/var/log
NameSizeModeActions
audit/-0700rm
chrony/-0750rm
httpd/-0700rm
imunify360/-0700rm
imunify360_user_logs/-1777rm
mailman/-0775rm
mariadb/-0750rm
nginx/-0750rm
passenger/-0750rm
passenger-analytics/-0755rm
pcp/-0775rm
plesk/-0750rm
plesk-php71-fpm/-0750rm
plesk-php72-fpm/-0750rm
plesk-php73-fpm/-0750rm
plesk-php74-fpm/-0750rm
plesk-php80-fpm/-0750rm
plesk-php81-fpm/-0700rm
plesk-php82-fpm/-0700rm
plesk-php83-fpm/-0700rm
plesk-php84-fpm/-0700rm
plesk-php85-fpm/-0700rm
plesk-roundcube/-0750rm
private/-0700rm
qemu-ga/-0755rm
rear/-0755rm
sa/-0755rm
sssd/-0750rm
sw-cp-server/-0750rm
tuned/-0755rm
boot.log7170650editdlrm
btmp00660editdlrm
btmp-2026080100660editdlrm
cloud-init-output.log6317460650editdlrm
cloud-init.log7836250640editdlrm
cron9896800650editdlrm
cron-2026080964986800650editdlrm
cron-2026081664775660650editdlrm
cron-2026082364158050650editdlrm
cron-2026083062149190650editdlrm
dnf.librepo.log552840654editdlrm
dnf.librepo.log.110483940654editdlrm
dnf.librepo.log.210484860654editdlrm
dnf.librepo.log.310484940654editdlrm
dnf.librepo.log.410484120654editdlrm
dnf.log2782840654editdlrm
dnf.log-202410209929720654editdlrm
dnf.log-202410279090280654editdlrm
dnf.log.110485210654editdlrm
dnf.log.210484940654editdlrm
dnf.log.310485600654editdlrm
dnf.log.410484860654editdlrm
dnf.rpm.log8177090654editdlrm
dnf.rpm.log.110485600654editdlrm
dnf.rpm.log.210485610654editdlrm
dnf.rpm.log.310485720654editdlrm
dnf.rpm.log.410485500654editdlrm
firewalld00650editdlrm
firewalld-202410201860640editdlrm
firewalld-2024102700640editdlrm
hawkey.log10200654editdlrm
hawkey.log-2026080993600654editdlrm
hawkey.log-2026081688800654editdlrm
hawkey.log-2026082373800654editdlrm
hawkey.log-2026083088800654editdlrm
imav-deploy.log406170600editdlrm
imunify-agent-proxy.log4130570644editdlrm
lastlog29264240664editdlrm
lfd.log635200650editdlrm
lfd.log-20260830.gz377510650editdlrm
maillog4989340640editdlrm
maillog-2024102023370770640editdlrm
maillog-2024102727770850640editdlrm
maillog.processed117077680640editdlrm
maillog.processed.1.gz7121530640editdlrm
maillog.processed.2.gz7813820640editdlrm
maillog.processed.3.gz7019430640editdlrm
messages143177100650editdlrm
messages-202608093341730740650editdlrm
messages-202608161666763820650editdlrm
messages-20260823694460860650editdlrm
messages-20260830701807550650editdlrm
modsec_audit.log5460630654editdlrm
modsec_audit.log-20260825.gz4153380654editdlrm
modsec_audit.log-20260826.gz2095830654editdlrm
modsec_audit.log-20260827.gz6070290654editdlrm
modsec_audit.log-20260828.gz3206010654editdlrm
modsec_audit.log-20260829.gz6672030654editdlrm
modsec_audit.log-20260830.gz4968910654editdlrm
modsec_audit.log-20260831.gz5957370654editdlrm
mysql-slow.log00654editdlrm
mysqld.log64140650editdlrm
mysqld.log-20241020416393000644editdlrm
mysqld.log-2024102700644editdlrm
mysqld.log-20260831.gz111770650editdlrm
mysqld.log.1.gz8530600editdlrm
restic.log5005840644editdlrm
rkhunter.log1278690650editdlrm
rkhunter.log.old64060650editdlrm
sa-update.log1455800654editdlrm
sa-update.log-202605011454800654editdlrm
sa-update.log-202606011505630654editdlrm
sa-update.log-202607011454100654editdlrm
sa-update.log-202608011498530654editdlrm
secure3415140650editdlrm
secure-2026080917878710650editdlrm
secure-2026081618393510650editdlrm
secure-2026082318117160650editdlrm
secure-2026083019483790650editdlrm
spooler00650editdlrm
spooler-2026080900650editdlrm
spooler-2026081600650editdlrm
spooler-2026082300650editdlrm
spooler-2026083000650editdlrm
wtmp2956800664editdlrm
wtmp-2026040310494720664editdlrm
Edit: /var/log/modsec_audit.log (546063B)
--babed52b-A-- [31/Aug/2026:04:05:40.384691 +0300] apTTZCfaLSuAj0yzdueSCAAAAAQ 34.28.26.247 57832 127.0.0.1 7081 --babed52b-B-- GET /.git/config HTTP/1.1 Host: mediabuy.ro X-Real-IP: 34.28.26.247 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 Accept: */* --babed52b-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/7.3.33 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --babed52b-H-- Message: Warning. Matched phrase "/.git/config" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.git/config||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Matched phrase "/.git/config" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.git/config||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Message: Warning. String match "/.git/" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "656"] [id "77318034"] [msg "IM360 WAF: Blocked access to git folder||T:APACHE||MV:/.git/config||"] [severity "NOTICE"] [tag "service_i360custom"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "/.git/config" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.git/config||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "mediabuy.ro"] [uri "/.git/config"] [unique_id "apTTZCfaLSuAj0yzdueSCAAAAAQ"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "/.git/config" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.git/config||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "mediabuy.ro"] [uri "/.git/config"] [unique_id "apTTZCfaLSuAj0yzdueSCAAAAAQ"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.git/" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "656"] [id "77318034"] [msg "IM360 WAF: Blocked access to git folder||T:APACHE||MV:/.git/config||"] [severity "NOTICE"] [tag "service_i360custom"] [hostname "mediabuy.ro"] [uri "/.git/config"] [unique_id "apTTZCfaLSuAj0yzdueSCAAAAAQ"] Apache-Handler: proxy:unix:/var/www/vhosts/system/mediabuy.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788138340124313 260432 (- - -) Stopwatch2: 1788138340124313 260432; combined=37056, p1=264, p2=36711, p3=0, p4=0, p5=81, sr=96, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --babed52b-Z-- --5e40c140-A-- [31/Aug/2026:04:07:54.536517 +0300] apTT6tmUuou1H8H2UKW93wAAAMA 38.141.62.235 52668 127.0.0.1 7081 --5e40c140-B-- POST /contact HTTP/1.1 Host: ihelp.ro X-Real-IP: 38.141.62.235 X-Accel-Internal: /internal-nginx-static-location Content-Length: 593 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) obsidian/1.8.10 Chrome/132.0.6834.196 Electron/34.2.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7 Accept-Language: en-US,en;q=0.9 Accept-Encoding: gzip, deflate, br Referer: https://ihelp.ro/contact Sec-Fetch-Dest: document Sec-Fetch-Mode: same-origin Sec-Fetch-Site: same-origin Sec-Fetch-User: ?1 Cookie: csrfToken=oJYjXqYj%2BvnXD3zOpYXIHmZiMWQ3YjJiODRmNjE0NTY1YTA4ZjRjMmE2N2VmZmFiOTRkZjc1MzY%3D Content-Type: application/x-www-form-urlencoded Sec-CH-UA: "Google Chrome";v="132", "Chromium";v="132", "Not)A;Brand";v="24" Sec-CH-UA-Mobile: ?0 Sec-CH-UA-Platform: "Windows" --5e40c140-F-- HTTP/1.1 200 OK X-Powered-By: PHP/8.1.34 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache X-DEBUGKIT-ID: a3e26ee0-c901-459b-b9a7-f90c5167e904 Set-Cookie: PHPSESSID=dkmfrqmsubkgnffq9qrjg1ljlb; path=/; secure; HttpOnly; SameSite=Lax Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --5e40c140-H-- Message: Match of "rbl nxdomain.v2.rbl.imunify.com." against "TX:rbl_ip" required. [file "/etc/httpd/conf/modsecurity.d/rules/custom/011_i360_8_spam.conf"] [line "102"] [id "77141095"] [msg "IM360 WAF: Block spam in PrestaShop||T:APACHE||MVN:TX:rbl_ip||MV:04-07.38.141.62.235||"] [severity "CRITICAL"] [tag "other_apps"] Message: Matched phrase "/contact" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/011_i360_8_spam.conf"] [line "182"] [id "77142192"] [msg "IM360 WAF: Track spam attempts||T:APACHE||MVN:REQUEST_FILENAME||MV:/contact||"] [severity "NOTICE"] [tag "other_apps"] [tag "noshow"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788138474359394 177366 (- - -) Stopwatch2: 1788138474359394 177366; combined=63503, p1=392, p2=63035, p3=0, p4=0, p5=76, sr=133, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "DETECTION_ONLY" --5e40c140-Z-- --79955f09-A-- [31/Aug/2026:04:09:24.022367 +0300] apTUQ9mUuou1H8H2UKW95QAAAMw 64.227.61.137 59018 127.0.0.1 7081 --79955f09-B-- GET /?author=1 HTTP/1.1 Host: axapres.ro X-Real-IP: 64.227.61.137 X-Accel-Internal: /internal-nginx-static-location Accept: */* User-Agent: Mozilla/5.0 Accept-Encoding: gzip,deflate --79955f09-F-- HTTP/1.1 301 Moved Permanently X-Powered-By: PHP/7.1.33 X-Redirect-By: WordPress Location: https://axapres.ro/author/cosmin/ Content-Length: 0 Content-Type: text/html; charset=UTF-8 --79955f09-E-- --79955f09-H-- Message: Operator GE matched 1 at ARGS:author. [file "/etc/httpd/conf/modsecurity.d/rules/custom/007_i360_4_wordpress.conf"] [line "59"] [id "77140876"] [msg "IM360 WAF: Track WordPress users enumeration||MVN:ARGS:author||MV:1||T:APACHE||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Apache-Handler: proxy:unix:/var/www/vhosts/system/axapres.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788138563708456 314019 (- - -) Stopwatch2: 1788138563708456 314019; combined=4577, p1=369, p2=3978, p3=135, p4=10, p5=85, sr=124, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --79955f09-Z-- --f7be3f65-A-- [31/Aug/2026:04:09:24.511911 +0300] apTURNmUuou1H8H2UKW95gAAAM4 64.227.61.137 59024 127.0.0.1 7081 --f7be3f65-B-- GET /?author=2 HTTP/1.1 Host: axapres.ro X-Real-IP: 64.227.61.137 X-Accel-Internal: /internal-nginx-static-location Accept: */* User-Agent: Mozilla/5.0 Accept-Encoding: gzip,deflate --f7be3f65-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/7.1.33 Expires: Wed, 11 Jan 1984 05:00:00 GMT Cache-Control: no-cache, must-revalidate, max-age=0 Link: ; rel="https://api.w.org/" Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --f7be3f65-E-- --f7be3f65-H-- Message: Operator GE matched 1 at ARGS:author. [file "/etc/httpd/conf/modsecurity.d/rules/custom/007_i360_4_wordpress.conf"] [line "59"] [id "77140876"] [msg "IM360 WAF: Track WordPress users enumeration||MVN:ARGS:author||MV:2||T:APACHE||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Apache-Handler: proxy:unix:/var/www/vhosts/system/axapres.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788138564194746 317236 (- - -) Stopwatch2: 1788138564194746 317236; combined=3681, p1=276, p2=3241, p3=102, p4=25, p5=36, sr=91, sw=1, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --f7be3f65-Z-- --babed52b-A-- [31/Aug/2026:04:13:12.015280 +0300] apTVJ37glkZrdsSdRApHEgAAAIY 114.16.206.169 50522 127.0.0.1 7081 --babed52b-B-- POST /wp-login.php HTTP/1.1 Host: axapres.ro X-Real-IP: 114.16.206.169 X-Accel-Internal: /internal-nginx-static-location Content-Length: 125 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7 Accept-Language: ru-RU,ru;q=0.9,en-US;q=0.8,en;q=0.7 Cache-Control: max-age=0 Content-Type: application/x-www-form-urlencoded Origin: https://axapres.ro Referer: https://axapres.ro/wp-login.php Sec-Ch-Ua: "Not=A?Brand";v="99", "Google Chrome";v="151", "Chromium";v="151" Sec-Ch-Ua-Mobile: ?0 Sec-Ch-Ua-Platform: "Windows" Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: same-origin Sec-Fetch-User: ?1 Upgrade-Insecure-Requests: 1 User-Agent: 114.16.206.169 Accept-Encoding: gzip, deflate, br Cookie: wordpress_test_cookie=WP%20Cookie%20check --babed52b-F-- HTTP/1.1 403 Forbidden Content-Length: 199 Content-Type: text/html; charset=iso-8859-1 --babed52b-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:04-13.114.16.206.169"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Apache-Handler: proxy:unix:/var/www/vhosts/system/axapres.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788138791954546 60822 (- - -) Stopwatch2: 1788138791954546 60822; combined=59528, p1=347, p2=58593, p3=0, p4=0, p5=446, sr=155, sw=142, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --babed52b-Z-- --babed52b-A-- [31/Aug/2026:04:23:35.015749 +0300] apTXlm7fDIutYTwcPOkZJgAAAEI 216.73.217.35 47890 127.0.0.1 7081 --babed52b-B-- GET /img/ufo19w_831.php HTTP/1.1 Host: ihelp.ro X-Real-IP: 216.73.217.35 X-Accel-Internal: /internal-nginx-static-location accept: */* user-agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com) accept-encoding: gzip, br, zstd, deflate --babed52b-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.1.34 X-DEBUGKIT-ID: 7d4b16b8-cb24-43c4-928c-0552402eae7e Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --babed52b-H-- Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19w_831.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19w_831.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19w_831.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "ihelp.ro"] [uri "/img/ufo19w_831.php"] [unique_id "apTXlm7fDIutYTwcPOkZJgAAAEI"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19w_831.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] [hostname "ihelp.ro"] [uri "/img/ufo19w_831.php"] [unique_id "apTXlm7fDIutYTwcPOkZJgAAAEI"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788139414642301 373536 (- - -) Stopwatch2: 1788139414642301 373536; combined=37448, p1=377, p2=36945, p3=0, p4=0, p5=125, sr=195, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "DETECTION_ONLY" --babed52b-Z-- --c6dd5143-A-- [31/Aug/2026:04:23:47.105284 +0300] apTXotmUuou1H8H2UKW@EQAAANY 216.73.217.35 45342 127.0.0.1 7081 --c6dd5143-B-- GET /img/ufo19_shell_30207.php HTTP/1.1 Host: ihelp.ro X-Real-IP: 216.73.217.35 X-Accel-Internal: /internal-nginx-static-location accept: */* user-agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com) accept-encoding: gzip, br, zstd, deflate --c6dd5143-F-- HTTP/1.1 200 OK X-Powered-By: PHP/8.1.34 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --c6dd5143-H-- Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19_shell_30207.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19_shell_30207.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19_shell_30207.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "ihelp.ro"] [uri "/img/ufo19_shell_30207.php"] [unique_id "apTXotmUuou1H8H2UKW@EQAAANY"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19_shell_30207.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] [hostname "ihelp.ro"] [uri "/img/ufo19_shell_30207.php"] [unique_id "apTXotmUuou1H8H2UKW@EQAAANY"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788139426882432 222908 (- - -) Stopwatch2: 1788139426882432 222908; combined=34493, p1=311, p2=34118, p3=0, p4=0, p5=64, sr=152, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "DETECTION_ONLY" --c6dd5143-Z-- --f58f7b59-A-- [31/Aug/2026:04:24:09.085453 +0300] apTXuH7glkZrdsSdRApHIgAAAIw 216.73.217.35 37236 127.0.0.1 7081 --f58f7b59-B-- GET /img/ufo19p_20539.php HTTP/1.1 Host: ihelp.ro X-Real-IP: 216.73.217.35 X-Accel-Internal: /internal-nginx-static-location accept: */* user-agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com) accept-encoding: gzip, br, zstd, deflate --f58f7b59-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.1.34 X-DEBUGKIT-ID: cbe7d303-1d38-414a-b80f-c00c590637af Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --f58f7b59-H-- Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19p_20539.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19p_20539.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19p_20539.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "ihelp.ro"] [uri "/img/ufo19p_20539.php"] [unique_id "apTXuH7glkZrdsSdRApHIgAAAIw"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19p_20539.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] [hostname "ihelp.ro"] [uri "/img/ufo19p_20539.php"] [unique_id "apTXuH7glkZrdsSdRApHIgAAAIw"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788139448853010 232493 (- - -) Stopwatch2: 1788139448853010 232493; combined=33918, p1=329, p2=33463, p3=0, p4=0, p5=126, sr=116, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "DETECTION_ONLY" --f58f7b59-Z-- --a43cbc2c-A-- [31/Aug/2026:04:26:23.925576 +0300] apTYP37glkZrdsSdRApHJQAAAJA 103.119.98.55 38614 127.0.0.1 7081 --a43cbc2c-B-- GET /xmlrpc.php HTTP/1.1 Host: ajutam.ro X-Real-IP: 103.119.98.55 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36 Accept-Encoding: gzip, deflate, zstd Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en-US,en;q=0.5 --a43cbc2c-F-- HTTP/1.1 405 Method Not Allowed X-Powered-By: PHP/7.3.33 Allow: POST Transfer-Encoding: chunked Content-Type: text/plain;charset=UTF-8 --a43cbc2c-E-- --a43cbc2c-H-- Message: Warning. String match "xmlrpc.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "290"] [id "77141064"] [msg "IM360 WAF: CMS Recon Bot detected||MVN:REQUEST_FILENAME||T:APACHE||MV:/xmlrpc.php||RM:GET"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "xmlrpc.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "290"] [id "77141064"] [msg "IM360 WAF: CMS Recon Bot detected||MVN:REQUEST_FILENAME||T:APACHE||MV:/xmlrpc.php||RM:GET"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "ajutam.ro"] [uri "/xmlrpc.php"] [unique_id "apTYP37glkZrdsSdRApHJQAAAJA"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ajutam.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788139583595333 330336 (- - -) Stopwatch2: 1788139583595333 330336; combined=4228, p1=230, p2=3849, p3=95, p4=9, p5=45, sr=89, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --a43cbc2c-Z-- --854be211-A-- [31/Aug/2026:04:26:29.009001 +0300] apTYRNmUuou1H8H2UKW@GQAAAM4 103.119.98.55 45936 127.0.0.1 7081 --854be211-B-- GET /xmlrpc.php?rsd HTTP/1.1 Host: ajutam.ro X-Real-IP: 103.119.98.55 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36 Accept-Encoding: gzip, deflate, zstd Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en-US,en;q=0.5 --854be211-F-- HTTP/1.1 200 OK X-Powered-By: PHP/7.3.33 Transfer-Encoding: chunked Content-Type: text/xml; charset=UTF-8 --854be211-E-- --854be211-H-- Message: Warning. String match "xmlrpc.