136.80.139.226

blockedPersistentRegularToolkit

Case file

First seen on 2026-10-05T10:33:39Z, most recently active on 2026-10-07T03:09:41Z.

Recorded 420 attack-shaped requests across 2 separate days.

Its traffic requested a .env file, hoping to find API keys or database credentials; it also used a directory-traversal segment (literal or percent-encoded ../) in the request path to try to escape the web root; it also requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot.

Seen on our edge, web sensors.

Scored into the "Persistent" level, carrying the badges Regular, Toolkit.

Routed via AS396982 (Google LLC), an ASN we classify as cloud.

Blocked by the firewalls on our servers since 2026-10-07T03:20:04Z, through 2027-01-05T03:20:04Z.

Enrichment

rDNS226.139.80.136.bc.googleusercontent.com
ASNAS396982 — Google LLC
ASN typecloud
CountryUnited States (US)
FlagsCloud range

External references: GreyNoise, Shodan, AbuseIPDB

Timeline

Evidence (newest first, up to 50)

Time (UTC)VantageSiteClassStatusEvidence
2026-10-07T03:09:41Zwebservbg.comprobed a Spring Boot actuator endpoint, which can leak environment variables and internal config if left open404GET /actuator/gateway/routes -> 404
2026-10-07T03:09:40Zwebservbg.comtried to abuse a PHP-CGI argument-injection flaw (allow_url_include/auto_prepend_file) to execute code404GET /cgi-bin/php? -> 404
2026-10-07T03:09:40Zwebservbg.comswept a generic login/signup/account/dashboard route this site does not expose, consistent with an automated app-framework scanner404GET /api/v1/loginmethod? -> 404
2026-10-07T03:09:40Zwebservbg.comtried to abuse a PHP-CGI argument-injection flaw (allow_url_include/auto_prepend_file) to execute code404GET /cgi-bin/php-cgi? -> 404
2026-10-07T03:09:40Zwebservbg.comtried to abuse a local or remote file inclusion parameter such as allow_url_include200GET /index.php? -> 200
2026-10-07T03:09:40Zwebservbg.comprobed a Next.js/Auth.js (NextAuth) authentication route, consistent with fingerprinting a Next.js app's auth stack404GET /api/auth -> 404
2026-10-07T03:09:40Zwebservbg.com2 × tried to abuse a PHP-CGI argument-injection flaw (allow_url_include/auto_prepend_file) to execute code404GET /cgi-bin/php? -> 404 (2 distinct paths)
2026-10-07T03:09:39Zwebservbg.comrequested a generic /config or /api/config endpoint, hoping the app exposes its runtime configuration unauthenticated403/config -> 403
2026-10-07T03:09:39Zwebservbg.comrequested a generic /config or /api/config endpoint, hoping the app exposes its runtime configuration unauthenticated404GET /api/v1/configs -> 404
2026-10-07T03:09:39Zwebservbg.comtried to abuse a local or remote file inclusion parameter such as allow_url_include404GET /php-cgi/php-cgi.exe? -> 404
2026-10-07T03:09:39Zwebservbg.comtried to abuse a local or remote file inclusion parameter such as allow_url_include200GET /index.php? -> 200
2026-10-07T03:09:39Zwebservbg.comrequested a .env file, hoping to find API keys or database credentials403GET /@fs/app/.env.local? -> 403
2026-10-07T03:09:39Zwebservbg.comrequested a Vite/React-Server-Components source map, likely while mapping the app's bundled source404GET /__vite_rsc_findSourceMapURL? -> 404
2026-10-07T03:09:39Zwebservbg.comrequested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot403GET /config/gcp-credentials.json -> 403
2026-10-07T03:09:39Zwebservbg.com2 × requested a Vite/React-Server-Components source map, likely while mapping the app's bundled source404GET /__vite_rsc_findSourceMapURL? -> 404
2026-10-07T03:09:38Zwebservbg.comrequested a generic /config or /api/config endpoint, hoping the app exposes its runtime configuration unauthenticated403/config -> 403
