34.185.170.199
Case file
First seen on 2026-10-02T17:13:04Z, most recently active on 2026-10-06T11:21:48Z.
Recorded 420 attack-shaped requests across 2 separate days.
Its traffic requested a .env file, hoping to find API keys or database credentials; it also requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot; it also used a directory-traversal segment (literal or percent-encoded ../) in the request path to try to escape the web root.
Seen on our edge, web sensors.
Scored into the "Persistent" level, carrying the badges Regular, Toolkit.
Routed via AS396982 (Google LLC), an ASN we classify as cloud.
Blocked by the firewalls on our servers since 2026-10-06T11:30:05Z, through 2027-01-04T11:30:05Z.
Enrichment
| rDNS | 199.170.185.34.bc.googleusercontent.com |
|---|---|
| ASN | AS396982 — Google LLC |
| ASN type | cloud |
| Country | Germany (DE) |
| Flags | Cloud range |
Timeline
- 2026-10-02246
- 2026-10-06174
Evidence (newest first, up to 50)
| Time (UTC) | Vantage | Site | Class | Status | Evidence |
|---|---|---|---|---|---|
| 2026-10-06T11:21:48Z | web | schetio.com | 2 × tried to abuse a PHP-CGI argument-injection flaw (allow_url_include/auto_prepend_file) to execute code | 404 | GET /cgi-bin/php? -> 404 (2 distinct paths) |
| 2026-10-06T11:21:48Z | web | schetio.com | fuzzed a short, random filename looking for a forgotten script that responds | 404 | GET /index.php? -> 404 |
| 2026-10-06T11:21:47Z | web | schetio.com | 2 × tried to abuse a PHP-CGI argument-injection flaw (allow_url_include/auto_prepend_file) to execute code | 404 | GET /cgi-bin/php? -> 404 (2 distinct paths) |
| 2026-10-06T11:21:46Z | web | schetio.com | tried to abuse a local or remote file inclusion parameter such as allow_url_include | 404 | GET /php-cgi/php-cgi.exe? -> 404 |
| 2026-10-06T11:21:46Z | web | schetio.com | fuzzed a short, random filename looking for a forgotten script that responds | 404 | GET /index.php? -> 404 |
| 2026-10-06T11:21:43Z | web | schetio.com | probed a Spring Boot actuator endpoint, which can leak environment variables and internal config if left open | 404 | GET /actuator/gateway/routes -> 404 |
| 2026-10-06T11:21:42Z | web | schetio.com | swept a generic login/signup/account/dashboard route this site does not expose, consistent with an automated app-framework scanner | 404 | GET /api/v1/loginmethod? -> 404 |
| 2026-10-06T11:21:41Z | web | schetio.com | probed a Next.js/Auth.js (NextAuth) authentication route, consistent with fingerprinting a Next.js app's auth stack | 404 | GET /api/auth -> 404 |
| 2026-10-06T11:21:41Z | web | schetio.com | requested a generic /config or /api/config endpoint, hoping the app exposes its runtime configuration unauthenticated | 404 | GET /api/v1/configs -> 404 |
| 2026-10-06T11:21:40Z | web | schetio.com | probed a Next.js/Auth.js (NextAuth) authentication route, consistent with fingerprinting a Next.js app's auth stack | 404 | GET /api/auth -> 404 |
| 2026-10-06T11:21:40Z | web | schetio.com | probed a list of common site paths looking for an unprotected admin panel or staging copy | 404 | GET /admin -> 404 |
| 2026-10-06T11:21:40Z | web | schetio.com | 2 × swept a generic login/signup/account/dashboard route this site does not expose, consistent with an automated app-framework scanner | 404 | GET /dashboard -> 404 (2 distinct paths) |
| 2026-10-06T11:21:39Z | web | schetio.com | requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot | 404 | GET /app-config.json -> 404 |
| 2026-10-06T11:21:38Z | web | schetio.com | 2 × requested a generic /config or /api/config endpoint, hoping the app exposes its runtime configuration unauthenticated | 404 | GET /api/v2/config -> 404 (2 distinct paths) |
| 2026-10-06T11:21:38Z | web | schetio.com | requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot | 404 | GET /firebase-config.json -> 404 |
| 2026-10-06T11:21:37Z | web | schetio.com | requested a config.json file, hoping it exposes API keys or internal settings | 404 | GET /config.json -> 404 |
| 2026-10-06T11:21:37Z | web | schetio.com | requested a generic /config or /api/config endpoint, hoping the app exposes its runtime configuration unauthenticated | 404 | GET /api/config -> 404 |
| 2026-10-06T11:21:37Z | web | schetio.com | 2 × requested a .env file, hoping to find API keys or database credentials | 404 | GET /static/app/.env -> 404 (2 distinct paths) |
| 2026-10-06T11:21:37Z | web | schetio.com | 2 × requested a .env file, hoping to find API keys or database credentials | 403 | GET /.env -> 403 |
| 2026-10-06T11:21:37Z | web | schetio.com | requested a .env file, hoping to find API keys or database credentials | 404 | GET /static/.env -> 404 |
| 2026-10-06T11:21:37Z | web | schetio.com | 7 × used a directory-traversal segment (literal or percent-encoded ../) in the request path to try to escape the web root | 404 | GET /css../.env -> 404 (7 distinct paths) |
| 2026-10-06T11:21:36Z | web | schetio.com | probed for an exposed .svn directory to read the site's version-control metadata | 403 | /.svn -> 403 |
| 2026-10-06T11:21:36Z | web | schetio.com | used a directory-traversal segment (literal or percent-encoded ../) in the request path to try to escape the web root | 404 | GET /media../.env -> 404 |
| 2026-10-06T11:21:36Z | web | schetio.com | requested a .env file, hoping to find API keys or database credentials | 403 | GET /.env -> 403 |
| 2026-10-06T11:21:36Z | web | schetio.com | 4 × used a directory-traversal segment (literal or percent-encoded ../) in the request path to try to escape the web root | 404 | GET /files../.env -> 404 (4 distinct paths) |
| 2026-10-06T11:21:36Z | web | schetio.com | probed a WordPress admin/content path used to fingerprint the installation or hunt for an exposed upload/plugin surface | 404 | GET /wp-json -> 404 |
| 2026-10-06T11:21:36Z | web | schetio.com | requested a .env file, hoping to find API keys or database credentials | 404 | GET /api/.env/public/.env -> 404 |
| 2026-10-06T11:21:36Z | web | schetio.com | requested a config.json file, hoping it exposes API keys or internal settings | 404 | GET /.docker/config.json -> 404 |
| 2026-10-06T11:21:36Z | web | schetio.com | requested a .env file, hoping to find API keys or database credentials | 404 | GET /.github/.env -> 404 |
| 2026-10-06T11:21:36Z | web | schetio.com | probed for an exposed .svn directory to read the site's version-control metadata | 403 | GET /.svn/entries -> 403 |
| 2026-10-06T11:21:35Z | web | schetio.com | 4 × requested a private SSH key file by its conventional name | 404 | GET /id_ed25519 -> 404 (4 distinct paths) |
| 2026-10-06T11:21:35Z | web | schetio.com | made a request that matched no known pattern | 404 | GET /.gitconfig -> 404 |
Not currently correlated with any campaign.
Dispute or removal: [email protected] — reference 34.185.170.199. See /threats/about for the method and the 7-day review window.
card.svg (used as this page's og:image)