Edit: /var/log/modsec_audit.log (546063B)
--babed52b-A--
[31/Aug/2026:04:05:40.384691 +0300] apTTZCfaLSuAj0yzdueSCAAAAAQ 34.28.26.247 57832 127.0.0.1 7081
--babed52b-B--
GET /.git/config HTTP/1.1
Host: mediabuy.ro
X-Real-IP: 34.28.26.247
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36
Accept: */*
--babed52b-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/7.3.33
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--babed52b-H--
Message: Warning. Matched phrase "/.git/config" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.git/config||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"]
Message: Warning. Matched phrase "/.git/config" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.git/config||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"]
Message: Warning. String match "/.git/" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "656"] [id "77318034"] [msg "IM360 WAF: Blocked access to git folder||T:APACHE||MV:/.git/config||"] [severity "NOTICE"] [tag "service_i360custom"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "/.git/config" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.git/config||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "mediabuy.ro"] [uri "/.git/config"] [unique_id "apTTZCfaLSuAj0yzdueSCAAAAAQ"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "/.git/config" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.git/config||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "mediabuy.ro"] [uri "/.git/config"] [unique_id "apTTZCfaLSuAj0yzdueSCAAAAAQ"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.git/" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "656"] [id "77318034"] [msg "IM360 WAF: Blocked access to git folder||T:APACHE||MV:/.git/config||"] [severity "NOTICE"] [tag "service_i360custom"] [hostname "mediabuy.ro"] [uri "/.git/config"] [unique_id "apTTZCfaLSuAj0yzdueSCAAAAAQ"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/mediabuy.ro/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788138340124313 260432 (- - -)
Stopwatch2: 1788138340124313 260432; combined=37056, p1=264, p2=36711, p3=0, p4=0, p5=81, sr=96, sw=0, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--babed52b-Z--
--5e40c140-A--
[31/Aug/2026:04:07:54.536517 +0300] apTT6tmUuou1H8H2UKW93wAAAMA 38.141.62.235 52668 127.0.0.1 7081
--5e40c140-B--
POST /contact HTTP/1.1
Host: ihelp.ro
X-Real-IP: 38.141.62.235
X-Accel-Internal: /internal-nginx-static-location
Content-Length: 593
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) obsidian/1.8.10 Chrome/132.0.6834.196 Electron/34.2.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Accept-Language: en-US,en;q=0.9
Accept-Encoding: gzip, deflate, br
Referer: https://ihelp.ro/contact
Sec-Fetch-Dest: document
Sec-Fetch-Mode: same-origin
Sec-Fetch-Site: same-origin
Sec-Fetch-User: ?1
Cookie: csrfToken=oJYjXqYj%2BvnXD3zOpYXIHmZiMWQ3YjJiODRmNjE0NTY1YTA4ZjRjMmE2N2VmZmFiOTRkZjc1MzY%3D
Content-Type: application/x-www-form-urlencoded
Sec-CH-UA: "Google Chrome";v="132", "Chromium";v="132", "Not)A;Brand";v="24"
Sec-CH-UA-Mobile: ?0
Sec-CH-UA-Platform: "Windows"
--5e40c140-F--
HTTP/1.1 200 OK
X-Powered-By: PHP/8.1.34
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate
Pragma: no-cache
X-DEBUGKIT-ID: a3e26ee0-c901-459b-b9a7-f90c5167e904
Set-Cookie: PHPSESSID=dkmfrqmsubkgnffq9qrjg1ljlb; path=/; secure; HttpOnly; SameSite=Lax
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--5e40c140-H--
Message: Match of "rbl nxdomain.v2.rbl.imunify.com." against "TX:rbl_ip" required. [file "/etc/httpd/conf/modsecurity.d/rules/custom/011_i360_8_spam.conf"] [line "102"] [id "77141095"] [msg "IM360 WAF: Block spam in PrestaShop||T:APACHE||MVN:TX:rbl_ip||MV:04-07.38.141.62.235||"] [severity "CRITICAL"] [tag "other_apps"]
Message: Matched phrase "/contact" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/011_i360_8_spam.conf"] [line "182"] [id "77142192"] [msg "IM360 WAF: Track spam attempts||T:APACHE||MVN:REQUEST_FILENAME||MV:/contact||"] [severity "NOTICE"] [tag "other_apps"] [tag "noshow"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788138474359394 177366 (- - -)
Stopwatch2: 1788138474359394 177366; combined=63503, p1=392, p2=63035, p3=0, p4=0, p5=76, sr=133, sw=0, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "DETECTION_ONLY"
--5e40c140-Z--
--79955f09-A--
[31/Aug/2026:04:09:24.022367 +0300] apTUQ9mUuou1H8H2UKW95QAAAMw 64.227.61.137 59018 127.0.0.1 7081
--79955f09-B--
GET /?author=1 HTTP/1.1
Host: axapres.ro
X-Real-IP: 64.227.61.137
X-Accel-Internal: /internal-nginx-static-location
Accept: */*
User-Agent: Mozilla/5.0
Accept-Encoding: gzip,deflate
--79955f09-F--
HTTP/1.1 301 Moved Permanently
X-Powered-By: PHP/7.1.33
X-Redirect-By: WordPress
Location: https://axapres.ro/author/cosmin/
Content-Length: 0
Content-Type: text/html; charset=UTF-8
--79955f09-E--
--79955f09-H--
Message: Operator GE matched 1 at ARGS:author. [file "/etc/httpd/conf/modsecurity.d/rules/custom/007_i360_4_wordpress.conf"] [line "59"] [id "77140876"] [msg "IM360 WAF: Track WordPress users enumeration||MVN:ARGS:author||MV:1||T:APACHE||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/axapres.ro/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788138563708456 314019 (- - -)
Stopwatch2: 1788138563708456 314019; combined=4577, p1=369, p2=3978, p3=135, p4=10, p5=85, sr=124, sw=0, l=0, gc=0
Response-Body-Transformed: Dechunked
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--79955f09-Z--
--f7be3f65-A--
[31/Aug/2026:04:09:24.511911 +0300] apTURNmUuou1H8H2UKW95gAAAM4 64.227.61.137 59024 127.0.0.1 7081
--f7be3f65-B--
GET /?author=2 HTTP/1.1
Host: axapres.ro
X-Real-IP: 64.227.61.137
X-Accel-Internal: /internal-nginx-static-location
Accept: */*
User-Agent: Mozilla/5.0
Accept-Encoding: gzip,deflate
--f7be3f65-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/7.1.33
Expires: Wed, 11 Jan 1984 05:00:00 GMT
Cache-Control: no-cache, must-revalidate, max-age=0
Link:
; rel="https://api.w.org/"
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--f7be3f65-E--
--f7be3f65-H--
Message: Operator GE matched 1 at ARGS:author. [file "/etc/httpd/conf/modsecurity.d/rules/custom/007_i360_4_wordpress.conf"] [line "59"] [id "77140876"] [msg "IM360 WAF: Track WordPress users enumeration||MVN:ARGS:author||MV:2||T:APACHE||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/axapres.ro/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788138564194746 317236 (- - -)
Stopwatch2: 1788138564194746 317236; combined=3681, p1=276, p2=3241, p3=102, p4=25, p5=36, sr=91, sw=1, l=0, gc=0
Response-Body-Transformed: Dechunked
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--f7be3f65-Z--
--babed52b-A--
[31/Aug/2026:04:13:12.015280 +0300] apTVJ37glkZrdsSdRApHEgAAAIY 114.16.206.169 50522 127.0.0.1 7081
--babed52b-B--
POST /wp-login.php HTTP/1.1
Host: axapres.ro
X-Real-IP: 114.16.206.169
X-Accel-Internal: /internal-nginx-static-location
Content-Length: 125
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Accept-Language: ru-RU,ru;q=0.9,en-US;q=0.8,en;q=0.7
Cache-Control: max-age=0
Content-Type: application/x-www-form-urlencoded
Origin: https://axapres.ro
Referer: https://axapres.ro/wp-login.php
Sec-Ch-Ua: "Not=A?Brand";v="99", "Google Chrome";v="151", "Chromium";v="151"
Sec-Ch-Ua-Mobile: ?0
Sec-Ch-Ua-Platform: "Windows"
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: same-origin
Sec-Fetch-User: ?1
Upgrade-Insecure-Requests: 1
User-Agent: 114.16.206.169
Accept-Encoding: gzip, deflate, br
Cookie: wordpress_test_cookie=WP%20Cookie%20check
--babed52b-F--
HTTP/1.1 403 Forbidden
Content-Length: 199
Content-Type: text/html; charset=iso-8859-1
--babed52b-H--
Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:04-13.114.16.206.169"] [severity "CRITICAL"] [tag "wp_core"]
Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"]
Action: Intercepted (phase 2)
Apache-Handler: proxy:unix:/var/www/vhosts/system/axapres.ro/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788138791954546 60822 (- - -)
Stopwatch2: 1788138791954546 60822; combined=59528, p1=347, p2=58593, p3=0, p4=0, p5=446, sr=155, sw=142, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--babed52b-Z--
--babed52b-A--
[31/Aug/2026:04:23:35.015749 +0300] apTXlm7fDIutYTwcPOkZJgAAAEI 216.73.217.35 47890 127.0.0.1 7081
--babed52b-B--
GET /img/ufo19w_831.php HTTP/1.1
Host: ihelp.ro
X-Real-IP: 216.73.217.35
X-Accel-Internal: /internal-nginx-static-location
accept: */*
user-agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)
accept-encoding: gzip, br, zstd, deflate
--babed52b-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/8.1.34
X-DEBUGKIT-ID: 7d4b16b8-cb24-43c4-928c-0552402eae7e
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--babed52b-H--
Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19w_831.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"]
Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19w_831.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19w_831.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "ihelp.ro"] [uri "/img/ufo19w_831.php"] [unique_id "apTXlm7fDIutYTwcPOkZJgAAAEI"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19w_831.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] [hostname "ihelp.ro"] [uri "/img/ufo19w_831.php"] [unique_id "apTXlm7fDIutYTwcPOkZJgAAAEI"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788139414642301 373536 (- - -)
Stopwatch2: 1788139414642301 373536; combined=37448, p1=377, p2=36945, p3=0, p4=0, p5=125, sr=195, sw=1, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "DETECTION_ONLY"
--babed52b-Z--
--c6dd5143-A--
[31/Aug/2026:04:23:47.105284 +0300] apTXotmUuou1H8H2UKW@EQAAANY 216.73.217.35 45342 127.0.0.1 7081
--c6dd5143-B--
GET /img/ufo19_shell_30207.php HTTP/1.1
Host: ihelp.ro
X-Real-IP: 216.73.217.35
X-Accel-Internal: /internal-nginx-static-location
accept: */*
user-agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)
accept-encoding: gzip, br, zstd, deflate
--c6dd5143-F--
HTTP/1.1 200 OK
X-Powered-By: PHP/8.1.34
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--c6dd5143-H--
Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19_shell_30207.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"]
Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19_shell_30207.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19_shell_30207.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "ihelp.ro"] [uri "/img/ufo19_shell_30207.php"] [unique_id "apTXotmUuou1H8H2UKW@EQAAANY"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19_shell_30207.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] [hostname "ihelp.ro"] [uri "/img/ufo19_shell_30207.php"] [unique_id "apTXotmUuou1H8H2UKW@EQAAANY"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788139426882432 222908 (- - -)
Stopwatch2: 1788139426882432 222908; combined=34493, p1=311, p2=34118, p3=0, p4=0, p5=64, sr=152, sw=0, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "DETECTION_ONLY"
--c6dd5143-Z--
--f58f7b59-A--
[31/Aug/2026:04:24:09.085453 +0300] apTXuH7glkZrdsSdRApHIgAAAIw 216.73.217.35 37236 127.0.0.1 7081
--f58f7b59-B--
GET /img/ufo19p_20539.php HTTP/1.1
Host: ihelp.ro
X-Real-IP: 216.73.217.35
X-Accel-Internal: /internal-nginx-static-location
accept: */*
user-agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)
accept-encoding: gzip, br, zstd, deflate
--f58f7b59-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/8.1.34
X-DEBUGKIT-ID: cbe7d303-1d38-414a-b80f-c00c590637af
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--f58f7b59-H--
Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19p_20539.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"]
Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19p_20539.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19p_20539.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "ihelp.ro"] [uri "/img/ufo19p_20539.php"] [unique_id "apTXuH7glkZrdsSdRApHIgAAAIw"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19p_20539.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] [hostname "ihelp.ro"] [uri "/img/ufo19p_20539.php"] [unique_id "apTXuH7glkZrdsSdRApHIgAAAIw"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788139448853010 232493 (- - -)
Stopwatch2: 1788139448853010 232493; combined=33918, p1=329, p2=33463, p3=0, p4=0, p5=126, sr=116, sw=0, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "DETECTION_ONLY"
--f58f7b59-Z--
--a43cbc2c-A--
[31/Aug/2026:04:26:23.925576 +0300] apTYP37glkZrdsSdRApHJQAAAJA 103.119.98.55 38614 127.0.0.1 7081
--a43cbc2c-B--
GET /xmlrpc.php HTTP/1.1
Host: ajutam.ro
X-Real-IP: 103.119.98.55
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36
Accept-Encoding: gzip, deflate, zstd
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
--a43cbc2c-F--
HTTP/1.1 405 Method Not Allowed
X-Powered-By: PHP/7.3.33
Allow: POST
Transfer-Encoding: chunked
Content-Type: text/plain;charset=UTF-8
--a43cbc2c-E--
--a43cbc2c-H--
Message: Warning. String match "xmlrpc.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "290"] [id "77141064"] [msg "IM360 WAF: CMS Recon Bot detected||MVN:REQUEST_FILENAME||T:APACHE||MV:/xmlrpc.php||RM:GET"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "xmlrpc.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "290"] [id "77141064"] [msg "IM360 WAF: CMS Recon Bot detected||MVN:REQUEST_FILENAME||T:APACHE||MV:/xmlrpc.php||RM:GET"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "ajutam.ro"] [uri "/xmlrpc.php"] [unique_id "apTYP37glkZrdsSdRApHJQAAAJA"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/ajutam.ro/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788139583595333 330336 (- - -)
Stopwatch2: 1788139583595333 330336; combined=4228, p1=230, p2=3849, p3=95, p4=9, p5=45, sr=89, sw=0, l=0, gc=0
Response-Body-Transformed: Dechunked
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--a43cbc2c-Z--
--854be211-A--
[31/Aug/2026:04:26:29.009001 +0300] apTYRNmUuou1H8H2UKW@GQAAAM4 103.119.98.55 45936 127.0.0.1 7081
--854be211-B--
GET /xmlrpc.php?rsd HTTP/1.1
Host: ajutam.ro
X-Real-IP: 103.119.98.55
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36
Accept-Encoding: gzip, deflate, zstd
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
--854be211-F--
HTTP/1.1 200 OK
X-Powered-By: PHP/7.3.33
Transfer-Encoding: chunked
Content-Type: text/xml; charset=UTF-8
--854be211-E--
--854be211-H--
Message: Warning. String match "xmlrpc.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "290"] [id "77141064"] [msg "IM360 WAF: CMS Recon Bot detected||MVN:REQUEST_FILENAME||T:APACHE||MV:/xmlrpc.php||RM:GET"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"]
Message: Warning. Operator GT matched 0 at ARGS. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "529"] [id "77317945"] [msg "IM360 WAF: Really Simple Discovery to xmlrpc||MVN:ARGS||MV:1||T:APACHE||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "xmlrpc.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "290"] [id "77141064"] [msg "IM360 WAF: CMS Recon Bot detected||MVN:REQUEST_FILENAME||T:APACHE||MV:/xmlrpc.php||RM:GET"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "ajutam.ro"] [uri "/xmlrpc.php"] [unique_id "apTYRNmUuou1H8H2UKW@GQAAAM4"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Operator GT matched 0 at ARGS. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "529"] [id "77317945"] [msg "IM360 WAF: Really Simple Discovery to xmlrpc||MVN:ARGS||MV:1||T:APACHE||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "ajutam.ro"] [uri "/xmlrpc.php"] [unique_id "apTYRNmUuou1H8H2UKW@GQAAAM4"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/ajutam.ro/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788139588746104 262972 (- - -)
Stopwatch2: 1788139588746104 262972; combined=3456, p1=206, p2=3083, p3=107, p4=8, p5=52, sr=76, sw=0, l=0, gc=0
Response-Body-Transformed: Dechunked
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--854be211-Z--
--a722263d-A--
[31/Aug/2026:04:26:37.583403 +0300] apTYTdmUuou1H8H2UKW@IgAAAMk 216.73.217.35 45808 127.0.0.1 7081
--a722263d-B--
GET /img/ufo_fm.php HTTP/1.1
Host: ihelp.ro
X-Real-IP: 216.73.217.35
X-Accel-Internal: /internal-nginx-static-location
accept: */*
user-agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)
accept-encoding: gzip, br, zstd, deflate
--a722263d-F--
HTTP/1.1 200 OK
X-Powered-By: PHP/8.1.34
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--a722263d-H--
Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo_fm.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"]
Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo_fm.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo_fm.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "ihelp.ro"] [uri "/img/ufo_fm.php"] [unique_id "apTYTdmUuou1H8H2UKW@IgAAAMk"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo_fm.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] [hostname "ihelp.ro"] [uri "/img/ufo_fm.php"] [unique_id "apTYTdmUuou1H8H2UKW@IgAAAMk"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788139597529008 54458 (- - -)
Stopwatch2: 1788139597529008 54458; combined=35584, p1=209, p2=35298, p3=0, p4=0, p5=76, sr=76, sw=1, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "DETECTION_ONLY"
--a722263d-Z--
--7140f16d-A--
[31/Aug/2026:04:26:42.025410 +0300] apTYUX7glkZrdsSdRApHMAAAAI0 216.73.217.35 45878 127.0.0.1 7081
--7140f16d-B--
GET /img/ufo19b_6243.php HTTP/1.1
Host: ihelp.ro
X-Real-IP: 216.73.217.35
X-Accel-Internal: /internal-nginx-static-location
accept: */*
user-agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)
accept-encoding: gzip, br, zstd, deflate
--7140f16d-F--
HTTP/1.1 200 OK
X-Powered-By: PHP/8.1.34
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--7140f16d-H--
Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19b_6243.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"]
Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19b_6243.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19b_6243.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "ihelp.ro"] [uri "/img/ufo19b_6243.php"] [unique_id "apTYUX7glkZrdsSdRApHMAAAAI0"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19b_6243.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] [hostname "ihelp.ro"] [uri "/img/ufo19b_6243.php"] [unique_id "apTYUX7glkZrdsSdRApHMAAAAI0"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788139601991037 34418 (- - -)
Stopwatch2: 1788139601991037 34418; combined=32238, p1=241, p2=31949, p3=0, p4=0, p5=47, sr=105, sw=1, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "DETECTION_ONLY"
--7140f16d-Z--
--ecaa8622-A--
[31/Aug/2026:04:27:30.391857 +0300] apTYgtmUuou1H8H2UKW@LwAAAMo 216.73.217.35 58106 127.0.0.1 7081
--ecaa8622-B--
GET /img/ufo19c_20960.php HTTP/1.1
Host: ihelp.ro
X-Real-IP: 216.73.217.35
X-Accel-Internal: /internal-nginx-static-location
accept: */*
user-agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)
accept-encoding: gzip, br, zstd, deflate
--ecaa8622-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/8.1.34
X-DEBUGKIT-ID: b1af37c5-45e7-4aa1-8a6e-7aaa11de5adf
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--ecaa8622-H--
Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19c_20960.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"]
Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19c_20960.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19c_20960.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "ihelp.ro"] [uri "/img/ufo19c_20960.php"] [unique_id "apTYgtmUuou1H8H2UKW@LwAAAMo"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19c_20960.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] [hostname "ihelp.ro"] [uri "/img/ufo19c_20960.php"] [unique_id "apTYgtmUuou1H8H2UKW@LwAAAMo"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788139650172543 219383 (- - -)
Stopwatch2: 1788139650172543 219383; combined=33329, p1=252, p2=32961, p3=0, p4=0, p5=116, sr=96, sw=0, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "DETECTION_ONLY"
--ecaa8622-Z--
--f58f7b59-A--
[31/Aug/2026:04:27:30.425802 +0300] apTYgifaLSuAj0yzdueSFwAAABI 216.73.217.35 58118 127.0.0.1 7081
--f58f7b59-B--
GET /img/wso_ufo19.php HTTP/1.1
Host: ihelp.ro
X-Real-IP: 216.73.217.35
X-Accel-Internal: /internal-nginx-static-location
accept: */*
user-agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)
accept-encoding: gzip, br, zstd, deflate
--f58f7b59-F--
HTTP/1.1 200 OK
X-Powered-By: PHP/8.1.34
Set-Cookie: 646109d53af43c125a937b56d9f339f0key=fac378ac3b3d3886829021b3309d4fd1
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--f58f7b59-H--
Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/wso_ufo19.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"]
Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/wso_ufo19.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/wso_ufo19.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "ihelp.ro"] [uri "/img/wso_ufo19.php"] [unique_id "apTYgifaLSuAj0yzdueSFwAAABI"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/wso_ufo19.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] [hostname "ihelp.ro"] [uri "/img/wso_ufo19.php"] [unique_id "apTYgifaLSuAj0yzdueSFwAAABI"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788139650384706 41143 (- - -)
Stopwatch2: 1788139650384706 41143; combined=32055, p1=231, p2=31760, p3=0, p4=0, p5=63, sr=90, sw=1, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "DETECTION_ONLY"
--f58f7b59-Z--
--29e80a3f-A--
[31/Aug/2026:04:28:29.968365 +0300] apTYvX7glkZrdsSdRApHPAAAAIs 216.73.217.35 43546 127.0.0.1 7081
--29e80a3f-B--
GET /img/ufo19_20982.php HTTP/1.1
Host: ihelp.ro
X-Real-IP: 216.73.217.35
X-Accel-Internal: /internal-nginx-static-location
accept: */*
user-agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)
accept-encoding: gzip, br, zstd, deflate
--29e80a3f-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/8.1.34
X-DEBUGKIT-ID: c3c26b04-0f45-43b9-9708-0f7e4d2dc127
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--29e80a3f-H--
Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19_20982.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"]
Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19_20982.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19_20982.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "ihelp.ro"] [uri "/img/ufo19_20982.php"] [unique_id "apTYvX7glkZrdsSdRApHPAAAAIs"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19_20982.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] [hostname "ihelp.ro"] [uri "/img/ufo19_20982.php"] [unique_id "apTYvX7glkZrdsSdRApHPAAAAIs"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788139709702642 265775 (- - -)
Stopwatch2: 1788139709702642 265775; combined=34921, p1=222, p2=34628, p3=0, p4=0, p5=71, sr=84, sw=0, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "DETECTION_ONLY"
--29e80a3f-Z--
--d0b8c902-A--
[31/Aug/2026:04:30:40.728783 +0300] apTZQNmUuou1H8H2UKW@PwAAAM0 120.133.60.156 58146 127.0.0.1 7081
--d0b8c902-B--
POST /wp-login.php HTTP/1.1
Host: axapres.ro
X-Real-IP: 120.133.60.156
X-Accel-Internal: /internal-nginx-static-location
Content-Length: 110
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Content-Type: application/x-www-form-urlencoded
Cookie: wordpress_test_cookie=WP+Cookie+check
Origin: https://axapres.ro
Referer: https://axapres.ro/wp-login.php
--d0b8c902-F--
HTTP/1.1 403 Forbidden
Content-Length: 199
Content-Type: text/html; charset=iso-8859-1
--d0b8c902-H--
Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:04-30.120.133.60.156"] [severity "CRITICAL"] [tag "wp_core"]
Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"]
Action: Intercepted (phase 2)
Apache-Handler: proxy:unix:/var/www/vhosts/system/axapres.ro/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788139840668086 60755 (- - -)
Stopwatch2: 1788139840668086 60755; combined=59641, p1=324, p2=58588, p3=0, p4=0, p5=522, sr=102, sw=207, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--d0b8c902-Z--
--2d6c6e20-A--
[31/Aug/2026:04:31:28.347937 +0300] apTZcNmUuou1H8H2UKW@QwAAANc 43.156.13.166 55200 127.0.0.1 7081
--2d6c6e20-B--
POST /wp-login.php HTTP/1.1
Host: axapres.ro
X-Real-IP: 43.156.13.166
X-Accel-Internal: /internal-nginx-static-location
Content-Length: 104
Content-Type: application/x-www-form-urlencoded
User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.36 Edg/142.0.0.0
Accept-Encoding: gzip, deflate
Accept: */*
Cookie: wordpress_test_cookie=WP+Cookie+check
--2d6c6e20-F--
HTTP/1.1 403 Forbidden
Content-Length: 199
Content-Type: text/html; charset=iso-8859-1
--2d6c6e20-H--
Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:04-31.43.156.13.166"] [severity "CRITICAL"] [tag "wp_core"]
Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"]
Action: Intercepted (phase 2)
Apache-Handler: proxy:unix:/var/www/vhosts/system/axapres.ro/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788139888286034 62057 (- - -)
Stopwatch2: 1788139888286034 62057; combined=60357, p1=423, p2=58533, p3=0, p4=0, p5=1022, sr=152, sw=379, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--2d6c6e20-Z--
--a43cbc2c-A--
[31/Aug/2026:04:32:01.848761 +0300] apTZkSfaLSuAj0yzdueSGQAAAAA 207.154.219.81 56588 127.0.0.1 7081
--a43cbc2c-B--
GET /?author=1 HTTP/1.1
Host: ajutam.ro
X-Real-IP: 207.154.219.81
X-Accel-Internal: /internal-nginx-static-location
Accept: */*
User-Agent: Mozilla/5.0
Accept-Encoding: gzip,deflate
--a43cbc2c-F--
HTTP/1.1 301 Moved Permanently
X-Powered-By: PHP/7.3.33
X-Redirect-By: WordPress
Location: https://ajutam.ro/author/admin/
Content-Length: 0
Content-Type: text/html; charset=UTF-8
--a43cbc2c-E--
--a43cbc2c-H--
Message: Operator GE matched 1 at ARGS:author. [file "/etc/httpd/conf/modsecurity.d/rules/custom/007_i360_4_wordpress.conf"] [line "59"] [id "77140876"] [msg "IM360 WAF: Track WordPress users enumeration||MVN:ARGS:author||MV:1||T:APACHE||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/ajutam.ro/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788139921325196 523635 (- - -)
Stopwatch2: 1788139921325196 523635; combined=5796, p1=620, p2=4969, p3=144, p4=13, p5=49, sr=221, sw=1, l=0, gc=0
Response-Body-Transformed: Dechunked
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--a43cbc2c-Z--
--1cd0f101-A--
[31/Aug/2026:04:32:02.418495 +0300] apTZkdmUuou1H8H2UKW@RgAAAME 207.154.219.81 56598 127.0.0.1 7081
--1cd0f101-B--
GET /?author=2 HTTP/1.1
Host: ajutam.ro
X-Real-IP: 207.154.219.81
X-Accel-Internal: /internal-nginx-static-location
Accept: */*
User-Agent: Mozilla/5.0
Accept-Encoding: gzip,deflate
--1cd0f101-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/7.3.33
Expires: Wed, 11 Jan 1984 05:00:00 GMT
Cache-Control: no-cache, must-revalidate, max-age=0, no-store, private
Link:
; rel="https://api.w.org/"
X-TEC-API-VERSION: v1
X-TEC-API-ROOT: https://ajutam.ro/wp-json/tribe/events/v1/
X-TEC-API-ORIGIN: https://ajutam.ro
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--1cd0f101-E--
--1cd0f101-H--
Message: Operator GE matched 1 at ARGS:author. [file "/etc/httpd/conf/modsecurity.d/rules/custom/007_i360_4_wordpress.conf"] [line "59"] [id "77140876"] [msg "IM360 WAF: Track WordPress users enumeration||MVN:ARGS:author||MV:2||T:APACHE||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/ajutam.ro/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788139921885045 533628 (- - -)
Stopwatch2: 1788139921885045 533628; combined=5354, p1=336, p2=4786, p3=174, p4=13, p5=45, sr=150, sw=0, l=0, gc=0
Response-Body-Transformed: Dechunked
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--1cd0f101-Z--
--a23cf107-A--
[31/Aug/2026:04:37:14.207976 +0300] apTaydmUuou1H8H2UKW@WwAAANM 137.184.233.53 55776 127.0.0.1 7081
--a23cf107-B--
GET /?author=1 HTTP/1.1
Host: chania24.taxi
X-Real-IP: 137.184.233.53
Accept: */*
User-Agent: Mozilla/5.0
Accept-Encoding: gzip,deflate
--a23cf107-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/7.4.33
Expires: Wed, 11 Jan 1984 05:00:00 GMT
Cache-Control: no-cache, must-revalidate, max-age=0
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--a23cf107-E--
--a23cf107-H--
Message: Operator GE matched 1 at ARGS:author. [file "/etc/httpd/conf/modsecurity.d/rules/custom/007_i360_4_wordpress.conf"] [line "59"] [id "77140876"] [msg "IM360 WAF: Track WordPress users enumeration||MVN:ARGS:author||MV:1||T:APACHE||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/chania24.taxi/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788140233624027 584021 (- - -)
Stopwatch2: 1788140233624027 584021; combined=9784, p1=957, p2=8671, p3=96, p4=21, p5=39, sr=98, sw=0, l=0, gc=0
Response-Body-Transformed: Dechunked
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--a23cf107-Z--
--a9d8211b-A--
[31/Aug/2026:04:42:02.408404 +0300] apTb6tmUuou1H8H2UKW@dAAAAM8 163.61.60.30 52118 127.0.0.1 7081
--a9d8211b-B--
POST /wp-login.php HTTP/1.1
Host: axapres.ro
X-Real-IP: 163.61.60.30
X-Accel-Internal: /internal-nginx-static-location
Content-Length: 117
Cookie: wordpress_test_cookie=WP+Cookie+check
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip, deflate
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.36 Edg/142.0.0.0
--a9d8211b-F--
HTTP/1.1 403 Forbidden
Content-Length: 199
Content-Type: text/html; charset=iso-8859-1
--a9d8211b-H--
Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:04-42.163.61.60.30"] [severity "CRITICAL"] [tag "wp_core"]
Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"]
Action: Intercepted (phase 2)
Apache-Handler: proxy:unix:/var/www/vhosts/system/axapres.ro/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788140522344297 64181 (- - -)
Stopwatch2: 1788140522344297 64181; combined=62659, p1=403, p2=61315, p3=0, p4=0, p5=696, sr=139, sw=245, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--a9d8211b-Z--
--6515330e-A--
[31/Aug/2026:04:43:17.898857 +0300] apTcNdmUuou1H8H2UKW@dgAAANg 59.125.102.226 34186 127.0.0.1 7081
--6515330e-B--
POST /wp-login.php HTTP/1.1
Host: axapres.ro
X-Real-IP: 59.125.102.226
X-Accel-Internal: /internal-nginx-static-location
Content-Length: 126
Accept-Encoding: gzip, deflate
Content-Type: application/x-www-form-urlencoded
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.36 Edg/142.0.0.0
Cookie: wordpress_test_cookie=WP+Cookie+check
--6515330e-F--
HTTP/1.1 403 Forbidden
Content-Length: 199
Content-Type: text/html; charset=iso-8859-1
--6515330e-H--
Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:04-43.59.125.102.226"] [severity "CRITICAL"] [tag "wp_core"]
Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"]
Action: Intercepted (phase 2)
Apache-Handler: proxy:unix:/var/www/vhosts/system/axapres.ro/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788140597829870 69103 (- - -)
Stopwatch2: 1788140597829870 69103; combined=59973, p1=1374, p2=57768, p3=0, p4=0, p5=559, sr=633, sw=272, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--6515330e-Z--
--02b7aa2e-A--
[31/Aug/2026:04:49:57.989304 +0300] apTdxdmUuou1H8H2UKW@mQAAAM4 137.184.225.216 46128 127.0.0.1 7081
--02b7aa2e-B--
POST /wp-login.php HTTP/1.1
Host: axapres.ro
X-Real-IP: 137.184.225.216
X-Accel-Internal: /internal-nginx-static-location
Content-Length: 108
Accept-Encoding: gzip, deflate
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/140.0.0.0 Safari/537.36 Edg/140.0.0.0
Cookie: wordpress_test_cookie=WP+Cookie+check
Content-Type: application/x-www-form-urlencoded
--02b7aa2e-F--
HTTP/1.1 403 Forbidden
Content-Length: 199
Content-Type: text/html; charset=iso-8859-1
--02b7aa2e-H--
Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:04-49.137.184.225.216"] [severity "CRITICAL"] [tag "wp_core"]
Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"]
Action: Intercepted (phase 2)
Apache-Handler: proxy:unix:/var/www/vhosts/system/axapres.ro/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788140997929755 59615 (- - -)
Stopwatch2: 1788140997929755 59615; combined=57486, p1=443, p2=56401, p3=0, p4=0, p5=460, sr=189, sw=182, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--02b7aa2e-Z--
--c959a14c-A--
[31/Aug/2026:05:13:04.903603 +0300] apTjMH7glkZrdsSdRApH0QAAAII 168.144.111.201 53912 127.0.0.1 7081
--c959a14c-B--
POST /wp-json/batch/v1 HTTP/1.1
Host: chania24.taxi
X-Real-IP: 168.144.111.201
Content-Length: 15
sec-ch-ua: "Not_A Brand";v="8", "Chromium";v="120", "Google Chrome";v="120"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "macOS"
Upgrade-Insecure-Requests: 1
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 Chrome/119.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Sec-Fetch-Site: none
Sec-Fetch-Mode: navigate
Sec-Fetch-User: ?1
Sec-Fetch-Dest: document
Accept-Encoding: gzip, deflate, br
Accept-Language: id-ID,id;q=0.9,en-US;q=0.8,en;q=0.7
Cache-Control: max-age=0
DNT: 1
Content-Type: application/json
--c959a14c-F--
HTTP/1.1 403 Forbidden
X-Powered-By: PHP/7.4.33
Pragma: no-cache
Cache-Control: no-cache, must-revalidate, private, max-age=0
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--c959a14c-H--
Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/chania24.taxi/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788142384794114 109625 (- - -)
Stopwatch2: 1788142384794114 109625; combined=6654, p1=311, p2=5966, p3=0, p4=0, p5=377, sr=131, sw=0, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--c959a14c-Z--
--ac894c49-A--
[31/Aug/2026:05:13:05.187346 +0300] apTjMdmUuou1H8H2UKW-dgAAAMM 168.144.111.201 53928 127.0.0.1 7081
--ac894c49-B--
POST /?rest_route=/batch/v1 HTTP/1.1
Host: chania24.taxi
X-Real-IP: 168.144.111.201
Content-Length: 16
sec-ch-ua: "Not_A Brand";v="8", "Chromium";v="120", "Google Chrome";v="120"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "macOS"
Upgrade-Insecure-Requests: 1
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/121.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Sec-Fetch-Site: none
Sec-Fetch-Mode: navigate
Sec-Fetch-User: ?1
Sec-Fetch-Dest: document
Accept-Encoding: gzip, deflate, br
Accept-Language: id-ID,id;q=0.9,en-US;q=0.8,en;q=0.7
Cache-Control: max-age=0
DNT: 1
Content-Type: application/json
--ac894c49-F--
HTTP/1.1 403 Forbidden
X-Powered-By: PHP/7.4.33
Pragma: no-cache
Cache-Control: no-cache, must-revalidate, private, max-age=0
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--ac894c49-E--
--ac894c49-H--
Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G:rest_route=/batch/v1& P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/chania24.taxi/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788142385099814 87621 (- - -)
Stopwatch2: 1788142385099814 87621; combined=5538, p1=521, p2=4521, p3=181, p4=23, p5=291, sr=316, sw=1, l=0, gc=0
Response-Body-Transformed: Dechunked
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--ac894c49-Z--
--d5bd142f-A--
[31/Aug/2026:05:20:55.096407 +0300] apTlB9mUuou1H8H2UKW-qwAAAMo 23.94.77.36 53756 127.0.0.1 7081
--d5bd142f-B--
GET /american-humane-association/ HTTP/1.1
Host: ajutam.ro
X-Real-IP: 23.94.77.36
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Accept-Language: en-US,en;q=0.9
Accept-Encoding: gzip, deflate, br
Referer: http://ajutam.ro/american-humane-association/
--d5bd142f-F--
HTTP/1.1 403 Forbidden
Last-Modified: Fri, 01 May 2020 21:00:27 GMT
ETag: "31b-5a49c787f10c0"
Accept-Ranges: bytes
Content-Length: 795
Content-Type: text/html
--d5bd142f-H--
Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "81"] [id "33311"] [msg "IM360 WAF: Found crawler not in whitelist||T:APACHE||User-Agent:Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)||MV:05-20.23.94.77.36"] [severity "CRITICAL"] [tag "service_i360"]
Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"]
Action: Intercepted (phase 2)
Stopwatch: 1788142855061911 34579 (- - -)
Stopwatch2: 1788142855061911 34579; combined=28428, p1=352, p2=27455, p3=0, p4=0, p5=620, sr=117, sw=1, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--d5bd142f-Z--
--7140f16d-A--
[31/Aug/2026:05:20:57.331289 +0300] apTlCSfaLSuAj0yzdueSVwAAABI 191.101.110.76 46040 127.0.0.1 7081
--7140f16d-B--
GET /american-humane-association/ HTTP/1.1
Host: ajutam.ro
X-Real-IP: 191.101.110.76
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Accept-Language: en-US,en;q=0.9
Accept-Encoding: gzip, deflate, br
--7140f16d-F--
HTTP/1.1 403 Forbidden
Last-Modified: Fri, 01 May 2020 21:00:27 GMT
ETag: "31b-5a49c787f10c0"
Accept-Ranges: bytes
Content-Length: 795
Content-Type: text/html
--7140f16d-H--
Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "81"] [id "33311"] [msg "IM360 WAF: Found crawler not in whitelist||T:APACHE||User-Agent:Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)||MV:05-20.191.101.110.76"] [severity "CRITICAL"] [tag "service_i360"]
Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"]
Action: Intercepted (phase 2)
Stopwatch: 1788142857299179 32191 (- - -)
Stopwatch2: 1788142857299179 32191; combined=30471, p1=203, p2=29994, p3=0, p4=0, p5=274, sr=83, sw=0, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--7140f16d-Z--
--76e14709-A--
[31/Aug/2026:05:20:59.413038 +0300] apTlC9mUuou1H8H2UKW-rAAAANE 172.245.60.137 46056 127.0.0.1 7081
--76e14709-B--
GET /american-humane-association/ HTTP/1.1
Host: ajutam.ro
X-Real-IP: 172.245.60.137
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Accept-Language: en-US,en;q=0.9
Accept-Encoding: gzip, deflate, br
--76e14709-F--
HTTP/1.1 403 Forbidden
Last-Modified: Fri, 01 May 2020 21:00:27 GMT
ETag: "31b-5a49c787f10c0"
Accept-Ranges: bytes
Content-Length: 795
Content-Type: text/html
--76e14709-H--
Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "81"] [id "33311"] [msg "IM360 WAF: Found crawler not in whitelist||T:APACHE||User-Agent:Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)||MV:05-20.172.245.60.137"] [severity "CRITICAL"] [tag "service_i360"]
Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"]
Action: Intercepted (phase 2)
Stopwatch: 1788142859378974 34141 (- - -)
Stopwatch2: 1788142859378974 34141; combined=31124, p1=351, p2=30401, p3=0, p4=0, p5=371, sr=149, sw=1, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--76e14709-Z--
--99b5b32b-A--
[31/Aug/2026:05:21:01.635949 +0300] apTlDdmUuou1H8H2UKW-rQAAAMI 172.245.60.182 46066 127.0.0.1 7081
--99b5b32b-B--
GET /american-humane-association/ HTTP/1.1
Host: ajutam.ro
X-Real-IP: 172.245.60.182
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Accept-Language: en-US,en;q=0.9
Accept-Encoding: gzip, deflate, br
--99b5b32b-F--
HTTP/1.1 403 Forbidden
Last-Modified: Fri, 01 May 2020 21:00:27 GMT
ETag: "31b-5a49c787f10c0"
Accept-Ranges: bytes
Content-Length: 795
Content-Type: text/html
--99b5b32b-H--
Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "81"] [id "33311"] [msg "IM360 WAF: Found crawler not in whitelist||T:APACHE||User-Agent:Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)||MV:05-21.172.245.60.182"] [severity "CRITICAL"] [tag "service_i360"]
Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"]
Action: Intercepted (phase 2)
Stopwatch: 1788142861599538 36561 (- - -)
Stopwatch2: 1788142861599538 36561; combined=33943, p1=901, p2=28095, p3=0, p4=0, p5=4947, sr=123, sw=0, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--99b5b32b-Z--
--5155e508-A--
[31/Aug/2026:05:23:15.755773 +0300] apTlk37glkZrdsSdRApH6QAAAIM 23.94.77.36 44080 127.0.0.1 7081
--5155e508-B--
GET /american-humane-association/ HTTP/1.1
Host: ajutam.ro
X-Real-IP: 23.94.77.36
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Accept-Language: en-US,en;q=0.9
Accept-Encoding: gzip, deflate, br
Referer: http://ajutam.ro/american-humane-association/
--5155e508-F--
HTTP/1.1 403 Forbidden
Last-Modified: Fri, 01 May 2020 21:00:27 GMT
ETag: "31b-5a49c787f10c0"
Accept-Ranges: bytes
Content-Length: 795
Content-Type: text/html
--5155e508-H--
Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "81"] [id "33311"] [msg "IM360 WAF: Found crawler not in whitelist||T:APACHE||User-Agent:Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)||MV:05-23.23.94.77.36"] [severity "CRITICAL"] [tag "service_i360"]
Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"]
Action: Intercepted (phase 2)
Stopwatch: 1788142995723174 32676 (- - -)
