2a0f:ca80:b00b:eff9::5
In feed-v6.txt Persistent Regular Toolkit
In feed-v6.txt since UTC, through UTC; IPv6 is published only, not refused by our own servers.
Record
- Score
- 35/100each request counts half as much after 30 days
- Worst level
- Persistent
- Attack-shaped requests
- 24all time
- Active days
- 2UTC days
- First seen
- Last seen
- Servers hit
- 3
- Targets
- 2sites
- Times blocked
- 1by the evidence rules
Its traffic fuzzed a short, random filename looking for a forgotten script that responds; it also requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot; it also requested a .env file, hoping to find API keys or database credentials.
Surfaces: web-app. Attack types: scanning, hunting for secrets. Seen by: edge, web.
Activity, last 90 days
Active on 2 of the last 90 UTC days. Current block: to .
Daily counts
| Day (UTC) | Requests |
|---|---|
| 1 | |
| 23 |
- At least 10 requests a minute at its peak ( UTC; identical requests in the same second are stored once).
- Methods: GET 29.
- Our servers answered: 404 25, 403 2 (totals only, from our web servers).
Evidence
Newest first, the latest 50 stored requests grouped into runs. Times are UTC. The user agent is shown as its family only.
| Time | Site | What happened | Request | User agent | Seen by |
|---|---|---|---|---|---|
| odor-ex.com | requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot | GET /.env-config.js | browser claim | web | |
| odor-ex.com | requested a config.json file, hoping it exposes API keys or internal settings | GET /config.json | browser claim | web | |
| odor-ex.com | requested an AWS credentials file left in a web-accessible path by mistake | GET /.aws/credentials | browser claim | web | |
| odor-ex.com | requested a .env file, hoping to find API keys or database credentials | GET /.env.js | browser claim | web | |
| odor-ex.com | requested phpinfo.php, which dumps the full PHP configuration and environment if left in place | GET /portal/phpinfo.php | browser claim | web | |
| odor-ex.com | 3× fuzzed a short, random filename looking for a forgotten script that responds (3 distinct paths) | GET /test.php | browser claim | web | |
| odor-ex.com | 3× made a request that matched no known pattern (3 distinct paths) | GET /configuration.php | browser claim | web | |
| odor-ex.com | requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot | GET /settings.py | browser claim | web | |
| odor-ex.com | made a request that matched no known pattern | GET /config/parameters.yml | browser claim | web | |
| – | odor-ex.com | 2× fuzzed a short, random filename looking for a forgotten script that responds (2 distinct paths) | GET /index.php | browser claim | web |
| odor-ex.com | 2× requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot (2 distinct paths) | GET /config.js | browser claim | web | |
| odor-ex.com | made a request that matched no known pattern | GET /.gitconfig | browser claim | web | |
| odor-ex.com | fuzzed a short, random filename looking for a forgotten script that responds | GET /settings.php | browser claim | web | |
| odor-ex.com | requested a .env file, hoping to find API keys or database credentials | GET /.env.bak | browser claim | web | |
| odor-ex.com | requested docker-compose.yml, which often contains embedded passwords and connection strings | GET /docker-compose.yml | browser claim | web | |
| – | odor-ex.com | 2× fuzzed a short, random filename looking for a forgotten script that responds (2 distinct paths) | GET /database.php | browser claim | web |
| odor-ex.com | requested a .env file, hoping to find API keys or database credentials | GET /.env | browser claim | web | |
| odor-ex.com | fuzzed a short, random filename looking for a forgotten script that responds | GET /info.php | browser claim | web | |
| odor-ex.com | requested wp-config.php or a backup copy of it, hoping to read the database password in clear text | GET /wp-config.php | browser claim | edge | |
| odor-ex.com | probed for an exposed .git directory to download the site's source history and config | GET /.git/config | browser claim | web | |
| odor-ex.com | requested phpinfo.php, which dumps the full PHP configuration and environment if left in place | GET /phpinfo.php | browser claim | web | |
| stefanpetkov.day | requested wp-config.php or a backup copy of it, hoping to read the database password in clear text | GET /wp-config.php | browser claim | edge | |
Network
- ASN
- AS197170 TechTies Inc.
- Network type
- hosting
- Reverse DNS
- none
- Country
- Germany DE
- Flags
- none observed
- Abuse contact
- not found
- Checked