91.92.243.184
Case file
First seen on 2026-10-06T18:39:10Z, most recently active on 2026-10-07T03:00:00Z.
Recorded 26 attack-shaped requests across 2 separate days.
Its traffic requested a .env file, hoping to find API keys or database credentials; it also probed for an exposed GraphQL endpoint or its config file, often a precursor to an introspection query; it also requested wp-config.php or a backup copy of it, hoping to read the database password in clear text.
Seen on our edge, web sensors.
Scored into the "Persistent" level, carrying the badges Regular, Toolkit.
Routed via AS202412 (Omegatech LTD), an ASN we classify as hosting.
Blocked by the firewalls on our servers since 2026-10-07T03:10:07Z, through 2027-10-07T03:10:07Z.
Enrichment
| rDNS | none |
|---|---|
| ASN | AS202412 — Omegatech LTD |
| ASN type | hosting |
| Country | United States (US) |
| Flags | none observed |
Timeline
- 2026-10-0616
- 2026-10-0710
Evidence (newest first, up to 50)
| Time (UTC) | Vantage | Site | Class | Status | Evidence |
|---|---|---|---|---|---|
| 2026-10-07T03:00:00Z | web | haived.com | made a request that matched no known pattern | 404 | GET /api/admin -> 404 |
| 2026-10-07T02:59:57Z | web | haived.com | requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot | 404 | GET /next.config.js -> 404 |
| 2026-10-07T02:59:53Z – 2026-10-07T02:59:57Z | web | haived.com | 2 × made a request that matched no known pattern | 404 | GET /next.config.mjs -> 404 (2 distinct paths) |
| 2026-10-07T02:59:52Z | web | haived.com | probed for an exposed GraphQL endpoint or its config file, often a precursor to an introspection query | 404 | GET /graphql -> 404 |
| 2026-10-07T02:59:51Z | web | haived.com | probed for an exposed GraphQL endpoint or its config file, often a precursor to an introspection query | 301 | GET /graphql -> 301 |
| 2026-10-07T02:59:50Z | web | haived.com | swept a generic login/signup/account/dashboard route this site does not expose, consistent with an automated app-framework scanner | 404 | GET /api/ -> 404 |
| 2026-10-07T02:59:44Z | web | haived.com | requested a .env file, hoping to find API keys or database credentials | 404 | GET /.env.development -> 404 |
| 2026-10-07T02:59:43Z | web | haived.com | requested a .env file, hoping to find API keys or database credentials | 301 | GET /.env.development -> 301 |
| 2026-10-07T02:59:43Z | web | haived.com | requested a .env file, hoping to find API keys or database credentials | 404 | GET /.env -> 404 |
| 2026-10-07T02:59:40Z | web | haived.com | 3 × requested a .env file, hoping to find API keys or database credentials | 301 | GET /.env -> 301 (3 distinct paths) |
| 2026-10-06T19:08:43Z | web | haived.com | made a request that matched no known pattern | 404 | GET /api/admin -> 404 |
| 2026-10-06T19:08:42Z | web | haived.com | requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot | 404 | GET /next.config.js -> 404 |
| 2026-10-06T19:08:39Z | web | haived.com | made a request that matched no known pattern | 404 | GET /next.config.mjs -> 404 |
| 2026-10-06T19:08:39Z | web | haived.com | requested a generic /config or /api/config endpoint, hoping the app exposes its runtime configuration unauthenticated | 404 | GET /api/config -> 404 |
| 2026-10-06T19:08:38Z | web | haived.com | made a request that matched no known pattern | 404 | GET /api/auth/config -> 404 |
| 2026-10-06T19:08:36Z | web | haived.com | probed for an exposed GraphQL endpoint or its config file, often a precursor to an introspection query | 404 | GET /graphql -> 404 |
| 2026-10-06T19:08:34Z | web | haived.com | probed for an exposed GraphQL endpoint or its config file, often a precursor to an introspection query | 301 | GET /graphql -> 301 |
| 2026-10-06T19:08:32Z | web | haived.com | swept a generic login/signup/account/dashboard route this site does not expose, consistent with an automated app-framework scanner | 404 | GET /api/ -> 404 |
| 2026-10-06T19:08:23Z | web | haived.com | requested a .env file, hoping to find API keys or database credentials | 404 | GET /.env.development -> 404 |
| 2026-10-06T19:08:22Z | web | haived.com | requested a .env file, hoping to find API keys or database credentials | 301 | GET /.env.development -> 301 |
| 2026-10-06T19:08:22Z | web | haived.com | 3 × requested a .env file, hoping to find API keys or database credentials | 404 | GET /.env.production -> 404 (3 distinct paths) |
| 2026-10-06T19:08:21Z | web | haived.com | 3 × requested a .env file, hoping to find API keys or database credentials | 301 | GET /.env -> 301 (3 distinct paths) |
| 2026-10-06T18:39:10Z – 2026-10-06T18:39:12Z | edge | haived.com | 3 × requested wp-config.php or a backup copy of it, hoping to read the database password in clear text | GET /@fs/wp-config.php (3 distinct paths) |
Not currently correlated with any campaign.
Dispute or removal: [email protected] — reference 91.92.243.184. See /threats/about for the method and the 7-day review window.
card.svg (used as this page's og:image)