DigitalOcean Referral Badge
cloud1
cloud2
cloud3
cloud4
cloud5
cloud6
← Back to IP report

Log Explorer

Fact drill-down for 94.156.64.137
Risk 5 LOW Scope All time All-time facts 51 In-scope 51 Filtered 51 Seen 2024-06-042024-06-04
Active (none) Clear
Faceted filters (facts-based) exact core + snapshot + optional start/end
Annotation facets
HTTP facets
Snapshot facets
Custom time window (optional override)
Provide start/end to scope time explicitly (overrides days). Leave blank for all-time.
Tip: keep windows tight when you need speed, but the default is fact-complete.
Top annotators (facts, in-scope)
Click a pill to apply it as a filter.

Annotated access events

Showing page 1 / 2 — total 51 rows
#1 2024-06-04 20:43:18 event 1512334 POST 301 bytes 169
ann base label observed
Request event observed
/
referer
-
UA
Mozilla/5.0 (iPad; CPU OS 8_4_1 like Mac OS X) AppleWebKit/600.1.4 (KHTML, like Gecko) Version/8.0 Mobile/12H321 Safari/600.1.4nMobileSafari/602.1 CFNetwork/808.1.4 Darwin/16.1.0
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/
referer
-
UA
Mozilla/5.0 (iPad; CPU OS 8_4_1 like Mac OS X) AppleWebKit/600.1.4 (KHTML, like Gecko) Version/8.0 Mobile/12H321 Safari/600.1.4nMobileSafari/602.1 CFNetwork/808.1.4 Darwin/16.1.0
summary
event observed
details
subnet
94.156.64.0/24
asn
208893 — SPARKS COMMUNICATIONS LTD
geo
United Kingdom, England, Poplar
org
Sparks Communications LTD
#2 2024-06-04 20:43:17 event 1512333 GET 301 bytes 169
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (iPad; CPU OS 8_4_1 like Mac OS X) AppleWebKit/600.1.4 (KHTML, like Gecko) Version/8.0 Mobile/12H321 Safari/600.1.4nMobileSafari/602.1 CFNetwork/808.1.4 Darwin/16.1.0
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/.env
referer
-
UA
Mozilla/5.0 (iPad; CPU OS 8_4_1 like Mac OS X) AppleWebKit/600.1.4 (KHTML, like Gecko) Version/8.0 Mobile/12H321 Safari/600.1.4nMobileSafari/602.1 CFNetwork/808.1.4 Darwin/16.1.0
summary
event observed
details
subnet
94.156.64.0/24
asn
208893 — SPARKS COMMUNICATIONS LTD
geo
United Kingdom, England, Poplar
org
Sparks Communications LTD
#3 2024-06-04 20:43:17 event 1512332 POST 301 bytes 169
ann base label observed
Request event observed
/
referer
-
UA
Mozilla/5.0 Windows NT 6.1 WOW64 rv 16.0 Gecko/20100101 Firefox/16.0
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/
referer
-
UA
Mozilla/5.0 Windows NT 6.1 WOW64 rv 16.0 Gecko/20100101 Firefox/16.0
summary
event observed
details
subnet
94.156.64.0/24
asn
208893 — SPARKS COMMUNICATIONS LTD
geo
United Kingdom, England, Poplar
org
Sparks Communications LTD
#4 2024-06-04 20:43:17 event 1512331 GET 301 bytes 169
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 Windows NT 6.1 WOW64 rv 16.0 Gecko/20100101 Firefox/16.0
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/.env
referer
-
UA
Mozilla/5.0 Windows NT 6.1 WOW64 rv 16.0 Gecko/20100101 Firefox/16.0
summary
event observed
details
subnet
94.156.64.0/24
asn
208893 — SPARKS COMMUNICATIONS LTD
geo
United Kingdom, England, Poplar
org
Sparks Communications LTD
#5 2024-06-04 20:43:17 event 1512330 POST 301 bytes 169
ann base label observed
Request event observed
/
referer
-
UA
Mozilla/5.0 (Linux; U; Android 4.4.2; fr-fr; GT-P5210 Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Safari/534.30
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/
referer
-
UA
Mozilla/5.0 (Linux; U; Android 4.4.2; fr-fr; GT-P5210 Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Safari/534.30
summary
event observed
details
subnet
94.156.64.0/24
asn
208893 — SPARKS COMMUNICATIONS LTD
geo
United Kingdom, England, Poplar
org
Sparks Communications LTD
#6 2024-06-04 20:43:17 event 1512333 GET 301 bytes 169
ann sfp 40 label sensitive_file
Request Probe for environment/secret file (.env)
referer
-
UA
Mozilla/5.0 (iPad; CPU OS 8_4_1 like Mac OS X) AppleWebKit/600.1.4 (KHTML, like Gecko) Version/8.0 Mobile/12H321 Safari/600.1.4nMobileSafari/602.1 CFNetwork/808.1.4 Darwin/16.1.0
Annotation facts
label
sensitive_file
rule
sfp:file:env
conf
92.00
details
Request targeted a .env-style file (often contains secrets). Snippet='/.env'
More (full fields + snapshot) expand
url
/.env
referer
-
UA
Mozilla/5.0 (iPad; CPU OS 8_4_1 like Mac OS X) AppleWebKit/600.1.4 (KHTML, like Gecko) Version/8.0 Mobile/12H321 Safari/600.1.4nMobileSafari/602.1 CFNetwork/808.1.4 Darwin/16.1.0
summary
Probe for environment/secret file (.env)
details
Request targeted a .env-style file (often contains secrets). Snippet='/.env'
subnet
94.156.64.0/24
asn
208893 — SPARKS COMMUNICATIONS LTD
geo
United Kingdom, England, Poplar
org
Sparks Communications LTD
#7 2024-06-04 20:43:17 event 1512331 GET 301 bytes 169
ann sfp 40 label sensitive_file
Request Probe for environment/secret file (.env)
referer
-
UA
Mozilla/5.0 Windows NT 6.1 WOW64 rv 16.0 Gecko/20100101 Firefox/16.0
Annotation facts
label
sensitive_file
rule
sfp:file:env
conf
92.00
details
Request targeted a .env-style file (often contains secrets). Snippet='/.env'
More (full fields + snapshot) expand
url
/.env
referer
-
UA
Mozilla/5.0 Windows NT 6.1 WOW64 rv 16.0 Gecko/20100101 Firefox/16.0
summary
Probe for environment/secret file (.env)
details
Request targeted a .env-style file (often contains secrets). Snippet='/.env'
subnet
94.156.64.0/24
asn
208893 — SPARKS COMMUNICATIONS LTD
geo
United Kingdom, England, Poplar
org
Sparks Communications LTD
#8 2024-06-04 20:43:16 event 1512329 GET 301 bytes 169
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Linux; U; Android 4.4.2; fr-fr; GT-P5210 Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Safari/534.30
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/.env
referer
-
UA
Mozilla/5.0 (Linux; U; Android 4.4.2; fr-fr; GT-P5210 Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Safari/534.30
summary
event observed
details
subnet
94.156.64.0/24
asn
208893 — SPARKS COMMUNICATIONS LTD
geo
United Kingdom, England, Poplar
org
Sparks Communications LTD
#9 2024-06-04 20:43:16 event 1512328 POST 301 bytes 169
ann base label observed
Request event observed
/
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; Touch; rv:11.0) like Gecko
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; Touch; rv:11.0) like Gecko
summary
event observed
details
subnet
94.156.64.0/24
asn
208893 — SPARKS COMMUNICATIONS LTD
geo
United Kingdom, England, Poplar
org
Sparks Communications LTD
