DigitalOcean Referral Badge
cloud1
cloud2
cloud3
cloud4
cloud5
cloud6
← Back to IP report

Log Explorer

Fact drill-down for 78.153.140.178
Risk 15 LOW Scope All time All-time facts 113 In-scope 113 Filtered 113 Seen 2025-11-062025-11-28
Active (none) Clear
Faceted filters (facts-based) exact core + snapshot + optional start/end
Annotation facets
HTTP facets
Snapshot facets
Custom time window (optional override)
Provide start/end to scope time explicitly (overrides days). Leave blank for all-time.
Tip: keep windows tight when you need speed, but the default is fact-complete.
Top annotators (facts, in-scope)
Click a pill to apply it as a filter.

Annotated access events

Showing page 1 / 3 — total 113 rows
#1 2025-11-28 15:22:31 event 20102269 GET 301 bytes 178
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Macintosh; U; PPC Mac OS X; nl-nl) AppleWebKit/416.11 (KHTML, like Gecko) Safari/416.12
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/private/aws-config.json
referer
-
UA
Mozilla/5.0 (Macintosh; U; PPC Mac OS X; nl-nl) AppleWebKit/416.11 (KHTML, like Gecko) Safari/416.12
summary
event observed
details
subnet
78.153.140.0/24
asn
202306 — HOSTGLOBAL.PLUS LTD
geo
United Kingdom, England, City of London
org
HOSTGLOBAL.PLUS LTD
#2 2025-11-28 15:22:31 event 20102267 GET 301 bytes 178
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Linux; U; Android 4.2.2; pt-br; GT-I9082L Build/JDQ39) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Mobile Safari/534.30
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/private/aws_config.json
referer
-
UA
Mozilla/5.0 (Linux; U; Android 4.2.2; pt-br; GT-I9082L Build/JDQ39) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Mobile Safari/534.30
summary
event observed
details
subnet
78.153.140.0/24
asn
202306 — HOSTGLOBAL.PLUS LTD
geo
United Kingdom, England, City of London
org
HOSTGLOBAL.PLUS LTD
#3 2025-11-28 15:22:30 event 20102266 GET 301 bytes 178
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Linux; Android 7.0; SM-G935V Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.111 Mobile Safari/537.36
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/home/*/.aws/credentials
referer
-
UA
Mozilla/5.0 (Linux; Android 7.0; SM-G935V Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.111 Mobile Safari/537.36
summary
event observed
details
subnet
78.153.140.0/24
asn
202306 — HOSTGLOBAL.PLUS LTD
geo
United Kingdom, England, City of London
org
HOSTGLOBAL.PLUS LTD
#4 2025-11-28 15:22:30 event 20102265 GET 301 bytes 178
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_6_8) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.85 Safari/537.36
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/config/aws/secrets.conf
referer
-
UA
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_6_8) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.85 Safari/537.36
summary
event observed
details
subnet
78.153.140.0/24
asn
202306 — HOSTGLOBAL.PLUS LTD
geo
United Kingdom, England, City of London
org
HOSTGLOBAL.PLUS LTD
#5 2025-11-28 15:22:30 event 20102264 GET 301 bytes 178
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Windows 98; U; en) Opera 8.54
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/.aws/ssh/public_key.pem
referer
-
UA
Mozilla/5.0 (Windows 98; U; en) Opera 8.54
summary
event observed
details
subnet
78.153.140.0/24
asn
202306 — HOSTGLOBAL.PLUS LTD
geo
United Kingdom, England, City of London
org
HOSTGLOBAL.PLUS LTD
#6 2025-11-28 15:22:29 event 20102262 GET 301 bytes 178
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (SymbianOS/9.1; U; [en-us]) AppleWebKit/413 (KHTML, like Gecko) Safari/413
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/secrets/aws/profile.log
referer
-
UA
Mozilla/5.0 (SymbianOS/9.1; U; [en-us]) AppleWebKit/413 (KHTML, like Gecko) Safari/413
summary
event observed
details
subnet
78.153.140.0/24
asn
202306 — HOSTGLOBAL.PLUS LTD
geo
United Kingdom, England, City of London
org
HOSTGLOBAL.PLUS LTD
#7 2025-11-28 15:22:29 event 20102258 GET 301 bytes 178
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Windows NT 6.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36 OPR/36.0.2130.80
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/website/.env.production
referer
-
UA
Mozilla/5.0 (Windows NT 6.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36 OPR/36.0.2130.80