Stopwatch2: 1788142995723174 32676; combined=30498, p1=940, p2=29236, p3=0, p4=0, p5=322, sr=166, sw=0, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--5155e508-Z--
--6ca34342-A--
[31/Aug/2026:05:23:17.718481 +0300] apTlldmUuou1H8H2UKW-tAAAAME 198.46.222.253 44094 127.0.0.1 7081
--6ca34342-B--
GET /american-humane-association/ HTTP/1.1
Host: ajutam.ro
X-Real-IP: 198.46.222.253
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Accept-Language: en-US,en;q=0.9
Accept-Encoding: gzip, deflate, br
--6ca34342-F--
HTTP/1.1 403 Forbidden
Last-Modified: Fri, 01 May 2020 21:00:27 GMT
ETag: "31b-5a49c787f10c0"
Accept-Ranges: bytes
Content-Length: 795
Content-Type: text/html
--6ca34342-H--
Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "81"] [id "33311"] [msg "IM360 WAF: Found crawler not in whitelist||T:APACHE||User-Agent:Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)||MV:05-23.198.46.222.253"] [severity "CRITICAL"] [tag "service_i360"]
Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"]
Action: Intercepted (phase 2)
Stopwatch: 1788142997685518 33028 (- - -)
Stopwatch2: 1788142997685518 33028; combined=31152, p1=703, p2=30148, p3=0, p4=0, p5=301, sr=135, sw=0, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--6ca34342-Z--
--d9179761-A--
[31/Aug/2026:05:23:19.926164 +0300] apTll9mUuou1H8H2UKW-tQAAAMM 191.101.110.188 44110 127.0.0.1 7081
--d9179761-B--
GET /american-humane-association/ HTTP/1.1
Host: ajutam.ro
X-Real-IP: 191.101.110.188
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Accept-Language: en-US,en;q=0.9
Accept-Encoding: gzip, deflate, br
--d9179761-F--
HTTP/1.1 403 Forbidden
Last-Modified: Fri, 01 May 2020 21:00:27 GMT
ETag: "31b-5a49c787f10c0"
Accept-Ranges: bytes
Content-Length: 795
Content-Type: text/html
--d9179761-H--
Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "81"] [id "33311"] [msg "IM360 WAF: Found crawler not in whitelist||T:APACHE||User-Agent:Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)||MV:05-23.191.101.110.188"] [severity "CRITICAL"] [tag "service_i360"]
Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"]
Action: Intercepted (phase 2)
Stopwatch: 1788142999892198 34058 (- - -)
Stopwatch2: 1788142999892198 34058; combined=30824, p1=503, p2=29932, p3=0, p4=0, p5=388, sr=233, sw=1, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--d9179761-Z--
--3f9d4850-A--
[31/Aug/2026:05:23:22.078530 +0300] apTlmtmUuou1H8H2UKW-tgAAAMc 191.101.110.60 44122 127.0.0.1 7081
--3f9d4850-B--
GET /american-humane-association/ HTTP/1.1
Host: ajutam.ro
X-Real-IP: 191.101.110.60
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Accept-Language: en-US,en;q=0.9
Accept-Encoding: gzip, deflate, br
--3f9d4850-F--
HTTP/1.1 403 Forbidden
Last-Modified: Fri, 01 May 2020 21:00:27 GMT
ETag: "31b-5a49c787f10c0"
Accept-Ranges: bytes
Content-Length: 795
Content-Type: text/html
--3f9d4850-H--
Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "81"] [id "33311"] [msg "IM360 WAF: Found crawler not in whitelist||T:APACHE||User-Agent:Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)||MV:05-23.191.101.110.60"] [severity "CRITICAL"] [tag "service_i360"]
Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"]
Action: Intercepted (phase 2)
Stopwatch: 1788143002046367 32234 (- - -)
Stopwatch2: 1788143002046367 32234; combined=29508, p1=549, p2=28606, p3=0, p4=0, p5=352, sr=252, sw=1, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--3f9d4850-Z--
--78ba2517-A--
[31/Aug/2026:05:36:15.636204 +0300] apTon37glkZrdsSdRApIJQAAAJI 207.154.219.81 58222 127.0.0.1 7081
--78ba2517-B--
POST /wp-login.php HTTP/1.1
Host: ajutam.ro
X-Real-IP: 207.154.219.81
X-Accel-Internal: /internal-nginx-static-location
Content-Length: 105
Accept: */*
User-Agent: Mozilla/5.0
Content-Type: application/x-www-form-urlencoded
Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818
--78ba2517-F--
HTTP/1.1 403 Forbidden
Last-Modified: Fri, 01 May 2020 21:00:27 GMT
ETag: "31b-5a49c787f10c0"
Accept-Ranges: bytes
Content-Length: 795
Content-Type: text/html
--78ba2517-H--
Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:05-36.207.154.219.81"] [severity "CRITICAL"] [tag "wp_core"]
Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"]
Action: Intercepted (phase 2)
Stopwatch: 1788143775573307 62953 (- - -)
Stopwatch2: 1788143775573307 62953; combined=61208, p1=461, p2=60158, p3=0, p4=0, p5=445, sr=191, sw=144, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--78ba2517-Z--
--eadd4674-A--
[31/Aug/2026:05:36:17.160029 +0300] apToodmUuou1H8H2UKXAIgAAANI 35.254.196.10 58238 127.0.0.1 7081
--eadd4674-B--
GET /.git/config HTTP/1.1
Host: breveleyendatequila.com
X-Real-IP: 35.254.196.10
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36
Accept: */*
--eadd4674-F--
HTTP/1.1 404 Not Found
Content-Length: 196
Content-Type: text/html; charset=iso-8859-1
--eadd4674-E--
--eadd4674-H--
Message: Warning. Matched phrase "/.git/config" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.git/config||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"]
Message: Warning. Matched phrase "/.git/config" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.git/config||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"]
Message: Warning. String match "/.git/" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "656"] [id "77318034"] [msg "IM360 WAF: Blocked access to git folder||T:APACHE||MV:/.git/config||"] [severity "NOTICE"] [tag "service_i360custom"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "/.git/config" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.git/config||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "breveleyendatequila.com"] [uri "/.git/config"] [unique_id "apToodmUuou1H8H2UKXAIgAAANI"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "/.git/config" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.git/config||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "breveleyendatequila.com"] [uri "/.git/config"] [unique_id "apToodmUuou1H8H2UKXAIgAAANI"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.git/" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "656"] [id "77318034"] [msg "IM360 WAF: Blocked access to git folder||T:APACHE||MV:/.git/config||"] [severity "NOTICE"] [tag "service_i360custom"] [hostname "breveleyendatequila.com"] [uri "/.git/config"] [unique_id "apToodmUuou1H8H2UKXAIgAAANI"]
Stopwatch: 1788143777122473 37602 (- - -)
Stopwatch2: 1788143777122473 37602; combined=36081, p1=344, p2=35560, p3=111, p4=8, p5=58, sr=105, sw=0, l=0, gc=0
Response-Body-Transformed: Dechunked
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--eadd4674-Z--
--36ef4919-A--
[31/Aug/2026:05:38:38.149143 +0300] apTpLtmUuou1H8H2UKXAKQAAAMs 207.154.219.81 45162 127.0.0.1 7081
--36ef4919-B--
POST /wp-login.php HTTP/1.1
Host: ajutam.ro
X-Real-IP: 207.154.219.81
X-Accel-Internal: /internal-nginx-static-location
Content-Length: 108
Accept: */*
User-Agent: Mozilla/5.0
Content-Type: application/x-www-form-urlencoded
Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818
--36ef4919-F--
HTTP/1.1 403 Forbidden
Last-Modified: Fri, 01 May 2020 21:00:27 GMT
ETag: "31b-5a49c787f10c0"
Accept-Ranges: bytes
Content-Length: 795
Content-Type: text/html
--36ef4919-H--
Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "42"] [id "33302"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:1"] [severity "CRITICAL"] [tag "wp_core"]
Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"]
Action: Intercepted (phase 2)
Stopwatch: 1788143918146738 2492 (- - -)
Stopwatch2: 1788143918146738 2492; combined=713, p1=389, p2=95, p3=0, p4=0, p5=229, sr=111, sw=0, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--36ef4919-Z--
--67a23e1c-A--
[31/Aug/2026:05:41:44.547918 +0300] apTp6NmUuou1H8H2UKXALwAAANI 207.154.219.81 56512 127.0.0.1 7081
--67a23e1c-B--
POST /wp-login.php HTTP/1.1
Host: ajutam.ro
X-Real-IP: 207.154.219.81
X-Accel-Internal: /internal-nginx-static-location
Content-Length: 108
Accept: */*
User-Agent: Mozilla/5.0
Content-Type: application/x-www-form-urlencoded
Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818
--67a23e1c-F--
HTTP/1.1 403 Forbidden
Last-Modified: Fri, 01 May 2020 21:00:27 GMT
ETag: "31b-5a49c787f10c0"
Accept-Ranges: bytes
Content-Length: 795
Content-Type: text/html
--67a23e1c-H--
Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:05-41.207.154.219.81"] [severity "CRITICAL"] [tag "wp_core"]
Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"]
Action: Intercepted (phase 2)
Stopwatch: 1788144104480666 67392 (- - -)
Stopwatch2: 1788144104480666 67392; combined=61003, p1=275, p2=59322, p3=0, p4=0, p5=1220, sr=115, sw=186, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--67a23e1c-Z--
--f58f7b59-A--
[31/Aug/2026:05:44:30.282253 +0300] apTqjm7fDIutYTwcPOkZtAAAAFY 138.197.193.77 48556 127.0.0.1 7081
--f58f7b59-B--
GET /?author=1 HTTP/1.1
Host: ajutam.ro
X-Real-IP: 138.197.193.77
X-Accel-Internal: /internal-nginx-static-location
Accept: */*
User-Agent: Mozilla/5.0
Accept-Encoding: gzip,deflate
--f58f7b59-F--
HTTP/1.1 301 Moved Permanently
X-Powered-By: PHP/7.3.33
X-Redirect-By: WordPress
Location: https://ajutam.ro/author/admin/
Content-Length: 0
Content-Type: text/html; charset=UTF-8
--f58f7b59-E--
--f58f7b59-H--
Message: Operator GE matched 1 at ARGS:author. [file "/etc/httpd/conf/modsecurity.d/rules/custom/007_i360_4_wordpress.conf"] [line "59"] [id "77140876"] [msg "IM360 WAF: Track WordPress users enumeration||MVN:ARGS:author||MV:1||T:APACHE||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/ajutam.ro/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788144270007605 274701 (- - -)
Stopwatch2: 1788144270007605 274701; combined=3452, p1=277, p2=3042, p3=93, p4=8, p5=32, sr=105, sw=0, l=0, gc=0
Response-Body-Transformed: Dechunked
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--f58f7b59-Z--
--e8f2fd53-A--
[31/Aug/2026:05:44:30.831609 +0300] apTqjtmUuou1H8H2UKXANwAAAMQ 138.197.193.77 48558 127.0.0.1 7081
--e8f2fd53-B--
GET /?author=2 HTTP/1.1
Host: ajutam.ro
X-Real-IP: 138.197.193.77
X-Accel-Internal: /internal-nginx-static-location
Accept: */*
User-Agent: Mozilla/5.0
Accept-Encoding: gzip,deflate
--e8f2fd53-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/7.3.33
Expires: Wed, 11 Jan 1984 05:00:00 GMT
Cache-Control: no-cache, must-revalidate, max-age=0, no-store, private
Link:
; rel="https://api.w.org/"
X-TEC-API-VERSION: v1
X-TEC-API-ROOT: https://ajutam.ro/wp-json/tribe/events/v1/
X-TEC-API-ORIGIN: https://ajutam.ro
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--e8f2fd53-E--
--e8f2fd53-H--
Message: Operator GE matched 1 at ARGS:author. [file "/etc/httpd/conf/modsecurity.d/rules/custom/007_i360_4_wordpress.conf"] [line "59"] [id "77140876"] [msg "IM360 WAF: Track WordPress users enumeration||MVN:ARGS:author||MV:2||T:APACHE||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/ajutam.ro/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788144270480910 350830 (- - -)
Stopwatch2: 1788144270480910 350830; combined=3307, p1=247, p2=2869, p3=141, p4=11, p5=38, sr=106, sw=1, l=0, gc=0
Response-Body-Transformed: Dechunked
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--e8f2fd53-Z--
--29e80a3f-A--
[31/Aug/2026:05:47:47.636727 +0300] apTrUyfaLSuAj0yzdueSbgAAABg 207.154.219.81 33108 127.0.0.1 7081
--29e80a3f-B--
POST /wp-login.php HTTP/1.1
Host: ajutam.ro
X-Real-IP: 207.154.219.81
X-Accel-Internal: /internal-nginx-static-location
Content-Length: 110
Accept: */*
User-Agent: Mozilla/5.0
Content-Type: application/x-www-form-urlencoded
Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818
--29e80a3f-F--
HTTP/1.1 403 Forbidden
Last-Modified: Fri, 01 May 2020 21:00:27 GMT
ETag: "31b-5a49c787f10c0"
Accept-Ranges: bytes
Content-Length: 795
Content-Type: text/html
--29e80a3f-H--
Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:05-47.207.154.219.81"] [severity "CRITICAL"] [tag "wp_core"]
Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"]
Action: Intercepted (phase 2)
Stopwatch: 1788144467563740 73081 (- - -)
Stopwatch2: 1788144467563740 73081; combined=65983, p1=471, p2=64003, p3=0, p4=0, p5=1110, sr=196, sw=399, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--29e80a3f-Z--
--f05c8c30-A--
[31/Aug/2026:05:53:41.323477 +0300] apTstdmUuou1H8H2UKXAngAAAMQ 207.154.219.81 40972 127.0.0.1 7081
--f05c8c30-B--
POST /wp-login.php HTTP/1.1
Host: ajutam.ro
X-Real-IP: 207.154.219.81
X-Accel-Internal: /internal-nginx-static-location
Content-Length: 111
Accept: */*
User-Agent: Mozilla/5.0
Content-Type: application/x-www-form-urlencoded
Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818
--f05c8c30-F--
HTTP/1.1 403 Forbidden
Last-Modified: Fri, 01 May 2020 21:00:27 GMT
ETag: "31b-5a49c787f10c0"
Accept-Ranges: bytes
Content-Length: 795
Content-Type: text/html
--f05c8c30-H--
Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:05-53.207.154.219.81"] [severity "CRITICAL"] [tag "wp_core"]
Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"]
Action: Intercepted (phase 2)
Stopwatch: 1788144821261955 61784 (- - -)
Stopwatch2: 1788144821261955 61784; combined=60219, p1=272, p2=58828, p3=0, p4=0, p5=878, sr=88, sw=241, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--f05c8c30-Z--
--e0fb7e1c-A--
[31/Aug/2026:05:59:45.339900 +0300] apTuIdmUuou1H8H2UKXArgAAAMo 207.154.219.81 41674 127.0.0.1 7081
--e0fb7e1c-B--
POST /wp-login.php HTTP/1.1
Host: ajutam.ro
X-Real-IP: 207.154.219.81
X-Accel-Internal: /internal-nginx-static-location
Content-Length: 108
Accept: */*
User-Agent: Mozilla/5.0
Content-Type: application/x-www-form-urlencoded
Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818
--e0fb7e1c-F--
HTTP/1.1 403 Forbidden
Last-Modified: Fri, 01 May 2020 21:00:27 GMT
ETag: "31b-5a49c787f10c0"
Accept-Ranges: bytes
Content-Length: 795
Content-Type: text/html
--e0fb7e1c-H--
Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:05-59.207.154.219.81"] [severity "CRITICAL"] [tag "wp_core"]
Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"]
Action: Intercepted (phase 2)
Stopwatch: 1788145185280305 59700 (- - -)
Stopwatch2: 1788145185280305 59700; combined=58222, p1=316, p2=57354, p3=0, p4=0, p5=422, sr=94, sw=130, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--e0fb7e1c-Z--
--6c43d622-A--
[31/Aug/2026:06:03:49.932688 +0300] apTvFX7glkZrdsSdRApIZgAAAI4 35.81.82.181 59344 127.0.0.1 7081
--6c43d622-B--
GET /img/ufo_fm.php HTTP/1.1
Host: ihelp.ro
X-Real-IP: 35.81.82.181
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36
Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
Sec-Fetch-Site: same-origin
Sec-Fetch-Mode: no-cors
Sec-Fetch-Dest: image
Referer: https://ihelp.ro/
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cookie: csrfToken=mPvE2njAl36rBABWojKSTDJjOWZkNjQ2MTA5NmVkM2IzY2QxMmFmM2Q3YjE2YjJiMTE4ZjY5ZWM%3D
--6c43d622-F--
HTTP/1.1 200 OK
X-Powered-By: PHP/8.1.34
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--6c43d622-H--
Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo_fm.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"]
Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo_fm.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo_fm.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "ihelp.ro"] [uri "/img/ufo_fm.php"] [unique_id "apTvFX7glkZrdsSdRApIZgAAAI4"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo_fm.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] [hostname "ihelp.ro"] [uri "/img/ufo_fm.php"] [unique_id "apTvFX7glkZrdsSdRApIZgAAAI4"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788145429918353 14396 (- - -)
Stopwatch2: 1788145429918353 14396; combined=8145, p1=285, p2=7792, p3=0, p4=0, p5=68, sr=103, sw=0, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "DETECTION_ONLY"
--6c43d622-Z--
--21438830-A--
[31/Aug/2026:06:03:50.375794 +0300] apTvFtmUuou1H8H2UKXAxQAAAMs 35.81.82.181 59440 127.0.0.1 7081
--21438830-B--
GET /img/wso_ufo19.php HTTP/1.1
Host: ihelp.ro
X-Real-IP: 35.81.82.181
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36
Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
Sec-Fetch-Site: same-origin
Sec-Fetch-Mode: no-cors
Sec-Fetch-Dest: image
Referer: https://ihelp.ro/
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cookie: csrfToken=mPvE2njAl36rBABWojKSTDJjOWZkNjQ2MTA5NmVkM2IzY2QxMmFmM2Q3YjE2YjJiMTE4ZjY5ZWM%3D
--21438830-F--
HTTP/1.1 200 OK
X-Powered-By: PHP/8.1.34
Set-Cookie: 646109d53af43c125a937b56d9f339f0key=7a804c056f2d36c3c44be5f3d648e096
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--21438830-H--
Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/wso_ufo19.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"]
Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/wso_ufo19.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/wso_ufo19.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "ihelp.ro"] [uri "/img/wso_ufo19.php"] [unique_id "apTvFtmUuou1H8H2UKXAxQAAAMs"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/wso_ufo19.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] [hostname "ihelp.ro"] [uri "/img/wso_ufo19.php"] [unique_id "apTvFtmUuou1H8H2UKXAxQAAAMs"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788145430368637 7221 (- - -)
Stopwatch2: 1788145430368637 7221; combined=4391, p1=214, p2=4117, p3=0, p4=0, p5=59, sr=86, sw=1, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "DETECTION_ONLY"
--21438830-Z--
--c4eb1a14-A--
[31/Aug/2026:06:03:50.422087 +0300] apTvFtmUuou1H8H2UKXAxgAAAMg 35.81.82.181 59454 127.0.0.1 7081
--c4eb1a14-B--
GET /img/ufo19_shell_30207.php HTTP/1.1
Host: ihelp.ro
X-Real-IP: 35.81.82.181
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36
Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
Sec-Fetch-Site: same-origin
Sec-Fetch-Mode: no-cors
Sec-Fetch-Dest: image
Referer: https://ihelp.ro/
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cookie: csrfToken=mPvE2njAl36rBABWojKSTDJjOWZkNjQ2MTA5NmVkM2IzY2QxMmFmM2Q3YjE2YjJiMTE4ZjY5ZWM%3D
--c4eb1a14-F--
HTTP/1.1 200 OK
X-Powered-By: PHP/8.1.34
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--c4eb1a14-H--
Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19_shell_30207.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"]
Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19_shell_30207.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19_shell_30207.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "ihelp.ro"] [uri "/img/ufo19_shell_30207.php"] [unique_id "apTvFtmUuou1H8H2UKXAxgAAAMg"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19_shell_30207.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] [hostname "ihelp.ro"] [uri "/img/ufo19_shell_30207.php"] [unique_id "apTvFtmUuou1H8H2UKXAxgAAAMg"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788145430415007 7142 (- - -)
Stopwatch2: 1788145430415007 7142; combined=4459, p1=225, p2=4176, p3=0, p4=0, p5=57, sr=91, sw=1, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "DETECTION_ONLY"
--c4eb1a14-Z--
--a6dd045b-A--
[31/Aug/2026:06:03:50.725322 +0300] apTvFtmUuou1H8H2UKXAywAAAMo 35.81.82.181 59508 127.0.0.1 7081
--a6dd045b-B--
GET /img/ufo19b_6243.php HTTP/1.1
Host: ihelp.ro
X-Real-IP: 35.81.82.181
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36
Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
Sec-Fetch-Site: same-origin
Sec-Fetch-Mode: no-cors
Sec-Fetch-Dest: image
Referer: https://ihelp.ro/
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cookie: 646109d53af43c125a937b56d9f339f0key=7a804c056f2d36c3c44be5f3d648e096; csrfToken=mPvE2njAl36rBABWojKSTDJjOWZkNjQ2MTA5NmVkM2IzY2QxMmFmM2Q3YjE2YjJiMTE4ZjY5ZWM%3D
--a6dd045b-F--
HTTP/1.1 200 OK
X-Powered-By: PHP/8.1.34
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--a6dd045b-H--
Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19b_6243.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"]
Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19b_6243.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19b_6243.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "ihelp.ro"] [uri "/img/ufo19b_6243.php"] [unique_id "apTvFtmUuou1H8H2UKXAywAAAMo"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19b_6243.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] [hostname "ihelp.ro"] [uri "/img/ufo19b_6243.php"] [unique_id "apTvFtmUuou1H8H2UKXAywAAAMo"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788145430668079 57329 (- - -)
Stopwatch2: 1788145430668079 57329; combined=4616, p1=237, p2=4300, p3=0, p4=0, p5=79, sr=88, sw=0, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "DETECTION_ONLY"
--a6dd045b-Z--
--e4e54d4c-A--
[31/Aug/2026:06:03:50.755389 +0300] apTvFtmUuou1H8H2UKXAxwAAAMA 35.81.82.181 59470 127.0.0.1 7081
--e4e54d4c-B--
GET /img/ufo19c_20960.php HTTP/1.1
Host: ihelp.ro
X-Real-IP: 35.81.82.181
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36
Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
Sec-Fetch-Site: same-origin
Sec-Fetch-Mode: no-cors
Sec-Fetch-Dest: image
Referer: https://ihelp.ro/
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cookie: csrfToken=mPvE2njAl36rBABWojKSTDJjOWZkNjQ2MTA5NmVkM2IzY2QxMmFmM2Q3YjE2YjJiMTE4ZjY5ZWM%3D
--e4e54d4c-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/8.1.34
X-DEBUGKIT-ID: 204a8bcc-983e-4457-8c19-cf9124e13b87
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--e4e54d4c-H--
Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19c_20960.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"]
Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19c_20960.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19c_20960.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "ihelp.ro"] [uri "/img/ufo19c_20960.php"] [unique_id "apTvFtmUuou1H8H2UKXAxwAAAMA"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19c_20960.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] [hostname "ihelp.ro"] [uri "/img/ufo19c_20960.php"] [unique_id "apTvFtmUuou1H8H2UKXAxwAAAMA"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788145430494736 260717 (- - -)
Stopwatch2: 1788145430494736 260717; combined=4083, p1=234, p2=3772, p3=0, p4=0, p5=76, sr=90, sw=1, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "DETECTION_ONLY"
--e4e54d4c-Z--
--a43cbc2c-A--
[31/Aug/2026:06:03:50.878066 +0300] apTvFm7fDIutYTwcPOkZzAAAAFM 35.81.82.181 59476 127.0.0.1 7081
--a43cbc2c-B--
GET /img/ufo19p_20539.php HTTP/1.1
Host: ihelp.ro
X-Real-IP: 35.81.82.181
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36
Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
Sec-Fetch-Site: same-origin
Sec-Fetch-Mode: no-cors
Sec-Fetch-Dest: image
Referer: https://ihelp.ro/
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cookie: csrfToken=mPvE2njAl36rBABWojKSTDJjOWZkNjQ2MTA5NmVkM2IzY2QxMmFmM2Q3YjE2YjJiMTE4ZjY5ZWM%3D
--a43cbc2c-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/8.1.34
X-DEBUGKIT-ID: 4e11523c-08d4-4c80-a30b-164d0da593ce
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--a43cbc2c-H--
Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19p_20539.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"]
Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19p_20539.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19p_20539.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "ihelp.ro"] [uri "/img/ufo19p_20539.php"] [unique_id "apTvFm7fDIutYTwcPOkZzAAAAFM"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19p_20539.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] [hostname "ihelp.ro"] [uri "/img/ufo19p_20539.php"] [unique_id "apTvFm7fDIutYTwcPOkZzAAAAFM"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788145430542420 335710 (- - -)
Stopwatch2: 1788145430542420 335710; combined=4770, p1=268, p2=4437, p3=0, p4=0, p5=65, sr=104, sw=0, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "DETECTION_ONLY"
--a43cbc2c-Z--
--232cdc54-A--
[31/Aug/2026:06:03:50.961047 +0300] apTvFtmUuou1H8H2UKXAyQAAANM 35.81.82.181 59492 127.0.0.1 7081
--232cdc54-B--
GET /img/ufo19w_831.php HTTP/1.1
Host: ihelp.ro
X-Real-IP: 35.81.82.181
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36
Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
Sec-Fetch-Site: same-origin
Sec-Fetch-Mode: no-cors
Sec-Fetch-Dest: image
Referer: https://ihelp.ro/
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cookie: 646109d53af43c125a937b56d9f339f0key=7a804c056f2d36c3c44be5f3d648e096; csrfToken=mPvE2njAl36rBABWojKSTDJjOWZkNjQ2MTA5NmVkM2IzY2QxMmFmM2Q3YjE2YjJiMTE4ZjY5ZWM%3D
--232cdc54-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/8.1.34
X-DEBUGKIT-ID: 5e065ffc-3662-4f2b-baaa-0eefb8f09ef6
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--232cdc54-H--
Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19w_831.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"]
Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19w_831.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19w_831.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "ihelp.ro"] [uri "/img/ufo19w_831.php"] [unique_id "apTvFtmUuou1H8H2UKXAyQAAANM"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19w_831.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] [hostname "ihelp.ro"] [uri "/img/ufo19w_831.php"] [unique_id "apTvFtmUuou1H8H2UKXAyQAAANM"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788145430554836 406287 (- - -)
Stopwatch2: 1788145430554836 406287; combined=4354, p1=204, p2=4084, p3=0, p4=0, p5=66, sr=73, sw=0, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "DETECTION_ONLY"
--232cdc54-Z--
--1f736464-A--
[31/Aug/2026:06:03:51.120054 +0300] apTvFtmUuou1H8H2UKXAzQAAAMY 35.81.82.181 59544 127.0.0.1 7081
--1f736464-B--
GET /img/ufo19_20982.php HTTP/1.1
Host: ihelp.ro
X-Real-IP: 35.81.82.181
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36
Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
Sec-Fetch-Site: same-origin
Sec-Fetch-Mode: no-cors
Sec-Fetch-Dest: image
Referer: https://ihelp.ro/
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cookie: 646109d53af43c125a937b56d9f339f0key=7a804c056f2d36c3c44be5f3d648e096; csrfToken=mPvE2njAl36rBABWojKSTDJjOWZkNjQ2MTA5NmVkM2IzY2QxMmFmM2Q3YjE2YjJiMTE4ZjY5ZWM%3D
--1f736464-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/8.1.34
X-DEBUGKIT-ID: 03b3eb98-ecbc-46a5-8666-1e13378b293a
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--1f736464-H--
Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19_20982.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"]
Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19_20982.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19_20982.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "ihelp.ro"] [uri "/img/ufo19_20982.php"] [unique_id "apTvFtmUuou1H8H2UKXAzQAAAMY"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19_20982.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] [hostname "ihelp.ro"] [uri "/img/ufo19_20982.php"] [unique_id "apTvFtmUuou1H8H2UKXAzQAAAMY"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788145430906356 213770 (- - -)
Stopwatch2: 1788145430906356 213770; combined=4891, p1=281, p2=4487, p3=0, p4=0, p5=123, sr=84, sw=0, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "DETECTION_ONLY"
--1f736464-Z--
--dba48d31-A--
[31/Aug/2026:06:03:51.131150 +0300] apTvF9mUuou1H8H2UKXAzwAAAMk 35.81.82.181 59566 127.0.0.1 7081
--dba48d31-B--
GET /img/ufo_fm.php HTTP/1.1
Host: ihelp.ro
X-Real-IP: 35.81.82.181
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36
Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
Sec-Fetch-Site: same-origin
Sec-Fetch-Mode: no-cors
Sec-Fetch-Dest: image
Referer: https://ihelp.ro/
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cookie: 646109d53af43c125a937b56d9f339f0key=7a804c056f2d36c3c44be5f3d648e096; csrfToken=mPvE2njAl36rBABWojKSTDJjOWZkNjQ2MTA5NmVkM2IzY2QxMmFmM2Q3YjE2YjJiMTE4ZjY5ZWM%3D
--dba48d31-F--
HTTP/1.1 200 OK
X-Powered-By: PHP/8.1.34
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--dba48d31-H--
Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo_fm.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"]
Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo_fm.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo_fm.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "ihelp.ro"] [uri "/img/ufo_fm.php"] [unique_id "apTvF9mUuou1H8H2UKXAzwAAAMk"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo_fm.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] [hostname "ihelp.ro"] [uri "/img/ufo_fm.php"] [unique_id "apTvF9mUuou1H8H2UKXAzwAAAMk"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788145431117968 13242 (- - -)
Stopwatch2: 1788145431117968 13242; combined=9500, p1=257, p2=9187, p3=0, p4=0, p5=55, sr=114, sw=1, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "DETECTION_ONLY"
--dba48d31-Z--
--7140f16d-A--
[31/Aug/2026:06:04:15.764553 +0300] apTvL27fDIutYTwcPOkZ0AAAAEE 120.133.60.156 34272 127.0.0.1 7081
--7140f16d-B--
POST /wp-login.php HTTP/1.1
Host: axapres.ro
X-Real-IP: 120.133.60.156
X-Accel-Internal: /internal-nginx-static-location
Content-Length: 108
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Content-Type: application/x-www-form-urlencoded
Cookie: wordpress_test_cookie=WP+Cookie+check
Origin: https://axapres.ro
Referer: https://axapres.ro/wp-login.php
--7140f16d-F--
HTTP/1.1 403 Forbidden
Content-Length: 199
Content-Type: text/html; charset=iso-8859-1
--7140f16d-H--
Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:06-04.120.133.60.156"] [severity "CRITICAL"] [tag "wp_core"]
Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"]
Action: Intercepted (phase 2)
Apache-Handler: proxy:unix:/var/www/vhosts/system/axapres.ro/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788145455702143 62500 (- - -)
Stopwatch2: 1788145455702143 62500; combined=61518, p1=239, p2=60566, p3=0, p4=0, p5=483, sr=81, sw=230, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--7140f16d-Z--
--c959a14c-A--
[31/Aug/2026:06:06:22.605534 +0300] apTvrifaLSuAj0yzdueSfQAAAA0 207.154.219.81 43842 127.0.0.1 7081
--c959a14c-B--
POST /wp-login.php HTTP/1.1
Host: ajutam.ro
X-Real-IP: 207.154.219.81
X-Accel-Internal: /internal-nginx-static-location
Content-Length: 123
Accept: */*
User-Agent: Mozilla/5.0
Content-Type: application/x-www-form-urlencoded
Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818
--c959a14c-F--
HTTP/1.1 403 Forbidden
Last-Modified: Fri, 01 May 2020 21:00:27 GMT
ETag: "31b-5a49c787f10c0"
Accept-Ranges: bytes
Content-Length: 795
Content-Type: text/html
--c959a14c-H--
Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:06-06.207.154.219.81"] [severity "CRITICAL"] [tag "wp_core"]
Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"]
Action: Intercepted (phase 2)
Stopwatch: 1788145582542740 62869 (- - -)
Stopwatch2: 1788145582542740 62869; combined=61179, p1=858, p2=59801, p3=0, p4=0, p5=388, sr=101, sw=132, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--c959a14c-Z--
--e9092e18-A--
[31/Aug/2026:06:13:01.194919 +0300] apTxPdmUuou1H8H2UKXA8QAAAME 207.154.219.81 47156 127.0.0.1 7081
--e9092e18-B--
POST /wp-login.php HTTP/1.1
Host: ajutam.ro
X-Real-IP: 207.154.219.81
X-Accel-Internal: /internal-nginx-static-location
Content-Length: 105
Accept: */*
User-Agent: Mozilla/5.0
Content-Type: application/x-www-form-urlencoded
Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818
--e9092e18-F--
HTTP/1.1 403 Forbidden
Last-Modified: Fri, 01 May 2020 21:00:27 GMT
ETag: "31b-5a49c787f10c0"
Accept-Ranges: bytes
Content-Length: 795
Content-Type: text/html
--e9092e18-H--
Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:06-13.207.154.219.81"] [severity "CRITICAL"] [tag "wp_core"]
Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"]
Action: Intercepted (phase 2)
Stopwatch: 1788145981128333 66727 (- - -)
Stopwatch2: 1788145981128333 66727; combined=64624, p1=482, p2=60690, p3=0, p4=0, p5=2060, sr=222, sw=1392, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--e9092e18-Z--
--5155e508-A--
[31/Aug/2026:06:18:08.604947 +0300] apTycCfaLSuAj0yzdueSkQAAAAw 34.24.95.24 37350 127.0.0.1 7081
--5155e508-B--
GET /@fs/app/.env?raw?? HTTP/1.1
Host: webmail.chania24.taxi
X-Real-IP: 34.24.95.24
X-Forwarded-For: 172.28.181.196
User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 172.28.181.196
Fastly-Client-Ip: 172.28.181.196
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 172.28.181.196
Upgrade-Insecure-Requests: 1
X-Client-Ip: 172.28.181.196
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 172.28.181.196
sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8"
sec-ch-ua-mobile: ?1
sec-ch-ua-platform: "Android"
--5155e508-F--
HTTP/1.1 404 Not Found
Content-Length: 196
Content-Type: text/html; charset=iso-8859-1
--5155e508-E--
--5155e508-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/@fs/app/.env"] [unique_id "apTycCfaLSuAj0yzdueSkQAAAAw"]
Stopwatch: 1788146288595552 9479 (- - -)
Stopwatch2: 1788146288595552 9479; combined=7887, p1=341, p2=7352, p3=134, p4=9, p5=50, sr=129, sw=1, l=0, gc=0
Response-Body-Transformed: Dechunked
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--5155e508-Z--
--761ef133-A--
[31/Aug/2026:06:18:08.811724 +0300] apTycH7glkZrdsSdRApIkQAAAJg 34.24.95.24 37370 127.0.0.1 7081
--761ef133-B--
GET /@fs/..%252f..%252f..%252f..%252f..%252froot/.env?raw?? HTTP/1.1
Host: webmail.chania24.taxi
X-Real-IP: 34.24.95.24
X-Forwarded-For: 192.168.75.173
User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 192.168.75.173
Fastly-Client-Ip: 192.168.75.173
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 192.168.75.173
Upgrade-Insecure-Requests: 1
X-Client-Ip: 192.168.75.173
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 192.168.75.173
sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8"
sec-ch-ua-mobile: ?1
sec-ch-ua-platform: "Android"
--761ef133-F--
HTTP/1.1 404 Not Found
Content-Length: 196
Content-Type: text/html; charset=iso-8859-1
--761ef133-E--
--761ef133-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/@fs/..%2f..%2f..%2f..%2f..%2froot/.env"] [unique_id "apTycH7glkZrdsSdRApIkQAAAJg"]
Stopwatch: 1788146288804922 6908 (- - -)
Stopwatch2: 1788146288804922 6908; combined=5268, p1=327, p2=4776, p3=84, p4=10, p5=71, sr=118, sw=0, l=0, gc=0
Response-Body-Transformed: Dechunked
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--761ef133-Z--
--a4be4676-A--
[31/Aug/2026:06:18:08.993888 +0300] apTycNmUuou1H8H2UKXBFwAAANQ 34.24.95.24 37382 127.0.0.1 7081
--a4be4676-B--
GET /@fs/..%252f..%252f..%252f..%252f..%252fproc/self/environ?raw?? HTTP/1.1
Host: webmail.chania24.taxi
X-Real-IP: 34.24.95.24
X-Forwarded-For: 172.17.127.58
User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 172.17.127.58
Fastly-Client-Ip: 172.17.127.58
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 172.17.127.58
Upgrade-Insecure-Requests: 1
X-Client-Ip: 172.17.127.58
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 172.17.127.58
sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8"
sec-ch-ua-mobile: ?1
sec-ch-ua-platform: "Android"
--a4be4676-F--
HTTP/1.1 403 Forbidden
Content-Length: 199
Content-Type: text/html; charset=iso-8859-1
--a4be4676-H--
Message: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at MATCHED_VAR. [file "/etc/httpd/conf/modsecurity.d/rules/custom/012_i360_1_generic.conf"] [line "22"] [id "77140166"] [msg "IM360 WAF: Blocking directory traversal attempt||MVN:MATCHED_VAR||MV:/proc/self/environ?raw??||T:APACHE||"] [severity "CRITICAL"] [tag "service_gen"]
Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G:raw??=& P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at MATCHED_VAR. [file "/etc/httpd/conf/modsecurity.d/rules/custom/012_i360_1_generic.conf"] [line "22"] [id "77140166"] [msg "IM360 WAF: Blocking directory traversal attempt||MVN:MATCHED_VAR||MV:/proc/self/environ?raw??||T:APACHE||"] [severity "CRITICAL"] [tag "service_gen"] [hostname "webmail.chania24.taxi"] [uri "/@fs/..%2f..%2f..%2f..%2f..%2fproc/self/environ"] [unique_id "apTycNmUuou1H8H2UKXBFwAAANQ"]
Action: Intercepted (phase 2)
Stopwatch: 1788146288987897 6073 (- - -)
Stopwatch2: 1788146288987897 6073; combined=4435, p1=300, p2=3777, p3=0, p4=0, p5=358, sr=117, sw=0, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--a4be4676-Z--
--78ba2517-A--
[31/Aug/2026:06:18:09.219186 +0300] apTycSfaLSuAj0yzdueSkgAAABY 34.24.95.24 37434 127.0.0.1 7081
--78ba2517-B--
GET /static../.env HTTP/1.1
Host: webmail.chania24.taxi
X-Real-IP: 34.24.95.24
X-Forwarded-For: 172.17.65.186
User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 172.17.65.186
Fastly-Client-Ip: 172.17.65.186
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 172.17.65.186
Upgrade-Insecure-Requests: 1
X-Client-Ip: 172.17.65.186
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 172.17.65.186
sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8"
sec-ch-ua-mobile: ?1
sec-ch-ua-platform: "Android"
--78ba2517-F--
HTTP/1.1 404 Not Found
Content-Length: 196
Content-Type: text/html; charset=iso-8859-1
--78ba2517-E--
--78ba2517-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/static../.env"] [unique_id "apTycSfaLSuAj0yzdueSkgAAABY"]
Stopwatch: 1788146289209648 9651 (- - -)
Stopwatch2: 1788146289209648 9651; combined=7986, p1=447, p2=7385, p3=92, p4=9, p5=53, sr=207, sw=0, l=0, gc=0
Response-Body-Transformed: Dechunked
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--78ba2517-Z--
--82c7b36e-A--
[31/Aug/2026:06:18:09.229674 +0300] apTycdmUuou1H8H2UKXBGQAAAMc 34.24.95.24 37456 127.0.0.1 7081
--82c7b36e-B--
GET /@fs/src/.env?raw?? HTTP/1.1
Host: webmail.chania24.taxi
X-Real-IP: 34.24.95.24
X-Forwarded-For: 192.168.218.248
User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 192.168.218.248
Fastly-Client-Ip: 192.168.218.248
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 192.168.218.248
Upgrade-Insecure-Requests: 1
X-Client-Ip: 192.168.218.248
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 192.168.218.248
sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8"
sec-ch-ua-mobile: ?1
sec-ch-ua-platform: "Android"
--82c7b36e-F--
HTTP/1.1 404 Not Found
Content-Length: 196
Content-Type: text/html; charset=iso-8859-1
--82c7b36e-E--
--82c7b36e-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/@fs/src/.env"] [unique_id "apTycdmUuou1H8H2UKXBGQAAAMc"]
Stopwatch: 1788146289223425 6335 (- - -)
Stopwatch2: 1788146289223425 6335; combined=4753, p1=346, p2=4266, p3=84, p4=9, p5=47, sr=166, sw=1, l=0, gc=0
Response-Body-Transformed: Dechunked
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--82c7b36e-Z--
--29e80a3f-A--
[31/Aug/2026:06:18:09.232685 +0300] apTycW7fDIutYTwcPOkZ1wAAAFE 34.24.95.24 37446 127.0.0.1 7081
--29e80a3f-B--
GET /@fs/../.env?raw?? HTTP/1.1
Host: webmail.chania24.taxi
X-Real-IP: 34.24.95.24
X-Forwarded-For: 192.168.132.70
User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 192.168.132.70
Fastly-Client-Ip: 192.168.132.70
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 192.168.132.70
Upgrade-Insecure-Requests: 1
X-Client-Ip: 192.168.132.70
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 192.168.132.70
sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8"
sec-ch-ua-mobile: ?1
sec-ch-ua-platform: "Android"
--29e80a3f-F--
HTTP/1.1 404 Not Found
Content-Length: 196
Content-Type: text/html; charset=iso-8859-1
--29e80a3f-E--
--29e80a3f-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/.env"] [unique_id "apTycW7fDIutYTwcPOkZ1wAAAFE"]
Stopwatch: 1788146289217261 15620 (- - -)
Stopwatch2: 1788146289217261 15620; combined=7829, p1=559, p2=7029, p3=154, p4=12, p5=74, sr=161, sw=1, l=0, gc=0
Response-Body-Transformed: Dechunked
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--29e80a3f-Z--
--6c43d622-A--
[31/Aug/2026:06:18:09.254146 +0300] apTycSfaLSuAj0yzdueSkwAAABc 34.24.95.24 37468 127.0.0.1 7081
--6c43d622-B--
GET /_nuxt/../.env HTTP/1.1
Host: webmail.chania24.taxi
X-Real-IP: 34.24.95.24
X-Forwarded-For: 192.168.29.181
User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 192.168.29.181
Fastly-Client-Ip: 192.168.29.181
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 192.168.29.181
Upgrade-Insecure-Requests: 1
X-Client-Ip: 192.168.29.181
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 192.168.29.181
sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8"
sec-ch-ua-mobile: ?1
sec-ch-ua-platform: "Android"
--6c43d622-F--
