34.77.51.30
Blocked here
Blocked on our servers, including web requests through Cloudflare, since UTC, within minutes of its first clear attacks; not in feed.txt.
Record
- Score
- 40/100each request counts half as much after 30 days
- Worst level
- Persistent
- Attack-shaped requests
- 176all time
- Active days
- 1UTC days
- First seen
- Last seen
- Servers hit
- 2
- Targets
- 1site
- Times blocked
- 0by the evidence rules
Its traffic requested a .env file, hoping to find API keys or database credentials; it also used a directory-traversal segment (literal or percent-encoded ../) in the request path to try to escape the web root; it also requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot.
Surfaces: web-app. Attack types: fake crawlers, known exploits, injection, scanning, hunting for secrets, unclassified. Seen by: edge, web.
Activity, last 90 days
Active on 1 of the last 90 UTC days. Current block: to .
Daily counts
| Day (UTC) | Requests |
|---|---|
| 176 |
- At least 166 requests a minute at its peak ( UTC; identical requests in the same second are stored once).
- Methods: GET 153, POST 12, DELETE 1.
- The servers we watch answered: 404 141, 403 23, 200 2 (totals only, from our web servers).
Evidence
Newest first, the latest 50 stored requests grouped into runs. Times are UTC. The user agent is shown as its family only.
| Time | Site | What happened | Request | User agent | Seen by |
|---|---|---|---|---|---|
| foundyourjob.com | 2× tried to abuse a PHP-CGI argument-injection flaw (allow_url_include/auto_prepend_file) to execute code (2 distinct paths) | POST /cgi-bin/php? | declared bot | web | |
| foundyourjob.com | tried to abuse a local or remote file inclusion parameter such as allow_url_include | POST /index.php? | declared bot | web | |
| foundyourjob.com | was blocked at the edge without matching any specific attack signature | POST /api/templates/preview | declared bot | edge | |
| foundyourjob.com | 2× tried to abuse a PHP-CGI argument-injection flaw (allow_url_include/auto_prepend_file) to execute code (2 distinct paths) | POST /cgi-bin/php? | declared bot | web | |
| foundyourjob.com | tried to abuse a local or remote file inclusion parameter such as allow_url_include | POST /php-cgi/php-cgi.exe? | declared bot | web | |
| foundyourjob.com | tried to abuse a local or remote file inclusion parameter such as allow_url_include | POST /index.php? | declared bot | web | |
| foundyourjob.com | claimed to be Googlebot while POSTing, something the real crawler never does | POST /api/v1/validate/code | declared bot | web | |
| foundyourjob.com | was blocked at the edge without matching any specific attack signature | DELETE /api/events | declared bot | edge | |
| foundyourjob.com | requested a .env file, hoping to find API keys or database credentials | /.env | none | web | |
| foundyourjob.com | requested a .env file, hoping to find API keys or database credentials | GET /api/fs/read | declared bot | edge | |
| foundyourjob.com | triggered Cloudflare's managed rule for a Next.js server-action request-smuggling/RCE attempt | POST /api/auth | declared bot | edge | |
| foundyourjob.com | used a directory-traversal segment (literal or percent-encoded ../) in the request path to try to escape the web root | GET /userfiles | declared bot | edge | |
| foundyourjob.com | triggered Cloudflare's managed rule for a Next.js server-action request-smuggling/RCE attempt | POST /dashboard | declared bot | edge | |
| foundyourjob.com | used a directory-traversal segment (literal or percent-encoded ../) in the request path to try to escape the web root | GET /userfiles/x? | declared bot | web | |
| foundyourjob.com | requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot | GET /gcp-credentials.json | declared bot | web | |
| foundyourjob.com | tried to read /proc/self/environ to dump process environment variables, usually via a traversal or inclusion flaw | GET /api/system/fileView? | declared bot | web | |
| foundyourjob.com | used a directory-traversal segment (literal or percent-encoded ../) in the request path to try to escape the web root | GET /userfiles? | declared bot | web | |