#10 2024-06-04 20:43:16 event 1512327 GET 301 bytes 169
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; Touch; rv:11.0) like Gecko
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/.env
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; Touch; rv:11.0) like Gecko
summary
event observed
details
subnet
94.156.64.0/24
asn
208893 — SPARKS COMMUNICATIONS LTD
geo
United Kingdom, England, Poplar
org
Sparks Communications LTD
#11 2024-06-04 20:43:16 event 1512329 GET 301 bytes 169
ann sfp 40 label sensitive_file
Request Probe for environment/secret file (.env)
referer
-
UA
Mozilla/5.0 (Linux; U; Android 4.4.2; fr-fr; GT-P5210 Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Safari/534.30
Annotation facts
label
sensitive_file
rule
sfp:file:env
conf
92.00
details
Request targeted a .env-style file (often contains secrets). Snippet='/.env'
More (full fields + snapshot) expand
url
/.env
referer
-
UA
Mozilla/5.0 (Linux; U; Android 4.4.2; fr-fr; GT-P5210 Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Safari/534.30
summary
Probe for environment/secret file (.env)
details
Request targeted a .env-style file (often contains secrets). Snippet='/.env'
subnet
94.156.64.0/24
asn
208893 — SPARKS COMMUNICATIONS LTD
geo
United Kingdom, England, Poplar
org
Sparks Communications LTD
#12 2024-06-04 20:43:16 event 1512327 GET 301 bytes 169
ann sfp 40 label sensitive_file
Request Probe for environment/secret file (.env)
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; Touch; rv:11.0) like Gecko
Annotation facts
label
sensitive_file
rule
sfp:file:env
conf
92.00
details
Request targeted a .env-style file (often contains secrets). Snippet='/.env'
More (full fields + snapshot) expand
url
/.env
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; Touch; rv:11.0) like Gecko
summary
Probe for environment/secret file (.env)
details
Request targeted a .env-style file (often contains secrets). Snippet='/.env'
subnet
94.156.64.0/24
asn
208893 — SPARKS COMMUNICATIONS LTD
geo
United Kingdom, England, Poplar
org
Sparks Communications LTD
#13 2024-06-04 20:43:15 event 1512326 POST 301 bytes 169
ann base label observed
Request event observed
/
referer
-
UA
Mozilla/5.0 (Linux; U; Android 4.1.2; fr-fr; GT-N8010 Build/JZO54K) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Safari/534.30
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/
referer
-
UA
Mozilla/5.0 (Linux; U; Android 4.1.2; fr-fr; GT-N8010 Build/JZO54K) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Safari/534.30
summary
event observed
details
subnet
94.156.64.0/24
asn
208893 — SPARKS COMMUNICATIONS LTD
geo
United Kingdom, England, Poplar
org
Sparks Communications LTD
#14 2024-06-04 20:43:15 event 1512325 GET 301 bytes 169
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Linux; U; Android 4.1.2; fr-fr; GT-N8010 Build/JZO54K) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Safari/534.30
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/.env
referer
-
UA
Mozilla/5.0 (Linux; U; Android 4.1.2; fr-fr; GT-N8010 Build/JZO54K) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Safari/534.30
summary
event observed
details
subnet
94.156.64.0/24
asn
208893 — SPARKS COMMUNICATIONS LTD
geo
United Kingdom, England, Poplar
org
Sparks Communications LTD
#15 2024-06-04 20:43:15 event 1512324 POST 301 bytes 169
ann base label observed
Request event observed
/
referer
-
UA
Mozilla/5.0 (iPhone; CPU iPhone OS 7_0 like Mac OS X) AppleWebKit/537.51.1 (KHTML, like Gecko) Version/7.0 Mobile/11A465 Safari/9537.53 (compatible; bingbot/2.0; +http://www.bing.…
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/
referer
-
UA
Mozilla/5.0 (iPhone; CPU iPhone OS 7_0 like Mac OS X) AppleWebKit/537.51.1 (KHTML, like Gecko) Version/7.0 Mobile/11A465 Safari/9537.53 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)
summary
event observed
details
subnet
94.156.64.0/24
asn
208893 — SPARKS COMMUNICATIONS LTD
geo
United Kingdom, England, Poplar
org
Sparks Communications LTD
#16 2024-06-04 20:43:15 event 1512325 GET 301 bytes 169
ann sfp 40 label sensitive_file
Request Probe for environment/secret file (.env)
referer
-
UA
Mozilla/5.0 (Linux; U; Android 4.1.2; fr-fr; GT-N8010 Build/JZO54K) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Safari/534.30
Annotation facts
label
sensitive_file
rule
sfp:file:env
conf
92.00
details
Request targeted a .env-style file (often contains secrets). Snippet='/.env'
More (full fields + snapshot) expand
url
/.env
referer
-
UA
Mozilla/5.0 (Linux; U; Android 4.1.2; fr-fr; GT-N8010 Build/JZO54K) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Safari/534.30
summary
Probe for environment/secret file (.env)
details
Request targeted a .env-style file (often contains secrets). Snippet='/.env'
subnet
94.156.64.0/24
asn
208893 — SPARKS COMMUNICATIONS LTD
geo
United Kingdom, England, Poplar
org
Sparks Communications LTD
#17 2024-06-04 20:43:15 event 1512324 POST 301 bytes 169
ann bot 10 label bot
Request Bot user-agent detected: Bingbot
/
referer
-
UA
Mozilla/5.0 (iPhone; CPU iPhone OS 7_0 like Mac OS X) AppleWebKit/537.51.1 (KHTML, like Gecko) Version/7.0 Mobile/11A465 Safari/9537.53 (compatible; bingbot/2.0; +http://www.bing.…
Annotation facts
label
bot
rule
bot:bingbot
conf
95.00
details
Matched bot signature (explicit). Token='Bingbot'. UA='Mozilla/5.0 (iPhone; CPU iPhone OS 7_0 like Mac OS X) AppleWebKit/537.51.1 (KHTML, like Gecko) Version/7.0 Mobile/11A465 Safari/9537.53 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)'
More (full fields + snapshot) expand
url
/
referer
-
UA
Mozilla/5.0 (iPhone; CPU iPhone OS 7_0 like Mac OS X) AppleWebKit/537.51.1 (KHTML, like Gecko) Version/7.0 Mobile/11A465 Safari/9537.53 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)
summary
Bot user-agent detected: Bingbot
details
Matched bot signature (explicit). Token='Bingbot'. UA='Mozilla/5.0 (iPhone; CPU iPhone OS 7_0 like Mac OS X) AppleWebKit/537.51.1 (KHTML, like Gecko) Version/7.0 Mobile/11A465 Safari/9537.53 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)'
subnet
94.156.64.0/24
asn
208893 — SPARKS COMMUNICATIONS LTD
geo
United Kingdom, England, Poplar
org
Sparks Communications LTD
#18 2024-06-04 20:43:14 event 1512323 GET 301 bytes 169
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (iPhone; CPU iPhone OS 7_0 like Mac OS X) AppleWebKit/537.51.1 (KHTML, like Gecko) Version/7.0 Mobile/11A465 Safari/9537.53 (compatible; bingbot/2.0; +http://www.bing.…