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "290"] [id "77141064"] [msg "IM360 WAF: CMS Recon Bot detected||MVN:REQUEST_FILENAME||T:APACHE||MV:/xmlrpc.php||RM:GET"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Message: Warning. Operator GT matched 0 at ARGS. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "529"] [id "77317945"] [msg "IM360 WAF: Really Simple Discovery to xmlrpc||MVN:ARGS||MV:1||T:APACHE||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "xmlrpc.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "290"] [id "77141064"] [msg "IM360 WAF: CMS Recon Bot detected||MVN:REQUEST_FILENAME||T:APACHE||MV:/xmlrpc.php||RM:GET"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "ajutam.ro"] [uri "/xmlrpc.php"] [unique_id "apTYRNmUuou1H8H2UKW@GQAAAM4"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Operator GT matched 0 at ARGS. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "529"] [id "77317945"] [msg "IM360 WAF: Really Simple Discovery to xmlrpc||MVN:ARGS||MV:1||T:APACHE||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "ajutam.ro"] [uri "/xmlrpc.php"] [unique_id "apTYRNmUuou1H8H2UKW@GQAAAM4"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ajutam.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788139588746104 262972 (- - -) Stopwatch2: 1788139588746104 262972; combined=3456, p1=206, p2=3083, p3=107, p4=8, p5=52, sr=76, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --854be211-Z-- --a722263d-A-- [31/Aug/2026:04:26:37.583403 +0300] apTYTdmUuou1H8H2UKW@IgAAAMk 216.73.217.35 45808 127.0.0.1 7081 --a722263d-B-- GET /img/ufo_fm.php HTTP/1.1 Host: ihelp.ro X-Real-IP: 216.73.217.35 X-Accel-Internal: /internal-nginx-static-location accept: */* user-agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com) accept-encoding: gzip, br, zstd, deflate --a722263d-F-- HTTP/1.1 200 OK X-Powered-By: PHP/8.1.34 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --a722263d-H-- Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo_fm.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo_fm.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo_fm.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "ihelp.ro"] [uri "/img/ufo_fm.php"] [unique_id "apTYTdmUuou1H8H2UKW@IgAAAMk"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo_fm.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] [hostname "ihelp.ro"] [uri "/img/ufo_fm.php"] [unique_id "apTYTdmUuou1H8H2UKW@IgAAAMk"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788139597529008 54458 (- - -) Stopwatch2: 1788139597529008 54458; combined=35584, p1=209, p2=35298, p3=0, p4=0, p5=76, sr=76, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "DETECTION_ONLY" --a722263d-Z-- --7140f16d-A-- [31/Aug/2026:04:26:42.025410 +0300] apTYUX7glkZrdsSdRApHMAAAAI0 216.73.217.35 45878 127.0.0.1 7081 --7140f16d-B-- GET /img/ufo19b_6243.php HTTP/1.1 Host: ihelp.ro X-Real-IP: 216.73.217.35 X-Accel-Internal: /internal-nginx-static-location accept: */* user-agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com) accept-encoding: gzip, br, zstd, deflate --7140f16d-F-- HTTP/1.1 200 OK X-Powered-By: PHP/8.1.34 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --7140f16d-H-- Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19b_6243.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19b_6243.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19b_6243.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "ihelp.ro"] [uri "/img/ufo19b_6243.php"] [unique_id "apTYUX7glkZrdsSdRApHMAAAAI0"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19b_6243.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] [hostname "ihelp.ro"] [uri "/img/ufo19b_6243.php"] [unique_id "apTYUX7glkZrdsSdRApHMAAAAI0"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788139601991037 34418 (- - -) Stopwatch2: 1788139601991037 34418; combined=32238, p1=241, p2=31949, p3=0, p4=0, p5=47, sr=105, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "DETECTION_ONLY" --7140f16d-Z-- --ecaa8622-A-- [31/Aug/2026:04:27:30.391857 +0300] apTYgtmUuou1H8H2UKW@LwAAAMo 216.73.217.35 58106 127.0.0.1 7081 --ecaa8622-B-- GET /img/ufo19c_20960.php HTTP/1.1 Host: ihelp.ro X-Real-IP: 216.73.217.35 X-Accel-Internal: /internal-nginx-static-location accept: */* user-agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com) accept-encoding: gzip, br, zstd, deflate --ecaa8622-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.1.34 X-DEBUGKIT-ID: b1af37c5-45e7-4aa1-8a6e-7aaa11de5adf Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --ecaa8622-H-- Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19c_20960.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19c_20960.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19c_20960.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "ihelp.ro"] [uri "/img/ufo19c_20960.php"] [unique_id "apTYgtmUuou1H8H2UKW@LwAAAMo"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19c_20960.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] [hostname "ihelp.ro"] [uri "/img/ufo19c_20960.php"] [unique_id "apTYgtmUuou1H8H2UKW@LwAAAMo"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788139650172543 219383 (- - -) Stopwatch2: 1788139650172543 219383; combined=33329, p1=252, p2=32961, p3=0, p4=0, p5=116, sr=96, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "DETECTION_ONLY" --ecaa8622-Z-- --f58f7b59-A-- [31/Aug/2026:04:27:30.425802 +0300] apTYgifaLSuAj0yzdueSFwAAABI 216.73.217.35 58118 127.0.0.1 7081 --f58f7b59-B-- GET /img/wso_ufo19.php HTTP/1.1 Host: ihelp.ro X-Real-IP: 216.73.217.35 X-Accel-Internal: /internal-nginx-static-location accept: */* user-agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com) accept-encoding: gzip, br, zstd, deflate --f58f7b59-F-- HTTP/1.1 200 OK X-Powered-By: PHP/8.1.34 Set-Cookie: 646109d53af43c125a937b56d9f339f0key=fac378ac3b3d3886829021b3309d4fd1 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --f58f7b59-H-- Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/wso_ufo19.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/wso_ufo19.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/wso_ufo19.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "ihelp.ro"] [uri "/img/wso_ufo19.php"] [unique_id "apTYgifaLSuAj0yzdueSFwAAABI"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/wso_ufo19.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] [hostname "ihelp.ro"] [uri "/img/wso_ufo19.php"] [unique_id "apTYgifaLSuAj0yzdueSFwAAABI"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788139650384706 41143 (- - -) Stopwatch2: 1788139650384706 41143; combined=32055, p1=231, p2=31760, p3=0, p4=0, p5=63, sr=90, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "DETECTION_ONLY" --f58f7b59-Z-- --29e80a3f-A-- [31/Aug/2026:04:28:29.968365 +0300] apTYvX7glkZrdsSdRApHPAAAAIs 216.73.217.35 43546 127.0.0.1 7081 --29e80a3f-B-- GET /img/ufo19_20982.php HTTP/1.1 Host: ihelp.ro X-Real-IP: 216.73.217.35 X-Accel-Internal: /internal-nginx-static-location accept: */* user-agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com) accept-encoding: gzip, br, zstd, deflate --29e80a3f-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.1.34 X-DEBUGKIT-ID: c3c26b04-0f45-43b9-9708-0f7e4d2dc127 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --29e80a3f-H-- Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19_20982.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19_20982.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19_20982.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "ihelp.ro"] [uri "/img/ufo19_20982.php"] [unique_id "apTYvX7glkZrdsSdRApHPAAAAIs"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19_20982.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] [hostname "ihelp.ro"] [uri "/img/ufo19_20982.php"] [unique_id "apTYvX7glkZrdsSdRApHPAAAAIs"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788139709702642 265775 (- - -) Stopwatch2: 1788139709702642 265775; combined=34921, p1=222, p2=34628, p3=0, p4=0, p5=71, sr=84, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "DETECTION_ONLY" --29e80a3f-Z-- --d0b8c902-A-- [31/Aug/2026:04:30:40.728783 +0300] apTZQNmUuou1H8H2UKW@PwAAAM0 120.133.60.156 58146 127.0.0.1 7081 --d0b8c902-B-- POST /wp-login.php HTTP/1.1 Host: axapres.ro X-Real-IP: 120.133.60.156 X-Accel-Internal: /internal-nginx-static-location Content-Length: 110 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8 Accept-Language: en-US,en;q=0.5 Content-Type: application/x-www-form-urlencoded Cookie: wordpress_test_cookie=WP+Cookie+check Origin: https://axapres.ro Referer: https://axapres.ro/wp-login.php --d0b8c902-F-- HTTP/1.1 403 Forbidden Content-Length: 199 Content-Type: text/html; charset=iso-8859-1 --d0b8c902-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:04-30.120.133.60.156"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Apache-Handler: proxy:unix:/var/www/vhosts/system/axapres.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788139840668086 60755 (- - -) Stopwatch2: 1788139840668086 60755; combined=59641, p1=324, p2=58588, p3=0, p4=0, p5=522, sr=102, sw=207, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --d0b8c902-Z-- --2d6c6e20-A-- [31/Aug/2026:04:31:28.347937 +0300] apTZcNmUuou1H8H2UKW@QwAAANc 43.156.13.166 55200 127.0.0.1 7081 --2d6c6e20-B-- POST /wp-login.php HTTP/1.1 Host: axapres.ro X-Real-IP: 43.156.13.166 X-Accel-Internal: /internal-nginx-static-location Content-Length: 104 Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.36 Edg/142.0.0.0 Accept-Encoding: gzip, deflate Accept: */* Cookie: wordpress_test_cookie=WP+Cookie+check --2d6c6e20-F-- HTTP/1.1 403 Forbidden Content-Length: 199 Content-Type: text/html; charset=iso-8859-1 --2d6c6e20-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:04-31.43.156.13.166"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Apache-Handler: proxy:unix:/var/www/vhosts/system/axapres.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788139888286034 62057 (- - -) Stopwatch2: 1788139888286034 62057; combined=60357, p1=423, p2=58533, p3=0, p4=0, p5=1022, sr=152, sw=379, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --2d6c6e20-Z-- --a43cbc2c-A-- [31/Aug/2026:04:32:01.848761 +0300] apTZkSfaLSuAj0yzdueSGQAAAAA 207.154.219.81 56588 127.0.0.1 7081 --a43cbc2c-B-- GET /?author=1 HTTP/1.1 Host: ajutam.ro X-Real-IP: 207.154.219.81 X-Accel-Internal: /internal-nginx-static-location Accept: */* User-Agent: Mozilla/5.0 Accept-Encoding: gzip,deflate --a43cbc2c-F-- HTTP/1.1 301 Moved Permanently X-Powered-By: PHP/7.3.33 X-Redirect-By: WordPress Location: https://ajutam.ro/author/admin/ Content-Length: 0 Content-Type: text/html; charset=UTF-8 --a43cbc2c-E-- --a43cbc2c-H-- Message: Operator GE matched 1 at ARGS:author. [file "/etc/httpd/conf/modsecurity.d/rules/custom/007_i360_4_wordpress.conf"] [line "59"] [id "77140876"] [msg "IM360 WAF: Track WordPress users enumeration||MVN:ARGS:author||MV:1||T:APACHE||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ajutam.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788139921325196 523635 (- - -) Stopwatch2: 1788139921325196 523635; combined=5796, p1=620, p2=4969, p3=144, p4=13, p5=49, sr=221, sw=1, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --a43cbc2c-Z-- --1cd0f101-A-- [31/Aug/2026:04:32:02.418495 +0300] apTZkdmUuou1H8H2UKW@RgAAAME 207.154.219.81 56598 127.0.0.1 7081 --1cd0f101-B-- GET /?author=2 HTTP/1.1 Host: ajutam.ro X-Real-IP: 207.154.219.81 X-Accel-Internal: /internal-nginx-static-location Accept: */* User-Agent: Mozilla/5.0 Accept-Encoding: gzip,deflate --1cd0f101-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/7.3.33 Expires: Wed, 11 Jan 1984 05:00:00 GMT Cache-Control: no-cache, must-revalidate, max-age=0, no-store, private Link: ; rel="https://api.w.org/" X-TEC-API-VERSION: v1 X-TEC-API-ROOT: https://ajutam.ro/wp-json/tribe/events/v1/ X-TEC-API-ORIGIN: https://ajutam.ro Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --1cd0f101-E-- --1cd0f101-H-- Message: Operator GE matched 1 at ARGS:author. [file "/etc/httpd/conf/modsecurity.d/rules/custom/007_i360_4_wordpress.conf"] [line "59"] [id "77140876"] [msg "IM360 WAF: Track WordPress users enumeration||MVN:ARGS:author||MV:2||T:APACHE||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ajutam.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788139921885045 533628 (- - -) Stopwatch2: 1788139921885045 533628; combined=5354, p1=336, p2=4786, p3=174, p4=13, p5=45, sr=150, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --1cd0f101-Z-- --a23cf107-A-- [31/Aug/2026:04:37:14.207976 +0300] apTaydmUuou1H8H2UKW@WwAAANM 137.184.233.53 55776 127.0.0.1 7081 --a23cf107-B-- GET /?author=1 HTTP/1.1 Host: chania24.taxi X-Real-IP: 137.184.233.53 Accept: */* User-Agent: Mozilla/5.0 Accept-Encoding: gzip,deflate --a23cf107-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/7.4.33 Expires: Wed, 11 Jan 1984 05:00:00 GMT Cache-Control: no-cache, must-revalidate, max-age=0 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --a23cf107-E-- --a23cf107-H-- Message: Operator GE matched 1 at ARGS:author. [file "/etc/httpd/conf/modsecurity.d/rules/custom/007_i360_4_wordpress.conf"] [line "59"] [id "77140876"] [msg "IM360 WAF: Track WordPress users enumeration||MVN:ARGS:author||MV:1||T:APACHE||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Apache-Handler: proxy:unix:/var/www/vhosts/system/chania24.taxi/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788140233624027 584021 (- - -) Stopwatch2: 1788140233624027 584021; combined=9784, p1=957, p2=8671, p3=96, p4=21, p5=39, sr=98, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --a23cf107-Z-- --a9d8211b-A-- [31/Aug/2026:04:42:02.408404 +0300] apTb6tmUuou1H8H2UKW@dAAAAM8 163.61.60.30 52118 127.0.0.1 7081 --a9d8211b-B-- POST /wp-login.php HTTP/1.1 Host: axapres.ro X-Real-IP: 163.61.60.30 X-Accel-Internal: /internal-nginx-static-location Content-Length: 117 Cookie: wordpress_test_cookie=WP+Cookie+check Content-Type: application/x-www-form-urlencoded Accept-Encoding: gzip, deflate Accept: */* User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.36 Edg/142.0.0.0 --a9d8211b-F-- HTTP/1.1 403 Forbidden Content-Length: 199 Content-Type: text/html; charset=iso-8859-1 --a9d8211b-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:04-42.163.61.60.30"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Apache-Handler: proxy:unix:/var/www/vhosts/system/axapres.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788140522344297 64181 (- - -) Stopwatch2: 1788140522344297 64181; combined=62659, p1=403, p2=61315, p3=0, p4=0, p5=696, sr=139, sw=245, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --a9d8211b-Z-- --6515330e-A-- [31/Aug/2026:04:43:17.898857 +0300] apTcNdmUuou1H8H2UKW@dgAAANg 59.125.102.226 34186 127.0.0.1 7081 --6515330e-B-- POST /wp-login.php HTTP/1.1 Host: axapres.ro X-Real-IP: 59.125.102.226 X-Accel-Internal: /internal-nginx-static-location Content-Length: 126 Accept-Encoding: gzip, deflate Content-Type: application/x-www-form-urlencoded Accept: */* User-Agent: Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.36 Edg/142.0.0.0 Cookie: wordpress_test_cookie=WP+Cookie+check --6515330e-F-- HTTP/1.1 403 Forbidden Content-Length: 199 Content-Type: text/html; charset=iso-8859-1 --6515330e-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:04-43.59.125.102.226"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Apache-Handler: proxy:unix:/var/www/vhosts/system/axapres.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788140597829870 69103 (- - -) Stopwatch2: 1788140597829870 69103; combined=59973, p1=1374, p2=57768, p3=0, p4=0, p5=559, sr=633, sw=272, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --6515330e-Z-- --02b7aa2e-A-- [31/Aug/2026:04:49:57.989304 +0300] apTdxdmUuou1H8H2UKW@mQAAAM4 137.184.225.216 46128 127.0.0.1 7081 --02b7aa2e-B-- POST /wp-login.php HTTP/1.1 Host: axapres.ro X-Real-IP: 137.184.225.216 X-Accel-Internal: /internal-nginx-static-location Content-Length: 108 Accept-Encoding: gzip, deflate Accept: */* User-Agent: Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/140.0.0.0 Safari/537.36 Edg/140.0.0.0 Cookie: wordpress_test_cookie=WP+Cookie+check Content-Type: application/x-www-form-urlencoded --02b7aa2e-F-- HTTP/1.1 403 Forbidden Content-Length: 199 Content-Type: text/html; charset=iso-8859-1 --02b7aa2e-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:04-49.137.184.225.216"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Apache-Handler: proxy:unix:/var/www/vhosts/system/axapres.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788140997929755 59615 (- - -) Stopwatch2: 1788140997929755 59615; combined=57486, p1=443, p2=56401, p3=0, p4=0, p5=460, sr=189, sw=182, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --02b7aa2e-Z-- --c959a14c-A-- [31/Aug/2026:05:13:04.903603 +0300] apTjMH7glkZrdsSdRApH0QAAAII 168.144.111.201 53912 127.0.0.1 7081 --c959a14c-B-- POST /wp-json/batch/v1 HTTP/1.1 Host: chania24.taxi X-Real-IP: 168.144.111.201 Content-Length: 15 sec-ch-ua: "Not_A Brand";v="8", "Chromium";v="120", "Google Chrome";v="120" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "macOS" Upgrade-Insecure-Requests: 1 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 Chrome/119.