54.39.43.117
In feed.txt Persistent Regular Toolkit
Blocked indefinitely since UTC on our servers, including web requests through Cloudflare, and in feed.txt. A hosting-network block has no end date; it ends only through the delisting path.
Record
- Score
- 36/100each request counts half as much after 30 days
- Worst level
- Persistent
- Attack-shaped requests
- 60all time
- Active days
- 2UTC days
- First seen
- Last seen
- Servers hit
- 2
- Targets
- 2sites
- Times blocked
- 0by the evidence rules
Its traffic requested a .env file, hoping to find API keys or database credentials; it also requested an AWS credentials file left in a web-accessible path by mistake; it also used a directory-traversal segment (literal or percent-encoded ../) in the request path to try to escape the web root.
Surfaces: web-app. Attack types: injection, scanning, hunting for secrets. Seen by: edge, web.
Activity, last 90 days
Active on 2 of the last 90 UTC days. Current block: , with no end date.
Daily counts
| Day (UTC) | Requests |
|---|---|
| 26 | |
| 34 |
- At least 31 requests a minute at its peak ( UTC; identical requests in the same second are stored once).
- Methods: GET 54.
- The servers we watch answered: 403 35, 404 14 (totals only, from our web servers).
Evidence
Newest first, the latest 50 stored requests grouped into runs. Times are UTC. The user agent is shown as its family only.
| Time | Site | What happened | Request | User agent | Seen by |
|---|---|---|---|---|---|
| schetio.com | fuzzed a short, random filename looking for a forgotten script that responds | GET /info.php | browser claim | web | |
| schetio.com | 2× requested phpinfo.php, which dumps the full PHP configuration and environment if left in place (2 distinct paths) | GET /_profiler/phpinfo.php | browser claim | web | |
| schetio.com | requested a .env file, hoping to find API keys or database credentials | GET /.env.local | browser claim | web | |
| schetio.com | swept a generic login/signup/account/dashboard route this site does not expose, consistent with an automated app-framework scanner | /api | none | web | |
| schetio.com | requested a .env file, hoping to find API keys or database credentials | GET /api/.env | browser claim | web | |
| schetio.com | swept a generic login/signup/account/dashboard route this site does not expose, consistent with an automated app-framework scanner | /api | none | web | |
| schetio.com | 2× requested a .env file, hoping to find API keys or database credentials (2 distinct paths) | GET /api/shared/config/config.env | browser claim | web | |
| schetio.com | probed a list of common site paths looking for an unprotected admin panel or staging copy | /admin | none | web | |
| schetio.com | 4× requested a .env file, hoping to find API keys or database credentials (4 distinct paths) | GET /admin/.env | browser claim | web | |
| schetio.com | used a directory-traversal segment (literal or percent-encoded ../) in the request path to try to escape the web root | GET /pms? | browser claim | web | |
| schetio.com | 3× requested a .env file, hoping to find API keys or database credentials (3 distinct paths) | GET /application/.env | browser claim | web | |
| schetio.com | requested a generic /config or /api/config endpoint, hoping the app exposes its runtime configuration unauthenticated | /config | none | web | |
| schetio.com | 2× requested a .env file, hoping to find API keys or database credentials (2 distinct paths) | GET /config/.env | browser claim | web | |
| schetio.com | requested the .git directory itself, hoping it is exposed and browsable | /.git | none | web | |
| schetio.com | probed for an exposed .git directory to download the site's source history and config | GET /.git/config | browser claim | web | |
| schetio.com | requested an AWS credentials file left in a web-accessible path by mistake | GET /~/.aws/credentials | browser claim | web | |
| schetio.com | requested a generic /config or /api/config endpoint, hoping the app exposes its runtime configuration unauthenticated | /config | none | web | |
| schetio.com | requested an AWS credentials file left in a web-accessible path by mistake | GET /config/.aws/credentials | browser claim | web | |
| schetio.com | swept a generic login/signup/account/dashboard route this site does not expose, consistent with an automated app-framework scanner | /api | none | web | |
| schetio.com | 2× requested an AWS credentials file left in a web-accessible path by mistake (2 distinct paths) | GET /api/.aws/credentials | browser claim | web | |
| schetio.com | probed a list of common site paths looking for an unprotected admin panel or staging copy | /backup | none | web | |
| schetio.com | requested an AWS credentials file left in a web-accessible path by mistake | GET /backup/.aws/credentials | browser claim | web | |
| schetio.com | made a request that matched no known pattern | GET /aws/credentials.yml | browser claim | web | |
| schetio.com | requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot | GET /aws/credentials | browser claim | web | |
| schetio.com | used a directory-traversal segment (literal or percent-encoded ../) in the request path to try to escape the web root | GET /pms? | browser claim | web | |
| schetio.com | requested an AWS credentials file left in a web-accessible path by mistake | GET /.aws/credentials | browser claim | web | |
| amosix.eu | fuzzed a short, random filename looking for a forgotten script that responds | GET /info.php | browser claim | web | |
| amosix.eu | 2× requested phpinfo.php, which dumps the full PHP configuration and environment if left in place (2 distinct paths) | GET /_profiler/phpinfo.php | browser claim | web | |
| – | amosix.eu | 2× requested a .env file, hoping to find API keys or database credentials (2 distinct paths) | GET /.env.local | browser claim | edge |
| amosix.eu | requested a .env file, hoping to find API keys or database credentials | GET /api/shared/config/config.env | browser claim | web | |
| amosix.eu | 5× requested a .env file, hoping to find API keys or database credentials (5 distinct paths) | GET /app/.env | browser claim | edge | |
| amosix.eu | used a directory-traversal segment (literal or percent-encoded ../) in the request path to try to escape the web root | GET /pms? | browser claim | web | |
| amosix.eu | 3× requested a .env file, hoping to find API keys or database credentials (3 distinct paths) | GET /application/.env | browser claim | edge | |
Network
- ASN
- AS16276 OVH SAS
- Network type
- hosting
- Reverse DNS
ip117.ip-54-39-43.net- Country
- Canada CA
- City
- Beauharnois (registry location of a hosting network)
- Flags
- none observed
- Abuse contact
- found in the registry
- Checked
Delisting
This block has no end date. If the range now belongs to someone else, it can leave the list through the free delisting path; every decision is published on the delisting log.