HTTP/1.1 404 Not Found
Content-Length: 196
Content-Type: text/html; charset=iso-8859-1
--6c43d622-E--
--6c43d622-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/.env"] [unique_id "apTycSfaLSuAj0yzdueSkwAAABc"]
Stopwatch: 1788146289246687 7544 (- - -)
Stopwatch2: 1788146289246687 7544; combined=5854, p1=315, p2=5406, p3=82, p4=10, p5=41, sr=104, sw=0, l=0, gc=0
Response-Body-Transformed: Dechunked
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--6c43d622-Z--
--c959a14c-A--
[31/Aug/2026:06:18:09.526338 +0300] apTycW7fDIutYTwcPOkZ2AAAAEw 34.24.95.24 37472 127.0.0.1 7081
--c959a14c-B--
GET /static//app/.env HTTP/1.1
Host: webmail.chania24.taxi
X-Real-IP: 34.24.95.24
X-Forwarded-For: 10.233.245.68
User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 10.233.245.68
Fastly-Client-Ip: 10.233.245.68
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 10.233.245.68
Upgrade-Insecure-Requests: 1
X-Client-Ip: 10.233.245.68
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 10.233.245.68
sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8"
sec-ch-ua-mobile: ?1
sec-ch-ua-platform: "Android"
--c959a14c-F--
HTTP/1.1 404 Not Found
Content-Length: 196
Content-Type: text/html; charset=iso-8859-1
--c959a14c-E--
--c959a14c-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/static/app/.env"] [unique_id "apTycW7fDIutYTwcPOkZ2AAAAEw"]
Stopwatch: 1788146289517107 9316 (- - -)
Stopwatch2: 1788146289517107 9316; combined=7949, p1=265, p2=7558, p3=68, p4=7, p5=50, sr=100, sw=1, l=0, gc=0
Response-Body-Transformed: Dechunked
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--c959a14c-Z--
--d6b4b43a-A--
[31/Aug/2026:06:18:09.533443 +0300] apTycdmUuou1H8H2UKXBGgAAAMw 34.24.95.24 37482 127.0.0.1 7081
--d6b4b43a-B--
GET /media../.env HTTP/1.1
Host: webmail.chania24.taxi
X-Real-IP: 34.24.95.24
X-Forwarded-For: 100.107.189.187
User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 100.107.189.187
Fastly-Client-Ip: 100.107.189.187
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 100.107.189.187
Upgrade-Insecure-Requests: 1
X-Client-Ip: 100.107.189.187
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 100.107.189.187
sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8"
sec-ch-ua-mobile: ?1
sec-ch-ua-platform: "Android"
--d6b4b43a-F--
HTTP/1.1 404 Not Found
Content-Length: 196
Content-Type: text/html; charset=iso-8859-1
--d6b4b43a-E--
--d6b4b43a-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/media../.env"] [unique_id "apTycdmUuou1H8H2UKXBGgAAAMw"]
Stopwatch: 1788146289527195 6330 (- - -)
Stopwatch2: 1788146289527195 6330; combined=4965, p1=303, p2=4540, p3=75, p4=7, p5=40, sr=125, sw=0, l=0, gc=0
Response-Body-Transformed: Dechunked
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--d6b4b43a-Z--
--75771079-A--
[31/Aug/2026:06:18:09.554772 +0300] apTycdmUuou1H8H2UKXBGwAAANg 34.24.95.24 37502 127.0.0.1 7081
--75771079-B--
GET /files../.env HTTP/1.1
Host: webmail.chania24.taxi
X-Real-IP: 34.24.95.24
X-Forwarded-For: 100.118.234.89
User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 100.118.234.89
Fastly-Client-Ip: 100.118.234.89
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 100.118.234.89
Upgrade-Insecure-Requests: 1
X-Client-Ip: 100.118.234.89
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 100.118.234.89
sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8"
sec-ch-ua-mobile: ?1
sec-ch-ua-platform: "Android"
--75771079-F--
HTTP/1.1 404 Not Found
Content-Length: 196
Content-Type: text/html; charset=iso-8859-1
--75771079-E--
--75771079-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/files../.env"] [unique_id "apTycdmUuou1H8H2UKXBGwAAANg"]
Stopwatch: 1788146289547589 7265 (- - -)
Stopwatch2: 1788146289547589 7265; combined=5302, p1=371, p2=4801, p3=84, p4=7, p5=39, sr=113, sw=0, l=0, gc=0
Response-Body-Transformed: Dechunked
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--75771079-Z--
--5155e508-A--
[31/Aug/2026:06:18:09.555041 +0300] apTycW7fDIutYTwcPOkZ2QAAAFM 34.24.95.24 37496 127.0.0.1 7081
--5155e508-B--
GET /.//.env HTTP/1.1
Host: webmail.chania24.taxi
X-Real-IP: 34.24.95.24
X-Forwarded-For: 10.216.139.92
User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 10.216.139.92
Fastly-Client-Ip: 10.216.139.92
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 10.216.139.92
Upgrade-Insecure-Requests: 1
X-Client-Ip: 10.216.139.92
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 10.216.139.92
sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8"
sec-ch-ua-mobile: ?1
sec-ch-ua-platform: "Android"
--5155e508-F--
HTTP/1.1 404 Not Found
Content-Length: 196
Content-Type: text/html; charset=iso-8859-1
--5155e508-E--
--5155e508-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/.env"] [unique_id "apTycW7fDIutYTwcPOkZ2QAAAFM"]
Stopwatch: 1788146289535242 19921 (- - -)
Stopwatch2: 1788146289535242 19921; combined=7316, p1=278, p2=6876, p3=108, p4=9, p5=45, sr=106, sw=0, l=0, gc=0
Response-Body-Transformed: Dechunked
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--5155e508-Z--
--83ef5677-A--
[31/Aug/2026:06:18:09.567126 +0300] apTycX7glkZrdsSdRApIlAAAAIc 34.24.95.24 37516 127.0.0.1 7081
--83ef5677-B--
GET /static//.env HTTP/1.1
Host: webmail.chania24.taxi
X-Real-IP: 34.24.95.24
X-Forwarded-For: 192.168.41.6
User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 192.168.41.6
Fastly-Client-Ip: 192.168.41.6
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 192.168.41.6
Upgrade-Insecure-Requests: 1
X-Client-Ip: 192.168.41.6
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 192.168.41.6
sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8"
sec-ch-ua-mobile: ?1
sec-ch-ua-platform: "Android"
--83ef5677-F--
HTTP/1.1 404 Not Found
Content-Length: 196
Content-Type: text/html; charset=iso-8859-1
--83ef5677-E--
--83ef5677-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/static/.env"] [unique_id "apTycX7glkZrdsSdRApIlAAAAIc"]
Stopwatch: 1788146289561088 6121 (- - -)
Stopwatch2: 1788146289561088 6121; combined=4785, p1=298, p2=4372, p3=69, p4=7, p5=39, sr=104, sw=0, l=0, gc=0
Response-Body-Transformed: Dechunked
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--83ef5677-Z--
--78ba2517-A--
[31/Aug/2026:06:18:09.726822 +0300] apTycW7fDIutYTwcPOkZ2gAAAFY 34.24.95.24 37518 127.0.0.1 7081
--78ba2517-B--
GET /static//home/user/.env HTTP/1.1
Host: webmail.chania24.taxi
X-Real-IP: 34.24.95.24
X-Forwarded-For: 10.42.236.25
User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 10.42.236.25
Fastly-Client-Ip: 10.42.236.25
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 10.42.236.25
Upgrade-Insecure-Requests: 1
X-Client-Ip: 10.42.236.25
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 10.42.236.25
sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8"
sec-ch-ua-mobile: ?1
sec-ch-ua-platform: "Android"
--78ba2517-F--
HTTP/1.1 404 Not Found
Content-Length: 196
Content-Type: text/html; charset=iso-8859-1
--78ba2517-E--
--78ba2517-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/static/home/user/.env"] [unique_id "apTycW7fDIutYTwcPOkZ2gAAAFY"]
Stopwatch: 1788146289720117 6798 (- - -)
Stopwatch2: 1788146289720117 6798; combined=5312, p1=268, p2=4929, p3=65, p4=7, p5=43, sr=105, sw=0, l=0, gc=0
Response-Body-Transformed: Dechunked
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--78ba2517-Z--
--1c98420c-A--
[31/Aug/2026:06:18:10.012023 +0300] apTycn7glkZrdsSdRApIlQAAAIw 34.24.95.24 37528 127.0.0.1 7081
--1c98420c-B--
GET /api/.env/public/.env HTTP/1.1
Host: webmail.chania24.taxi
X-Real-IP: 34.24.95.24
X-Forwarded-For: 10.93.33.68
User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 10.93.33.68
Fastly-Client-Ip: 10.93.33.68
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 10.93.33.68
Upgrade-Insecure-Requests: 1
X-Client-Ip: 10.93.33.68
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 10.93.33.68
sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8"
sec-ch-ua-mobile: ?1
sec-ch-ua-platform: "Android"
--1c98420c-F--
HTTP/1.1 404 Not Found
Content-Length: 196
Content-Type: text/html; charset=iso-8859-1
--1c98420c-E--
--1c98420c-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/api/.env/public/.env"] [unique_id "apTycn7glkZrdsSdRApIlQAAAIw"]
Stopwatch: 1788146290005596 6523 (- - -)
Stopwatch2: 1788146290005596 6523; combined=5008, p1=313, p2=4574, p3=74, p4=8, p5=39, sr=127, sw=0, l=0, gc=0
Response-Body-Transformed: Dechunked
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--1c98420c-Z--
--761ef133-A--
[31/Aug/2026:06:18:10.019779 +0300] apTycifaLSuAj0yzdueSlAAAABE 34.24.95.24 37540 127.0.0.1 7081
--761ef133-B--
GET //.env HTTP/1.1
Host: webmail.chania24.taxi
X-Real-IP: 34.24.95.24
X-Forwarded-For: 192.168.3.21
User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 192.168.3.21
Fastly-Client-Ip: 192.168.3.21
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 192.168.3.21
Upgrade-Insecure-Requests: 1
X-Client-Ip: 192.168.3.21
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 192.168.3.21
sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8"
sec-ch-ua-mobile: ?1
sec-ch-ua-platform: "Android"
--761ef133-F--
HTTP/1.1 404 Not Found
Content-Length: 196
Content-Type: text/html; charset=iso-8859-1
--761ef133-E--
--761ef133-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/.env"] [unique_id "apTycifaLSuAj0yzdueSlAAAABE"]
Stopwatch: 1788146290012880 6999 (- - -)
Stopwatch2: 1788146290012880 6999; combined=5499, p1=245, p2=5073, p3=76, p4=54, p5=50, sr=96, sw=1, l=0, gc=0
Response-Body-Transformed: Dechunked
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--761ef133-Z--
--d5370b71-A--
[31/Aug/2026:06:18:10.020179 +0300] apTycn7glkZrdsSdRApIlgAAAIU 34.24.95.24 37546 127.0.0.1 7081
--d5370b71-B--
GET /%2eenv HTTP/1.1
Host: webmail.chania24.taxi
X-Real-IP: 34.24.95.24
X-Forwarded-For: 10.56.223.24
User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 10.56.223.24
Fastly-Client-Ip: 10.56.223.24
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 10.56.223.24
Upgrade-Insecure-Requests: 1
X-Client-Ip: 10.56.223.24
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 10.56.223.24
sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8"
sec-ch-ua-mobile: ?1
sec-ch-ua-platform: "Android"
--d5370b71-F--
HTTP/1.1 404 Not Found
Content-Length: 196
Content-Type: text/html; charset=iso-8859-1
--d5370b71-E--
--d5370b71-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/.env"] [unique_id "apTycn7glkZrdsSdRApIlgAAAIU"]
Stopwatch: 1788146290013045 7235 (- - -)
Stopwatch2: 1788146290013045 7235; combined=5798, p1=325, p2=5344, p3=77, p4=8, p5=44, sr=122, sw=0, l=0, gc=0
Response-Body-Transformed: Dechunked
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--d5370b71-Z--
--b033220f-A--
[31/Aug/2026:06:18:10.201936 +0300] apTyctmUuou1H8H2UKXBHAAAAMo 34.24.95.24 37570 127.0.0.1 7081
--b033220f-B--
GET /images../.env HTTP/1.1
Host: webmail.chania24.taxi
X-Real-IP: 34.24.95.24
X-Forwarded-For: 100.77.204.197
User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 100.77.204.197
Fastly-Client-Ip: 100.77.204.197
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 100.77.204.197
Upgrade-Insecure-Requests: 1
X-Client-Ip: 100.77.204.197
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 100.77.204.197
sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8"
sec-ch-ua-mobile: ?1
sec-ch-ua-platform: "Android"
--b033220f-F--
HTTP/1.1 404 Not Found
Content-Length: 196
Content-Type: text/html; charset=iso-8859-1
--b033220f-E--
--b033220f-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/images../.env"] [unique_id "apTyctmUuou1H8H2UKXBHAAAAMo"]
Stopwatch: 1788146290195634 6395 (- - -)
Stopwatch2: 1788146290195634 6395; combined=5118, p1=308, p2=4672, p3=83, p4=8, p5=47, sr=103, sw=0, l=0, gc=0
Response-Body-Transformed: Dechunked
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--b033220f-Z--
--f284a63c-A--
[31/Aug/2026:06:18:10.208347 +0300] apTyctmUuou1H8H2UKXBHQAAAM0 34.24.95.24 37582 127.0.0.1 7081
--f284a63c-B--
GET /uploads../.env HTTP/1.1
Host: webmail.chania24.taxi
X-Real-IP: 34.24.95.24
X-Forwarded-For: 192.168.188.130
User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 192.168.188.130
Fastly-Client-Ip: 192.168.188.130
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 192.168.188.130
Upgrade-Insecure-Requests: 1
X-Client-Ip: 192.168.188.130
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 192.168.188.130
sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8"
sec-ch-ua-mobile: ?1
sec-ch-ua-platform: "Android"
--f284a63c-F--
HTTP/1.1 404 Not Found
Content-Length: 196
Content-Type: text/html; charset=iso-8859-1
--f284a63c-E--
--f284a63c-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/uploads../.env"] [unique_id "apTyctmUuou1H8H2UKXBHQAAAM0"]
Stopwatch: 1788146290202493 5936 (- - -)
Stopwatch2: 1788146290202493 5936; combined=4647, p1=286, p2=4264, p3=54, p4=7, p5=36, sr=122, sw=0, l=0, gc=0
Response-Body-Transformed: Dechunked
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--f284a63c-Z--
--17b40101-A--
[31/Aug/2026:06:18:10.215392 +0300] apTyctmUuou1H8H2UKXBHgAAANU 34.24.95.24 37556 127.0.0.1 7081
--17b40101-B--
GET /img../.env HTTP/1.1
Host: webmail.chania24.taxi
X-Real-IP: 34.24.95.24
X-Forwarded-For: 172.31.10.90
User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 172.31.10.90
Fastly-Client-Ip: 172.31.10.90
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 172.31.10.90
Upgrade-Insecure-Requests: 1
X-Client-Ip: 172.31.10.90
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 172.31.10.90
sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8"
sec-ch-ua-mobile: ?1
sec-ch-ua-platform: "Android"
--17b40101-F--
HTTP/1.1 404 Not Found
Content-Length: 196
Content-Type: text/html; charset=iso-8859-1
--17b40101-E--
--17b40101-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/img../.env"] [unique_id "apTyctmUuou1H8H2UKXBHgAAANU"]
Stopwatch: 1788146290204485 11188 (- - -)
Stopwatch2: 1788146290204485 11188; combined=9393, p1=567, p2=8146, p3=604, p4=12, p5=63, sr=188, sw=1, l=0, gc=0
Response-Body-Transformed: Dechunked
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--17b40101-Z--
--590c442a-A--
[31/Aug/2026:06:18:10.394101 +0300] apTyctmUuou1H8H2UKXBHwAAAMQ 34.24.95.24 37624 127.0.0.1 7081
--590c442a-B--
GET /assets../.env HTTP/1.1
Host: webmail.chania24.taxi
X-Real-IP: 34.24.95.24
X-Forwarded-For: 100.87.155.24
User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 100.87.155.24
Fastly-Client-Ip: 100.87.155.24
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 100.87.155.24
Upgrade-Insecure-Requests: 1
X-Client-Ip: 100.87.155.24
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 100.87.155.24
sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8"
sec-ch-ua-mobile: ?1
sec-ch-ua-platform: "Android"
--590c442a-F--
HTTP/1.1 404 Not Found
Content-Length: 196
Content-Type: text/html; charset=iso-8859-1
--590c442a-E--
--590c442a-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/assets../.env"] [unique_id "apTyctmUuou1H8H2UKXBHwAAAMQ"]
Stopwatch: 1788146290383070 11317 (- - -)
Stopwatch2: 1788146290383070 11317; combined=9181, p1=535, p2=8371, p3=148, p4=56, p5=71, sr=161, sw=0, l=0, gc=0
Response-Body-Transformed: Dechunked
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--590c442a-Z--
--589ad94a-A--
[31/Aug/2026:06:18:10.455217 +0300] apTyctmUuou1H8H2UKXBIAAAAM4 34.24.95.24 37636 127.0.0.1 7081
--589ad94a-B--
GET /@fs/var/task/.env?raw?? HTTP/1.1
Host: webmail.chania24.taxi
X-Real-IP: 34.24.95.24
X-Forwarded-For: 10.224.20.36
User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 10.224.20.36
Fastly-Client-Ip: 10.224.20.36
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 10.224.20.36
Upgrade-Insecure-Requests: 1
X-Client-Ip: 10.224.20.36
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 10.224.20.36
sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8"
sec-ch-ua-mobile: ?1
sec-ch-ua-platform: "Android"
--589ad94a-F--
HTTP/1.1 404 Not Found
Content-Length: 196
Content-Type: text/html; charset=iso-8859-1
--589ad94a-E--
--589ad94a-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/@fs/var/task/.env"] [unique_id "apTyctmUuou1H8H2UKXBIAAAAM4"]
Stopwatch: 1788146290449950 5350 (- - -)
Stopwatch2: 1788146290449950 5350; combined=4012, p1=285, p2=3618, p3=64, p4=7, p5=37, sr=103, sw=1, l=0, gc=0
Response-Body-Transformed: Dechunked
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--589ad94a-Z--
--1a6bac2f-A--
[31/Aug/2026:06:18:10.485112 +0300] apTyctmUuou1H8H2UKXBIQAAAME 34.24.95.24 37646 127.0.0.1 7081
--1a6bac2f-B--
GET /@fs/proc/self/cwd/.env?raw?? HTTP/1.1
Host: webmail.chania24.taxi
X-Real-IP: 34.24.95.24
X-Forwarded-For: 172.26.80.199
User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 172.26.80.199
Fastly-Client-Ip: 172.26.80.199
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 172.26.80.199
Upgrade-Insecure-Requests: 1
X-Client-Ip: 172.26.80.199
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 172.26.80.199
sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8"
sec-ch-ua-mobile: ?1
sec-ch-ua-platform: "Android"
--1a6bac2f-F--
HTTP/1.1 404 Not Found
Content-Length: 196
Content-Type: text/html; charset=iso-8859-1
--1a6bac2f-E--
--1a6bac2f-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/@fs/proc/self/cwd/.env"] [unique_id "apTyctmUuou1H8H2UKXBIQAAAME"]
Stopwatch: 1788146290462379 22932 (- - -)
Stopwatch2: 1788146290462379 22932; combined=21011, p1=529, p2=20145, p3=241, p4=11, p5=85, sr=259, sw=0, l=0, gc=0
Response-Body-Transformed: Dechunked
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--1a6bac2f-Z--
--83ef5677-A--
[31/Aug/2026:06:18:11.226528 +0300] apTycyfaLSuAj0yzdueSlQAAAAU 34.24.95.24 37690 127.0.0.1 7081
--83ef5677-B--
GET /@fs/.env?raw&url?? HTTP/1.1
Host: webmail.chania24.taxi
X-Real-IP: 34.24.95.24
X-Forwarded-For: 100.89.48.229
User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 100.89.48.229
Fastly-Client-Ip: 100.89.48.229
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 100.89.48.229
Upgrade-Insecure-Requests: 1
X-Client-Ip: 100.89.48.229
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 100.89.48.229
sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8"
sec-ch-ua-mobile: ?1
sec-ch-ua-platform: "Android"
--83ef5677-F--
HTTP/1.1 404 Not Found
Content-Length: 196
Content-Type: text/html; charset=iso-8859-1
--83ef5677-E--
--83ef5677-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw&url??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw&url??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/@fs/.env"] [unique_id "apTycyfaLSuAj0yzdueSlQAAAAU"]
Stopwatch: 1788146291219638 6999 (- - -)
Stopwatch2: 1788146291219638 6999; combined=3932, p1=200, p2=3623, p3=64, p4=6, p5=39, sr=74, sw=0, l=0, gc=0
Response-Body-Transformed: Dechunked
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--83ef5677-Z--
--6c43d622-A--
[31/Aug/2026:06:18:11.227515 +0300] apTyc27fDIutYTwcPOkZ3AAAAEI 34.24.95.24 37674 127.0.0.1 7081
--6c43d622-B--
GET /@fs/.env?url&raw?? HTTP/1.1
Host: webmail.chania24.taxi
X-Real-IP: 34.24.95.24
X-Forwarded-For: 10.193.243.14
User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 10.193.243.14
Fastly-Client-Ip: 10.193.243.14
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 10.193.243.14
Upgrade-Insecure-Requests: 1
X-Client-Ip: 10.193.243.14
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 10.193.243.14
sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8"
sec-ch-ua-mobile: ?1
sec-ch-ua-platform: "Android"
--6c43d622-F--
HTTP/1.1 404 Not Found
Content-Length: 196
Content-Type: text/html; charset=iso-8859-1
--6c43d622-E--
--6c43d622-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:url&raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:url&raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/@fs/.env"] [unique_id "apTyc27fDIutYTwcPOkZ3AAAAEI"]
Stopwatch: 1788146291219139 8493 (- - -)
Stopwatch2: 1788146291219139 8493; combined=4063, p1=291, p2=3623, p3=99, p4=3, p5=46, sr=108, sw=1, l=0, gc=0
Response-Body-Transformed: Dechunked
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--6c43d622-Z--
--761ef133-A--
[31/Aug/2026:06:18:11.764499 +0300] apTyc27fDIutYTwcPOkZ3QAAAEM 34.24.95.24 37744 127.0.0.1 7081
--761ef133-B--
GET /@fs/.env?import&?raw?? HTTP/1.1
Host: webmail.chania24.taxi
X-Real-IP: 34.24.95.24
X-Forwarded-For: 10.3.184.21
User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 10.3.184.21
Fastly-Client-Ip: 10.3.184.21
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 10.3.184.21
Upgrade-Insecure-Requests: 1
X-Client-Ip: 10.3.184.21
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 10.3.184.21
sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8"
sec-ch-ua-mobile: ?1
sec-ch-ua-platform: "Android"
--761ef133-F--
HTTP/1.1 404 Not Found
Content-Length: 196
Content-Type: text/html; charset=iso-8859-1
--761ef133-E--
--761ef133-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:import&?raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:import&?raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/@fs/.env"] [unique_id "apTyc27fDIutYTwcPOkZ3QAAAEM"]
Stopwatch: 1788146291758670 5913 (- - -)
Stopwatch2: 1788146291758670 5913; combined=4653, p1=229, p2=4298, p3=76, p4=8, p5=41, sr=74, sw=1, l=0, gc=0
Response-Body-Transformed: Dechunked
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--761ef133-Z--
--05969073-A--
[31/Aug/2026:06:18:11.791062 +0300] apTyc9mUuou1H8H2UKXBJQAAAMU 34.24.95.24 37732 127.0.0.1 7081
--05969073-B--
GET /config/.env.php HTTP/1.1
Host: webmail.chania24.taxi
X-Real-IP: 34.24.95.24
X-Forwarded-For: 172.22.142.141
User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 172.22.142.141
Fastly-Client-Ip: 172.22.142.141
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 172.22.142.141
Upgrade-Insecure-Requests: 1
X-Client-Ip: 172.22.142.141
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 172.22.142.141
sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8"
sec-ch-ua-mobile: ?1
sec-ch-ua-platform: "Android"
--05969073-F--
HTTP/1.1 404 Not Found
Content-Length: 196
Content-Type: text/html; charset=iso-8859-1
--05969073-E--
--05969073-H--
Message: Warning. Matched phrase ".env.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/config/.env.php||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"]
Message: Warning. Matched phrase ".env.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/config/.env.php||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".env.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/config/.env.php||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "webmail.chania24.taxi"] [uri "/config/.env.php"] [unique_id "apTyc9mUuou1H8H2UKXBJQAAAMU"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".env.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/config/.env.php||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/config/.env.php"] [unique_id "apTyc9mUuou1H8H2UKXBJQAAAMU"]
Stopwatch: 1788146291752398 38758 (- - -)
Stopwatch2: 1788146291752398 38758; combined=37508, p1=301, p2=37089, p3=65, p4=7, p5=46, sr=136, sw=0, l=0, gc=0
Response-Body-Transformed: Dechunked
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--05969073-Z--
--2d58ee79-A--
[31/Aug/2026:06:18:11.791664 +0300] apTyc9mUuou1H8H2UKXBJgAAAMY 34.24.95.24 37742 127.0.0.1 7081
--2d58ee79-B--
GET /wp-config.php.bak HTTP/1.1
Host: webmail.chania24.taxi
X-Real-IP: 34.24.95.24
X-Forwarded-For: 100.110.233.113
User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 100.110.233.113
Fastly-Client-Ip: 100.110.233.113
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 100.110.233.113
Upgrade-Insecure-Requests: 1
X-Client-Ip: 100.110.233.113
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 100.110.233.113
sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8"
sec-ch-ua-mobile: ?1
sec-ch-ua-platform: "Android"
--2d58ee79-F--
HTTP/1.1 404 Not Found
Content-Length: 196
Content-Type: text/html; charset=iso-8859-1
--2d58ee79-E--
--2d58ee79-H--
Message: Warning. Matched phrase "wp-config.php." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/wp-config.php.bak||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"]
Message: Warning. Matched phrase "wp-config.php." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/wp-config.php.bak||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"]
Message: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "wp-config.php." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/wp-config.php.bak||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "webmail.chania24.taxi"] [uri "/wp-config.php.bak"] [unique_id "apTyc9mUuou1H8H2UKXBJgAAAMY"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "wp-config.php." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/wp-config.php.bak||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/wp-config.php.bak"] [unique_id "apTyc9mUuou1H8H2UKXBJgAAAMY"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/wp-config.php.bak"] [unique_id "apTyc9mUuou1H8H2UKXBJgAAAMY"]
Stopwatch: 1788146291756159 35587 (- - -)
Stopwatch2: 1788146291756159 35587; combined=34398, p1=278, p2=34014, p3=37, p4=5, p5=64, sr=121, sw=0, l=0, gc=0
Response-Body-Transformed: Dechunked
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--2d58ee79-Z--
--40b18017-A--
[31/Aug/2026:06:18:11.963201 +0300] apTyc37glkZrdsSdRApImwAAAJM 34.24.95.24 37768 127.0.0.1 7081
--40b18017-B--
GET /laravel/.env HTTP/1.1
Host: webmail.chania24.taxi
X-Real-IP: 34.24.95.24
X-Forwarded-For: 192.168.154.2
User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 192.168.154.2
Fastly-Client-Ip: 192.168.154.2
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 192.168.154.2
Upgrade-Insecure-Requests: 1
X-Client-Ip: 192.168.154.2
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 192.168.154.2
sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8"
sec-ch-ua-mobile: ?1
sec-ch-ua-platform: "Android"
--40b18017-F--
HTTP/1.1 404 Not Found
Content-Length: 196
Content-Type: text/html; charset=iso-8859-1
--40b18017-E--
--40b18017-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/laravel/.env"] [unique_id "apTyc37glkZrdsSdRApImwAAAJM"]
Stopwatch: 1788146291949816 13478 (- - -)
Stopwatch2: 1788146291949816 13478; combined=6316, p1=1594, p2=4606, p3=66, p4=7, p5=42, sr=102, sw=1, l=0, gc=0
Response-Body-Transformed: Dechunked
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--40b18017-Z--
--904cf438-A--
[31/Aug/2026:06:18:12.061086 +0300] apTydNmUuou1H8H2UKXBJwAAAMw 34.24.95.24 37784 127.0.0.1 7081
--904cf438-B--
GET /wp-config.php.old HTTP/1.1
Host: webmail.chania24.taxi
X-Real-IP: 34.24.95.24
X-Forwarded-For: 10.116.49.63
User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 10.116.49.63
Fastly-Client-Ip: 10.116.49.63
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 10.116.49.63
Upgrade-Insecure-Requests: 1
X-Client-Ip: 10.116.49.63
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 10.116.49.63
sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8"
sec-ch-ua-mobile: ?1
sec-ch-ua-platform: "Android"
--904cf438-F--
HTTP/1.1 404 Not Found
Content-Length: 196
Content-Type: text/html; charset=iso-8859-1
--904cf438-E--
--904cf438-H--
Message: Warning. Matched phrase "wp-config.php." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/wp-config.php.old||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"]
Message: Warning. Matched phrase "wp-config.php." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/wp-config.php.old||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"]
Message: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "wp-config.php." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/wp-config.php.old||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "webmail.chania24.taxi"] [uri "/wp-config.php.old"] [unique_id "apTydNmUuou1H8H2UKXBJwAAAMw"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "wp-config.php." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/wp-config.php.old||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/wp-config.php.old"] [unique_id "apTydNmUuou1H8H2UKXBJwAAAMw"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/wp-config.php.old"] [unique_id "apTydNmUuou1H8H2UKXBJwAAAMw"]
Stopwatch: 1788146292027588 33581 (- - -)
Stopwatch2: 1788146292027588 33581; combined=32260, p1=240, p2=31899, p3=61, p4=7, p5=52, sr=83, sw=1, l=0, gc=0
Response-Body-Transformed: Dechunked
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--904cf438-Z--
--1c98420c-A--
[31/Aug/2026:06:18:12.149572 +0300] apTydCfaLSuAj0yzdueSmAAAAA0 34.24.95.24 37802 127.0.0.1 7081
--1c98420c-B--
GET /core/.env HTTP/1.1
Host: webmail.chania24.taxi
X-Real-IP: 34.24.95.24
X-Forwarded-For: 172.30.60.95
User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 172.30.60.95
Fastly-Client-Ip: 172.30.60.95
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 172.30.60.95
Upgrade-Insecure-Requests: 1
X-Client-Ip: 172.30.60.95
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 172.30.60.95
sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8"
sec-ch-ua-mobile: ?1
sec-ch-ua-platform: "Android"
--1c98420c-F--
HTTP/1.1 404 Not Found
Content-Length: 196
Content-Type: text/html; charset=iso-8859-1
--1c98420c-E--
--1c98420c-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/core/.env"] [unique_id "apTydCfaLSuAj0yzdueSmAAAAA0"]
Stopwatch: 1788146292141121 8560 (- - -)
Stopwatch2: 1788146292141121 8560; combined=7031, p1=280, p2=6621, p3=78, p4=9, p5=43, sr=96, sw=0, l=0, gc=0
Response-Body-Transformed: Dechunked
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--1c98420c-Z--
--d5370b71-A--
[31/Aug/2026:06:18:12.169745 +0300] apTydCfaLSuAj0yzdueSlwAAABI 34.24.95.24 37800 127.0.0.1 7081
--d5370b71-B--
GET /.env.php.bak HTTP/1.1
Host: webmail.chania24.taxi
X-Real-IP: 34.24.95.24
X-Forwarded-For: 10.53.117.228
User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 10.53.117.228
Fastly-Client-Ip: 10.53.117.228
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 10.53.117.228
Upgrade-Insecure-Requests: 1
X-Client-Ip: 10.53.117.228
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 10.53.117.228
sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8"
sec-ch-ua-mobile: ?1
sec-ch-ua-platform: "Android"
--d5370b71-F--
HTTP/1.1 404 Not Found
Content-Length: 196
Content-Type: text/html; charset=iso-8859-1
--d5370b71-E--
--d5370b71-H--
Message: Warning. Matched phrase ".env.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.env.php.bak||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"]
Message: Warning. Matched phrase ".env.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.env.php.bak||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".env.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.env.php.bak||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "webmail.chania24.taxi"] [uri "/.env.php.bak"] [unique_id "apTydCfaLSuAj0yzdueSlwAAABI"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".env.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.env.php.bak||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/.env.php.bak"] [unique_id "apTydCfaLSuAj0yzdueSlwAAABI"]
Stopwatch: 1788146292132811 37042 (- - -)
Stopwatch2: 1788146292132811 37042; combined=35376, p1=339, p2=34893, p3=87, p4=8, p5=48, sr=123, sw=1, l=0, gc=0
Response-Body-Transformed: Dechunked
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--d5370b71-Z--
--83ef5677-A--
[31/Aug/2026:06:18:12.348283 +0300] apTydG7fDIutYTwcPOkZ3gAAAEY 34.24.95.24 37816 127.0.0.1 7081
--83ef5677-B--
GET /.env.swp HTTP/1.1
Host: webmail.chania24.taxi
X-Real-IP: 34.24.95.24
X-Forwarded-For: 10.27.17.157
User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 10.27.17.157
Fastly-Client-Ip: 10.27.17.157
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 10.27.17.157
Upgrade-Insecure-Requests: 1
X-Client-Ip: 10.27.17.157
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 10.27.17.157
sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8"
sec-ch-ua-mobile: ?1
sec-ch-ua-platform: "Android"
--83ef5677-F--
HTTP/1.1 404 Not Found
Content-Length: 196
Content-Type: text/html; charset=iso-8859-1
--83ef5677-E--
--83ef5677-H--
Message: Warning. Pattern match "(\\.swp|~)$" at REQUEST_BASENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "309"] [id "77142201"] [msg "IM360 WAF: Possible enumeration of sensitive data (dirb)||MVN:REQUEST_BASENAME||T:APACHE||MV:.env.swp||"] [severity "NOTICE"] [tag "service_i360custom"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\.swp|~)$" at REQUEST_BASENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "309"] [id "77142201"] [msg "IM360 WAF: Possible enumeration of sensitive data (dirb)||MVN:REQUEST_BASENAME||T:APACHE||MV:.env.swp||"] [severity "NOTICE"] [tag "service_i360custom"] [hostname "webmail.chania24.taxi"] [uri "/.env.swp"] [unique_id "apTydG7fDIutYTwcPOkZ3gAAAEY"]
Stopwatch: 1788146292338396 9990 (- - -)
Stopwatch2: 1788146292338396 9990; combined=7695, p1=327, p2=7194, p3=96, p4=9, p5=69, sr=137, sw=0, l=0, gc=0
Response-Body-Transformed: Dechunked
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--83ef5677-Z--
--9e4b441f-A--
[31/Aug/2026:06:18:12.365798 +0300] apTydNmUuou1H8H2UKXBKAAAAMM 34.24.95.24 37824 127.0.0.1 7081
--9e4b441f-B--
GET /config.php.bak HTTP/1.1
Host: webmail.chania24.taxi
X-Real-IP: 34.24.95.24
X-Forwarded-For: 192.168.119.7
User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 192.168.119.7
Fastly-Client-Ip: 192.168.119.7
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 192.168.119.7
Upgrade-Insecure-Requests: 1
X-Client-Ip: 192.168.119.7
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 192.168.119.7
sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8"
sec-ch-ua-mobile: ?1
sec-ch-ua-platform: "Android"
--9e4b441f-F--
HTTP/1.1 404 Not Found
Content-Length: 196
Content-Type: text/html; charset=iso-8859-1
--9e4b441f-E--
--9e4b441f-H--
Message: Warning. Matched phrase "/config.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "/config.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/config.php.bak"] [unique_id "apTydNmUuou1H8H2UKXBKAAAAMM"]
Stopwatch: 1788146292357293 8625 (- - -)
Stopwatch2: 1788146292357293 8625; combined=6908, p1=378, p2=6372, p3=96, p4=10, p5=52, sr=120, sw=0, l=0, gc=0
Response-Body-Transformed: Dechunked
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--9e4b441f-Z--
--40b18017-A--
[31/Aug/2026:06:18:12.383399 +0300] apTydCfaLSuAj0yzdueSmQAAAAc 34.24.95.24 37836 127.0.0.1 7081
--40b18017-B--
GET /configuration.php.bak HTTP/1.1
Host: webmail.chania24.taxi
X-Real-IP: 34.24.95.24
X-Forwarded-For: 172.22.147.122
User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 172.22.147.122
Fastly-Client-Ip: 172.22.147.122
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 172.22.147.122
Upgrade-Insecure-Requests: 1
X-Client-Ip: 172.22.147.122
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 172.22.147.122
sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8"
sec-ch-ua-mobile: ?1
sec-ch-ua-platform: "Android"
--40b18017-F--
HTTP/1.1 404 Not Found
Content-Length: 196
Content-Type: text/html; charset=iso-8859-1
--40b18017-E--
--40b18017-H--
Message: Warning. Matched phrase "/configuration.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "/configuration.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/configuration.php.bak"] [unique_id "apTydCfaLSuAj0yzdueSmQAAAAc"]
Stopwatch: 1788146292375308 8201 (- - -)
Stopwatch2: 1788146292375308 8201; combined=6451, p1=367, p2=5936, p3=88, p4=10, p5=50, sr=118, sw=0, l=0, gc=0
Response-Body-Transformed: Dechunked
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--40b18017-Z--
--1f538b55-A--
[31/Aug/2026:06:18:12.401999 +0300] apTydCfaLSuAj0yzdueSmgAAAA4 34.24.95.24 37846 127.0.0.1 7081
--1f538b55-B--
GET /public/.env HTTP/1.1
Host: webmail.chania24.taxi
X-Real-IP: 34.24.95.24
X-Forwarded-For: 100.95.78.93
User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 100.95.78.93
Fastly-Client-Ip: 100.95.78.93
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 100.95.78.93
Upgrade-Insecure-Requests: 1
X-Client-Ip: 100.95.78.93
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 100.95.78.93
sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8"
sec-ch-ua-mobile: ?1
sec-ch-ua-platform: "Android"
--1f538b55-F--
HTTP/1.1 404 Not Found
Content-Length: 196
Content-Type: text/html; charset=iso-8859-1
--1f538b55-E--
--1f538b55-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/public/.env"] [unique_id "apTydCfaLSuAj0yzdueSmgAAAA4"]
Stopwatch: 1788146292393549 8556 (- - -)
Stopwatch2: 1788146292393549 8556; combined=6915, p1=351, p2=6366, p3=138, p4=11, p5=49, sr=124, sw=0, l=0, gc=0
Response-Body-Transformed: Dechunked
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--1f538b55-Z--
--9afb313c-A--
[31/Aug/2026:06:18:12.683125 +0300] apTydNmUuou1H8H2UKXBKgAAAMA 34.24.95.24 37876 127.0.0.1 7081
--9afb313c-B--
GET /wp/.env HTTP/1.1
Host: webmail.chania24.taxi
X-Real-IP: 34.24.95.24
X-Forwarded-For: 100.67.9.215
User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 100.67.9.215
Fastly-Client-Ip: 100.67.9.215
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 100.67.9.215
Upgrade-Insecure-Requests: 1
X-Client-Ip: 100.67.9.215
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 100.67.9.215
sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8"
sec-ch-ua-mobile: ?1
sec-ch-ua-platform: "Android"
--9afb313c-F--
HTTP/1.1 404 Not Found
Content-Length: 196
Content-Type: text/html; charset=iso-8859-1
--9afb313c-E--
--9afb313c-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/wp/.env"] [unique_id "apTydNmUuou1H8H2UKXBKgAAAMA"]
Stopwatch: 1788146292676181 7037 (- - -)
Stopwatch2: 1788146292676181 7037; combined=4611, p1=256, p2=4239, p3=62, p4=7, p5=47, sr=100, sw=0, l=0, gc=0
Response-Body-Transformed: Dechunked
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--9afb313c-Z--
--1c98420c-A--
[31/Aug/2026:06:18:12.714216 +0300] apTydG7fDIutYTwcPOkZ3wAAAEc 34.24.95.24 37904 127.0.0.1 7081
--1c98420c-B--
GET /web/.env HTTP/1.1
Host: webmail.chania24.taxi
X-Real-IP: 34.24.95.24
X-Forwarded-For: 172.20.118.49
User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 172.20.118.49
Fastly-Client-Ip: 172.20.118.49
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 172.20.118.49
Upgrade-Insecure-Requests: 1
X-Client-Ip: 172.20.118.49
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 172.20.118.49
sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8"
sec-ch-ua-mobile: ?1
sec-ch-ua-platform: "Android"
--1c98420c-F--
HTTP/1.1 404 Not Found
Content-Length: 196
Content-Type: text/html; charset=iso-8859-1
--1c98420c-E--
--1c98420c-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/web/.env"] [unique_id "apTydG7fDIutYTwcPOkZ3wAAAEc"]
Stopwatch: 1788146292704411 9888 (- - -)
Stopwatch2: 1788146292704411 9888; combined=8500, p1=337, p2=8060, p3=59, p4=7, p5=37, sr=151, sw=0, l=0, gc=0
Response-Body-Transformed: Dechunked
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--1c98420c-Z--
--6a648b1a-A--
[31/Aug/2026:06:18:12.740687 +0300] apTydNmUuou1H8H2UKXBLAAAAMA 34.24.95.24 37884 127.0.0.1 7081
--6a648b1a-B--
GET /wp-config.php~ HTTP/1.1
Host: webmail.chania24.taxi
X-Real-IP: 34.24.95.24
X-Forwarded-For: 192.168.85.77
User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 192.168.85.77
Fastly-Client-Ip: 192.168.85.77
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 192.168.85.77
Upgrade-Insecure-Requests: 1
X-Client-Ip: 192.168.85.77
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 192.168.85.77
sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8"
sec-ch-ua-mobile: ?1
sec-ch-ua-platform: "Android"
--6a648b1a-F--
HTTP/1.1 404 Not Found
Content-Length: 196
Content-Type: text/html; charset=iso-8859-1
--6a648b1a-E--
--6a648b1a-H--
Message: Warning. Matched phrase "wp-config.php~" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/wp-config.php~||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"]
Message: Warning. Matched phrase "wp-config.php~" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/wp-config.php~||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"]