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8 Sec-Fetch-Site: none Sec-Fetch-Mode: navigate Sec-Fetch-User: ?1 Sec-Fetch-Dest: document Accept-Encoding: gzip, deflate, br Accept-Language: id-ID,id;q=0.9,en-US;q=0.8,en;q=0.7 Cache-Control: max-age=0 DNT: 1 Content-Type: application/json --c959a14c-F-- HTTP/1.1 403 Forbidden X-Powered-By: PHP/7.4.33 Pragma: no-cache Cache-Control: no-cache, must-revalidate, private, max-age=0 Expires: Sat, 26 Jul 1997 05:00:00 GMT Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --c959a14c-H-- Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Apache-Handler: proxy:unix:/var/www/vhosts/system/chania24.taxi/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788142384794114 109625 (- - -) Stopwatch2: 1788142384794114 109625; combined=6654, p1=311, p2=5966, p3=0, p4=0, p5=377, sr=131, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --c959a14c-Z-- --ac894c49-A-- [31/Aug/2026:05:13:05.187346 +0300] apTjMdmUuou1H8H2UKW-dgAAAMM 168.144.111.201 53928 127.0.0.1 7081 --ac894c49-B-- POST /?rest_route=/batch/v1 HTTP/1.1 Host: chania24.taxi X-Real-IP: 168.144.111.201 Content-Length: 16 sec-ch-ua: "Not_A Brand";v="8", "Chromium";v="120", "Google Chrome";v="120" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "macOS" Upgrade-Insecure-Requests: 1 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/121.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8 Sec-Fetch-Site: none Sec-Fetch-Mode: navigate Sec-Fetch-User: ?1 Sec-Fetch-Dest: document Accept-Encoding: gzip, deflate, br Accept-Language: id-ID,id;q=0.9,en-US;q=0.8,en;q=0.7 Cache-Control: max-age=0 DNT: 1 Content-Type: application/json --ac894c49-F-- HTTP/1.1 403 Forbidden X-Powered-By: PHP/7.4.33 Pragma: no-cache Cache-Control: no-cache, must-revalidate, private, max-age=0 Expires: Sat, 26 Jul 1997 05:00:00 GMT Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --ac894c49-E-- --ac894c49-H-- Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G:rest_route=/batch/v1& P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Apache-Handler: proxy:unix:/var/www/vhosts/system/chania24.taxi/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788142385099814 87621 (- - -) Stopwatch2: 1788142385099814 87621; combined=5538, p1=521, p2=4521, p3=181, p4=23, p5=291, sr=316, sw=1, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --ac894c49-Z-- --d5bd142f-A-- [31/Aug/2026:05:20:55.096407 +0300] apTlB9mUuou1H8H2UKW-qwAAAMo 23.94.77.36 53756 127.0.0.1 7081 --d5bd142f-B-- GET /american-humane-association/ HTTP/1.1 Host: ajutam.ro X-Real-IP: 23.94.77.36 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html) Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7 Accept-Language: en-US,en;q=0.9 Accept-Encoding: gzip, deflate, br Referer: http://ajutam.ro/american-humane-association/ --d5bd142f-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --d5bd142f-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "81"] [id "33311"] [msg "IM360 WAF: Found crawler not in whitelist||T:APACHE||User-Agent:Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)||MV:05-20.23.94.77.36"] [severity "CRITICAL"] [tag "service_i360"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788142855061911 34579 (- - -) Stopwatch2: 1788142855061911 34579; combined=28428, p1=352, p2=27455, p3=0, p4=0, p5=620, sr=117, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --d5bd142f-Z-- --7140f16d-A-- [31/Aug/2026:05:20:57.331289 +0300] apTlCSfaLSuAj0yzdueSVwAAABI 191.101.110.76 46040 127.0.0.1 7081 --7140f16d-B-- GET /american-humane-association/ HTTP/1.1 Host: ajutam.ro X-Real-IP: 191.101.110.76 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html) Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7 Accept-Language: en-US,en;q=0.9 Accept-Encoding: gzip, deflate, br --7140f16d-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --7140f16d-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "81"] [id "33311"] [msg "IM360 WAF: Found crawler not in whitelist||T:APACHE||User-Agent:Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)||MV:05-20.191.101.110.76"] [severity "CRITICAL"] [tag "service_i360"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788142857299179 32191 (- - -) Stopwatch2: 1788142857299179 32191; combined=30471, p1=203, p2=29994, p3=0, p4=0, p5=274, sr=83, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --7140f16d-Z-- --76e14709-A-- [31/Aug/2026:05:20:59.413038 +0300] apTlC9mUuou1H8H2UKW-rAAAANE 172.245.60.137 46056 127.0.0.1 7081 --76e14709-B-- GET /american-humane-association/ HTTP/1.1 Host: ajutam.ro X-Real-IP: 172.245.60.137 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html) Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7 Accept-Language: en-US,en;q=0.9 Accept-Encoding: gzip, deflate, br --76e14709-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --76e14709-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "81"] [id "33311"] [msg "IM360 WAF: Found crawler not in whitelist||T:APACHE||User-Agent:Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)||MV:05-20.172.245.60.137"] [severity "CRITICAL"] [tag "service_i360"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788142859378974 34141 (- - -) Stopwatch2: 1788142859378974 34141; combined=31124, p1=351, p2=30401, p3=0, p4=0, p5=371, sr=149, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --76e14709-Z-- --99b5b32b-A-- [31/Aug/2026:05:21:01.635949 +0300] apTlDdmUuou1H8H2UKW-rQAAAMI 172.245.60.182 46066 127.0.0.1 7081 --99b5b32b-B-- GET /american-humane-association/ HTTP/1.1 Host: ajutam.ro X-Real-IP: 172.245.60.182 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html) Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7 Accept-Language: en-US,en;q=0.9 Accept-Encoding: gzip, deflate, br --99b5b32b-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --99b5b32b-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "81"] [id "33311"] [msg "IM360 WAF: Found crawler not in whitelist||T:APACHE||User-Agent:Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)||MV:05-21.172.245.60.182"] [severity "CRITICAL"] [tag "service_i360"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788142861599538 36561 (- - -) Stopwatch2: 1788142861599538 36561; combined=33943, p1=901, p2=28095, p3=0, p4=0, p5=4947, sr=123, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --99b5b32b-Z-- --5155e508-A-- [31/Aug/2026:05:23:15.755773 +0300] apTlk37glkZrdsSdRApH6QAAAIM 23.94.77.36 44080 127.0.0.1 7081 --5155e508-B-- GET /american-humane-association/ HTTP/1.1 Host: ajutam.ro X-Real-IP: 23.94.77.36 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html) Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7 Accept-Language: en-US,en;q=0.9 Accept-Encoding: gzip, deflate, br Referer: http://ajutam.ro/american-humane-association/ --5155e508-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --5155e508-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "81"] [id "33311"] [msg "IM360 WAF: Found crawler not in whitelist||T:APACHE||User-Agent:Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)||MV:05-23.23.94.77.36"] [severity "CRITICAL"] [tag "service_i360"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788142995723174 32676 (- - -) Stopwatch2: 1788142995723174 32676; combined=30498, p1=940, p2=29236, p3=0, p4=0, p5=322, sr=166, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --5155e508-Z-- --6ca34342-A-- [31/Aug/2026:05:23:17.718481 +0300] apTlldmUuou1H8H2UKW-tAAAAME 198.46.222.253 44094 127.0.0.1 7081 --6ca34342-B-- GET /american-humane-association/ HTTP/1.1 Host: ajutam.ro X-Real-IP: 198.46.222.253 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html) Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7 Accept-Language: en-US,en;q=0.9 Accept-Encoding: gzip, deflate, br --6ca34342-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --6ca34342-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "81"] [id "33311"] [msg "IM360 WAF: Found crawler not in whitelist||T:APACHE||User-Agent:Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)||MV:05-23.198.46.222.253"] [severity "CRITICAL"] [tag "service_i360"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788142997685518 33028 (- - -) Stopwatch2: 1788142997685518 33028; combined=31152, p1=703, p2=30148, p3=0, p4=0, p5=301, sr=135, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --6ca34342-Z-- --d9179761-A-- [31/Aug/2026:05:23:19.926164 +0300] apTll9mUuou1H8H2UKW-tQAAAMM 191.101.110.188 44110 127.0.0.1 7081 --d9179761-B-- GET /american-humane-association/ HTTP/1.1 Host: ajutam.ro X-Real-IP: 191.101.110.188 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html) Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7 Accept-Language: en-US,en;q=0.9 Accept-Encoding: gzip, deflate, br --d9179761-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --d9179761-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "81"] [id "33311"] [msg "IM360 WAF: Found crawler not in whitelist||T:APACHE||User-Agent:Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)||MV:05-23.191.101.110.188"] [severity "CRITICAL"] [tag "service_i360"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788142999892198 34058 (- - -) Stopwatch2: 1788142999892198 34058; combined=30824, p1=503, p2=29932, p3=0, p4=0, p5=388, sr=233, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --d9179761-Z-- --3f9d4850-A-- [31/Aug/2026:05:23:22.078530 +0300] apTlmtmUuou1H8H2UKW-tgAAAMc 191.101.110.60 44122 127.0.0.1 7081 --3f9d4850-B-- GET /american-humane-association/ HTTP/1.1 Host: ajutam.ro X-Real-IP: 191.101.110.60 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html) Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7 Accept-Language: en-US,en;q=0.9 Accept-Encoding: gzip, deflate, br --3f9d4850-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --3f9d4850-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "81"] [id "33311"] [msg "IM360 WAF: Found crawler not in whitelist||T:APACHE||User-Agent:Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)||MV:05-23.191.101.110.60"] [severity "CRITICAL"] [tag "service_i360"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788143002046367 32234 (- - -) Stopwatch2: 1788143002046367 32234; combined=29508, p1=549, p2=28606, p3=0, p4=0, p5=352, sr=252, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --3f9d4850-Z-- --78ba2517-A-- [31/Aug/2026:05:36:15.636204 +0300] apTon37glkZrdsSdRApIJQAAAJI 207.154.219.81 58222 127.0.0.1 7081 --78ba2517-B-- POST /wp-login.php HTTP/1.1 Host: ajutam.ro X-Real-IP: 207.154.219.81 X-Accel-Internal: /internal-nginx-static-location Content-Length: 105 Accept: */* User-Agent: Mozilla/5.0 Content-Type: application/x-www-form-urlencoded Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818 --78ba2517-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --78ba2517-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:05-36.207.154.219.81"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788143775573307 62953 (- - -) Stopwatch2: 1788143775573307 62953; combined=61208, p1=461, p2=60158, p3=0, p4=0, p5=445, sr=191, sw=144, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --78ba2517-Z-- --eadd4674-A-- [31/Aug/2026:05:36:17.160029 +0300] apToodmUuou1H8H2UKXAIgAAANI 35.254.196.10 58238 127.0.0.1 7081 --eadd4674-B-- GET /.git/config HTTP/1.1 Host: breveleyendatequila.com X-Real-IP: 35.254.196.10 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 Accept: */* --eadd4674-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --eadd4674-E-- --eadd4674-H-- Message: Warning. Matched phrase "/.git/config" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.git/config||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Matched phrase "/.git/config" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.git/config||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Message: Warning. String match "/.git/" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "656"] [id "77318034"] [msg "IM360 WAF: Blocked access to git folder||T:APACHE||MV:/.git/config||"] [severity "NOTICE"] [tag "service_i360custom"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "/.git/config" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.git/config||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "breveleyendatequila.com"] [uri "/.git/config"] [unique_id "apToodmUuou1H8H2UKXAIgAAANI"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "/.git/config" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.git/config||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "breveleyendatequila.com"] [uri "/.git/config"] [unique_id "apToodmUuou1H8H2UKXAIgAAANI"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.git/" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "656"] [id "77318034"] [msg "IM360 WAF: Blocked access to git folder||T:APACHE||MV:/.git/config||"] [severity "NOTICE"] [tag "service_i360custom"] [hostname "breveleyendatequila.com"] [uri "/.git/config"] [unique_id "apToodmUuou1H8H2UKXAIgAAANI"] Stopwatch: 1788143777122473 37602 (- - -) Stopwatch2: 1788143777122473 37602; combined=36081, p1=344, p2=35560, p3=111, p4=8, p5=58, sr=105, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --eadd4674-Z-- --36ef4919-A-- [31/Aug/2026:05:38:38.149143 +0300] apTpLtmUuou1H8H2UKXAKQAAAMs 207.154.219.81 45162 127.0.0.1 7081 --36ef4919-B-- POST /wp-login.php HTTP/1.1 Host: ajutam.ro X-Real-IP: 207.154.219.81 X-Accel-Internal: /internal-nginx-static-location Content-Length: 108 Accept: */* User-Agent: Mozilla/5.0 Content-Type: application/x-www-form-urlencoded Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818 --36ef4919-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --36ef4919-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "42"] [id "33302"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:1"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788143918146738 2492 (- - -) Stopwatch2: 1788143918146738 2492; combined=713, p1=389, p2=95, p3=0, p4=0, p5=229, sr=111, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --36ef4919-Z-- --67a23e1c-A-- [31/Aug/2026:05:41:44.547918 +0300] apTp6NmUuou1H8H2UKXALwAAANI 207.154.219.81 56512 127.0.0.1 7081 --67a23e1c-B-- POST /wp-login.php HTTP/1.1 Host: ajutam.ro X-Real-IP: 207.154.219.81 X-Accel-Internal: /internal-nginx-static-location Content-Length: 108 Accept: */* User-Agent: Mozilla/5.0 Content-Type: application/x-www-form-urlencoded Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818 --67a23e1c-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --67a23e1c-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:05-41.207.154.219.81"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788144104480666 67392 (- - -) Stopwatch2: 1788144104480666 67392; combined=61003, p1=275, p2=59322, p3=0, p4=0, p5=1220, sr=115, sw=186, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --67a23e1c-Z-- --f58f7b59-A-- [31/Aug/2026:05:44:30.282253 +0300] apTqjm7fDIutYTwcPOkZtAAAAFY 138.197.193.77 48556 127.0.0.1 7081 --f58f7b59-B-- GET /?author=1 HTTP/1.1 Host: ajutam.ro X-Real-IP: 138.197.193.77 X-Accel-Internal: /internal-nginx-static-location Accept: */* User-Agent: Mozilla/5.0 Accept-Encoding: gzip,deflate --f58f7b59-F-- HTTP/1.1 301 Moved Permanently X-Powered-By: PHP/7.3.33 X-Redirect-By: WordPress Location: https://ajutam.ro/author/admin/ Content-Length: 0 Content-Type: text/html; charset=UTF-8 --f58f7b59-E-- --f58f7b59-H-- Message: Operator GE matched 1 at ARGS:author. [file "/etc/httpd/conf/modsecurity.d/rules/custom/007_i360_4_wordpress.conf"] [line "59"] [id "77140876"] [msg "IM360 WAF: Track WordPress users enumeration||MVN:ARGS:author||MV:1||T:APACHE||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ajutam.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788144270007605 274701 (- - -) Stopwatch2: 1788144270007605 274701; combined=3452, p1=277, p2=3042, p3=93, p4=8, p5=32, sr=105, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --f58f7b59-Z-- --e8f2fd53-A-- [31/Aug/2026:05:44:30.831609 +0300] apTqjtmUuou1H8H2UKXANwAAAMQ 138.197.193.77 48558 127.0.0.1 7081 --e8f2fd53-B-- GET /?author=2 HTTP/1.1 Host: ajutam.ro X-Real-IP: 138.197.193.77 X-Accel-Internal: /internal-nginx-static-location Accept: */* User-Agent: Mozilla/5.0 Accept-Encoding: gzip,deflate --e8f2fd53-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/7.3.33 Expires: Wed, 11 Jan 1984 05:00:00 GMT Cache-Control: no-cache, must-revalidate, max-age=0, no-store, private Link: ; rel="https://api.w.org/" X-TEC-API-VERSION: v1 X-TEC-API-ROOT: https://ajutam.ro/wp-json/tribe/events/v1/ X-TEC-API-ORIGIN: https://ajutam.ro Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --e8f2fd53-E-- --e8f2fd53-H-- Message: Operator GE matched 1 at ARGS:author. [file "/etc/httpd/conf/modsecurity.d/rules/custom/007_i360_4_wordpress.conf"] [line "59"] [id "77140876"] [msg "IM360 WAF: Track WordPress users enumeration||MVN:ARGS:author||MV:2||T:APACHE||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ajutam.