136.110.44.201
Case file
First seen on 2026-10-02T18:14:04Z, most recently active on 2026-10-05T22:31:22Z.
Recorded 980 attack-shaped requests across 2 separate days.
Its traffic requested a .env file, hoping to find API keys or database credentials; it also used a directory-traversal segment (literal or percent-encoded ../) in the request path to try to escape the web root; it also requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot.
Seen on our edge, web sensors.
Scored into the "Persistent" level, carrying the badges Regular, Toolkit.
Routed via AS396982 (Google LLC), an ASN we classify as cloud.
Blocked by the firewalls on our servers since 2026-10-05T22:40:04Z, through 2027-01-03T22:40:04Z.
Enrichment
| rDNS | 201.44.110.136.bc.googleusercontent.com |
|---|---|
| ASN | AS396982 — Google LLC |
| ASN type | cloud |
| Country | Singapore (SG) |
| Flags | Cloud range |
Timeline
- 2026-10-02770
- 2026-10-05210
Evidence (newest first, up to 50)
| Time (UTC) | Vantage | Site | Class | Status | Evidence |
|---|---|---|---|---|---|
| 2026-10-05T22:31:22Z | web | servbg.com | probed a Spring Boot actuator endpoint, which can leak environment variables and internal config if left open | 404 | GET /actuator/gateway/routes -> 404 |
| 2026-10-05T22:31:21Z | web | servbg.com | swept a generic login/signup/account/dashboard route this site does not expose, consistent with an automated app-framework scanner | 404 | GET /api/v1/loginmethod? -> 404 |
| 2026-10-05T22:31:21Z | web | servbg.com | 2 × tried to abuse a PHP-CGI argument-injection flaw (allow_url_include/auto_prepend_file) to execute code | 404 | POST /cgi-bin/php? -> 404 (2 distinct paths) |
| 2026-10-05T22:31:21Z | web | servbg.com | probed a Next.js/Auth.js (NextAuth) authentication route, consistent with fingerprinting a Next.js app's auth stack | 404 | GET /api/auth -> 404 |
| 2026-10-05T22:31:20Z | web | servbg.com | tried to abuse a local or remote file inclusion parameter such as allow_url_include | 200 | POST /index.php? -> 200 |
| 2026-10-05T22:31:20Z | web | servbg.com | requested a generic /config or /api/config endpoint, hoping the app exposes its runtime configuration unauthenticated | 404 | GET /api/v1/configs -> 404 |
| 2026-10-05T22:31:20Z | web | servbg.com | 2 × tried to abuse a PHP-CGI argument-injection flaw (allow_url_include/auto_prepend_file) to execute code | 404 | POST /cgi-bin/php? -> 404 (2 distinct paths) |
| 2026-10-05T22:31:20Z | web | servbg.com | tried to abuse a local or remote file inclusion parameter such as allow_url_include | 404 | POST /php-cgi/php-cgi.exe? -> 404 |
| 2026-10-05T22:31:19Z | web | servbg.com | requested the .git directory itself, hoping it is exposed and browsable | 403 | /.git -> 403 |
| 2026-10-05T22:31:19Z | web | servbg.com | requested a .env file, hoping to find API keys or database credentials | 403 | /.env -> 403 |
| 2026-10-05T22:31:19Z | web | servbg.com | requested the .git directory itself, hoping it is exposed and browsable | 403 | /.git -> 403 |
| 2026-10-05T22:31:19Z | web | servbg.com | tried to abuse a local or remote file inclusion parameter such as allow_url_include | 200 | POST /index.php? -> 200 |
| 2026-10-05T22:31:19Z | web | servbg.com | used a directory-traversal segment (literal or percent-encoded ../) in the request path to try to escape the web root | 404 | GET /userfiles? -> 404 |
| 2026-10-05T22:31:19Z | web | servbg.com | requested a .env file, hoping to find API keys or database credentials | 403 | GET /backend/.env -> 403 |
| 2026-10-05T22:31:19Z | web | servbg.com | used a directory-traversal segment (literal or percent-encoded ../) in the request path to try to escape the web root | 404 | GET /userfiles? -> 404 |
| 2026-10-05T22:31:19Z | web | servbg.com | requested a .env file, hoping to find API keys or database credentials | 403 | GET /api/.env -> 403 |
| 2026-10-05T22:31:19Z | web | servbg.com | used a directory-traversal segment (literal or percent-encoded ../) in the request path to try to escape the web root | 404 | GET /userfiles? -> 404 |
| 2026-10-05T22:31:19Z | web | servbg.com | requested a .env file, hoping to find API keys or database credentials | 403 | GET /admin/.env -> 403 |