summary
event observed
details
subnet
78.153.140.0/24
asn
202306 — HOSTGLOBAL.PLUS LTD
geo
United Kingdom, England, City of London
org
HOSTGLOBAL.PLUS LTD
#8 2025-11-28 15:22:29 event 20102258 GET 301 bytes 178
ann sfp 40 label sensitive_file
Request Probe for environment/secret file (.env)
referer
-
UA
Mozilla/5.0 (Windows NT 6.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36 OPR/36.0.2130.80
Annotation facts
label
sensitive_file
rule
sfp:file:env
conf
92.00
details
Request targeted a .env-style file (often contains secrets). Snippet='/website/.env.production'
More (full fields + snapshot) expand
url
/website/.env.production
referer
-
UA
Mozilla/5.0 (Windows NT 6.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36 OPR/36.0.2130.80
summary
Probe for environment/secret file (.env)
details
Request targeted a .env-style file (often contains secrets). Snippet='/website/.env.production'
subnet
78.153.140.0/24
asn
202306 — HOSTGLOBAL.PLUS LTD
geo
United Kingdom, England, City of London
org
HOSTGLOBAL.PLUS LTD
#9 2025-11-28 15:22:28 event 20102255 GET 301 bytes 178
ann base label observed
Request event observed
referer
-
UA
Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; de) Opera 8.54
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/server/.env.credentials
referer
-
UA
Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; de) Opera 8.54
summary
event observed
details
subnet
78.153.140.0/24
asn
202306 — HOSTGLOBAL.PLUS LTD
geo
United Kingdom, England, City of London
org
HOSTGLOBAL.PLUS LTD
#10 2025-11-28 15:22:28 event 20102253 GET 301 bytes 178
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/43.0.2357.65 Safari/537.36
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/service/.env.production
referer
-
UA
Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/43.0.2357.65 Safari/537.36
summary
event observed
details
subnet
78.153.140.0/24
asn
202306 — HOSTGLOBAL.PLUS LTD
geo
United Kingdom, England, City of London
org
HOSTGLOBAL.PLUS LTD
#11 2025-11-28 15:22:28 event 20102252 GET 301 bytes 178
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Windows; U; Windows NT 6.0; de; rv:1.9.2.20) Gecko/20110803 Firefox/3.6.20
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/project/.env.production
referer
-
UA
Mozilla/5.0 (Windows; U; Windows NT 6.0; de; rv:1.9.2.20) Gecko/20110803 Firefox/3.6.20
summary
event observed
details
subnet
78.153.140.0/24
asn
202306 — HOSTGLOBAL.PLUS LTD
geo
United Kingdom, England, City of London
org
HOSTGLOBAL.PLUS LTD
#12 2025-11-28 15:22:28 event 20102255 GET 301 bytes 178
ann sfp 40 label sensitive_file
Request Probe for environment/secret file (.env)
referer
-
UA
Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; de) Opera 8.54
Annotation facts
label
sensitive_file
rule
sfp:file:env
conf
92.00
details
Request targeted a .env-style file (often contains secrets). Snippet='/server/.env.credentials'
More (full fields + snapshot) expand
url
/server/.env.credentials
referer
-
UA
Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; de) Opera 8.54
summary
Probe for environment/secret file (.env)
details
Request targeted a .env-style file (often contains secrets). Snippet='/server/.env.credentials'
subnet
78.153.140.0/24
asn
202306 — HOSTGLOBAL.PLUS LTD
geo
United Kingdom, England, City of London
org
HOSTGLOBAL.PLUS LTD
#13 2025-11-28 15:22:28 event 20102253 GET 301 bytes 178
ann sfp 40 label sensitive_file
Request Probe for environment/secret file (.env)
referer
-
UA
Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/43.0.2357.65 Safari/537.36
Annotation facts
label
sensitive_file
rule
sfp:file:env
conf
92.00
details
Request targeted a .env-style file (often contains secrets). Snippet='/service/.env.production'
More (full fields + snapshot) expand
url
/service/.env.production
referer
-
UA
Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/43.0.2357.65 Safari/537.36
summary
Probe for environment/secret file (.env)
details
Request targeted a .env-style file (often contains secrets). Snippet='/service/.env.production'
subnet
78.153.140.0/24
asn
202306 — HOSTGLOBAL.PLUS LTD
geo
United Kingdom, England, City of London
org
HOSTGLOBAL.PLUS LTD
#14 2025-11-28 15:22:28 event 20102252 GET 301 bytes 178
ann sfp 40 label sensitive_file
Request Probe for environment/secret file (.env)