Message: Warning. Pattern match "(\\.swp|~)$" at REQUEST_BASENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "309"] [id "77142201"] [msg "IM360 WAF: Possible enumeration of sensitive data (dirb)||MVN:REQUEST_BASENAME||T:APACHE||MV:wp-config.php~||"] [severity "NOTICE"] [tag "service_i360custom"]
Message: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "wp-config.php~" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/wp-config.php~||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "webmail.chania24.taxi"] [uri "/wp-config.php~"] [unique_id "apTydNmUuou1H8H2UKXBLAAAAMA"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "wp-config.php~" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/wp-config.php~||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/wp-config.php~"] [unique_id "apTydNmUuou1H8H2UKXBLAAAAMA"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\.swp|~)$" at REQUEST_BASENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "309"] [id "77142201"] [msg "IM360 WAF: Possible enumeration of sensitive data (dirb)||MVN:REQUEST_BASENAME||T:APACHE||MV:wp-config.php~||"] [severity "NOTICE"] [tag "service_i360custom"] [hostname "webmail.chania24.taxi"] [uri "/wp-config.php~"] [unique_id "apTydNmUuou1H8H2UKXBLAAAAMA"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/wp-config.php~"] [unique_id "apTydNmUuou1H8H2UKXBLAAAAMA"]
Stopwatch: 1788146292708494 32280 (- - -)
Stopwatch2: 1788146292708494 32280; combined=30855, p1=387, p2=30317, p3=65, p4=6, p5=80, sr=127, sw=0, l=0, gc=0
Response-Body-Transformed: Dechunked
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--6a648b1a-Z--
--d5370b71-A--
[31/Aug/2026:06:18:13.273278 +0300] apTydW7fDIutYTwcPOkZ4AAAAEo 34.24.95.24 37906 127.0.0.1 7081
--d5370b71-B--
GET /wp-config.php.swp HTTP/1.1
Host: webmail.chania24.taxi
X-Real-IP: 34.24.95.24
X-Forwarded-For: 100.90.25.186
User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 100.90.25.186
Fastly-Client-Ip: 100.90.25.186
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 100.90.25.186
Upgrade-Insecure-Requests: 1
X-Client-Ip: 100.90.25.186
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 100.90.25.186
sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8"
sec-ch-ua-mobile: ?1
sec-ch-ua-platform: "Android"
--d5370b71-F--
HTTP/1.1 404 Not Found
Content-Length: 196
Content-Type: text/html; charset=iso-8859-1
--d5370b71-E--
--d5370b71-H--
Message: Warning. Matched phrase "wp-config.php." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/wp-config.php.swp||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"]
Message: Warning. Matched phrase "wp-config.php." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/wp-config.php.swp||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"]
Message: Warning. Pattern match "(\\.swp|~)$" at REQUEST_BASENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "309"] [id "77142201"] [msg "IM360 WAF: Possible enumeration of sensitive data (dirb)||MVN:REQUEST_BASENAME||T:APACHE||MV:wp-config.php.swp||"] [severity "NOTICE"] [tag "service_i360custom"]
Message: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "wp-config.php." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/wp-config.php.swp||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "webmail.chania24.taxi"] [uri "/wp-config.php.swp"] [unique_id "apTydW7fDIutYTwcPOkZ4AAAAEo"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "wp-config.php." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/wp-config.php.swp||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/wp-config.php.swp"] [unique_id "apTydW7fDIutYTwcPOkZ4AAAAEo"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\.swp|~)$" at REQUEST_BASENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "309"] [id "77142201"] [msg "IM360 WAF: Possible enumeration of sensitive data (dirb)||MVN:REQUEST_BASENAME||T:APACHE||MV:wp-config.php.swp||"] [severity "NOTICE"] [tag "service_i360custom"] [hostname "webmail.chania24.taxi"] [uri "/wp-config.php.swp"] [unique_id "apTydW7fDIutYTwcPOkZ4AAAAEo"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/wp-config.php.swp"] [unique_id "apTydW7fDIutYTwcPOkZ4AAAAEo"]
Stopwatch: 1788146293238851 34551 (- - -)
Stopwatch2: 1788146293238851 34551; combined=33115, p1=256, p2=32745, p3=56, p4=6, p5=52, sr=98, sw=0, l=0, gc=0
Response-Body-Transformed: Dechunked
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--d5370b71-Z--
--1f538b55-A--
[31/Aug/2026:06:18:13.447552 +0300] apTydX7glkZrdsSdRApInQAAAJA 34.24.95.24 37934 127.0.0.1 7081
--1f538b55-B--
GET /storage/.env HTTP/1.1
Host: webmail.chania24.taxi
X-Real-IP: 34.24.95.24
X-Forwarded-For: 192.168.23.223
User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 192.168.23.223
Fastly-Client-Ip: 192.168.23.223
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 192.168.23.223
Upgrade-Insecure-Requests: 1
X-Client-Ip: 192.168.23.223
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 192.168.23.223
sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8"
sec-ch-ua-mobile: ?1
sec-ch-ua-platform: "Android"
--1f538b55-F--
HTTP/1.1 404 Not Found
Content-Length: 196
Content-Type: text/html; charset=iso-8859-1
--1f538b55-E--
--1f538b55-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/storage/.env"] [unique_id "apTydX7glkZrdsSdRApInQAAAJA"]
Stopwatch: 1788146293440235 7432 (- - -)
Stopwatch2: 1788146293440235 7432; combined=5827, p1=325, p2=5366, p3=83, p4=8, p5=45, sr=112, sw=0, l=0, gc=0
Response-Body-Transformed: Dechunked
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--1f538b55-Z--
--6df58a70-A--
[31/Aug/2026:06:18:14.355511 +0300] apTydn7glkZrdsSdRApIoQAAAIE 34.24.95.24 38050 127.0.0.1 7081
--6df58a70-B--
GET /web.config HTTP/1.1
Host: webmail.chania24.taxi
X-Real-IP: 34.24.95.24
X-Forwarded-For: 192.168.230.247
User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 192.168.230.247
Fastly-Client-Ip: 192.168.230.247
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 192.168.230.247
Upgrade-Insecure-Requests: 1
X-Client-Ip: 192.168.230.247
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 192.168.230.247
sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8"
sec-ch-ua-mobile: ?1
sec-ch-ua-platform: "Android"
--6df58a70-F--
HTTP/1.1 404 Not Found
Content-Length: 196
Content-Type: text/html; charset=iso-8859-1
--6df58a70-E--
--6df58a70-H--
Message: Warning. Matched phrase "/web.config" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "/web.config" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/web.config"] [unique_id "apTydn7glkZrdsSdRApIoQAAAIE"]
Stopwatch: 1788146294349456 6180 (- - -)
Stopwatch2: 1788146294349456 6180; combined=4875, p1=336, p2=4429, p3=61, p4=7, p5=41, sr=155, sw=1, l=0, gc=0
Response-Body-Transformed: Dechunked
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--6df58a70-Z--
--3d6edc59-A--
[31/Aug/2026:06:18:16.612527 +0300] apTyeH7glkZrdsSdRApIpgAAAI8 34.24.95.24 55498 127.0.0.1 7081
--3d6edc59-B--
GET /production/.env HTTP/1.1
Host: webmail.chania24.taxi
X-Real-IP: 34.24.95.24
X-Forwarded-For: 100.98.232.217
User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 100.98.232.217
Fastly-Client-Ip: 100.98.232.217
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 100.98.232.217
Upgrade-Insecure-Requests: 1
X-Client-Ip: 100.98.232.217
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 100.98.232.217
sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8"
sec-ch-ua-mobile: ?1
sec-ch-ua-platform: "Android"
--3d6edc59-F--
HTTP/1.1 404 Not Found
Content-Length: 196
Content-Type: text/html; charset=iso-8859-1
--3d6edc59-E--
--3d6edc59-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/production/.env"] [unique_id "apTyeH7glkZrdsSdRApIpgAAAI8"]
Stopwatch: 1788146296604462 8148 (- - -)
Stopwatch2: 1788146296604462 8148; combined=6655, p1=336, p2=6144, p3=116, p4=15, p5=44, sr=148, sw=0, l=0, gc=0
Response-Body-Transformed: Dechunked
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--3d6edc59-Z--
--3b1af431-A--
[31/Aug/2026:06:18:16.660588 +0300] apTyeH7glkZrdsSdRApIpwAAAJM 34.24.95.24 55520 127.0.0.1 7081
--3b1af431-B--
GET /src/.env HTTP/1.1
Host: webmail.chania24.taxi
X-Real-IP: 34.24.95.24
X-Forwarded-For: 10.18.140.53
User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 10.18.140.53
Fastly-Client-Ip: 10.18.140.53
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 10.18.140.53
Upgrade-Insecure-Requests: 1
X-Client-Ip: 10.18.140.53
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 10.18.140.53
sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8"
sec-ch-ua-mobile: ?1
sec-ch-ua-platform: "Android"
--3b1af431-F--
HTTP/1.1 404 Not Found
Content-Length: 196
Content-Type: text/html; charset=iso-8859-1
--3b1af431-E--
--3b1af431-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/src/.env"] [unique_id "apTyeH7glkZrdsSdRApIpwAAAJM"]
Stopwatch: 1788146296654866 5854 (- - -)
Stopwatch2: 1788146296654866 5854; combined=4516, p1=275, p2=4135, p3=62, p4=7, p5=37, sr=114, sw=0, l=0, gc=0
Response-Body-Transformed: Dechunked
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--3b1af431-Z--
--5acf943e-A--
[31/Aug/2026:06:18:16.668487 +0300] apTyeH7glkZrdsSdRApIqAAAAI4 34.24.95.24 55514 127.0.0.1 7081
--5acf943e-B--
GET /app/.env HTTP/1.1
Host: webmail.chania24.taxi
X-Real-IP: 34.24.95.24
X-Forwarded-For: 172.18.156.47
User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 172.18.156.47
Fastly-Client-Ip: 172.18.156.47
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 172.18.156.47
Upgrade-Insecure-Requests: 1
X-Client-Ip: 172.18.156.47
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 172.18.156.47
sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8"
sec-ch-ua-mobile: ?1
sec-ch-ua-platform: "Android"
--5acf943e-F--
HTTP/1.1 404 Not Found
Content-Length: 196
Content-Type: text/html; charset=iso-8859-1
--5acf943e-E--
--5acf943e-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/app/.env"] [unique_id "apTyeH7glkZrdsSdRApIqAAAAI4"]
Stopwatch: 1788146296662215 6356 (- - -)
Stopwatch2: 1788146296662215 6356; combined=5053, p1=251, p2=4696, p3=60, p4=6, p5=40, sr=99, sw=0, l=0, gc=0
Response-Body-Transformed: Dechunked
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--5acf943e-Z--
--40b18017-A--
[31/Aug/2026:06:18:16.813292 +0300] apTyeG7fDIutYTwcPOkZ5gAAAFU 34.24.95.24 55530 127.0.0.1 7081
--40b18017-B--
GET /server/.env HTTP/1.1
Host: webmail.chania24.taxi
X-Real-IP: 34.24.95.24
X-Forwarded-For: 10.127.65.47
User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 10.127.65.47
Fastly-Client-Ip: 10.127.65.47
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 10.127.65.47
Upgrade-Insecure-Requests: 1
X-Client-Ip: 10.127.65.47
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 10.127.65.47
sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8"
sec-ch-ua-mobile: ?1
sec-ch-ua-platform: "Android"
--40b18017-F--
HTTP/1.1 404 Not Found
Content-Length: 196
Content-Type: text/html; charset=iso-8859-1
--40b18017-E--
--40b18017-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/server/.env"] [unique_id "apTyeG7fDIutYTwcPOkZ5gAAAFU"]
Stopwatch: 1788146296807126 6260 (- - -)
Stopwatch2: 1788146296807126 6260; combined=4883, p1=287, p2=4489, p3=61, p4=7, p5=38, sr=101, sw=1, l=0, gc=0
Response-Body-Transformed: Dechunked
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--40b18017-Z--
--1f538b55-A--
[31/Aug/2026:06:18:16.851397 +0300] apTyeG7fDIutYTwcPOkZ5wAAAFc 34.24.95.24 55532 127.0.0.1 7081
--1f538b55-B--
GET /frontend/.env HTTP/1.1
Host: webmail.chania24.taxi
X-Real-IP: 34.24.95.24
X-Forwarded-For: 172.23.151.239
User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 172.23.151.239
Fastly-Client-Ip: 172.23.151.239
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 172.23.151.239
Upgrade-Insecure-Requests: 1
X-Client-Ip: 172.23.151.239
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 172.23.151.239
sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8"
sec-ch-ua-mobile: ?1
sec-ch-ua-platform: "Android"
--1f538b55-F--
HTTP/1.1 404 Not Found
Content-Length: 196
Content-Type: text/html; charset=iso-8859-1
--1f538b55-E--
--1f538b55-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/frontend/.env"] [unique_id "apTyeG7fDIutYTwcPOkZ5wAAAFc"]
Stopwatch: 1788146296845539 5965 (- - -)
Stopwatch2: 1788146296845539 5965; combined=4584, p1=259, p2=4208, p3=64, p4=8, p5=45, sr=100, sw=0, l=0, gc=0
Response-Body-Transformed: Dechunked
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--1f538b55-Z--
--dde88c6f-A--
[31/Aug/2026:06:18:16.855816 +0300] apTyeNmUuou1H8H2UKXBOwAAANE 34.24.95.24 55534 127.0.0.1 7081
--dde88c6f-B--
GET /staging/.env HTTP/1.1
Host: webmail.chania24.taxi
X-Real-IP: 34.24.95.24
X-Forwarded-For: 10.180.250.39
User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 10.180.250.39
Fastly-Client-Ip: 10.180.250.39
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 10.180.250.39
Upgrade-Insecure-Requests: 1
X-Client-Ip: 10.180.250.39
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 10.180.250.39
sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8"
sec-ch-ua-mobile: ?1
sec-ch-ua-platform: "Android"
--dde88c6f-F--
HTTP/1.1 404 Not Found
Content-Length: 196
Content-Type: text/html; charset=iso-8859-1
--dde88c6f-E--
--dde88c6f-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/staging/.env"] [unique_id "apTyeNmUuou1H8H2UKXBOwAAANE"]
Stopwatch: 1788146296848798 7116 (- - -)
Stopwatch2: 1788146296848798 7116; combined=5918, p1=259, p2=5530, p3=77, p4=8, p5=43, sr=95, sw=1, l=0, gc=0
Response-Body-Transformed: Dechunked
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--dde88c6f-Z--
--84d97830-A--
[31/Aug/2026:06:18:16.865150 +0300] apTyeNmUuou1H8H2UKXBPAAAAM8 34.24.95.24 55550 127.0.0.1 7081
--84d97830-B--
GET /docker/.env HTTP/1.1
Host: webmail.chania24.taxi
X-Real-IP: 34.24.95.24
X-Forwarded-For: 172.23.154.108
User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 172.23.154.108
Fastly-Client-Ip: 172.23.154.108
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 172.23.154.108
Upgrade-Insecure-Requests: 1
X-Client-Ip: 172.23.154.108
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 172.23.154.108
sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8"
sec-ch-ua-mobile: ?1
sec-ch-ua-platform: "Android"
--84d97830-F--
HTTP/1.1 404 Not Found
Content-Length: 196
Content-Type: text/html; charset=iso-8859-1
--84d97830-E--
--84d97830-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/docker/.env"] [unique_id "apTyeNmUuou1H8H2UKXBPAAAAM8"]
Stopwatch: 1788146296859348 5885 (- - -)
Stopwatch2: 1788146296859348 5885; combined=4564, p1=278, p2=4180, p3=60, p4=8, p5=38, sr=95, sw=0, l=0, gc=0
Response-Body-Transformed: Dechunked
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--84d97830-Z--
--6df58a70-A--
[31/Aug/2026:06:18:16.923073 +0300] apTyeG7fDIutYTwcPOkZ6AAAAEA 34.24.95.24 55556 127.0.0.1 7081
--6df58a70-B--
GET /dev/.env HTTP/1.1
Host: webmail.chania24.taxi
X-Real-IP: 34.24.95.24
X-Forwarded-For: 10.201.112.26
User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 10.201.112.26
Fastly-Client-Ip: 10.201.112.26
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 10.201.112.26
Upgrade-Insecure-Requests: 1
X-Client-Ip: 10.201.112.26
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 10.201.112.26
sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8"
sec-ch-ua-mobile: ?1
sec-ch-ua-platform: "Android"
--6df58a70-F--
HTTP/1.1 404 Not Found
Content-Length: 196
Content-Type: text/html; charset=iso-8859-1
--6df58a70-E--
--6df58a70-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/dev/.env"] [unique_id "apTyeG7fDIutYTwcPOkZ6AAAAEA"]
Stopwatch: 1788146296916732 6436 (- - -)
Stopwatch2: 1788146296916732 6436; combined=4922, p1=337, p2=4480, p3=59, p4=8, p5=38, sr=144, sw=0, l=0, gc=0
Response-Body-Transformed: Dechunked
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--6df58a70-Z--
--c31cca52-A--
[31/Aug/2026:06:18:17.036011 +0300] apTyeX7glkZrdsSdRApIqQAAAJY 34.24.95.24 55562 127.0.0.1 7081
--c31cca52-B--
GET /apps/.env HTTP/1.1
Host: webmail.chania24.taxi
X-Real-IP: 34.24.95.24
X-Forwarded-For: 192.168.58.51
User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 192.168.58.51
Fastly-Client-Ip: 192.168.58.51
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 192.168.58.51
Upgrade-Insecure-Requests: 1
X-Client-Ip: 192.168.58.51
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 192.168.58.51
sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8"
sec-ch-ua-mobile: ?1
sec-ch-ua-platform: "Android"
--c31cca52-F--
HTTP/1.1 404 Not Found
Content-Length: 196
Content-Type: text/html; charset=iso-8859-1
--c31cca52-E--
--c31cca52-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/apps/.env"] [unique_id "apTyeX7glkZrdsSdRApIqQAAAJY"]
Stopwatch: 1788146297029982 6119 (- - -)
Stopwatch2: 1788146297029982 6119; combined=4856, p1=263, p2=4477, p3=63, p4=8, p5=44, sr=93, sw=1, l=0, gc=0
Response-Body-Transformed: Dechunked
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--c31cca52-Z--
--1ea68b55-A--
[31/Aug/2026:06:18:17.359323 +0300] apTyeX7glkZrdsSdRApIqgAAAJg 34.24.95.24 55598 127.0.0.1 7081
--1ea68b55-B--
GET /.git/HEAD HTTP/1.1
Host: webmail.chania24.taxi
X-Real-IP: 34.24.95.24
X-Forwarded-For: 172.20.101.121
User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 172.20.101.121
Fastly-Client-Ip: 172.20.101.121
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 172.20.101.121
Upgrade-Insecure-Requests: 1
X-Client-Ip: 172.20.101.121
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 172.20.101.121
sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8"
sec-ch-ua-mobile: ?1
sec-ch-ua-platform: "Android"
--1ea68b55-F--
HTTP/1.1 404 Not Found
Content-Length: 196
Content-Type: text/html; charset=iso-8859-1
--1ea68b55-E--
--1ea68b55-H--
Message: Warning. String match "/.git/" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "656"] [id "77318034"] [msg "IM360 WAF: Blocked access to git folder||T:APACHE||MV:/.git/head||"] [severity "NOTICE"] [tag "service_i360custom"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.git/" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "656"] [id "77318034"] [msg "IM360 WAF: Blocked access to git folder||T:APACHE||MV:/.git/head||"] [severity "NOTICE"] [tag "service_i360custom"] [hostname "webmail.chania24.taxi"] [uri "/.git/HEAD"] [unique_id "apTyeX7glkZrdsSdRApIqgAAAJg"]
Stopwatch: 1788146297353309 6121 (- - -)
Stopwatch2: 1788146297353309 6121; combined=4820, p1=286, p2=4416, p3=69, p4=6, p5=42, sr=103, sw=1, l=0, gc=0
Response-Body-Transformed: Dechunked
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--1ea68b55-Z--
--a053d533-A--
[31/Aug/2026:06:18:17.473773 +0300] apTyedmUuou1H8H2UKXBPwAAAMw 34.24.95.24 55602 127.0.0.1 7081
--a053d533-B--
GET /v2/.env HTTP/1.1
Host: webmail.chania24.taxi
X-Real-IP: 34.24.95.24
X-Forwarded-For: 192.168.89.16
User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 192.168.89.16
Fastly-Client-Ip: 192.168.89.16
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 192.168.89.16
Upgrade-Insecure-Requests: 1
X-Client-Ip: 192.168.89.16
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 192.168.89.16
sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8"
sec-ch-ua-mobile: ?1
sec-ch-ua-platform: "Android"
--a053d533-F--
HTTP/1.1 404 Not Found
Content-Length: 196
Content-Type: text/html; charset=iso-8859-1
--a053d533-E--
--a053d533-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/v2/.env"] [unique_id "apTyedmUuou1H8H2UKXBPwAAAMw"]
Stopwatch: 1788146297467877 5981 (- - -)
Stopwatch2: 1788146297467877 5981; combined=4611, p1=317, p2=4173, p3=61, p4=7, p5=53, sr=125, sw=0, l=0, gc=0
Response-Body-Transformed: Dechunked
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--a053d533-Z--
--ee575677-A--
[31/Aug/2026:06:18:17.556327 +0300] apTyeX7glkZrdsSdRApIqwAAAIQ 34.24.95.24 55608 127.0.0.1 7081
--ee575677-B--
GET /old/.env HTTP/1.1
Host: webmail.chania24.taxi
X-Real-IP: 34.24.95.24
X-Forwarded-For: 192.168.58.243
User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 192.168.58.243
Fastly-Client-Ip: 192.168.58.243
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 192.168.58.243
Upgrade-Insecure-Requests: 1
X-Client-Ip: 192.168.58.243
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 192.168.58.243
sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8"
sec-ch-ua-mobile: ?1
sec-ch-ua-platform: "Android"
--ee575677-F--
HTTP/1.1 404 Not Found
Content-Length: 196
Content-Type: text/html; charset=iso-8859-1
--ee575677-E--
--ee575677-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/old/.env"] [unique_id "apTyeX7glkZrdsSdRApIqwAAAIQ"]
Stopwatch: 1788146297550242 6193 (- - -)
Stopwatch2: 1788146297550242 6193; combined=4848, p1=291, p2=4447, p3=62, p4=7, p5=41, sr=116, sw=0, l=0, gc=0
Response-Body-Transformed: Dechunked
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--ee575677-Z--
--458bcb0b-A--
[31/Aug/2026:06:18:39.711453 +0300] apTyjtmUuou1H8H2UKXBRgAAAM4 81.171.72.135 45334 127.0.0.1 7081
--458bcb0b-B--
GET /.ssh/id_rsa HTTP/1.1
Host: ajutam.ro
X-Real-IP: 81.171.72.135
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Go-http-client/1.1
Accept-Encoding: gzip
--458bcb0b-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/7.3.33
Expires: Wed, 11 Jan 1984 05:00:00 GMT
Cache-Control: no-cache, must-revalidate, max-age=0, no-store, private
Link:
; rel="https://api.w.org/"
X-TEC-API-VERSION: v1
X-TEC-API-ROOT: https://ajutam.ro/wp-json/tribe/events/v1/
X-TEC-API-ORIGIN: https://ajutam.ro
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--458bcb0b-H--
Message: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.ssh/id_rsa||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"]
Message: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.ssh/id_rsa||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.ssh/id_rsa||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "ajutam.ro"] [uri "/.ssh/id_rsa"] [unique_id "apTyjtmUuou1H8H2UKXBRgAAAM4"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.ssh/id_rsa||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "ajutam.ro"] [uri "/.ssh/id_rsa"] [unique_id "apTyjtmUuou1H8H2UKXBRgAAAM4"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/ajutam.ro/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788146318994356 717164 (- - -)
Stopwatch2: 1788146318994356 717164; combined=41607, p1=247, p2=41303, p3=0, p4=0, p5=57, sr=95, sw=0, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--458bcb0b-Z--
--6ccc7604-A--
[31/Aug/2026:06:18:40.454980 +0300] apTykNmUuou1H8H2UKXBSwAAANQ 81.171.72.135 45376 127.0.0.1 7081
--6ccc7604-B--
GET /.git/HEAD HTTP/1.1
Host: ajutam.ro
X-Real-IP: 81.171.72.135
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Go-http-client/1.1
Accept-Encoding: gzip
--6ccc7604-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/7.3.33
Expires: Wed, 11 Jan 1984 05:00:00 GMT
Cache-Control: no-cache, must-revalidate, max-age=0, no-store, private
Link:
; rel="https://api.w.org/"
X-TEC-API-VERSION: v1
X-TEC-API-ROOT: https://ajutam.ro/wp-json/tribe/events/v1/
X-TEC-API-ORIGIN: https://ajutam.ro
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--6ccc7604-H--
Message: Warning. String match "/.git/" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "656"] [id "77318034"] [msg "IM360 WAF: Blocked access to git folder||T:APACHE||MV:/.git/head||"] [severity "NOTICE"] [tag "service_i360custom"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.git/" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "656"] [id "77318034"] [msg "IM360 WAF: Blocked access to git folder||T:APACHE||MV:/.git/head||"] [severity "NOTICE"] [tag "service_i360custom"] [hostname "ajutam.ro"] [uri "/.git/HEAD"] [unique_id "apTykNmUuou1H8H2UKXBSwAAANQ"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/ajutam.ro/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788146320112532 342506 (- - -)
Stopwatch2: 1788146320112532 342506; combined=3568, p1=234, p2=3282, p3=0, p4=0, p5=52, sr=86, sw=0, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--6ccc7604-Z--
--9af7f705-A--
[31/Aug/2026:06:18:40.785324 +0300] apTykH7glkZrdsSdRApIrQAAAIc 81.171.72.135 45380 127.0.0.1 7081
--9af7f705-B--
GET /.env HTTP/1.1
Host: ajutam.ro
X-Real-IP: 81.171.72.135
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Go-http-client/1.1
Accept-Encoding: gzip
--9af7f705-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/7.3.33
Expires: Wed, 11 Jan 1984 05:00:00 GMT
Cache-Control: no-cache, must-revalidate, max-age=0, no-store, private
Link:
; rel="https://api.w.org/"
X-TEC-API-VERSION: v1
X-TEC-API-ROOT: https://ajutam.ro/wp-json/tribe/events/v1/
X-TEC-API-ORIGIN: https://ajutam.ro
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--9af7f705-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "ajutam.ro"] [uri "/.env"] [unique_id "apTykH7glkZrdsSdRApIrQAAAIc"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/ajutam.ro/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788146320495255 290137 (- - -)
Stopwatch2: 1788146320495255 290137; combined=3730, p1=197, p2=3479, p3=0, p4=0, p5=54, sr=85, sw=0, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--9af7f705-Z--
--90b06164-A--
[31/Aug/2026:06:18:41.057730 +0300] apTykNmUuou1H8H2UKXBTAAAAMw 81.171.72.135 45392 127.0.0.1 7081
--90b06164-B--
GET /api/.env HTTP/1.1
Host: ajutam.ro
X-Real-IP: 81.171.72.135
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Go-http-client/1.1
Accept-Encoding: gzip
--90b06164-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/7.3.33
Expires: Wed, 11 Jan 1984 05:00:00 GMT
Cache-Control: no-cache, must-revalidate, max-age=0, no-store, private
Link:
; rel="https://api.w.org/"
X-TEC-API-VERSION: v1
X-TEC-API-ROOT: https://ajutam.ro/wp-json/tribe/events/v1/
X-TEC-API-ORIGIN: https://ajutam.ro
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--90b06164-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "ajutam.ro"] [uri "/api/.env"] [unique_id "apTykNmUuou1H8H2UKXBTAAAAMw"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/ajutam.ro/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788146320699311 358491 (- - -)
Stopwatch2: 1788146320699311 358491; combined=3640, p1=200, p2=3391, p3=0, p4=0, p5=49, sr=86, sw=0, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--90b06164-Z--
--d5d10130-A--
[31/Aug/2026:06:18:42.475332 +0300] apTykn7glkZrdsSdRApIrwAAAIs 81.171.72.135 45452 127.0.0.1 7081
--d5d10130-B--
GET /backup.tar.gz HTTP/1.1
Host: ajutam.ro
X-Real-IP: 81.171.72.135
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Go-http-client/1.1
Accept-Encoding: gzip
--d5d10130-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/7.3.33
Expires: Wed, 11 Jan 1984 05:00:00 GMT
Cache-Control: no-cache, must-revalidate, max-age=0, no-store, private
Link:
; rel="https://api.w.org/"
X-TEC-API-VERSION: v1
X-TEC-API-ROOT: https://ajutam.ro/wp-json/tribe/events/v1/
X-TEC-API-ORIGIN: https://ajutam.ro
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--d5d10130-H--
Message: Warning. Matched phrase "/backup." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/backup.tar.gz||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"]
Message: Warning. Matched phrase "/backup." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/backup.tar.gz||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "/backup." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/backup.tar.gz||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "ajutam.ro"] [uri "/backup.tar.gz"] [unique_id "apTykn7glkZrdsSdRApIrwAAAIs"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "/backup." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/backup.tar.gz||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "ajutam.ro"] [uri "/backup.tar.gz"] [unique_id "apTykn7glkZrdsSdRApIrwAAAIs"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/ajutam.ro/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788146322066117 409273 (- - -)
Stopwatch2: 1788146322066117 409273; combined=37959, p1=184, p2=37720, p3=0, p4=0, p5=55, sr=73, sw=0, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--d5d10130-Z--
--25874a28-A--
[31/Aug/2026:06:18:43.015279 +0300] apTyktmUuou1H8H2UKXBUgAAAM4 81.171.72.135 45470 127.0.0.1 7081
--25874a28-B--
GET /.npmrc HTTP/1.1
Host: ajutam.ro
X-Real-IP: 81.171.72.135
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Go-http-client/1.1
Accept-Encoding: gzip
--25874a28-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/7.3.33
Expires: Wed, 11 Jan 1984 05:00:00 GMT
Cache-Control: no-cache, must-revalidate, max-age=0, no-store, private
Link:
; rel="https://api.w.org/"
X-TEC-API-VERSION: v1
X-TEC-API-ROOT: https://ajutam.ro/wp-json/tribe/events/v1/
X-TEC-API-ORIGIN: https://ajutam.ro
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--25874a28-H--
Message: Warning. Matched phrase ".npmrc" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.npmrc||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"]
Message: Warning. Matched phrase ".npmrc" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.npmrc||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".npmrc" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.npmrc||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "ajutam.ro"] [uri "/.npmrc"] [unique_id "apTyktmUuou1H8H2UKXBUgAAAM4"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".npmrc" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.npmrc||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "ajutam.ro"] [uri "/.npmrc"] [unique_id "apTyktmUuou1H8H2UKXBUgAAAM4"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/ajutam.ro/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788146322534872 480471 (- - -)
Stopwatch2: 1788146322534872 480471; combined=33966, p1=362, p2=33548, p3=0, p4=0, p5=55, sr=175, sw=1, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--25874a28-Z--
--3d6edc59-A--
[31/Aug/2026:06:18:43.156299 +0300] apTykm7fDIutYTwcPOkZ7AAAAEQ 81.171.72.135 45486 127.0.0.1 7081
--3d6edc59-B--
GET /backup.zip HTTP/1.1
Host: ajutam.ro
X-Real-IP: 81.171.72.135
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Go-http-client/1.1
Accept-Encoding: gzip
--3d6edc59-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/7.3.33
Expires: Wed, 11 Jan 1984 05:00:00 GMT
Cache-Control: no-cache, must-revalidate, max-age=0, no-store, private
Link:
; rel="https://api.w.org/"
X-TEC-API-VERSION: v1
X-TEC-API-ROOT: https://ajutam.ro/wp-json/tribe/events/v1/
X-TEC-API-ORIGIN: https://ajutam.ro
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--3d6edc59-H--
Message: Warning. Matched phrase "/backup." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/backup.zip||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"]
Message: Warning. Matched phrase "/backup." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/backup.zip||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "/backup." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/backup.zip||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "ajutam.ro"] [uri "/backup.zip"] [unique_id "apTykm7fDIutYTwcPOkZ7AAAAEQ"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "/backup." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/backup.zip||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "ajutam.ro"] [uri "/backup.zip"] [unique_id "apTykm7fDIutYTwcPOkZ7AAAAEQ"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/ajutam.ro/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788146322638064 518312 (- - -)
Stopwatch2: 1788146322638064 518312; combined=36877, p1=166, p2=36654, p3=0, p4=0, p5=56, sr=65, sw=1, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--3d6edc59-Z--
--3b1af431-A--
[31/Aug/2026:06:18:43.368403 +0300] apTykm7fDIutYTwcPOkZ7QAAAEk 81.171.72.135 45492 127.0.0.1 7081
--3b1af431-B--
GET /.ssh/id_ed25519 HTTP/1.1
Host: ajutam.ro
X-Real-IP: 81.171.72.135
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Go-http-client/1.1
Accept-Encoding: gzip
--3b1af431-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/7.3.33
Expires: Wed, 11 Jan 1984 05:00:00 GMT
Cache-Control: no-cache, must-revalidate, max-age=0, no-store, private
Link:
; rel="https://api.w.org/"
X-TEC-API-VERSION: v1
X-TEC-API-ROOT: https://ajutam.ro/wp-json/tribe/events/v1/
X-TEC-API-ORIGIN: https://ajutam.ro
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--3b1af431-H--
Message: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.ssh/id_ed25519||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"]
Message: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.ssh/id_ed25519||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.ssh/id_ed25519||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "ajutam.ro"] [uri "/.ssh/id_ed25519"] [unique_id "apTykm7fDIutYTwcPOkZ7QAAAEk"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.ssh/id_ed25519||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "ajutam.ro"] [uri "/.ssh/id_ed25519"] [unique_id "apTykm7fDIutYTwcPOkZ7QAAAEk"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/ajutam.ro/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788146322915826 452636 (- - -)
Stopwatch2: 1788146322915826 452636; combined=32530, p1=238, p2=32233, p3=0, p4=0, p5=58, sr=125, sw=1, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--3b1af431-Z--
--8d0fff34-A--
[31/Aug/2026:06:18:43.854479 +0300] apTyk9mUuou1H8H2UKXBVAAAANY 81.171.72.135 45514 127.0.0.1 7081
--8d0fff34-B--
GET /config.php HTTP/1.1
Host: ajutam.ro
X-Real-IP: 81.171.72.135
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Go-http-client/1.1
Accept-Encoding: gzip
--8d0fff34-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/7.3.33
Expires: Wed, 11 Jan 1984 05:00:00 GMT
Cache-Control: no-cache, must-revalidate, max-age=0, no-store, private
Link:
; rel="https://api.w.org/"
X-TEC-API-VERSION: v1
X-TEC-API-ROOT: https://ajutam.ro/wp-json/tribe/events/v1/
X-TEC-API-ORIGIN: https://ajutam.ro
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--8d0fff34-H--
Message: Warning. Matched phrase "/config.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "/config.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "ajutam.ro"] [uri "/config.php"] [unique_id "apTyk9mUuou1H8H2UKXBVAAAANY"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/ajutam.ro/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788146323471566 382982 (- - -)
Stopwatch2: 1788146323471566 382982; combined=13246, p1=228, p2=12968, p3=0, p4=0, p5=49, sr=112, sw=1, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--8d0fff34-Z--
--559c7c78-A--
[31/Aug/2026:06:18:43.871529 +0300] apTyk9mUuou1H8H2UKXBVQAAANc 81.171.72.135 45530 127.0.0.1 7081
--559c7c78-B--
GET /.svn/wc.db HTTP/1.1
Host: ajutam.ro
X-Real-IP: 81.171.72.135
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Go-http-client/1.1
Accept-Encoding: gzip
--559c7c78-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/7.3.33
Expires: Wed, 11 Jan 1984 05:00:00 GMT
Cache-Control: no-cache, must-revalidate, max-age=0, no-store, private
Link:
; rel="https://api.w.org/"
X-TEC-API-VERSION: v1
X-TEC-API-ROOT: https://ajutam.ro/wp-json/tribe/events/v1/
X-TEC-API-ORIGIN: https://ajutam.ro
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--559c7c78-H--
Message: Warning. Matched phrase ".svn/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.svn/wc.db||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"]
Message: Warning. Matched phrase ".svn/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.svn/wc.db||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".svn/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.svn/wc.db||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "ajutam.ro"] [uri "/.svn/wc.db"] [unique_id "apTyk9mUuou1H8H2UKXBVQAAANc"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".svn/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.svn/wc.db||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "ajutam.ro"] [uri "/.svn/wc.db"] [unique_id "apTyk9mUuou1H8H2UKXBVQAAANc"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/ajutam.ro/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788146323483415 388238 (- - -)
Stopwatch2: 1788146323483415 388238; combined=33241, p1=194, p2=32981, p3=0, p4=0, p5=66, sr=68, sw=0, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--559c7c78-Z--
--cc644f03-A--
[31/Aug/2026:06:18:44.077667 +0300] apTyk9mUuou1H8H2UKXBVgAAAM8 81.171.72.135 45542 127.0.0.1 7081
--cc644f03-B--
GET /backup.sql HTTP/1.1
Host: ajutam.ro
X-Real-IP: 81.171.72.135
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Go-http-client/1.1
Accept-Encoding: gzip
--cc644f03-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/7.3.33
Expires: Wed, 11 Jan 1984 05:00:00 GMT
Cache-Control: no-cache, must-revalidate, max-age=0, no-store, private
Link:
; rel="https://api.w.org/"
X-TEC-API-VERSION: v1
X-TEC-API-ROOT: https://ajutam.ro/wp-json/tribe/events/v1/
X-TEC-API-ORIGIN: https://ajutam.ro
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--cc644f03-H--
Message: Warning. Matched phrase "/backup." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/backup.sql||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"]
Message: Warning. Matched phrase "/backup." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/backup.sql||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "/backup." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/backup.sql||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "ajutam.ro"] [uri "/backup.sql"] [unique_id "apTyk9mUuou1H8H2UKXBVgAAAM8"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "/backup." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/backup.sql||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "ajutam.ro"] [uri "/backup.sql"] [unique_id "apTyk9mUuou1H8H2UKXBVgAAAM8"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/ajutam.ro/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788146323758393 319341 (- - -)
Stopwatch2: 1788146323758393 319341; combined=31236, p1=281, p2=30888, p3=0, p4=0, p5=66, sr=117, sw=1, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--cc644f03-Z--
--5acf943e-A--
[31/Aug/2026:06:19:41.656415 +0300] apTyzW7fDIutYTwcPOkZ7gAAAE8 207.154.219.81 55532 127.0.0.1 7081
--5acf943e-B--
POST /wp-login.php HTTP/1.1
Host: ajutam.ro
X-Real-IP: 207.154.219.81
X-Accel-Internal: /internal-nginx-static-location
Content-Length: 108
Accept: */*
User-Agent: Mozilla/5.0
Content-Type: application/x-www-form-urlencoded
Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818
--5acf943e-F--
HTTP/1.1 403 Forbidden
Last-Modified: Fri, 01 May 2020 21:00:27 GMT
ETag: "31b-5a49c787f10c0"
Accept-Ranges: bytes
Content-Length: 795
Content-Type: text/html
--5acf943e-H--
Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:06-19.207.154.219.81"] [severity "CRITICAL"] [tag "wp_core"]
Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"]
Action: Intercepted (phase 2)
Stopwatch: 1788146381432788 223719 (- - -)
Stopwatch2: 1788146381432788 223719; combined=214003, p1=2297, p2=210970, p3=0, p4=0, p5=570, sr=192, sw=166, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--5acf943e-Z--
--71f54c01-A--
[31/Aug/2026:06:26:23.945400 +0300] apT0X9mUuou1H8H2UKXBeAAAAMA 207.154.219.81 60682 127.0.0.1 7081
--71f54c01-B--
POST /wp-login.php HTTP/1.1
Host: ajutam.ro
X-Real-IP: 207.154.219.81
X-Accel-Internal: /internal-nginx-static-location
Content-Length: 110
Accept: */*
User-Agent: Mozilla/5.0
Content-Type: application/x-www-form-urlencoded
Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818
--71f54c01-F--
HTTP/1.1 403 Forbidden
Last-Modified: Fri, 01 May 2020 21:00:27 GMT
ETag: "31b-5a49c787f10c0"
Accept-Ranges: bytes
Content-Length: 795
Content-Type: text/html
--71f54c01-H--
Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:06-26.207.154.219.81"] [severity "CRITICAL"] [tag "wp_core"]
Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"]
Action: Intercepted (phase 2)
Stopwatch: 1788146783882308 63148 (- - -)
Stopwatch2: 1788146783882308 63148; combined=61290, p1=460, p2=60240, p3=0, p4=0, p5=447, sr=158, sw=143, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--71f54c01-Z--
