Loading threats
Matches HTTP requests attempting to access a plaintext file at /.aws/credentials.txt. This primitive helps identify reconnaissance or exploitation attempts where attackers probe for exposed cloud credential material stored in unsecured text files, often accessible due to directory listing, misconfigured file serving, or file disclosure vulnerabilities.
| IP Address | Risk | Events | Sessions | Country | ASN | Last Seen |
|---|---|---|---|---|---|---|
| 185.177.72.38 | 98% | 32,475 | 2,114 | 🇫🇷 FR | AS211590 | 2026-04-02 |
| 185.177.72.51 | 97% | 17,572 | 1,481 | 🇫🇷 FR | AS211590 | 2026-04-02 |
| 45.148.10.5 | 94% | 553 | 553 | 🇳🇱 NL | AS48090 | 2026-03-21 |
| 195.178.110.28 | 94% | 507 | 507 | 🇧🇬 BG | AS48090 | 2026-03-21 |