2026-10-07T03:09:38Zwebservbg.comrequested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot404GET /google-credentials.json -> 404
2026-10-07T03:09:38Zwebservbg.comrequested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot403GET /config/firebase-admin.json -> 403
2026-10-07T03:09:38Zwebservbg.comrequested a .env file, hoping to find API keys or database credentials403GET /.env? -> 403
2026-10-07T03:09:38Zwebservbg.comrequested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot404GET /public/admin.json -> 404
2026-10-07T03:09:38Zwebservbg.com2 × requested a .env file, hoping to find API keys or database credentials403GET /@fs/src/.env? -> 403 (2 distinct paths)
2026-10-07T03:09:38Zwebservbg.comrequested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot404GET /firebase-admin.json -> 404
2026-10-07T03:09:38Zwebservbg.comused Vite dev server's @fs/ path to try to read arbitrary files outside the project root404GET /@fs/proc/self/cmdline? -> 404
2026-10-07T03:09:38Zwebservbg.com2 × requested a .env file, hoping to find API keys or database credentials403GET /@fs/app/.env? -> 403 (2 distinct paths)
2026-10-07T03:09:38Zwebservbg.comrequested an AWS credentials file left in a web-accessible path by mistake403GET /@fs/home/ec2-user/.aws/credentials? -> 403
2026-10-07T03:09:38Zwebservbg.comrequested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot404GET /firebase-credentials.json -> 404
2026-10-07T03:09:38Zwebservbg.comrequested an AWS credentials file left in a web-accessible path by mistake403GET /@fs/home/ubuntu/.aws/credentials? -> 403
2026-10-07T03:09:38Zwebservbg.com2 × requested a .env file, hoping to find API keys or database credentials403GET /@fs/.env? -> 403 (2 distinct paths)
2026-10-07T03:09:38Zwebservbg.comrequested an AWS credentials file left in a web-accessible path by mistake403GET /@fs/root/.aws/credentials? -> 403
2026-10-07T03:09:38Zwebservbg.com5 × requested a .env file, hoping to find API keys or database credentials403GET /@fs/.env? -> 403 (4 distinct paths)
2026-10-07T03:09:38Zwebservbg.comrequested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot404GET /push_config.json -> 404
2026-10-07T03:09:38Zwebservbg.com2 × requested a .env file, hoping to find API keys or database credentials403GET /docker/.env -> 403 (2 distinct paths)
2026-10-07T03:09:38Zwebservbg.comrequested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot404GET /gcp-credentials.json -> 404
2026-10-07T03:09:37Zwebservbg.com2 × requested the .git directory itself, hoping it is exposed and browsable403/.git -> 403
2026-10-07T03:09:37Zedgeservbg.comrequested wp-config.php or a backup copy of it, hoping to read the database password in clear textGET /wp-config.php.swp
2026-10-07T03:09:37Zwebservbg.comused Vite dev server's @fs/ path to try to read arbitrary files outside the project root404GET /@fs/var/run/secrets/kubernetes.io/serviceaccount/ca.crt? -> 404
2026-10-07T03:09:37Zwebservbg.comrequested a .env file, hoping to find API keys or database credentials403GET /.env.example -> 403
2026-10-07T03:09:37Zwebservbg.comrequested a Vite/React-Server-Components source map, likely while mapping the app's bundled source404GET /__vite_rsc_findSourceMapURL? -> 404
2026-10-07T03:09:37Zwebservbg.comused Vite dev server's @fs/ path to try to read arbitrary files outside the project root404GET /@fs/var/run/secrets/kubernetes.io/serviceaccount/token? -> 404

Not currently correlated with any campaign.

Dispute or removal: [email protected] — reference 136.80.139.226. See /threats/about for the method and the 7-day review window.

card.svg (used as this page's og:image)