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/.env
referer
-
UA
Mozilla/5.0 (iPhone; CPU iPhone OS 7_0 like Mac OS X) AppleWebKit/537.51.1 (KHTML, like Gecko) Version/7.0 Mobile/11A465 Safari/9537.53 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)
summary
event observed
details
subnet
94.156.64.0/24
asn
208893 — SPARKS COMMUNICATIONS LTD
geo
United Kingdom, England, Poplar
org
Sparks Communications LTD
#19 2024-06-04 20:43:14 event 1512322 POST 301 bytes 169
ann base label observed
Request event observed
/
referer
-
UA
Mozilla/5.0 (Windows NT 6.3; WOW64; Trident/7.0; ASU2JS; rv:11.0) like Gecko
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/
referer
-
UA
Mozilla/5.0 (Windows NT 6.3; WOW64; Trident/7.0; ASU2JS; rv:11.0) like Gecko
summary
event observed
details
subnet
94.156.64.0/24
asn
208893 — SPARKS COMMUNICATIONS LTD
geo
United Kingdom, England, Poplar
org
Sparks Communications LTD
#20 2024-06-04 20:43:14 event 1512321 GET 301 bytes 169
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Windows NT 6.3; WOW64; Trident/7.0; ASU2JS; rv:11.0) like Gecko
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/.env
referer
-
UA
Mozilla/5.0 (Windows NT 6.3; WOW64; Trident/7.0; ASU2JS; rv:11.0) like Gecko
summary
event observed
details
subnet
94.156.64.0/24
asn
208893 — SPARKS COMMUNICATIONS LTD
geo
United Kingdom, England, Poplar
org
Sparks Communications LTD
#21 2024-06-04 20:43:14 event 1512323 GET 301 bytes 169
ann sfp 40 label sensitive_file
Request Probe for environment/secret file (.env)
referer
-
UA
Mozilla/5.0 (iPhone; CPU iPhone OS 7_0 like Mac OS X) AppleWebKit/537.51.1 (KHTML, like Gecko) Version/7.0 Mobile/11A465 Safari/9537.53 (compatible; bingbot/2.0; +http://www.bing.…
Annotation facts
label
sensitive_file
rule
sfp:file:env
conf
92.00
details
Request targeted a .env-style file (often contains secrets). Snippet='/.env'
More (full fields + snapshot) expand
url
/.env
referer
-
UA
Mozilla/5.0 (iPhone; CPU iPhone OS 7_0 like Mac OS X) AppleWebKit/537.51.1 (KHTML, like Gecko) Version/7.0 Mobile/11A465 Safari/9537.53 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)
summary
Probe for environment/secret file (.env)
details
Request targeted a .env-style file (often contains secrets). Snippet='/.env'
subnet
94.156.64.0/24
asn
208893 — SPARKS COMMUNICATIONS LTD
geo
United Kingdom, England, Poplar
org
Sparks Communications LTD
#22 2024-06-04 20:43:14 event 1512321 GET 301 bytes 169
ann sfp 40 label sensitive_file
Request Probe for environment/secret file (.env)
referer
-
UA
Mozilla/5.0 (Windows NT 6.3; WOW64; Trident/7.0; ASU2JS; rv:11.0) like Gecko
Annotation facts
label
sensitive_file
rule
sfp:file:env
conf
92.00
details
Request targeted a .env-style file (often contains secrets). Snippet='/.env'
More (full fields + snapshot) expand
url
/.env
referer
-
UA
Mozilla/5.0 (Windows NT 6.3; WOW64; Trident/7.0; ASU2JS; rv:11.0) like Gecko
summary
Probe for environment/secret file (.env)
details
Request targeted a .env-style file (often contains secrets). Snippet='/.env'
subnet
94.156.64.0/24
asn
208893 — SPARKS COMMUNICATIONS LTD
geo
United Kingdom, England, Poplar
org
Sparks Communications LTD
#23 2024-06-04 20:43:14 event 1512323 GET 301 bytes 169
ann bot 10 label bot
Request Bot user-agent detected: Bingbot
referer
-
UA
Mozilla/5.0 (iPhone; CPU iPhone OS 7_0 like Mac OS X) AppleWebKit/537.51.1 (KHTML, like Gecko) Version/7.0 Mobile/11A465 Safari/9537.53 (compatible; bingbot/2.0; +http://www.bing.…
Annotation facts
label
bot
rule
bot:bingbot
conf
95.00
details
Matched bot signature (explicit). Token='Bingbot'. UA='Mozilla/5.0 (iPhone; CPU iPhone OS 7_0 like Mac OS X) AppleWebKit/537.51.1 (KHTML, like Gecko) Version/7.0 Mobile/11A465 Safari/9537.53 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)'
More (full fields + snapshot) expand
url
/.env
referer
-
UA
Mozilla/5.0 (iPhone; CPU iPhone OS 7_0 like Mac OS X) AppleWebKit/537.51.1 (KHTML, like Gecko) Version/7.0 Mobile/11A465 Safari/9537.53 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)
summary
Bot user-agent detected: Bingbot
details
Matched bot signature (explicit). Token='Bingbot'. UA='Mozilla/5.0 (iPhone; CPU iPhone OS 7_0 like Mac OS X) AppleWebKit/537.51.1 (KHTML, like Gecko) Version/7.0 Mobile/11A465 Safari/9537.53 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)'
subnet
94.156.64.0/24
asn
208893 — SPARKS COMMUNICATIONS LTD
geo
United Kingdom, England, Poplar
org
Sparks Communications LTD
#24 2024-06-04 20:43:13 event 1512320 POST 301 bytes 169
ann base label observed
Request event observed
/
referer
-
UA
Mozilla/5.0 (iPhone; CPU iPhone OS 10_2_1 like Mac OS X) AppleWebKit/600.1.4 (KHTML, like Gecko) GSA/22.0.141836113 Mobile/14D27 Safari/600.1.4
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/
referer
-
UA
Mozilla/5.0 (iPhone; CPU iPhone OS 10_2_1 like Mac OS X) AppleWebKit/600.1.4 (KHTML, like Gecko) GSA/22.0.141836113 Mobile/14D27 Safari/600.1.4
summary
event observed
details
subnet
94.156.64.0/24
asn
208893 — SPARKS COMMUNICATIONS LTD
geo
United Kingdom, England, Poplar
org
Sparks Communications LTD
#25 2024-06-04 20:43:13 event 1512319 GET 301 bytes 169
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (iPhone; CPU iPhone OS 10_2_1 like Mac OS X) AppleWebKit/600.1.4 (KHTML, like Gecko) GSA/22.0.141836113 Mobile/14D27 Safari/600.1.4
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/.env
referer
-
UA
Mozilla/5.0 (iPhone; CPU iPhone OS 10_2_1 like Mac OS X) AppleWebKit/600.1.4 (KHTML, like Gecko) GSA/22.0.141836113 Mobile/14D27 Safari/600.1.4
summary
event observed
details
subnet
94.156.64.0/24
asn
208893 — SPARKS COMMUNICATIONS LTD
geo
United Kingdom, England, Poplar
org
Sparks Communications LTD
#26 2024-06-04 20:43:13 event 1512318 POST 301 bytes 169
ann base label observed
Request event observed
/
referer
-
UA
Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:14.0) Gecko/20100101 Firefox/14.0.1
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/
referer
-
UA
Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:14.0) Gecko/20100101 Firefox/14.0.1
summary
event observed
details
subnet
94.156.64.0/24
asn
208893 — SPARKS COMMUNICATIONS LTD
geo
United Kingdom, England, Poplar
org
Sparks Communications LTD
