34.81.121.228
Blocked here
Blocked on our servers, including web requests through Cloudflare, since UTC, within minutes of its first clear attacks; not in feed.txt.
Record
- Score
- 41/100each request counts half as much after 30 days
- Worst level
- Brute
- Attack-shaped requests
- 171all time
- Active days
- 1UTC days
- First seen
- Last seen
- Servers hit
- 1
- Targets
- 1site
- Times blocked
- 0by the evidence rules
First seen on UTC, most recently active on UTC.
Recorded 171 attack-shaped requests across 1 separate day.
Its traffic requested a .env file, hoping to find API keys or database credentials (91 requests); it also used a directory-traversal segment (literal or percent-encoded ../) in the request path to try to escape the web root (31); it also requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot (11).
Seen by our web sensor, against dubstard.com.
Scored into the "Brute" level, its highest so far. Badge: Toolkit.
Its busiest hour on record began UTC, with 171 requests.
Routed via AS396982 (Google LLC), a cloud network.
Surfaces: web-app. Attack types: injection, scanning, hunting for secrets. Seen by: web.
Activity, last 90 days
Active on 1 of the last 90 UTC days. Current block: to .
Daily counts
| Day (UTC) | Requests |
|---|---|
| 171 |
- At least 171 requests a minute at its peak ( UTC; identical requests in the same second are stored once).
- Methods: GET 169, POST 1.
- The servers we watch answered: 404 158, 403 15 (totals only, from our web servers).
Evidence
Newest first, the latest 50 stored requests grouped into runs. Times are UTC. The user agent is shown as its family only.
| Time | Site | What happened | Request | User agent | Seen by |
|---|---|---|---|---|---|
| dubstard.com | probed for an exposed .svn directory to read the site's version-control metadata | /.svn | none | web | |
| dubstard.com | 2× requested a .env file, hoping to find API keys or database credentials (2 distinct paths) | GET /config/env/aws_credentials.env | declared bot | web | |
| dubstard.com | probed for an exposed .svn directory to read the site's version-control metadata | GET /.svn/entries | declared bot | web | |
| dubstard.com | 3× requested a private SSH key file by its conventional name (3 distinct paths) | GET /id_ed25519 | declared bot | web | |
| dubstard.com | made a request that matched no known pattern | GET /.gitconfig | declared bot | web | |
| dubstard.com | 8× requested a .env file, hoping to find API keys or database credentials (8 distinct paths) | GET /.env.live | declared bot | web | |
| dubstard.com | requested a .env file, hoping to find API keys or database credentials | GET /tmp/.env | declared bot | web | |
| dubstard.com | 33× requested a .env file, hoping to find API keys or database credentials (33 distinct paths) | GET /assets/.env | declared bot | web | |
Network
- ASN
- AS396982 Google LLC
- Network type
- cloud
- Reverse DNS
228.121.81.34.bc.googleusercontent.com- Country
- Taiwan TW
- City
- Taipei (registry location of a hosting network)
- Flags
- cloud range (GCP)
- Abuse contact
- found in the registry
- Checked