referer
-
UA
Mozilla/5.0 (Windows; U; Windows NT 6.0; de; rv:1.9.2.20) Gecko/20110803 Firefox/3.6.20
Annotation facts
label
sensitive_file
rule
sfp:file:env
conf
92.00
details
Request targeted a .env-style file (often contains secrets). Snippet='/project/.env.production'
More (full fields + snapshot) expand
url
/project/.env.production
referer
-
UA
Mozilla/5.0 (Windows; U; Windows NT 6.0; de; rv:1.9.2.20) Gecko/20110803 Firefox/3.6.20
summary
Probe for environment/secret file (.env)
details
Request targeted a .env-style file (often contains secrets). Snippet='/project/.env.production'
subnet
78.153.140.0/24
asn
202306 — HOSTGLOBAL.PLUS LTD
geo
United Kingdom, England, City of London
org
HOSTGLOBAL.PLUS LTD
#15 2025-11-28 15:22:27 event 20102251 GET 301 bytes 178
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Windows NT 6.3; WOW64; Trident/7.0; Touch; USPortal; rv:11.0) like Gecko
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/storage/.env.production
referer
-
UA
Mozilla/5.0 (Windows NT 6.3; WOW64; Trident/7.0; Touch; USPortal; rv:11.0) like Gecko
summary
event observed
details
subnet
78.153.140.0/24
asn
202306 — HOSTGLOBAL.PLUS LTD
geo
United Kingdom, England, City of London
org
HOSTGLOBAL.PLUS LTD
#16 2025-11-28 15:22:27 event 20102249 GET 301 bytes 178
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/61.0.3163.100 Safari/537.36 OPR/48.0.2685.52
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/resources/.env.settings
referer
-
UA
Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/61.0.3163.100 Safari/537.36 OPR/48.0.2685.52
summary
event observed
details
subnet
78.153.140.0/24
asn
202306 — HOSTGLOBAL.PLUS LTD
geo
United Kingdom, England, City of London
org
HOSTGLOBAL.PLUS LTD
#17 2025-11-28 15:22:27 event 20102247 GET 301 bytes 178
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Linux; U; Android 4.0.3; en-us; HTC_C715c Build/IML74K) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Mobile Safari/534.30
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/var/www/html/admin/.env
referer
-
UA
Mozilla/5.0 (Linux; U; Android 4.0.3; en-us; HTC_C715c Build/IML74K) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Mobile Safari/534.30
summary
event observed
details
subnet
78.153.140.0/24
asn
202306 — HOSTGLOBAL.PLUS LTD
geo
United Kingdom, England, City of London
org
HOSTGLOBAL.PLUS LTD
#18 2025-11-28 15:22:27 event 20102251 GET 301 bytes 178
ann sfp 40 label sensitive_file
Request Probe for environment/secret file (.env)
referer
-
UA
Mozilla/5.0 (Windows NT 6.3; WOW64; Trident/7.0; Touch; USPortal; rv:11.0) like Gecko
Annotation facts
label
sensitive_file
rule
sfp:file:env
conf
92.00
details
Request targeted a .env-style file (often contains secrets). Snippet='/storage/.env.production'
More (full fields + snapshot) expand
url
/storage/.env.production
referer
-
UA
Mozilla/5.0 (Windows NT 6.3; WOW64; Trident/7.0; Touch; USPortal; rv:11.0) like Gecko
summary
Probe for environment/secret file (.env)
details
Request targeted a .env-style file (often contains secrets). Snippet='/storage/.env.production'
subnet
78.153.140.0/24
asn
202306 — HOSTGLOBAL.PLUS LTD
geo
United Kingdom, England, City of London
org
HOSTGLOBAL.PLUS LTD
#19 2025-11-28 15:22:27 event 20102249 GET 301 bytes 178
ann sfp 40 label sensitive_file
Request Probe for environment/secret file (.env)
referer
-
UA
Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/61.0.3163.100 Safari/537.36 OPR/48.0.2685.52
Annotation facts
label
sensitive_file
rule
sfp:file:env
conf
92.00
details
Request targeted a .env-style file (often contains secrets). Snippet='/resources/.env.settings'
More (full fields + snapshot) expand
url
/resources/.env.settings
referer
-
UA
Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/61.0.3163.100 Safari/537.36 OPR/48.0.2685.52
summary
Probe for environment/secret file (.env)
details
Request targeted a .env-style file (often contains secrets). Snippet='/resources/.env.settings'
subnet
78.153.140.0/24
asn
202306 — HOSTGLOBAL.PLUS LTD
geo
United Kingdom, England, City of London
org
HOSTGLOBAL.PLUS LTD
#20 2025-11-28 15:22:27 event 20102247 GET 301 bytes 178
ann sfp 40 label sensitive_file
Request Probe for environment/secret file (.env)
referer
-
UA
Mozilla/5.0 (Linux; U; Android 4.0.3; en-us; HTC_C715c Build/IML74K) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Mobile Safari/534.30
