๐ฉ๐ช
Gwyneth Llewelyn
2026-10-05 13:12:48
(59 minutes ago)
2026/10/05 14:12:46 [error] 3069275#3069275: *233585 access forbidden by rule, client: 34.62.1.174, ...
show more
2026/10/05 14:12:46 [error] 3069275#3069275: *233585 access forbidden by rule, client: 34.62.1.174, server: vp-arc.org, request: "GET /images../.env HTTP/2.0", host: "vp-arc.org"
2026/10/05 14:12:46 [error] 3069275#3069275: *233585 access forbidden by rule, client: 34.62.1.174, server: vp-arc.org, request: "GET /img../.env HTTP/2.0", host: "vp-arc.org"
2026/10/05 14:12:46 [error] 3069275#3069275: *233585 access forbidden by rule, client: 34.62.1.174, server: vp-arc.org, request: "GET /assets../.env HTTP/2.0", host: "vp-arc.org"
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 12:32:48
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.62.1.174 (174.1.62.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.62.1.174 (174.1.62.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 08:32:44.988031 2026] [security2:error] [pid 31654:tid 31654] [client 34.62.1.174:45854] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "schoolrx.org"] [uri "/%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env"] [unique_id "asOY7AZOLGxhEYa44uxRTgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-05 12:31:32
(1 hour ago)
34.62.1.174 - - [05/Oct/2026:07:31:31 -0500] "GET /.env?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Maci ...
show more
34.62.1.174 - - [05/Oct/2026:07:31:31 -0500] "GET /.env?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)" 34.62.1.174
34.62.1.174 - - [05/Oct/2026:07:31:31 -0500] "GET /.env?import&raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)" 34.62.1.174
34.62.1.174 - - [05/Oct/2026:07:31:31 -0500] "GET /.env?import&url&inline HTTP/1.1" 403 199 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)" 34.62.1.174
34.62.1.174 - - [05/Oct/2026:07:31:31 -0500] "GET /.env.local?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)" 34.62.1.174
34.62.1.174 - - [05/Oct/2026:07:31:31 -0500] "GET /.env.local?import&raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 34.62.1.174
34.62.
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Rocky Mountain Bioengineering Symposium
2026-10-05 12:27:06
(1 hour ago)
34.62.1.174 - - [05/Oct/2026:06:27:06 -0600] "POST /cgi-bin/php-cgi.exe?%ADd+allow_url_include%3d1+% ...
show more
34.62.1.174 - - [05/Oct/2026:06:27:06 -0600] "POST /cgi-bin/php-cgi.exe?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/2.0" 404 314 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)"
...
show less
Web App Attack
Anonymous
2026-10-05 12:24:28
(1 hour ago)
Logfile match
Web App Attack
๐ฉ๐ช
Blexyel
2026-10-05 12:13:32
(1 hour ago)
34.62.1.174 - - [05/Oct/2026:14:13:31 +0200] "POST /cgi-bin/php-cgi.exe?%ADd+allow_url_include%3d1+% ...
show more
34.62.1.174 - - [05/Oct/2026:14:13:31 +0200] "POST /cgi-bin/php-cgi.exe?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/1.1" 404 153 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)" "pingusmc.org"
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 12:02:57
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.62.1.174 (174.1.62.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.62.1.174 (174.1.62.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 08:02:53.944250 2026] [security2:error] [pid 15597:tid 15597] [client 34.62.1.174:43990] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "okeetokee.org"] [uri "/public../.env"] [unique_id "asOR7RClbYa05kDnssVa0wAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
melroy89
2026-10-05 11:39:04
(2 hours ago)
34.62.1.174 - - [05/Oct/2026:13:38:48 +0200] "GET /9jzpxexvmm0v9wt9zs53 HTTP/2.0" 403 93 "-" "Mozil ...
