8.231.206.27
Case file
First seen on 2026-10-04T14:10:42Z, most recently active on 2026-10-04T22:04:18Z.
Recorded 406 attack-shaped requests across 1 separate day.
Its traffic requested a .env file, hoping to find API keys or database credentials; it also used a directory-traversal segment (literal or percent-encoded ../) in the request path to try to escape the web root; it also requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot.
Seen on our edge, web sensors.
Scored into the "Persistent" level, carrying the badge Toolkit.
Routed via AS396982 (Google LLC), an ASN we classify as cloud.
Recorded internally; has not yet crossed the bar for a public listing.
Enrichment
| rDNS | 27.206.231.8.bc.googleusercontent.com |
|---|---|
| ASN | AS396982 — Google LLC |
| ASN type | cloud |
| Country | United States (US) |
| Flags | Cloud range |
Timeline
- 2026-10-04406
Evidence (newest first, up to 50)
| Time (UTC) | Vantage | Site | Class | Status | Evidence |
|---|---|---|---|---|---|
| 2026-10-04T22:04:18Z | web | servbg.com | probed a Spring Boot actuator endpoint, which can leak environment variables and internal config if left open | 404 | GET /actuator/gateway/routes -> 404 |
| 2026-10-04T22:04:18Z | web | servbg.com | 2 × tried to abuse a PHP-CGI argument-injection flaw (allow_url_include/auto_prepend_file) to execute code | 404 | GET /cgi-bin/php? -> 404 (2 distinct paths) |
| 2026-10-04T22:04:18Z | web | servbg.com | swept a generic login/signup/account/dashboard route this site does not expose, consistent with an automated app-framework scanner | 404 | GET /api/v1/loginmethod? -> 404 |
| 2026-10-04T22:04:17Z | web | servbg.com | tried to abuse a local or remote file inclusion parameter such as allow_url_include | 200 | GET /index.php? -> 200 |
| 2026-10-04T22:04:17Z | web | servbg.com | tried to abuse a PHP-CGI argument-injection flaw (allow_url_include/auto_prepend_file) to execute code | 404 | GET /cgi-bin/php? -> 404 |
| 2026-10-04T22:04:17Z | web | servbg.com | probed a Next.js/Auth.js (NextAuth) authentication route, consistent with fingerprinting a Next.js app's auth stack | 404 | GET /api/auth -> 404 |
| 2026-10-04T22:04:17Z | web | servbg.com | tried to abuse a PHP-CGI argument-injection flaw (allow_url_include/auto_prepend_file) to execute code | 404 | GET /cgi-bin/php-cgi.exe? -> 404 |
| 2026-10-04T22:04:17Z | web | servbg.com | requested a generic /config or /api/config endpoint, hoping the app exposes its runtime configuration unauthenticated | 404 | GET /api/v1/configs -> 404 |
| 2026-10-04T22:04:16Z | web | servbg.com | 3 × requested a .env file, hoping to find API keys or database credentials | 403 | /.env -> 403 |
| 2026-10-04T22:04:16Z | web | servbg.com | tried to abuse a local or remote file inclusion parameter such as allow_url_include | 404 | GET /php-cgi/php-cgi.exe? -> 404 |
| 2026-10-04T22:04:16Z | web | servbg.com | tried to abuse a local or remote file inclusion parameter such as allow_url_include | 200 | GET /index.php? -> 200 |
| 2026-10-04T22:04:16Z | web | servbg.com | 3 × requested a .env file, hoping to find API keys or database credentials | 403 | GET /.env? -> 403 (2 distinct paths) |
| 2026-10-04T22:04:16Z | web | servbg.com | requested a Vite/React-Server-Components source map, likely while mapping the app's bundled source | 404 | GET /__vite_rsc_findSourceMapURL? -> 404 |
| 2026-10-04T22:04:16Z | web | servbg.com | 3 × requested a .env file, hoping to find API keys or database credentials | 403 | GET /.env.production? -> 403 (2 distinct paths) |
| 2026-10-04T22:04:16Z | web | servbg.com | requested a Vite/React-Server-Components source map, likely while mapping the app's bundled source | 404 | GET /__vite_rsc_findSourceMapURL? -> 404 |
| 2026-10-04T22:04:16Z | web | servbg.com | requested a .env file, hoping to find API keys or database credentials | 403 | GET /.env? -> 403 |
| 2026-10-04T22:04:16Z | web | servbg.com | requested wp-config.php or a backup copy of it, hoping to read the database password in clear text | 403 | GET /wp-config.old -> 403 |
| 2026-10-04T22:04:16Z | web | servbg.com | requested a Vite/React-Server-Components source map, likely while mapping the app's bundled source | 404 | GET /__vite_rsc_findSourceMapURL? -> 404 |
| 2026-10-04T22:04:15Z | edge | servbg.com | 3 × requested wp-config.php or a backup copy of it, hoping to read the database password in clear text | GET /wp-config.php~ (3 distinct paths) | |
| 2026-10-04T22:04:15Z | web | servbg.com | requested a Vite/React-Server-Components source map, likely while mapping the app's bundled source | 404 | GET /__vite_rsc_findSourceMapURL? -> 404 |
| 2026-10-04T22:04:15Z | web | servbg.com | requested a .env file, hoping to find API keys or database credentials | 403 | GET /wp/.env -> 403 |
| 2026-10-04T22:04:15Z | web | servbg.com | 2 × used Vite dev server's @fs/ path to try to read arbitrary files outside the project root | 404 | GET /@fs/proc/self/cmdline? -> 404 (2 distinct paths) |
| 2026-10-04T22:04:15Z | web | servbg.com | 5 × requested a .env file, hoping to find API keys or database credentials | 403 | GET /api/.env -> 403 (5 distinct paths) |
| 2026-10-04T22:04:15Z | web | servbg.com | 2 × requested a database dump or site archive by its common backup filename | 403 | GET /config.php.bak -> 403 (2 distinct paths) |
| 2026-10-04T22:04:15Z | web | servbg.com | requested a .env file, hoping to find API keys or database credentials | 403 | GET /.env.old -> 403 |
| 2026-10-04T22:04:15Z | web | servbg.com | requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot | 404 | GET /credentials.json -> 404 |
| 2026-10-04T22:04:15Z | web | servbg.com | 7 × requested a .env file, hoping to find API keys or database credentials | 403 | GET /.env.bak -> 403 (7 distinct paths) |
| 2026-10-04T22:04:15Z | web | servbg.com | requested docker-compose.yml, which often contains embedded passwords and connection strings | 404 | GET /docker-compose.yml -> 404 |
| 2026-10-04T22:04:15Z | web | servbg.com | requested a .env file, hoping to find API keys or database credentials | 403 | GET /.env.example -> 403 |
Not currently correlated with any campaign.
Dispute or removal: [email protected] — reference 8.231.206.27. See /threats/about for the method and the 7-day review window.
card.svg (used as this page's og:image)