Annotation facts
label
sensitive_file
rule
sfp:file:env
conf
92.00
details
Request targeted a .env-style file (often contains secrets). Snippet='/var/www/html/admin/.env'
More (full fields + snapshot) expand
url
/var/www/html/admin/.env
referer
-
UA
Mozilla/5.0 (Linux; U; Android 4.0.3; en-us; HTC_C715c Build/IML74K) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Mobile Safari/534.30
summary
Probe for environment/secret file (.env)
details
Request targeted a .env-style file (often contains secrets). Snippet='/var/www/html/admin/.env'
subnet
78.153.140.0/24
asn
202306 — HOSTGLOBAL.PLUS LTD
geo
United Kingdom, England, City of London
org
HOSTGLOBAL.PLUS LTD
#21 2025-11-28 15:22:26 event 20102246 GET 301 bytes 178
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Linux; U; Android 4.0.3; es-es; Sony Tablet S Build/TISU0143) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Safari/534.30
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/platform/.env/conf/.env
referer
-
UA
Mozilla/5.0 (Linux; U; Android 4.0.3; es-es; Sony Tablet S Build/TISU0143) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Safari/534.30
summary
event observed
details
subnet
78.153.140.0/24
asn
202306 — HOSTGLOBAL.PLUS LTD
geo
United Kingdom, England, City of London
org
HOSTGLOBAL.PLUS LTD
#22 2025-11-28 15:22:26 event 20102245 GET 301 bytes 178
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/525.19 (KHTML, like Gecko) Chrome/1.0.154.53 Safari/525.19
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/production/.env.staging
referer
-
UA
Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/525.19 (KHTML, like Gecko) Chrome/1.0.154.53 Safari/525.19
summary
event observed
details
subnet
78.153.140.0/24
asn
202306 — HOSTGLOBAL.PLUS LTD
geo
United Kingdom, England, City of London
org
HOSTGLOBAL.PLUS LTD
#23 2025-11-28 15:22:26 event 20102246 GET 301 bytes 178
ann sfp 40 label sensitive_file
Request Probe for environment/secret file (.env)
referer
-
UA
Mozilla/5.0 (Linux; U; Android 4.0.3; es-es; Sony Tablet S Build/TISU0143) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Safari/534.30
Annotation facts
label
sensitive_file
rule
sfp:file:env
conf
92.00
details
Request targeted a .env-style file (often contains secrets). Snippet='/platform/.env/conf/.env'
More (full fields + snapshot) expand
url
/platform/.env/conf/.env
referer
-
UA
Mozilla/5.0 (Linux; U; Android 4.0.3; es-es; Sony Tablet S Build/TISU0143) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Safari/534.30
summary
Probe for environment/secret file (.env)
details
Request targeted a .env-style file (often contains secrets). Snippet='/platform/.env/conf/.env'
subnet
78.153.140.0/24
asn
202306 — HOSTGLOBAL.PLUS LTD
geo
United Kingdom, England, City of London
org
HOSTGLOBAL.PLUS LTD
#24 2025-11-28 15:22:26 event 20102245 GET 301 bytes 178
ann sfp 40 label sensitive_file
Request Probe for environment/secret file (.env)
referer
-
UA
Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/525.19 (KHTML, like Gecko) Chrome/1.0.154.53 Safari/525.19
Annotation facts
label
sensitive_file
rule
sfp:file:env
conf
92.00
details
Request targeted a .env-style file (often contains secrets). Snippet='/production/.env.staging'
More (full fields + snapshot) expand
url
/production/.env.staging
referer
-
UA
Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/525.19 (KHTML, like Gecko) Chrome/1.0.154.53 Safari/525.19
summary
Probe for environment/secret file (.env)
details
Request targeted a .env-style file (often contains secrets). Snippet='/production/.env.staging'
subnet
78.153.140.0/24
asn
202306 — HOSTGLOBAL.PLUS LTD
geo
United Kingdom, England, City of London
org
HOSTGLOBAL.PLUS LTD
#25 2025-11-28 15:22:25 event 20102242 GET 301 bytes 178
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Windows; U; Windows NT 5.1; pt-BR; rv:1.8.0.2) Gecko/20060308 Firefox/1.5.0.2
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/wp-content/backups/.env
referer
-
UA
Mozilla/5.0 (Windows; U; Windows NT 5.1; pt-BR; rv:1.8.0.2) Gecko/20060308 Firefox/1.5.0.2
summary
event observed
details
subnet
78.153.140.0/24
asn
202306 — HOSTGLOBAL.PLUS LTD
geo
United Kingdom, England, City of London
org
HOSTGLOBAL.PLUS LTD
#26 2025-11-28 15:22:25 event 20102241 GET 301 bytes 178
