35.247.129.72
Blocked here
Blocked on our servers, including web requests through Cloudflare, since UTC, within minutes of its first clear attacks; not in feed.txt.
Record
- Score
- 38/100each request counts half as much after 30 days
- Worst level
- Brute
- Attack-shaped requests
- 104all time
- Active days
- 1UTC days
- First seen
- Last seen
- Servers hit
- 1
- Targets
- 1site
- Times blocked
- 0by the evidence rules
Its traffic requested a .env file, hoping to find API keys or database credentials; it also used a directory-traversal segment (literal or percent-encoded ../) in the request path to try to escape the web root; it also swept a generic login/signup/account/dashboard route this site does not expose, consistent with an automated app-framework scanner.
Surfaces: web-app. Attack types: known exploits, injection, scanning, hunting for secrets. Seen by: web.
Activity, last 90 days
Active on 1 of the last 90 UTC days. Current block: to .
Daily counts
| Day (UTC) | Requests |
|---|---|
| 104 |
- At least 76 requests a minute at its peak ( UTC; identical requests in the same second are stored once).
- Methods: GET 88, POST 8.
- The servers we watch answered: 403 55, 404 47, 200 2 (totals only, from our web servers).
Evidence
Newest first, the latest 50 stored requests grouped into runs. Times are UTC. The user agent is shown as its family only.
| Time | Site | What happened | Request | User agent | Seen by |
|---|---|---|---|---|---|
| servbg.com | 2× tried to abuse a PHP-CGI argument-injection flaw (allow_url_include/auto_prepend_file) to execute code (2 distinct paths) | POST /cgi-bin/php? | declared bot | web | |
| servbg.com | tried to abuse a local or remote file inclusion parameter such as allow_url_include | POST /index.php? | declared bot | web | |
| servbg.com | 2× tried to abuse a PHP-CGI argument-injection flaw (allow_url_include/auto_prepend_file) to execute code (2 distinct paths) | POST /cgi-bin/php? | declared bot | web | |
| servbg.com | tried to abuse a local or remote file inclusion parameter such as allow_url_include | POST /php-cgi/php-cgi.exe? | declared bot | web | |
| servbg.com | tried to abuse a local or remote file inclusion parameter such as allow_url_include | POST /index.php? | declared bot | web | |
| servbg.com | 3× requested a .env file, hoping to find API keys or database credentials (3 distinct paths) | GET /dist/.env | declared bot | web | |
| servbg.com | requested an AWS credentials file left in a web-accessible path by mistake | GET /.aws/credentials | declared bot | web | |
| servbg.com | 2× requested a .env file, hoping to find API keys or database credentials (2 distinct paths) | GET /core/.env | declared bot | web | |
| servbg.com | requested a generic /config or /api/config endpoint, hoping the app exposes its runtime configuration unauthenticated | /config | none | web | |
| servbg.com | 19× requested a .env file, hoping to find API keys or database credentials (19 distinct paths) | GET /frontend/.env | declared bot | web | |
| servbg.com | requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot | GET /push_config.json | declared bot | web | |
| servbg.com | 2× requested a generic /config or /api/config endpoint, hoping the app exposes its runtime configuration unauthenticated | /config | none | web | |
| servbg.com | 2× requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot (2 distinct paths) | GET /firebase-credentials.json | declared bot | web | |
| servbg.com | 2× requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot (2 distinct paths) | GET /config/gcp-credentials.json | declared bot | web | |
| servbg.com | 3× requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot (3 distinct paths) | GET /firebase-admin.json | declared bot | web | |
| servbg.com | used a directory-traversal segment (literal or percent-encoded ../) in the request path to try to escape the web root | GET /userfiles/x? | declared bot | web | |
| servbg.com | 4× swept a generic login/signup/account/dashboard route this site does not expose, consistent with an automated app-framework scanner (4 distinct paths) | GET /account | browser claim | web | |
| servbg.com | probed a Next.js/Auth.js (NextAuth) authentication route, consistent with fingerprinting a Next.js app's auth stack | GET /auth | browser claim | web | |
| servbg.com | probed a list of common site paths looking for an unprotected admin panel or staging copy | GET /admin | browser claim | web | |
Network
- ASN
- AS396982 Google LLC
- Network type
- cloud
- Reverse DNS
72.129.247.35.bc.googleusercontent.com- Country
- Singapore SG
- City
- Singapore (registry location of a hosting network)
- Flags
- cloud range (GCP)
- Abuse contact
- not found
- Checked