Loading threats
Matches HTTP requests attempting to access a backup copy of an AWS credentials file at /.aws/credentials.bak. This primitive helps identify reconnaissance or exploitation attempts where attackers probe for exposed backup or temporary credential files that may contain cloud access keys or secrets due to misconfigured file serving, directory listing, or file disclosure vulnerabilities.
| IP Address | Risk | Events | Sessions | Country | ASN | Last Seen |
|---|---|---|---|---|---|---|
| 185.177.72.38 | 95% | 31,943 | 1,582 | 🇫🇷 FR | AS211590 | 2026-03-20 |
| 185.177.72.30 | 95% | 26,421 | 1,104 | 🇫🇷 FR | AS211590 | 2026-03-20 |
| 185.177.72.52 | 95% | 23,842 | 998 | 🇫🇷 FR | AS211590 | 2026-03-20 |
| 185.177.72.49 | 93% | 20,655 | 1,000 | 🇫🇷 FR | AS211590 | 2026-03-20 |
| 185.177.72.22 | 97% | 20,461 | 1,157 | 🇫🇷 FR | AS211590 | 2026-03-20 |
| 185.177.72.51 | 93% | 17,251 | 1,160 | 🇫🇷 FR | AS211590 | 2026-03-20 |
| 185.177.72.13 | 93% | 17,222 | 1,093 | 🇫🇷 FR | AS211590 | 2026-03-20 |
| 185.177.72.23 | 94% | 14,990 | 1,161 | 🇫🇷 FR | AS211590 | 2026-03-20 |
| 185.177.72.56 | 91% | 14,306 | 1,036 | 🇫🇷 FR | AS211590 | 2026-03-18 |
| 45.148.10.5 | 99% | 507 | 507 | 🇳🇱 NL | AS48090 | 2026-03-20 |
| 45.139.104.161 | 84% | 472 | 472 | 🇧🇬 BG | AS399979 | 2026-03-11 |
| 195.178.110.28 | 99% | 459 | 459 | 🇧🇬 BG | AS48090 | 2026-03-20 |
| 216.81.248.11 | 78% | 234 | 234 | 🇺🇸 US | AS11320 | 2026-03-17 |
| 209.74.81.119 | 97% | 96 | 96 | 🇸🇬 SG | AS22612 | 2026-02-27 |
| 209.74.83.179 | 95% | 92 | 92 | 🇺🇸 US | AS22612 | 2026-03-03 |
| 203.161.47.249 | 94% | 83 | 83 | 🇺🇸 US | AS22612 | 2026-02-23 |
| 141.101.95.114 | 5% | 50 | 9 | 🇫🇷 FR | AS13335 | 2026-03-13 |
| 172.68.151.163 | 4% | 46 | 15 | 🇫🇷 FR | AS13335 | 2026-03-18 |
| 2.58.56.55 | 61% | 38 | 38 | 🇳🇱 NL | AS210558 | 2026-03-19 |
| 203.161.47.85 | 74% | 33 | 33 | 🇺🇸 US | AS22612 | 2026-02-28 |