#27 2024-06-04 20:43:13 event 1512319 GET 301 bytes 169
ann sfp 40 label sensitive_file
Request Probe for environment/secret file (.env)
referer
-
UA
Mozilla/5.0 (iPhone; CPU iPhone OS 10_2_1 like Mac OS X) AppleWebKit/600.1.4 (KHTML, like Gecko) GSA/22.0.141836113 Mobile/14D27 Safari/600.1.4
Annotation facts
label
sensitive_file
rule
sfp:file:env
conf
92.00
details
Request targeted a .env-style file (often contains secrets). Snippet='/.env'
More (full fields + snapshot) expand
url
/.env
referer
-
UA
Mozilla/5.0 (iPhone; CPU iPhone OS 10_2_1 like Mac OS X) AppleWebKit/600.1.4 (KHTML, like Gecko) GSA/22.0.141836113 Mobile/14D27 Safari/600.1.4
summary
Probe for environment/secret file (.env)
details
Request targeted a .env-style file (often contains secrets). Snippet='/.env'
subnet
94.156.64.0/24
asn
208893 — SPARKS COMMUNICATIONS LTD
geo
United Kingdom, England, Poplar
org
Sparks Communications LTD
#28 2024-06-04 20:43:12 event 1512317 GET 301 bytes 169
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:14.0) Gecko/20100101 Firefox/14.0.1
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/.env
referer
-
UA
Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:14.0) Gecko/20100101 Firefox/14.0.1
summary
event observed
details
subnet
94.156.64.0/24
asn
208893 — SPARKS COMMUNICATIONS LTD
geo
United Kingdom, England, Poplar
org
Sparks Communications LTD
#29 2024-06-04 20:43:12 event 1512316 POST 301 bytes 169
ann base label observed
Request event observed
/
referer
-
UA
Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36 (Nonlibot/1.0; https://www.nonli.com)
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/
referer
-
UA
Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36 (Nonlibot/1.0; https://www.nonli.com)
summary
event observed
details
subnet
94.156.64.0/24
asn
208893 — SPARKS COMMUNICATIONS LTD
geo
United Kingdom, England, Poplar
org
Sparks Communications LTD
#30 2024-06-04 20:43:12 event 1512315 GET 301 bytes 169
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36 (Nonlibot/1.0; https://www.nonli.com)
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/.env
referer
-
UA
Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36 (Nonlibot/1.0; https://www.nonli.com)
summary
event observed
details
subnet
94.156.64.0/24
asn
208893 — SPARKS COMMUNICATIONS LTD
geo
United Kingdom, England, Poplar
org
Sparks Communications LTD
#31 2024-06-04 20:43:12 event 1512317 GET 301 bytes 169
ann sfp 40 label sensitive_file
Request Probe for environment/secret file (.env)
referer
-
UA
Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:14.0) Gecko/20100101 Firefox/14.0.1
Annotation facts
label
sensitive_file
rule
sfp:file:env
conf
92.00
details
Request targeted a .env-style file (often contains secrets). Snippet='/.env'
More (full fields + snapshot) expand
url
/.env
referer
-
UA
Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:14.0) Gecko/20100101 Firefox/14.0.1
summary
Probe for environment/secret file (.env)
details
Request targeted a .env-style file (often contains secrets). Snippet='/.env'
subnet
94.156.64.0/24
asn
208893 — SPARKS COMMUNICATIONS LTD
geo
United Kingdom, England, Poplar
org
Sparks Communications LTD
#32 2024-06-04 20:43:12 event 1512315 GET 301 bytes 169
ann sfp 40 label sensitive_file
Request Probe for environment/secret file (.env)
referer
-
UA
Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36 (Nonlibot/1.0; https://www.nonli.com)
Annotation facts
label
sensitive_file
rule
sfp:file:env
conf
92.00
details
Request targeted a .env-style file (often contains secrets). Snippet='/.env'
More (full fields + snapshot) expand
url
/.env
referer
-
UA
Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36 (Nonlibot/1.0; https://www.nonli.com)
summary
Probe for environment/secret file (.env)
details
Request targeted a .env-style file (often contains secrets). Snippet='/.env'
subnet
94.156.64.0/24
asn
208893 — SPARKS COMMUNICATIONS LTD
geo
United Kingdom, England, Poplar
org
Sparks Communications LTD
#33 2024-06-04 20:43:11 event 1512314 POST 301 bytes 169
ann base label observed
Request event observed
/
referer
-
UA
Mozilla/5.0 (Linux; Android 5.1.1; SM-J320FN Build/LMY47V) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.91 Mobile Safari/537.36
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/
referer
-
UA
Mozilla/5.0 (Linux; Android 5.1.1; SM-J320FN Build/LMY47V) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.91 Mobile Safari/537.36
summary
event observed
details
subnet
94.156.64.0/24
asn
208893 — SPARKS COMMUNICATIONS LTD
geo
United Kingdom, England, Poplar
org
Sparks Communications LTD
#34 2024-06-04 20:43:11 event 1512313 GET 301 bytes 169
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Linux; Android 5.1.1; SM-J320FN Build/LMY47V) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.91 Mobile Safari/537.36
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/.env
referer
-
UA
Mozilla/5.0 (Linux; Android 5.1.1; SM-J320FN Build/LMY47V) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.91 Mobile Safari/537.36
summary
event observed
details
subnet
94.156.64.0/24
asn
208893 — SPARKS COMMUNICATIONS LTD
geo
United Kingdom, England, Poplar
org
Sparks Communications LTD
#35 2024-06-04 20:43:11 event 1512312 POST 301 bytes 169
ann base label observed
Request event observed
/
referer
-
UA
Mozilla/5.0 (Windows NT 5.1; rv:31.0) Gecko/20100101 Firefox/31.0
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/
referer
-
UA
Mozilla/5.0 (Windows NT 5.1; rv:31.0) Gecko/20100101 Firefox/31.0
summary
event observed
details
subnet
94.156.64.0/24
asn
208893 — SPARKS COMMUNICATIONS LTD
geo
United Kingdom, England, Poplar
org
Sparks Communications LTD
#36 2024-06-04 20:43:11 event 1512311 GET 301 bytes 169
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Windows NT 5.1; rv:31.0) Gecko/20100101 Firefox/31.0
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/.env
referer
-
UA
Mozilla/5.0 (Windows NT 5.1; rv:31.0) Gecko/20100101 Firefox/31.0
summary
event observed
details
subnet
94.156.64.0/24
asn
208893 — SPARKS COMMUNICATIONS LTD
geo
United Kingdom, England, Poplar
org
Sparks Communications LTD
#37 2024-06-04 20:43:11 event 1512313 GET 301 bytes 169
ann sfp 40 label sensitive_file
Request Probe for environment/secret file (.env)
referer
-
UA
Mozilla/5.0 (Linux; Android 5.1.1; SM-J320FN Build/LMY47V) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.91 Mobile Safari/537.36