--78c8584d-A--
[31/Aug/2026:06:31:22.840325 +0300] apT1itmUuou1H8H2UKXBjAAAAMs 138.197.193.77 46962 127.0.0.1 7081
--78c8584d-B--
POST /wp-login.php HTTP/1.1
Host: ajutam.ro
X-Real-IP: 138.197.193.77
X-Accel-Internal: /internal-nginx-static-location
Content-Length: 105
Accept: */*
User-Agent: Mozilla/5.0
Content-Type: application/x-www-form-urlencoded
Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818
--78c8584d-F--
HTTP/1.1 403 Forbidden
Last-Modified: Fri, 01 May 2020 21:00:27 GMT
ETag: "31b-5a49c787f10c0"
Accept-Ranges: bytes
Content-Length: 795
Content-Type: text/html
--78c8584d-H--
Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:06-31.138.197.193.77"] [severity "CRITICAL"] [tag "wp_core"]
Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"]
Action: Intercepted (phase 2)
Stopwatch: 1788147082777068 63406 (- - -)
Stopwatch2: 1788147082777068 63406; combined=58769, p1=298, p2=57042, p3=0, p4=0, p5=1040, sr=109, sw=389, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--78c8584d-Z--
--6659a052-A--
[31/Aug/2026:06:33:06.468117 +0300] apT18n7glkZrdsSdRApI1wAAAIo 207.154.219.81 33312 127.0.0.1 7081
--6659a052-B--
POST /wp-login.php HTTP/1.1
Host: ajutam.ro
X-Real-IP: 207.154.219.81
X-Accel-Internal: /internal-nginx-static-location
Content-Length: 111
Accept: */*
User-Agent: Mozilla/5.0
Content-Type: application/x-www-form-urlencoded
Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818
--6659a052-F--
HTTP/1.1 403 Forbidden
Last-Modified: Fri, 01 May 2020 21:00:27 GMT
ETag: "31b-5a49c787f10c0"
Accept-Ranges: bytes
Content-Length: 795
Content-Type: text/html
--6659a052-H--
Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:06-33.207.154.219.81"] [severity "CRITICAL"] [tag "wp_core"]
Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"]
Action: Intercepted (phase 2)
Stopwatch: 1788147186406485 61716 (- - -)
Stopwatch2: 1788147186406485 61716; combined=59131, p1=362, p2=57834, p3=0, p4=0, p5=672, sr=99, sw=263, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--6659a052-Z--
--ebd7b367-A--
[31/Aug/2026:06:33:15.423751 +0300] apT1@9mUuou1H8H2UKXBpAAAAMk 216.73.217.35 33358 127.0.0.1 7081
--ebd7b367-B--
GET /img/ufo_fm.php?p=%27+.+urlencode%28%24bp%29+.+%27 HTTP/1.1
Host: ihelp.ro
X-Real-IP: 216.73.217.35
X-Accel-Internal: /internal-nginx-static-location
accept: */*
user-agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)
accept-encoding: gzip, br, zstd, deflate
--ebd7b367-F--
HTTP/1.1 200 OK
X-Powered-By: PHP/8.1.34
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--ebd7b367-H--
Message: Warning. Pattern match "(?i)\\b(?:s(?:e(?:t(?:_(?:e(?:xception|rror)_handler|magic_quotes_runtime|include_path)|defaultstub)|ssion_s(?:et_save_handler|tart))|qlite_(?:(?:(?:unbuffered|single|array)_)?query|create_(?:aggregate|function)|p?open|exec)|tr(?:eam_(?:context_create| ..." at ARGS:p. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "63"] [id "77134464"] [msg "IM360 WAF: Infectors: PHP Injection High-Risk PHP Function||T:APACHE||MVN:ARGS:p||MV:' . urlencode($bp) . '||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_o"] [tag "service_i360"]
Message: Warning. Pattern match "(?i)\\b(?:s(?:e(?:t(?:_(?:e(?:xception|rror)_handler|magic_quotes_runtime|include_path)|defaultstub)|ssion_s(?:et_save_handler|tart))|qlite_(?:(?:(?:unbuffered|single|array)_)?query|create_(?:aggregate|function)|p?open|exec)|tr(?:eam_(?:context_create| ..." at ARGS:p. [file "/etc/httpd/conf/modsecurity.d/rules/custom/012_i360_1_generic.conf"] [line "19"] [id "77134463"] [msg "IM360 WAF: PHP Injection Attack: High-Risk PHP Function Call Found||T:APACHE||MVN:ARGS:p||MV:' . urlencode($bp) . '||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "NOTICE"] [tag "service_o"] [tag "service_i360"] [tag "noshow"] [tag "service_rbl_infectors"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(?i)\\\\\\\\b(?:s(?:e(?:t(?:_(?:e(?:xception|rror)_handler|magic_quotes_runtime|include_path)|defaultstub)|ssion_s(?:et_save_handler|tart))|qlite_(?:(?:(?:unbuffered|single|array)_)?query|create_(?:aggregate|function)|p?open|exec)|tr(?:eam_(?:context_create| ..." at ARGS:p. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "63"] [id "77134464"] [msg "IM360 WAF: Infectors: PHP Injection High-Risk PHP Function||T:APACHE||MVN:ARGS:p||MV:' . urlencode($bp) . '||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_o"] [tag "service_i360"] [hostname "ihelp.ro"] [uri "/img/ufo_fm.php"] [unique_id "apT1@9mUuou1H8H2UKXBpAAAAMk"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(?i)\\\\\\\\b(?:s(?:e(?:t(?:_(?:e(?:xception|rror)_handler|magic_quotes_runtime|include_path)|defaultstub)|ssion_s(?:et_save_handler|tart))|qlite_(?:(?:(?:unbuffered|single|array)_)?query|create_(?:aggregate|function)|p?open|exec)|tr(?:eam_(?:context_create| ..." at ARGS:p. [file "/etc/httpd/conf/modsecurity.d/rules/custom/012_i360_1_generic.conf"] [line "19"] [id "77134463"] [msg "IM360 WAF: PHP Injection Attack: High-Risk PHP Function Call Found||T:APACHE||MVN:ARGS:p||MV:' . urlencode($bp) . '||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "NOTICE"] [tag "service_o"] [tag "service_i360"] [tag "noshow"] [tag "service_rbl_infectors"] [hostname "ihelp.ro"] [uri "/img/ufo_fm.php"] [unique_id "apT1@9mUuou1H8H2UKXBpAAAAMk"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788147195388110 35685 (- - -)
Stopwatch2: 1788147195388110 35685; combined=33022, p1=239, p2=32728, p3=0, p4=0, p5=54, sr=110, sw=1, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "DETECTION_ONLY"
--ebd7b367-Z--
--4c9ada32-A--
[31/Aug/2026:06:33:42.334179 +0300] apT2FtmUuou1H8H2UKXBtAAAANA 216.73.217.35 42272 127.0.0.1 7081
--4c9ada32-B--
GET /img/ufo_fm.php?p=%27.urlencode%28%24acc%29.%27 HTTP/1.1
Host: ihelp.ro
X-Real-IP: 216.73.217.35
X-Accel-Internal: /internal-nginx-static-location
accept: */*
user-agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)
accept-encoding: gzip, br, zstd, deflate
--4c9ada32-F--
HTTP/1.1 200 OK
X-Powered-By: PHP/8.1.34
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--4c9ada32-H--
Message: Warning. Pattern match "(?i)\\b(?:s(?:e(?:t(?:_(?:e(?:xception|rror)_handler|magic_quotes_runtime|include_path)|defaultstub)|ssion_s(?:et_save_handler|tart))|qlite_(?:(?:(?:unbuffered|single|array)_)?query|create_(?:aggregate|function)|p?open|exec)|tr(?:eam_(?:context_create| ..." at ARGS:p. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "63"] [id "77134464"] [msg "IM360 WAF: Infectors: PHP Injection High-Risk PHP Function||T:APACHE||MVN:ARGS:p||MV:'.urlencode($acc).'||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_o"] [tag "service_i360"]
Message: Warning. Pattern match "(?i)\\b(?:s(?:e(?:t(?:_(?:e(?:xception|rror)_handler|magic_quotes_runtime|include_path)|defaultstub)|ssion_s(?:et_save_handler|tart))|qlite_(?:(?:(?:unbuffered|single|array)_)?query|create_(?:aggregate|function)|p?open|exec)|tr(?:eam_(?:context_create| ..." at ARGS:p. [file "/etc/httpd/conf/modsecurity.d/rules/custom/012_i360_1_generic.conf"] [line "19"] [id "77134463"] [msg "IM360 WAF: PHP Injection Attack: High-Risk PHP Function Call Found||T:APACHE||MVN:ARGS:p||MV:'.urlencode($acc).'||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "NOTICE"] [tag "service_o"] [tag "service_i360"] [tag "noshow"] [tag "service_rbl_infectors"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(?i)\\\\\\\\b(?:s(?:e(?:t(?:_(?:e(?:xception|rror)_handler|magic_quotes_runtime|include_path)|defaultstub)|ssion_s(?:et_save_handler|tart))|qlite_(?:(?:(?:unbuffered|single|array)_)?query|create_(?:aggregate|function)|p?open|exec)|tr(?:eam_(?:context_create| ..." at ARGS:p. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "63"] [id "77134464"] [msg "IM360 WAF: Infectors: PHP Injection High-Risk PHP Function||T:APACHE||MVN:ARGS:p||MV:'.urlencode($acc).'||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_o"] [tag "service_i360"] [hostname "ihelp.ro"] [uri "/img/ufo_fm.php"] [unique_id "apT2FtmUuou1H8H2UKXBtAAAANA"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(?i)\\\\\\\\b(?:s(?:e(?:t(?:_(?:e(?:xception|rror)_handler|magic_quotes_runtime|include_path)|defaultstub)|ssion_s(?:et_save_handler|tart))|qlite_(?:(?:(?:unbuffered|single|array)_)?query|create_(?:aggregate|function)|p?open|exec)|tr(?:eam_(?:context_create| ..." at ARGS:p. [file "/etc/httpd/conf/modsecurity.d/rules/custom/012_i360_1_generic.conf"] [line "19"] [id "77134463"] [msg "IM360 WAF: PHP Injection Attack: High-Risk PHP Function Call Found||T:APACHE||MVN:ARGS:p||MV:'.urlencode($acc).'||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "NOTICE"] [tag "service_o"] [tag "service_i360"] [tag "noshow"] [tag "service_rbl_infectors"] [hostname "ihelp.ro"] [uri "/img/ufo_fm.php"] [unique_id "apT2FtmUuou1H8H2UKXBtAAAANA"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788147222299416 34810 (- - -)
Stopwatch2: 1788147222299416 34810; combined=31357, p1=252, p2=31039, p3=0, p4=0, p5=66, sr=91, sw=0, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "DETECTION_ONLY"
--4c9ada32-Z--
--61d28665-A--
[31/Aug/2026:06:34:01.083844 +0300] apT2KdmUuou1H8H2UKXBxAAAAMA 138.197.193.77 41028 127.0.0.1 7081
--61d28665-B--
POST /wp-login.php HTTP/1.1
Host: ajutam.ro
X-Real-IP: 138.197.193.77
X-Accel-Internal: /internal-nginx-static-location
Content-Length: 108
Accept: */*
User-Agent: Mozilla/5.0
Content-Type: application/x-www-form-urlencoded
Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818
--61d28665-F--
HTTP/1.1 403 Forbidden
Last-Modified: Fri, 01 May 2020 21:00:27 GMT
ETag: "31b-5a49c787f10c0"
Accept-Ranges: bytes
Content-Length: 795
Content-Type: text/html
--61d28665-H--
Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "42"] [id "33302"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:1"] [severity "CRITICAL"] [tag "wp_core"]
Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"]
Action: Intercepted (phase 2)
Stopwatch: 1788147241081871 2042 (- - -)
Stopwatch2: 1788147241081871 2042; combined=670, p1=275, p2=74, p3=0, p4=0, p5=321, sr=104, sw=0, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--61d28665-Z--
--6209bb50-A--
[31/Aug/2026:06:34:10.857892 +0300] apT2Mn7glkZrdsSdRApI7QAAAIE 216.73.217.35 49202 127.0.0.1 7081
--6209bb50-B--
GET /img/ufo_fm.php?f=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2F.htaccess&p=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs HTTP/1.1
Host: ihelp.ro
X-Real-IP: 216.73.217.35
X-Accel-Internal: /internal-nginx-static-location
accept: */*
user-agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)
accept-encoding: gzip, br, zstd, deflate
--6209bb50-F--
HTTP/1.1 200 OK
X-Powered-By: PHP/8.1.34
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--6209bb50-H--
Message: Warning. Match of "pm cpanel AdminTranslations" against "REQUEST_URI" required. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "65"] [id "77140882"] [msg "IM360 WAF: Infectors: Remote File Access Attempt||MVN:REQUEST_URI||MV:/img/ufo_fm.php?f=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2F.htaccess&p=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs||T:APACHE||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Match of "pm cpanel AdminTranslations" against "REQUEST_URI" required. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "65"] [id "77140882"] [msg "IM360 WAF: Infectors: Remote File Access Attempt||MVN:REQUEST_URI||MV:/img/ufo_fm.php?f=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2F.htaccess&p=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs||T:APACHE||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [hostname "ihelp.ro"] [uri "/img/ufo_fm.php"] [unique_id "apT2Mn7glkZrdsSdRApI7QAAAIE"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788147250822547 35393 (- - -)
Stopwatch2: 1788147250822547 35393; combined=31347, p1=330, p2=30975, p3=0, p4=0, p5=42, sr=154, sw=0, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "DETECTION_ONLY"
--6209bb50-Z--
--9096fa5d-A--
[31/Aug/2026:06:35:54.784664 +0300] apT2mtmUuou1H8H2UKXB3AAAANU 216.73.217.35 45148 127.0.0.1 7081
--9096fa5d-B--
GET /img/ufo_fm.php?f=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2F.htaccess&p=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs&rm=1 HTTP/1.1
Host: ihelp.ro
X-Real-IP: 216.73.217.35
X-Accel-Internal: /internal-nginx-static-location
accept: */*
user-agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)
accept-encoding: gzip, br, zstd, deflate
--9096fa5d-F--
HTTP/1.1 200 OK
X-Powered-By: PHP/8.1.34
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--9096fa5d-H--
Message: Warning. Match of "pm cpanel AdminTranslations" against "REQUEST_URI" required. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "65"] [id "77140882"] [msg "IM360 WAF: Infectors: Remote File Access Attempt||MVN:REQUEST_URI||MV:/img/ufo_fm.php?f=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2F.htaccess&p=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs&rm=1||T:APACHE||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Match of "pm cpanel AdminTranslations" against "REQUEST_URI" required. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "65"] [id "77140882"] [msg "IM360 WAF: Infectors: Remote File Access Attempt||MVN:REQUEST_URI||MV:/img/ufo_fm.php?f=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2F.htaccess&p=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs&rm=1||T:APACHE||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [hostname "ihelp.ro"] [uri "/img/ufo_fm.php"] [unique_id "apT2mtmUuou1H8H2UKXB3AAAANU"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788147354747689 37025 (- - -)
Stopwatch2: 1788147354747689 37025; combined=33760, p1=378, p2=33328, p3=0, p4=0, p5=53, sr=129, sw=1, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "DETECTION_ONLY"
--9096fa5d-Z--
--c31cca52-A--
[31/Aug/2026:06:36:09.255535 +0300] apT2qW7fDIutYTwcPOkaEgAAAEc 216.73.217.35 54010 127.0.0.1 7081
--c31cca52-B--
GET /img/ufo_fm.php?dl=1&f=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2F.htaccess&p=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs HTTP/1.1
Host: ihelp.ro
X-Real-IP: 216.73.217.35
X-Accel-Internal: /internal-nginx-static-location
accept: */*
user-agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)
accept-encoding: gzip, br, zstd, deflate
--c31cca52-F--
HTTP/1.1 200 OK
X-Powered-By: PHP/8.1.34
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--c31cca52-H--
Message: Warning. Match of "pm cpanel AdminTranslations" against "REQUEST_URI" required. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "65"] [id "77140882"] [msg "IM360 WAF: Infectors: Remote File Access Attempt||MVN:REQUEST_URI||MV:/img/ufo_fm.php?dl=1&f=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2F.htaccess&p=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs||T:APACHE||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Match of "pm cpanel AdminTranslations" against "REQUEST_URI" required. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "65"] [id "77140882"] [msg "IM360 WAF: Infectors: Remote File Access Attempt||MVN:REQUEST_URI||MV:/img/ufo_fm.php?dl=1&f=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2F.htaccess&p=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs||T:APACHE||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [hostname "ihelp.ro"] [uri "/img/ufo_fm.php"] [unique_id "apT2qW7fDIutYTwcPOkaEgAAAEc"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788147369218464 37119 (- - -)
Stopwatch2: 1788147369218464 37119; combined=34546, p1=268, p2=34223, p3=0, p4=0, p5=55, sr=128, sw=0, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "DETECTION_ONLY"
--c31cca52-Z--
--cf618e21-A--
[31/Aug/2026:06:36:10.034061 +0300] apT2qtmUuou1H8H2UKXB7wAAAMc 216.73.217.35 54092 127.0.0.1 7081
--cf618e21-B--
GET /img/ufo_fm.php?f=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2Fwebroot%2F.htaccess&p=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2Fwebroot HTTP/1.1
Host: ihelp.ro
X-Real-IP: 216.73.217.35
X-Accel-Internal: /internal-nginx-static-location
accept: */*
user-agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)
accept-encoding: gzip, br, zstd, deflate
--cf618e21-F--
HTTP/1.1 200 OK
X-Powered-By: PHP/8.1.34
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--cf618e21-H--
Message: Warning. Match of "pm cpanel AdminTranslations" against "REQUEST_URI" required. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "65"] [id "77140882"] [msg "IM360 WAF: Infectors: Remote File Access Attempt||MVN:REQUEST_URI||MV:/img/ufo_fm.php?f=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2Fwebroot%2F.htaccess&p=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2Fwebroot||T:APACHE||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Match of "pm cpanel AdminTranslations" against "REQUEST_URI" required. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "65"] [id "77140882"] [msg "IM360 WAF: Infectors: Remote File Access Attempt||MVN:REQUEST_URI||MV:/img/ufo_fm.php?f=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2Fwebroot%2F.htaccess&p=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2Fwebroot||T:APACHE||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [hostname "ihelp.ro"] [uri "/img/ufo_fm.php"] [unique_id "apT2qtmUuou1H8H2UKXB7wAAAMc"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788147370001236 32873 (- - -)
Stopwatch2: 1788147370001236 32873; combined=30483, p1=203, p2=30232, p3=0, p4=0, p5=47, sr=78, sw=1, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "DETECTION_ONLY"
--cf618e21-Z--
--ebd6563c-A--
[31/Aug/2026:06:36:36.014925 +0300] apT2w37glkZrdsSdRApJCwAAAII 138.197.193.77 43740 127.0.0.1 7081
--ebd6563c-B--
POST /wp-login.php HTTP/1.1
Host: ajutam.ro
X-Real-IP: 138.197.193.77
X-Accel-Internal: /internal-nginx-static-location
Content-Length: 108
Accept: */*
User-Agent: Mozilla/5.0
Content-Type: application/x-www-form-urlencoded
Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818
--ebd6563c-F--
HTTP/1.1 403 Forbidden
Last-Modified: Fri, 01 May 2020 21:00:27 GMT
ETag: "31b-5a49c787f10c0"
Accept-Ranges: bytes
Content-Length: 795
Content-Type: text/html
--ebd6563c-H--
Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:06-36.138.197.193.77"] [severity "CRITICAL"] [tag "wp_core"]
Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"]
Action: Intercepted (phase 2)
Stopwatch: 1788147395946407 68577 (- - -)
Stopwatch2: 1788147395946407 68577; combined=67062, p1=322, p2=66096, p3=0, p4=0, p5=478, sr=129, sw=166, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--ebd6563c-Z--
--37873b20-A--
[31/Aug/2026:06:37:52.038879 +0300] apT3D9mUuou1H8H2UKXCFwAAAM8 216.73.217.35 53192 127.0.0.1 7081
--37873b20-B--
GET /img/ufo_fm.php?f=%27.%24enc.%27&p=%27.urlencode%28%24p%29.%27 HTTP/1.1
Host: ihelp.ro
X-Real-IP: 216.73.217.35
X-Accel-Internal: /internal-nginx-static-location
accept: */*
user-agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)
accept-encoding: gzip, br, zstd, deflate
--37873b20-F--
HTTP/1.1 200 OK
X-Powered-By: PHP/8.1.34
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--37873b20-H--
Message: Warning. Pattern match "(?i)\\b(?:s(?:e(?:t(?:_(?:e(?:xception|rror)_handler|magic_quotes_runtime|include_path)|defaultstub)|ssion_s(?:et_save_handler|tart))|qlite_(?:(?:(?:unbuffered|single|array)_)?query|create_(?:aggregate|function)|p?open|exec)|tr(?:eam_(?:context_create| ..." at ARGS:p. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "63"] [id "77134464"] [msg "IM360 WAF: Infectors: PHP Injection High-Risk PHP Function||T:APACHE||MVN:ARGS:p||MV:'.urlencode($p).'||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_o"] [tag "service_i360"]
Message: Warning. Pattern match "(?i)\\b(?:s(?:e(?:t(?:_(?:e(?:xception|rror)_handler|magic_quotes_runtime|include_path)|defaultstub)|ssion_s(?:et_save_handler|tart))|qlite_(?:(?:(?:unbuffered|single|array)_)?query|create_(?:aggregate|function)|p?open|exec)|tr(?:eam_(?:context_create| ..." at ARGS:p. [file "/etc/httpd/conf/modsecurity.d/rules/custom/012_i360_1_generic.conf"] [line "19"] [id "77134463"] [msg "IM360 WAF: PHP Injection Attack: High-Risk PHP Function Call Found||T:APACHE||MVN:ARGS:p||MV:'.urlencode($p).'||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "NOTICE"] [tag "service_o"] [tag "service_i360"] [tag "noshow"] [tag "service_rbl_infectors"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(?i)\\\\\\\\b(?:s(?:e(?:t(?:_(?:e(?:xception|rror)_handler|magic_quotes_runtime|include_path)|defaultstub)|ssion_s(?:et_save_handler|tart))|qlite_(?:(?:(?:unbuffered|single|array)_)?query|create_(?:aggregate|function)|p?open|exec)|tr(?:eam_(?:context_create| ..." at ARGS:p. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "63"] [id "77134464"] [msg "IM360 WAF: Infectors: PHP Injection High-Risk PHP Function||T:APACHE||MVN:ARGS:p||MV:'.urlencode($p).'||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_o"] [tag "service_i360"] [hostname "ihelp.ro"] [uri "/img/ufo_fm.php"] [unique_id "apT3D9mUuou1H8H2UKXCFwAAAM8"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(?i)\\\\\\\\b(?:s(?:e(?:t(?:_(?:e(?:xception|rror)_handler|magic_quotes_runtime|include_path)|defaultstub)|ssion_s(?:et_save_handler|tart))|qlite_(?:(?:(?:unbuffered|single|array)_)?query|create_(?:aggregate|function)|p?open|exec)|tr(?:eam_(?:context_create| ..." at ARGS:p. [file "/etc/httpd/conf/modsecurity.d/rules/custom/012_i360_1_generic.conf"] [line "19"] [id "77134463"] [msg "IM360 WAF: PHP Injection Attack: High-Risk PHP Function Call Found||T:APACHE||MVN:ARGS:p||MV:'.urlencode($p).'||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "NOTICE"] [tag "service_o"] [tag "service_i360"] [tag "noshow"] [tag "service_rbl_infectors"] [hostname "ihelp.ro"] [uri "/img/ufo_fm.php"] [unique_id "apT3D9mUuou1H8H2UKXCFwAAAM8"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788147471993993 44935 (- - -)
Stopwatch2: 1788147471993993 44935; combined=38612, p1=275, p2=38231, p3=0, p4=0, p5=106, sr=114, sw=0, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "DETECTION_ONLY"
--37873b20-Z--
--050e0b57-A--
[31/Aug/2026:06:38:18.710033 +0300] apT3KtmUuou1H8H2UKXCHgAAANA 216.73.217.35 50862 127.0.0.1 7081
--050e0b57-B--
GET /img/ufo_fm.php?f=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2Fwebroot%2F.htaccess&p=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2Fwebroot&rm=1 HTTP/1.1
Host: ihelp.ro
X-Real-IP: 216.73.217.35
X-Accel-Internal: /internal-nginx-static-location
accept: */*
user-agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)
accept-encoding: gzip, br, zstd, deflate
--050e0b57-F--
HTTP/1.1 200 OK
X-Powered-By: PHP/8.1.34
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--050e0b57-H--
Message: Warning. Match of "pm cpanel AdminTranslations" against "REQUEST_URI" required. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "65"] [id "77140882"] [msg "IM360 WAF: Infectors: Remote File Access Attempt||MVN:REQUEST_URI||MV:/img/ufo_fm.php?f=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2Fwebroot%2F.htaccess&p=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2Fwebroot&rm=1||T:APACHE||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Match of "pm cpanel AdminTranslations" against "REQUEST_URI" required. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "65"] [id "77140882"] [msg "IM360 WAF: Infectors: Remote File Access Attempt||MVN:REQUEST_URI||MV:/img/ufo_fm.php?f=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2Fwebroot%2F.htaccess&p=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2Fwebroot&rm=1||T:APACHE||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [hostname "ihelp.ro"] [uri "/img/ufo_fm.php"] [unique_id "apT3KtmUuou1H8H2UKXCHgAAANA"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788147498673823 36268 (- - -)
Stopwatch2: 1788147498673823 36268; combined=33337, p1=281, p2=33010, p3=0, p4=0, p5=45, sr=130, sw=1, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "DETECTION_ONLY"
--050e0b57-Z--
--7f95b030-A--
[31/Aug/2026:06:38:19.979048 +0300] apT3K9mUuou1H8H2UKXCIwAAANY 216.73.217.35 50962 127.0.0.1 7081
--7f95b030-B--
GET /img/ufo_fm.php?dl=1&f=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2Fwebroot%2F.htaccess&p=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2Fwebroot HTTP/1.1
Host: ihelp.ro
X-Real-IP: 216.73.217.35
X-Accel-Internal: /internal-nginx-static-location
accept: */*
user-agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)
accept-encoding: gzip, br, zstd, deflate
--7f95b030-F--
HTTP/1.1 200 OK
X-Powered-By: PHP/8.1.34
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--7f95b030-H--
Message: Warning. Match of "pm cpanel AdminTranslations" against "REQUEST_URI" required. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "65"] [id "77140882"] [msg "IM360 WAF: Infectors: Remote File Access Attempt||MVN:REQUEST_URI||MV:/img/ufo_fm.php?dl=1&f=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2Fwebroot%2F.htaccess&p=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2Fwebroot||T:APACHE||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Match of "pm cpanel AdminTranslations" against "REQUEST_URI" required. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "65"] [id "77140882"] [msg "IM360 WAF: Infectors: Remote File Access Attempt||MVN:REQUEST_URI||MV:/img/ufo_fm.php?dl=1&f=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2Fwebroot%2F.htaccess&p=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2Fwebroot||T:APACHE||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [hostname "ihelp.ro"] [uri "/img/ufo_fm.php"] [unique_id "apT3K9mUuou1H8H2UKXCIwAAANY"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788147499945526 33571 (- - -)
Stopwatch2: 1788147499945526 33571; combined=31148, p1=230, p2=30867, p3=0, p4=0, p5=51, sr=87, sw=0, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "DETECTION_ONLY"
--7f95b030-Z--
--ecd73067-A--
[31/Aug/2026:06:38:43.164179 +0300] apT3Q37glkZrdsSdRApJKAAAAII 216.73.217.35 54824 127.0.0.1 7081
--ecd73067-B--
GET /img/ufo_fm.php?f=%27.%24enc.%27&p=%27.urlencode%28%24p%29.%27&rm=1 HTTP/1.1
Host: ihelp.ro
X-Real-IP: 216.73.217.35
X-Accel-Internal: /internal-nginx-static-location
accept: */*
user-agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)
accept-encoding: gzip, br, zstd, deflate
--ecd73067-F--
HTTP/1.1 200 OK
X-Powered-By: PHP/8.1.34
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--ecd73067-H--
Message: Warning. Pattern match "(?i)\\b(?:s(?:e(?:t(?:_(?:e(?:xception|rror)_handler|magic_quotes_runtime|include_path)|defaultstub)|ssion_s(?:et_save_handler|tart))|qlite_(?:(?:(?:unbuffered|single|array)_)?query|create_(?:aggregate|function)|p?open|exec)|tr(?:eam_(?:context_create| ..." at ARGS:p. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "63"] [id "77134464"] [msg "IM360 WAF: Infectors: PHP Injection High-Risk PHP Function||T:APACHE||MVN:ARGS:p||MV:'.urlencode($p).'||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_o"] [tag "service_i360"]
Message: Warning. Pattern match "(?i)\\b(?:s(?:e(?:t(?:_(?:e(?:xception|rror)_handler|magic_quotes_runtime|include_path)|defaultstub)|ssion_s(?:et_save_handler|tart))|qlite_(?:(?:(?:unbuffered|single|array)_)?query|create_(?:aggregate|function)|p?open|exec)|tr(?:eam_(?:context_create| ..." at ARGS:p. [file "/etc/httpd/conf/modsecurity.d/rules/custom/012_i360_1_generic.conf"] [line "19"] [id "77134463"] [msg "IM360 WAF: PHP Injection Attack: High-Risk PHP Function Call Found||T:APACHE||MVN:ARGS:p||MV:'.urlencode($p).'||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "NOTICE"] [tag "service_o"] [tag "service_i360"] [tag "noshow"] [tag "service_rbl_infectors"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(?i)\\\\\\\\b(?:s(?:e(?:t(?:_(?:e(?:xception|rror)_handler|magic_quotes_runtime|include_path)|defaultstub)|ssion_s(?:et_save_handler|tart))|qlite_(?:(?:(?:unbuffered|single|array)_)?query|create_(?:aggregate|function)|p?open|exec)|tr(?:eam_(?:context_create| ..." at ARGS:p. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "63"] [id "77134464"] [msg "IM360 WAF: Infectors: PHP Injection High-Risk PHP Function||T:APACHE||MVN:ARGS:p||MV:'.urlencode($p).'||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_o"] [tag "service_i360"] [hostname "ihelp.ro"] [uri "/img/ufo_fm.php"] [unique_id "apT3Q37glkZrdsSdRApJKAAAAII"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(?i)\\\\\\\\b(?:s(?:e(?:t(?:_(?:e(?:xception|rror)_handler|magic_quotes_runtime|include_path)|defaultstub)|ssion_s(?:et_save_handler|tart))|qlite_(?:(?:(?:unbuffered|single|array)_)?query|create_(?:aggregate|function)|p?open|exec)|tr(?:eam_(?:context_create| ..." at ARGS:p. [file "/etc/httpd/conf/modsecurity.d/rules/custom/012_i360_1_generic.conf"] [line "19"] [id "77134463"] [msg "IM360 WAF: PHP Injection Attack: High-Risk PHP Function Call Found||T:APACHE||MVN:ARGS:p||MV:'.urlencode($p).'||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "NOTICE"] [tag "service_o"] [tag "service_i360"] [tag "noshow"] [tag "service_rbl_infectors"] [hostname "ihelp.ro"] [uri "/img/ufo_fm.php"] [unique_id "apT3Q37glkZrdsSdRApJKAAAAII"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788147523129051 35174 (- - -)
Stopwatch2: 1788147523129051 35174; combined=32591, p1=196, p2=32294, p3=0, p4=0, p5=101, sr=82, sw=0, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "DETECTION_ONLY"
--ecd73067-Z--
--3ff26137-A--
[31/Aug/2026:06:39:15.969288 +0300] apT3Y37glkZrdsSdRApJKQAAAJM 138.197.193.77 56892 127.0.0.1 7081
--3ff26137-B--
POST /wp-login.php HTTP/1.1
Host: ajutam.ro
X-Real-IP: 138.197.193.77
X-Accel-Internal: /internal-nginx-static-location
Content-Length: 110
Accept: */*
User-Agent: Mozilla/5.0
Content-Type: application/x-www-form-urlencoded
Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818
--3ff26137-F--
HTTP/1.1 403 Forbidden
Last-Modified: Fri, 01 May 2020 21:00:27 GMT
ETag: "31b-5a49c787f10c0"
Accept-Ranges: bytes
Content-Length: 795
Content-Type: text/html
--3ff26137-H--
Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "42"] [id "33302"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:1"] [severity "CRITICAL"] [tag "wp_core"]
Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"]
Action: Intercepted (phase 2)
Stopwatch: 1788147555967468 1890 (- - -)
Stopwatch2: 1788147555967468 1890; combined=595, p1=257, p2=84, p3=0, p4=0, p5=254, sr=108, sw=0, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--3ff26137-Z--
--2a0ce25c-A--
[31/Aug/2026:06:39:39.472364 +0300] apT3e9mUuou1H8H2UKXCMQAAANY 216.73.217.35 55910 127.0.0.1 7081
--2a0ce25c-B--
GET /img/ufo_fm.php?dl=1&f=%27.%24enc.%27&p=%27.urlencode%28%24p%29.%27 HTTP/1.1
Host: ihelp.ro
X-Real-IP: 216.73.217.35
X-Accel-Internal: /internal-nginx-static-location
accept: */*
user-agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)
accept-encoding: gzip, br, zstd, deflate
--2a0ce25c-F--
HTTP/1.1 200 OK
X-Powered-By: PHP/8.1.34
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--2a0ce25c-H--
Message: Warning. Pattern match "(?i)\\b(?:s(?:e(?:t(?:_(?:e(?:xception|rror)_handler|magic_quotes_runtime|include_path)|defaultstub)|ssion_s(?:et_save_handler|tart))|qlite_(?:(?:(?:unbuffered|single|array)_)?query|create_(?:aggregate|function)|p?open|exec)|tr(?:eam_(?:context_create| ..." at ARGS:p. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "63"] [id "77134464"] [msg "IM360 WAF: Infectors: PHP Injection High-Risk PHP Function||T:APACHE||MVN:ARGS:p||MV:'.urlencode($p).'||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_o"] [tag "service_i360"]
Message: Warning. Pattern match "(?i)\\b(?:s(?:e(?:t(?:_(?:e(?:xception|rror)_handler|magic_quotes_runtime|include_path)|defaultstub)|ssion_s(?:et_save_handler|tart))|qlite_(?:(?:(?:unbuffered|single|array)_)?query|create_(?:aggregate|function)|p?open|exec)|tr(?:eam_(?:context_create| ..." at ARGS:p. [file "/etc/httpd/conf/modsecurity.d/rules/custom/012_i360_1_generic.conf"] [line "19"] [id "77134463"] [msg "IM360 WAF: PHP Injection Attack: High-Risk PHP Function Call Found||T:APACHE||MVN:ARGS:p||MV:'.urlencode($p).'||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "NOTICE"] [tag "service_o"] [tag "service_i360"] [tag "noshow"] [tag "service_rbl_infectors"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(?i)\\\\\\\\b(?:s(?:e(?:t(?:_(?:e(?:xception|rror)_handler|magic_quotes_runtime|include_path)|defaultstub)|ssion_s(?:et_save_handler|tart))|qlite_(?:(?:(?:unbuffered|single|array)_)?query|create_(?:aggregate|function)|p?open|exec)|tr(?:eam_(?:context_create| ..." at ARGS:p. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "63"] [id "77134464"] [msg "IM360 WAF: Infectors: PHP Injection High-Risk PHP Function||T:APACHE||MVN:ARGS:p||MV:'.urlencode($p).'||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_o"] [tag "service_i360"] [hostname "ihelp.ro"] [uri "/img/ufo_fm.php"] [unique_id "apT3e9mUuou1H8H2UKXCMQAAANY"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(?i)\\\\\\\\b(?:s(?:e(?:t(?:_(?:e(?:xception|rror)_handler|magic_quotes_runtime|include_path)|defaultstub)|ssion_s(?:et_save_handler|tart))|qlite_(?:(?:(?:unbuffered|single|array)_)?query|create_(?:aggregate|function)|p?open|exec)|tr(?:eam_(?:context_create| ..." at ARGS:p. [file "/etc/httpd/conf/modsecurity.d/rules/custom/012_i360_1_generic.conf"] [line "19"] [id "77134463"] [msg "IM360 WAF: PHP Injection Attack: High-Risk PHP Function Call Found||T:APACHE||MVN:ARGS:p||MV:'.urlencode($p).'||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "NOTICE"] [tag "service_o"] [tag "service_i360"] [tag "noshow"] [tag "service_rbl_infectors"] [hostname "ihelp.ro"] [uri "/img/ufo_fm.php"] [unique_id "apT3e9mUuou1H8H2UKXCMQAAANY"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788147579435229 37192 (- - -)
Stopwatch2: 1788147579435229 37192; combined=33980, p1=389, p2=33525, p3=0, p4=0, p5=65, sr=160, sw=1, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "DETECTION_ONLY"
--2a0ce25c-Z--
--27f8364d-A--
[31/Aug/2026:06:39:52.134583 +0300] apT3iH7glkZrdsSdRApJNwAAAI8 207.154.219.81 52340 127.0.0.1 7081
--27f8364d-B--
POST /wp-login.php HTTP/1.1
Host: ajutam.ro
X-Real-IP: 207.154.219.81
X-Accel-Internal: /internal-nginx-static-location
Content-Length: 110
Accept: */*
User-Agent: Mozilla/5.0
Content-Type: application/x-www-form-urlencoded
Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818
--27f8364d-F--
HTTP/1.1 403 Forbidden
Last-Modified: Fri, 01 May 2020 21:00:27 GMT
ETag: "31b-5a49c787f10c0"
Accept-Ranges: bytes
Content-Length: 795
Content-Type: text/html
--27f8364d-H--
Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:06-39.207.154.219.81"] [severity "CRITICAL"] [tag "wp_core"]
Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"]
Action: Intercepted (phase 2)
Stopwatch: 1788147592074826 59879 (- - -)
Stopwatch2: 1788147592074826 59879; combined=58193, p1=246, p2=57181, p3=0, p4=0, p5=553, sr=92, sw=213, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--27f8364d-Z--
--ec426506-A--
[31/Aug/2026:06:40:33.059710 +0300] apT3sH7glkZrdsSdRApJPAAAAJc 45.79.180.146 54096 127.0.0.1 7081
--ec426506-B--
POST /wp-login.php HTTP/1.1
Host: axapres.ro
X-Real-IP: 45.79.180.146
X-Accel-Internal: /internal-nginx-static-location
Content-Length: 98
Accept: */*
Accept-Encoding: gzip, deflate
Cookie: wordpress_test_cookie=WP+Cookie+check
User-Agent: Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.43 (KHTML, like Gecko) Chrome/139.0.0.0 Safari/537.36 OPR/123.0.0.0
Content-Type: application/x-www-form-urlencoded
--ec426506-F--
HTTP/1.1 403 Forbidden
Content-Length: 199
Content-Type: text/html; charset=iso-8859-1
--ec426506-H--
Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:06-40.45.79.180.146"] [severity "CRITICAL"] [tag "wp_core"]
Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"]
Action: Intercepted (phase 2)
Apache-Handler: proxy:unix:/var/www/vhosts/system/axapres.ro/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788147632995695 64071 (- - -)
Stopwatch2: 1788147632995695 64071; combined=62215, p1=523, p2=60937, p3=0, p4=0, p5=526, sr=254, sw=229, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--ec426506-Z--
--f9b03763-A--
[31/Aug/2026:06:44:44.762206 +0300] apT4rH7glkZrdsSdRApJSwAAAJA 138.197.193.77 51650 127.0.0.1 7081
--f9b03763-B--
POST /wp-login.php HTTP/1.1
Host: ajutam.ro
X-Real-IP: 138.197.193.77
X-Accel-Internal: /internal-nginx-static-location
Content-Length: 111
Accept: */*
User-Agent: Mozilla/5.0
Content-Type: application/x-www-form-urlencoded
Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818
--f9b03763-F--
HTTP/1.1 403 Forbidden
Last-Modified: Fri, 01 May 2020 21:00:27 GMT
ETag: "31b-5a49c787f10c0"
Accept-Ranges: bytes
Content-Length: 795
Content-Type: text/html
--f9b03763-H--
Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:06-44.138.197.193.77"] [severity "CRITICAL"] [tag "wp_core"]
Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"]
Action: Intercepted (phase 2)
Stopwatch: 1788147884692831 69450 (- - -)
Stopwatch2: 1788147884692831 69450; combined=76813, p1=262, p2=58315, p3=0, p4=0, p5=9266, sr=110, sw=148, l=0, gc=8822
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--f9b03763-Z--
--1c88b226-A--
[31/Aug/2026:06:46:37.830846 +0300] apT5HX7glkZrdsSdRApJUAAAAI8 207.154.219.81 36712 127.0.0.1 7081
--1c88b226-B--
POST /wp-login.php HTTP/1.1
Host: ajutam.ro
X-Real-IP: 207.154.219.81
X-Accel-Internal: /internal-nginx-static-location
Content-Length: 109
Accept: */*
User-Agent: Mozilla/5.0
Content-Type: application/x-www-form-urlencoded
Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818
--1c88b226-F--
HTTP/1.1 403 Forbidden
Last-Modified: Fri, 01 May 2020 21:00:27 GMT
ETag: "31b-5a49c787f10c0"
Accept-Ranges: bytes
Content-Length: 795
Content-Type: text/html
--1c88b226-H--
Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:06-46.207.154.219.81"] [severity "CRITICAL"] [tag "wp_core"]
Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"]
Action: Intercepted (phase 2)
Stopwatch: 1788147997769009 61900 (- - -)
Stopwatch2: 1788147997769009 61900; combined=60041, p1=261, p2=58836, p3=0, p4=0, p5=664, sr=114, sw=280, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--1c88b226-Z--
--1ea68b55-A--
[31/Aug/2026:06:52:06.470030 +0300] apT6Zm7fDIutYTwcPOkaMwAAAFM 138.197.193.77 38052 127.0.0.1 7081
--1ea68b55-B--
POST /wp-login.php HTTP/1.1
Host: ajutam.ro
X-Real-IP: 138.197.193.77
X-Accel-Internal: /internal-nginx-static-location
Content-Length: 108
Accept: */*
User-Agent: Mozilla/5.0
Content-Type: application/x-www-form-urlencoded
Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818
--1ea68b55-F--
HTTP/1.1 403 Forbidden
Last-Modified: Fri, 01 May 2020 21:00:27 GMT
ETag: "31b-5a49c787f10c0"
Accept-Ranges: bytes
Content-Length: 795
Content-Type: text/html
--1ea68b55-H--
Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:06-52.138.197.193.77"] [severity "CRITICAL"] [tag "wp_core"]
Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"]
Action: Intercepted (phase 2)
Stopwatch: 1788148326406234 63866 (- - -)
Stopwatch2: 1788148326406234 63866; combined=62168, p1=349, p2=61283, p3=0, p4=0, p5=409, sr=140, sw=127, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--1ea68b55-Z--
--1cc20c58-A--
[31/Aug/2026:06:53:12.666337 +0300] apT6qNmUuou1H8H2UKXCjAAAANI 207.154.219.81 45260 127.0.0.1 7081
--1cc20c58-B--
POST /wp-login.php HTTP/1.1
Host: ajutam.ro
X-Real-IP: 207.154.219.81
X-Accel-Internal: /internal-nginx-static-location
Content-Length: 108
Accept: */*
User-Agent: Mozilla/5.0
Content-Type: application/x-www-form-urlencoded
Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818
--1cc20c58-F--
HTTP/1.1 403 Forbidden
Last-Modified: Fri, 01 May 2020 21:00:27 GMT
ETag: "31b-5a49c787f10c0"
Accept-Ranges: bytes
Content-Length: 795
Content-Type: text/html
--1cc20c58-H--
Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:06-53.207.154.219.81"] [severity "CRITICAL"] [tag "wp_core"]
Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"]
Action: Intercepted (phase 2)
Stopwatch: 1788148392603552 62871 (- - -)
Stopwatch2: 1788148392603552 62871; combined=60050, p1=262, p2=59081, p3=0, p4=0, p5=520, sr=109, sw=187, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--1cc20c58-Z--
