195.178.110.18
Case file
First seen on 2026-09-25T17:47:13Z, most recently active on 2026-10-05T07:36:15Z.
Recorded 12 attack-shaped requests across 5 separate days.
Its traffic requested wp-config.php or a backup copy of it, hoping to read the database password in clear text; it also requested a .env file, hoping to find API keys or database credentials; it also requested the .git directory itself, hoping it is exposed and browsable.
Seen on our edge, web sensors.
Scored into the "Persistent" level, carrying the badges Regular, Toolkit.
Routed via AS48090 (Techoff Srv Limited), an ASN we classify as hosting.
Blocked by the firewalls on our servers since 2026-10-05T07:50:04Z, through 2027-10-05T07:50:04Z.
Enrichment
| rDNS | none |
|---|---|
| ASN | AS48090 — Techoff Srv Limited |
| ASN type | hosting |
| Country | Bulgaria (BG) |
| Flags | none observed |
Timeline
- 2026-09-251
- 2026-09-261
- 2026-09-301
- 2026-10-011
- 2026-10-058
Evidence (newest first, up to 50)
| Time (UTC) | Vantage | Site | Class | Status | Evidence |
|---|---|---|---|---|---|
| 2026-10-05T07:36:15Z | web | svestnik.com | requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot | 404 | GET /config.js -> 404 |
| 2026-10-05T07:36:14Z | web | svestnik.com | requested the .git directory itself, hoping it is exposed and browsable | 403 | /.git -> 403 |
| 2026-10-05T07:36:14Z | edge | svestnik.com | requested wp-config.php or a backup copy of it, hoping to read the database password in clear text | GET /wp-config.php | |
| 2026-10-05T07:36:14Z | web | svestnik.com | requested a config.json file, hoping it exposes API keys or internal settings | 404 | GET /config.json -> 404 |
| 2026-10-05T07:36:14Z | web | svestnik.com | requested a database dump or site archive by its common backup filename | 404 | GET /dump.sql -> 404 |
| 2026-10-05T07:36:14Z | web | svestnik.com | requested a generic /config or /api/config endpoint, hoping the app exposes its runtime configuration unauthenticated | 404 | GET /api/config -> 404 |
| 2026-10-05T07:36:14Z | web | svestnik.com | probed for an exposed .git directory to download the site's source history and config | 403 | GET /.git/config -> 403 |
| 2026-10-05T07:36:13Z | web | svestnik.com | requested a .env file, hoping to find API keys or database credentials | 403 | GET /.env -> 403 |
| 2026-10-01T17:10:46Z | edge | haiv.dev | requested wp-config.php or a backup copy of it, hoping to read the database password in clear text | GET /wp-config.php | |
| 2026-09-30T03:38:30Z | edge | haiv.dev | requested wp-config.php or a backup copy of it, hoping to read the database password in clear text | GET /wp-config.php | |
| 2026-09-26T05:37:02Z | edge | obdebug.com | requested wp-config.php or a backup copy of it, hoping to read the database password in clear text | GET /wp-config.php | |
| 2026-09-25T17:47:13Z | edge | haiv.dev | requested wp-config.php or a backup copy of it, hoping to read the database password in clear text | GET /wp-config.php |
Not currently correlated with any campaign.
Dispute or removal: [email protected] — reference 195.178.110.18. See /threats/about for the method and the 7-day review window.
card.svg (used as this page's og:image)