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788144270480910 350830 (- - -) Stopwatch2: 1788144270480910 350830; combined=3307, p1=247, p2=2869, p3=141, p4=11, p5=38, sr=106, sw=1, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --e8f2fd53-Z-- --29e80a3f-A-- [31/Aug/2026:05:47:47.636727 +0300] apTrUyfaLSuAj0yzdueSbgAAABg 207.154.219.81 33108 127.0.0.1 7081 --29e80a3f-B-- POST /wp-login.php HTTP/1.1 Host: ajutam.ro X-Real-IP: 207.154.219.81 X-Accel-Internal: /internal-nginx-static-location Content-Length: 110 Accept: */* User-Agent: Mozilla/5.0 Content-Type: application/x-www-form-urlencoded Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818 --29e80a3f-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --29e80a3f-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:05-47.207.154.219.81"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788144467563740 73081 (- - -) Stopwatch2: 1788144467563740 73081; combined=65983, p1=471, p2=64003, p3=0, p4=0, p5=1110, sr=196, sw=399, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --29e80a3f-Z-- --f05c8c30-A-- [31/Aug/2026:05:53:41.323477 +0300] apTstdmUuou1H8H2UKXAngAAAMQ 207.154.219.81 40972 127.0.0.1 7081 --f05c8c30-B-- POST /wp-login.php HTTP/1.1 Host: ajutam.ro X-Real-IP: 207.154.219.81 X-Accel-Internal: /internal-nginx-static-location Content-Length: 111 Accept: */* User-Agent: Mozilla/5.0 Content-Type: application/x-www-form-urlencoded Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818 --f05c8c30-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --f05c8c30-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:05-53.207.154.219.81"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788144821261955 61784 (- - -) Stopwatch2: 1788144821261955 61784; combined=60219, p1=272, p2=58828, p3=0, p4=0, p5=878, sr=88, sw=241, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --f05c8c30-Z-- --e0fb7e1c-A-- [31/Aug/2026:05:59:45.339900 +0300] apTuIdmUuou1H8H2UKXArgAAAMo 207.154.219.81 41674 127.0.0.1 7081 --e0fb7e1c-B-- POST /wp-login.php HTTP/1.1 Host: ajutam.ro X-Real-IP: 207.154.219.81 X-Accel-Internal: /internal-nginx-static-location Content-Length: 108 Accept: */* User-Agent: Mozilla/5.0 Content-Type: application/x-www-form-urlencoded Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818 --e0fb7e1c-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --e0fb7e1c-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:05-59.207.154.219.81"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788145185280305 59700 (- - -) Stopwatch2: 1788145185280305 59700; combined=58222, p1=316, p2=57354, p3=0, p4=0, p5=422, sr=94, sw=130, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --e0fb7e1c-Z-- --6c43d622-A-- [31/Aug/2026:06:03:49.932688 +0300] apTvFX7glkZrdsSdRApIZgAAAI4 35.81.82.181 59344 127.0.0.1 7081 --6c43d622-B-- GET /img/ufo_fm.php HTTP/1.1 Host: ihelp.ro X-Real-IP: 35.81.82.181 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: https://ihelp.ro/ Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cookie: csrfToken=mPvE2njAl36rBABWojKSTDJjOWZkNjQ2MTA5NmVkM2IzY2QxMmFmM2Q3YjE2YjJiMTE4ZjY5ZWM%3D --6c43d622-F-- HTTP/1.1 200 OK X-Powered-By: PHP/8.1.34 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --6c43d622-H-- Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo_fm.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo_fm.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo_fm.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "ihelp.ro"] [uri "/img/ufo_fm.php"] [unique_id "apTvFX7glkZrdsSdRApIZgAAAI4"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo_fm.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] [hostname "ihelp.ro"] [uri "/img/ufo_fm.php"] [unique_id "apTvFX7glkZrdsSdRApIZgAAAI4"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788145429918353 14396 (- - -) Stopwatch2: 1788145429918353 14396; combined=8145, p1=285, p2=7792, p3=0, p4=0, p5=68, sr=103, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "DETECTION_ONLY" --6c43d622-Z-- --21438830-A-- [31/Aug/2026:06:03:50.375794 +0300] apTvFtmUuou1H8H2UKXAxQAAAMs 35.81.82.181 59440 127.0.0.1 7081 --21438830-B-- GET /img/wso_ufo19.php HTTP/1.1 Host: ihelp.ro X-Real-IP: 35.81.82.181 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: https://ihelp.ro/ Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cookie: csrfToken=mPvE2njAl36rBABWojKSTDJjOWZkNjQ2MTA5NmVkM2IzY2QxMmFmM2Q3YjE2YjJiMTE4ZjY5ZWM%3D --21438830-F-- HTTP/1.1 200 OK X-Powered-By: PHP/8.1.34 Set-Cookie: 646109d53af43c125a937b56d9f339f0key=7a804c056f2d36c3c44be5f3d648e096 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --21438830-H-- Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/wso_ufo19.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/wso_ufo19.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/wso_ufo19.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "ihelp.ro"] [uri "/img/wso_ufo19.php"] [unique_id "apTvFtmUuou1H8H2UKXAxQAAAMs"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/wso_ufo19.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] [hostname "ihelp.ro"] [uri "/img/wso_ufo19.php"] [unique_id "apTvFtmUuou1H8H2UKXAxQAAAMs"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788145430368637 7221 (- - -) Stopwatch2: 1788145430368637 7221; combined=4391, p1=214, p2=4117, p3=0, p4=0, p5=59, sr=86, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "DETECTION_ONLY" --21438830-Z-- --c4eb1a14-A-- [31/Aug/2026:06:03:50.422087 +0300] apTvFtmUuou1H8H2UKXAxgAAAMg 35.81.82.181 59454 127.0.0.1 7081 --c4eb1a14-B-- GET /img/ufo19_shell_30207.php HTTP/1.1 Host: ihelp.ro X-Real-IP: 35.81.82.181 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: https://ihelp.ro/ Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cookie: csrfToken=mPvE2njAl36rBABWojKSTDJjOWZkNjQ2MTA5NmVkM2IzY2QxMmFmM2Q3YjE2YjJiMTE4ZjY5ZWM%3D --c4eb1a14-F-- HTTP/1.1 200 OK X-Powered-By: PHP/8.1.34 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --c4eb1a14-H-- Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19_shell_30207.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19_shell_30207.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19_shell_30207.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "ihelp.ro"] [uri "/img/ufo19_shell_30207.php"] [unique_id "apTvFtmUuou1H8H2UKXAxgAAAMg"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19_shell_30207.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] [hostname "ihelp.ro"] [uri "/img/ufo19_shell_30207.php"] [unique_id "apTvFtmUuou1H8H2UKXAxgAAAMg"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788145430415007 7142 (- - -) Stopwatch2: 1788145430415007 7142; combined=4459, p1=225, p2=4176, p3=0, p4=0, p5=57, sr=91, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "DETECTION_ONLY" --c4eb1a14-Z-- --a6dd045b-A-- [31/Aug/2026:06:03:50.725322 +0300] apTvFtmUuou1H8H2UKXAywAAAMo 35.81.82.181 59508 127.0.0.1 7081 --a6dd045b-B-- GET /img/ufo19b_6243.php HTTP/1.1 Host: ihelp.ro X-Real-IP: 35.81.82.181 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: https://ihelp.ro/ Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cookie: 646109d53af43c125a937b56d9f339f0key=7a804c056f2d36c3c44be5f3d648e096; csrfToken=mPvE2njAl36rBABWojKSTDJjOWZkNjQ2MTA5NmVkM2IzY2QxMmFmM2Q3YjE2YjJiMTE4ZjY5ZWM%3D --a6dd045b-F-- HTTP/1.1 200 OK X-Powered-By: PHP/8.1.34 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --a6dd045b-H-- Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19b_6243.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19b_6243.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19b_6243.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "ihelp.ro"] [uri "/img/ufo19b_6243.php"] [unique_id "apTvFtmUuou1H8H2UKXAywAAAMo"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19b_6243.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] [hostname "ihelp.ro"] [uri "/img/ufo19b_6243.php"] [unique_id "apTvFtmUuou1H8H2UKXAywAAAMo"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788145430668079 57329 (- - -) Stopwatch2: 1788145430668079 57329; combined=4616, p1=237, p2=4300, p3=0, p4=0, p5=79, sr=88, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "DETECTION_ONLY" --a6dd045b-Z-- --e4e54d4c-A-- [31/Aug/2026:06:03:50.755389 +0300] apTvFtmUuou1H8H2UKXAxwAAAMA 35.81.82.181 59470 127.0.0.1 7081 --e4e54d4c-B-- GET /img/ufo19c_20960.php HTTP/1.1 Host: ihelp.ro X-Real-IP: 35.81.82.181 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: https://ihelp.ro/ Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cookie: csrfToken=mPvE2njAl36rBABWojKSTDJjOWZkNjQ2MTA5NmVkM2IzY2QxMmFmM2Q3YjE2YjJiMTE4ZjY5ZWM%3D --e4e54d4c-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.1.34 X-DEBUGKIT-ID: 204a8bcc-983e-4457-8c19-cf9124e13b87 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --e4e54d4c-H-- Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19c_20960.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19c_20960.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19c_20960.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "ihelp.ro"] [uri "/img/ufo19c_20960.php"] [unique_id "apTvFtmUuou1H8H2UKXAxwAAAMA"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19c_20960.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] [hostname "ihelp.ro"] [uri "/img/ufo19c_20960.php"] [unique_id "apTvFtmUuou1H8H2UKXAxwAAAMA"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788145430494736 260717 (- - -) Stopwatch2: 1788145430494736 260717; combined=4083, p1=234, p2=3772, p3=0, p4=0, p5=76, sr=90, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "DETECTION_ONLY" --e4e54d4c-Z-- --a43cbc2c-A-- [31/Aug/2026:06:03:50.878066 +0300] apTvFm7fDIutYTwcPOkZzAAAAFM 35.81.82.181 59476 127.0.0.1 7081 --a43cbc2c-B-- GET /img/ufo19p_20539.php HTTP/1.1 Host: ihelp.ro X-Real-IP: 35.81.82.181 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: https://ihelp.ro/ Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cookie: csrfToken=mPvE2njAl36rBABWojKSTDJjOWZkNjQ2MTA5NmVkM2IzY2QxMmFmM2Q3YjE2YjJiMTE4ZjY5ZWM%3D --a43cbc2c-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.1.34 X-DEBUGKIT-ID: 4e11523c-08d4-4c80-a30b-164d0da593ce Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --a43cbc2c-H-- Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19p_20539.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19p_20539.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19p_20539.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "ihelp.ro"] [uri "/img/ufo19p_20539.php"] [unique_id "apTvFm7fDIutYTwcPOkZzAAAAFM"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19p_20539.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] [hostname "ihelp.ro"] [uri "/img/ufo19p_20539.php"] [unique_id "apTvFm7fDIutYTwcPOkZzAAAAFM"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788145430542420 335710 (- - -) Stopwatch2: 1788145430542420 335710; combined=4770, p1=268, p2=4437, p3=0, p4=0, p5=65, sr=104, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "DETECTION_ONLY" --a43cbc2c-Z-- --232cdc54-A-- [31/Aug/2026:06:03:50.961047 +0300] apTvFtmUuou1H8H2UKXAyQAAANM 35.81.82.181 59492 127.0.0.1 7081 --232cdc54-B-- GET /img/ufo19w_831.php HTTP/1.1 Host: ihelp.ro X-Real-IP: 35.81.82.181 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: https://ihelp.ro/ Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cookie: 646109d53af43c125a937b56d9f339f0key=7a804c056f2d36c3c44be5f3d648e096; csrfToken=mPvE2njAl36rBABWojKSTDJjOWZkNjQ2MTA5NmVkM2IzY2QxMmFmM2Q3YjE2YjJiMTE4ZjY5ZWM%3D --232cdc54-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.1.34 X-DEBUGKIT-ID: 5e065ffc-3662-4f2b-baaa-0eefb8f09ef6 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --232cdc54-H-- Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19w_831.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19w_831.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19w_831.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "ihelp.ro"] [uri "/img/ufo19w_831.php"] [unique_id "apTvFtmUuou1H8H2UKXAyQAAANM"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19w_831.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] [hostname "ihelp.ro"] [uri "/img/ufo19w_831.php"] [unique_id "apTvFtmUuou1H8H2UKXAyQAAANM"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788145430554836 406287 (- - -) Stopwatch2: 1788145430554836 406287; combined=4354, p1=204, p2=4084, p3=0, p4=0, p5=66, sr=73, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "DETECTION_ONLY" --232cdc54-Z-- --1f736464-A-- [31/Aug/2026:06:03:51.120054 +0300] apTvFtmUuou1H8H2UKXAzQAAAMY 35.81.82.181 59544 127.0.0.1 7081 --1f736464-B-- GET /img/ufo19_20982.php HTTP/1.1 Host: ihelp.ro X-Real-IP: 35.81.82.181 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: https://ihelp.ro/ Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cookie: 646109d53af43c125a937b56d9f339f0key=7a804c056f2d36c3c44be5f3d648e096; csrfToken=mPvE2njAl36rBABWojKSTDJjOWZkNjQ2MTA5NmVkM2IzY2QxMmFmM2Q3YjE2YjJiMTE4ZjY5ZWM%3D --1f736464-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.1.34 X-DEBUGKIT-ID: 03b3eb98-ecbc-46a5-8666-1e13378b293a Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --1f736464-H-- Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19_20982.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19_20982.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19_20982.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "ihelp.ro"] [uri "/img/ufo19_20982.php"] [unique_id "apTvFtmUuou1H8H2UKXAzQAAAMY"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19_20982.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] [hostname "ihelp.ro"] [uri "/img/ufo19_20982.php"] [unique_id "apTvFtmUuou1H8H2UKXAzQAAAMY"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788145430906356 213770 (- - -) Stopwatch2: 1788145430906356 213770; combined=4891, p1=281, p2=4487, p3=0, p4=0, p5=123, sr=84, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "DETECTION_ONLY" --1f736464-Z-- --dba48d31-A-- [31/Aug/2026:06:03:51.131150 +0300] apTvF9mUuou1H8H2UKXAzwAAAMk 35.81.82.181 59566 127.0.0.1 7081 --dba48d31-B-- GET /img/ufo_fm.php HTTP/1.1 Host: ihelp.ro X-Real-IP: 35.81.82.181 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: https://ihelp.ro/ Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cookie: 646109d53af43c125a937b56d9f339f0key=7a804c056f2d36c3c44be5f3d648e096; csrfToken=mPvE2njAl36rBABWojKSTDJjOWZkNjQ2MTA5NmVkM2IzY2QxMmFmM2Q3YjE2YjJiMTE4ZjY5ZWM%3D --dba48d31-F-- HTTP/1.1 200 OK X-Powered-By: PHP/8.1.34 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --dba48d31-H-- Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo_fm.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo_fm.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo_fm.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "ihelp.ro"] [uri "/img/ufo_fm.php"] [unique_id "apTvF9mUuou1H8H2UKXAzwAAAMk"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo_fm.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] [hostname "ihelp.ro"] [uri "/img/ufo_fm.php"] [unique_id "apTvF9mUuou1H8H2UKXAzwAAAMk"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788145431117968 13242 (- - -) Stopwatch2: 1788145431117968 13242; combined=9500, p1=257, p2=9187, p3=0, p4=0, p5=55, sr=114, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "DETECTION_ONLY" --dba48d31-Z-- --7140f16d-A-- [31/Aug/2026:06:04:15.764553 +0300] apTvL27fDIutYTwcPOkZ0AAAAEE 120.133.60.156 34272 127.0.0.1 7081 --7140f16d-B-- POST /wp-login.php HTTP/1.1 Host: axapres.ro X-Real-IP: 120.133.60.156 X-Accel-Internal: /internal-nginx-static-location Content-Length: 108 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8 Accept-Language: en-US,en;q=0.5 Content-Type: application/x-www-form-urlencoded Cookie: wordpress_test_cookie=WP+Cookie+check Origin: https://axapres.ro Referer: https://axapres.ro/wp-login.php --7140f16d-F-- HTTP/1.1 403 Forbidden Content-Length: 199 Content-Type: text/html; charset=iso-8859-1 --7140f16d-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:06-04.120.133.60.156"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Apache-Handler: proxy:unix:/var/www/vhosts/system/axapres.