This IP address has been reported a total of
14
times from
13 distinct
sources.
136.117.93.74 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
686 requests, including :
GET /proxy?url=file%3A%2F%2F%2Froot%2F.azure%2FaccessTokens.json HTTP/1.1 ...
show more686 requests, including :
GET /proxy?url=file%3A%2F%2F%2Froot%2F.azure%2FaccessTokens.json HTTP/1.1
GET /proxy?url=file%3A%2F%2F%2Fapp%2F.env HTTP/1.1
GET /.well-known/credentials.json HTTP/1.1
GET /google-cloud-key.json HTTP/1.1
GET /kubernetes.yml HTTP/1.1
GET /.env.local HTTP/1.1
GET /terraform.tfstate HTTP/1.1
GET /logs/app.log HTTP/1.1
GET /firebase-admin.json HTTP/1.1
GET /.continue/config.json HTTP/1.1
GET /k8s/eks/credentials HTTP/1.1
GET /api/account HTTP/1.1
GET /ai.json HTTP/1.1
GET /sftp-config.json HTTP/1.1
GET /.env.save HTTP/1.1
show less
275 attacks on env grabbing URLs (type 2), site downloads, PHP URLs, password/key grabbing URLs, env ...
show more275 attacks on env grabbing URLs (type 2), site downloads, PHP URLs, password/key grabbing URLs, env grabbing URLs, config grabbing URLs (type 2), VC URLs:
GET /@fs/proc/self/environ?import&raw?? HTTP/1.1
GET /dump.sql HTTP/1.1
GET /info.php HTTP/1.1
GET /.aws/credentials.1 HTTP/1.1
GET /%2e%2e/%2e%2e/.env HTTP/1.1
GET /secrets.yml HTTP/1.1
GET /.git/config HTTP/1.1
show less
[12/Sep/2026:05:32:41.152] HTTP 404 - GET /__aws_leak_probe_f2c5f969__
[12/Sep/2026:05:32:45.165] HT ...
show more[12/Sep/2026:05:32:41.152] HTTP 404 - GET /__aws_leak_probe_f2c5f969__
[12/Sep/2026:05:32:45.165] HTTP 404 - GET /.azure/credentials
[12/Sep/2026:05:32:45.597] HTTP 404 - GET /@fs/root/.config/gcloud/application_default_credentials.json?raw??
[12/Sep/2026:05:32:45.600] HTTP 404 - GET /static../.azure/credentials
[12/Sep/2026:05:32:45.601] HTTP 404 - GET /.env.local
[12/Sep/2026:05:32:45.600] HTTP 404 - GET /@fs/root/.aws/credentials?raw??
[12/Sep/2026:05:32:45.604] HTTP 404 - GET /@fs/home/ec2-user/.aws/credentials?raw??
[12/Sep/2026:05:32:45.602] HTTP 404 - GET /.aws/credentials
show less
ET INFO ChatGPT-User Traffic Detected Inbound M1
ET INFO ChatGPT-User Traffic Detected Inbound M2 ...
show moreET INFO ChatGPT-User Traffic Detected Inbound M1
ET INFO ChatGPT-User Traffic Detected Inbound M2
ET INFO Request for Visual Studio Code sftp.json - Possible Information Leak
ET INFO Request to Hidden Environment File - Inbound
ET SCAN SFTP/FTP Password Exposure via sftp-config.json
ET WEB_SERVER .bash_history Detected in URI
ET WEB_SERVER /etc/passwd Detected in URI
ET WEB_SERVER Likely Malicious Request for /proc/self/environ
ET WEB_SERVER Tilde in URI - potential .php~ source disclosure vulnerability
ET WEB_SERVER WEB-PHP phpinfo access
ET WEB_SPECIFIC_APPS Vite Arbitrary File Read Via raw parameter (CVE-2025-30208)
ET WEB_SPECIFIC_APPS Wordpress LiteSpeed Cache Plugin debug.log Access Attempt (CVE-2024-44000)
show less