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Linux; Android)AppleWebKit/535.19 (KHTML, like Gecko) DevBrowse/18.0.1025.133 Mobile Safari/535.19
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/production/.env.example
referer
-
UA
Mozilla/5.0 (Linux; Android)AppleWebKit/535.19 (KHTML, like Gecko) DevBrowse/18.0.1025.133 Mobile Safari/535.19
summary
event observed
details
subnet
78.153.140.0/24
asn
202306 — HOSTGLOBAL.PLUS LTD
geo
United Kingdom, England, City of London
org
HOSTGLOBAL.PLUS LTD
#27 2025-11-28 15:22:25 event 20102240 GET 301 bytes 178
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Linux; U; Android 4.2.2; en-us; mk808 Build/JDQ39) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Safari/534.30
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/wp-content/plugins/.env
referer
-
UA
Mozilla/5.0 (Linux; U; Android 4.2.2; en-us; mk808 Build/JDQ39) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Safari/534.30
summary
event observed
details
subnet
78.153.140.0/24
asn
202306 — HOSTGLOBAL.PLUS LTD
geo
United Kingdom, England, City of London
org
HOSTGLOBAL.PLUS LTD
#28 2025-11-28 15:22:25 event 20102242 GET 301 bytes 178
ann sfp 40 label sensitive_file
Request Probe for environment/secret file (.env)
referer
-
UA
Mozilla/5.0 (Windows; U; Windows NT 5.1; pt-BR; rv:1.8.0.2) Gecko/20060308 Firefox/1.5.0.2
Annotation facts
label
sensitive_file
rule
sfp:file:env
conf
92.00
details
Request targeted a .env-style file (often contains secrets). Snippet='/wp-content/backups/.env'
More (full fields + snapshot) expand
url
/wp-content/backups/.env
referer
-
UA
Mozilla/5.0 (Windows; U; Windows NT 5.1; pt-BR; rv:1.8.0.2) Gecko/20060308 Firefox/1.5.0.2
summary
Probe for environment/secret file (.env)
details
Request targeted a .env-style file (often contains secrets). Snippet='/wp-content/backups/.env'
subnet
78.153.140.0/24
asn
202306 — HOSTGLOBAL.PLUS LTD
geo
United Kingdom, England, City of London
org
HOSTGLOBAL.PLUS LTD
#29 2025-11-28 15:22:25 event 20102241 GET 301 bytes 178
ann sfp 40 label sensitive_file
Request Probe for environment/secret file (.env)
referer
-
UA
Mozilla/5.0 (Linux; Android)AppleWebKit/535.19 (KHTML, like Gecko) DevBrowse/18.0.1025.133 Mobile Safari/535.19
Annotation facts
label
sensitive_file
rule
sfp:file:env
conf
92.00
details
Request targeted a .env-style file (often contains secrets). Snippet='/production/.env.example'
More (full fields + snapshot) expand
url
/production/.env.example
referer
-
UA
Mozilla/5.0 (Linux; Android)AppleWebKit/535.19 (KHTML, like Gecko) DevBrowse/18.0.1025.133 Mobile Safari/535.19
summary
Probe for environment/secret file (.env)
details
Request targeted a .env-style file (often contains secrets). Snippet='/production/.env.example'
subnet
78.153.140.0/24
asn
202306 — HOSTGLOBAL.PLUS LTD
geo
United Kingdom, England, City of London
org
HOSTGLOBAL.PLUS LTD
#30 2025-11-28 15:22:25 event 20102240 GET 301 bytes 178
ann sfp 40 label sensitive_file
Request Probe for environment/secret file (.env)
referer
-
UA
Mozilla/5.0 (Linux; U; Android 4.2.2; en-us; mk808 Build/JDQ39) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Safari/534.30
Annotation facts
label
sensitive_file
rule
sfp:file:env
conf
92.00
details
Request targeted a .env-style file (often contains secrets). Snippet='/wp-content/plugins/.env'
More (full fields + snapshot) expand
url
/wp-content/plugins/.env
referer
-
UA
Mozilla/5.0 (Linux; U; Android 4.2.2; en-us; mk808 Build/JDQ39) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Safari/534.30
summary
Probe for environment/secret file (.env)
details
Request targeted a .env-style file (often contains secrets). Snippet='/wp-content/plugins/.env'
subnet
78.153.140.0/24
asn
202306 — HOSTGLOBAL.PLUS LTD
geo
United Kingdom, England, City of London
org
HOSTGLOBAL.PLUS LTD
#31 2025-11-28 15:22:23 event 20102239 GET 301 bytes 178
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (iPod; CPU iPhone OS 10_0 like Mac OS X) AppleWebKit/602.1.38 (KHTML, like Gecko) Version/10.0 Mobile/14A300 Safari/602.1
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/.env.example.production
referer
-
UA
Mozilla/5.0 (iPod; CPU iPhone OS 10_0 like Mac OS X) AppleWebKit/602.1.38 (KHTML, like Gecko) Version/10.0 Mobile/14A300 Safari/602.1
summary
event observed
details
subnet
78.153.140.0/24
asn
