94.26.106.214
In feed.txt Persistent Regular Toolkit
Blocked indefinitely since UTC on our servers, including web requests through Cloudflare, and in feed.txt. A hosting-network block has no end date; it ends only through the delisting path.
Record
- Score
- 42/100each request counts half as much after 30 days
- Worst level
- Persistent
- Attack-shaped requests
- 79all time
- Active days
- 2UTC days
- First seen
- Last seen
- Servers hit
- 2
- Targets
- 1site
- Times blocked
- 1by the evidence rules
Its traffic requested a .env file, hoping to find API keys or database credentials; it also requested a config.json file, hoping it exposes API keys or internal settings; it also probed for an exposed .git directory to download the site's source history and config.
Surfaces: web-app. Attack types: scanning, hunting for secrets. Seen by: edge, web.
Activity, last 90 days
Active on 2 of the last 90 UTC days. Current block: , with no end date.
Daily counts
| Day (UTC) | Requests |
|---|---|
| 3 | |
| 76 |
- At least 76 requests a minute at its peak ( UTC; identical requests in the same second are stored once).
- Methods: GET 87.
- The servers we watch answered: 404 50, 301 33 (totals only, from our web servers).
Evidence
Newest first, the latest 50 stored requests grouped into runs. Times are UTC. The user agent is shown as its family only.
| Time | Site | What happened | Request | User agent | Seen by |
|---|---|---|---|---|---|
| haived.com | requested wp-config.php or a backup copy of it, hoping to read the database password in clear text | GET /wp-config.php | browser claim | edge | |
| haived.com | 3× requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot (3 distinct paths) | GET /config.js | browser claim | web | |
| haived.com | requested a .env file, hoping to find API keys or database credentials | GET /@fs/.env.local? | browser claim | web | |
| haived.com | probed for an exposed .git directory to download the site's source history and config | GET /.git/HEAD | browser claim | web | |
| haived.com | requested a .env file, hoping to find API keys or database credentials | GET /@fs/.env? | browser claim | web | |
| haived.com | requested a config.json file, hoping it exposes API keys or internal settings | GET /.langchain/config.json | browser claim | web | |
| haived.com | requested a .env file, hoping to find API keys or database credentials | GET /cypress.env.json | browser claim | web | |
| haived.com | 2× requested a config.json file, hoping it exposes API keys or internal settings (2 distinct paths) | GET /config/config.json | browser claim | web | |
| haived.com | requested docker-compose.yml, which often contains embedded passwords and connection strings | GET /docker-compose.yml | browser claim | web | |
| haived.com | probed for an exposed .git directory to download the site's source history and config | GET /.git/config | browser claim | web | |
| haived.com | requested a .env file, hoping to find API keys or database credentials | GET /@fs/.env.local? | browser claim | web | |
| haived.com | requested an AWS credentials file left in a web-accessible path by mistake | GET /.aws/credentials | browser claim | web | |
| haived.com | made a request that matched no known pattern | GET /bootstrap/cache/config.php | browser claim | web | |
| haived.com | probed for an exposed .git directory to download the site's source history and config | GET /.git/HEAD | browser claim | web | |
| haived.com | requested a .env file, hoping to find API keys or database credentials | GET /@fs/.env? | browser claim | web | |
| haived.com | requested docker-compose.yml, which often contains embedded passwords and connection strings | GET /docker-compose.yml | browser claim | web | |
| haived.com | made a request that matched no known pattern | GET /config/mail.php | browser claim | web | |
| haived.com | requested a config.json file, hoping it exposes API keys or internal settings | GET /config.json | browser claim | web | |
| haived.com | probed for an exposed .git directory to download the site's source history and config | GET /.git/config | browser claim | web | |
| haived.com | requested an AWS credentials file left in a web-accessible path by mistake | GET /.aws/credentials | browser claim | web | |
| haived.com | made a request that matched no known pattern | GET /config/app.php | browser claim | web | |
| haived.com | requested a .env file, hoping to find API keys or database credentials | GET /cypress.env.json | browser claim | web | |
| haived.com | 3× made a request that matched no known pattern (3 distinct paths) | GET /config/auth.php | browser claim | web | |
| haived.com | requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot | GET /next.config.js | browser claim | web | |
| haived.com | probed for an exposed GraphQL endpoint or its config file, often a precursor to an introspection query | GET /graphql | browser claim | web | |
| haived.com | requested a generic /config or /api/config endpoint, hoping the app exposes its runtime configuration unauthenticated | GET /api/config | browser claim | web | |
| haived.com | 2× made a request that matched no known pattern (2 distinct paths) | GET /api/auth/config | browser claim | web | |
| haived.com | probed for an exposed GraphQL endpoint or its config file, often a precursor to an introspection query | GET /graphql | browser claim | web | |
| haived.com | 9× requested a .env file, hoping to find API keys or database credentials (9 distinct paths) | GET /laravel/.env | browser claim | web | |
| haived.com | requested a .env file, hoping to find API keys or database credentials | GET /laravel/.env | browser claim | web | |
| haived.com | requested a .env file, hoping to find API keys or database credentials | GET /config/.env | browser claim | web | |
| haived.com | 5× requested a .env file, hoping to find API keys or database credentials (5 distinct paths) | GET /backend/.env | browser claim | web | |
Network
- ASN
- AS197170 TechTies Inc.
- Network type
- hosting
- Reverse DNS
- none
- Country
- Germany DE
- City
- Frankfurt am Main (registry location of a hosting network)
- Flags
- none observed
- Abuse contact
- found in the registry
- Checked
Delisting
This block has no end date. If the range now belongs to someone else, it can leave the list through the free delisting path; every decision is published on the delisting log.