34.159.8.40
Case file
First seen on 2026-10-04T21:38:50Z, most recently active on 2026-10-04T21:39:11Z.
Recorded 159 attack-shaped requests across 1 separate day.
Its traffic requested a .env file, hoping to find API keys or database credentials; it also used a directory-traversal segment (literal or percent-encoded ../) in the request path to try to escape the web root; it also requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot.
Seen on our edge, web sensors.
Scored into the "Persistent" level, carrying the badge Toolkit.
Routed via AS396982 (Google LLC), an ASN we classify as cloud.
Recorded internally; has not yet crossed the bar for a public listing.
Enrichment
| rDNS | 40.8.159.34.bc.googleusercontent.com |
|---|---|
| ASN | AS396982 — Google LLC |
| ASN type | cloud |
| Country | Germany (DE) |
| Flags | Cloud range |
Timeline
- 2026-10-04159
Evidence (newest first, up to 50)
| Time (UTC) | Vantage | Site | Class | Status | Evidence |
|---|---|---|---|---|---|
| 2026-10-04T21:39:11Z | web | bgpoet.com | 2 × tried to abuse a PHP-CGI argument-injection flaw (allow_url_include/auto_prepend_file) to execute code | 404 | POST /cgi-bin/php? -> 404 (2 distinct paths) |
| 2026-10-04T21:39:10Z | web | bgpoet.com | fuzzed a short, random filename looking for a forgotten script that responds | 404 | POST /index.php? -> 404 |
| 2026-10-04T21:39:09Z – 2026-10-04T21:39:10Z | web | bgpoet.com | 2 × tried to abuse a PHP-CGI argument-injection flaw (allow_url_include/auto_prepend_file) to execute code | 404 | POST /cgi-bin/php? -> 404 (2 distinct paths) |
| 2026-10-04T21:39:09Z | web | bgpoet.com | tried to abuse a local or remote file inclusion parameter such as allow_url_include | 404 | POST /php-cgi/php-cgi.exe? -> 404 |
| 2026-10-04T21:39:09Z | web | bgpoet.com | fuzzed a short, random filename looking for a forgotten script that responds | 404 | POST /index.php? -> 404 |
| 2026-10-04T21:39:04Z – 2026-10-04T21:39:05Z | web | bgpoet.com | 2 × swept a generic login/signup/account/dashboard route this site does not expose, consistent with an automated app-framework scanner | 403 | /api -> 403 |
| 2026-10-04T21:39:03Z | edge | bgpoet.com | triggered Cloudflare's managed rule for a Next.js server-action request-smuggling/RCE attempt | POST /admin | |
| 2026-10-04T21:39:02Z | web | bgpoet.com | 2 × requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot | 404 | GET /config.json.js -> 404 (2 distinct paths) |
| 2026-10-04T21:39:02Z | web | bgpoet.com | requested a .env file, hoping to find API keys or database credentials | 404 | GET /.env.js -> 404 |
| 2026-10-04T21:39:01Z – 2026-10-04T21:39:02Z | web | bgpoet.com | 3 × requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot | 404 | GET /configuration.js -> 404 (3 distinct paths) |
| 2026-10-04T21:39:01Z | web | bgpoet.com | 2 × requested a generic /config or /api/config endpoint, hoping the app exposes its runtime configuration unauthenticated | 404 | GET /api/v1/config -> 404 (2 distinct paths) |
| 2026-10-04T21:39:01Z | web | bgpoet.com | requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot | 404 | GET /firebase-config.json -> 404 |
| 2026-10-04T21:39:01Z | web | bgpoet.com | 2 × used a directory-traversal segment (literal or percent-encoded ../) in the request path to try to escape the web root | 404 | GET /img../.env -> 404 (2 distinct paths) |
| 2026-10-04T21:39:01Z | web | bgpoet.com | requested a config.json file, hoping it exposes API keys or internal settings | 404 | GET /config.json -> 404 |
| 2026-10-04T21:39:01Z | web | bgpoet.com | requested a generic /config or /api/config endpoint, hoping the app exposes its runtime configuration unauthenticated | 404 | GET /api/config -> 404 |
| 2026-10-04T21:39:00Z | edge | bgpoet.com | triggered Cloudflare's managed rule for a Next.js server-action request-smuggling/RCE attempt | POST /api | |
| 2026-10-04T21:39:00Z | web | bgpoet.com | 5 × used a directory-traversal segment (literal or percent-encoded ../) in the request path to try to escape the web root | 404 | GET /assets../.env -> 404 (5 distinct paths) |
| 2026-10-04T21:39:00Z | web | bgpoet.com | made a request that matched no known pattern | 404 | GET /%2Fapi/config -> 404 |
| 2026-10-04T21:39:00Z | web | bgpoet.com | 5 × used a directory-traversal segment (literal or percent-encoded ../) in the request path to try to escape the web root | 404 | GET /_image? -> 404 (5 distinct paths) |
| 2026-10-04T21:38:59Z | web | bgpoet.com | 2 × requested a .env file, hoping to find API keys or database credentials | 403 | /.env -> 403 |
| 2026-10-04T21:38:59Z | web | bgpoet.com | used a directory-traversal segment (literal or percent-encoded ../) in the request path to try to escape the web root | 403 | GET /_nuxt/../.env -> 403 |
| 2026-10-04T21:38:59Z | web | bgpoet.com | tried to read /proc/self/environ to dump process environment variables, usually via a traversal or inclusion flaw | 404 | GET /@fs/proc/self/environ? -> 404 |
| 2026-10-04T21:38:59Z | web | bgpoet.com | 4 × requested a .env file, hoping to find API keys or database credentials | 404 | GET /@fs/.env? -> 404 (4 distinct paths) |
| 2026-10-04T21:38:59Z | web | bgpoet.com | requested a .env file, hoping to find API keys or database credentials | 403 | GET /.env? -> 403 |
| 2026-10-04T21:38:59Z | web | bgpoet.com | 2 × requested a .env file, hoping to find API keys or database credentials | 404 | GET /.env.development? -> 404 (2 distinct paths) |
| 2026-10-04T21:38:58Z | web | bgpoet.com | 4 × requested a .env file, hoping to find API keys or database credentials | 403 | /.env -> 403 |
Not currently correlated with any campaign.
Dispute or removal: [email protected] — reference 34.159.8.40. See /threats/about for the method and the 7-day review window.
card.svg (used as this page's og:image)