34.53.184.30
In feed.txt Relentless Regular Toolkit
Blocked on our servers, including web requests through Cloudflare, since UTC, through UTC, and in feed.txt.
Record
- Score
- 46/100each request counts half as much after 30 days
- Worst level
- Relentless
- Attack-shaped requests
- 218all time
- Active days
- 2UTC days
- First seen
- Last seen
- Servers hit
- 4
- Targets
- 3sites
- Times blocked
- 1by the evidence rules
Its traffic requested a .env file, hoping to find API keys or database credentials; it also probed for an exposed .git directory to download the site's source history and config; it also requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot.
Surfaces: web-app. Attack types: scanning, hunting for secrets. Seen by: edge, web.
Activity, last 90 days
Active on 2 of the last 90 UTC days. Current block: to .
Daily counts
| Day (UTC) | Requests |
|---|---|
| 82 | |
| 136 |
- At least 136 requests a minute at its peak ( UTC; identical requests in the same second are stored once).
- Methods: GET 217.
- The servers we watch answered: 301 134, 404 75, 403 9 (totals only, from our web servers).
Evidence
Newest first, the latest 50 stored requests grouped into runs. Times are UTC. The user agent is shown as its family only.
| Time | Site | What happened | Request | User agent | Seen by |
|---|---|---|---|---|---|
| vaibed.com | 2× requested wp-config.php or a backup copy of it, hoping to read the database password in clear text | GET /wp-config.php.bak | browser claim | edge | |
| haived.com | 3× requested a .env file, hoping to find API keys or database credentials (3 distinct paths) | GET /.env.paystack | browser claim | web | |
| haived.com | requested WordPress's debug.log, which can leak paths, queries or credentials left in debug output | GET /wp-content/debug.log | browser claim | web | |
| haived.com | 10× requested a .env file, hoping to find API keys or database credentials (10 distinct paths) | GET /web/.env | browser claim | web | |
| haived.com | requested phpinfo.php, which dumps the full PHP configuration and environment if left in place | GET /phpinfo.php | browser claim | web | |
| haived.com | 5× requested a .env file, hoping to find API keys or database credentials (5 distinct paths) | GET /old/.env | browser claim | web | |
| haived.com | requested docker-compose.yml, which often contains embedded passwords and connection strings | GET /docker-compose.yml | browser claim | web | |
| haived.com | 11× requested a .env file, hoping to find API keys or database credentials (11 distinct paths) | GET /dev/.env | browser claim | web | |
| haived.com | requested phpinfo.php, which dumps the full PHP configuration and environment if left in place | GET /api/phpinfo.php | browser claim | web | |
| haived.com | 2× requested a .env file, hoping to find API keys or database credentials (2 distinct paths) | GET /admin/.env | browser claim | web | |
| haived.com | 2× probed for an exposed .git directory to download the site's source history and config (2 distinct paths) | GET /.git/logs/HEAD | browser claim | web | |
| haived.com | requested the .git directory itself, hoping it is exposed and browsable | GET /.git/logs/refs/heads/main | browser claim | web | |
| haived.com | probed for an exposed .git directory to download the site's source history and config | GET /.git/config | browser claim | web | |
| haived.com | 9× requested a .env file, hoping to find API keys or database credentials (9 distinct paths) | GET /.env.staging | browser claim | web | |
Network
- ASN
- AS396982 Google LLC
- Network type
- cloud
- Reverse DNS
30.184.53.34.bc.googleusercontent.com- Country
- Belgium BE
- City
- Brussels (registry location of a hosting network)
- Flags
- cloud range (GCP)
- Abuse contact
- found in the registry
- Checked