34.179.190.38
In feed.txt Relentless Regular Toolkit
Blocked on our servers, including web requests through Cloudflare, since UTC, through UTC, and in feed.txt.
Record
- Score
- 51/100each request counts half as much after 30 days
- Worst level
- Relentless
- Attack-shaped requests
- 2,048all time
- Active days
- 2UTC days
- First seen
- Last seen
- Servers hit
- 3
- Targets
- 3sites
- Times blocked
- 0by the evidence rules
Its traffic requested a .env file, hoping to find API keys or database credentials; it also used a directory-traversal segment (literal or percent-encoded ../) in the request path to try to escape the web root; it also requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot.
Surfaces: web-app. Attack types: fake crawlers, known exploits, injection, scanning, hunting for secrets. Seen by: edge, web.
Activity, last 90 days
Active on 2 of the last 90 UTC days. Current block: to .
Daily counts
| Day (UTC) | Requests |
|---|---|
| 1,858 | |
| 190 |
- At least 342 requests a minute at its peak ( UTC; identical requests in the same second are stored once).
- Methods: GET 1,886, POST 153.
- The servers we watch answered: 403 1,776, 301 136, 404 85, 200 2 (totals only, from our web servers).
Evidence
Newest first, the latest 50 stored requests grouped into runs. Times are UTC. The user agent is shown as its family only.
| Time | Site | What happened | Request | User agent | Seen by |
|---|---|---|---|---|---|
| haived.com | 2× tried to abuse a PHP-CGI argument-injection flaw (allow_url_include/auto_prepend_file) to execute code (2 distinct paths) | POST /cgi-bin/php? | declared bot | web | |
| haived.com | fuzzed a short, random filename looking for a forgotten script that responds | POST /index.php? | declared bot | web | |
| haived.com | 2× tried to abuse a PHP-CGI argument-injection flaw (allow_url_include/auto_prepend_file) to execute code (2 distinct paths) | POST /cgi-bin/php? | declared bot | web | |
| haived.com | tried to abuse a local or remote file inclusion parameter such as allow_url_include | POST /php-cgi/php-cgi.exe? | declared bot | web | |
| haived.com | fuzzed a short, random filename looking for a forgotten script that responds | POST /index.php? | declared bot | web | |
| haived.com | claimed to be Googlebot while POSTing, something the real crawler never does | POST /api/designer/v1/file-content | declared bot | web | |
| servbg.dev | triggered Cloudflare's managed rule for a Next.js server-action request-smuggling/RCE attempt | POST /api/auth | declared bot | edge | |
| haived.com | requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot | GET /configuration.js | declared bot | web | |
| haived.com | 5× used a directory-traversal segment (literal or percent-encoded ../) in the request path to try to escape the web root (5 distinct paths) | GET /public../.env | declared bot | web | |
| haived.com | requested docker-compose.yml, which often contains embedded passwords and connection strings | GET /docker-compose.yaml | declared bot | web | |
| haived.com | used a directory-traversal segment (literal or percent-encoded ../) in the request path to try to escape the web root | GET /files../.env | declared bot | web | |
| haived.com | requested docker-compose.yml, which often contains embedded passwords and connection strings | GET /docker-compose.yml | declared bot | web | |
| haived.com | 2× used a directory-traversal segment (literal or percent-encoded ../) in the request path to try to escape the web root (2 distinct paths) | GET /media../.env | declared bot | web | |
| haived.com | 4× requested a .env file, hoping to find API keys or database credentials (4 distinct paths) | GET /dist/.env | declared bot | web | |
| haived.com | requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot | GET /credentials.json | declared bot | web | |
| haived.com | requested a .env file, hoping to find API keys or database credentials | GET /frontend/.env | declared bot | web | |
| haived.com | 2× requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot (2 distinct paths) | GET /secrets.json | declared bot | web | |
| haived.com | 2× requested a .env file, hoping to find API keys or database credentials (2 distinct paths) | GET /web/.env | declared bot | web | |
| haived.com | requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot | GET /.git-credentials | declared bot | web | |
| haived.com | 2× requested a .env file, hoping to find API keys or database credentials (2 distinct paths) | GET /public/.env | declared bot | web | |
| haived.com | 2× probed for an exposed .git directory to download the site's source history and config (2 distinct paths) | GET /.git/config | declared bot | web | |
| haived.com | requested an AWS credentials file left in a web-accessible path by mistake | GET /.aws/credentials | declared bot | web | |
| haived.com | requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot | GET /.aws/config | declared bot | web | |
| haived.com | 3× requested a .env file, hoping to find API keys or database credentials (3 distinct paths) | GET /core/.env | declared bot | web | |
| haived.com | 2× used a directory-traversal segment (literal or percent-encoded ../) in the request path to try to escape the web root (2 distinct paths) | GET /api/w/admins/jobs_u/get_log_file/../../../../proc/self/environ | declared bot | web | |
| haived.com | requested a .env file, hoping to find API keys or database credentials | GET /config/.env | declared bot | web | |
| haived.com | used a directory-traversal segment (literal or percent-encoded ../) in the request path to try to escape the web root | GET /api/console/api_server? | declared bot | web | |
| haived.com | requested a .env file, hoping to find API keys or database credentials | GET /backend/.env | declared bot | web | |
| haived.com | 2× requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot (2 distinct paths) | GET /config/gcp-credentials.json | declared bot | web | |
| haived.com | requested a .env file, hoping to find API keys or database credentials | GET /.env.prod | declared bot | web | |
| haived.com | requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot | GET /public/admin.json | declared bot | web | |
| haived.com | requested a .env file, hoping to find API keys or database credentials | GET /api/.env | declared bot | web | |
Network
- ASN
- AS396982 Google LLC
- Network type
- cloud
- Reverse DNS
38.190.179.34.bc.googleusercontent.com- Country
- Germany DE
- City
- Frankfurt am Main (registry location of a hosting network)
- Flags
- cloud range (GCP)
- Abuse contact
- found in the registry
- Checked