| foundyourjob.com | requested a .env file, hoping to find API keys or database credentials | GET /api/system/fileView? | declared bot | web | |
| foundyourjob.com | 2× used a directory-traversal segment (literal or percent-encoded ../) in the request path to try to escape the web root | GET /userfiles? | declared bot | web | |
| foundyourjob.com | used a directory-traversal segment (literal or percent-encoded ../) in the request path to try to escape the web root | GET /cache/original/%2e%2e/%2e%2e/.env | declared bot | web | |
| foundyourjob.com | used a directory-traversal segment (literal or percent-encoded ../) in the request path to try to escape the web root | GET /cache/original/%2e%2e/.env | declared bot | web | |
| foundyourjob.com | tried to read /proc/self/environ to dump process environment variables, usually via a traversal or inclusion flaw | GET /api/fs/read? | declared bot | web | |
| foundyourjob.com | used a directory-traversal segment (literal or percent-encoded ../) in the request path to try to escape the web root | GET /api/w/starter/jobs_u/get_log_file/../../../../proc/self/environ | declared bot | web | |
| foundyourjob.com | requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot | GET /var/run/secrets/kubernetes.io/serviceaccount/token | declared bot | web | |
| foundyourjob.com | 2× requested a .env file, hoping to find API keys or database credentials | /.env | none | web | |
| foundyourjob.com | was blocked at the edge without matching any specific attack signature | GET /api/v1/models | declared bot | edge | |
| foundyourjob.com | fuzzed a short, random filename looking for a forgotten script that responds | GET /i.php | declared bot | web | |
| foundyourjob.com | 4× used a directory-traversal segment (literal or percent-encoded ../) in the request path to try to escape the web root (4 distinct paths) | GET /api/w/default/jobs_u/get_log_file/../../../../proc/self/environ | declared bot | web | |
| foundyourjob.com | fuzzed a short, random filename looking for a forgotten script that responds | GET /test.php | declared bot | web | |
| foundyourjob.com | probed a Spring Boot actuator endpoint, which can leak environment variables and internal config if left open | GET /actuator/configprops | declared bot | web | |
| foundyourjob.com | fuzzed a short, random filename looking for a forgotten script that responds | GET /pi.php | declared bot | web | |
| foundyourjob.com | requested a .env file, hoping to find API keys or database credentials | GET /settings%2F.env | declared bot | web | |
| foundyourjob.com | probed a Spring Boot actuator endpoint, which can leak environment variables and internal config if left open | GET /actuator/mappings | declared bot | web | |
| foundyourjob.com | requested phpinfo.php, which dumps the full PHP configuration and environment if left in place | GET /phpinfo.php | declared bot | web | |
| foundyourjob.com | probed a Spring Boot actuator endpoint, which can leak environment variables and internal config if left open | GET /actuator | declared bot | web | |
| foundyourjob.com | requested a .env file, hoping to find API keys or database credentials | GET /dashboard%2F.env | declared bot | web | |
| foundyourjob.com | probed for an exposed GraphQL endpoint or its config file, often a precursor to an introspection query | GET /graphql/console | declared bot | web | |
| foundyourjob.com | requested a .env file, hoping to find API keys or database credentials | GET /admin%2F.env | declared bot | web | |
| foundyourjob.com | 3× requested a generic /config or /api/config endpoint, hoping the app exposes its runtime configuration unauthenticated (3 distinct paths) | GET /v1/onboarding/config? | declared bot | web | |
| foundyourjob.com | requested a .env file, hoping to find API keys or database credentials | GET /static//app/.env | declared bot | web | |
| foundyourjob.com | requested a .env file, hoping to find API keys or database credentials | GET /.//.env | declared bot | web | |
Network
- ASN
- AS396982 Google LLC
- Network type
- cloud
- Reverse DNS
30.51.77.34.bc.googleusercontent.com- Country
- Belgium BE
- City
- Brussels (registry location of a hosting network)
- Flags
- cloud range (GCP)
- Abuse contact
- found in the registry
- Checked