Annotation facts
label
sensitive_file
rule
sfp:file:env
conf
92.00
details
Request targeted a .env-style file (often contains secrets). Snippet='/.env'
More (full fields + snapshot) expand
url
/.env
referer
-
UA
Mozilla/5.0 (Linux; Android 5.1.1; SM-J320FN Build/LMY47V) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.91 Mobile Safari/537.36
summary
Probe for environment/secret file (.env)
details
Request targeted a .env-style file (often contains secrets). Snippet='/.env'
subnet
94.156.64.0/24
asn
208893 — SPARKS COMMUNICATIONS LTD
geo
United Kingdom, England, Poplar
org
Sparks Communications LTD
#38 2024-06-04 20:43:11 event 1512311 GET 301 bytes 169
ann sfp 40 label sensitive_file
Request Probe for environment/secret file (.env)
referer
-
UA
Mozilla/5.0 (Windows NT 5.1; rv:31.0) Gecko/20100101 Firefox/31.0
Annotation facts
label
sensitive_file
rule
sfp:file:env
conf
92.00
details
Request targeted a .env-style file (often contains secrets). Snippet='/.env'
More (full fields + snapshot) expand
url
/.env
referer
-
UA
Mozilla/5.0 (Windows NT 5.1; rv:31.0) Gecko/20100101 Firefox/31.0
summary
Probe for environment/secret file (.env)
details
Request targeted a .env-style file (often contains secrets). Snippet='/.env'
subnet
94.156.64.0/24
asn
208893 — SPARKS COMMUNICATIONS LTD
geo
United Kingdom, England, Poplar
org
Sparks Communications LTD
#39 2024-06-04 20:43:10 event 1512310 POST 301 bytes 169
ann base label observed
Request event observed
/
referer
-
UA
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:49.0) Gecko/20100101 Firefox/49.0
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/
referer
-
UA
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:49.0) Gecko/20100101 Firefox/49.0
summary
event observed
details
subnet
94.156.64.0/24
asn
208893 — SPARKS COMMUNICATIONS LTD
geo
United Kingdom, England, Poplar
org
Sparks Communications LTD
#40 2024-06-04 20:43:10 event 1512309 GET 301 bytes 169
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:49.0) Gecko/20100101 Firefox/49.0
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/.env
referer
-
UA
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:49.0) Gecko/20100101 Firefox/49.0
summary
event observed
details
subnet
94.156.64.0/24
asn
208893 — SPARKS COMMUNICATIONS LTD
geo
United Kingdom, England, Poplar
org
Sparks Communications LTD
#41 2024-06-04 20:43:10 event 1512308 POST 301 bytes 169
ann base label observed
Request event observed
/
referer
-
UA
Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:45.0) Gecko/20100101 Firefox/45.0
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/
referer
-
UA
Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:45.0) Gecko/20100101 Firefox/45.0
summary
event observed
details
subnet
94.156.64.0/24
asn
208893 — SPARKS COMMUNICATIONS LTD
geo
United Kingdom, England, Poplar
org
Sparks Communications LTD
#42 2024-06-04 20:43:10 event 1512309 GET 301 bytes 169
ann sfp 40 label sensitive_file
Request Probe for environment/secret file (.env)
referer
-
UA
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:49.0) Gecko/20100101 Firefox/49.0
Annotation facts
label
sensitive_file
rule
sfp:file:env
conf
92.00
details
Request targeted a .env-style file (often contains secrets). Snippet='/.env'
More (full fields + snapshot) expand
url
/.env
referer
-
UA
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:49.0) Gecko/20100101 Firefox/49.0
summary
Probe for environment/secret file (.env)
details
Request targeted a .env-style file (often contains secrets). Snippet='/.env'
subnet
94.156.64.0/24
asn
208893 — SPARKS COMMUNICATIONS LTD
geo
United Kingdom, England, Poplar
org
Sparks Communications LTD
#43 2024-06-04 20:43:09 event 1512306 POST 301 bytes 169
ann ua 12 label ua
Request Unusually long User-Agent string
/
referer
-
UA
Mozilla/5.0 (Linux; Android 5.1.1; SM-J320FN Build/LMY47V) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.91 Mobile Safari/537.36Mozilla/5.0 (X11; Ubuntu; Linux x86_64; r…
Annotation facts
label
ua
rule
ua:excessive_length
conf
70.00
details
Very long UAs can be obfuscation/randomization or buggy clients.
More (full fields + snapshot) expand
url
/
referer
-
UA
Mozilla/5.0 (Linux; Android 5.1.1; SM-J320FN Build/LMY47V) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.91 Mobile Safari/537.36Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:14.0) Gecko/20100101 Firefox/14.0.1Mozilla/5.0 (iPhone; CPU iPhone OS 10_2_1 like Mac OS X) AppleWebKit/600.1.4 (KHTML, like Gecko) GSA/22.0.141836113 Mobile/14D27 Safari/600.1.4Mozilla/5.0 (Windows NT 6.3; WOW64; Trident/7.0; ASU2JS; rv:11.0) like GeckoMozilla/5.0 (iPhone; CPU iPhone OS 7_0 like Mac OS X) AppleWebKit/537.51.1 (KHTML, like Gecko) Version/7.0 Mobile/11A465 Safari/9537.53 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)Mozilla/5.0 (Linux; U; Android 4.1.2; fr-fr; GT-N8010 Build/JZO54K) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Safari/534.30Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; Touch; rv:11.0) like GeckoMozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)Mozilla/5.0 (Linux; U; Android 4.4.2; fr-fr; GT-P5210 Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Safari/534.30Mozilla/5.0 Windows NT 6.1 WOW64 rv 16.0 Gecko/20100101 Firefox/16.0Mozilla/5.0 (iPad; CPU OS 8_4_1 like Mac OS X) AppleWebKit/600.1.4 (KHTML, like Gecko) Version/8.0 Mobile/12H321 Safari/600.1.4MobileSafari/602.1 CFNetwork/808.1.4 Darwin/16.1.0Mozilla/5.0 (Windows NT 5.1; rv:51.0) Gecko/20100101 Firefox/51.0Mozilla/5.0 (Windows NT 6.3; Trident/7.0; Touch; SMJB; rv:11.0) like GeckoMozilla/5.0 (Macintosh; Intel Mac OS X 10_10_5) AppleWebKit/602.4.8 (KHTML, like Gecko) Version/10.0.3 Safari/602.4.8Mozilla/5.0 (iPhone; CPU iPhone OS 9_3_2 like Mac OS X) AppleWebKit/601.1.46 (KHTML, like Gecko) Version/9.0 Mobile/13F69 Safari/601.1Mozilla/5.0 (iPhone; CPU iPhone OS 10_2_1 like Mac OS X) AppleWebKit/602.4.6 (KHTML, like Gecko) Mobile/14D27 [FBAN/FBIOS;FBAV/78.0.0.40.70;FBBV/48784289;FBRV/0;FBDV/iPhone7,2;FBMD/iPhone;FBSN/iOS;FBSV/10.2.1;FBSS/2;FBCR/SFR;FBID/phone;FBLC/fr_FR;FBOP/5]Mozilla/5.0 (iPhone; CPU iPhone OS 10_2_1 like Mac OS X) AppleWebKit/602.4.6 (KHTML, like Gecko) Mobile/14
summary
Unusually long User-Agent string
details
Very long UAs can be obfuscation/randomization or buggy clients.
