DigitalOcean Referral Badge
cloud1
cloud2
cloud3
cloud4
cloud5
cloud6
← Back to IP report

Log Explorer

Fact drill-down for 31.171.130.99
Risk 4 LOW Scope All time All-time facts 28 In-scope 28 Filtered 28 Seen 2024-12-232024-12-23
Active (none) Clear
Faceted filters (facts-based) exact core + snapshot + optional start/end
Annotation facets
HTTP facets
Snapshot facets
Custom time window (optional override)
Provide start/end to scope time explicitly (overrides days). Leave blank for all-time.
Tip: keep windows tight when you need speed, but the default is fact-complete.
Top annotators (facts, in-scope)
Top labels (facts, in-scope)
Click a pill to apply it as a filter.

Annotated access events

Showing page 1 / 1 — total 28 rows
#1 2024-12-23 23:42:18 event 2113117 GET 404 bytes 7980
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.1 Safari/605.1.15
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/logs/smtp.log
referer
-
UA
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.1 Safari/605.1.15
summary
event observed
details
subnet
31.171.130.0/24
asn
206092 — F.N.S. HOLDINGS LIMITED
geo
United Kingdom, England, Slough
org
NR Cust Expressvpn
#2 2024-12-23 23:42:18 event 2113116 GET 404 bytes 7980
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.1 Safari/605.1.15
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/logs/smtp.log
referer
-
UA
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.1 Safari/605.1.15
summary
event observed
details
subnet
31.171.130.0/24
asn
206092 — F.N.S. HOLDINGS LIMITED
geo
United Kingdom, England, Slough
org
NR Cust Expressvpn
#3 2024-12-23 23:40:08 event 2113003 GET 410 bytes 143
ann sfp 40 label sensitive_file
Request Probe for environment/secret file (.env)
referer
-
UA
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.1 Safari/605.1.15
Annotation facts
label
sensitive_file
rule
sfp:file:env
conf
92.00
details
Request targeted a .env-style file (often contains secrets). Snippet='/staging/.env'
More (full fields + snapshot) expand
url
/staging/.env
referer
-
UA
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.1 Safari/605.1.15
summary
Probe for environment/secret file (.env)
details
Request targeted a .env-style file (often contains secrets). Snippet='/staging/.env'
subnet
31.171.130.0/24
asn
206092 — F.N.S. HOLDINGS LIMITED
geo
United Kingdom, England, Slough
org
NR Cust Expressvpn
#4 2024-12-23 23:40:08 event 2113002 GET 410 bytes 143
ann sfp 40 label sensitive_file
Request Probe for environment/secret file (.env)
referer
-
UA
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.1 Safari/605.1.15
Annotation facts
label
sensitive_file
rule
sfp:file:env
conf
92.00
details
Request targeted a .env-style file (often contains secrets). Snippet='/staging/.env'
More (full fields + snapshot) expand
url
/staging/.env
referer
-
UA
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.1 Safari/605.1.15
summary
Probe for environment/secret file (.env)
details
Request targeted a .env-style file (often contains secrets). Snippet='/staging/.env'
subnet
31.171.130.0/24
asn
206092 — F.N.S. HOLDINGS LIMITED
geo
United Kingdom, England, Slough
org
NR Cust Expressvpn
#5 2024-12-23 23:40:08 event 2113003 GET 410 bytes 143
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.1 Safari/605.1.15
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/staging/.env
referer
-
UA
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.1 Safari/605.1.15
summary
event observed
details
subnet
31.171.130.0/24
asn
206092 — F.N.S. HOLDINGS LIMITED
geo
United Kingdom, England, Slough
org
NR Cust Expressvpn
#6 2024-12-23 23:40:08 event 2113002 GET 410 bytes 143
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.1 Safari/605.1.15
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/staging/.env
referer
-
UA
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.1 Safari/605.1.15
summary
event observed
details
subnet
31.171.130.0/24
asn
206092 — F.N.S. HOLDINGS LIMITED
geo
United Kingdom, England, Slough
org
NR Cust Expressvpn
#7 2024-12-23 23:37:48 event 2112895 GET 301 bytes 169
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.1 Safari/605.1.15
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/secure/.aws/credentials
referer
-
UA
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.1 Safari/605.1.15
summary
event observed
details
subnet
31.171.130.0/24
asn
206092 — F.N.S. HOLDINGS LIMITED
geo
United Kingdom, England, Slough
org
NR Cust Expressvpn
#8 2024-12-23 23:37:48 event 2112894 GET 301 bytes 169
