34.158.152.37
In feed.txt Persistent Regular Toolkit
Blocked on our servers, including web requests through Cloudflare, since UTC, through UTC, and in feed.txt.
Record
- Score
- 44/100each request counts half as much after 30 days
- Worst level
- Persistent
- Attack-shaped requests
- 414all time
- Active days
- 2UTC days
- First seen
- Last seen
- Servers hit
- 3
- Targets
- 2sites
- Times blocked
- 0by the evidence rules
Its traffic requested a .env file, hoping to find API keys or database credentials; it also used a directory-traversal segment (literal or percent-encoded ../) in the request path to try to escape the web root; it also requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot.
Surfaces: web-app. Attack types: fake crawlers, known exploits, injection, scanning, hunting for secrets. Seen by: edge, web.
Activity, last 90 days
Active on 2 of the last 90 UTC days. Current block: to .
Daily counts
| Day (UTC) | Requests |
|---|---|
| 198 | |
| 216 |
- At least 216 requests a minute at its peak ( UTC; identical requests in the same second are stored once).
- Methods: GET 345, POST 27.
- The servers we watch answered: 403 232, 404 172, 301 2 (totals only, from our web servers).
Evidence
Newest first, the latest 50 stored requests grouped into runs. Times are UTC. The user agent is shown as its family only.
| Time | Site | What happened | Request | User agent | Seen by |
|---|---|---|---|---|---|
| servbg.com | 2× fuzzed a common filename under /cgi-bin/, looking for a forgotten legacy CGI script | /cgi-bin | none | web | |
| servbg.com | fuzzed a short, random filename looking for a forgotten script that responds | /index.php | none | web | |
| servbg.com | 2× fuzzed a common filename under /cgi-bin/, looking for a forgotten legacy CGI script | /cgi-bin | none | web | |
| servbg.com | 2× tried to abuse a PHP-CGI argument-injection flaw (allow_url_include/auto_prepend_file) to execute code (2 distinct paths) | POST /cgi-bin/php? | declared bot | web | |
| servbg.com | fuzzed a short, random filename looking for a forgotten script that responds | POST /index.php? | declared bot | web | |
| servbg.com | 2× tried to abuse a PHP-CGI argument-injection flaw (allow_url_include/auto_prepend_file) to execute code (2 distinct paths) | POST /cgi-bin/php? | declared bot | web | |
| servbg.com | fuzzed a short, random filename looking for a forgotten script that responds | /index.php | none | web | |
| servbg.com | tried to abuse a local or remote file inclusion parameter such as allow_url_include | POST /php-cgi/php-cgi.exe? | declared bot | web | |
| servbg.com | fuzzed a short, random filename looking for a forgotten script that responds | POST /index.php? | declared bot | web | |
| servbg.com | claimed to be Googlebot while POSTing, something the real crawler never does | POST /api/designer/v1/file-content | declared bot | web | |
| servbg.com | 2× triggered Cloudflare's managed rule for a Next.js server-action request-smuggling/RCE attempt (2 distinct paths) | POST /api/auth | declared bot | edge | |
| servbg.com | 10× used a directory-traversal segment (literal or percent-encoded ../) in the request path to try to escape the web root (10 distinct paths) | GET /build../.env | declared bot | web | |
| servbg.com | 2× requested docker-compose.yml, which often contains embedded passwords and connection strings (2 distinct paths) | GET /docker-compose.yml | declared bot | web | |
| servbg.com | 2× requested the .git directory itself, hoping it is exposed and browsable | /.git | none | web | |
| servbg.com | probed a list of common site paths looking for an unprotected admin panel or staging copy | /admin | none | web | |
| servbg.com | 3× requested a generic /config or /api/config endpoint, hoping the app exposes its runtime configuration unauthenticated | /config | none | web | |
| servbg.com | requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot | GET /credentials.json | declared bot | web | |
| servbg.com | requested a .env file, hoping to find API keys or database credentials | GET /secrets.env | declared bot | web | |
| servbg.com | 2× probed for an exposed .git directory to download the site's source history and config (2 distinct paths) | GET /.git/config | declared bot | web | |
| servbg.com | 3× requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot (3 distinct paths) | GET /.aws/config | declared bot | web | |
| servbg.com | requested an AWS credentials file left in a web-accessible path by mistake | GET /.aws/credentials | declared bot | web | |
| servbg.com | 8× requested a .env file, hoping to find API keys or database credentials (8 distinct paths) | GET /.next/.env | declared bot | web | |
Network
- ASN
- AS396982 Google LLC
- Network type
- cloud
- Reverse DNS
37.152.158.34.bc.googleusercontent.com- Country
- The Netherlands NL
- City
- Groningen (registry location of a hosting network)
- Flags
- cloud range (GCP)
- Abuse contact
- found in the registry
- Checked