--d8a1f45a-A--
[31/Aug/2026:06:53:43.149580 +0300] apT6x9mUuou1H8H2UKXCjgAAAM8 167.86.74.74 57124 127.0.0.1 7081
--d8a1f45a-B--
GET /.env HTTP/1.1
Host: funshop.ro
X-Real-IP: 167.86.74.74
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36
Accept-Encoding: gzip, deflate
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,image/apng,*/*;q=0.8
Cache-Control: max-age=0
Upgrade-Insecure-Requests: 1
Accept-Language: en-US,en;q=0.9,fr;q=0.8
--d8a1f45a-F--
HTTP/1.1 404 Not Found
Content-Length: 196
Content-Type: text/html; charset=iso-8859-1
--d8a1f45a-E--
--d8a1f45a-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "funshop.ro"] [uri "/.env"] [unique_id "apT6x9mUuou1H8H2UKXCjgAAAM8"]
Stopwatch: 1788148423142296 7424 (- - -)
Stopwatch2: 1788148423142296 7424; combined=5214, p1=385, p2=4716, p3=61, p4=7, p5=45, sr=123, sw=0, l=0, gc=0
Response-Body-Transformed: Dechunked
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--d8a1f45a-Z--
--82a6bb27-A--
[31/Aug/2026:06:59:33.015303 +0300] apT8JNmUuou1H8H2UKXCrQAAAMI 138.197.193.77 44908 127.0.0.1 7081
--82a6bb27-B--
POST /wp-login.php HTTP/1.1
Host: ajutam.ro
X-Real-IP: 138.197.193.77
X-Accel-Internal: /internal-nginx-static-location
Content-Length: 123
Accept: */*
User-Agent: Mozilla/5.0
Content-Type: application/x-www-form-urlencoded
Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818
--82a6bb27-F--
HTTP/1.1 403 Forbidden
Last-Modified: Fri, 01 May 2020 21:00:27 GMT
ETag: "31b-5a49c787f10c0"
Accept-Ranges: bytes
Content-Length: 795
Content-Type: text/html
--82a6bb27-H--
Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:06-59.138.197.193.77"] [severity "CRITICAL"] [tag "wp_core"]
Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"]
Action: Intercepted (phase 2)
Stopwatch: 1788148772957215 58163 (- - -)
Stopwatch2: 1788148772957215 58163; combined=56605, p1=261, p2=55735, p3=0, p4=0, p5=452, sr=105, sw=157, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--82a6bb27-Z--
--362db907-A--
[31/Aug/2026:06:59:49.057166 +0300] apT8NNmUuou1H8H2UKXCsQAAANc 207.154.219.81 42046 127.0.0.1 7081
--362db907-B--
POST /wp-login.php HTTP/1.1
Host: ajutam.ro
X-Real-IP: 207.154.219.81
X-Accel-Internal: /internal-nginx-static-location
Content-Length: 126
Accept: */*
User-Agent: Mozilla/5.0
Content-Type: application/x-www-form-urlencoded
Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818
--362db907-F--
HTTP/1.1 403 Forbidden
Last-Modified: Fri, 01 May 2020 21:00:27 GMT
ETag: "31b-5a49c787f10c0"
Accept-Ranges: bytes
Content-Length: 795
Content-Type: text/html
--362db907-H--
Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:06-59.207.154.219.81"] [severity "CRITICAL"] [tag "wp_core"]
Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"]
Action: Intercepted (phase 2)
Stopwatch: 1788148788998178 59045 (- - -)
Stopwatch2: 1788148788998178 59045; combined=57671, p1=235, p2=56944, p3=0, p4=0, p5=363, sr=92, sw=129, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--362db907-Z--
--dd37854e-A--
[31/Aug/2026:07:05:50.012376 +0300] apT9ndmUuou1H8H2UKXC8AAAAMI 129.213.185.111 40292 127.0.0.1 7081
--dd37854e-B--
GET /wp-json/wp/v2/users/me HTTP/1.1
Host: ajutam.ro
X-Real-IP: 129.213.185.111
X-Accel-Internal: /internal-nginx-static-location
Authorization: Basic YWRtaW46YWRtaW4yMDEw
Accept: application/json
Accept-Language: en-US,en;q=0.9
Sec-Ch-Ua: "Not=A?Brand";v="99", "Google Chrome";v="151", "Chromium";v="151"
Sec-Ch-Ua-Mobile: ?0
Sec-Ch-Ua-Platform: "Windows"
User-Agent: 129.213.185.111
Accept-Encoding: gzip, deflate, br
--dd37854e-F--
HTTP/1.1 401 Unauthorized
X-Powered-By: PHP/7.3.33
X-Robots-Tag: noindex
Link:
; rel="https://api.w.org/"
X-Content-Type-Options: nosniff
Access-Control-Expose-Headers: X-WP-Total, X-WP-TotalPages, Link
Access-Control-Allow-Headers: Authorization, X-WP-Nonce, Content-Disposition, Content-MD5, Content-Type
Allow: GET
Vary: Origin
Transfer-Encoding: chunked
Content-Type: application/json; charset=UTF-8
--dd37854e-H--
Message: String match "wp-json/wp/v2/users" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "80"] [id "77140942"] [msg "IM360 WAF: Block WordPress 5.3 User Enumeration attempts||T:APACHE||MV:/wp-json/wp/v2/users/me||"] [severity "DEBUG"] [tag "service_i360custom"] [tag "wp_core"]
Message: Operator EQ matched 0 at REQUEST_COOKIES. [file "/etc/httpd/conf/modsecurity.d/rules/custom/007_i360_4_wordpress.conf"] [line "426"] [id "77316783"] [msg "IM360 WAF: Monitoring WordPress 5.3 User Enumeration attempts||T:APACHE||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "wp_core"] [tag "noshow"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/ajutam.ro/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788149149639599 372866 (- - -)
Stopwatch2: 1788149149639599 372866; combined=34092, p1=314, p2=33726, p3=0, p4=0, p5=51, sr=109, sw=1, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--dd37854e-Z--
--affea921-A--
[31/Aug/2026:07:06:43.457590 +0300] apT909mUuou1H8H2UKXC@AAAAMo 207.154.219.81 48528 127.0.0.1 7081
--affea921-B--
POST /wp-login.php HTTP/1.1
Host: ajutam.ro
X-Real-IP: 207.154.219.81
X-Accel-Internal: /internal-nginx-static-location
Content-Length: 111
Accept: */*
User-Agent: Mozilla/5.0
Content-Type: application/x-www-form-urlencoded
Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818
--affea921-F--
HTTP/1.1 403 Forbidden
Last-Modified: Fri, 01 May 2020 21:00:27 GMT
ETag: "31b-5a49c787f10c0"
Accept-Ranges: bytes
Content-Length: 795
Content-Type: text/html
--affea921-H--
Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:07-06.207.154.219.81"] [severity "CRITICAL"] [tag "wp_core"]
Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"]
Action: Intercepted (phase 2)
Stopwatch: 1788149203394192 63498 (- - -)
Stopwatch2: 1788149203394192 63498; combined=62081, p1=257, p2=61319, p3=0, p4=0, p5=376, sr=84, sw=129, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--affea921-Z--
--907f2133-A--
[31/Aug/2026:07:07:38.530316 +0300] apT@Cn7glkZrdsSdRApJgQAAAIg 138.197.193.77 36694 127.0.0.1 7081
--907f2133-B--
POST /wp-login.php HTTP/1.1
Host: ajutam.ro
X-Real-IP: 138.197.193.77
X-Accel-Internal: /internal-nginx-static-location
Content-Length: 105
Accept: */*
User-Agent: Mozilla/5.0
Content-Type: application/x-www-form-urlencoded
Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818
--907f2133-F--
HTTP/1.1 403 Forbidden
Last-Modified: Fri, 01 May 2020 21:00:27 GMT
ETag: "31b-5a49c787f10c0"
Accept-Ranges: bytes
Content-Length: 795
Content-Type: text/html
--907f2133-H--
Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:07-07.138.197.193.77"] [severity "CRITICAL"] [tag "wp_core"]
Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"]
Action: Intercepted (phase 2)
Stopwatch: 1788149258466383 63993 (- - -)
Stopwatch2: 1788149258466383 63993; combined=60481, p1=364, p2=59569, p3=0, p4=0, p5=408, sr=133, sw=140, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--907f2133-Z--
--c779ad40-A--
[31/Aug/2026:07:11:58.878858 +0300] apT-DtmUuou1H8H2UKXDFwAAANA 82.223.5.23 49652 127.0.0.1 7081
--c779ad40-B--
POST / HTTP/1.1
Host: www.ihelp.ro
X-Real-IP: 82.223.5.23
X-Accel-Internal: /internal-nginx-static-location
Content-Length: 0
User-agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
Accept-Encoding: gzip, deflate
Accept: */*
--c779ad40-F--
HTTP/1.1 403 Forbidden
X-Powered-By: PHP/8.1.34
X-DEBUGKIT-ID: a0c0409b-70cd-40b2-aecd-04c53a601f20
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--c779ad40-H--
Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788149518698777 180157 (- - -)
Stopwatch2: 1788149518698777 180157; combined=10573, p1=429, p2=9764, p3=0, p4=0, p5=379, sr=188, sw=1, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "DETECTION_ONLY"
--c779ad40-Z--
--6af12851-A--
[31/Aug/2026:07:11:59.696280 +0300] apT-D37glkZrdsSdRApJigAAAIQ 82.223.5.23 49654 127.0.0.1 7081
--6af12851-B--
POST /debug/default/view?panel=config HTTP/1.1
Host: www.ihelp.ro
X-Real-IP: 82.223.5.23
X-Accel-Internal: /internal-nginx-static-location
Content-Length: 0
User-agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
Accept-Encoding: gzip, deflate
Accept: */*
--6af12851-F--
HTTP/1.1 403 Forbidden
X-Powered-By: PHP/8.1.34
X-DEBUGKIT-ID: 01a10848-fbaa-40c9-92b3-5b6586c24bb4
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--6af12851-H--
Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G:panel=config& P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788149519555346 141024 (- - -)
Stopwatch2: 1788149519555346 141024; combined=10895, p1=2453, p2=8049, p3=0, p4=0, p5=393, sr=299, sw=0, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "DETECTION_ONLY"
--6af12851-Z--
--7b83c96d-A--
[31/Aug/2026:07:12:00.499373 +0300] apT-ENmUuou1H8H2UKXDGAAAAMI 82.223.5.23 49658 127.0.0.1 7081
--7b83c96d-B--
POST /tool/view/phpinfo.view.php HTTP/1.1
Host: www.ihelp.ro
X-Real-IP: 82.223.5.23
X-Accel-Internal: /internal-nginx-static-location
Content-Length: 0
User-agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
Accept-Encoding: gzip, deflate
Accept: */*
--7b83c96d-F--
HTTP/1.1 403 Forbidden
X-Powered-By: PHP/8.1.34
X-DEBUGKIT-ID: 5e88358a-3801-425b-9e9a-38ae1d3e8a01
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--7b83c96d-H--
Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788149520363845 135593 (- - -)
Stopwatch2: 1788149520363845 135593; combined=6798, p1=1770, p2=4695, p3=0, p4=0, p5=332, sr=190, sw=1, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "DETECTION_ONLY"
--7b83c96d-Z--
--ee575677-A--
[31/Aug/2026:07:12:01.216848 +0300] apT-EW7fDIutYTwcPOkaTQAAAFQ 82.223.5.23 49666 127.0.0.1 7081
--ee575677-B--
POST /wp-config.php-backup HTTP/1.1
Host: www.ihelp.ro
X-Real-IP: 82.223.5.23
X-Accel-Internal: /internal-nginx-static-location
Content-Length: 0
User-agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
Accept-Encoding: gzip, deflate
Accept: */*
--ee575677-F--
HTTP/1.1 403 Forbidden
X-Powered-By: PHP/8.1.34
X-DEBUGKIT-ID: 51f9f82c-e500-445a-b838-c47b0d10fc03
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--ee575677-H--
Message: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "www.ihelp.ro"] [uri "/wp-config.php-backup"] [unique_id "apT-EW7fDIutYTwcPOkaTQAAAFQ"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788149521089838 127074 (- - -)
Stopwatch2: 1788149521089838 127074; combined=7112, p1=534, p2=6190, p3=0, p4=0, p5=388, sr=153, sw=0, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "DETECTION_ONLY"
--ee575677-Z--
--49fadb5d-A--
[31/Aug/2026:07:13:31.176583 +0300] apT-a9mUuou1H8H2UKXDHgAAAMQ 207.154.219.81 40214 127.0.0.1 7081
--49fadb5d-B--
POST /wp-login.php HTTP/1.1
Host: ajutam.ro
X-Real-IP: 207.154.219.81
X-Accel-Internal: /internal-nginx-static-location
Content-Length: 111
Accept: */*
User-Agent: Mozilla/5.0
Content-Type: application/x-www-form-urlencoded
Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818
--49fadb5d-F--
HTTP/1.1 403 Forbidden
Last-Modified: Fri, 01 May 2020 21:00:27 GMT
ETag: "31b-5a49c787f10c0"
Accept-Ranges: bytes
Content-Length: 795
Content-Type: text/html
--49fadb5d-H--
Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:07-13.207.154.219.81"] [severity "CRITICAL"] [tag "wp_core"]
Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"]
Action: Intercepted (phase 2)
Stopwatch: 1788149611115485 61305 (- - -)
Stopwatch2: 1788149611115485 61305; combined=58220, p1=729, p2=56453, p3=0, p4=0, p5=784, sr=333, sw=254, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--49fadb5d-Z--
--31de385b-A--
[31/Aug/2026:07:15:45.271723 +0300] apT-8dmUuou1H8H2UKXDJQAAAMI 138.197.193.77 60782 127.0.0.1 7081
--31de385b-B--
POST /wp-login.php HTTP/1.1
Host: ajutam.ro
X-Real-IP: 138.197.193.77
X-Accel-Internal: /internal-nginx-static-location
Content-Length: 108
Accept: */*
User-Agent: Mozilla/5.0
Content-Type: application/x-www-form-urlencoded
Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818
--31de385b-F--
HTTP/1.1 403 Forbidden
Last-Modified: Fri, 01 May 2020 21:00:27 GMT
ETag: "31b-5a49c787f10c0"
Accept-Ranges: bytes
Content-Length: 795
Content-Type: text/html
--31de385b-H--
Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:07-15.138.197.193.77"] [severity "CRITICAL"] [tag "wp_core"]
Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"]
Action: Intercepted (phase 2)
Stopwatch: 1788149745202938 68862 (- - -)
Stopwatch2: 1788149745202938 68862; combined=60549, p1=1008, p2=58667, p3=0, p4=0, p5=610, sr=776, sw=264, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--31de385b-Z--
--586c565d-A--
[31/Aug/2026:07:20:16.338771 +0300] apUBANmUuou1H8H2UKXDcQAAANE 207.154.219.81 55996 127.0.0.1 7081
--586c565d-B--
POST /wp-login.php HTTP/1.1
Host: ajutam.ro
X-Real-IP: 207.154.219.81
X-Accel-Internal: /internal-nginx-static-location
Content-Length: 109
Accept: */*
User-Agent: Mozilla/5.0
Content-Type: application/x-www-form-urlencoded
Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818
--586c565d-F--
HTTP/1.1 403 Forbidden
Last-Modified: Fri, 01 May 2020 21:00:27 GMT
ETag: "31b-5a49c787f10c0"
Accept-Ranges: bytes
Content-Length: 795
Content-Type: text/html
--586c565d-H--
Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:07-20.207.154.219.81"] [severity "CRITICAL"] [tag "wp_core"]
Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"]
Action: Intercepted (phase 2)
Stopwatch: 1788150016276103 62740 (- - -)
Stopwatch2: 1788150016276103 62740; combined=61065, p1=364, p2=59933, p3=0, p4=0, p5=560, sr=168, sw=208, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--586c565d-Z--
--4670bd65-A--
[31/Aug/2026:07:23:50.532405 +0300] apUB1n7glkZrdsSdRApJqgAAAJM 138.197.193.77 42428 127.0.0.1 7081
--4670bd65-B--
POST /wp-login.php HTTP/1.1
Host: ajutam.ro
X-Real-IP: 138.197.193.77
X-Accel-Internal: /internal-nginx-static-location
Content-Length: 110
Accept: */*
User-Agent: Mozilla/5.0
Content-Type: application/x-www-form-urlencoded
Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818
--4670bd65-F--
HTTP/1.1 403 Forbidden
Last-Modified: Fri, 01 May 2020 21:00:27 GMT
ETag: "31b-5a49c787f10c0"
Accept-Ranges: bytes
Content-Length: 795
Content-Type: text/html
--4670bd65-H--
Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:07-23.138.197.193.77"] [severity "CRITICAL"] [tag "wp_core"]
Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"]
Action: Intercepted (phase 2)
Stopwatch: 1788150230467385 65095 (- - -)
Stopwatch2: 1788150230467385 65095; combined=62275, p1=555, p2=60732, p3=0, p4=0, p5=749, sr=269, sw=239, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--4670bd65-Z--
--cdd3540e-A--
[31/Aug/2026:07:27:14.068113 +0300] apUCotmUuou1H8H2UKXDigAAANE 207.154.219.81 42546 127.0.0.1 7081
--cdd3540e-B--
POST /wp-login.php HTTP/1.1
Host: ajutam.ro
X-Real-IP: 207.154.219.81
X-Accel-Internal: /internal-nginx-static-location
Content-Length: 109
Accept: */*
User-Agent: Mozilla/5.0
Content-Type: application/x-www-form-urlencoded
Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818
--cdd3540e-F--
HTTP/1.1 403 Forbidden
Last-Modified: Fri, 01 May 2020 21:00:27 GMT
ETag: "31b-5a49c787f10c0"
Accept-Ranges: bytes
Content-Length: 795
Content-Type: text/html
--cdd3540e-H--
Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:07-27.207.154.219.81"] [severity "CRITICAL"] [tag "wp_core"]
Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"]
Action: Intercepted (phase 2)
Stopwatch: 1788150434006496 61728 (- - -)
Stopwatch2: 1788150434006496 61728; combined=59381, p1=373, p2=58266, p3=0, p4=0, p5=581, sr=128, sw=161, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--cdd3540e-Z--
--6df58a70-A--
[31/Aug/2026:07:27:45.301112 +0300] apUCwCfaLSuAj0yzdueTCgAAABA 137.131.61.214 58094 127.0.0.1 7081
--6df58a70-B--
GET /xmlrpc.php HTTP/1.1
Host: ajutam.ro
X-Real-IP: 137.131.61.214
X-Accel-Internal: /internal-nginx-static-location
User-Agent: AteveSearchSourceUrlDiscovery/0.1 (+mailto:crawler@example.com)
Accept: */*
Accept-Encoding: gzip, deflate
--6df58a70-F--
HTTP/1.1 405 Method Not Allowed
X-Powered-By: PHP/7.3.33
Allow: POST
Transfer-Encoding: chunked
Content-Type: text/plain;charset=UTF-8
--6df58a70-E--
--6df58a70-H--
Message: Warning. String match "xmlrpc.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "290"] [id "77141064"] [msg "IM360 WAF: CMS Recon Bot detected||MVN:REQUEST_FILENAME||T:APACHE||MV:/xmlrpc.php||RM:GET"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "xmlrpc.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "290"] [id "77141064"] [msg "IM360 WAF: CMS Recon Bot detected||MVN:REQUEST_FILENAME||T:APACHE||MV:/xmlrpc.php||RM:GET"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "ajutam.ro"] [uri "/xmlrpc.php"] [unique_id "apUCwCfaLSuAj0yzdueTCgAAABA"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/ajutam.ro/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788150464940461 360768 (- - -)
Stopwatch2: 1788150464940461 360768; combined=10875, p1=3025, p2=7552, p3=205, p4=15, p5=78, sr=245, sw=0, l=0, gc=0
Response-Body-Transformed: Dechunked
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--6df58a70-Z--
--59d9c27f-A--
[31/Aug/2026:07:28:00.213224 +0300] apUCz37glkZrdsSdRApJtgAAAIs 137.131.61.214 44832 127.0.0.1 7081
--59d9c27f-B--
GET /xmlrpc.php?rsd= HTTP/1.1
Host: ajutam.ro
X-Real-IP: 137.131.61.214
X-Accel-Internal: /internal-nginx-static-location
User-Agent: AteveSearchSourceUrlDiscovery/0.1 (+mailto:crawler@example.com)
Accept: */*
Accept-Encoding: gzip, deflate
--59d9c27f-F--
HTTP/1.1 200 OK
X-Powered-By: PHP/7.3.33
Transfer-Encoding: chunked
Content-Type: text/xml; charset=UTF-8
--59d9c27f-E--
--59d9c27f-H--
Message: Warning. String match "xmlrpc.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "290"] [id "77141064"] [msg "IM360 WAF: CMS Recon Bot detected||MVN:REQUEST_FILENAME||T:APACHE||MV:/xmlrpc.php||RM:GET"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"]
Message: Warning. Operator GT matched 0 at ARGS. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "529"] [id "77317945"] [msg "IM360 WAF: Really Simple Discovery to xmlrpc||MVN:ARGS||MV:1||T:APACHE||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "xmlrpc.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "290"] [id "77141064"] [msg "IM360 WAF: CMS Recon Bot detected||MVN:REQUEST_FILENAME||T:APACHE||MV:/xmlrpc.php||RM:GET"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "ajutam.ro"] [uri "/xmlrpc.php"] [unique_id "apUCz37glkZrdsSdRApJtgAAAIs"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Operator GT matched 0 at ARGS. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "529"] [id "77317945"] [msg "IM360 WAF: Really Simple Discovery to xmlrpc||MVN:ARGS||MV:1||T:APACHE||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "ajutam.ro"] [uri "/xmlrpc.php"] [unique_id "apUCz37glkZrdsSdRApJtgAAAIs"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/ajutam.ro/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788150479938092 275243 (- - -)
Stopwatch2: 1788150479938092 275243; combined=7404, p1=667, p2=6374, p3=182, p4=75, p5=106, sr=231, sw=0, l=0, gc=0
Response-Body-Transformed: Dechunked
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--59d9c27f-Z--
--9af7f705-A--
[31/Aug/2026:07:30:10.735649 +0300] apUDUm7fDIutYTwcPOkabQAAAEQ 120.133.60.156 54968 127.0.0.1 7081
--9af7f705-B--
POST /wp-login.php HTTP/1.1
Host: axapres.ro
X-Real-IP: 120.133.60.156
X-Accel-Internal: /internal-nginx-static-location
Content-Length: 107
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Content-Type: application/x-www-form-urlencoded
Cookie: wordpress_test_cookie=WP+Cookie+check
Origin: https://axapres.ro
Referer: https://axapres.ro/wp-login.php
--9af7f705-F--
HTTP/1.1 403 Forbidden
Content-Length: 199
Content-Type: text/html; charset=iso-8859-1
--9af7f705-H--
Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:07-30.120.133.60.156"] [severity "CRITICAL"] [tag "wp_core"]
Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"]
Action: Intercepted (phase 2)
Apache-Handler: proxy:unix:/var/www/vhosts/system/axapres.ro/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788150610658910 76859 (- - -)
Stopwatch2: 1788150610658910 76859; combined=76077, p1=680, p2=59572, p3=0, p4=0, p5=8099, sr=377, sw=238, l=0, gc=7488
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--9af7f705-Z--
--d1310e0f-A--
[31/Aug/2026:07:31:19.726606 +0300] apUDl9mUuou1H8H2UKXD6AAAAM0 34.73.181.25 43486 127.0.0.1 7081
--d1310e0f-B--
GET /.git/config HTTP/1.1
Host: alexandervodka.com
X-Real-IP: 34.73.181.25
X-Forwarded-For: 172.26.241.90
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 172.26.241.90
Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D
Fastly-Client-Ip: 172.26.241.90
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 172.26.241.90
Upgrade-Insecure-Requests: 1
X-Client-Ip: 172.26.241.90
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 172.26.241.90
sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "Linux"
--d1310e0f-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/8.5.9
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--d1310e0f-H--
Message: Warning. Matched phrase "/.git/config" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.git/config||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"]
Message: Warning. Matched phrase "/.git/config" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.git/config||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"]
Message: Warning. String match "/.git/" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "656"] [id "77318034"] [msg "IM360 WAF: Blocked access to git folder||T:APACHE||MV:/.git/config||"] [severity "NOTICE"] [tag "service_i360custom"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "/.git/config" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.git/config||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/.git/config"] [unique_id "apUDl9mUuou1H8H2UKXD6AAAAM0"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "/.git/config" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.git/config||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/.git/config"] [unique_id "apUDl9mUuou1H8H2UKXD6AAAAM0"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.git/" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "656"] [id "77318034"] [msg "IM360 WAF: Blocked access to git folder||T:APACHE||MV:/.git/config||"] [severity "NOTICE"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/.git/config"] [unique_id "apUDl9mUuou1H8H2UKXD6AAAAM0"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788150679486485 240285 (- - -)
Stopwatch2: 1788150679486485 240285; combined=34445, p1=327, p2=34044, p3=0, p4=0, p5=74, sr=110, sw=0, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--d1310e0f-Z--
--9df72169-A--
[31/Aug/2026:07:31:19.880502 +0300] apUDl9mUuou1H8H2UKXD4wAAANQ 34.73.181.25 43410 127.0.0.1 7081
--9df72169-B--
GET /.git/HEAD HTTP/1.1
Host: alexandervodka.com
X-Real-IP: 34.73.181.25
X-Forwarded-For: 172.30.50.136
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 172.30.50.136
Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D
Fastly-Client-Ip: 172.30.50.136
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 172.30.50.136
Upgrade-Insecure-Requests: 1
X-Client-Ip: 172.30.50.136
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 172.30.50.136
sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "Linux"
--9df72169-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/8.5.9
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--9df72169-H--
Message: Warning. String match "/.git/" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "656"] [id "77318034"] [msg "IM360 WAF: Blocked access to git folder||T:APACHE||MV:/.git/head||"] [severity "NOTICE"] [tag "service_i360custom"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.git/" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "656"] [id "77318034"] [msg "IM360 WAF: Blocked access to git folder||T:APACHE||MV:/.git/head||"] [severity "NOTICE"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/.git/HEAD"] [unique_id "apUDl9mUuou1H8H2UKXD4wAAANQ"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788150679342114 538480 (- - -)
Stopwatch2: 1788150679342114 538480; combined=7236, p1=273, p2=6904, p3=0, p4=0, p5=59, sr=82, sw=0, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--9df72169-Z--
--39a0cb12-A--
[31/Aug/2026:07:31:19.900591 +0300] apUDl9mUuou1H8H2UKXD6QAAANU 34.73.181.25 43498 127.0.0.1 7081
--39a0cb12-B--
POST /graphql HTTP/1.1
Host: alexandervodka.com
X-Real-IP: 34.73.181.25
X-Accel-Internal: /internal-nginx-static-location
Content-Length: 86
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
Accept: */*
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Content-Type: application/json
Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D
Origin: https://alexandervodka.com
Referer: https://alexandervodka.com
Sec-Fetch-Dest: empty
Sec-Fetch-Mode: cors
Sec-Fetch-Site: same-origin
sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "Linux"
--39a0cb12-F--
HTTP/1.1 403 Forbidden
X-Powered-By: PHP/8.5.9
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--39a0cb12-H--
Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788150679527968 372725 (- - -)
Stopwatch2: 1788150679527968 372725; combined=5718, p1=274, p2=5168, p3=0, p4=0, p5=276, sr=93, sw=0, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--39a0cb12-Z--
--bc460e5a-A--
[31/Aug/2026:07:31:19.940423 +0300] apUDl37glkZrdsSdRApJ1gAAAJA 34.73.181.25 43552 127.0.0.1 7081
--bc460e5a-B--
GET /.git-credentials HTTP/1.1
Host: alexandervodka.com
X-Real-IP: 34.73.181.25
X-Forwarded-For: 172.17.3.147
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 172.17.3.147
Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D
Fastly-Client-Ip: 172.17.3.147
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 172.17.3.147
Upgrade-Insecure-Requests: 1
X-Client-Ip: 172.17.3.147
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 172.17.3.147
sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "Linux"
--bc460e5a-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/8.5.9
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--bc460e5a-H--
Message: Warning. Matched phrase "/.git-credentials" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.git-credentials||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"]
Message: Warning. Matched phrase "/.git-credentials" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.git-credentials||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "/.git-credentials" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.git-credentials||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/.git-credentials"] [unique_id "apUDl37glkZrdsSdRApJ1gAAAJA"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "/.git-credentials" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.git-credentials||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/.git-credentials"] [unique_id "apUDl37glkZrdsSdRApJ1gAAAJA"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788150679847592 92942 (- - -)
Stopwatch2: 1788150679847592 92942; combined=35051, p1=296, p2=34689, p3=0, p4=0, p5=65, sr=84, sw=1, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--bc460e5a-Z--
--3d6edc59-A--
[31/Aug/2026:07:31:20.167319 +0300] apUDmCfaLSuAj0yzdueTFgAAABY 34.73.181.25 43618 127.0.0.1 7081
--3d6edc59-B--
POST /api/graphql HTTP/1.1
Host: alexandervodka.com
X-Real-IP: 34.73.181.25
X-Accel-Internal: /internal-nginx-static-location
Content-Length: 86
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
Accept: */*
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Content-Type: application/json
Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D
Origin: https://alexandervodka.com
Referer: https://alexandervodka.com
Sec-Fetch-Dest: empty
Sec-Fetch-Mode: cors
Sec-Fetch-Site: same-origin
sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "Linux"
--3d6edc59-F--
HTTP/1.1 403 Forbidden
X-Powered-By: PHP/8.5.9
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--3d6edc59-H--
Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788150680087042 80380 (- - -)
Stopwatch2: 1788150680087042 80380; combined=7681, p1=227, p2=7169, p3=0, p4=0, p5=285, sr=80, sw=0, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--3d6edc59-Z--
--d5d10130-A--
[31/Aug/2026:07:31:20.283693 +0300] apUDl27fDIutYTwcPOkacgAAAFM 34.73.181.25 43578 127.0.0.1 7081
--d5d10130-B--
GET /.gitconfig HTTP/1.1
Host: alexandervodka.com
X-Real-IP: 34.73.181.25
X-Forwarded-For: 192.168.206.250
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 192.168.206.250
Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D
Fastly-Client-Ip: 192.168.206.250
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 192.168.206.250
Upgrade-Insecure-Requests: 1
X-Client-Ip: 192.168.206.250
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 192.168.206.250
sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "Linux"
--d5d10130-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/8.5.9
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--d5d10130-H--
Message: Warning. Matched phrase "/.gitconfig" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.gitconfig||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"]
Message: Warning. Matched phrase "/.gitconfig" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.gitconfig||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "/.gitconfig" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.gitconfig||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/.gitconfig"] [unique_id "apUDl27fDIutYTwcPOkacgAAAFM"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "/.gitconfig" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.gitconfig||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/.gitconfig"] [unique_id "apUDl27fDIutYTwcPOkacgAAAFM"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788150679986778 297110 (- - -)
Stopwatch2: 1788150679986778 297110; combined=62272, p1=261, p2=61900, p3=0, p4=0, p5=110, sr=81, sw=1, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--d5d10130-Z--
--3b1af431-A--
[31/Aug/2026:07:31:20.285993 +0300] apUDmCfaLSuAj0yzdueTFQAAAAw 34.73.181.25 43608 127.0.0.1 7081
--3b1af431-B--
GET /.env HTTP/1.1
Host: alexandervodka.com
X-Real-IP: 34.73.181.25
X-Forwarded-For: 172.29.251.105
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 172.29.251.105
Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D
Fastly-Client-Ip: 172.29.251.105
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 172.29.251.105
Upgrade-Insecure-Requests: 1
X-Client-Ip: 172.29.251.105
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 172.29.251.105
sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "Linux"
--3b1af431-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/8.5.9
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--3b1af431-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/.env"] [unique_id "apUDmCfaLSuAj0yzdueTFQAAAAw"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788150680082519 203560 (- - -)
Stopwatch2: 1788150680082519 203560; combined=4950, p1=293, p2=4605, p3=0, p4=0, p5=51, sr=99, sw=1, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--3b1af431-Z--
--62e26f73-A--
[31/Aug/2026:07:31:20.566942 +0300] apUDmNmUuou1H8H2UKXD8gAAANc 34.73.181.25 43640 127.0.0.1 7081
--62e26f73-B--
GET /.env.local HTTP/1.1
Host: alexandervodka.com
X-Real-IP: 34.73.181.25
X-Forwarded-For: 100.107.80.230
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 100.107.80.230
Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D
Fastly-Client-Ip: 100.107.80.230
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 100.107.80.230
Upgrade-Insecure-Requests: 1
X-Client-Ip: 100.107.80.230
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 100.107.80.230
sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "Linux"
--62e26f73-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/8.5.9
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--62e26f73-H--
Message: Warning. Matched phrase ".local" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.env.local||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"]
Message: Warning. Matched phrase ".local" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.env.local||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".local" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.env.local||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/.env.local"] [unique_id "apUDmNmUuou1H8H2UKXD8gAAANc"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".local" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.env.local||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/.env.local"] [unique_id "apUDmNmUuou1H8H2UKXD8gAAANc"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788150680294591 272442 (- - -)
Stopwatch2: 1788150680294591 272442; combined=34640, p1=265, p2=34309, p3=0, p4=0, p5=65, sr=96, sw=1, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--62e26f73-Z--
--c37e6c11-A--
[31/Aug/2026:07:31:20.580933 +0300] apUDmNmUuou1H8H2UKXD9gAAANg 34.73.181.25 43710 127.0.0.1 7081
--c37e6c11-B--
GET /api/.env HTTP/1.1
Host: alexandervodka.com
X-Real-IP: 34.73.181.25
X-Forwarded-For: 172.25.84.73
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 172.25.84.73
Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D
Fastly-Client-Ip: 172.25.84.73
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 172.25.84.73
Upgrade-Insecure-Requests: 1
X-Client-Ip: 172.25.84.73
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 172.25.84.73
sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "Linux"
--c37e6c11-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/8.5.9
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--c37e6c11-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/api/.env"] [unique_id "apUDmNmUuou1H8H2UKXD9gAAANg"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788150680448950 132083 (- - -)
Stopwatch2: 1788150680448950 132083; combined=4583, p1=245, p2=4284, p3=0, p4=0, p5=54, sr=82, sw=0, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--c37e6c11-Z--
--be2ae37c-A--
[31/Aug/2026:07:31:20.663837 +0300] apUDmH7glkZrdsSdRApJ1wAAAIE 34.73.181.25 43656 127.0.0.1 7081
--be2ae37c-B--
POST /v1/graphql HTTP/1.1
Host: alexandervodka.com
X-Real-IP: 34.73.181.25
X-Accel-Internal: /internal-nginx-static-location
Content-Length: 86
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
Accept: */*
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Content-Type: application/json
Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D
Origin: https://alexandervodka.com
Referer: https://alexandervodka.com
Sec-Fetch-Dest: empty
Sec-Fetch-Mode: cors
Sec-Fetch-Site: same-origin
sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "Linux"
--be2ae37c-F--
HTTP/1.1 403 Forbidden
X-Powered-By: PHP/8.5.9
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--be2ae37c-H--
Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788150680317225 346693 (- - -)
Stopwatch2: 1788150680317225 346693; combined=5583, p1=283, p2=4931, p3=0, p4=0, p5=369, sr=117, sw=0, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--be2ae37c-Z--
--c6afca47-A--
[31/Aug/2026:07:31:20.691510 +0300] apUDmNmUuou1H8H2UKXD@AAAAMY 34.73.181.25 43734 127.0.0.1 7081
--c6afca47-B--
GET /admin/.env HTTP/1.1
Host: alexandervodka.com
X-Real-IP: 34.73.181.25
X-Forwarded-For: 172.27.43.39
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 172.27.43.39
Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D
Fastly-Client-Ip: 172.27.43.39
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 172.27.43.39
Upgrade-Insecure-Requests: 1
X-Client-Ip: 172.27.43.39
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 172.27.43.39
sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "Linux"
--c6afca47-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/8.5.9
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--c6afca47-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/admin/.env"] [unique_id "apUDmNmUuou1H8H2UKXD@AAAAMY"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788150680477040 214604 (- - -)
Stopwatch2: 1788150680477040 214604; combined=5282, p1=243, p2=4980, p3=0, p4=0, p5=59, sr=81, sw=0, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--c6afca47-Z--
--5acf943e-A--
[31/Aug/2026:07:31:20.886961 +0300] apUDmCfaLSuAj0yzdueTFwAAABc 34.73.181.25 43770 127.0.0.1 7081
--5acf943e-B--
GET /config/.env HTTP/1.1
Host: alexandervodka.com
X-Real-IP: 34.73.181.25
X-Forwarded-For: 100.81.34.110
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 100.81.34.110
Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D
Fastly-Client-Ip: 100.81.34.110
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 100.81.34.110
Upgrade-Insecure-Requests: 1
X-Client-Ip: 100.81.34.110
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 100.81.34.110
sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "Linux"
--5acf943e-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/8.5.9
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--5acf943e-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/config/.env"] [unique_id "apUDmCfaLSuAj0yzdueTFwAAABc"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788150680766132 120919 (- - -)
Stopwatch2: 1788150680766132 120919; combined=5858, p1=275, p2=5526, p3=0, p4=0, p5=57, sr=94, sw=0, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--5acf943e-Z--
--b77eec6b-A--
[31/Aug/2026:07:31:20.940064 +0300] apUDmNmUuou1H8H2UKXD@gAAANQ 34.73.181.25 43756 127.0.0.1 7081
--b77eec6b-B--
GET /backend/.env HTTP/1.1
Host: alexandervodka.com
X-Real-IP: 34.73.181.25
X-Forwarded-For: 100.107.79.54
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 100.107.79.54
Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D
Fastly-Client-Ip: 100.107.79.54
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 100.107.79.54
Upgrade-Insecure-Requests: 1
X-Client-Ip: 100.107.79.54
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 100.107.79.54
sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "Linux"
--b77eec6b-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/8.5.9
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--b77eec6b-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/backend/.env"] [unique_id "apUDmNmUuou1H8H2UKXD@gAAANQ"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788150680742148 198003 (- - -)
Stopwatch2: 1788150680742148 198003; combined=6098, p1=325, p2=5718, p3=0, p4=0, p5=54, sr=110, sw=1, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--b77eec6b-Z--
--8fe3bb14-A--
[31/Aug/2026:07:31:21.537531 +0300] apUDmdmUuou1H8H2UKXEAQAAAMc 34.73.181.25 43902 127.0.0.1 7081
--8fe3bb14-B--
GET /.github/.env HTTP/1.1
Host: alexandervodka.com
X-Real-IP: 34.73.181.25
X-Forwarded-For: 10.188.56.58
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 10.188.56.58
Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D
Fastly-Client-Ip: 10.188.56.58
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 10.188.56.58
Upgrade-Insecure-Requests: 1
X-Client-Ip: 10.188.56.58
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 10.188.56.58
sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "Linux"
--8fe3bb14-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/8.5.9
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--8fe3bb14-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/.github/.env"] [unique_id "apUDmdmUuou1H8H2UKXEAQAAAMc"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788150681474845 62813 (- - -)
Stopwatch2: 1788150681474845 62813; combined=4918, p1=284, p2=4577, p3=0, p4=0, p5=56, sr=108, sw=1, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--8fe3bb14-Z--
--37a51749-A--
[31/Aug/2026:07:31:21.684163 +0300] apUDmdmUuou1H8H2UKXEAgAAAMk 34.73.181.25 43910 127.0.0.1 7081
--37a51749-B--
GET /.npmrc HTTP/1.1
Host: alexandervodka.com
X-Real-IP: 34.73.181.25
X-Forwarded-For: 10.109.48.131
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 10.109.48.131
Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D
Fastly-Client-Ip: 10.109.48.131
