34.92.155.175

blockedPersistentRegularToolkit

Case file

First seen on 2026-09-25T23:19:04Z, most recently active on 2026-10-07T17:54:51Z.

Recorded 82 attack-shaped requests across 2 separate days.

Its traffic requested a .env file, hoping to find API keys or database credentials; it also requested the .git directory itself, hoping it is exposed and browsable; it also requested wp-config.php or a backup copy of it, hoping to read the database password in clear text.

Seen on our edge, web sensors.

Scored into the "Persistent" level, carrying the badges Regular, Toolkit.

Routed via AS396982 (Google LLC), an ASN we classify as cloud.

Blocked by the firewalls on our servers since 2026-10-07T18:00:06Z, through 2027-01-05T18:00:06Z.

Enrichment

rDNS175.155.92.34.bc.googleusercontent.com
ASNAS396982 — Google LLC
ASN typecloud
CountryHong Kong (HK)
FlagsCloud range

External references: GreyNoise, Shodan, AbuseIPDB

Timeline

Evidence (newest first, up to 50)

Time (UTC)VantageSiteClassStatusEvidence
2026-10-07T17:54:48Z – 2026-10-07T17:54:51Zwebhomocontinum.net4 × probed a Spring Boot actuator endpoint, which can leak environment variables and internal config if left open301GET /actuator/configprops -> 301 (2 distinct paths)
2026-10-07T17:54:14Z – 2026-10-07T17:54:17Zwebhomocontinum.net4 × requested a private SSH key file by its conventional name301GET /id_ed25519 -> 301 (2 distinct paths)
2026-10-07T17:53:50Zwebhomocontinum.net2 × requested .htaccess or .htpasswd, which can leak access rules or password hashes403GET /.htpasswd -> 403
2026-10-07T17:53:24Z – 2026-10-07T17:53:25Zwebhomocontinum.net2 × requested an AWS credentials file left in a web-accessible path by mistake301GET /.aws/credentials -> 301
2026-10-07T17:51:54Zwebhomocontinum.netrequested wp-config.php or a backup copy of it, hoping to read the database password in clear text301GET /wp-config.bak -> 301
2026-10-07T17:51:53Zwebhomocontinum.netprobed for an exposed .svn directory to read the site's version-control metadata403/.svn -> 403
2026-10-07T17:51:53Zedgehomocontinum.net6 × requested wp-config.php or a backup copy of it, hoping to read the database password in clear textGET /wp-config.php.bak (4 distinct paths)
2026-10-07T17:51:53Zwebhomocontinum.netrequested wp-config.php or a backup copy of it, hoping to read the database password in clear text301GET /wp-config.bak -> 301
2026-10-07T17:51:53Zwebhomocontinum.netprobed for an exposed .svn directory to read the site's version-control metadata403GET /.svn/entries -> 403
2026-10-07T17:51:52Zwebhomocontinum.netprobed for an exposed .svn directory to read the site's version-control metadata403/.svn -> 403
2026-10-07T17:51:52Zwebhomocontinum.netprobed for an exposed .svn directory to read the site's version-control metadata403GET /.svn/entries -> 403
2026-10-07T17:51:38Zwebhomocontinum.net4 × requested the .git directory itself, hoping it is exposed and browsable403/.git -> 403
2026-10-07T17:51:38Zwebhomocontinum.net3 × requested the .git directory itself, hoping it is exposed and browsable403GET /.git/credentials -> 403 (2 distinct paths)
2026-10-07T17:51:37Zwebhomocontinum.net5 × requested the .git directory itself, hoping it is exposed and browsable403/.git -> 403
2026-10-07T17:51:37Zwebhomocontinum.net5 × requested the .git directory itself, hoping it is exposed and browsable403GET /.git/config.save -> 403 (3 distinct paths)
2026-10-07T17:51:36Zwebhomocontinum.net3 × requested the .git directory itself, hoping it is exposed and browsable403/.git -> 403
2026-10-07T17:51:36Zwebhomocontinum.netrequested the .git directory itself, hoping it is exposed and browsable403GET /.git/config.old -> 403
2026-10-07T17:51:36Zwebhomocontinum.net2 × probed for an exposed .git directory to download the site's source history and config403GET /.git/config -> 403
2026-10-07T17:51:28Z – 2026-10-07T17:51:34Zwebhomocontinum.net3 × requested a .env file, hoping to find API keys or database credentials301GET /.env.js -> 301 (2 distinct paths)

Not currently correlated with any campaign.

Dispute or removal: [email protected] — reference 34.92.155.175. See /threats/about for the method and the 7-day review window.

card.svg (used as this page's og:image)