34.19.173.83
Case file
First seen on 2026-10-05T16:28:43Z, most recently active on 2026-10-06T07:53:15Z.
Recorded 1771 attack-shaped requests across 2 separate days.
Its traffic requested a .env file, hoping to find API keys or database credentials; it also requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot; it also used a directory-traversal segment (literal or percent-encoded ../) in the request path to try to escape the web root.
Seen on our edge, web sensors.
Scored into the "Persistent" level, carrying the badges Regular, Toolkit.
Routed via AS396982 (Google LLC), an ASN we classify as cloud.
Blocked by the firewalls on our servers since 2026-10-06T06:50:04Z, through 2027-01-04T06:50:04Z.
Enrichment
| rDNS | 83.173.19.34.bc.googleusercontent.com |
|---|---|
| ASN | AS396982 — Google LLC |
| ASN type | cloud |
| Country | Canada (CA) |
| Flags | Cloud range |
Timeline
- 2026-10-05299
- 2026-10-061472
Evidence (newest first, up to 50)
| Time (UTC) | Vantage | Site | Class | Status | Evidence |
|---|---|---|---|---|---|
| 2026-10-06T07:53:15Z | web | obdebug.com | 2 × tried to abuse a PHP-CGI argument-injection flaw (allow_url_include/auto_prepend_file) to execute code | 404 | GET /cgi-bin/php? -> 404 (2 distinct paths) |
| 2026-10-06T07:53:15Z | web | obdebug.com | fuzzed a short, random filename looking for a forgotten script that responds | 404 | GET /index.php? -> 404 |
| 2026-10-06T07:53:14Z | web | obdebug.com | 2 × tried to abuse a PHP-CGI argument-injection flaw (allow_url_include/auto_prepend_file) to execute code | 404 | GET /cgi-bin/php? -> 404 (2 distinct paths) |
| 2026-10-06T07:53:14Z | web | obdebug.com | tried to abuse a local or remote file inclusion parameter such as allow_url_include | 404 | GET /php-cgi/php-cgi.exe? -> 404 |
| 2026-10-06T07:53:14Z | web | obdebug.com | fuzzed a short, random filename looking for a forgotten script that responds | 404 | GET /index.php? -> 404 |
| 2026-10-06T07:53:11Z | edge | obdebug.com | 4 × triggered Cloudflare's managed rule for a Next.js server-action request-smuggling/RCE attempt | POST /api/auth (4 distinct paths) | |
| 2026-10-06T07:53:11Z | web | obdebug.com | probed a Spring Boot actuator endpoint, which can leak environment variables and internal config if left open | 404 | GET /actuator/configprops -> 404 |
| 2026-10-06T07:53:11Z | web | obdebug.com | requested a generic /config or /api/config endpoint, hoping the app exposes its runtime configuration unauthenticated | 404 | GET /api/config -> 404 |
| 2026-10-06T07:53:10Z | web | obdebug.com | probed for an exposed GraphQL endpoint or its config file, often a precursor to an introspection query | 404 | GET /graphql -> 404 |
| 2026-10-06T07:53:10Z | web | obdebug.com | probed a Spring Boot actuator endpoint, which can leak environment variables and internal config if left open | 404 | GET /actuator -> 404 |
| 2026-10-06T07:53:10Z | web | obdebug.com | requested a generic /config or /api/config endpoint, hoping the app exposes its runtime configuration unauthenticated | 404 | GET /v1/onboarding/config? -> 404 |
| 2026-10-06T07:53:10Z | web | obdebug.com | probed for an exposed GraphQL endpoint or its config file, often a precursor to an introspection query | 404 | GET /graphql/console -> 404 |
| 2026-10-06T07:53:10Z | web | obdebug.com | 4 × requested a generic /config or /api/config endpoint, hoping the app exposes its runtime configuration unauthenticated | 404 | GET /api/4/config -> 404 (4 distinct paths) |
| 2026-10-06T07:53:10Z | web | obdebug.com | fuzzed a short, random filename looking for a forgotten script that responds | 404 | GET /test.php -> 404 |
| 2026-10-06T07:53:10Z | web | obdebug.com | requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot | 404 | GET /firebase-config.json -> 404 |
| 2026-10-06T07:53:10Z | web | obdebug.com | 2 × fuzzed a short, random filename looking for a forgotten script that responds | 404 | GET /i.php -> 404 (2 distinct paths) |
| 2026-10-06T07:53:09Z | web | obdebug.com | probed for an exposed .svn directory to read the site's version-control metadata | 403 | /.svn -> 403 |
| 2026-10-06T07:53:09Z | web | obdebug.com | requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot | 404 | GET /app-config.json -> 404 |
| 2026-10-06T07:53:09Z | web | obdebug.com | fuzzed a short, random filename looking for a forgotten script that responds | 404 | GET /info.php -> 404 |
| 2026-10-06T07:53:09Z | web | obdebug.com | requested phpinfo.php, which dumps the full PHP configuration and environment if left in place | 404 | GET /phpinfo.php -> 404 |
| 2026-10-06T07:53:09Z | web | obdebug.com | probed a Spring Boot actuator endpoint, which can leak environment variables and internal config if left open | 404 | GET /actuator/mappings -> 404 |
| 2026-10-06T07:53:09Z | web | obdebug.com | requested a generic /config or /api/config endpoint, hoping the app exposes its runtime configuration unauthenticated | 404 | GET /api/config -> 404 |
| 2026-10-06T07:53:09Z | web | obdebug.com | requested a config.json file, hoping it exposes API keys or internal settings | 404 | GET /config.json -> 404 |
| 2026-10-06T07:53:09Z | web | obdebug.com | probed a Spring Boot actuator endpoint, which can leak environment variables and internal config if left open | 404 | GET /actuator/loggers -> 404 |
| 2026-10-06T07:53:09Z | web | obdebug.com | probed a WordPress admin/content path used to fingerprint the installation or hunt for an exposed upload/plugin surface | 404 | GET /wp-json -> 404 |
| 2026-10-06T07:53:09Z | web | obdebug.com | 2 × requested a .env file, hoping to find API keys or database credentials | 404 | GET /config/env/aws_credentials.env -> 404 (2 distinct paths) |
| 2026-10-06T07:53:09Z | web | obdebug.com | requested a config.json file, hoping it exposes API keys or internal settings | 404 | GET /.docker/config.json -> 404 |
| 2026-10-06T07:53:09Z | web | obdebug.com | probed for an exposed .svn directory to read the site's version-control metadata | 403 | GET /.svn/entries -> 403 |
| 2026-10-06T07:53:08Z | web | obdebug.com | 4 × requested a private SSH key file by its conventional name | 404 | GET /id_ed25519 -> 404 (4 distinct paths) |
| 2026-10-06T07:53:08Z | web | obdebug.com | made a request that matched no known pattern | 404 | GET /.gitconfig -> 404 |
| 2026-10-06T07:53:08Z | web | obdebug.com | 7 × requested a .env file, hoping to find API keys or database credentials | 404 | GET /.env.www -> 404 (7 distinct paths) |
Not currently correlated with any campaign.
Dispute or removal: [email protected] — reference 34.19.173.83. See /threats/about for the method and the 7-day review window.
card.svg (used as this page's og:image)