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 10.109.48.131
Upgrade-Insecure-Requests: 1
X-Client-Ip: 10.109.48.131
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 10.109.48.131
sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "Linux"
--37a51749-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/8.5.9
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--37a51749-H--
Message: Warning. Matched phrase ".npmrc" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.npmrc||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"]
Message: Warning. Matched phrase ".npmrc" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.npmrc||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".npmrc" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.npmrc||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/.npmrc"] [unique_id "apUDmdmUuou1H8H2UKXEAgAAAMk"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".npmrc" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.npmrc||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/.npmrc"] [unique_id "apUDmdmUuou1H8H2UKXEAgAAAMk"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788150681583184 101176 (- - -)
Stopwatch2: 1788150681583184 101176; combined=33207, p1=219, p2=32890, p3=0, p4=0, p5=97, sr=69, sw=1, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--37a51749-Z--
--2f474539-A--
[31/Aug/2026:07:31:21.822768 +0300] apUDmdmUuou1H8H2UKXEBgAAANM 34.73.181.25 43962 127.0.0.1 7081
--2f474539-B--
GET /.svn/entries HTTP/1.1
Host: alexandervodka.com
X-Real-IP: 34.73.181.25
X-Forwarded-For: 100.111.65.1
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 100.111.65.1
Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D
Fastly-Client-Ip: 100.111.65.1
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 100.111.65.1
Upgrade-Insecure-Requests: 1
X-Client-Ip: 100.111.65.1
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 100.111.65.1
sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "Linux"
--2f474539-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/8.5.9
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--2f474539-H--
Message: Warning. Matched phrase ".svn/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.svn/entries||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"]
Message: Warning. Matched phrase ".svn/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.svn/entries||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".svn/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.svn/entries||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/.svn/entries"] [unique_id "apUDmdmUuou1H8H2UKXEBgAAANM"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".svn/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.svn/entries||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/.svn/entries"] [unique_id "apUDmdmUuou1H8H2UKXEBgAAANM"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788150681721834 101024 (- - -)
Stopwatch2: 1788150681721834 101024; combined=32372, p1=241, p2=32066, p3=0, p4=0, p5=64, sr=80, sw=1, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--2f474539-Z--
--7abb6f7c-A--
[31/Aug/2026:07:31:23.098967 +0300] apUDmtmUuou1H8H2UKXEGQAAAM8 34.73.181.25 44266 127.0.0.1 7081
--7abb6f7c-B--
GET /.idea/WebServers.xml HTTP/1.1
Host: alexandervodka.com
X-Real-IP: 34.73.181.25
X-Forwarded-For: 172.28.235.57
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 172.28.235.57
Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D
Fastly-Client-Ip: 172.28.235.57
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 172.28.235.57
Upgrade-Insecure-Requests: 1
X-Client-Ip: 172.28.235.57
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 172.28.235.57
sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "Linux"
--7abb6f7c-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/8.5.9
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--7abb6f7c-H--
Message: Warning. Matched phrase ".idea/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.idea/webservers.xml||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"]
Message: Warning. Matched phrase ".idea/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.idea/webservers.xml||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".idea/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.idea/webservers.xml||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/.idea/WebServers.xml"] [unique_id "apUDmtmUuou1H8H2UKXEGQAAAM8"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".idea/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.idea/webservers.xml||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/.idea/WebServers.xml"] [unique_id "apUDmtmUuou1H8H2UKXEGQAAAM8"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788150682931115 167954 (- - -)
Stopwatch2: 1788150682931115 167954; combined=36322, p1=255, p2=36003, p3=0, p4=0, p5=64, sr=77, sw=0, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--7abb6f7c-Z--
--c61c9922-A--
[31/Aug/2026:07:31:23.119130 +0300] apUDmn7glkZrdsSdRApJ5QAAAIw 34.73.181.25 44294 127.0.0.1 7081
--c61c9922-B--
GET /.ssh/id_rsa HTTP/1.1
Host: alexandervodka.com
X-Real-IP: 34.73.181.25
X-Forwarded-For: 172.23.126.205
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 172.23.126.205
Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D
Fastly-Client-Ip: 172.23.126.205
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 172.23.126.205
Upgrade-Insecure-Requests: 1
X-Client-Ip: 172.23.126.205
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 172.23.126.205
sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "Linux"
--c61c9922-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/8.5.9
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--c61c9922-H--
Message: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.ssh/id_rsa||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"]
Message: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.ssh/id_rsa||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.ssh/id_rsa||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/.ssh/id_rsa"] [unique_id "apUDmn7glkZrdsSdRApJ5QAAAIw"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.ssh/id_rsa||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/.ssh/id_rsa"] [unique_id "apUDmn7glkZrdsSdRApJ5QAAAIw"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788150682986604 132625 (- - -)
Stopwatch2: 1788150682986604 132625; combined=37692, p1=252, p2=37378, p3=0, p4=0, p5=62, sr=91, sw=0, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--c61c9922-Z--
--843ff27b-A--
[31/Aug/2026:07:31:23.265264 +0300] apUDm9mUuou1H8H2UKXEHQAAAM4 34.73.181.25 44320 127.0.0.1 7081
--843ff27b-B--
GET /.ssh/id_ecdsa HTTP/1.1
Host: alexandervodka.com
X-Real-IP: 34.73.181.25
X-Forwarded-For: 192.168.134.198
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 192.168.134.198
Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D
Fastly-Client-Ip: 192.168.134.198
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 192.168.134.198
Upgrade-Insecure-Requests: 1
X-Client-Ip: 192.168.134.198
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 192.168.134.198
sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "Linux"
--843ff27b-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/8.5.9
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--843ff27b-H--
Message: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.ssh/id_ecdsa||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"]
Message: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.ssh/id_ecdsa||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.ssh/id_ecdsa||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/.ssh/id_ecdsa"] [unique_id "apUDm9mUuou1H8H2UKXEHQAAAM4"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.ssh/id_ecdsa||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/.ssh/id_ecdsa"] [unique_id "apUDm9mUuou1H8H2UKXEHQAAAM4"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788150683136393 128960 (- - -)
Stopwatch2: 1788150683136393 128960; combined=49718, p1=312, p2=49342, p3=0, p4=0, p5=63, sr=102, sw=1, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--843ff27b-Z--
--9019cc1e-A--
[31/Aug/2026:07:31:23.393975 +0300] apUDm9mUuou1H8H2UKXEIAAAANM 34.73.181.25 44342 127.0.0.1 7081
--9019cc1e-B--
GET /.ssh/config HTTP/1.1
Host: alexandervodka.com
X-Real-IP: 34.73.181.25
X-Forwarded-For: 172.17.16.18
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 172.17.16.18
Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D
Fastly-Client-Ip: 172.17.16.18
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 172.17.16.18
Upgrade-Insecure-Requests: 1
X-Client-Ip: 172.17.16.18
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 172.17.16.18
sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "Linux"
--9019cc1e-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/8.5.9
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--9019cc1e-H--
Message: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.ssh/config||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"]
Message: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.ssh/config||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.ssh/config||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/.ssh/config"] [unique_id "apUDm9mUuou1H8H2UKXEIAAAANM"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.ssh/config||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/.ssh/config"] [unique_id "apUDm9mUuou1H8H2UKXEIAAAANM"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788150683303115 90971 (- - -)
Stopwatch2: 1788150683303115 90971; combined=34006, p1=245, p2=33694, p3=0, p4=0, p5=66, sr=80, sw=1, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--9019cc1e-Z--
--0a526a5a-A--
[31/Aug/2026:07:31:23.410967 +0300] apUDm9mUuou1H8H2UKXEHAAAAMQ 34.73.181.25 44308 127.0.0.1 7081
--0a526a5a-B--
GET /.ssh/id_ed25519 HTTP/1.1
Host: alexandervodka.com
X-Real-IP: 34.73.181.25
X-Forwarded-For: 10.232.245.241
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 10.232.245.241
Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D
Fastly-Client-Ip: 10.232.245.241
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 10.232.245.241
Upgrade-Insecure-Requests: 1
X-Client-Ip: 10.232.245.241
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 10.232.245.241
sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "Linux"
--0a526a5a-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/8.5.9
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--0a526a5a-H--
Message: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.ssh/id_ed25519||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"]
Message: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.ssh/id_ed25519||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.ssh/id_ed25519||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/.ssh/id_ed25519"] [unique_id "apUDm9mUuou1H8H2UKXEHAAAAMQ"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.ssh/id_ed25519||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/.ssh/id_ed25519"] [unique_id "apUDm9mUuou1H8H2UKXEHAAAAMQ"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788150683133588 277469 (- - -)
Stopwatch2: 1788150683133588 277469; combined=70153, p1=258, p2=69829, p3=0, p4=0, p5=65, sr=91, sw=1, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--0a526a5a-Z--
--53a1801d-A--
[31/Aug/2026:07:31:23.429221 +0300] apUDm9mUuou1H8H2UKXEGwAAAMM 34.73.181.25 44310 127.0.0.1 7081
--53a1801d-B--
GET /.ssh/id_dsa HTTP/1.1
Host: alexandervodka.com
X-Real-IP: 34.73.181.25
X-Forwarded-For: 10.51.159.196
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 10.51.159.196
Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D
Fastly-Client-Ip: 10.51.159.196
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 10.51.159.196
Upgrade-Insecure-Requests: 1
X-Client-Ip: 10.51.159.196
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 10.51.159.196
sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "Linux"
--53a1801d-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/8.5.9
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--53a1801d-H--
Message: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.ssh/id_dsa||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"]
Message: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.ssh/id_dsa||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.ssh/id_dsa||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/.ssh/id_dsa"] [unique_id "apUDm9mUuou1H8H2UKXEGwAAAMM"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.ssh/id_dsa||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/.ssh/id_dsa"] [unique_id "apUDm9mUuou1H8H2UKXEGwAAAMM"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788150683128580 300767 (- - -)
Stopwatch2: 1788150683128580 300767; combined=73399, p1=280, p2=73053, p3=0, p4=0, p5=66, sr=82, sw=0, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--53a1801d-Z--
--c8a0073f-A--
[31/Aug/2026:07:31:23.430890 +0300] apUDm9mUuou1H8H2UKXEHwAAANU 34.73.181.25 44332 127.0.0.1 7081
--c8a0073f-B--
GET /.ssh/known_hosts HTTP/1.1
Host: alexandervodka.com
X-Real-IP: 34.73.181.25
X-Forwarded-For: 172.16.159.63
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 172.16.159.63
Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D
Fastly-Client-Ip: 172.16.159.63
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 172.16.159.63
Upgrade-Insecure-Requests: 1
X-Client-Ip: 172.16.159.63
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 172.16.159.63
sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "Linux"
--c8a0073f-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/8.5.9
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--c8a0073f-H--
Message: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.ssh/known_hosts||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"]
Message: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.ssh/known_hosts||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.ssh/known_hosts||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/.ssh/known_hosts"] [unique_id "apUDm9mUuou1H8H2UKXEHwAAANU"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.ssh/known_hosts||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/.ssh/known_hosts"] [unique_id "apUDm9mUuou1H8H2UKXEHwAAANU"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788150683280354 150631 (- - -)
Stopwatch2: 1788150683280354 150631; combined=34147, p1=251, p2=33847, p3=0, p4=0, p5=49, sr=80, sw=0, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--c8a0073f-Z--
--0f607531-A--
[31/Aug/2026:07:31:23.455410 +0300] apUDm9mUuou1H8H2UKXEHgAAANQ 34.73.181.25 44324 127.0.0.1 7081
--0f607531-B--
GET /.ssh/authorized_keys HTTP/1.1
Host: alexandervodka.com
X-Real-IP: 34.73.181.25
X-Forwarded-For: 10.248.73.111
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 10.248.73.111
Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D
Fastly-Client-Ip: 10.248.73.111
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 10.248.73.111
Upgrade-Insecure-Requests: 1
X-Client-Ip: 10.248.73.111
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 10.248.73.111
sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "Linux"
--0f607531-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/8.5.9
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--0f607531-H--
Message: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.ssh/authorized_keys||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"]
Message: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.ssh/authorized_keys||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.ssh/authorized_keys||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/.ssh/authorized_keys"] [unique_id "apUDm9mUuou1H8H2UKXEHgAAANQ"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.ssh/authorized_keys||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/.ssh/authorized_keys"] [unique_id "apUDm9mUuou1H8H2UKXEHgAAANQ"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788150683247032 208468 (- - -)
Stopwatch2: 1788150683247032 208468; combined=31760, p1=247, p2=31446, p3=0, p4=0, p5=67, sr=81, sw=0, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--0f607531-Z--
--d236314e-A--
[31/Aug/2026:07:31:23.525262 +0300] apUDm9mUuou1H8H2UKXEIQAAANc 34.73.181.25 44356 127.0.0.1 7081
--d236314e-B--
GET /id_rsa HTTP/1.1
Host: alexandervodka.com
X-Real-IP: 34.73.181.25
X-Forwarded-For: 172.22.52.138
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 172.22.52.138
Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D
Fastly-Client-Ip: 172.22.52.138
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 172.22.52.138
Upgrade-Insecure-Requests: 1
X-Client-Ip: 172.22.52.138
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 172.22.52.138
sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "Linux"
--d236314e-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/8.5.9
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--d236314e-H--
Message: Warning. Matched phrase "id_rsa" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/id_rsa||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"]
Message: Warning. Matched phrase "id_rsa" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/id_rsa||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "id_rsa" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/id_rsa||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/id_rsa"] [unique_id "apUDm9mUuou1H8H2UKXEIQAAANc"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "id_rsa" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/id_rsa||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/id_rsa"] [unique_id "apUDm9mUuou1H8H2UKXEIQAAANc"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788150683431503 93899 (- - -)
Stopwatch2: 1788150683431503 93899; combined=32509, p1=469, p2=31974, p3=0, p4=0, p5=65, sr=290, sw=1, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--d236314e-Z--
--f2ace91b-A--
[31/Aug/2026:07:31:23.891893 +0300] apUDm9mUuou1H8H2UKXEJgAAAM0 34.73.181.25 44372 127.0.0.1 7081
--f2ace91b-B--
GET /id_dsa HTTP/1.1
Host: alexandervodka.com
X-Real-IP: 34.73.181.25
X-Forwarded-For: 100.81.93.248
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 100.81.93.248
Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D
Fastly-Client-Ip: 100.81.93.248
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 100.81.93.248
Upgrade-Insecure-Requests: 1
X-Client-Ip: 100.81.93.248
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 100.81.93.248
sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "Linux"
--f2ace91b-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/8.5.9
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--f2ace91b-H--
Message: Warning. Matched phrase "id_dsa" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/id_dsa||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"]
Message: Warning. Matched phrase "id_dsa" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/id_dsa||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "id_dsa" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/id_dsa||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/id_dsa"] [unique_id "apUDm9mUuou1H8H2UKXEJgAAAM0"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "id_dsa" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/id_dsa||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/id_dsa"] [unique_id "apUDm9mUuou1H8H2UKXEJgAAAM0"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788150683627203 264780 (- - -)
Stopwatch2: 1788150683627203 264780; combined=32471, p1=250, p2=32155, p3=0, p4=0, p5=65, sr=93, sw=1, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--f2ace91b-Z--
--2c228209-A--
[31/Aug/2026:07:31:24.453300 +0300] apUDnNmUuou1H8H2UKXELAAAAMg 34.73.181.25 44496 127.0.0.1 7081
--2c228209-B--
GET /@fs/app/.env?raw?? HTTP/1.1
Host: alexandervodka.com
X-Real-IP: 34.73.181.25
X-Forwarded-For: 100.66.184.74
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 100.66.184.74
Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D
Fastly-Client-Ip: 100.66.184.74
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 100.66.184.74
Upgrade-Insecure-Requests: 1
X-Client-Ip: 100.66.184.74
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 100.66.184.74
sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "Linux"
--2c228209-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/8.5.9
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--2c228209-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/@fs/app/.env"] [unique_id "apUDnNmUuou1H8H2UKXELAAAAMg"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788150684386859 66543 (- - -)
Stopwatch2: 1788150684386859 66543; combined=4352, p1=313, p2=3980, p3=0, p4=0, p5=59, sr=143, sw=0, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--2c228209-Z--
--aad82529-A--
[31/Aug/2026:07:31:24.520025 +0300] apUDnNmUuou1H8H2UKXELgAAAMc 34.73.181.25 44536 127.0.0.1 7081
--aad82529-B--
GET /@fs/..%252f..%252f..%252f..%252f..%252fproc/self/environ?raw?? HTTP/1.1
Host: alexandervodka.com
X-Real-IP: 34.73.181.25
X-Forwarded-For: 172.20.201.113
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 172.20.201.113
Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D
Fastly-Client-Ip: 172.20.201.113
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 172.20.201.113
Upgrade-Insecure-Requests: 1
X-Client-Ip: 172.20.201.113
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 172.20.201.113
sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "Linux"
--aad82529-F--
HTTP/1.1 403 Forbidden
Content-Length: 199
Content-Type: text/html; charset=iso-8859-1
--aad82529-H--
Message: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at MATCHED_VAR. [file "/etc/httpd/conf/modsecurity.d/rules/custom/012_i360_1_generic.conf"] [line "22"] [id "77140166"] [msg "IM360 WAF: Blocking directory traversal attempt||MVN:MATCHED_VAR||MV:/proc/self/environ?raw??||T:APACHE||"] [severity "CRITICAL"] [tag "service_gen"]
Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G:raw??=& P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at MATCHED_VAR. [file "/etc/httpd/conf/modsecurity.d/rules/custom/012_i360_1_generic.conf"] [line "22"] [id "77140166"] [msg "IM360 WAF: Blocking directory traversal attempt||MVN:MATCHED_VAR||MV:/proc/self/environ?raw??||T:APACHE||"] [severity "CRITICAL"] [tag "service_gen"] [hostname "alexandervodka.com"] [uri "/@fs/..%2f..%2f..%2f..%2f..%2fproc/self/environ"] [unique_id "apUDnNmUuou1H8H2UKXELgAAAMc"]
Action: Intercepted (phase 2)
Stopwatch: 1788150684514720 5388 (- - -)
Stopwatch2: 1788150684514720 5388; combined=3892, p1=260, p2=3304, p3=0, p4=0, p5=328, sr=89, sw=0, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--aad82529-Z--
--7453a543-A--
[31/Aug/2026:07:31:24.539349 +0300] apUDnNmUuou1H8H2UKXELwAAAMA 34.73.181.25 44540 127.0.0.1 7081
--7453a543-B--
GET /@fs/..%252f..%252f..%252f..%252f..%252froot/.env?raw?? HTTP/1.1
Host: alexandervodka.com
X-Real-IP: 34.73.181.25
X-Forwarded-For: 172.16.149.242
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 172.16.149.242
Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D
Fastly-Client-Ip: 172.16.149.242
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 172.16.149.242
Upgrade-Insecure-Requests: 1
X-Client-Ip: 172.16.149.242
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 172.16.149.242
sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "Linux"
--7453a543-F--
HTTP/1.1 404 Not Found
Content-Length: 196
Content-Type: text/html; charset=iso-8859-1
--7453a543-E--
--7453a543-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/@fs/..%2f..%2f..%2f..%2f..%2froot/.env"] [unique_id "apUDnNmUuou1H8H2UKXELwAAAMA"]
Stopwatch: 1788150684533865 5587 (- - -)
Stopwatch2: 1788150684533865 5587; combined=4146, p1=267, p2=3759, p3=73, p4=7, p5=40, sr=89, sw=0, l=0, gc=0
Response-Body-Transformed: Dechunked
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--7453a543-Z--
--c31cca52-A--
[31/Aug/2026:07:31:24.549999 +0300] apUDnCfaLSuAj0yzdueTHQAAABI 34.73.181.25 44510 127.0.0.1 7081
--c31cca52-B--
GET /@fs/../.env?raw?? HTTP/1.1
Host: alexandervodka.com
X-Real-IP: 34.73.181.25
X-Forwarded-For: 192.168.148.47
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 192.168.148.47
Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D
Fastly-Client-Ip: 192.168.148.47
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 192.168.148.47
Upgrade-Insecure-Requests: 1
X-Client-Ip: 192.168.148.47
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 192.168.148.47
sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "Linux"
--c31cca52-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/8.5.9
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--c31cca52-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/.env"] [unique_id "apUDnCfaLSuAj0yzdueTHQAAABI"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788150684460091 90012 (- - -)
Stopwatch2: 1788150684460091 90012; combined=5194, p1=332, p2=4803, p3=0, p4=0, p5=58, sr=125, sw=1, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--c31cca52-Z--
--624f3b11-A--
[31/Aug/2026:07:31:24.561052 +0300] apUDnNmUuou1H8H2UKXELQAAANg 34.73.181.25 44520 127.0.0.1 7081
--624f3b11-B--
GET /@fs/src/.env?raw?? HTTP/1.1
Host: alexandervodka.com
X-Real-IP: 34.73.181.25
X-Forwarded-For: 10.44.215.84
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 10.44.215.84
Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D
Fastly-Client-Ip: 10.44.215.84
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 10.44.215.84
Upgrade-Insecure-Requests: 1
X-Client-Ip: 10.44.215.84
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 10.44.215.84
sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "Linux"
--624f3b11-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/8.5.9
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--624f3b11-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/@fs/src/.env"] [unique_id "apUDnNmUuou1H8H2UKXELQAAANg"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788150684476381 84771 (- - -)
Stopwatch2: 1788150684476381 84771; combined=5060, p1=380, p2=4623, p3=0, p4=0, p5=57, sr=161, sw=0, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--624f3b11-Z--
--1ea68b55-A--
[31/Aug/2026:07:31:24.623635 +0300] apUDnCfaLSuAj0yzdueTHgAAABI 34.73.181.25 44550 127.0.0.1 7081
--1ea68b55-B--
GET /_nuxt/../.env HTTP/1.1
Host: alexandervodka.com
X-Real-IP: 34.73.181.25
X-Forwarded-For: 192.168.117.76
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 192.168.117.76
Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D
Fastly-Client-Ip: 192.168.117.76
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 192.168.117.76
Upgrade-Insecure-Requests: 1
X-Client-Ip: 192.168.117.76
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 192.168.117.76
sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "Linux"
--1ea68b55-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/8.5.9
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--1ea68b55-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/.env"] [unique_id "apUDnCfaLSuAj0yzdueTHgAAABI"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788150684559832 63981 (- - -)
Stopwatch2: 1788150684559832 63981; combined=5809, p1=272, p2=5478, p3=0, p4=0, p5=59, sr=91, sw=0, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--1ea68b55-Z--
--8710ab77-A--
[31/Aug/2026:07:31:24.719222 +0300] apUDnNmUuou1H8H2UKXEMAAAAMY 34.73.181.25 44560 127.0.0.1 7081
--8710ab77-B--
GET /static../.env HTTP/1.1
Host: alexandervodka.com
X-Real-IP: 34.73.181.25
X-Forwarded-For: 172.23.34.44
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 172.23.34.44
Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D
Fastly-Client-Ip: 172.23.34.44
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 172.23.34.44
Upgrade-Insecure-Requests: 1
X-Client-Ip: 172.23.34.44
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 172.23.34.44
sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "Linux"
--8710ab77-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/8.5.9
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--8710ab77-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/static../.env"] [unique_id "apUDnNmUuou1H8H2UKXEMAAAAMY"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788150684642010 77303 (- - -)
Stopwatch2: 1788150684642010 77303; combined=7379, p1=271, p2=7044, p3=0, p4=0, p5=64, sr=101, sw=0, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--8710ab77-Z--
--3265ff0d-A--
[31/Aug/2026:07:31:24.807124 +0300] apUDnH7glkZrdsSdRApJ6AAAAIo 34.73.181.25 44564 127.0.0.1 7081
--3265ff0d-B--
GET /files../.env HTTP/1.1
Host: alexandervodka.com
X-Real-IP: 34.73.181.25
X-Forwarded-For: 100.106.20.19
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 100.106.20.19
Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D
Fastly-Client-Ip: 100.106.20.19
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 100.106.20.19
Upgrade-Insecure-Requests: 1
X-Client-Ip: 100.106.20.19
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 100.106.20.19
sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "Linux"
--3265ff0d-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/8.5.9
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--3265ff0d-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/files../.env"] [unique_id "apUDnH7glkZrdsSdRApJ6AAAAIo"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788150684732982 74231 (- - -)
Stopwatch2: 1788150684732982 74231; combined=5196, p1=302, p2=4837, p3=0, p4=0, p5=56, sr=117, sw=1, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--3265ff0d-Z--
--23524f65-A--
[31/Aug/2026:07:31:24.881847 +0300] apUDnNmUuou1H8H2UKXEMQAAAM4 34.73.181.25 44576 127.0.0.1 7081
--23524f65-B--
GET /static//app/.env HTTP/1.1
Host: alexandervodka.com
X-Real-IP: 34.73.181.25
X-Forwarded-For: 100.96.181.137
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 100.96.181.137
Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D
Fastly-Client-Ip: 100.96.181.137
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 100.96.181.137
Upgrade-Insecure-Requests: 1
X-Client-Ip: 100.96.181.137
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 100.96.181.137
sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "Linux"
--23524f65-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/8.5.9
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--23524f65-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/static/app/.env"] [unique_id "apUDnNmUuou1H8H2UKXEMQAAAM4"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788150684735405 146556 (- - -)
Stopwatch2: 1788150684735405 146556; combined=6537, p1=457, p2=6022, p3=0, p4=0, p5=57, sr=175, sw=1, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--23524f65-Z--
--29c9e851-A--
[31/Aug/2026:07:31:24.908042 +0300] apUDnNmUuou1H8H2UKXEMwAAANM 34.73.181.25 44606 127.0.0.1 7081
--29c9e851-B--
GET /static//home/user/.env HTTP/1.1
Host: alexandervodka.com
X-Real-IP: 34.73.181.25
X-Forwarded-For: 10.39.142.71
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 10.39.142.71
Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D
Fastly-Client-Ip: 10.39.142.71
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 10.39.142.71
Upgrade-Insecure-Requests: 1
X-Client-Ip: 10.39.142.71
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 10.39.142.71
sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "Linux"
--29c9e851-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/8.5.9
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--29c9e851-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/static/home/user/.env"] [unique_id "apUDnNmUuou1H8H2UKXEMwAAANM"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788150684829165 78966 (- - -)
Stopwatch2: 1788150684829165 78966; combined=5177, p1=247, p2=4868, p3=0, p4=0, p5=62, sr=79, sw=0, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--29c9e851-Z--
--02947465-A--
[31/Aug/2026:07:31:24.918992 +0300] apUDnNmUuou1H8H2UKXEMgAAANA 34.73.181.25 44588 127.0.0.1 7081
--02947465-B--
GET /static//.env HTTP/1.1
Host: alexandervodka.com
X-Real-IP: 34.73.181.25
X-Forwarded-For: 10.230.237.85
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 10.230.237.85
Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D
Fastly-Client-Ip: 10.230.237.85
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 10.230.237.85
Upgrade-Insecure-Requests: 1
X-Client-Ip: 10.230.237.85
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 10.230.237.85
sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "Linux"
--02947465-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/8.5.9
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--02947465-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/static/.env"] [unique_id "apUDnNmUuou1H8H2UKXEMgAAANA"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788150684751053 168088 (- - -)
Stopwatch2: 1788150684751053 168088; combined=4774, p1=281, p2=4438, p3=0, p4=0, p5=55, sr=86, sw=0, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--02947465-Z--
--6659a052-A--
[31/Aug/2026:07:31:24.937893 +0300] apUDnG7fDIutYTwcPOkaeAAAAEo 34.73.181.25 44590 127.0.0.1 7081
--6659a052-B--
GET /media../.env HTTP/1.1
Host: alexandervodka.com
X-Real-IP: 34.73.181.25
X-Forwarded-For: 100.106.214.148
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 100.106.214.148
Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D
Fastly-Client-Ip: 100.106.214.148
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 100.106.214.148
Upgrade-Insecure-Requests: 1
X-Client-Ip: 100.106.214.148
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 100.106.214.148
sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "Linux"
--6659a052-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/8.5.9
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--6659a052-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/media../.env"] [unique_id "apUDnG7fDIutYTwcPOkaeAAAAEo"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788150684801316 136665 (- - -)
Stopwatch2: 1788150684801316 136665; combined=16222, p1=287, p2=15878, p3=0, p4=0, p5=57, sr=93, sw=0, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--6659a052-Z--
--6209bb50-A--
[31/Aug/2026:07:31:24.966259 +0300] apUDnG7fDIutYTwcPOkaeQAAAEc 34.73.181.25 44610 127.0.0.1 7081
--6209bb50-B--
GET /.//.env HTTP/1.1
Host: alexandervodka.com
X-Real-IP: 34.73.181.25
X-Forwarded-For: 10.9.252.225
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 10.9.252.225
Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D
Fastly-Client-Ip: 10.9.252.225
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 10.9.252.225
Upgrade-Insecure-Requests: 1
X-Client-Ip: 10.9.252.225
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 10.9.252.225
sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "Linux"
--6209bb50-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/8.5.9
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--6209bb50-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/.env"] [unique_id "apUDnG7fDIutYTwcPOkaeQAAAEc"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788150684885466 80883 (- - -)
Stopwatch2: 1788150684885466 80883; combined=5110, p1=269, p2=4783, p3=0, p4=0, p5=58, sr=109, sw=0, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--6209bb50-Z--
--ebd6563c-A--
[31/Aug/2026:07:31:25.038905 +0300] apUDnG7fDIutYTwcPOkaegAAAEQ 34.73.181.25 44624 127.0.0.1 7081
--ebd6563c-B--
GET //.env HTTP/1.1
Host: alexandervodka.com
X-Real-IP: 34.73.181.25
X-Forwarded-For: 172.20.111.144
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 172.20.111.144
Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D
Fastly-Client-Ip: 172.20.111.144
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 172.20.111.144
Upgrade-Insecure-Requests: 1
X-Client-Ip: 172.20.111.144
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 172.20.111.144
sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "Linux"
--ebd6563c-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/8.5.9
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--ebd6563c-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/.env"] [unique_id "apUDnG7fDIutYTwcPOkaegAAAEQ"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788150684966271 72841 (- - -)
Stopwatch2: 1788150684966271 72841; combined=4881, p1=241, p2=4551, p3=0, p4=0, p5=88, sr=71, sw=1, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--ebd6563c-Z--
--6d4c2b43-A--
[31/Aug/2026:07:31:25.152952 +0300] apUDndmUuou1H8H2UKXENAAAAMU 34.73.181.25 44638 127.0.0.1 7081
--6d4c2b43-B--
GET /api/.env/public/.env HTTP/1.1
Host: alexandervodka.com
X-Real-IP: 34.73.181.25
X-Forwarded-For: 100.111.57.59
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 100.111.57.59
Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D
Fastly-Client-Ip: 100.111.57.59
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 100.111.57.59
Upgrade-Insecure-Requests: 1
X-Client-Ip: 100.111.57.59
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 100.111.57.59
sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "Linux"
--6d4c2b43-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/8.5.9
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--6d4c2b43-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/api/.env/public/.env"] [unique_id "apUDndmUuou1H8H2UKXENAAAAMU"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788150685070253 82788 (- - -)
Stopwatch2: 1788150685070253 82788; combined=6962, p1=434, p2=6469, p3=0, p4=0, p5=59, sr=122, sw=0, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--6d4c2b43-Z--
--5aa7212d-A--
[31/Aug/2026:07:31:25.178738 +0300] apUDndmUuou1H8H2UKXENQAAAMQ 34.73.181.25 44640 127.0.0.1 7081
--5aa7212d-B--
GET /%2eenv HTTP/1.1
Host: alexandervodka.com
X-Real-IP: 34.73.181.25
X-Forwarded-For: 100.72.98.143
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 100.72.98.143
Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D
Fastly-Client-Ip: 100.72.98.143
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 100.72.98.143
Upgrade-Insecure-Requests: 1
X-Client-Ip: 100.72.98.143
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 100.72.98.143
sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "Linux"
--5aa7212d-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/8.5.9
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--5aa7212d-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/.env"] [unique_id "apUDndmUuou1H8H2UKXENQAAAMQ"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788150685106096 72766 (- - -)
Stopwatch2: 1788150685106096 72766; combined=4974, p1=256, p2=4635, p3=0, p4=0, p5=82, sr=84, sw=1, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--5aa7212d-Z--
--411a3a74-A--
[31/Aug/2026:07:31:25.256975 +0300] apUDnX7glkZrdsSdRApJ6QAAAJM 34.73.181.25 44642 127.0.0.1 7081
--411a3a74-B--
GET /assets../.env HTTP/1.1
Host: alexandervodka.com
X-Real-IP: 34.73.181.25
X-Forwarded-For: 172.16.44.181
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 172.16.44.181
Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D
Fastly-Client-Ip: 172.16.44.181
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 172.16.44.181
Upgrade-Insecure-Requests: 1
X-Client-Ip: 172.16.44.181
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 172.16.44.181
sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "Linux"
--411a3a74-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/8.5.9
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--411a3a74-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/assets../.env"] [unique_id "apUDnX7glkZrdsSdRApJ6QAAAJM"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788150685194881 62178 (- - -)
Stopwatch2: 1788150685194881 62178; combined=5018, p1=277, p2=4685, p3=0, p4=0, p5=55, sr=88, sw=1, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--411a3a74-Z--
--e2b4db2e-A--
[31/Aug/2026:07:31:25.406805 +0300] apUDnX7glkZrdsSdRApJ6gAAAJU 34.73.181.25 44668 127.0.0.1 7081
--e2b4db2e-B--
GET /img../.env HTTP/1.1
Host: alexandervodka.com
