34.34.160.116
Case file
First seen on 2026-10-04T23:56:54Z, most recently active on 2026-10-05T10:12:53Z.
Recorded 180 attack-shaped requests across 2 separate days.
Its traffic requested a .env file, hoping to find API keys or database credentials; it also requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot; it also requested the .git directory itself, hoping it is exposed and browsable.
Seen on our edge, web sensors.
Scored into the "Persistent" level, carrying the badges Regular, Toolkit.
Routed via AS396982 (Google LLC), an ASN we classify as cloud.
Blocked by the firewalls on our servers since 2026-10-05T10:20:03Z, through 2027-01-03T10:20:03Z.
Enrichment
| rDNS | 116.160.34.34.bc.googleusercontent.com |
|---|---|
| ASN | AS396982 — Google LLC |
| ASN type | cloud |
| Country | Belgium (BE) |
| Flags | Cloud range |
Timeline
- 2026-10-0490
- 2026-10-0590
Evidence (newest first, up to 50)
| Time (UTC) | Vantage | Site | Class | Status | Evidence |
|---|---|---|---|---|---|
| 2026-10-05T10:12:53Z | web | neutralizatori.com | 6 × requested the .git directory itself, hoping it is exposed and browsable | 403 | /.git -> 403 |
| 2026-10-05T10:12:53Z | edge | neutralizatori.com | requested wp-config.php or a backup copy of it, hoping to read the database password in clear text | GET /wp-config.php.bak | |
| 2026-10-05T10:12:53Z | web | neutralizatori.com | requested the .git directory itself, hoping it is exposed and browsable | 403 | GET /.git/config.old -> 403 |
| 2026-10-05T10:12:53Z | web | neutralizatori.com | made a request that matched no known pattern | 404 | GET /.gitconfig -> 404 |
| 2026-10-05T10:12:53Z | web | neutralizatori.com | requested the .git directory itself, hoping it is exposed and browsable | 403 | GET /.git/config.bak -> 403 |
| 2026-10-05T10:12:53Z | web | neutralizatori.com | requested a .env file, hoping to find API keys or database credentials | 404 | GET /web/.env -> 404 |
| 2026-10-05T10:12:53Z | web | neutralizatori.com | requested WordPress's debug.log, which can leak paths, queries or credentials left in debug output | 404 | GET /wp-content/debug.log -> 404 |
| 2026-10-05T10:12:53Z | web | neutralizatori.com | 6 × requested a .env file, hoping to find API keys or database credentials | 404 | GET /v1/.env -> 404 (6 distinct paths) |
| 2026-10-05T10:12:53Z | web | neutralizatori.com | requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot | 404 | GET /runtime-config.js -> 404 |
| 2026-10-05T10:12:53Z | web | neutralizatori.com | 2 × requested a .env file, hoping to find API keys or database credentials | 404 | GET /v2/.env -> 404 (2 distinct paths) |
| 2026-10-05T10:12:53Z | web | neutralizatori.com | requested phpinfo.php, which dumps the full PHP configuration and environment if left in place | 404 | GET /phpinfo.php -> 404 |
| 2026-10-05T10:12:53Z | web | neutralizatori.com | requested a .env file, hoping to find API keys or database credentials | 301 | GET /old/.env -> 301 |
| 2026-10-05T10:12:53Z | web | neutralizatori.com | 2 × requested a .env file, hoping to find API keys or database credentials | 404 | GET /media/.env -> 404 (2 distinct paths) |
| 2026-10-05T10:12:53Z | web | neutralizatori.com | requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot | 404 | GET /secrets.json -> 404 |
| 2026-10-05T10:12:53Z | web | neutralizatori.com | requested a .env file, hoping to find API keys or database credentials | 404 | GET /public/.env -> 404 |
| 2026-10-05T10:12:53Z | web | neutralizatori.com | fuzzed a short, random filename looking for a forgotten script that responds | 404 | GET /info.php -> 404 |
| 2026-10-05T10:12:53Z | web | neutralizatori.com | requested the .git directory itself, hoping it is exposed and browsable | 403 | GET /.git/logs/refs/heads/main -> 403 |
| 2026-10-05T10:12:53Z | web | neutralizatori.com | requested a .env file, hoping to find API keys or database credentials | 301 | GET /new/.env -> 301 |
| 2026-10-05T10:12:53Z | web | neutralizatori.com | probed for an exposed .git directory to download the site's source history and config | 403 | GET /.git/logs/HEAD -> 403 |
| 2026-10-05T10:12:53Z | web | neutralizatori.com | requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot | 404 | GET /.git-credentials -> 404 |
| 2026-10-05T10:12:53Z | web | neutralizatori.com | 2 × probed for an exposed .git directory to download the site's source history and config | 403 | GET /.git/index -> 403 (2 distinct paths) |
| 2026-10-05T10:12:53Z | web | neutralizatori.com | 15 × requested a .env file, hoping to find API keys or database credentials | 404 | GET /frontend/.env -> 404 (15 distinct paths) |
| 2026-10-05T10:12:53Z | web | neutralizatori.com | requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot | 404 | GET /env-config.js -> 404 |
Not currently correlated with any campaign.
Dispute or removal: [email protected] — reference 34.34.160.116. See /threats/about for the method and the 7-day review window.
card.svg (used as this page's og:image)