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788145455702143 62500 (- - -) Stopwatch2: 1788145455702143 62500; combined=61518, p1=239, p2=60566, p3=0, p4=0, p5=483, sr=81, sw=230, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --7140f16d-Z-- --c959a14c-A-- [31/Aug/2026:06:06:22.605534 +0300] apTvrifaLSuAj0yzdueSfQAAAA0 207.154.219.81 43842 127.0.0.1 7081 --c959a14c-B-- POST /wp-login.php HTTP/1.1 Host: ajutam.ro X-Real-IP: 207.154.219.81 X-Accel-Internal: /internal-nginx-static-location Content-Length: 123 Accept: */* User-Agent: Mozilla/5.0 Content-Type: application/x-www-form-urlencoded Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818 --c959a14c-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --c959a14c-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:06-06.207.154.219.81"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788145582542740 62869 (- - -) Stopwatch2: 1788145582542740 62869; combined=61179, p1=858, p2=59801, p3=0, p4=0, p5=388, sr=101, sw=132, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --c959a14c-Z-- --e9092e18-A-- [31/Aug/2026:06:13:01.194919 +0300] apTxPdmUuou1H8H2UKXA8QAAAME 207.154.219.81 47156 127.0.0.1 7081 --e9092e18-B-- POST /wp-login.php HTTP/1.1 Host: ajutam.ro X-Real-IP: 207.154.219.81 X-Accel-Internal: /internal-nginx-static-location Content-Length: 105 Accept: */* User-Agent: Mozilla/5.0 Content-Type: application/x-www-form-urlencoded Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818 --e9092e18-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --e9092e18-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:06-13.207.154.219.81"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788145981128333 66727 (- - -) Stopwatch2: 1788145981128333 66727; combined=64624, p1=482, p2=60690, p3=0, p4=0, p5=2060, sr=222, sw=1392, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --e9092e18-Z-- --5155e508-A-- [31/Aug/2026:06:18:08.604947 +0300] apTycCfaLSuAj0yzdueSkQAAAAw 34.24.95.24 37350 127.0.0.1 7081 --5155e508-B-- GET /@fs/app/.env?raw?? HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 172.28.181.196 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 172.28.181.196 Fastly-Client-Ip: 172.28.181.196 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 172.28.181.196 Upgrade-Insecure-Requests: 1 X-Client-Ip: 172.28.181.196 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 172.28.181.196 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --5155e508-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --5155e508-E-- --5155e508-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/@fs/app/.env"] [unique_id "apTycCfaLSuAj0yzdueSkQAAAAw"] Stopwatch: 1788146288595552 9479 (- - -) Stopwatch2: 1788146288595552 9479; combined=7887, p1=341, p2=7352, p3=134, p4=9, p5=50, sr=129, sw=1, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --5155e508-Z-- --761ef133-A-- [31/Aug/2026:06:18:08.811724 +0300] apTycH7glkZrdsSdRApIkQAAAJg 34.24.95.24 37370 127.0.0.1 7081 --761ef133-B-- GET /@fs/..%252f..%252f..%252f..%252f..%252froot/.env?raw?? HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 192.168.75.173 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 192.168.75.173 Fastly-Client-Ip: 192.168.75.173 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 192.168.75.173 Upgrade-Insecure-Requests: 1 X-Client-Ip: 192.168.75.173 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 192.168.75.173 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --761ef133-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --761ef133-E-- --761ef133-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/@fs/..%2f..%2f..%2f..%2f..%2froot/.env"] [unique_id "apTycH7glkZrdsSdRApIkQAAAJg"] Stopwatch: 1788146288804922 6908 (- - -) Stopwatch2: 1788146288804922 6908; combined=5268, p1=327, p2=4776, p3=84, p4=10, p5=71, sr=118, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --761ef133-Z-- --a4be4676-A-- [31/Aug/2026:06:18:08.993888 +0300] apTycNmUuou1H8H2UKXBFwAAANQ 34.24.95.24 37382 127.0.0.1 7081 --a4be4676-B-- GET /@fs/..%252f..%252f..%252f..%252f..%252fproc/self/environ?raw?? HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 172.17.127.58 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 172.17.127.58 Fastly-Client-Ip: 172.17.127.58 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 172.17.127.58 Upgrade-Insecure-Requests: 1 X-Client-Ip: 172.17.127.58 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 172.17.127.58 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --a4be4676-F-- HTTP/1.1 403 Forbidden Content-Length: 199 Content-Type: text/html; charset=iso-8859-1 --a4be4676-H-- Message: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at MATCHED_VAR. [file "/etc/httpd/conf/modsecurity.d/rules/custom/012_i360_1_generic.conf"] [line "22"] [id "77140166"] [msg "IM360 WAF: Blocking directory traversal attempt||MVN:MATCHED_VAR||MV:/proc/self/environ?raw??||T:APACHE||"] [severity "CRITICAL"] [tag "service_gen"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G:raw??=& P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at MATCHED_VAR. [file "/etc/httpd/conf/modsecurity.d/rules/custom/012_i360_1_generic.conf"] [line "22"] [id "77140166"] [msg "IM360 WAF: Blocking directory traversal attempt||MVN:MATCHED_VAR||MV:/proc/self/environ?raw??||T:APACHE||"] [severity "CRITICAL"] [tag "service_gen"] [hostname "webmail.chania24.taxi"] [uri "/@fs/..%2f..%2f..%2f..%2f..%2fproc/self/environ"] [unique_id "apTycNmUuou1H8H2UKXBFwAAANQ"] Action: Intercepted (phase 2) Stopwatch: 1788146288987897 6073 (- - -) Stopwatch2: 1788146288987897 6073; combined=4435, p1=300, p2=3777, p3=0, p4=0, p5=358, sr=117, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --a4be4676-Z-- --78ba2517-A-- [31/Aug/2026:06:18:09.219186 +0300] apTycSfaLSuAj0yzdueSkgAAABY 34.24.95.24 37434 127.0.0.1 7081 --78ba2517-B-- GET /static../.env HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 172.17.65.186 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 172.17.65.186 Fastly-Client-Ip: 172.17.65.186 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 172.17.65.186 Upgrade-Insecure-Requests: 1 X-Client-Ip: 172.17.65.186 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 172.17.65.186 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --78ba2517-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --78ba2517-E-- --78ba2517-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/static../.env"] [unique_id "apTycSfaLSuAj0yzdueSkgAAABY"] Stopwatch: 1788146289209648 9651 (- - -) Stopwatch2: 1788146289209648 9651; combined=7986, p1=447, p2=7385, p3=92, p4=9, p5=53, sr=207, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --78ba2517-Z-- --82c7b36e-A-- [31/Aug/2026:06:18:09.229674 +0300] apTycdmUuou1H8H2UKXBGQAAAMc 34.24.95.24 37456 127.0.0.1 7081 --82c7b36e-B-- GET /@fs/src/.env?raw?? HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 192.168.218.248 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 192.168.218.248 Fastly-Client-Ip: 192.168.218.248 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 192.168.218.248 Upgrade-Insecure-Requests: 1 X-Client-Ip: 192.168.218.248 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 192.168.218.248 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --82c7b36e-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --82c7b36e-E-- --82c7b36e-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/@fs/src/.env"] [unique_id "apTycdmUuou1H8H2UKXBGQAAAMc"] Stopwatch: 1788146289223425 6335 (- - -) Stopwatch2: 1788146289223425 6335; combined=4753, p1=346, p2=4266, p3=84, p4=9, p5=47, sr=166, sw=1, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --82c7b36e-Z-- --29e80a3f-A-- [31/Aug/2026:06:18:09.232685 +0300] apTycW7fDIutYTwcPOkZ1wAAAFE 34.24.95.24 37446 127.0.0.1 7081 --29e80a3f-B-- GET /@fs/../.env?raw?? HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 192.168.132.70 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 192.168.132.70 Fastly-Client-Ip: 192.168.132.70 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 192.168.132.70 Upgrade-Insecure-Requests: 1 X-Client-Ip: 192.168.132.70 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 192.168.132.70 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --29e80a3f-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --29e80a3f-E-- --29e80a3f-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/.env"] [unique_id "apTycW7fDIutYTwcPOkZ1wAAAFE"] Stopwatch: 1788146289217261 15620 (- - -) Stopwatch2: 1788146289217261 15620; combined=7829, p1=559, p2=7029, p3=154, p4=12, p5=74, sr=161, sw=1, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --29e80a3f-Z-- --6c43d622-A-- [31/Aug/2026:06:18:09.254146 +0300] apTycSfaLSuAj0yzdueSkwAAABc 34.24.95.24 37468 127.0.0.1 7081 --6c43d622-B-- GET /_nuxt/../.env HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 192.168.29.181 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 192.168.29.181 Fastly-Client-Ip: 192.168.29.181 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 192.168.29.181 Upgrade-Insecure-Requests: 1 X-Client-Ip: 192.168.29.181 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 192.168.29.181 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --6c43d622-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --6c43d622-E-- --6c43d622-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/.env"] [unique_id "apTycSfaLSuAj0yzdueSkwAAABc"] Stopwatch: 1788146289246687 7544 (- - -) Stopwatch2: 1788146289246687 7544; combined=5854, p1=315, p2=5406, p3=82, p4=10, p5=41, sr=104, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --6c43d622-Z-- --c959a14c-A-- [31/Aug/2026:06:18:09.526338 +0300] apTycW7fDIutYTwcPOkZ2AAAAEw 34.24.95.24 37472 127.0.0.1 7081 --c959a14c-B-- GET /static//app/.env HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 10.233.245.68 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 10.233.245.68 Fastly-Client-Ip: 10.233.245.68 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 10.233.245.68 Upgrade-Insecure-Requests: 1 X-Client-Ip: 10.233.245.68 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 10.233.245.68 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --c959a14c-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --c959a14c-E-- --c959a14c-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/static/app/.env"] [unique_id "apTycW7fDIutYTwcPOkZ2AAAAEw"] Stopwatch: 1788146289517107 9316 (- - -) Stopwatch2: 1788146289517107 9316; combined=7949, p1=265, p2=7558, p3=68, p4=7, p5=50, sr=100, sw=1, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --c959a14c-Z-- --d6b4b43a-A-- [31/Aug/2026:06:18:09.533443 +0300] apTycdmUuou1H8H2UKXBGgAAAMw 34.24.95.24 37482 127.0.0.1 7081 --d6b4b43a-B-- GET /media../.env HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 100.107.189.187 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 100.107.189.187 Fastly-Client-Ip: 100.107.189.187 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 100.107.189.187 Upgrade-Insecure-Requests: 1 X-Client-Ip: 100.107.189.187 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 100.107.189.187 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --d6b4b43a-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --d6b4b43a-E-- --d6b4b43a-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/media../.env"] [unique_id "apTycdmUuou1H8H2UKXBGgAAAMw"] Stopwatch: 1788146289527195 6330 (- - -) Stopwatch2: 1788146289527195 6330; combined=4965, p1=303, p2=4540, p3=75, p4=7, p5=40, sr=125, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --d6b4b43a-Z-- --75771079-A-- [31/Aug/2026:06:18:09.554772 +0300] apTycdmUuou1H8H2UKXBGwAAANg 34.24.95.24 37502 127.0.0.1 7081 --75771079-B-- GET /files../.env HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 100.118.234.89 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 100.118.234.89 Fastly-Client-Ip: 100.118.234.89 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 100.118.234.89 Upgrade-Insecure-Requests: 1 X-Client-Ip: 100.118.234.89 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 100.118.234.89 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --75771079-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --75771079-E-- --75771079-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/files../.env"] [unique_id "apTycdmUuou1H8H2UKXBGwAAANg"] Stopwatch: 1788146289547589 7265 (- - -) Stopwatch2: 1788146289547589 7265; combined=5302, p1=371, p2=4801, p3=84, p4=7, p5=39, sr=113, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --75771079-Z-- --5155e508-A-- [31/Aug/2026:06:18:09.555041 +0300] apTycW7fDIutYTwcPOkZ2QAAAFM 34.24.95.24 37496 127.0.0.1 7081 --5155e508-B-- GET /.//.env HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 10.216.139.92 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 10.216.139.92 Fastly-Client-Ip: 10.216.139.92 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 10.216.139.92 Upgrade-Insecure-Requests: 1 X-Client-Ip: 10.216.139.92 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 10.216.139.92 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --5155e508-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --5155e508-E-- --5155e508-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/.env"] [unique_id "apTycW7fDIutYTwcPOkZ2QAAAFM"] Stopwatch: 1788146289535242 19921 (- - -) Stopwatch2: 1788146289535242 19921; combined=7316, p1=278, p2=6876, p3=108, p4=9, p5=45, sr=106, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --5155e508-Z-- --83ef5677-A-- [31/Aug/2026:06:18:09.567126 +0300] apTycX7glkZrdsSdRApIlAAAAIc 34.24.95.24 37516 127.0.0.1 7081 --83ef5677-B-- GET /static//.env HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 192.168.41.6 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 192.168.41.6 Fastly-Client-Ip: 192.168.41.6 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 192.168.41.6 Upgrade-Insecure-Requests: 1 X-Client-Ip: 192.168.41.6 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 192.168.41.6 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --83ef5677-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --83ef5677-E-- --83ef5677-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/static/.env"] [unique_id "apTycX7glkZrdsSdRApIlAAAAIc"] Stopwatch: 1788146289561088 6121 (- - -) Stopwatch2: 1788146289561088 6121; combined=4785, p1=298, p2=4372, p3=69, p4=7, p5=39, sr=104, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --83ef5677-Z-- --78ba2517-A-- [31/Aug/2026:06:18:09.726822 +0300] apTycW7fDIutYTwcPOkZ2gAAAFY 34.24.95.24 37518 127.0.0.1 7081 --78ba2517-B-- GET /static//home/user/.env HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 10.42.236.25 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 10.42.236.25 Fastly-Client-Ip: 10.42.236.25 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 10.42.236.25 Upgrade-Insecure-Requests: 1 X-Client-Ip: 10.42.236.25 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 10.42.236.25 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --78ba2517-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --78ba2517-E-- --78ba2517-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/static/home/user/.env"] [unique_id "apTycW7fDIutYTwcPOkZ2gAAAFY"] Stopwatch: 1788146289720117 6798 (- - -) Stopwatch2: 1788146289720117 6798; combined=5312, p1=268, p2=4929, p3=65, p4=7, p5=43, sr=105, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --78ba2517-Z-- --1c98420c-A-- [31/Aug/2026:06:18:10.012023 +0300] apTycn7glkZrdsSdRApIlQAAAIw 34.24.95.24 37528 127.0.0.1 7081 --1c98420c-B-- GET /api/.env/public/.env HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 10.93.33.68 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 10.93.33.68 Fastly-Client-Ip: 10.93.33.68 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 10.93.33.68 Upgrade-Insecure-Requests: 1 X-Client-Ip: 10.93.33.68 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 10.93.33.68 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --1c98420c-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --1c98420c-E-- --1c98420c-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/api/.env/public/.env"] [unique_id "apTycn7glkZrdsSdRApIlQAAAIw"] Stopwatch: 1788146290005596 6523 (- - -) Stopwatch2: 1788146290005596 6523; combined=5008, p1=313, p2=4574, p3=74, p4=8, p5=39, sr=127, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --1c98420c-Z-- --761ef133-A-- [31/Aug/2026:06:18:10.019779 +0300] apTycifaLSuAj0yzdueSlAAAABE 34.24.95.24 37540 127.0.0.1 7081 --761ef133-B-- GET //.env HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 192.168.3.21 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 192.168.3.21 Fastly-Client-Ip: 192.168.3.21 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 192.168.3.21 Upgrade-Insecure-Requests: 1 X-Client-Ip: 192.168.3.21 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 192.168.3.21 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --761ef133-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --761ef133-E-- --761ef133-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/.env"] [unique_id "apTycifaLSuAj0yzdueSlAAAABE"] Stopwatch: 1788146290012880 6999 (- - -) Stopwatch2: 1788146290012880 6999; combined=5499, p1=245, p2=5073, p3=76, p4=54, p5=50, sr=96, sw=1, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --761ef133-Z-- --d5370b71-A-- [31/Aug/2026:06:18:10.020179 +0300] apTycn7glkZrdsSdRApIlgAAAIU 34.24.95.24 37546 127.0.0.1 7081 --d5370b71-B-- GET /%2eenv HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 10.56.223.24 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 10.56.223.24 Fastly-Client-Ip: 10.56.223.24 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 10.56.223.24 Upgrade-Insecure-Requests: 1 X-Client-Ip: 10.56.223.24 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 10.56.223.24 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --d5370b71-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --d5370b71-E-- --d5370b71-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/.env"] [unique_id "apTycn7glkZrdsSdRApIlgAAAIU"] Stopwatch: 1788146290013045 7235 (- - -) Stopwatch2: 1788146290013045 7235; combined=5798, p1=325, p2=5344, p3=77, p4=8, p5=44, sr=122, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --d5370b71-Z-- --b033220f-A-- [31/Aug/2026:06:18:10.201936 +0300] apTyctmUuou1H8H2UKXBHAAAAMo 34.24.95.24 37570 127.0.0.1 7081 --b033220f-B-- GET /images../.env HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 100.77.204.197 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 100.77.204.197 Fastly-Client-Ip: 100.77.204.197 