136.110.31.111

recordedPersistentToolkit

Case file

First seen on 2026-10-04T22:05:32Z, most recently active on 2026-10-04T23:57:02Z.

Recorded 511 attack-shaped requests across 1 separate day.

Its traffic requested a .env file, hoping to find API keys or database credentials; it also used a directory-traversal segment (literal or percent-encoded ../) in the request path to try to escape the web root; it also requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot.

Seen on our edge, web sensors.

Scored into the "Persistent" level, carrying the badge Toolkit.

Routed via AS396982 (Google LLC), an ASN we classify as cloud.

Recorded internally; has not yet crossed the bar for a public listing.

Enrichment

rDNS111.31.110.136.bc.googleusercontent.com
ASNAS396982 — Google LLC
ASN typecloud
CountrySingapore (SG)
FlagsCloud range

External references: GreyNoise, Shodan, AbuseIPDB

Timeline

Evidence (newest first, up to 50)

Time (UTC)VantageSiteClassStatusEvidence
2026-10-04T23:57:01Z – 2026-10-04T23:57:02Zwebhaived.com2 × tried to abuse a PHP-CGI argument-injection flaw (allow_url_include/auto_prepend_file) to execute code301POST /cgi-bin/php? -> 301 (2 distinct paths)
2026-10-04T23:57:01Zwebhaived.comtried to abuse a local or remote file inclusion parameter such as allow_url_include301POST /index.php? -> 301
2026-10-04T23:57:00Zwebhaived.com2 × tried to abuse a PHP-CGI argument-injection flaw (allow_url_include/auto_prepend_file) to execute code301POST /cgi-bin/php? -> 301 (2 distinct paths)
2026-10-04T23:56:59Zwebhaived.com2 × tried to abuse a local or remote file inclusion parameter such as allow_url_include301POST /php-cgi/php-cgi.exe? -> 301 (2 distinct paths)
2026-10-04T23:56:47Zedgeservbg.devtriggered Cloudflare's managed rule for a Next.js server-action request-smuggling/RCE attemptPOST /api/auth
2026-10-04T23:56:46Zwebhaived.com3 × requested a .env file, hoping to find API keys or database credentials301GET /.//.env -> 301 (3 distinct paths)
2026-10-04T23:56:46Zwebhaived.comprobed for an exposed GraphQL endpoint or its config file, often a precursor to an introspection query301GET /graphql -> 301
2026-10-04T23:56:44Zwebhaived.comrequested a .env file, hoping to find API keys or database credentials301GET /.env.js -> 301
2026-10-04T23:56:44Zwebhaived.comprobed a Spring Boot actuator endpoint, which can leak environment variables and internal config if left open301GET /actuator/loggers -> 301
2026-10-04T23:56:39Z – 2026-10-04T23:56:40Zwebhaived.com5 × used a directory-traversal segment (literal or percent-encoded ../) in the request path to try to escape the web root301GET /api/data/..%2f..%2f.env -> 301 (5 distinct paths)
2026-10-04T23:56:39Zwebhaived.comtried to read /proc/self/environ to dump process environment variables, usually via a traversal or inclusion flaw301GET /@fs/proc/self/environ? -> 301
2026-10-04T23:56:39Zwebhaived.comused a directory-traversal segment (literal or percent-encoded ../) in the request path to try to escape the web root301GET /_nuxt/../.env -> 301
2026-10-04T23:56:37Z – 2026-10-04T23:56:38Zwebhaived.com12 × requested a .env file, hoping to find API keys or database credentials301GET /.env.local? -> 301 (6 distinct paths)
2026-10-04T23:56:37Zwebhaived.comused Vite dev server's @fs/ path to try to read arbitrary files outside the project root301GET /@fs/proc/self/cmdline? -> 301
2026-10-04T23:56:37Zwebhaived.com4 × requested a Vite/React-Server-Components source map, likely while mapping the app's bundled source301GET /__vite_rsc_findSourceMapURL? -> 301
2026-10-04T23:56:37Zwebhaived.comrequested a .env file, hoping to find API keys or database credentials301GET /.env? -> 301
2026-10-04T23:56:36Zwebhaived.comused Vite dev server's @fs/ path to try to read arbitrary files outside the project root301GET /@fs/var/run/secrets/kubernetes.io/serviceaccount/ca.crt? -> 301
2026-10-04T23:56:36Zwebhaived.comrequested a .env file, hoping to find API keys or database credentials301GET /@fs/app/.env.local? -> 301
2026-10-04T23:56:36Zwebhaived.comused a directory-traversal segment (literal or percent-encoded ../) in the request path to try to escape the web root301GET /@fs/../.env? -> 301
2026-10-04T23:56:36Zwebhaived.com2 × requested a .env file, hoping to find API keys or database credentials301GET /@fs/src/.env? -> 301 (2 distinct paths)
2026-10-04T23:56:36Zwebhaived.comused Vite dev server's @fs/ path to try to read arbitrary files outside the project root301GET /@fs/var/run/secrets/kubernetes.io/serviceaccount/token? -> 301
2026-10-04T23:56:35Z – 2026-10-04T23:56:36Zwebhaived.com5 × requested a .env file, hoping to find API keys or database credentials301GET /@fs/app/.env? -> 301 (4 distinct paths)

Not currently correlated with any campaign.

Dispute or removal: [email protected] — reference 136.110.31.111. See /threats/about for the method and the 7-day review window.

card.svg (used as this page's og:image)