| 2026-10-05T22:31:19Z | web | servbg.com | used a directory-traversal segment (literal or percent-encoded ../) in the request path to try to escape the web root | 404 | GET /userfiles? -> 404 |
| 2026-10-05T22:31:19Z | web | servbg.com | requested a .env file, hoping to find API keys or database credentials | 403 | GET /.env.prod -> 403 |
| 2026-10-05T22:31:19Z | web | servbg.com | requested a .env file, hoping to find API keys or database credentials | 404 | GET /api/system/fileView? -> 404 |
| 2026-10-05T22:31:19Z | web | servbg.com | 2 × requested a .env file, hoping to find API keys or database credentials | 403 | GET /.env.save -> 403 (2 distinct paths) |
| 2026-10-05T22:31:19Z | web | servbg.com | tried to read /proc/self/environ to dump process environment variables, usually via a traversal or inclusion flaw | 404 | GET /api/system/fileView? -> 404 |
| 2026-10-05T22:31:19Z | web | servbg.com | requested a .env file, hoping to find API keys or database credentials | 403 | GET /docker/.env -> 403 |
| 2026-10-05T22:31:19Z | web | servbg.com | probed for an exposed .git directory to download the site's source history and config | 403 | GET /.git/HEAD -> 403 |
| 2026-10-05T22:31:19Z | web | servbg.com | requested a .env file, hoping to find API keys or database credentials | 403 | GET /frontend/.env -> 403 |
| 2026-10-05T22:31:19Z | web | servbg.com | requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot | 403 | GET /.aws/config -> 403 |
| 2026-10-05T22:31:19Z | web | servbg.com | 2 × requested a .env file, hoping to find API keys or database credentials | 403 | GET /.env.old -> 403 (2 distinct paths) |
| 2026-10-05T22:31:19Z | web | servbg.com | used a directory-traversal segment (literal or percent-encoded ../) in the request path to try to escape the web root | 403 | GET /cache/original/%2e%2e/%2e%2e/.env -> 403 |
| 2026-10-05T22:31:19Z | web | servbg.com | requested a .env file, hoping to find API keys or database credentials | 403 | GET /public/.env -> 403 |
| 2026-10-05T22:31:19Z | web | servbg.com | probed for an exposed .git directory to download the site's source history and config | 403 | GET /.git/config -> 403 |
| 2026-10-05T22:31:19Z | web | servbg.com | 3 × requested a .env file, hoping to find API keys or database credentials | 403 | GET /core/.env -> 403 (3 distinct paths) |
| 2026-10-05T22:31:18Z | web | servbg.com | 3 × requested a generic /config or /api/config endpoint, hoping the app exposes its runtime configuration unauthenticated | 403 | /config -> 403 |
| 2026-10-05T22:31:18Z | web | servbg.com | requested a .env file, hoping to find API keys or database credentials | 403 | GET /.env.bak -> 403 |
| 2026-10-05T22:31:18Z | web | servbg.com | requested an AWS credentials file left in a web-accessible path by mistake | 403 | GET /.aws/credentials -> 403 |
| 2026-10-05T22:31:18Z | web | servbg.com | requested a .env file, hoping to find API keys or database credentials | 403 | GET /dist/.env -> 403 |
| 2026-10-05T22:31:18Z | web | servbg.com | used a directory-traversal segment (literal or percent-encoded ../) in the request path to try to escape the web root | 403 | GET /cache/original/%2e%2e/.env -> 403 |
| 2026-10-05T22:31:18Z | web | servbg.com | requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot | 403 | GET /config/firebase-admin.json -> 403 |
| 2026-10-05T22:31:18Z | web | servbg.com | requested a .env file, hoping to find API keys or database credentials | 403 | GET /.env.backup -> 403 |
| 2026-10-05T22:31:18Z | web | servbg.com | requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot | 404 | GET /public/admin.json -> 404 |
| 2026-10-05T22:31:18Z | web | servbg.com | requested a .env file, hoping to find API keys or database credentials | 404 | GET /api/fs/read? -> 404 |
| 2026-10-05T22:31:18Z | web | servbg.com | requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot | 403 | GET /config/gcp-credentials.json -> 403 |
Not currently correlated with any campaign.
Dispute or removal: [email protected] — reference 136.110.44.201. See /threats/about for the method and the 7-day review window.
card.svg (used as this page's og:image)