subnet
94.156.64.0/24
asn
208893 — SPARKS COMMUNICATIONS LTD
geo
United Kingdom, England, Poplar
org
Sparks Communications LTD
#44 2024-06-04 20:43:09 event 1512305 GET 301 bytes 169
ann ua 12 label ua
Request Unusually long User-Agent string
referer
-
UA
Mozilla/5.0 (Linux; Android 5.1.1; SM-J320FN Build/LMY47V) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.91 Mobile Safari/537.36Mozilla/5.0 (X11; Ubuntu; Linux x86_64; r…
Annotation facts
label
ua
rule
ua:excessive_length
conf
70.00
details
Very long UAs can be obfuscation/randomization or buggy clients.
More (full fields + snapshot) expand
url
/.env
referer
-
UA
Mozilla/5.0 (Linux; Android 5.1.1; SM-J320FN Build/LMY47V) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.91 Mobile Safari/537.36Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:14.0) Gecko/20100101 Firefox/14.0.1Mozilla/5.0 (iPhone; CPU iPhone OS 10_2_1 like Mac OS X) AppleWebKit/600.1.4 (KHTML, like Gecko) GSA/22.0.141836113 Mobile/14D27 Safari/600.1.4Mozilla/5.0 (Windows NT 6.3; WOW64; Trident/7.0; ASU2JS; rv:11.0) like GeckoMozilla/5.0 (iPhone; CPU iPhone OS 7_0 like Mac OS X) AppleWebKit/537.51.1 (KHTML, like Gecko) Version/7.0 Mobile/11A465 Safari/9537.53 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)Mozilla/5.0 (Linux; U; Android 4.1.2; fr-fr; GT-N8010 Build/JZO54K) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Safari/534.30Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; Touch; rv:11.0) like GeckoMozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)Mozilla/5.0 (Linux; U; Android 4.4.2; fr-fr; GT-P5210 Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Safari/534.30Mozilla/5.0 Windows NT 6.1 WOW64 rv 16.0 Gecko/20100101 Firefox/16.0Mozilla/5.0 (iPad; CPU OS 8_4_1 like Mac OS X) AppleWebKit/600.1.4 (KHTML, like Gecko) Version/8.0 Mobile/12H321 Safari/600.1.4MobileSafari/602.1 CFNetwork/808.1.4 Darwin/16.1.0Mozilla/5.0 (Windows NT 5.1; rv:51.0) Gecko/20100101 Firefox/51.0Mozilla/5.0 (Windows NT 6.3; Trident/7.0; Touch; SMJB; rv:11.0) like GeckoMozilla/5.0 (Macintosh; Intel Mac OS X 10_10_5) AppleWebKit/602.4.8 (KHTML, like Gecko) Version/10.0.3 Safari/602.4.8Mozilla/5.0 (iPhone; CPU iPhone OS 9_3_2 like Mac OS X) AppleWebKit/601.1.46 (KHTML, like Gecko) Version/9.0 Mobile/13F69 Safari/601.1Mozilla/5.0 (iPhone; CPU iPhone OS 10_2_1 like Mac OS X) AppleWebKit/602.4.6 (KHTML, like Gecko) Mobile/14D27 [FBAN/FBIOS;FBAV/78.0.0.40.70;FBBV/48784289;FBRV/0;FBDV/iPhone7,2;FBMD/iPhone;FBSN/iOS;FBSV/10.2.1;FBSS/2;FBCR/SFR;FBID/phone;FBLC/fr_FR;FBOP/5]Mozilla/5.0 (iPhone; CPU iPhone OS 10_2_1 like Mac OS X) AppleWebKit/602.4.6 (KHTML, like Gecko) Mobile/14
summary
Unusually long User-Agent string
details
Very long UAs can be obfuscation/randomization or buggy clients.
subnet
94.156.64.0/24
asn
208893 — SPARKS COMMUNICATIONS LTD
geo
United Kingdom, England, Poplar
org
Sparks Communications LTD
#45 2024-06-04 20:43:09 event 1512307 GET 301 bytes 169
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:45.0) Gecko/20100101 Firefox/45.0
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/.env
referer
-
UA
Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:45.0) Gecko/20100101 Firefox/45.0
summary
event observed
details
subnet
94.156.64.0/24
asn
208893 — SPARKS COMMUNICATIONS LTD
geo
United Kingdom, England, Poplar
org
Sparks Communications LTD
#46 2024-06-04 20:43:09 event 1512306 POST 301 bytes 169
ann base label observed
Request event observed
/
referer
-
UA
Mozilla/5.0 (Linux; Android 5.1.1; SM-J320FN Build/LMY47V) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.91 Mobile Safari/537.36Mozilla/5.0 (X11; Ubuntu; Linux x86_64; r…
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/
referer
-
UA
Mozilla/5.0 (Linux; Android 5.1.1; SM-J320FN Build/LMY47V) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.91 Mobile Safari/537.36Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:14.0) Gecko/20100101 Firefox/14.0.1Mozilla/5.0 (iPhone; CPU iPhone OS 10_2_1 like Mac OS X) AppleWebKit/600.1.4 (KHTML, like Gecko) GSA/22.0.141836113 Mobile/14D27 Safari/600.1.4Mozilla/5.0 (Windows NT 6.3; WOW64; Trident/7.0; ASU2JS; rv:11.0) like GeckoMozilla/5.0 (iPhone; CPU iPhone OS 7_0 like Mac OS X) AppleWebKit/537.51.1 (KHTML, like Gecko) Version/7.0 Mobile/11A465 Safari/9537.53 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)Mozilla/5.0 (Linux; U; Android 4.1.2; fr-fr; GT-N8010 Build/JZO54K) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Safari/534.30Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; Touch; rv:11.0) like GeckoMozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)Mozilla/5.0 (Linux; U; Android 4.4.2; fr-fr; GT-P5210 Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Safari/534.30Mozilla/5.0 Windows NT 6.1 WOW64 rv 16.0 Gecko/20100101 Firefox/16.0Mozilla/5.0 (iPad; CPU OS 8_4_1 like Mac OS X) AppleWebKit/600.1.4 (KHTML, like Gecko) Version/8.0 Mobile/12H321 Safari/600.1.4MobileSafari/602.1 CFNetwork/808.1.4 Darwin/16.1.0Mozilla/5.0 (Windows NT 5.1; rv:51.0) Gecko/20100101 Firefox/51.0Mozilla/5.0 (Windows NT 6.3; Trident/7.0; Touch; SMJB; rv:11.0) like GeckoMozilla/5.0 (Macintosh; Intel Mac OS X 10_10_5) AppleWebKit/602.4.8 (KHTML, like Gecko) Version/10.0.3 Safari/602.4.8Mozilla/5.0 (iPhone; CPU iPhone OS 9_3_2 like Mac OS X) AppleWebKit/601.1.46 (KHTML, like Gecko) Version/9.0 Mobile/13F69 Safari/601.1Mozilla/5.0 (iPhone; CPU iPhone OS 10_2_1 like Mac OS X) AppleWebKit/602.4.6 (KHTML, like Gecko) Mobile/14D27 [FBAN/FBIOS;FBAV/78.0.0.40.70;FBBV/48784289;FBRV/0;FBDV/iPhone7,2;FBMD/iPhone;FBSN/iOS;FBSV/10.2.1;FBSS/2;FBCR/SFR;FBID/phone;FBLC/fr_FR;FBOP/5]Mozilla/5.0 (iPhone; CPU iPhone OS 10_2_1 like Mac OS X) AppleWebKit/602.4.6 (KHTML, like Gecko) Mobile/14