X-Real-IP: 34.73.181.25
X-Forwarded-For: 192.168.129.29
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 192.168.129.29
Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D
Fastly-Client-Ip: 192.168.129.29
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 192.168.129.29
Upgrade-Insecure-Requests: 1
X-Client-Ip: 192.168.129.29
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 192.168.129.29
sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "Linux"
--e2b4db2e-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/8.5.9
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--e2b4db2e-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/img../.env"] [unique_id "apUDnX7glkZrdsSdRApJ6gAAAJU"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788150685305944 100950 (- - -)
Stopwatch2: 1788150685305944 100950; combined=5802, p1=282, p2=5460, p3=0, p4=0, p5=60, sr=91, sw=0, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--e2b4db2e-Z--
--ecd73067-A--
[31/Aug/2026:07:31:25.485904 +0300] apUDnW7fDIutYTwcPOkaewAAAEs 34.73.181.25 44660 127.0.0.1 7081
--ecd73067-B--
GET /uploads../.env HTTP/1.1
Host: alexandervodka.com
X-Real-IP: 34.73.181.25
X-Forwarded-For: 100.114.221.197
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 100.114.221.197
Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D
Fastly-Client-Ip: 100.114.221.197
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 100.114.221.197
Upgrade-Insecure-Requests: 1
X-Client-Ip: 100.114.221.197
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 100.114.221.197
sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "Linux"
--ecd73067-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/8.5.9
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--ecd73067-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/uploads../.env"] [unique_id "apUDnW7fDIutYTwcPOkaewAAAEs"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788150685281322 204672 (- - -)
Stopwatch2: 1788150685281322 204672; combined=5014, p1=163, p2=4793, p3=0, p4=0, p5=58, sr=57, sw=0, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--ecd73067-Z--
--5a00cb42-A--
[31/Aug/2026:07:31:25.494548 +0300] apUDndmUuou1H8H2UKXENgAAANU 34.73.181.25 44648 127.0.0.1 7081
--5a00cb42-B--
GET /images../.env HTTP/1.1
Host: alexandervodka.com
X-Real-IP: 34.73.181.25
X-Forwarded-For: 10.98.22.165
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 10.98.22.165
Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D
Fastly-Client-Ip: 10.98.22.165
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 10.98.22.165
Upgrade-Insecure-Requests: 1
X-Client-Ip: 10.98.22.165
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 10.98.22.165
sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "Linux"
--5a00cb42-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/8.5.9
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--5a00cb42-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/images../.env"] [unique_id "apUDndmUuou1H8H2UKXENgAAANU"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788150685280812 213914 (- - -)
Stopwatch2: 1788150685280812 213914; combined=5029, p1=302, p2=4671, p3=0, p4=0, p5=56, sr=104, sw=0, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--5a00cb42-Z--
--3a208051-A--
[31/Aug/2026:07:31:25.642342 +0300] apUDndmUuou1H8H2UKXENwAAAMo 34.73.181.25 55428 127.0.0.1 7081
--3a208051-B--
GET /@fs/var/task/.env?raw?? HTTP/1.1
Host: alexandervodka.com
X-Real-IP: 34.73.181.25
X-Forwarded-For: 100.88.75.84
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 100.88.75.84
Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D
Fastly-Client-Ip: 100.88.75.84
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 100.88.75.84
Upgrade-Insecure-Requests: 1
X-Client-Ip: 100.88.75.84
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 100.88.75.84
sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "Linux"
--3a208051-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/8.5.9
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--3a208051-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/@fs/var/task/.env"] [unique_id "apUDndmUuou1H8H2UKXENwAAAMo"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788150685568530 73930 (- - -)
Stopwatch2: 1788150685568530 73930; combined=3983, p1=294, p2=3626, p3=0, p4=0, p5=62, sr=96, sw=1, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--3a208051-Z--
--ee575677-A--
[31/Aug/2026:07:31:25.691923 +0300] apUDnSfaLSuAj0yzdueTHwAAAAg 34.73.181.25 55430 127.0.0.1 7081
--ee575677-B--
GET /@fs/proc/self/cwd/.env?raw?? HTTP/1.1
Host: alexandervodka.com
X-Real-IP: 34.73.181.25
X-Forwarded-For: 10.60.252.134
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 10.60.252.134
Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D
Fastly-Client-Ip: 10.60.252.134
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 10.60.252.134
Upgrade-Insecure-Requests: 1
X-Client-Ip: 10.60.252.134
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 10.60.252.134
sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "Linux"
--ee575677-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/8.5.9
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--ee575677-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/@fs/proc/self/cwd/.env"] [unique_id "apUDnSfaLSuAj0yzdueTHwAAAAg"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788150685624484 67548 (- - -)
Stopwatch2: 1788150685624484 67548; combined=4560, p1=360, p2=4131, p3=0, p4=0, p5=69, sr=99, sw=0, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--ee575677-Z--
--079d0a7f-A--
[31/Aug/2026:07:31:25.859521 +0300] apUDnX7glkZrdsSdRApJ7gAAAIU 172.69.223.200 55436 127.0.0.1 7081
--079d0a7f-B--
GET /.git/HEAD HTTP/1.1
Host: funshop.ro
X-Real-IP: 172.69.223.200
X-Forwarded-For: 2a06:98c0:3600::103
X-Accel-Internal: /internal-nginx-static-location
cf-ray: a3394e38f8536f05-CDG
CF-EW-Via: 15
CDN-Loop: cloudflare; loops=1
Upgrade-Insecure-Requests: 1
Sec-Fetch-User: ?1
Accept-Language: en-US,en;q=0.9
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Cache-Control: no-cache
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
Pragma: no-cache
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
cf-worker: jx1akqrgxx5exg.workers.dev
CF-Visitor: {"scheme":"https"}
X-Forwarded-Proto: https
accept-encoding: gzip
--079d0a7f-F--
HTTP/1.1 404 Not Found
Content-Length: 196
Content-Type: text/html; charset=iso-8859-1
--079d0a7f-E--
--079d0a7f-H--
Message: Warning. String match "/.git/" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "656"] [id "77318034"] [msg "IM360 WAF: Blocked access to git folder||T:APACHE||MV:/.git/head||"] [severity "NOTICE"] [tag "service_i360custom"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.git/" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "656"] [id "77318034"] [msg "IM360 WAF: Blocked access to git folder||T:APACHE||MV:/.git/head||"] [severity "NOTICE"] [tag "service_i360custom"] [hostname "funshop.ro"] [uri "/.git/HEAD"] [unique_id "apUDnX7glkZrdsSdRApJ7gAAAIU"]
Stopwatch: 1788150685852216 7389 (- - -)
Stopwatch2: 1788150685852216 7389; combined=5898, p1=391, p2=5331, p3=72, p4=7, p5=97, sr=153, sw=0, l=0, gc=0
Response-Body-Transformed: Dechunked
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--079d0a7f-Z--
--81cbba0b-A--
[31/Aug/2026:07:31:25.894711 +0300] apUDnX7glkZrdsSdRApJ7wAAAJc 172.69.223.200 55438 127.0.0.1 7081
--81cbba0b-B--
GET /.git/config HTTP/1.1
Host: funshop.ro
X-Real-IP: 172.69.223.200
X-Forwarded-For: 2a06:98c0:3600::103
X-Accel-Internal: /internal-nginx-static-location
cf-ray: a3394e38f8546f05-CDG
CF-EW-Via: 15
CDN-Loop: cloudflare; loops=1
Upgrade-Insecure-Requests: 1
Sec-Fetch-User: ?1
Accept-Language: en-US,en;q=0.9
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Cache-Control: no-cache
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
Pragma: no-cache
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
cf-worker: jx1akqrgxx5exg.workers.dev
CF-Visitor: {"scheme":"https"}
X-Forwarded-Proto: https
accept-encoding: gzip
--81cbba0b-F--
HTTP/1.1 404 Not Found
Content-Length: 196
Content-Type: text/html; charset=iso-8859-1
--81cbba0b-E--
--81cbba0b-H--
Message: Warning. Matched phrase "/.git/config" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.git/config||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"]
Message: Warning. Matched phrase "/.git/config" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.git/config||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"]
Message: Warning. String match "/.git/" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "656"] [id "77318034"] [msg "IM360 WAF: Blocked access to git folder||T:APACHE||MV:/.git/config||"] [severity "NOTICE"] [tag "service_i360custom"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "/.git/config" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.git/config||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "funshop.ro"] [uri "/.git/config"] [unique_id "apUDnX7glkZrdsSdRApJ7wAAAJc"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "/.git/config" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.git/config||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "funshop.ro"] [uri "/.git/config"] [unique_id "apUDnX7glkZrdsSdRApJ7wAAAJc"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.git/" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "656"] [id "77318034"] [msg "IM360 WAF: Blocked access to git folder||T:APACHE||MV:/.git/config||"] [severity "NOTICE"] [tag "service_i360custom"] [hostname "funshop.ro"] [uri "/.git/config"] [unique_id "apUDnX7glkZrdsSdRApJ7wAAAJc"]
Stopwatch: 1788150685854167 40756 (- - -)
Stopwatch2: 1788150685854167 40756; combined=38890, p1=588, p2=38073, p3=90, p4=10, p5=129, sr=228, sw=0, l=0, gc=0
Response-Body-Transformed: Dechunked
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--81cbba0b-Z--
--02086704-A--
[31/Aug/2026:07:31:25.976746 +0300] apUDnX7glkZrdsSdRApJ8AAAAIc 34.73.181.25 55450 127.0.0.1 7081
--02086704-B--
GET /@fs/.env?url&raw?? HTTP/1.1
Host: alexandervodka.com
X-Real-IP: 34.73.181.25
X-Forwarded-For: 10.7.156.211
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 10.7.156.211
Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D
Fastly-Client-Ip: 10.7.156.211
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 10.7.156.211
Upgrade-Insecure-Requests: 1
X-Client-Ip: 10.7.156.211
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 10.7.156.211
sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "Linux"
--02086704-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/8.5.9
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--02086704-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:url&raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:url&raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/@fs/.env"] [unique_id "apUDnX7glkZrdsSdRApJ8AAAAIc"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788150685875088 101758 (- - -)
Stopwatch2: 1788150685875088 101758; combined=13613, p1=295, p2=13261, p3=0, p4=0, p5=57, sr=104, sw=0, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--02086704-Z--
--2cd92f3c-A--
[31/Aug/2026:07:31:26.060951 +0300] apUDndmUuou1H8H2UKXEOwAAAMk 34.73.181.25 55498 127.0.0.1 7081
--2cd92f3c-B--
GET /@fs/.env?raw&url?? HTTP/1.1
Host: alexandervodka.com
X-Real-IP: 34.73.181.25
X-Forwarded-For: 172.23.46.20
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 172.23.46.20
Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D
Fastly-Client-Ip: 172.23.46.20
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 172.23.46.20
Upgrade-Insecure-Requests: 1
X-Client-Ip: 172.23.46.20
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 172.23.46.20
sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "Linux"
--2cd92f3c-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/8.5.9
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--2cd92f3c-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw&url??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw&url??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/@fs/.env"] [unique_id "apUDndmUuou1H8H2UKXEOwAAAMk"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788150685982809 78228 (- - -)
Stopwatch2: 1788150685982809 78228; combined=3936, p1=251, p2=3644, p3=0, p4=0, p5=41, sr=89, sw=0, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--2cd92f3c-Z--
--f8f7ec2b-A--
[31/Aug/2026:07:31:26.218176 +0300] apUDntmUuou1H8H2UKXEPAAAANg 34.73.181.25 55508 127.0.0.1 7081
--f8f7ec2b-B--
GET /wp-config.php.bak HTTP/1.1
Host: alexandervodka.com
X-Real-IP: 34.73.181.25
X-Forwarded-For: 172.30.242.199
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 172.30.242.199
Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D
Fastly-Client-Ip: 172.30.242.199
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 172.30.242.199
Upgrade-Insecure-Requests: 1
X-Client-Ip: 172.30.242.199
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 172.30.242.199
sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "Linux"
--f8f7ec2b-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/8.5.9
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--f8f7ec2b-H--
Message: Warning. Matched phrase "wp-config.php." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/wp-config.php.bak||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"]
Message: Warning. Matched phrase "wp-config.php." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/wp-config.php.bak||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"]
Message: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "wp-config.php." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/wp-config.php.bak||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/wp-config.php.bak"] [unique_id "apUDntmUuou1H8H2UKXEPAAAANg"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "wp-config.php." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/wp-config.php.bak||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/wp-config.php.bak"] [unique_id "apUDntmUuou1H8H2UKXEPAAAANg"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/wp-config.php.bak"] [unique_id "apUDntmUuou1H8H2UKXEPAAAANg"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788150686058394 159935 (- - -)
Stopwatch2: 1788150686058394 159935; combined=31863, p1=274, p2=31459, p3=0, p4=0, p5=129, sr=81, sw=1, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--f8f7ec2b-Z--
--3ff26137-A--
[31/Aug/2026:07:31:26.228542 +0300] apUDnm7fDIutYTwcPOkafAAAAE0 34.73.181.25 55524 127.0.0.1 7081
--3ff26137-B--
GET /@fs/.env?import&?raw?? HTTP/1.1
Host: alexandervodka.com
X-Real-IP: 34.73.181.25
X-Forwarded-For: 10.190.150.154
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 10.190.150.154
Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D
Fastly-Client-Ip: 10.190.150.154
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 10.190.150.154
Upgrade-Insecure-Requests: 1
X-Client-Ip: 10.190.150.154
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 10.190.150.154
sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "Linux"
--3ff26137-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/8.5.9
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--3ff26137-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:import&?raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:import&?raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/@fs/.env"] [unique_id "apUDnm7fDIutYTwcPOkafAAAAE0"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788150686093108 136644 (- - -)
Stopwatch2: 1788150686093108 136644; combined=24967, p1=224, p2=3820, p3=0, p4=0, p5=10497, sr=77, sw=1, l=0, gc=10425
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--3ff26137-Z--
--74c04b64-A--
[31/Aug/2026:07:31:26.285846 +0300] apUDntmUuou1H8H2UKXEPgAAAM4 34.73.181.25 55530 127.0.0.1 7081
--74c04b64-B--
GET /wp-config.php.old HTTP/1.1
Host: alexandervodka.com
X-Real-IP: 34.73.181.25
X-Forwarded-For: 172.27.214.248
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 172.27.214.248
Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D
Fastly-Client-Ip: 172.27.214.248
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 172.27.214.248
Upgrade-Insecure-Requests: 1
X-Client-Ip: 172.27.214.248
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 172.27.214.248
sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "Linux"
--74c04b64-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/8.5.9
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--74c04b64-H--
Message: Warning. Matched phrase "wp-config.php." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/wp-config.php.old||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"]
Message: Warning. Matched phrase "wp-config.php." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/wp-config.php.old||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"]
Message: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "wp-config.php." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/wp-config.php.old||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/wp-config.php.old"] [unique_id "apUDntmUuou1H8H2UKXEPgAAAM4"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "wp-config.php." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/wp-config.php.old||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/wp-config.php.old"] [unique_id "apUDntmUuou1H8H2UKXEPgAAAM4"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/wp-config.php.old"] [unique_id "apUDntmUuou1H8H2UKXEPgAAAM4"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788150686191118 94841 (- - -)
Stopwatch2: 1788150686191118 94841; combined=31934, p1=276, p2=31576, p3=0, p4=0, p5=81, sr=78, sw=1, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--74c04b64-Z--
--8ebb9f2f-A--
[31/Aug/2026:07:31:26.480284 +0300] apUDntmUuou1H8H2UKXEQQAAANI 34.73.181.25 55566 127.0.0.1 7081
--8ebb9f2f-B--
GET /core/.env HTTP/1.1
Host: alexandervodka.com
X-Real-IP: 34.73.181.25
X-Forwarded-For: 100.107.100.135
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 100.107.100.135
Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D
Fastly-Client-Ip: 100.107.100.135
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 100.107.100.135
Upgrade-Insecure-Requests: 1
X-Client-Ip: 100.107.100.135
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 100.107.100.135
sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "Linux"
--8ebb9f2f-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/8.5.9
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--8ebb9f2f-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/core/.env"] [unique_id "apUDntmUuou1H8H2UKXEQQAAANI"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788150686409376 71017 (- - -)
Stopwatch2: 1788150686409376 71017; combined=4890, p1=287, p2=4544, p3=0, p4=0, p5=58, sr=95, sw=1, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--8ebb9f2f-Z--
--7492956f-A--
[31/Aug/2026:07:31:26.503093 +0300] apUDnn7glkZrdsSdRApJ8wAAAII 34.73.181.25 55556 127.0.0.1 7081
--7492956f-B--
GET /laravel/.env HTTP/1.1
Host: alexandervodka.com
X-Real-IP: 34.73.181.25
X-Forwarded-For: 100.125.45.109
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 100.125.45.109
Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D
Fastly-Client-Ip: 100.125.45.109
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 100.125.45.109
Upgrade-Insecure-Requests: 1
X-Client-Ip: 100.125.45.109
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 100.125.45.109
sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "Linux"
--7492956f-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/8.5.9
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--7492956f-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/laravel/.env"] [unique_id "apUDnn7glkZrdsSdRApJ8wAAAII"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788150686349240 153955 (- - -)
Stopwatch2: 1788150686349240 153955; combined=6642, p1=292, p2=6287, p3=0, p4=0, p5=62, sr=102, sw=1, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--7492956f-Z--
--bb76593d-A--
[31/Aug/2026:07:31:26.511978 +0300] apUDntmUuou1H8H2UKXEPwAAANA 34.73.181.25 55544 127.0.0.1 7081
--bb76593d-B--
GET /config/.env.php HTTP/1.1
Host: alexandervodka.com
X-Real-IP: 34.73.181.25
X-Forwarded-For: 172.17.188.36
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 172.17.188.36
Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D
Fastly-Client-Ip: 172.17.188.36
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 172.17.188.36
Upgrade-Insecure-Requests: 1
X-Client-Ip: 172.17.188.36
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 172.17.188.36
sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "Linux"
--bb76593d-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/8.5.9
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--bb76593d-H--
Message: Warning. Matched phrase ".env.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/config/.env.php||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"]
Message: Warning. Matched phrase ".env.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/config/.env.php||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".env.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/config/.env.php||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/config/.env.php"] [unique_id "apUDntmUuou1H8H2UKXEPwAAANA"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".env.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/config/.env.php||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/config/.env.php"] [unique_id "apUDntmUuou1H8H2UKXEPwAAANA"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788150686348462 163622 (- - -)
Stopwatch2: 1788150686348462 163622; combined=35449, p1=359, p2=35020, p3=0, p4=0, p5=70, sr=155, sw=0, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--bb76593d-Z--
--3a70162c-A--
[31/Aug/2026:07:31:26.541748 +0300] apUDntmUuou1H8H2UKXEQAAAANE 34.73.181.25 55562 127.0.0.1 7081
--3a70162c-B--
GET /.env.php.bak HTTP/1.1
Host: alexandervodka.com
X-Real-IP: 34.73.181.25
X-Forwarded-For: 172.25.37.10
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 172.25.37.10
Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D
Fastly-Client-Ip: 172.25.37.10
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 172.25.37.10
Upgrade-Insecure-Requests: 1
X-Client-Ip: 172.25.37.10
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 172.25.37.10
sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "Linux"
--3a70162c-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/8.5.9
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--3a70162c-H--
Message: Warning. Matched phrase ".env.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.env.php.bak||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"]
Message: Warning. Matched phrase ".env.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.env.php.bak||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".env.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.env.php.bak||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/.env.php.bak"] [unique_id "apUDntmUuou1H8H2UKXEQAAAANE"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".env.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.env.php.bak||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/.env.php.bak"] [unique_id "apUDntmUuou1H8H2UKXEQAAAANE"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788150686403683 138154 (- - -)
Stopwatch2: 1788150686403683 138154; combined=37492, p1=260, p2=37169, p3=0, p4=0, p5=63, sr=96, sw=0, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--3a70162c-Z--
--27f8364d-A--
[31/Aug/2026:07:31:26.709199 +0300] apUDnm7fDIutYTwcPOkafQAAAFE 34.73.181.25 55592 127.0.0.1 7081
--27f8364d-B--
GET /configuration.php.bak HTTP/1.1
Host: alexandervodka.com
X-Real-IP: 34.73.181.25
X-Forwarded-For: 100.83.50.152
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 100.83.50.152
Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D
Fastly-Client-Ip: 100.83.50.152
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 100.83.50.152
Upgrade-Insecure-Requests: 1
X-Client-Ip: 100.83.50.152
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 100.83.50.152
sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "Linux"
--27f8364d-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/8.5.9
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--27f8364d-H--
Message: Warning. Matched phrase "/configuration.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "/configuration.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/configuration.php.bak"] [unique_id "apUDnm7fDIutYTwcPOkafQAAAFE"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788150686643121 66189 (- - -)
Stopwatch2: 1788150686643121 66189; combined=4428, p1=238, p2=4127, p3=0, p4=0, p5=62, sr=80, sw=1, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--27f8364d-Z--
--453a8c1b-A--
[31/Aug/2026:07:31:26.789982 +0300] apUDntmUuou1H8H2UKXEQgAAAMI 34.73.181.25 55610 127.0.0.1 7081
--453a8c1b-B--
GET /.env.swp HTTP/1.1
Host: alexandervodka.com
X-Real-IP: 34.73.181.25
X-Forwarded-For: 192.168.148.213
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 192.168.148.213
Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D
Fastly-Client-Ip: 192.168.148.213
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 192.168.148.213
Upgrade-Insecure-Requests: 1
X-Client-Ip: 192.168.148.213
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 192.168.148.213
sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "Linux"
--453a8c1b-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/8.5.9
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--453a8c1b-H--
Message: Warning. Pattern match "(\\.swp|~)$" at REQUEST_BASENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "309"] [id "77142201"] [msg "IM360 WAF: Possible enumeration of sensitive data (dirb)||MVN:REQUEST_BASENAME||T:APACHE||MV:.env.swp||"] [severity "NOTICE"] [tag "service_i360custom"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\.swp|~)$" at REQUEST_BASENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "309"] [id "77142201"] [msg "IM360 WAF: Possible enumeration of sensitive data (dirb)||MVN:REQUEST_BASENAME||T:APACHE||MV:.env.swp||"] [severity "NOTICE"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/.env.swp"] [unique_id "apUDntmUuou1H8H2UKXEQgAAAMI"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788150686698077 92018 (- - -)
Stopwatch2: 1788150686698077 92018; combined=4719, p1=236, p2=4418, p3=0, p4=0, p5=65, sr=77, sw=0, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--453a8c1b-Z--
--9af7f705-A--
[31/Aug/2026:07:31:26.821212 +0300] apUDnifaLSuAj0yzdueTIAAAAAM 34.73.181.25 55584 127.0.0.1 7081
--9af7f705-B--
GET /config.php.bak HTTP/1.1
Host: alexandervodka.com
X-Real-IP: 34.73.181.25
X-Forwarded-For: 100.104.9.168
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 100.104.9.168
Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D
Fastly-Client-Ip: 100.104.9.168
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 100.104.9.168
Upgrade-Insecure-Requests: 1
X-Client-Ip: 100.104.9.168
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 100.104.9.168
sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "Linux"
--9af7f705-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/8.5.9
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--9af7f705-H--
Message: Warning. Matched phrase "/config.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "/config.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/config.php.bak"] [unique_id "apUDnifaLSuAj0yzdueTIAAAAAM"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788150686614770 206556 (- - -)
Stopwatch2: 1788150686614770 206556; combined=5072, p1=231, p2=4786, p3=0, p4=0, p5=55, sr=86, sw=0, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--9af7f705-Z--
--4a5a1552-A--
[31/Aug/2026:07:31:26.870921 +0300] apUDntmUuou1H8H2UKXEQwAAANU 34.73.181.25 55616 127.0.0.1 7081
--4a5a1552-B--
GET /public/.env HTTP/1.1
Host: alexandervodka.com
X-Real-IP: 34.73.181.25
X-Forwarded-For: 10.211.70.244
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 10.211.70.244
Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D
Fastly-Client-Ip: 10.211.70.244
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 10.211.70.244
Upgrade-Insecure-Requests: 1
X-Client-Ip: 10.211.70.244
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 10.211.70.244
sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "Linux"
--4a5a1552-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/8.5.9
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--4a5a1552-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/public/.env"] [unique_id "apUDntmUuou1H8H2UKXEQwAAANU"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788150686720916 150117 (- - -)
Stopwatch2: 1788150686720916 150117; combined=4835, p1=266, p2=4511, p3=0, p4=0, p5=57, sr=84, sw=1, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--4a5a1552-Z--
--be399765-A--
[31/Aug/2026:07:31:26.971427 +0300] apUDnn7glkZrdsSdRApJ9QAAAIs 34.73.181.25 55620 127.0.0.1 7081
--be399765-B--
GET /web/.env HTTP/1.1
Host: alexandervodka.com
X-Real-IP: 34.73.181.25
X-Forwarded-For: 10.18.76.71
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 10.18.76.71
Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D
Fastly-Client-Ip: 10.18.76.71
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 10.18.76.71
Upgrade-Insecure-Requests: 1
X-Client-Ip: 10.18.76.71
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 10.18.76.71
sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "Linux"
--be399765-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/8.5.9
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--be399765-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/web/.env"] [unique_id "apUDnn7glkZrdsSdRApJ9QAAAIs"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788150686902609 68907 (- - -)
Stopwatch2: 1788150686902609 68907; combined=5107, p1=297, p2=4753, p3=0, p4=0, p5=57, sr=92, sw=0, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--be399765-Z--
--3d225b36-A--
[31/Aug/2026:07:31:27.023888 +0300] apUDnn7glkZrdsSdRApJ9gAAAJM 34.73.181.25 55628 127.0.0.1 7081
--3d225b36-B--
GET /storage/.env HTTP/1.1
Host: alexandervodka.com
X-Real-IP: 34.73.181.25
X-Forwarded-For: 100.89.221.10
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 100.89.221.10
Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D
Fastly-Client-Ip: 100.89.221.10
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 100.89.221.10
Upgrade-Insecure-Requests: 1
X-Client-Ip: 100.89.221.10
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 100.89.221.10
sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "Linux"
--3d225b36-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/8.5.9
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--3d225b36-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/storage/.env"] [unique_id "apUDnn7glkZrdsSdRApJ9gAAAJM"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788150686956235 67740 (- - -)
Stopwatch2: 1788150686956235 67740; combined=5545, p1=322, p2=5177, p3=0, p4=0, p5=46, sr=89, sw=0, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--3d225b36-Z--
--cf612a2e-A--
[31/Aug/2026:07:31:27.085770 +0300] apUDnn7glkZrdsSdRApJ9wAAAJU 34.73.181.25 55634 127.0.0.1 7081
--cf612a2e-B--
GET /wp/.env HTTP/1.1
Host: alexandervodka.com
X-Real-IP: 34.73.181.25
X-Forwarded-For: 192.168.22.52
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 192.168.22.52
Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D
Fastly-Client-Ip: 192.168.22.52
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 192.168.22.52
Upgrade-Insecure-Requests: 1
X-Client-Ip: 192.168.22.52
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 192.168.22.52
sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "Linux"
--cf612a2e-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/8.5.9
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--cf612a2e-H--
Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/wp/.env"] [unique_id "apUDnn7glkZrdsSdRApJ9wAAAJU"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788150686982651 103208 (- - -)
Stopwatch2: 1788150686982651 103208; combined=4655, p1=243, p2=4352, p3=0, p4=0, p5=59, sr=79, sw=1, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--cf612a2e-Z--
--ec426506-A--
[31/Aug/2026:07:31:27.156144 +0300] apUDn27fDIutYTwcPOkafgAAAEw 34.73.181.25 55646 127.0.0.1 7081
--ec426506-B--
GET /wp-config.php~ HTTP/1.1
Host: alexandervodka.com
X-Real-IP: 34.73.181.25
X-Forwarded-For: 10.199.79.64
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 10.199.79.64
Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D
Fastly-Client-Ip: 10.199.79.64
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 10.199.79.64
Upgrade-Insecure-Requests: 1
X-Client-Ip: 10.199.79.64
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 10.199.79.64
sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "Linux"
--ec426506-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/8.5.9
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--ec426506-H--
Message: Warning. Matched phrase "wp-config.php~" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/wp-config.php~||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"]
Message: Warning. Matched phrase "wp-config.php~" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/wp-config.php~||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"]
Message: Warning. Pattern match "(\\.swp|~)$" at REQUEST_BASENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "309"] [id "77142201"] [msg "IM360 WAF: Possible enumeration of sensitive data (dirb)||MVN:REQUEST_BASENAME||T:APACHE||MV:wp-config.php~||"] [severity "NOTICE"] [tag "service_i360custom"]
Message: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "wp-config.php~" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/wp-config.php~||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/wp-config.php~"] [unique_id "apUDn27fDIutYTwcPOkafgAAAEw"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "wp-config.php~" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/wp-config.php~||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/wp-config.php~"] [unique_id "apUDn27fDIutYTwcPOkafgAAAEw"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\.swp|~)$" at REQUEST_BASENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "309"] [id "77142201"] [msg "IM360 WAF: Possible enumeration of sensitive data (dirb)||MVN:REQUEST_BASENAME||T:APACHE||MV:wp-config.php~||"] [severity "NOTICE"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/wp-config.php~"] [unique_id "apUDn27fDIutYTwcPOkafgAAAEw"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/wp-config.php~"] [unique_id "apUDn27fDIutYTwcPOkafgAAAEw"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788150687021543 134690 (- - -)
Stopwatch2: 1788150687021543 134690; combined=38069, p1=255, p2=37737, p3=0, p4=0, p5=77, sr=78, sw=0, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--ec426506-Z--
--81566138-A--
[31/Aug/2026:07:31:27.162923 +0300] apUDn37glkZrdsSdRApJ@AAAAI4 34.73.181.25 55664 127.0.0.1 7081
--81566138-B--
GET /wp-config.php.swp HTTP/1.1
Host: alexandervodka.com
X-Real-IP: 34.73.181.25
X-Forwarded-For: 172.17.143.31
X-Accel-Internal: /internal-nginx-static-location
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: en-US,en;q=0.9
Cf-Connecting-Ip: 172.17.143.31
Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D
Fastly-Client-Ip: 172.17.143.31
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: none
Sec-Fetch-User: ?1
True-Client-Ip: 172.17.143.31
Upgrade-Insecure-Requests: 1
X-Client-Ip: 172.17.143.31
X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware
X-Originating-Ip: 172.17.143.31
sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "Linux"
--81566138-F--
HTTP/1.1 404 Not Found
X-Powered-By: PHP/8.5.9
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
--81566138-H--
Message: Warning. Matched phrase "wp-config.php." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/wp-config.php.swp||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"]
Message: Warning. Matched phrase "wp-config.php." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/wp-config.php.swp||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"]
Message: Warning. Pattern match "(\\.swp|~)$" at REQUEST_BASENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "309"] [id "77142201"] [msg "IM360 WAF: Possible enumeration of sensitive data (dirb)||MVN:REQUEST_BASENAME||T:APACHE||MV:wp-config.php.swp||"] [severity "NOTICE"] [tag "service_i360custom"]
Message: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "wp-config.php." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/wp-config.php.swp||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/wp-config.php.swp"] [unique_id "apUDn37glkZrdsSdRApJ@AAAAI4"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "wp-config.php." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/wp-config.php.swp||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/wp-config.php.swp"] [unique_id "apUDn37glkZrdsSdRApJ@AAAAI4"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\.swp|~)$" at REQUEST_BASENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "309"] [id "77142201"] [msg "IM360 WAF: Possible enumeration of sensitive data (dirb)||MVN:REQUEST_BASENAME||T:APACHE||MV:wp-config.php.swp||"] [severity "NOTICE"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/wp-config.php.swp"] [unique_id "apUDn37glkZrdsSdRApJ@AAAAI4"]
Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/wp-config.php.swp"] [unique_id "apUDn37glkZrdsSdRApJ@AAAAI4"]
Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000
Stopwatch: 1788150687037359 125652 (- - -)
Stopwatch2: 1788150687037359 125652; combined=32258, p1=302, p2=31883, p3=0, p4=0, p5=73, sr=96, sw=0, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--81566138-Z--
--72152e75-A--
[31/Aug/2026:07:32:04.784701 +0300] apUDxNmUuou1H8H2UKXEcgAAAMU 138.197.193.77 40658 127.0.0.1 7081
--72152e75-B--
POST /wp-login.php HTTP/1.1
Host: ajutam.ro
X-Real-IP: 138.197.193.77
X-Accel-Internal: /internal-nginx-static-location
Content-Length: 111
Accept: */*
User-Agent: Mozilla/5.0
Content-Type: application/x-www-form-urlencoded
Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818
--72152e75-F--
HTTP/1.1 403 Forbidden
Last-Modified: Fri, 01 May 2020 21:00:27 GMT
ETag: "31b-5a49c787f10c0"
Accept-Ranges: bytes
Content-Length: 795
Content-Type: text/html
--72152e75-H--
Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:07-32.138.197.193.77"] [severity "CRITICAL"] [tag "wp_core"]
Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"]
Action: Intercepted (phase 2)
Stopwatch: 1788150724724259 60501 (- - -)
Stopwatch2: 1788150724724259 60501; combined=59135, p1=268, p2=58241, p3=0, p4=0, p5=442, sr=108, sw=184, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--72152e75-Z--
--f9b03763-A--
[31/Aug/2026:07:34:13.196495 +0300] apUERW7fDIutYTwcPOkaqAAAAFg 207.154.219.81 45234 127.0.0.1 7081
--f9b03763-B--
POST /wp-login.php HTTP/1.1
Host: ajutam.ro
X-Real-IP: 207.154.219.81
X-Accel-Internal: /internal-nginx-static-location
Content-Length: 109
Accept: */*
User-Agent: Mozilla/5.0
Content-Type: application/x-www-form-urlencoded
Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818
--f9b03763-F--
HTTP/1.1 403 Forbidden
Last-Modified: Fri, 01 May 2020 21:00:27 GMT
ETag: "31b-5a49c787f10c0"
Accept-Ranges: bytes
Content-Length: 795
Content-Type: text/html
--f9b03763-H--
Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:07-34.207.154.219.81"] [severity "CRITICAL"] [tag "wp_core"]
Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"]
Action: Intercepted (phase 2)
Stopwatch: 1788150853132856 63723 (- - -)
Stopwatch2: 1788150853132856 63723; combined=61208, p1=416, p2=60009, p3=0, p4=0, p5=573, sr=161, sw=210, l=0, gc=0
Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/).
Server: Apache
Engine-Mode: "ENABLED"
--f9b03763-Z--