2a0f:ca80:b00b:8089::5

In feed-v6.txt Brute Regular

In feed-v6.txt indefinitely since UTC; IPv6 is published only, not refused by our own servers. A hosting-network block has no end date; it ends only through the delisting path.

Record

Score
33/100each request counts half as much after 30 days
Worst level
Brute
Attack-shaped requests
12all time
Active days
3UTC days
First seen
Last seen
Servers hit
1
Targets
3sites
Times blocked
1by the evidence rules

First seen on UTC, most recently active on UTC.

Recorded 12 attack-shaped requests across 3 separate days.

Its traffic requested a .env file, hoping to find API keys or database credentials (8 requests); it also fuzzed a short, random filename looking for a forgotten script that responds (4).

Seen by our web sensor, against 3 of the sites we watch: bursukov.com, odor-ex.com and svestnik.com.

Scored into the "Brute" level, its highest so far. Badge: Regular.

Its busiest hour on record began UTC, with 5 requests.

Routed via AS197170 (TechTies Inc.), a hosting network.

Surfaces: web-app. Attack types: scanning, hunting for secrets. Seen by: web.

Activity, last 90 days

Active on 3 of the last 90 UTC days. Current block: , with no end date.

Daily counts
Attack requests per UTC day, days with activity only
Day (UTC)Requests
2
5
5
  • At least 5 requests a minute at its peak ( UTC; identical requests in the same second are stored once).
  • Methods: GET 12.
  • The servers we watch answered: 404 9, 403 3 (totals only, from our web servers).

Evidence

Newest first, the latest 50 stored requests grouped into runs. Times are UTC. The user agent is shown as its family only.

Evidence, newest first, grouped by UTC day
TimeSiteWhat happenedRequestUser agentSeen by
odor-ex.comfuzzed a short, random filename looking for a forgotten script that respondsGET /config.phpbrowser claimweb
odor-ex.com3× requested a .env file, hoping to find API keys or database credentials (3 distinct paths)GET /.env.examplebrowser claimweb
odor-ex.comrequested a .env file, hoping to find API keys or database credentialsGET /.envbrowser claimweb
svestnik.comfuzzed a short, random filename looking for a forgotten script that respondsGET /config.phpbrowser claimweb
svestnik.comrequested a .env file, hoping to find API keys or database credentialsGET /.env.examplebrowser claimweb
svestnik.comrequested a .env file, hoping to find API keys or database credentialsGET /api/.envbrowser claimweb
svestnik.comrequested a .env file, hoping to find API keys or database credentialsGET /backend/.envbrowser claimweb
svestnik.comrequested a .env file, hoping to find API keys or database credentialsGET /.envbrowser claimweb
2 sites2× fuzzed a short, random filename looking for a forgotten script that respondsGET /config.phpbrowser claimweb

Network

ASN
AS197170 TechTies Inc.
Network type
hosting
Reverse DNS
none
Country
Germany DE
Flags
none observed
Abuse contact
not found
Checked

Elsewhere: GreyNoise, Shodan, AbuseIPDB.

Delisting

This block has no end date. If the range now belongs to someone else, it can leave the list through the free delisting path; every decision is published on the delisting log.