show more
34.62.1.174 - - [05/Oct/2026:13:38:48 +0200] "GET /9jzpxexvmm0v9wt9zs53 HTTP/2.0" 403 93 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)" "melroy.org" 0.001
34.62.1.174 - - [05/Oct/2026:13:38:48 +0200] "GET /z9x8c7v6b5-debug-trigger-melroy.org HTTP/2.0" 403 93 "-" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)" "melroy.org" 0.001
34.62.1.174 - - [05/Oct/2026:13:38:48 +0200] "POST / HTTP/2.0" 403 93 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)" "melroy.org" 0.000
34.62.1.174 - - [05/Oct/2026:13:38:48 +0200] "GET /g7qtnkpqyjnb95x0717w HTTP/2.0" 403 93 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36" "melroy.org" 0.000
34.62.1.174 - - [05/Oct/2026:13:38:48 +0200] "GET /assets/manifest.json HTTP/2.0" 403 64 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0" "melroy.org" 0.000
34.62.1.174 - - [05/Oct
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 11:34:32
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.62.1.174 (174.1.62.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.62.1.174 (174.1.62.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 07:34:25.747052 2026] [security2:error] [pid 1401:tid 1401] [client 34.62.1.174:42378] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mariettacaseyclub.org"] [uri "/.htpasswd"] [unique_id "asOLQWIGLefdJysLCdOkuQAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
WellSpring
2026-10-05 10:36:45
(3 hours ago)
Automated probe detected by Ody Sentinel / WellSpr.ing. Type: env_exposure. Path: /.env.development: ...
show more
Automated probe detected by Ody Sentinel / WellSpr.ing. Type: env_exposure. Path: /.env.development::$DATA. Auto-blocked after threshold exceeded. Dossier: https://wellspr.ing/dossier/sentinel-34-62-1-174
show less
Web App Attack
๐บ๐ธ
Sonoflet
2026-10-05 09:30:58
(4 hours ago)
CrowdSec detection | scenario: http-sensitive-files
Web App Attack
Exploited Host
๐ฉ๐ช
yitzhaq
2026-10-05 09:25:11
(4 hours ago)
34.62.1.174 - - [05/Oct/2026:11:25:07 +0200] "GET /.env?import&url&inline HTTP/2.0" 403 297 "-" "Moz ...
show more
34.62.1.174 - - [05/Oct/2026:11:25:07 +0200] "GET /.env?import&url&inline HTTP/2.0" 403 297 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email])"
34.62.1.174 - - [05/Oct/2026:11:25:07 +0200] "GET /__vite_rsc_findSourceMapURL?filename=file:///proc/self/environ&environmentName=rsc HTTP/2.0" 404 43270 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)"
34.62.1.174 - - [05/Oct/2026:11:25:07 +0200] "GET /__vite_rsc_findSourceMapURL?filename=file:///root/.aws/credentials&environmentName=rsc HTTP/2.0" 404 43270 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)"
34.62.1.174 - - [05/Oct/2026:11:25:07 +0200] "GET /__vite_rsc_findSourceMapURL?filename=file:///root/.ssh/id_rsa&environmentName=rsc HTTP/2.0" 404 43270 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot"
34.62.1.174 - - [05/Oct/2026:11:25:07 +0200] "GET /__vite_rsc_findSourceMapURL?filename=file:///app/.env&e
show less
Bad Web Bot
๐บ๐ธ
WellSpring
2026-10-05 08:53:18
(5 hours ago)
env leak on lawmuse.org/@fs/.env โ WellSpr.ing/NetSentinel civic-AI security layer
Web App Attack
๐ฌ๐ง
f3sc
2026-10-05 08:45:58
(5 hours ago)
34.62.1.174 - - [05/Oct/2026:09:45:57 +0100] "POST /api/graphql HTTP/2.0" 403 260 "https://last-stri ...
show more
34.62.1.174 - - [05/Oct/2026:09:45:57 +0100] "POST /api/graphql HTTP/2.0" 403 260 "https://last-strike.org" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
34.62.1.174 - - [05/Oct/2026:09:45:57 +0100] "POST /login HTTP/2.0" 403 250 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)"
show less
Port Scan
Hacking
Web App Attack
๐ซ๐ฎ
Kotisivu.org
2026-10-05 07:53:30
(6 hours ago)
Automated web scanner probe: GET /.ssh/id_rsa on kotisivu.org.
Brute-Force
Web App Attack