34.79.12.228

In feed.txt Persistent Regular Toolkit

Blocked on our servers, including web requests through Cloudflare, since UTC, through UTC, and in feed.txt.

Record

Score
44/100each request counts half as much after 30 days
Worst level
Persistent
Attack-shaped requests
149all time
Active days
2UTC days
First seen
Last seen
Servers hit
3
Targets
2sites
Times blocked
1by the evidence rules

First seen on UTC, most recently active on UTC.

Recorded 149 attack-shaped requests across 2 separate days.

Its traffic requested a .env file, hoping to find API keys or database credentials (81 requests); it also requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot (27); it also requested a config.json file, hoping it exposes API keys or internal settings (7); 1 request matched no known pattern.

Seen by our edge and web sensors, against 2 of the sites we watch: amosix.eu and schetio.com.

Scored into the "Persistent" level, its highest so far. Badges: Regular and Toolkit.

Its busiest hour on record began UTC, with 95 requests.

Routed via AS396982 (Google LLC), a cloud network.

Surfaces: web-app. Attack types: scanning, hunting for secrets, unclassified. Seen by: edge, web.

Activity, last 90 days

Active on 2 of the last 90 UTC days. Current block: to .

Daily counts
Attack requests per UTC day, days with activity only
Day (UTC)Requests
121
28
  • At least 95 requests a minute at its peak ( UTC; identical requests in the same second are stored once).
  • Methods: GET 149.
  • The servers we watch answered: 404 113, 403 24 (totals only, from our web servers).

Evidence

Newest first, the latest 50 stored requests grouped into runs. Times are UTC. The user agent is shown as its family only.

Evidence, newest first, grouped by UTC day
TimeSiteWhat happenedRequestUser agentSeen by
amosix.eu5× requested a .env file, hoping to find API keys or database credentials (5 distinct paths)GET /test/.envbrowser claimedge
amosix.euwas blocked at the edge without matching any specific attack signatureGET /.aws/credentials.bakbrowser claimedge
amosix.eu2× requested a .env file, hoping to find API keys or database credentials (2 distinct paths)GET /laravel/.envbrowser claimedge
amosix.eu2× requested a .env file, hoping to find API keys or database credentials (2 distinct paths)GET /docker-compose.envbrowser claimweb
amosix.eurequested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webrootGET /credentials.jsonbrowser claimweb
amosix.eu3× made a request that matched no known pattern (3 distinct paths)GET /.influxdb/configbrowser claimweb
amosix.eurequested WordPress's debug.log, which can leak paths, queries or credentials left in debug outputGET /wp-content/debug.logbrowser claimweb
amosix.eumade a request that matched no known patternGET /.mongosh/configbrowser claimweb
amosix.eurequested a .env file, hoping to find API keys or database credentialsGET /sendgrid.envbrowser claimweb
amosix.eurequested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webrootGET /secrets.jsonbrowser claimweb
amosix.eurequested phpinfo.php, which dumps the full PHP configuration and environment if left in placeGET /phpinfo.phpbrowser claimweb
amosix.eufuzzed a short, random filename looking for a forgotten script that respondsGET /info.phpbrowser claimweb
amosix.eurequested docker-compose.yml, which often contains embedded passwords and connection stringsGET /docker-compose.ymlbrowser claimweb
amosix.eurequested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webrootGET /credentials.inibrowser claimweb
amosix.eurequested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webrootGET /credentialsbrowser claimweb
amosix.eufuzzed a short, random filename looking for a forgotten script that respondsGET /config.phpbrowser claimweb
amosix.eurequested a config.json file, hoping it exposes API keys or internal settingsGET /config.jsonbrowser claimweb
amosix.eu2× requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot (2 distinct paths)GET /config.yamlbrowser claimweb
amosix.eurequested phpinfo.php, which dumps the full PHP configuration and environment if left in placeGET /api/phpinfo.phpbrowser claimweb
amosix.eurequested a .env file, hoping to find API keys or database credentialsGET /config.envbrowser claimweb
amosix.eurequested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webrootGET /.aws/configbrowser claimweb
amosix.eurequested a config.json file, hoping it exposes API keys or internal settingsGET /.docker/config.jsonbrowser claimweb
amosix.eurequested an AWS credentials file left in a web-accessible path by mistakeGET /.aws/credentialsbrowser claimweb
schetio.comrequested wp-config.php or a backup copy of it, hoping to read the database password in clear textGET /wp-config.php.bakbrowser claimedge
schetio.com6× requested a .env file, hoping to find API keys or database credentials (6 distinct paths)GET /primary/.envbrowser claimweb
schetio.comrequested WordPress's debug.log, which can leak paths, queries or credentials left in debug outputGET /wp-content/debug.logbrowser claimweb
schetio.com4× requested a .env file, hoping to find API keys or database credentials (4 distinct paths)GET /tmp/.envbrowser claimweb
schetio.comrequested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webrootGET /runtime-config.jsbrowser claimweb
schetio.com5× requested a .env file, hoping to find API keys or database credentials (5 distinct paths)GET /staging/.envbrowser claimweb

Network

ASN
AS396982 Google LLC
Network type
cloud
Reverse DNS
228.12.79.34.bc.googleusercontent.com
Country
Belgium BE
City
Brussels (registry location of a hosting network)
Flags
cloud range (GCP)
Abuse contact
found in the registry
Checked

Elsewhere: GreyNoise, Shodan, AbuseIPDB.