195.178.110.18

blockedPersistentRegularToolkit

Case file

First seen on 2026-09-25T17:47:13Z, most recently active on 2026-10-05T07:36:15Z.

Recorded 12 attack-shaped requests across 5 separate days.

Its traffic requested wp-config.php or a backup copy of it, hoping to read the database password in clear text; it also requested a .env file, hoping to find API keys or database credentials; it also requested the .git directory itself, hoping it is exposed and browsable.

Seen on our edge, web sensors.

Scored into the "Persistent" level, carrying the badges Regular, Toolkit.

Routed via AS48090 (Techoff Srv Limited), an ASN we classify as hosting.

Blocked by the firewalls on our servers since 2026-10-05T07:50:04Z, through 2027-10-05T07:50:04Z.

Enrichment

rDNSnone
ASNAS48090 — Techoff Srv Limited
ASN typehosting
CountryBulgaria (BG)
Flagsnone observed

External references: GreyNoise, Shodan, AbuseIPDB

Timeline

Evidence (newest first, up to 50)

Time (UTC)VantageSiteClassStatusEvidence
2026-10-05T07:36:15Zwebsvestnik.comrequested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot404GET /config.js -> 404
2026-10-05T07:36:14Zwebsvestnik.comrequested the .git directory itself, hoping it is exposed and browsable403/.git -> 403
2026-10-05T07:36:14Zedgesvestnik.comrequested wp-config.php or a backup copy of it, hoping to read the database password in clear textGET /wp-config.php
2026-10-05T07:36:14Zwebsvestnik.comrequested a config.json file, hoping it exposes API keys or internal settings404GET /config.json -> 404
2026-10-05T07:36:14Zwebsvestnik.comrequested a database dump or site archive by its common backup filename404GET /dump.sql -> 404
2026-10-05T07:36:14Zwebsvestnik.comrequested a generic /config or /api/config endpoint, hoping the app exposes its runtime configuration unauthenticated404GET /api/config -> 404
2026-10-05T07:36:14Zwebsvestnik.comprobed for an exposed .git directory to download the site's source history and config403GET /.git/config -> 403
2026-10-05T07:36:13Zwebsvestnik.comrequested a .env file, hoping to find API keys or database credentials403GET /.env -> 403
2026-10-01T17:10:46Zedgehaiv.devrequested wp-config.php or a backup copy of it, hoping to read the database password in clear textGET /wp-config.php
2026-09-30T03:38:30Zedgehaiv.devrequested wp-config.php or a backup copy of it, hoping to read the database password in clear textGET /wp-config.php
2026-09-26T05:37:02Zedgeobdebug.comrequested wp-config.php or a backup copy of it, hoping to read the database password in clear textGET /wp-config.php
2026-09-25T17:47:13Zedgehaiv.devrequested wp-config.php or a backup copy of it, hoping to read the database password in clear textGET /wp-config.php

Not currently correlated with any campaign.

Dispute or removal: [email protected] — reference 195.178.110.18. See /threats/about for the method and the 7-day review window.

card.svg (used as this page's og:image)