summary
event observed
details
subnet
94.156.64.0/24
asn
208893 — SPARKS COMMUNICATIONS LTD
geo
United Kingdom, England, Poplar
org
Sparks Communications LTD
#47 2024-06-04 20:43:09 event 1512305 GET 301 bytes 169
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Linux; Android 5.1.1; SM-J320FN Build/LMY47V) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.91 Mobile Safari/537.36Mozilla/5.0 (X11; Ubuntu; Linux x86_64; r…
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/.env
referer
-
UA
Mozilla/5.0 (Linux; Android 5.1.1; SM-J320FN Build/LMY47V) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.91 Mobile Safari/537.36Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:14.0) Gecko/20100101 Firefox/14.0.1Mozilla/5.0 (iPhone; CPU iPhone OS 10_2_1 like Mac OS X) AppleWebKit/600.1.4 (KHTML, like Gecko) GSA/22.0.141836113 Mobile/14D27 Safari/600.1.4Mozilla/5.0 (Windows NT 6.3; WOW64; Trident/7.0; ASU2JS; rv:11.0) like GeckoMozilla/5.0 (iPhone; CPU iPhone OS 7_0 like Mac OS X) AppleWebKit/537.51.1 (KHTML, like Gecko) Version/7.0 Mobile/11A465 Safari/9537.53 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)Mozilla/5.0 (Linux; U; Android 4.1.2; fr-fr; GT-N8010 Build/JZO54K) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Safari/534.30Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; Touch; rv:11.0) like GeckoMozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)Mozilla/5.0 (Linux; U; Android 4.4.2; fr-fr; GT-P5210 Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Safari/534.30Mozilla/5.0 Windows NT 6.1 WOW64 rv 16.0 Gecko/20100101 Firefox/16.0Mozilla/5.0 (iPad; CPU OS 8_4_1 like Mac OS X) AppleWebKit/600.1.4 (KHTML, like Gecko) Version/8.0 Mobile/12H321 Safari/600.1.4MobileSafari/602.1 CFNetwork/808.1.4 Darwin/16.1.0Mozilla/5.0 (Windows NT 5.1; rv:51.0) Gecko/20100101 Firefox/51.0Mozilla/5.0 (Windows NT 6.3; Trident/7.0; Touch; SMJB; rv:11.0) like GeckoMozilla/5.0 (Macintosh; Intel Mac OS X 10_10_5) AppleWebKit/602.4.8 (KHTML, like Gecko) Version/10.0.3 Safari/602.4.8Mozilla/5.0 (iPhone; CPU iPhone OS 9_3_2 like Mac OS X) AppleWebKit/601.1.46 (KHTML, like Gecko) Version/9.0 Mobile/13F69 Safari/601.1Mozilla/5.0 (iPhone; CPU iPhone OS 10_2_1 like Mac OS X) AppleWebKit/602.4.6 (KHTML, like Gecko) Mobile/14D27 [FBAN/FBIOS;FBAV/78.0.0.40.70;FBBV/48784289;FBRV/0;FBDV/iPhone7,2;FBMD/iPhone;FBSN/iOS;FBSV/10.2.1;FBSS/2;FBCR/SFR;FBID/phone;FBLC/fr_FR;FBOP/5]Mozilla/5.0 (iPhone; CPU iPhone OS 10_2_1 like Mac OS X) AppleWebKit/602.4.6 (KHTML, like Gecko) Mobile/14
summary
event observed
details
subnet
94.156.64.0/24
asn
208893 — SPARKS COMMUNICATIONS LTD
geo
United Kingdom, England, Poplar
org
Sparks Communications LTD
#48 2024-06-04 20:43:09 event 1512307 GET 301 bytes 169
ann sfp 40 label sensitive_file
Request Probe for environment/secret file (.env)
referer
-
UA
Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:45.0) Gecko/20100101 Firefox/45.0
Annotation facts
label
sensitive_file
rule
sfp:file:env
conf
92.00
details
Request targeted a .env-style file (often contains secrets). Snippet='/.env'
More (full fields + snapshot) expand
url
/.env
referer
-
UA
Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:45.0) Gecko/20100101 Firefox/45.0
summary
Probe for environment/secret file (.env)
details
Request targeted a .env-style file (often contains secrets). Snippet='/.env'
subnet
94.156.64.0/24
asn
208893 — SPARKS COMMUNICATIONS LTD
geo
United Kingdom, England, Poplar
org
Sparks Communications LTD
#49 2024-06-04 20:43:09 event 1512305 GET 301 bytes 169
ann sfp 40 label sensitive_file
Request Probe for environment/secret file (.env)
referer
-
UA
Mozilla/5.0 (Linux; Android 5.1.1; SM-J320FN Build/LMY47V) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.91 Mobile Safari/537.36Mozilla/5.0 (X11; Ubuntu; Linux x86_64; r…
Annotation facts
label
sensitive_file
rule
sfp:file:env
conf
92.00
details
Request targeted a .env-style file (often contains secrets). Snippet='/.env'
More (full fields + snapshot) expand
url
/.env
referer
-
UA
