34.19.173.83

blockedPersistentRegularToolkit

Case file

First seen on 2026-10-05T16:28:43Z, most recently active on 2026-10-06T07:53:15Z.

Recorded 1771 attack-shaped requests across 2 separate days.

Its traffic requested a .env file, hoping to find API keys or database credentials; it also requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot; it also used a directory-traversal segment (literal or percent-encoded ../) in the request path to try to escape the web root.

Seen on our edge, web sensors.

Scored into the "Persistent" level, carrying the badges Regular, Toolkit.

Routed via AS396982 (Google LLC), an ASN we classify as cloud.

Blocked by the firewalls on our servers since 2026-10-06T06:50:04Z, through 2027-01-04T06:50:04Z.

Enrichment

rDNS83.173.19.34.bc.googleusercontent.com
ASNAS396982 — Google LLC
ASN typecloud
CountryCanada (CA)
FlagsCloud range

External references: GreyNoise, Shodan, AbuseIPDB

Timeline

Evidence (newest first, up to 50)

Time (UTC)VantageSiteClassStatusEvidence
2026-10-06T07:53:15Zwebobdebug.com2 × tried to abuse a PHP-CGI argument-injection flaw (allow_url_include/auto_prepend_file) to execute code404GET /cgi-bin/php? -> 404 (2 distinct paths)
2026-10-06T07:53:15Zwebobdebug.comfuzzed a short, random filename looking for a forgotten script that responds404GET /index.php? -> 404
2026-10-06T07:53:14Zwebobdebug.com2 × tried to abuse a PHP-CGI argument-injection flaw (allow_url_include/auto_prepend_file) to execute code404GET /cgi-bin/php? -> 404 (2 distinct paths)
2026-10-06T07:53:14Zwebobdebug.comtried to abuse a local or remote file inclusion parameter such as allow_url_include404GET /php-cgi/php-cgi.exe? -> 404
2026-10-06T07:53:14Zwebobdebug.comfuzzed a short, random filename looking for a forgotten script that responds404GET /index.php? -> 404
2026-10-06T07:53:11Zedgeobdebug.com4 × triggered Cloudflare's managed rule for a Next.js server-action request-smuggling/RCE attemptPOST /api/auth (4 distinct paths)
2026-10-06T07:53:11Zwebobdebug.comprobed a Spring Boot actuator endpoint, which can leak environment variables and internal config if left open404GET /actuator/configprops -> 404
2026-10-06T07:53:11Zwebobdebug.comrequested a generic /config or /api/config endpoint, hoping the app exposes its runtime configuration unauthenticated404GET /api/config -> 404
2026-10-06T07:53:10Zwebobdebug.comprobed for an exposed GraphQL endpoint or its config file, often a precursor to an introspection query404GET /graphql -> 404
2026-10-06T07:53:10Zwebobdebug.comprobed a Spring Boot actuator endpoint, which can leak environment variables and internal config if left open404GET /actuator -> 404
2026-10-06T07:53:10Zwebobdebug.comrequested a generic /config or /api/config endpoint, hoping the app exposes its runtime configuration unauthenticated404GET /v1/onboarding/config? -> 404
2026-10-06T07:53:10Zwebobdebug.comprobed for an exposed GraphQL endpoint or its config file, often a precursor to an introspection query404GET /graphql/console -> 404
2026-10-06T07:53:10Zwebobdebug.com4 × requested a generic /config or /api/config endpoint, hoping the app exposes its runtime configuration unauthenticated404GET /api/4/config -> 404 (4 distinct paths)
2026-10-06T07:53:10Zwebobdebug.comfuzzed a short, random filename looking for a forgotten script that responds404GET /test.php -> 404
2026-10-06T07:53:10Zwebobdebug.comrequested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot404GET /firebase-config.json -> 404
2026-10-06T07:53:10Zwebobdebug.com2 × fuzzed a short, random filename looking for a forgotten script that responds404GET /i.php -> 404 (2 distinct paths)
2026-10-06T07:53:09Zwebobdebug.comprobed for an exposed .svn directory to read the site's version-control metadata403/.svn -> 403
2026-10-06T07:53:09Zwebobdebug.comrequested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot404GET /app-config.json -> 404
2026-10-06T07:53:09Zwebobdebug.comfuzzed a short, random filename looking for a forgotten script that responds404GET /info.php -> 404
2026-10-06T07:53:09Zwebobdebug.comrequested phpinfo.php, which dumps the full PHP configuration and environment if left in place404GET /phpinfo.php -> 404
2026-10-06T07:53:09Zwebobdebug.comprobed a Spring Boot actuator endpoint, which can leak environment variables and internal config if left open404GET /actuator/mappings -> 404
2026-10-06T07:53:09Zwebobdebug.comrequested a generic /config or /api/config endpoint, hoping the app exposes its runtime configuration unauthenticated404GET /api/config -> 404
2026-10-06T07:53:09Zwebobdebug.comrequested a config.json file, hoping it exposes API keys or internal settings404GET /config.json -> 404
2026-10-06T07:53:09Zwebobdebug.comprobed a Spring Boot actuator endpoint, which can leak environment variables and internal config if left open404GET /actuator/loggers -> 404
2026-10-06T07:53:09Zwebobdebug.comprobed a WordPress admin/content path used to fingerprint the installation or hunt for an exposed upload/plugin surface404GET /wp-json -> 404
2026-10-06T07:53:09Zwebobdebug.com2 × requested a .env file, hoping to find API keys or database credentials404GET /config/env/aws_credentials.env -> 404 (2 distinct paths)
2026-10-06T07:53:09Zwebobdebug.comrequested a config.json file, hoping it exposes API keys or internal settings404GET /.docker/config.json -> 404
2026-10-06T07:53:09Zwebobdebug.comprobed for an exposed .svn directory to read the site's version-control metadata403GET /.svn/entries -> 403
2026-10-06T07:53:08Zwebobdebug.com4 × requested a private SSH key file by its conventional name404GET /id_ed25519 -> 404 (4 distinct paths)
2026-10-06T07:53:08Zwebobdebug.commade a request that matched no known pattern404GET /.gitconfig -> 404
2026-10-06T07:53:08Zwebobdebug.com7 × requested a .env file, hoping to find API keys or database credentials404GET /.env.www -> 404 (7 distinct paths)

Not currently correlated with any campaign.

Dispute or removal: [email protected] — reference 34.19.173.83. See /threats/about for the method and the 7-day review window.

card.svg (used as this page's og:image)