202306 — HOSTGLOBAL.PLUS LTD
geo
United Kingdom, England, City of London
org
HOSTGLOBAL.PLUS LTD
#32 2025-11-28 15:22:23 event 20102238 GET 301 bytes 178
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Macintosh; Intel Mac OS X 10.7; rv:38.0) Gecko/20100101 Firefox/38.0
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/.env
referer
-
UA
Mozilla/5.0 (Macintosh; Intel Mac OS X 10.7; rv:38.0) Gecko/20100101 Firefox/38.0
summary
event observed
details
subnet
78.153.140.0/24
asn
202306 — HOSTGLOBAL.PLUS LTD
geo
United Kingdom, England, City of London
org
HOSTGLOBAL.PLUS LTD
#33 2025-11-28 15:22:23 event 20102239 GET 301 bytes 178
ann sfp 40 label sensitive_file
Request Probe for environment/secret file (.env)
referer
-
UA
Mozilla/5.0 (iPod; CPU iPhone OS 10_0 like Mac OS X) AppleWebKit/602.1.38 (KHTML, like Gecko) Version/10.0 Mobile/14A300 Safari/602.1
Annotation facts
label
sensitive_file
rule
sfp:file:env
conf
92.00
details
Request targeted a .env-style file (often contains secrets). Snippet='/.env.example.production'
More (full fields + snapshot) expand
url
/.env.example.production
referer
-
UA
Mozilla/5.0 (iPod; CPU iPhone OS 10_0 like Mac OS X) AppleWebKit/602.1.38 (KHTML, like Gecko) Version/10.0 Mobile/14A300 Safari/602.1
summary
Probe for environment/secret file (.env)
details
Request targeted a .env-style file (often contains secrets). Snippet='/.env.example.production'
subnet
78.153.140.0/24
asn
202306 — HOSTGLOBAL.PLUS LTD
geo
United Kingdom, England, City of London
org
HOSTGLOBAL.PLUS LTD
#34 2025-11-28 15:22:23 event 20102238 GET 301 bytes 178
ann sfp 40 label sensitive_file
Request Probe for environment/secret file (.env)
referer
-
UA
Mozilla/5.0 (Macintosh; Intel Mac OS X 10.7; rv:38.0) Gecko/20100101 Firefox/38.0
Annotation facts
label
sensitive_file
rule
sfp:file:env
conf
92.00
details
Request targeted a .env-style file (often contains secrets). Snippet='/.env'
More (full fields + snapshot) expand
url
/.env
referer
-
UA
Mozilla/5.0 (Macintosh; Intel Mac OS X 10.7; rv:38.0) Gecko/20100101 Firefox/38.0
summary
Probe for environment/secret file (.env)
details
Request targeted a .env-style file (often contains secrets). Snippet='/.env'
subnet
78.153.140.0/24
asn
202306 — HOSTGLOBAL.PLUS LTD
geo
United Kingdom, England, City of London
org
HOSTGLOBAL.PLUS LTD
#35 2025-11-16 23:39:10 event 18754000 GET 301 bytes 178
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (iPad; CPU OS 9_3_2 like Mac OS X) AppleWebKit/601.1 (KHTML, like Gecko) CriOS/51.0.2704.104 Mobile/13F69 Safari/601.1.46
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/ssi/envout.bat?
referer
-
UA
Mozilla/5.0 (iPad; CPU OS 9_3_2 like Mac OS X) AppleWebKit/601.1 (KHTML, like Gecko) CriOS/51.0.2704.104 Mobile/13F69 Safari/601.1.46
summary
event observed
details
subnet
78.153.140.0/24
asn
202306 — HOSTGLOBAL.PLUS LTD
geo
United Kingdom, England, City of London
org
HOSTGLOBAL.PLUS LTD
#36 2025-11-16 23:39:08 event 18753998 GET 301 bytes 178
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Windows NT 5.1; rv:16.0) Gecko/20100101 Firefox/16.0
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/service-worker.js?local_access_token=2xkqYs8CCaI3g9tenveoHltLFKf
referer
-
UA
Mozilla/5.0 (Windows NT 5.1; rv:16.0) Gecko/20100101 Firefox/16.0
summary
event observed
details
subnet
78.153.140.0/24
asn
202306 — HOSTGLOBAL.PLUS LTD
geo
United Kingdom, England, City of London
org
HOSTGLOBAL.PLUS LTD
#37 2025-11-16 23:39:08 event 18753997 GET 301 bytes 178
ann base label observed
Request event observed
referer
-
UA
Dalvik/2.1.0 (Linux; U; Android 8.0.0; SM-N950U Build/R16NW)
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/wp-content/plugins/envato-market/inc/class-envato-market-api.php
referer
-
UA
Dalvik/2.1.0 (Linux; U; Android 8.0.0; SM-N950U Build/R16NW)
summary
event observed
details
subnet
78.153.140.0/24
asn
202306 — HOSTGLOBAL.PLUS LTD
geo
United Kingdom, England, City of London
org
HOSTGLOBAL.PLUS LTD
#38 2025-11-16 23:39:07 event 18753995 GET 301 bytes 178
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202.62 Safari/537.36 OPR/49.0.2725.34
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/login_up.php?success_redirect...2B%2Froot%2F.aws%2Fcredentials
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202.62 Safari/537.36 OPR/49.0.2725.34
summary
event observed