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 100.77.204.197 Upgrade-Insecure-Requests: 1 X-Client-Ip: 100.77.204.197 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 100.77.204.197 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --b033220f-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --b033220f-E-- --b033220f-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/images../.env"] [unique_id "apTyctmUuou1H8H2UKXBHAAAAMo"] Stopwatch: 1788146290195634 6395 (- - -) Stopwatch2: 1788146290195634 6395; combined=5118, p1=308, p2=4672, p3=83, p4=8, p5=47, sr=103, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --b033220f-Z-- --f284a63c-A-- [31/Aug/2026:06:18:10.208347 +0300] apTyctmUuou1H8H2UKXBHQAAAM0 34.24.95.24 37582 127.0.0.1 7081 --f284a63c-B-- GET /uploads../.env HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 192.168.188.130 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 192.168.188.130 Fastly-Client-Ip: 192.168.188.130 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 192.168.188.130 Upgrade-Insecure-Requests: 1 X-Client-Ip: 192.168.188.130 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 192.168.188.130 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --f284a63c-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --f284a63c-E-- --f284a63c-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/uploads../.env"] [unique_id "apTyctmUuou1H8H2UKXBHQAAAM0"] Stopwatch: 1788146290202493 5936 (- - -) Stopwatch2: 1788146290202493 5936; combined=4647, p1=286, p2=4264, p3=54, p4=7, p5=36, sr=122, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --f284a63c-Z-- --17b40101-A-- [31/Aug/2026:06:18:10.215392 +0300] apTyctmUuou1H8H2UKXBHgAAANU 34.24.95.24 37556 127.0.0.1 7081 --17b40101-B-- GET /img../.env HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 172.31.10.90 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 172.31.10.90 Fastly-Client-Ip: 172.31.10.90 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 172.31.10.90 Upgrade-Insecure-Requests: 1 X-Client-Ip: 172.31.10.90 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 172.31.10.90 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --17b40101-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --17b40101-E-- --17b40101-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/img../.env"] [unique_id "apTyctmUuou1H8H2UKXBHgAAANU"] Stopwatch: 1788146290204485 11188 (- - -) Stopwatch2: 1788146290204485 11188; combined=9393, p1=567, p2=8146, p3=604, p4=12, p5=63, sr=188, sw=1, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --17b40101-Z-- --590c442a-A-- [31/Aug/2026:06:18:10.394101 +0300] apTyctmUuou1H8H2UKXBHwAAAMQ 34.24.95.24 37624 127.0.0.1 7081 --590c442a-B-- GET /assets../.env HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 100.87.155.24 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 100.87.155.24 Fastly-Client-Ip: 100.87.155.24 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 100.87.155.24 Upgrade-Insecure-Requests: 1 X-Client-Ip: 100.87.155.24 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 100.87.155.24 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --590c442a-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --590c442a-E-- --590c442a-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/assets../.env"] [unique_id "apTyctmUuou1H8H2UKXBHwAAAMQ"] Stopwatch: 1788146290383070 11317 (- - -) Stopwatch2: 1788146290383070 11317; combined=9181, p1=535, p2=8371, p3=148, p4=56, p5=71, sr=161, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --590c442a-Z-- --589ad94a-A-- [31/Aug/2026:06:18:10.455217 +0300] apTyctmUuou1H8H2UKXBIAAAAM4 34.24.95.24 37636 127.0.0.1 7081 --589ad94a-B-- GET /@fs/var/task/.env?raw?? HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 10.224.20.36 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 10.224.20.36 Fastly-Client-Ip: 10.224.20.36 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 10.224.20.36 Upgrade-Insecure-Requests: 1 X-Client-Ip: 10.224.20.36 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 10.224.20.36 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --589ad94a-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --589ad94a-E-- --589ad94a-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/@fs/var/task/.env"] [unique_id "apTyctmUuou1H8H2UKXBIAAAAM4"] Stopwatch: 1788146290449950 5350 (- - -) Stopwatch2: 1788146290449950 5350; combined=4012, p1=285, p2=3618, p3=64, p4=7, p5=37, sr=103, sw=1, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --589ad94a-Z-- --1a6bac2f-A-- [31/Aug/2026:06:18:10.485112 +0300] apTyctmUuou1H8H2UKXBIQAAAME 34.24.95.24 37646 127.0.0.1 7081 --1a6bac2f-B-- GET /@fs/proc/self/cwd/.env?raw?? HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 172.26.80.199 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 172.26.80.199 Fastly-Client-Ip: 172.26.80.199 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 172.26.80.199 Upgrade-Insecure-Requests: 1 X-Client-Ip: 172.26.80.199 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 172.26.80.199 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --1a6bac2f-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --1a6bac2f-E-- --1a6bac2f-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/@fs/proc/self/cwd/.env"] [unique_id "apTyctmUuou1H8H2UKXBIQAAAME"] Stopwatch: 1788146290462379 22932 (- - -) Stopwatch2: 1788146290462379 22932; combined=21011, p1=529, p2=20145, p3=241, p4=11, p5=85, sr=259, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --1a6bac2f-Z-- --83ef5677-A-- [31/Aug/2026:06:18:11.226528 +0300] apTycyfaLSuAj0yzdueSlQAAAAU 34.24.95.24 37690 127.0.0.1 7081 --83ef5677-B-- GET /@fs/.env?raw&url?? HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 100.89.48.229 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 100.89.48.229 Fastly-Client-Ip: 100.89.48.229 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 100.89.48.229 Upgrade-Insecure-Requests: 1 X-Client-Ip: 100.89.48.229 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 100.89.48.229 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --83ef5677-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --83ef5677-E-- --83ef5677-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw&url??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw&url??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/@fs/.env"] [unique_id "apTycyfaLSuAj0yzdueSlQAAAAU"] Stopwatch: 1788146291219638 6999 (- - -) Stopwatch2: 1788146291219638 6999; combined=3932, p1=200, p2=3623, p3=64, p4=6, p5=39, sr=74, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --83ef5677-Z-- --6c43d622-A-- [31/Aug/2026:06:18:11.227515 +0300] apTyc27fDIutYTwcPOkZ3AAAAEI 34.24.95.24 37674 127.0.0.1 7081 --6c43d622-B-- GET /@fs/.env?url&raw?? HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 10.193.243.14 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 10.193.243.14 Fastly-Client-Ip: 10.193.243.14 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 10.193.243.14 Upgrade-Insecure-Requests: 1 X-Client-Ip: 10.193.243.14 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 10.193.243.14 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --6c43d622-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --6c43d622-E-- --6c43d622-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:url&raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:url&raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/@fs/.env"] [unique_id "apTyc27fDIutYTwcPOkZ3AAAAEI"] Stopwatch: 1788146291219139 8493 (- - -) Stopwatch2: 1788146291219139 8493; combined=4063, p1=291, p2=3623, p3=99, p4=3, p5=46, sr=108, sw=1, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --6c43d622-Z-- --761ef133-A-- [31/Aug/2026:06:18:11.764499 +0300] apTyc27fDIutYTwcPOkZ3QAAAEM 34.24.95.24 37744 127.0.0.1 7081 --761ef133-B-- GET /@fs/.env?import&?raw?? HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 10.3.184.21 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 10.3.184.21 Fastly-Client-Ip: 10.3.184.21 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 10.3.184.21 Upgrade-Insecure-Requests: 1 X-Client-Ip: 10.3.184.21 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 10.3.184.21 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --761ef133-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --761ef133-E-- --761ef133-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:import&?raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:import&?raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/@fs/.env"] [unique_id "apTyc27fDIutYTwcPOkZ3QAAAEM"] Stopwatch: 1788146291758670 5913 (- - -) Stopwatch2: 1788146291758670 5913; combined=4653, p1=229, p2=4298, p3=76, p4=8, p5=41, sr=74, sw=1, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --761ef133-Z-- --05969073-A-- [31/Aug/2026:06:18:11.791062 +0300] apTyc9mUuou1H8H2UKXBJQAAAMU 34.24.95.24 37732 127.0.0.1 7081 --05969073-B-- GET /config/.env.php HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 172.22.142.141 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 172.22.142.141 Fastly-Client-Ip: 172.22.142.141 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 172.22.142.141 Upgrade-Insecure-Requests: 1 X-Client-Ip: 172.22.142.141 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 172.22.142.141 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --05969073-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --05969073-E-- --05969073-H-- Message: Warning. Matched phrase ".env.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/config/.env.php||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Matched phrase ".env.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/config/.env.php||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".env.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/config/.env.php||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "webmail.chania24.taxi"] [uri "/config/.env.php"] [unique_id "apTyc9mUuou1H8H2UKXBJQAAAMU"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".env.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/config/.env.php||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/config/.env.php"] [unique_id "apTyc9mUuou1H8H2UKXBJQAAAMU"] Stopwatch: 1788146291752398 38758 (- - -) Stopwatch2: 1788146291752398 38758; combined=37508, p1=301, p2=37089, p3=65, p4=7, p5=46, sr=136, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --05969073-Z-- --2d58ee79-A-- [31/Aug/2026:06:18:11.791664 +0300] apTyc9mUuou1H8H2UKXBJgAAAMY 34.24.95.24 37742 127.0.0.1 7081 --2d58ee79-B-- GET /wp-config.php.bak HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 100.110.233.113 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 100.110.233.113 Fastly-Client-Ip: 100.110.233.113 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 100.110.233.113 Upgrade-Insecure-Requests: 1 X-Client-Ip: 100.110.233.113 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 100.110.233.113 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --2d58ee79-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --2d58ee79-E-- --2d58ee79-H-- Message: Warning. Matched phrase "wp-config.php." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/wp-config.php.bak||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Matched phrase "wp-config.php." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/wp-config.php.bak||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Message: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "wp-config.php." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/wp-config.php.bak||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "webmail.chania24.taxi"] [uri "/wp-config.php.bak"] [unique_id "apTyc9mUuou1H8H2UKXBJgAAAMY"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "wp-config.php." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/wp-config.php.bak||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/wp-config.php.bak"] [unique_id "apTyc9mUuou1H8H2UKXBJgAAAMY"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/wp-config.php.bak"] [unique_id "apTyc9mUuou1H8H2UKXBJgAAAMY"] Stopwatch: 1788146291756159 35587 (- - -) Stopwatch2: 1788146291756159 35587; combined=34398, p1=278, p2=34014, p3=37, p4=5, p5=64, sr=121, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --2d58ee79-Z-- --40b18017-A-- [31/Aug/2026:06:18:11.963201 +0300] apTyc37glkZrdsSdRApImwAAAJM 34.24.95.24 37768 127.0.0.1 7081 --40b18017-B-- GET /laravel/.env HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 192.168.154.2 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 192.168.154.2 Fastly-Client-Ip: 192.168.154.2 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 192.168.154.2 Upgrade-Insecure-Requests: 1 X-Client-Ip: 192.168.154.2 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 192.168.154.2 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --40b18017-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --40b18017-E-- --40b18017-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/laravel/.env"] [unique_id "apTyc37glkZrdsSdRApImwAAAJM"] Stopwatch: 1788146291949816 13478 (- - -) Stopwatch2: 1788146291949816 13478; combined=6316, p1=1594, p2=4606, p3=66, p4=7, p5=42, sr=102, sw=1, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --40b18017-Z-- --904cf438-A-- [31/Aug/2026:06:18:12.061086 +0300] apTydNmUuou1H8H2UKXBJwAAAMw 34.24.95.24 37784 127.0.0.1 7081 --904cf438-B-- GET /wp-config.php.old HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 10.116.49.63 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 10.116.49.63 Fastly-Client-Ip: 10.116.49.63 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 10.116.49.63 Upgrade-Insecure-Requests: 1 X-Client-Ip: 10.116.49.63 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 10.116.49.63 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --904cf438-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --904cf438-E-- --904cf438-H-- Message: Warning. Matched phrase "wp-config.php." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/wp-config.php.old||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Matched phrase "wp-config.php." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/wp-config.php.old||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Message: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "wp-config.php." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/wp-config.php.old||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "webmail.chania24.taxi"] [uri "/wp-config.php.old"] [unique_id "apTydNmUuou1H8H2UKXBJwAAAMw"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "wp-config.php." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/wp-config.php.old||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/wp-config.php.old"] [unique_id "apTydNmUuou1H8H2UKXBJwAAAMw"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/wp-config.php.old"] [unique_id "apTydNmUuou1H8H2UKXBJwAAAMw"] Stopwatch: 1788146292027588 33581 (- - -) Stopwatch2: 1788146292027588 33581; combined=32260, p1=240, p2=31899, p3=61, p4=7, p5=52, sr=83, sw=1, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --904cf438-Z-- --1c98420c-A-- [31/Aug/2026:06:18:12.149572 +0300] apTydCfaLSuAj0yzdueSmAAAAA0 34.24.95.24 37802 127.0.0.1 7081 --1c98420c-B-- GET /core/.env HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 172.30.60.95 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 172.30.60.95 Fastly-Client-Ip: 172.30.60.95 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 172.30.60.95 Upgrade-Insecure-Requests: 1 X-Client-Ip: 172.30.60.95 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 172.30.60.95 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --1c98420c-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --1c98420c-E-- --1c98420c-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/core/.env"] [unique_id "apTydCfaLSuAj0yzdueSmAAAAA0"] Stopwatch: 1788146292141121 8560 (- - -) Stopwatch2: 1788146292141121 8560; combined=7031, p1=280, p2=6621, p3=78, p4=9, p5=43, sr=96, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --1c98420c-Z-- --d5370b71-A-- [31/Aug/2026:06:18:12.169745 +0300] apTydCfaLSuAj0yzdueSlwAAABI 34.24.95.24 37800 127.0.0.1 7081 --d5370b71-B-- GET /.env.php.bak HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 10.53.117.228 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 10.53.117.228 Fastly-Client-Ip: 10.53.117.228 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 10.53.117.228 Upgrade-Insecure-Requests: 1 X-Client-Ip: 10.53.117.228 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 10.53.117.228 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --d5370b71-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --d5370b71-E-- --d5370b71-H-- Message: Warning. Matched phrase ".env.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.env.php.bak||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Matched phrase ".env.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.env.php.bak||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".env.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.env.php.bak||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "webmail.chania24.taxi"] [uri "/.env.php.bak"] [unique_id "apTydCfaLSuAj0yzdueSlwAAABI"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".env.