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.1 Safari/605.1.15
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/secure/.aws/credentials
referer
-
UA
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.1 Safari/605.1.15
summary
event observed
details
subnet
31.171.130.0/24
asn
206092 — F.N.S. HOLDINGS LIMITED
geo
United Kingdom, England, Slough
org
NR Cust Expressvpn
#9 2024-12-23 23:36:19 event 2112813 GET 410 bytes 143
ann sfp 40 label sensitive_file
Request Probe for environment/secret file (.env)
referer
-
UA
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.1 Safari/605.1.15
Annotation facts
label
sensitive_file
rule
sfp:file:env
conf
92.00
details
Request targeted a .env-style file (often contains secrets). Snippet='/github/workflows/.env'
More (full fields + snapshot) expand
url
/github/workflows/.env
referer
-
UA
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.1 Safari/605.1.15
summary
Probe for environment/secret file (.env)
details
Request targeted a .env-style file (often contains secrets). Snippet='/github/workflows/.env'
subnet
31.171.130.0/24
asn
206092 — F.N.S. HOLDINGS LIMITED
geo
United Kingdom, England, Slough
org
NR Cust Expressvpn
#10 2024-12-23 23:36:19 event 2112811 GET 410 bytes 143
ann sfp 40 label sensitive_file
Request Probe for environment/secret file (.env)
referer
-
UA
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.1 Safari/605.1.15
Annotation facts
label
sensitive_file
rule
sfp:file:env
conf
92.00
details
Request targeted a .env-style file (often contains secrets). Snippet='/github/workflows/.env'
More (full fields + snapshot) expand
url
/github/workflows/.env
referer
-
UA
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.1 Safari/605.1.15
summary
Probe for environment/secret file (.env)
details
Request targeted a .env-style file (often contains secrets). Snippet='/github/workflows/.env'
subnet
31.171.130.0/24
asn
206092 — F.N.S. HOLDINGS LIMITED
geo
United Kingdom, England, Slough
org
NR Cust Expressvpn
#11 2024-12-23 23:36:19 event 2112813 GET 410 bytes 143
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.1 Safari/605.1.15
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/github/workflows/.env
referer
-
UA
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.1 Safari/605.1.15
summary
event observed
details
subnet
31.171.130.0/24
asn
206092 — F.N.S. HOLDINGS LIMITED
geo
United Kingdom, England, Slough
org
NR Cust Expressvpn
#12 2024-12-23 23:36:19 event 2112811 GET 410 bytes 143
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.1 Safari/605.1.15
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/github/workflows/.env
referer
-
UA
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.1 Safari/605.1.15
summary
event observed
details
subnet
31.171.130.0/24
asn
206092 — F.N.S. HOLDINGS LIMITED
geo
United Kingdom, England, Slough
org
NR Cust Expressvpn
#13 2024-12-23 23:33:27 event 2112675 GET 404 bytes 7979
ann trav 34 label trav
Request Path traversal / LFI indicator detected
referer
-
UA
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.1 Safari/605.1.15
Annotation facts
label
trav
rule
trav:sensitive_target
conf
95.00
details
Detected explicit traversal/LFI mechanics (dotdot segments, encoded traversal, local file / stream wrappers, or sensitive file targets). This annotator intentionally does not fire on mere URL depth or on traversal-ish parameter names without mechanics.
More (full fields + snapshot) expand
url
/private/settings.env
referer
-
UA
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.1 Safari/605.1.15
summary
Path traversal / LFI indicator detected
details
Detected explicit traversal/LFI mechanics (dotdot segments, encoded traversal, local file / stream wrappers, or sensitive file targets). This annotator intentionally does not fire on mere URL depth or on traversal-ish parameter names without mechanics.
subnet
31.171.130.0/24
asn
206092 — F.N.S. HOLDINGS LIMITED
geo
United Kingdom, England, Slough
org
NR Cust Expressvpn
#14 2024-12-23 23:33:27 event 2112674 GET 404 bytes 7979
ann trav 34 label trav
Request Path traversal / LFI indicator detected
referer
-
UA
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.1 Safari/605.1.15
Annotation facts
label
trav
rule
trav:sensitive_target
conf
95.00
details
Detected explicit traversal/LFI mechanics (dotdot segments, encoded traversal, local file / stream wrappers, or sensitive file targets). This annotator intentionally does not fire on mere URL depth or on traversal-ish parameter names without mechanics.