Mozilla/5.0 (Linux; Android 5.1.1; SM-J320FN Build/LMY47V) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.91 Mobile Safari/537.36Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:14.0) Gecko/20100101 Firefox/14.0.1Mozilla/5.0 (iPhone; CPU iPhone OS 10_2_1 like Mac OS X) AppleWebKit/600.1.4 (KHTML, like Gecko) GSA/22.0.141836113 Mobile/14D27 Safari/600.1.4Mozilla/5.0 (Windows NT 6.3; WOW64; Trident/7.0; ASU2JS; rv:11.0) like GeckoMozilla/5.0 (iPhone; CPU iPhone OS 7_0 like Mac OS X) AppleWebKit/537.51.1 (KHTML, like Gecko) Version/7.0 Mobile/11A465 Safari/9537.53 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)Mozilla/5.0 (Linux; U; Android 4.1.2; fr-fr; GT-N8010 Build/JZO54K) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Safari/534.30Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; Touch; rv:11.0) like GeckoMozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)Mozilla/5.0 (Linux; U; Android 4.4.2; fr-fr; GT-P5210 Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Safari/534.30Mozilla/5.0 Windows NT 6.1 WOW64 rv 16.0 Gecko/20100101 Firefox/16.0Mozilla/5.0 (iPad; CPU OS 8_4_1 like Mac OS X) AppleWebKit/600.1.4 (KHTML, like Gecko) Version/8.0 Mobile/12H321 Safari/600.1.4MobileSafari/602.1 CFNetwork/808.1.4 Darwin/16.1.0Mozilla/5.0 (Windows NT 5.1; rv:51.0) Gecko/20100101 Firefox/51.0Mozilla/5.0 (Windows NT 6.3; Trident/7.0; Touch; SMJB; rv:11.0) like GeckoMozilla/5.0 (Macintosh; Intel Mac OS X 10_10_5) AppleWebKit/602.4.8 (KHTML, like Gecko) Version/10.0.3 Safari/602.4.8Mozilla/5.0 (iPhone; CPU iPhone OS 9_3_2 like Mac OS X) AppleWebKit/601.1.46 (KHTML, like Gecko) Version/9.0 Mobile/13F69 Safari/601.1Mozilla/5.0 (iPhone; CPU iPhone OS 10_2_1 like Mac OS X) AppleWebKit/602.4.6 (KHTML, like Gecko) Mobile/14D27 [FBAN/FBIOS;FBAV/78.0.0.40.70;FBBV/48784289;FBRV/0;FBDV/iPhone7,2;FBMD/iPhone;FBSN/iOS;FBSV/10.2.1;FBSS/2;FBCR/SFR;FBID/phone;FBLC/fr_FR;FBOP/5]Mozilla/5.0 (iPhone; CPU iPhone OS 10_2_1 like Mac OS X) AppleWebKit/602.4.6 (KHTML, like Gecko) Mobile/14
summary
Probe for environment/secret file (.env)
details
Request targeted a .env-style file (often contains secrets). Snippet='/.env'
subnet
94.156.64.0/24
asn
208893 — SPARKS COMMUNICATIONS LTD
geo
United Kingdom, England, Poplar
org
Sparks Communications LTD
#50 2024-06-04 20:43:09 event 1512306 POST 301 bytes 169
ann bot 10 label bot
Request Bot user-agent detected: Bingbot
/
referer
-
UA
Mozilla/5.0 (Linux; Android 5.1.1; SM-J320FN Build/LMY47V) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.91 Mobile Safari/537.36Mozilla/5.0 (X11; Ubuntu; Linux x86_64; r…
Annotation facts
label
bot
rule
bot:bingbot
conf
95.00
details
Matched bot signature (explicit). Token='Bingbot'. UA='Mozilla/5.0 (Linux; Android 5.1.1; SM-J320FN Build/LMY47V) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.91 Mobile Safari/537.36Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:14.0) Gecko/20100101 Firefox/14.0.1Mozilla/5.0 (iPhone; CPU iPhone OS 10_2_1 like Mac OS X) AppleWebKit/600.1.4 (KHTML, like Gecko) GSA/22.0.141836113 Mobile/14D27 Safari/600.1.4Mozilla/5.0 (Windows NT 6.3; WOW64; Tride…'
More (full fields + snapshot) expand
url
/
referer
-
UA
Mozilla/5.0 (Linux; Android 5.1.1; SM-J320FN Build/LMY47V) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.91 Mobile Safari/537.36Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:14.0) Gecko/20100101 Firefox/14.0.1Mozilla/5.0 (iPhone; CPU iPhone OS 10_2_1 like Mac OS X) AppleWebKit/600.1.4 (KHTML, like Gecko) GSA/22.0.141836113 Mobile/14D27 Safari/600.1.4Mozilla/5.0 (Windows NT 6.3; WOW64; Trident/7.0; ASU2JS; rv:11.0) like GeckoMozilla/5.0 (iPhone; CPU iPhone OS 7_0 like Mac OS X) AppleWebKit/537.51.1 (KHTML, like Gecko) Version/7.0 Mobile/11A465 Safari/9537.53 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)Mozilla/5.0 (Linux; U; Android 4.1.2; fr-fr; GT-N8010 Build/JZO54K) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Safari/534.30Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; Touch; rv:11.0) like GeckoMozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)Mozilla/5.0 (Linux; U; Android 4.4.2; fr-fr; GT-P5210 Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Safari/534.30Mozilla/5.0 Windows NT 6.1 WOW64 rv 16.0 Gecko/20100101 Firefox/16.0Mozilla/5.0 (iPad; CPU OS 8_4_1 like Mac OS X) AppleWebKit/600.1.4 (KHTML, like Gecko) Version/8.0 Mobile/12H321 Safari/600.1.4MobileSafari/602.1 CFNetwork/808.1.4 Darwin/16.1.0Mozilla/5.0 (Windows NT 5.1; rv:51.0) Gecko/20100101 Firefox/51.0Mozilla/5.0 (Windows NT 6.3; Trident/7.0; Touch; SMJB; rv:11.0) like GeckoMozilla/5.0 (Macintosh; Intel Mac OS X 10_10_5) AppleWebKit/602.4.8 (KHTML, like Gecko) Version/10.0.3 Safari/602.4.8Mozilla/5.0 (iPhone; CPU iPhone OS 9_3_2 like Mac OS X) AppleWebKit/601.1.46 (KHTML, like Gecko) Version/9.0 Mobile/13F69 Safari/601.1Mozilla/5.0 (iPhone; CPU iPhone OS 10_2_1 like Mac OS X) AppleWebKit/602.4.6 (KHTML, like Gecko) Mobile/14D27 [FBAN/FBIOS;FBAV/78.0.0.40.70;FBBV/48784289;FBRV/0;FBDV/iPhone7,2;FBMD/iPhone;FBSN/iOS;FBSV/10.2.1;FBSS/2;FBCR/SFR;FBID/phone;FBLC/fr_FR;FBOP/5]Mozilla/5.0 (iPhone; CPU iPhone OS 10_2_1 like Mac OS X) AppleWebKit/602.4.6 (KHTML, like Gecko) Mobile/14
summary
Bot user-agent detected: Bingbot
details
Matched bot signature (explicit). Token='Bingbot'. UA='Mozilla/5.0 (Linux; Android 5.1.1; SM-J320FN Build/LMY47V) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.91 Mobile Safari/537.36Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:14.0) Gecko/20100101 Firefox/14.0.1Mozilla/5.0 (iPhone; CPU iPhone OS 10_2_1 like Mac OS X) AppleWebKit/600.1.4 (KHTML, like Gecko) GSA/22.0.141836113 Mobile/14D27 Safari/600.1.4Mozilla/5.0 (Windows NT 6.3; WOW64; Tride…'
subnet
94.156.64.0/24
asn
208893 — SPARKS COMMUNICATIONS LTD
geo
United Kingdom, England, Poplar
org
Sparks Communications LTD