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.env.php.bak||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/.env.php.bak"] [unique_id "apTydCfaLSuAj0yzdueSlwAAABI"] Stopwatch: 1788146292132811 37042 (- - -) Stopwatch2: 1788146292132811 37042; combined=35376, p1=339, p2=34893, p3=87, p4=8, p5=48, sr=123, sw=1, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --d5370b71-Z-- --83ef5677-A-- [31/Aug/2026:06:18:12.348283 +0300] apTydG7fDIutYTwcPOkZ3gAAAEY 34.24.95.24 37816 127.0.0.1 7081 --83ef5677-B-- GET /.env.swp HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 10.27.17.157 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 10.27.17.157 Fastly-Client-Ip: 10.27.17.157 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 10.27.17.157 Upgrade-Insecure-Requests: 1 X-Client-Ip: 10.27.17.157 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 10.27.17.157 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --83ef5677-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --83ef5677-E-- --83ef5677-H-- Message: Warning. Pattern match "(\\.swp|~)$" at REQUEST_BASENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "309"] [id "77142201"] [msg "IM360 WAF: Possible enumeration of sensitive data (dirb)||MVN:REQUEST_BASENAME||T:APACHE||MV:.env.swp||"] [severity "NOTICE"] [tag "service_i360custom"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\.swp|~)$" at REQUEST_BASENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "309"] [id "77142201"] [msg "IM360 WAF: Possible enumeration of sensitive data (dirb)||MVN:REQUEST_BASENAME||T:APACHE||MV:.env.swp||"] [severity "NOTICE"] [tag "service_i360custom"] [hostname "webmail.chania24.taxi"] [uri "/.env.swp"] [unique_id "apTydG7fDIutYTwcPOkZ3gAAAEY"] Stopwatch: 1788146292338396 9990 (- - -) Stopwatch2: 1788146292338396 9990; combined=7695, p1=327, p2=7194, p3=96, p4=9, p5=69, sr=137, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --83ef5677-Z-- --9e4b441f-A-- [31/Aug/2026:06:18:12.365798 +0300] apTydNmUuou1H8H2UKXBKAAAAMM 34.24.95.24 37824 127.0.0.1 7081 --9e4b441f-B-- GET /config.php.bak HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 192.168.119.7 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 192.168.119.7 Fastly-Client-Ip: 192.168.119.7 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 192.168.119.7 Upgrade-Insecure-Requests: 1 X-Client-Ip: 192.168.119.7 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 192.168.119.7 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --9e4b441f-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --9e4b441f-E-- --9e4b441f-H-- Message: Warning. Matched phrase "/config.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "/config.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/config.php.bak"] [unique_id "apTydNmUuou1H8H2UKXBKAAAAMM"] Stopwatch: 1788146292357293 8625 (- - -) Stopwatch2: 1788146292357293 8625; combined=6908, p1=378, p2=6372, p3=96, p4=10, p5=52, sr=120, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --9e4b441f-Z-- --40b18017-A-- [31/Aug/2026:06:18:12.383399 +0300] apTydCfaLSuAj0yzdueSmQAAAAc 34.24.95.24 37836 127.0.0.1 7081 --40b18017-B-- GET /configuration.php.bak HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 172.22.147.122 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 172.22.147.122 Fastly-Client-Ip: 172.22.147.122 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 172.22.147.122 Upgrade-Insecure-Requests: 1 X-Client-Ip: 172.22.147.122 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 172.22.147.122 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --40b18017-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --40b18017-E-- --40b18017-H-- Message: Warning. Matched phrase "/configuration.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "/configuration.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/configuration.php.bak"] [unique_id "apTydCfaLSuAj0yzdueSmQAAAAc"] Stopwatch: 1788146292375308 8201 (- - -) Stopwatch2: 1788146292375308 8201; combined=6451, p1=367, p2=5936, p3=88, p4=10, p5=50, sr=118, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --40b18017-Z-- --1f538b55-A-- [31/Aug/2026:06:18:12.401999 +0300] apTydCfaLSuAj0yzdueSmgAAAA4 34.24.95.24 37846 127.0.0.1 7081 --1f538b55-B-- GET /public/.env HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 100.95.78.93 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 100.95.78.93 Fastly-Client-Ip: 100.95.78.93 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 100.95.78.93 Upgrade-Insecure-Requests: 1 X-Client-Ip: 100.95.78.93 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 100.95.78.93 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --1f538b55-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --1f538b55-E-- --1f538b55-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/public/.env"] [unique_id "apTydCfaLSuAj0yzdueSmgAAAA4"] Stopwatch: 1788146292393549 8556 (- - -) Stopwatch2: 1788146292393549 8556; combined=6915, p1=351, p2=6366, p3=138, p4=11, p5=49, sr=124, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --1f538b55-Z-- --9afb313c-A-- [31/Aug/2026:06:18:12.683125 +0300] apTydNmUuou1H8H2UKXBKgAAAMA 34.24.95.24 37876 127.0.0.1 7081 --9afb313c-B-- GET /wp/.env HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 100.67.9.215 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 100.67.9.215 Fastly-Client-Ip: 100.67.9.215 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 100.67.9.215 Upgrade-Insecure-Requests: 1 X-Client-Ip: 100.67.9.215 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 100.67.9.215 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --9afb313c-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --9afb313c-E-- --9afb313c-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/wp/.env"] [unique_id "apTydNmUuou1H8H2UKXBKgAAAMA"] Stopwatch: 1788146292676181 7037 (- - -) Stopwatch2: 1788146292676181 7037; combined=4611, p1=256, p2=4239, p3=62, p4=7, p5=47, sr=100, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --9afb313c-Z-- --1c98420c-A-- [31/Aug/2026:06:18:12.714216 +0300] apTydG7fDIutYTwcPOkZ3wAAAEc 34.24.95.24 37904 127.0.0.1 7081 --1c98420c-B-- GET /web/.env HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 172.20.118.49 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 172.20.118.49 Fastly-Client-Ip: 172.20.118.49 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 172.20.118.49 Upgrade-Insecure-Requests: 1 X-Client-Ip: 172.20.118.49 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 172.20.118.49 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --1c98420c-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --1c98420c-E-- --1c98420c-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/web/.env"] [unique_id "apTydG7fDIutYTwcPOkZ3wAAAEc"] Stopwatch: 1788146292704411 9888 (- - -) Stopwatch2: 1788146292704411 9888; combined=8500, p1=337, p2=8060, p3=59, p4=7, p5=37, sr=151, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --1c98420c-Z-- --6a648b1a-A-- [31/Aug/2026:06:18:12.740687 +0300] apTydNmUuou1H8H2UKXBLAAAAMA 34.24.95.24 37884 127.0.0.1 7081 --6a648b1a-B-- GET /wp-config.php~ HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 192.168.85.77 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 192.168.85.77 Fastly-Client-Ip: 192.168.85.77 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 192.168.85.77 Upgrade-Insecure-Requests: 1 X-Client-Ip: 192.168.85.77 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 192.168.85.77 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --6a648b1a-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --6a648b1a-E-- --6a648b1a-H-- Message: Warning. Matched phrase "wp-config.php~" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/wp-config.php~||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Matched phrase "wp-config.php~" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/wp-config.php~||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Message: Warning. Pattern match "(\\.swp|~)$" at REQUEST_BASENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "309"] [id "77142201"] [msg "IM360 WAF: Possible enumeration of sensitive data (dirb)||MVN:REQUEST_BASENAME||T:APACHE||MV:wp-config.php~||"] [severity "NOTICE"] [tag "service_i360custom"] Message: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "wp-config.php~" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/wp-config.php~||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "webmail.chania24.taxi"] [uri "/wp-config.php~"] [unique_id "apTydNmUuou1H8H2UKXBLAAAAMA"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "wp-config.php~" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/wp-config.php~||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/wp-config.php~"] [unique_id "apTydNmUuou1H8H2UKXBLAAAAMA"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\.swp|~)$" at REQUEST_BASENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "309"] [id "77142201"] [msg "IM360 WAF: Possible enumeration of sensitive data (dirb)||MVN:REQUEST_BASENAME||T:APACHE||MV:wp-config.php~||"] [severity "NOTICE"] [tag "service_i360custom"] [hostname "webmail.chania24.taxi"] [uri "/wp-config.php~"] [unique_id "apTydNmUuou1H8H2UKXBLAAAAMA"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/wp-config.php~"] [unique_id "apTydNmUuou1H8H2UKXBLAAAAMA"] Stopwatch: 1788146292708494 32280 (- - -) Stopwatch2: 1788146292708494 32280; combined=30855, p1=387, p2=30317, p3=65, p4=6, p5=80, sr=127, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --6a648b1a-Z-- --d5370b71-A-- [31/Aug/2026:06:18:13.273278 +0300] apTydW7fDIutYTwcPOkZ4AAAAEo 34.24.95.24 37906 127.0.0.1 7081 --d5370b71-B-- GET /wp-config.php.swp HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 100.90.25.186 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 100.90.25.186 Fastly-Client-Ip: 100.90.25.186 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 100.90.25.186 Upgrade-Insecure-Requests: 1 X-Client-Ip: 100.90.25.186 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 100.90.25.186 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --d5370b71-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --d5370b71-E-- --d5370b71-H-- Message: Warning. Matched phrase "wp-config.php." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/wp-config.php.swp||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Matched phrase "wp-config.php." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/wp-config.php.swp||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Message: Warning. Pattern match "(\\.swp|~)$" at REQUEST_BASENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "309"] [id "77142201"] [msg "IM360 WAF: Possible enumeration of sensitive data (dirb)||MVN:REQUEST_BASENAME||T:APACHE||MV:wp-config.php.swp||"] [severity "NOTICE"] [tag "service_i360custom"] Message: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "wp-config.php." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/wp-config.php.swp||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "webmail.chania24.taxi"] [uri "/wp-config.php.swp"] [unique_id "apTydW7fDIutYTwcPOkZ4AAAAEo"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "wp-config.php." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/wp-config.php.swp||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/wp-config.php.swp"] [unique_id "apTydW7fDIutYTwcPOkZ4AAAAEo"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\.swp|~)$" at REQUEST_BASENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "309"] [id "77142201"] [msg "IM360 WAF: Possible enumeration of sensitive data (dirb)||MVN:REQUEST_BASENAME||T:APACHE||MV:wp-config.php.swp||"] [severity "NOTICE"] [tag "service_i360custom"] [hostname "webmail.chania24.taxi"] [uri "/wp-config.php.swp"] [unique_id "apTydW7fDIutYTwcPOkZ4AAAAEo"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/wp-config.php.swp"] [unique_id "apTydW7fDIutYTwcPOkZ4AAAAEo"] Stopwatch: 1788146293238851 34551 (- - -) Stopwatch2: 1788146293238851 34551; combined=33115, p1=256, p2=32745, p3=56, p4=6, p5=52, sr=98, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --d5370b71-Z-- --1f538b55-A-- [31/Aug/2026:06:18:13.447552 +0300] apTydX7glkZrdsSdRApInQAAAJA 34.24.95.24 37934 127.0.0.1 7081 --1f538b55-B-- GET /storage/.env HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 192.168.23.223 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 192.168.23.223 Fastly-Client-Ip: 192.168.23.223 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 192.168.23.223 Upgrade-Insecure-Requests: 1 X-Client-Ip: 192.168.23.223 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 192.168.23.223 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --1f538b55-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --1f538b55-E-- --1f538b55-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/storage/.env"] [unique_id "apTydX7glkZrdsSdRApInQAAAJA"] Stopwatch: 1788146293440235 7432 (- - -) Stopwatch2: 1788146293440235 7432; combined=5827, p1=325, p2=5366, p3=83, p4=8, p5=45, sr=112, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --1f538b55-Z-- --6df58a70-A-- [31/Aug/2026:06:18:14.355511 +0300] apTydn7glkZrdsSdRApIoQAAAIE 34.24.95.24 38050 127.0.0.1 7081 --6df58a70-B-- GET /web.config HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 192.168.230.247 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 192.168.230.247 Fastly-Client-Ip: 192.168.230.247 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 192.168.230.247 Upgrade-Insecure-Requests: 1 X-Client-Ip: 192.168.230.247 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 192.168.230.247 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --6df58a70-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --6df58a70-E-- --6df58a70-H-- Message: Warning. Matched phrase "/web.config" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "/web.config" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/web.config"] [unique_id "apTydn7glkZrdsSdRApIoQAAAIE"] Stopwatch: 1788146294349456 6180 (- - -) Stopwatch2: 1788146294349456 6180; combined=4875, p1=336, p2=4429, p3=61, p4=7, p5=41, sr=155, sw=1, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --6df58a70-Z-- --3d6edc59-A-- [31/Aug/2026:06:18:16.612527 +0300] apTyeH7glkZrdsSdRApIpgAAAI8 34.24.95.24 55498 127.0.0.1 7081 --3d6edc59-B-- GET /production/.env HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 100.98.232.217 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 100.98.232.217 Fastly-Client-Ip: 100.98.232.217 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 100.98.232.217 Upgrade-Insecure-Requests: 1 X-Client-Ip: 100.98.232.217 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 100.98.232.217 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --3d6edc59-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --3d6edc59-E-- --3d6edc59-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/production/.env"] [unique_id "apTyeH7glkZrdsSdRApIpgAAAI8"] Stopwatch: 1788146296604462 8148 (- - -) Stopwatch2: 1788146296604462 8148; combined=6655, p1=336, p2=6144, p3=116, p4=15, p5=44, sr=148, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --3d6edc59-Z-- --3b1af431-A-- [31/Aug/2026:06:18:16.660588 +0300] apTyeH7glkZrdsSdRApIpwAAAJM 34.24.95.24 55520 127.0.0.1 7081 --3b1af431-B-- GET /src/.env HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 10.18.140.53 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 10.18.140.53 Fastly-Client-Ip: 10.18.140.53 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 10.18.140.53 Upgrade-Insecure-Requests: 1 X-Client-Ip: 10.18.140.53 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 10.18.140.53 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --3b1af431-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --3b1af431-E-- --3b1af431-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/src/.env"] [unique_id "apTyeH7glkZrdsSdRApIpwAAAJM"] Stopwatch: 1788146296654866 5854 (- - -) Stopwatch2: 1788146296654866 5854; combined=4516, p1=275, p2=4135, p3=62, p4=7, p5=37, sr=114, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --3b1af431-Z-- --5acf943e-A-- [31/Aug/2026:06:18:16.668487 +0300] apTyeH7glkZrdsSdRApIqAAAAI4 34.24.95.24 55514 127.0.0.1 7081 --5acf943e-B-- GET /app/.env HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 172.18.156.47 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 172.18.156.47 Fastly-Client-Ip: 172.18.156.47 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 172.18.156.47 Upgrade-Insecure-Requests: 1 X-Client-Ip: 172.18.156.47 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 172.18.156.47 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --5acf943e-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --5acf943e-E-- --5acf943e-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/app/.env"] [unique_id "apTyeH7glkZrdsSdRApIqAAAAI4"] Stopwatch: 1788146296662215 6356 (- - -) Stopwatch2: 1788146296662215 6356; combined=5053, p1=251, p2=4696, p3=60, p4=6, p5=40, sr=99, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --5acf943e-Z-- --40b18017-A-- [31/Aug/2026:06:18:16.813292 +0300] apTyeG7fDIutYTwcPOkZ5gAAAFU 34.24.95.24 55530 127.0.0.1 7081 --40b18017-B-- GET /server/.env HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 10.127.65.47 