More (full fields + snapshot) expand
url
/private/settings.env
referer
-
UA
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.1 Safari/605.1.15
summary
Path traversal / LFI indicator detected
details
Detected explicit traversal/LFI mechanics (dotdot segments, encoded traversal, local file / stream wrappers, or sensitive file targets). This annotator intentionally does not fire on mere URL depth or on traversal-ish parameter names without mechanics.
subnet
31.171.130.0/24
asn
206092 — F.N.S. HOLDINGS LIMITED
geo
United Kingdom, England, Slough
org
NR Cust Expressvpn
#15 2024-12-23 23:33:27 event 2112675 GET 404 bytes 7979
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.1 Safari/605.1.15
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/private/settings.env
referer
-
UA
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.1 Safari/605.1.15
summary
event observed
details
subnet
31.171.130.0/24
asn
206092 — F.N.S. HOLDINGS LIMITED
geo
United Kingdom, England, Slough
org
NR Cust Expressvpn
#16 2024-12-23 23:33:27 event 2112674 GET 404 bytes 7979
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.1 Safari/605.1.15
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/private/settings.env
referer
-
UA
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.1 Safari/605.1.15
summary
event observed
details
subnet
31.171.130.0/24
asn
206092 — F.N.S. HOLDINGS LIMITED
geo
United Kingdom, England, Slough
org
NR Cust Expressvpn
#17 2024-12-23 23:30:28 event 2112536 GET 410 bytes 143
ann sfp 40 label sensitive_file
Request Probe for environment/secret file (.env)
referer
-
UA
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.1 Safari/605.1.15
Annotation facts
label
sensitive_file
rule
sfp:file:env
conf
92.00
details
Request targeted a .env-style file (often contains secrets). Snippet='/services/crm/.env'
More (full fields + snapshot) expand
url
/services/crm/.env
referer
-
UA
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.1 Safari/605.1.15
summary
Probe for environment/secret file (.env)
details
Request targeted a .env-style file (often contains secrets). Snippet='/services/crm/.env'
subnet
31.171.130.0/24
asn
206092 — F.N.S. HOLDINGS LIMITED
geo
United Kingdom, England, Slough
org
NR Cust Expressvpn
#18 2024-12-23 23:30:28 event 2112535 GET 410 bytes 143
ann sfp 40 label sensitive_file
Request Probe for environment/secret file (.env)
referer
-
UA
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.1 Safari/605.1.15
Annotation facts
label
sensitive_file
rule
sfp:file:env
conf
92.00
details
Request targeted a .env-style file (often contains secrets). Snippet='/services/crm/.env'
More (full fields + snapshot) expand
url
/services/crm/.env
referer
-
UA
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.1 Safari/605.1.15
summary
Probe for environment/secret file (.env)
details
Request targeted a .env-style file (often contains secrets). Snippet='/services/crm/.env'
subnet
31.171.130.0/24
asn
206092 — F.N.S. HOLDINGS LIMITED
geo
United Kingdom, England, Slough
org
NR Cust Expressvpn
#19 2024-12-23 23:30:28 event 2112536 GET 410 bytes 143
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.1 Safari/605.1.15
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/services/crm/.env
referer
-
UA
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.1 Safari/605.1.15
summary
event observed
details
subnet
31.171.130.0/24
asn
206092 — F.N.S. HOLDINGS LIMITED
geo
United Kingdom, England, Slough
org
NR Cust Expressvpn
#20 2024-12-23 23:30:28 event 2112535 GET 410 bytes 143
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.1 Safari/605.1.15
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/services/crm/.env
referer
-
UA
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.1 Safari/605.1.15
summary
event observed
details
subnet
31.171.130.0/24
asn
206092 — F.N.S. HOLDINGS LIMITED
geo
United Kingdom, England, Slough
org
NR Cust Expressvpn
#21 2024-12-23 23:28:50 event 2112456 GET 301 bytes 169
ann sfp 40 label sensitive_file
Request Probe for environment/secret file (.env)
referer
-
UA
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.1 Safari/605.1.15
Annotation facts
label
sensitive_file
rule
sfp:file:env
conf
92.00
details
Request targeted a .env-style file (often contains secrets). Snippet='/website/.env'
More (full fields + snapshot) expand
url
/website/.env
referer
-
UA
