34.97.233.3
Case file
First seen on 2026-10-04T22:00:06Z, most recently active on 2026-10-04T22:01:10Z.
Recorded 207 attack-shaped requests across 1 separate day.
Its traffic requested a .env file, hoping to find API keys or database credentials; it also requested the .git directory itself, hoping it is exposed and browsable; it also probed for an exposed .git directory to download the site's source history and config.
Seen on our web sensor.
Scored into the "Brute" level, carrying the badge Toolkit.
Routed via AS396982 (Google LLC), an ASN we classify as cloud.
Recorded internally; has not yet crossed the bar for a public listing.
Enrichment
| rDNS | 3.233.97.34.bc.googleusercontent.com |
|---|---|
| ASN | AS396982 — Google LLC |
| ASN type | cloud |
| Country | Japan (JP) |
| Flags | Cloud range |
Timeline
- 2026-10-04207
Evidence (newest first, up to 50)
| Time (UTC) | Vantage | Site | Class | Status | Evidence |
|---|---|---|---|---|---|
| 2026-10-04T22:01:10Z | web | 4emx.com | requested phpinfo.php, which dumps the full PHP configuration and environment if left in place | 301 | GET /wp-admin/phpinfo.php -> 301 |
| 2026-10-04T22:00:52Z – 2026-10-04T22:00:59Z | web | 4emx.com | 27 × requested a .env file, hoping to find API keys or database credentials | 301 | GET /config/app/.env -> 301 (27 distinct paths) |
| 2026-10-04T22:00:51Z | web | 4emx.com | requested the .git directory itself, hoping it is exposed and browsable | 403 | /.git -> 403 |
| 2026-10-04T22:00:51Z | web | 4emx.com | requested a .env file, hoping to find API keys or database credentials | 301 | GET /ci/.env -> 301 |
| 2026-10-04T22:00:51Z | web | 4emx.com | requested a .env file, hoping to find API keys or database credentials | 403 | GET /.git/.env -> 403 |
| 2026-10-04T22:00:46Z – 2026-10-04T22:00:51Z | web | 4emx.com | 19 × requested a .env file, hoping to find API keys or database credentials | 301 | GET /ansible/.env -> 301 (19 distinct paths) |
Not currently correlated with any campaign.
Dispute or removal: [email protected] — reference 34.97.233.3. See /threats/about for the method and the 7-day review window.
card.svg (used as this page's og:image)