.
| Time | Site | What happened | Request | User agent | Seen by |
|---|---|---|---|---|---|
| haived.com | made a request that matched no known pattern | GET /api/admin | browser claim | web | |
| haived.com | requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot | GET /next.config.js | browser claim | web | |
| haived.com | made a request that matched no known pattern | GET /next.config.mjs | browser claim | web | |
| haived.com | requested a generic /config or /api/config endpoint, hoping the app exposes its runtime configuration unauthenticated | GET /api/config | browser claim | web | |
| haived.com | made a request that matched no known pattern | GET /api/auth/config | browser claim | web | |
| haived.com | probed for an exposed GraphQL endpoint or its config file, often a precursor to an introspection query | GET /graphql | browser claim | web | |
| haived.com | probed for an exposed GraphQL endpoint or its config file, often a precursor to an introspection query | GET /graphql | browser claim | web | |
| haived.com | swept a generic login/signup/account/dashboard route this site does not expose, consistent with an automated app-framework scanner | GET /api/ | browser claim | web | |
| haived.com | requested a .env file, hoping to find API keys or database credentials | GET /.env.development | browser claim | web | |
| haived.com | requested a .env file, hoping to find API keys or database credentials | GET /.env.development | browser claim | web | |
| haived.com | 3× requested a .env file, hoping to find API keys or database credentials (3 distinct paths) | GET /.env.local | browser claim | web | |
| haived.com | 3× requested a .env file, hoping to find API keys or database credentials (3 distinct paths) | GET /.env.local | browser claim | web | |
| servbg.com | requested the .git directory itself, hoping it is exposed and browsable | /.git | none | web | |
| servbg.com | probed for an exposed .git directory to download the site's source history and config | GET /.git/config | browser claim | web | |
Network
- ASN
- AS14061 DigitalOcean, LLC
- Network type
- hosting
- Reverse DNS
ayko.site- Country
- The Netherlands NL
- City
- Amsterdam (registry location of a hosting network)
- Flags
- none observed
- Abuse contact
- found in the registry
- Checked
Delisting
This block has no end date. If the range now belongs to someone else, it can leave the list through the free delisting path; every decision is published on the delisting log.