85.239.151.82
In feed.txt Relentless Regular Toolkit
Blocked indefinitely since UTC on our servers, including web requests through Cloudflare, and in feed.txt. A hosting-network block has no end date; it ends only through the delisting path.
Record
- Score
- 45/100each request counts half as much after 30 days
- Worst level
- Relentless
- Attack-shaped requests
- 501all time
- Active days
- 2UTC days
- First seen
- Last seen
- Servers hit
- 3
- Targets
- 3sites
- Times blocked
- 0by the evidence rules
First seen on UTC, most recently active on UTC.
Recorded 501 attack-shaped requests across 2 separate days.
Its traffic requested a .env file, hoping to find API keys or database credentials (167 requests); it also used a directory-traversal segment (literal or percent-encoded ../) in the request path to try to escape the web root (97); it also requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot (44); 1 request matched no known pattern.
Seen by our edge and web sensors, against 3 of the sites we watch: haived.com, servbg.dev and urbanmoto.eu.
Scored into the "Relentless" level, its highest so far. Badges: Regular and Toolkit.
Its busiest hour on record began UTC, with 173 requests.
Routed via AS19318 (Interserver, Inc), a hosting network.
Surfaces: web-app. Attack types: known exploits, flooding, injection, scanning, hunting for secrets, unclassified. Seen by: edge, web.
Activity, last 90 days
Active on 2 of the last 90 UTC days. Current block: , with no end date.
Daily counts
| Day (UTC) | Requests |
|---|---|
| 160 | |
| 341 |
- At least 148 requests a minute at its peak ( UTC; identical requests in the same second are stored once).
- Methods: GET 638, POST 18.
- The servers we watch answered: 403 482, 404 184, 301 3 (totals only, from our web servers).
Evidence
Newest first, the latest 50 stored requests grouped into runs. Times are UTC. The user agent is shown as its family only.
| Time | Site | What happened | Request | User agent | Seen by |
|---|---|---|---|---|---|
| haived.com | made a request that matched no known pattern | GET /config/env.js | browser claim | web | |
| haived.com | requested a config.json file, hoping it exposes API keys or internal settings | GET /config.json | browser claim | web | |
| haived.com | made a request that matched no known pattern | GET /.config/claude.json | browser claim | web | |
| haived.com | tried to read /proc/self/environ to dump process environment variables, usually via a traversal or inclusion flaw | GET /proc/self/environ | browser claim | web | |
| haived.com | requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot | GET /aws.yml | browser claim | web | |
| haived.com | made a request that matched no known pattern | GET /config/secrets/aws.json | browser claim | web | |
| haived.com | 7× requested an AWS credentials file left in a web-accessible path by mistake (7 distinct paths) | GET /home/ec2-user/.aws/credentials | browser claim | web | |
| haived.com | requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot | GET /aws/credentials | browser claim | web | |
| haived.com | 27× requested a .env file, hoping to find API keys or database credentials (27 distinct paths) | GET ///.env | browser claim | web | |
| haived.com | fuzzed a short, random filename looking for a forgotten script that responds | GET /getcfg.php? | browser claim | web | |
| haived.com | requested a .env file, hoping to find API keys or database credentials | GET /config/.env | browser claim | web | |
| haived.com | made a request that matched no known pattern | GET /internal/v2/config/mps_secret/ADM_SESSIONID | browser claim | web | |
| haived.com | requested a .env file, hoping to find API keys or database credentials | GET /admin/.env.production | browser claim | web | |
| haived.com | made a request that matched no known pattern | POST /app/modules/ut-cac/admin/cli.php | browser claim | web | |
| haived.com | requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot | GET /API/V1/credentials | browser claim | web | |
| haived.com | 3× requested a .env file, hoping to find API keys or database credentials (3 distinct paths) | GET /admin/.env | browser claim | web | |
Network
- ASN
- AS19318 Interserver, Inc
- Network type
- hosting
- Reverse DNS
- none
- Country
- Eritrea ER
- City
- Asmara (registry location of a hosting network)
- Flags
- none observed
- Abuse contact
- found in the registry
- Checked
Delisting
This block has no end date. If the range now belongs to someone else, it can leave the list through the free delisting path; every decision is published on the delisting log.