136.117.73.244

blockedBruteRegularToolkit

Case file

First seen on 2026-09-19T02:30:53Z, most recently active on 2026-09-29T12:55:56Z.

Recorded 10 attack-shaped requests across 2 separate days.

Its traffic requested the .git directory itself, hoping it is exposed and browsable; it also requested a .env file, hoping to find API keys or database credentials; it also requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot.

Seen from 2 of our sensors: edge, nl4-web.

Scored into the "Brute" level, carrying the badges Regular, Toolkit.

Routed via AS396982 (Google LLC), an ASN we classify as cloud.

Blocked on every one of our hosts and at our edge since 2026-10-04T17:50:03Z, through 2027-01-02T17:50:03Z.

Enrichment

rDNS244.73.117.136.bc.googleusercontent.com
ASNAS396982 — Google LLC
ASN typecloud
CountryUnited States (US)
FlagsCloud range

External references: GreyNoise, Shodan, AbuseIPDB

Timeline

Evidence (newest first, up to 50)

Time (UTC)VantageSiteClassStatusEvidence
2026-09-19T02:30:53Zedgetechauthors.eurequested wp-config.php or a backup copy of it, hoping to read the database password in clear text{"ts":"2026-09-19T02:30:53Z","ip":"136.117.73.244","zone":"techauthors.eu","host":"techauthors.eu","path":"/wp-config.php","method":"GET","query":"","ua":"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.0 Safari/605.1.15","action":"block","source":…
2026-09-29T12:55:53Z – 2026-09-29T12:55:54Z ×2nl4-webobdebug.com2 × requested the .git directory itself, hoping it is exposed and browsable403[Tue Sep 29 15:55:54.238486 2026] [authz_core:error] AH01630: client denied by server configuration: <path>
2026-09-29T12:55:56Znl4-webobdebug.comrequested an AWS credentials file left in a web-accessible path by mistake404136.117.73.244 - - [29/Sep/2026:15:55:56 +0300] "GET /.aws/credentials HTTP/1.1" 404 236 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:138.0) Gecko/20100101 Firefox/138.0"
2026-09-29T12:55:56Znl4-webobdebug.comrequested docker-compose.yml, which often contains embedded passwords and connection strings404136.117.73.244 - - [29/Sep/2026:15:55:56 +0300] "GET /docker-compose.yml HTTP/1.1" 404 236 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:138.0) Gecko/20100101 Firefox/138.0"
2026-09-29T12:55:54Znl4-webobdebug.comrequested a .env file, hoping to find API keys or database credentials404136.117.73.244 - - [29/Sep/2026:15:55:54 +0300] "GET /.env.production HTTP/1.1" 404 236 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:138.0) Gecko/20100101 Firefox/138.0"
2026-09-29T12:55:54Znl4-webobdebug.comrequested a .env file, hoping to find API keys or database credentials403136.117.73.244 - - [29/Sep/2026:15:55:54 +0300] "GET /.env HTTP/1.1" 403 239 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:138.0) Gecko/20100101 Firefox/138.0"
2026-09-29T12:55:54Znl4-webobdebug.comrequested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot404136.117.73.244 - - [29/Sep/2026:15:55:54 +0300] "GET /.git-credentials HTTP/1.1" 404 236 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:138.0) Gecko/20100101 Firefox/138.0"
2026-09-29T12:55:54Znl4-webobdebug.comrequested the .git directory itself, hoping it is exposed and browsable403136.117.73.244 - - [29/Sep/2026:15:55:54 +0300] "GET /.git/credentials HTTP/1.1" 403 239 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:138.0) Gecko/20100101 Firefox/138.0"
2026-09-29T12:55:53Znl4-webobdebug.comprobed for an exposed .git directory to download the site's source history and config403136.117.73.244 - - [29/Sep/2026:15:55:53 +0300] "GET /.git/config HTTP/1.1" 403 239 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:138.0) Gecko/20100101 Firefox/138.0"

Report history

No abuse report sent for this address yet.

Not currently correlated with any campaign.

Dispute or removal: [email protected] — reference 136.117.73.244 (mailbox goes live with phase 3). See /threats/about for the method and the 7-day review window.

card.svg (used as this page's og:image)