2.57.122.208

listedBruteRegularToolkit

Case file

First seen on 2026-09-15T12:21:47Z, most recently active on 2026-10-02T03:49:41Z.

Recorded 9 attack-shaped requests across 2 separate days.

Its traffic requested a .env file, hoping to find API keys or database credentials; it also requested wp-config.php or a backup copy of it, hoping to read the database password in clear text; it also requested the .git directory itself, hoping it is exposed and browsable.

Seen on our edge, web sensors.

Scored into the "Brute" level, carrying the badges Regular, Toolkit.

Routed via AS47890 (Unmanaged Ltd), an ASN we classify as residential.

Publicly listed on this board, but not currently blocked on any of our hosts.

Enrichment

rDNSnone
ASNAS47890 — Unmanaged Ltd
ASN typeresidential
CountryRomania (RO)
Flagsnone observed

External references: GreyNoise, Shodan, AbuseIPDB

Timeline

Evidence (newest first, up to 50)

Time (UTC)VantageSiteClassStatusEvidence
2026-10-02T03:49:41Zwebobdebug.comrequested the .git directory itself, hoping it is exposed and browsable403/.git -> 403
2026-10-02T03:49:41Zwebobdebug.comprobed for an exposed .git directory to download the site's source history and config403GET /.git/HEAD -> 403
2026-10-02T03:49:41Zwebobdebug.comrequested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot404GET /credentials.json -> 404
2026-10-02T03:49:41Zwebobdebug.com2 × requested a .env file, hoping to find API keys or database credentials404GET /.env.production -> 404 (2 distinct paths)
2026-10-02T03:49:41Zwebobdebug.comrequested a .env file, hoping to find API keys or database credentials403GET /.env -> 403
2026-09-15T12:21:47Zedgevictorantonov.com3 × requested wp-config.php or a backup copy of it, hoping to read the database password in clear textGET /wp-config.php.save (3 distinct paths)

Not currently correlated with any campaign.

Dispute or removal: [email protected] — reference 2.57.122.208. See /threats/about for the method and the 7-day review window.

card.svg (used as this page's og:image)