details
subnet
78.153.140.0/24
asn
202306 — HOSTGLOBAL.PLUS LTD
geo
United Kingdom, England, City of London
org
HOSTGLOBAL.PLUS LTD
#39 2025-11-16 23:39:07 event 18753992 GET 301 bytes 178
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/48.0.2564.116 Safari/537.36 OPR/35.0.2066.92
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/api_\x5Cxe3\x5Cx82\x5Cxad\x5Cxe3\x5Cx83\x5Cxbc/aws_\x5Cxe3\x5Cx82\x5Cxad\x5Cxe3\x5Cx83\x5Cxbc.json
referer
-
UA
Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/48.0.2564.116 Safari/537.36 OPR/35.0.2066.92
summary
event observed
details
subnet
78.153.140.0/24
asn
202306 — HOSTGLOBAL.PLUS LTD
geo
United Kingdom, England, City of London
org
HOSTGLOBAL.PLUS LTD
#40 2025-11-16 23:39:07 event 18753991 GET 301 bytes 178
ann base label observed
Request event observed
referer
-
UA
Opera/9.80 (Linux) Presto/2.12.388 Version/12.14
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/mgmt/shared/authn/login/~../~../~../~../root/.aws/credentials
referer
-
UA
Opera/9.80 (Linux) Presto/2.12.388 Version/12.14
summary
event observed
details
subnet
78.153.140.0/24
asn
202306 — HOSTGLOBAL.PLUS LTD
geo
United Kingdom, England, City of London
org
HOSTGLOBAL.PLUS LTD
#41 2025-11-16 23:39:07 event 18753991 GET 301 bytes 178
ann trav 26 label trav
Request Path traversal / LFI indicator detected
referer
-
UA
Opera/9.80 (Linux) Presto/2.12.388 Version/12.14
Annotation facts
label
trav
rule
trav:mixed_separators
conf
90.00
details
Detected explicit traversal/LFI mechanics (dotdot segments, encoded traversal, local file / stream wrappers, or sensitive file targets). This annotator intentionally does not fire on mere URL depth or on traversal-ish parameter names without mechanics.
More (full fields + snapshot) expand
url
/mgmt/shared/authn/login/~../~../~../~../root/.aws/credentials
referer
-
UA
Opera/9.80 (Linux) Presto/2.12.388 Version/12.14
summary
Path traversal / LFI indicator detected
details
Detected explicit traversal/LFI mechanics (dotdot segments, encoded traversal, local file / stream wrappers, or sensitive file targets). This annotator intentionally does not fire on mere URL depth or on traversal-ish parameter names without mechanics.
subnet
78.153.140.0/24
asn
202306 — HOSTGLOBAL.PLUS LTD
geo
United Kingdom, England, City of London
org
HOSTGLOBAL.PLUS LTD
#42 2025-11-16 23:39:07 event 18753991 GET 301 bytes 178
ann sfp 34 label sensitive_file
Request Directory traversal indicator
referer
-
UA
Opera/9.80 (Linux) Presto/2.12.388 Version/12.14
Annotation facts
label
sensitive_file
rule
sfp:traversal
conf
86.00
details
Traversal sequences were present (raw or encoded). Snippet='/mgmt/shared/authn/login/~../~../~../~../root/.aws/credentials'
More (full fields + snapshot) expand
url
/mgmt/shared/authn/login/~../~../~../~../root/.aws/credentials
referer
-
UA
Opera/9.80 (Linux) Presto/2.12.388 Version/12.14
summary
Directory traversal indicator
details
Traversal sequences were present (raw or encoded). Snippet='/mgmt/shared/authn/login/~../~../~../~../root/.aws/credentials'
subnet
78.153.140.0/24
asn
202306 — HOSTGLOBAL.PLUS LTD
geo
United Kingdom, England, City of London
org
HOSTGLOBAL.PLUS LTD
#43 2025-11-16 23:39:07 event 18753991 GET 301 bytes 178
ann cred 10 label cred
Request Auth redirect (301) on auth endpoint
referer
-
UA
Opera/9.80 (Linux) Presto/2.12.388 Version/12.14
Annotation facts
label
cred
rule
cred:auth_redirect
conf
72.00
details
Redirect outcomes can participate in 'success-after-fails' patterns during aggregation.
More (full fields + snapshot) expand
url
/mgmt/shared/authn/login/~../~../~../~../root/.aws/credentials
referer
-
UA
Opera/9.80 (Linux) Presto/2.12.388 Version/12.14
summary
Auth redirect (301) on auth endpoint
details
Redirect outcomes can participate in 'success-after-fails' patterns during aggregation.
subnet
78.153.140.0/24
asn
202306 — HOSTGLOBAL.PLUS LTD
geo
United Kingdom, England, City of London
org
HOSTGLOBAL.PLUS LTD
#44 2025-11-16 23:39:07 event 18753991 GET 301 bytes 178
ann cred 10 label cred
Request Auth request appears to use an automation-oriented user agent
referer
-
UA
Opera/9.80 (Linux) Presto/2.12.388 Version/12.14
Annotation facts
label
cred
rule
cred:scripted_user_agent
conf
70.00
details
Automation-ish UA strings are useful correlates when paired with failures or spraying patterns.