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.1 Safari/605.1.15
summary
Probe for environment/secret file (.env)
details
Request targeted a .env-style file (often contains secrets). Snippet='/website/.env'
subnet
31.171.130.0/24
asn
206092 — F.N.S. HOLDINGS LIMITED
geo
United Kingdom, England, Slough
org
NR Cust Expressvpn
#22 2024-12-23 23:28:50 event 2112455 GET 301 bytes 169
ann sfp 40 label sensitive_file
Request Probe for environment/secret file (.env)
referer
-
UA
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.1 Safari/605.1.15
Annotation facts
label
sensitive_file
rule
sfp:file:env
conf
92.00
details
Request targeted a .env-style file (often contains secrets). Snippet='/website/.env'
More (full fields + snapshot) expand
url
/website/.env
referer
-
UA
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.1 Safari/605.1.15
summary
Probe for environment/secret file (.env)
details
Request targeted a .env-style file (often contains secrets). Snippet='/website/.env'
subnet
31.171.130.0/24
asn
206092 — F.N.S. HOLDINGS LIMITED
geo
United Kingdom, England, Slough
org
NR Cust Expressvpn
#23 2024-12-23 23:28:50 event 2112456 GET 301 bytes 169
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.1 Safari/605.1.15
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/website/.env
referer
-
UA
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.1 Safari/605.1.15
summary
event observed
details
subnet
31.171.130.0/24
asn
206092 — F.N.S. HOLDINGS LIMITED
geo
United Kingdom, England, Slough
org
NR Cust Expressvpn
#24 2024-12-23 23:28:50 event 2112455 GET 301 bytes 169
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.1 Safari/605.1.15
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/website/.env
referer
-
UA
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.1 Safari/605.1.15
summary
event observed
details
subnet
31.171.130.0/24
asn
206092 — F.N.S. HOLDINGS LIMITED
geo
United Kingdom, England, Slough
org
NR Cust Expressvpn
#25 2024-12-23 23:28:41 event 2112452 GET 410 bytes 143
ann sfp 40 label sensitive_file
Request Probe for environment/secret file (.env)
referer
-
UA
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.1 Safari/605.1.15
Annotation facts
label
sensitive_file
rule
sfp:file:env
conf
92.00
details
Request targeted a .env-style file (often contains secrets). Snippet='/app/.env'
More (full fields + snapshot) expand
url
/app/.env
referer
-
UA
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.1 Safari/605.1.15
summary
Probe for environment/secret file (.env)
details
Request targeted a .env-style file (often contains secrets). Snippet='/app/.env'
subnet
31.171.130.0/24
asn
206092 — F.N.S. HOLDINGS LIMITED
geo
United Kingdom, England, Slough
org
NR Cust Expressvpn
#26 2024-12-23 23:28:41 event 2112451 GET 410 bytes 143
ann sfp 40 label sensitive_file
Request Probe for environment/secret file (.env)
referer
-
UA
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.1 Safari/605.1.15
Annotation facts
label
sensitive_file
rule
sfp:file:env
conf
92.00
details
Request targeted a .env-style file (often contains secrets). Snippet='/app/.env'
More (full fields + snapshot) expand
url
/app/.env
referer
-
UA
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.1 Safari/605.1.15
summary
Probe for environment/secret file (.env)
details
Request targeted a .env-style file (often contains secrets). Snippet='/app/.env'
subnet
31.171.130.0/24
asn
206092 — F.N.S. HOLDINGS LIMITED
geo
United Kingdom, England, Slough
org
NR Cust Expressvpn
#27 2024-12-23 23:28:41 event 2112452 GET 410 bytes 143
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.1 Safari/605.1.15
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/app/.env
referer
-
UA
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.1 Safari/605.1.15
summary
event observed
details
subnet
31.171.130.0/24
asn
206092 — F.N.S. HOLDINGS LIMITED
geo
United Kingdom, England, Slough
org
NR Cust Expressvpn
#28 2024-12-23 23:28:41 event 2112451 GET 410 bytes 143
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.1 Safari/605.1.15
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/app/.env
referer
-
UA
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.1 Safari/605.1.15
summary
event observed
details
subnet
31.171.130.0/24
asn
206092 — F.N.S. HOLDINGS LIMITED
geo
United Kingdom, England, Slough
org
NR Cust Expressvpn