193.32.162.175

recordedScannerRegular

Case file

First seen on 2026-10-06T22:07:58Z, most recently active on 2026-10-07T02:46:37Z.

Recorded 4 attack-shaped requests across 2 separate days.

Its traffic probed for an exposed .git directory to download the site's source history and config; it also fuzzed a short, random filename looking for a forgotten script that responds; it also requested the .git directory itself, hoping it is exposed and browsable.

Seen on our web sensor.

Scored into the "Scanner" level, carrying the badge Regular.

Routed via AS47890 (Unmanaged Ltd), an ASN we classify as residential.

Recorded internally; has not yet crossed the bar for a public listing.

Enrichment

rDNSnone
ASNAS47890 — Unmanaged Ltd
ASN typeresidential
CountryRomania (RO)
Flagsnone observed

External references: GreyNoise, Shodan, AbuseIPDB

Timeline

Evidence (newest first, up to 50)

Time (UTC)VantageSiteClassStatusEvidence
2026-10-07T02:46:37Zwebstefanpetkov.daymade a request that matched no known pattern403/stefanpetkovday/.git -> 403
2026-10-07T02:46:37Zwebstefanpetkov.dayprobed for an exposed .git directory to download the site's source history and config403GET /.git/config -> 403
2026-10-06T22:07:58Zweburbanmoto.eufuzzed a short, random filename looking for a forgotten script that responds403/index.php -> 403
2026-10-06T22:07:58Zweburbanmoto.eurequested the .git directory itself, hoping it is exposed and browsable403/.git -> 403
2026-10-06T22:07:58Zweburbanmoto.euprobed for an exposed .git directory to download the site's source history and config403GET /.git/config -> 403

Not currently correlated with any campaign.

Dispute or removal: [email protected] — reference 193.32.162.175. See /threats/about for the method and the 7-day review window.

card.svg (used as this page's og:image)