More (full fields + snapshot) expand
url
/mgmt/shared/authn/login/~../~../~../~../root/.aws/credentials
referer
-
UA
Opera/9.80 (Linux) Presto/2.12.388 Version/12.14
summary
Auth request appears to use an automation-oriented user agent
details
Automation-ish UA strings are useful correlates when paired with failures or spraying patterns.
subnet
78.153.140.0/24
asn
202306 — HOSTGLOBAL.PLUS LTD
geo
United Kingdom, England, City of London
org
HOSTGLOBAL.PLUS LTD
#45 2025-11-16 23:39:07 event 18753991 GET 301 bytes 178
ann cred label cred
Request Auth endpoint request observed
referer
-
UA
Opera/9.80 (Linux) Presto/2.12.388 Version/12.14
Annotation facts
label
cred
rule
cred:auth_hit:login
conf
55.00
details
Row-level auth primitive for downstream aggregation (no velocity logic here).
More (full fields + snapshot) expand
url
/mgmt/shared/authn/login/~../~../~../~../root/.aws/credentials
referer
-
UA
Opera/9.80 (Linux) Presto/2.12.388 Version/12.14
summary
Auth endpoint request observed
details
Row-level auth primitive for downstream aggregation (no velocity logic here).
subnet
78.153.140.0/24
asn
202306 — HOSTGLOBAL.PLUS LTD
geo
United Kingdom, England, City of London
org
HOSTGLOBAL.PLUS LTD
#46 2025-11-16 23:39:06 event 18753990 GET 301 bytes 178
ann base label observed
Request event observed
referer
-
UA
Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E; …
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/aws/aws_\x5Cxe7\x5Cxa7\x5Cx98\x5Cxe5\x5Cxaf\x5Cx86_\x5Cxe8\x5Cxa8\x5Cxad\x5Cxe5\x5Cxae\x5Cx9a.php
referer
-
UA
Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E; MS-RTC LM 8; InfoPath.3)
summary
event observed
details
subnet
78.153.140.0/24
asn
202306 — HOSTGLOBAL.PLUS LTD
geo
United Kingdom, England, City of London
org
HOSTGLOBAL.PLUS LTD
#47 2025-11-16 23:39:06 event 18753988 GET 301 bytes 178
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/64.0.3282.168 Safari/537.36 OPR/51.0.2830.40
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/api/aws/\x5Cxe8\x5Cxaa\x5Cx8d\x5Cxe8\x5Cxa8\x5Cxbc\x5Cxe6\x5Cx83\x5Cx85\x5Cxe5\x5Cxa0\x5Cxb1.json
referer
-
UA
Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/64.0.3282.168 Safari/537.36 OPR/51.0.2830.40
summary
event observed
details
subnet
78.153.140.0/24
asn
202306 — HOSTGLOBAL.PLUS LTD
geo
United Kingdom, England, City of London
org
HOSTGLOBAL.PLUS LTD
#48 2025-11-16 23:39:04 event 18753984 GET 301 bytes 178
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.9a1) Gecko/20070308 Minefield/3.0a1
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/aws/\x5Cxe8\x5Cxa8\x5Cxad\x5Cxe5\x5Cxae\x5Cx9a/aws_\x5Cxe8\x5Cxaa\x5Cx8d\x5Cxe8\x5Cxa8\x5Cxbc.php
referer
-
UA
Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.9a1) Gecko/20070308 Minefield/3.0a1
summary
event observed
details
subnet
78.153.140.0/24
asn
202306 — HOSTGLOBAL.PLUS LTD
geo
United Kingdom, England, City of London
org
HOSTGLOBAL.PLUS LTD
#49 2025-11-16 23:39:04 event 18753983 GET 301 bytes 178
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Windows; U; Windows NT 6.0; en-US) AppleWebKit/525.19 (KHTML, like Gecko) Chrome/1.0.154.43 Safari/525.19
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/\x5Cxe8\x5Cxa8\x5Cxad\x5Cxe5\x5Cxae\x5Cx9a/aws_sdk_\x5Cxe8\x5Cxa8\x5Cxad\x5Cxe5\x5Cxae\x5Cx9a.php
referer
-
UA
Mozilla/5.0 (Windows; U; Windows NT 6.0; en-US) AppleWebKit/525.19 (KHTML, like Gecko) Chrome/1.0.154.43 Safari/525.19
summary
event observed
details
subnet
78.153.140.0/24
asn
202306 — HOSTGLOBAL.PLUS LTD
geo
United Kingdom, England, City of London
org
HOSTGLOBAL.PLUS LTD
#50 2025-11-16 23:39:04 event 18753981 GET 301 bytes 178
ann base label observed
Request event observed
referer
-
UA
Opera/9.80 (Windows NT 6.1; Opera Tablet/15165; U; en) Presto/2.8.149 Version/11.1
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/administrator/components/com_ubackapi/aws_lambda_config.json
referer
-
UA
Opera/9.80 (Windows NT 6.1; Opera Tablet/15165; U; en) Presto/2.8.149 Version/11.1
summary
event observed
details
subnet
78.153.140.0/24
asn
202306 — HOSTGLOBAL.PLUS LTD
geo
United Kingdom, England, City of London
org
HOSTGLOBAL.PLUS LTD