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 10.127.65.47 Fastly-Client-Ip: 10.127.65.47 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 10.127.65.47 Upgrade-Insecure-Requests: 1 X-Client-Ip: 10.127.65.47 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 10.127.65.47 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --40b18017-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --40b18017-E-- --40b18017-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/server/.env"] [unique_id "apTyeG7fDIutYTwcPOkZ5gAAAFU"] Stopwatch: 1788146296807126 6260 (- - -) Stopwatch2: 1788146296807126 6260; combined=4883, p1=287, p2=4489, p3=61, p4=7, p5=38, sr=101, sw=1, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --40b18017-Z-- --1f538b55-A-- [31/Aug/2026:06:18:16.851397 +0300] apTyeG7fDIutYTwcPOkZ5wAAAFc 34.24.95.24 55532 127.0.0.1 7081 --1f538b55-B-- GET /frontend/.env HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 172.23.151.239 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 172.23.151.239 Fastly-Client-Ip: 172.23.151.239 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 172.23.151.239 Upgrade-Insecure-Requests: 1 X-Client-Ip: 172.23.151.239 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 172.23.151.239 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --1f538b55-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --1f538b55-E-- --1f538b55-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/frontend/.env"] [unique_id "apTyeG7fDIutYTwcPOkZ5wAAAFc"] Stopwatch: 1788146296845539 5965 (- - -) Stopwatch2: 1788146296845539 5965; combined=4584, p1=259, p2=4208, p3=64, p4=8, p5=45, sr=100, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --1f538b55-Z-- --dde88c6f-A-- [31/Aug/2026:06:18:16.855816 +0300] apTyeNmUuou1H8H2UKXBOwAAANE 34.24.95.24 55534 127.0.0.1 7081 --dde88c6f-B-- GET /staging/.env HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 10.180.250.39 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 10.180.250.39 Fastly-Client-Ip: 10.180.250.39 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 10.180.250.39 Upgrade-Insecure-Requests: 1 X-Client-Ip: 10.180.250.39 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 10.180.250.39 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --dde88c6f-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --dde88c6f-E-- --dde88c6f-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/staging/.env"] [unique_id "apTyeNmUuou1H8H2UKXBOwAAANE"] Stopwatch: 1788146296848798 7116 (- - -) Stopwatch2: 1788146296848798 7116; combined=5918, p1=259, p2=5530, p3=77, p4=8, p5=43, sr=95, sw=1, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --dde88c6f-Z-- --84d97830-A-- [31/Aug/2026:06:18:16.865150 +0300] apTyeNmUuou1H8H2UKXBPAAAAM8 34.24.95.24 55550 127.0.0.1 7081 --84d97830-B-- GET /docker/.env HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 172.23.154.108 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 172.23.154.108 Fastly-Client-Ip: 172.23.154.108 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 172.23.154.108 Upgrade-Insecure-Requests: 1 X-Client-Ip: 172.23.154.108 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 172.23.154.108 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --84d97830-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --84d97830-E-- --84d97830-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/docker/.env"] [unique_id "apTyeNmUuou1H8H2UKXBPAAAAM8"] Stopwatch: 1788146296859348 5885 (- - -) Stopwatch2: 1788146296859348 5885; combined=4564, p1=278, p2=4180, p3=60, p4=8, p5=38, sr=95, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --84d97830-Z-- --6df58a70-A-- [31/Aug/2026:06:18:16.923073 +0300] apTyeG7fDIutYTwcPOkZ6AAAAEA 34.24.95.24 55556 127.0.0.1 7081 --6df58a70-B-- GET /dev/.env HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 10.201.112.26 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 10.201.112.26 Fastly-Client-Ip: 10.201.112.26 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 10.201.112.26 Upgrade-Insecure-Requests: 1 X-Client-Ip: 10.201.112.26 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 10.201.112.26 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --6df58a70-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --6df58a70-E-- --6df58a70-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/dev/.env"] [unique_id "apTyeG7fDIutYTwcPOkZ6AAAAEA"] Stopwatch: 1788146296916732 6436 (- - -) Stopwatch2: 1788146296916732 6436; combined=4922, p1=337, p2=4480, p3=59, p4=8, p5=38, sr=144, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --6df58a70-Z-- --c31cca52-A-- [31/Aug/2026:06:18:17.036011 +0300] apTyeX7glkZrdsSdRApIqQAAAJY 34.24.95.24 55562 127.0.0.1 7081 --c31cca52-B-- GET /apps/.env HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 192.168.58.51 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 192.168.58.51 Fastly-Client-Ip: 192.168.58.51 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 192.168.58.51 Upgrade-Insecure-Requests: 1 X-Client-Ip: 192.168.58.51 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 192.168.58.51 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --c31cca52-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --c31cca52-E-- --c31cca52-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/apps/.env"] [unique_id "apTyeX7glkZrdsSdRApIqQAAAJY"] Stopwatch: 1788146297029982 6119 (- - -) Stopwatch2: 1788146297029982 6119; combined=4856, p1=263, p2=4477, p3=63, p4=8, p5=44, sr=93, sw=1, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --c31cca52-Z-- --1ea68b55-A-- [31/Aug/2026:06:18:17.359323 +0300] apTyeX7glkZrdsSdRApIqgAAAJg 34.24.95.24 55598 127.0.0.1 7081 --1ea68b55-B-- GET /.git/HEAD HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 172.20.101.121 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 172.20.101.121 Fastly-Client-Ip: 172.20.101.121 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 172.20.101.121 Upgrade-Insecure-Requests: 1 X-Client-Ip: 172.20.101.121 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 172.20.101.121 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --1ea68b55-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --1ea68b55-E-- --1ea68b55-H-- Message: Warning. String match "/.git/" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "656"] [id "77318034"] [msg "IM360 WAF: Blocked access to git folder||T:APACHE||MV:/.git/head||"] [severity "NOTICE"] [tag "service_i360custom"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.git/" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "656"] [id "77318034"] [msg "IM360 WAF: Blocked access to git folder||T:APACHE||MV:/.git/head||"] [severity "NOTICE"] [tag "service_i360custom"] [hostname "webmail.chania24.taxi"] [uri "/.git/HEAD"] [unique_id "apTyeX7glkZrdsSdRApIqgAAAJg"] Stopwatch: 1788146297353309 6121 (- - -) Stopwatch2: 1788146297353309 6121; combined=4820, p1=286, p2=4416, p3=69, p4=6, p5=42, sr=103, sw=1, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --1ea68b55-Z-- --a053d533-A-- [31/Aug/2026:06:18:17.473773 +0300] apTyedmUuou1H8H2UKXBPwAAAMw 34.24.95.24 55602 127.0.0.1 7081 --a053d533-B-- GET /v2/.env HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 192.168.89.16 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 192.168.89.16 Fastly-Client-Ip: 192.168.89.16 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 192.168.89.16 Upgrade-Insecure-Requests: 1 X-Client-Ip: 192.168.89.16 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 192.168.89.16 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --a053d533-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --a053d533-E-- --a053d533-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/v2/.env"] [unique_id "apTyedmUuou1H8H2UKXBPwAAAMw"] Stopwatch: 1788146297467877 5981 (- - -) Stopwatch2: 1788146297467877 5981; combined=4611, p1=317, p2=4173, p3=61, p4=7, p5=53, sr=125, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --a053d533-Z-- --ee575677-A-- [31/Aug/2026:06:18:17.556327 +0300] apTyeX7glkZrdsSdRApIqwAAAIQ 34.24.95.24 55608 127.0.0.1 7081 --ee575677-B-- GET /old/.env HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 192.168.58.243 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 192.168.58.243 Fastly-Client-Ip: 192.168.58.243 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 192.168.58.243 Upgrade-Insecure-Requests: 1 X-Client-Ip: 192.168.58.243 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 192.168.58.243 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --ee575677-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --ee575677-E-- --ee575677-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/old/.env"] [unique_id "apTyeX7glkZrdsSdRApIqwAAAIQ"] Stopwatch: 1788146297550242 6193 (- - -) Stopwatch2: 1788146297550242 6193; combined=4848, p1=291, p2=4447, p3=62, p4=7, p5=41, sr=116, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --ee575677-Z-- --458bcb0b-A-- [31/Aug/2026:06:18:39.711453 +0300] apTyjtmUuou1H8H2UKXBRgAAAM4 81.171.72.135 45334 127.0.0.1 7081 --458bcb0b-B-- GET /.ssh/id_rsa HTTP/1.1 Host: ajutam.ro X-Real-IP: 81.171.72.135 X-Accel-Internal: /internal-nginx-static-location User-Agent: Go-http-client/1.1 Accept-Encoding: gzip --458bcb0b-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/7.3.33 Expires: Wed, 11 Jan 1984 05:00:00 GMT Cache-Control: no-cache, must-revalidate, max-age=0, no-store, private Link: ; rel="https://api.w.org/" X-TEC-API-VERSION: v1 X-TEC-API-ROOT: https://ajutam.ro/wp-json/tribe/events/v1/ X-TEC-API-ORIGIN: https://ajutam.ro Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --458bcb0b-H-- Message: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.ssh/id_rsa||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.ssh/id_rsa||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.ssh/id_rsa||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "ajutam.ro"] [uri "/.ssh/id_rsa"] [unique_id "apTyjtmUuou1H8H2UKXBRgAAAM4"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.ssh/id_rsa||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "ajutam.ro"] [uri "/.ssh/id_rsa"] [unique_id "apTyjtmUuou1H8H2UKXBRgAAAM4"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ajutam.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788146318994356 717164 (- - -) Stopwatch2: 1788146318994356 717164; combined=41607, p1=247, p2=41303, p3=0, p4=0, p5=57, sr=95, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --458bcb0b-Z-- --6ccc7604-A-- [31/Aug/2026:06:18:40.454980 +0300] apTykNmUuou1H8H2UKXBSwAAANQ 81.171.72.135 45376 127.0.0.1 7081 --6ccc7604-B-- GET /.git/HEAD HTTP/1.1 Host: ajutam.ro X-Real-IP: 81.171.72.135 X-Accel-Internal: /internal-nginx-static-location User-Agent: Go-http-client/1.1 Accept-Encoding: gzip --6ccc7604-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/7.3.33 Expires: Wed, 11 Jan 1984 05:00:00 GMT Cache-Control: no-cache, must-revalidate, max-age=0, no-store, private Link: ; rel="https://api.w.org/" X-TEC-API-VERSION: v1 X-TEC-API-ROOT: https://ajutam.ro/wp-json/tribe/events/v1/ X-TEC-API-ORIGIN: https://ajutam.ro Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --6ccc7604-H-- Message: Warning. String match "/.git/" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "656"] [id "77318034"] [msg "IM360 WAF: Blocked access to git folder||T:APACHE||MV:/.git/head||"] [severity "NOTICE"] [tag "service_i360custom"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.git/" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "656"] [id "77318034"] [msg "IM360 WAF: Blocked access to git folder||T:APACHE||MV:/.git/head||"] [severity "NOTICE"] [tag "service_i360custom"] [hostname "ajutam.ro"] [uri "/.git/HEAD"] [unique_id "apTykNmUuou1H8H2UKXBSwAAANQ"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ajutam.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788146320112532 342506 (- - -) Stopwatch2: 1788146320112532 342506; combined=3568, p1=234, p2=3282, p3=0, p4=0, p5=52, sr=86, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --6ccc7604-Z-- --9af7f705-A-- [31/Aug/2026:06:18:40.785324 +0300] apTykH7glkZrdsSdRApIrQAAAIc 81.171.72.135 45380 127.0.0.1 7081 --9af7f705-B-- GET /.env HTTP/1.1 Host: ajutam.ro X-Real-IP: 81.171.72.135 X-Accel-Internal: /internal-nginx-static-location User-Agent: Go-http-client/1.1 Accept-Encoding: gzip --9af7f705-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/7.3.33 Expires: Wed, 11 Jan 1984 05:00:00 GMT Cache-Control: no-cache, must-revalidate, max-age=0, no-store, private Link: ; rel="https://api.w.org/" X-TEC-API-VERSION: v1 X-TEC-API-ROOT: https://ajutam.ro/wp-json/tribe/events/v1/ X-TEC-API-ORIGIN: https://ajutam.ro Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --9af7f705-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "ajutam.ro"] [uri "/.env"] [unique_id "apTykH7glkZrdsSdRApIrQAAAIc"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ajutam.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788146320495255 290137 (- - -) Stopwatch2: 1788146320495255 290137; combined=3730, p1=197, p2=3479, p3=0, p4=0, p5=54, sr=85, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --9af7f705-Z-- --90b06164-A-- [31/Aug/2026:06:18:41.057730 +0300] apTykNmUuou1H8H2UKXBTAAAAMw 81.171.72.135 45392 127.0.0.1 7081 --90b06164-B-- GET /api/.env HTTP/1.1 Host: ajutam.ro X-Real-IP: 81.171.72.135 X-Accel-Internal: /internal-nginx-static-location User-Agent: Go-http-client/1.1 Accept-Encoding: gzip --90b06164-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/7.3.33 Expires: Wed, 11 Jan 1984 05:00:00 GMT Cache-Control: no-cache, must-revalidate, max-age=0, no-store, private Link: ; rel="https://api.w.org/" X-TEC-API-VERSION: v1 X-TEC-API-ROOT: https://ajutam.ro/wp-json/tribe/events/v1/ X-TEC-API-ORIGIN: https://ajutam.ro Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --90b06164-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "ajutam.ro"] [uri "/api/.env"] [unique_id "apTykNmUuou1H8H2UKXBTAAAAMw"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ajutam.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788146320699311 358491 (- - -) Stopwatch2: 1788146320699311 358491; combined=3640, p1=200, p2=3391, p3=0, p4=0, p5=49, sr=86, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --90b06164-Z-- --d5d10130-A-- [31/Aug/2026:06:18:42.475332 +0300] apTykn7glkZrdsSdRApIrwAAAIs 81.171.72.135 45452 127.0.0.1 7081 --d5d10130-B-- GET /backup.tar.gz HTTP/1.1 Host: ajutam.ro X-Real-IP: 81.171.72.135 X-Accel-Internal: /internal-nginx-static-location User-Agent: Go-http-client/1.1 Accept-Encoding: gzip --d5d10130-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/7.3.33 Expires: Wed, 11 Jan 1984 05:00:00 GMT Cache-Control: no-cache, must-revalidate, max-age=0, no-store, private Link: ; rel="https://api.w.org/" X-TEC-API-VERSION: v1 X-TEC-API-ROOT: https://ajutam.ro/wp-json/tribe/events/v1/ X-TEC-API-ORIGIN: https://ajutam.ro Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --d5d10130-H-- Message: Warning. Matched phrase "/backup." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/backup.tar.gz||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Matched phrase "/backup." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/backup.tar.gz||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "/backup." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/backup.tar.gz||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "ajutam.ro"] [uri "/backup.tar.gz"] [unique_id "apTykn7glkZrdsSdRApIrwAAAIs"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "/backup." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/backup.tar.gz||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "ajutam.ro"] [uri "/backup.tar.gz"] [unique_id "apTykn7glkZrdsSdRApIrwAAAIs"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ajutam.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788146322066117 409273 (- - -) Stopwatch2: 1788146322066117 409273; combined=37959, p1=184, p2=37720, p3=0, p4=0, p5=55, sr=73, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --d5d10130-Z-- --25874a28-A-- [31/Aug/2026:06:18:43.015279 +0300] apTyktmUuou1H8H2UKXBUgAAAM4 81.171.72.135 45470 127.0.0.1 7081 --25874a28-B-- GET /.npmrc HTTP/1.1 Host: ajutam.ro X-Real-IP: 81.171.72.135 X-Accel-Internal: /internal-nginx-static-location User-Agent: Go-http-client/1.1 Accept-Encoding: gzip --25874a28-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/7.3.33 Expires: Wed, 11 Jan 1984 05:00:00 GMT Cache-Control: no-cache, must-revalidate, max-age=0, no-store, private Link: ; rel="https://api.w.org/" X-TEC-API-VERSION: v1 X-TEC-API-ROOT: https://ajutam.ro/wp-json/tribe/events/v1/ X-TEC-API-ORIGIN: https://ajutam.ro Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --25874a28-H-- Message: Warning. Matched phrase ".npmrc" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.npmrc||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Matched phrase ".npmrc" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.npmrc||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".npmrc" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.npmrc||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "ajutam.ro"] [uri "/.npmrc"] [unique_id "apTyktmUuou1H8H2UKXBUgAAAM4"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".npmrc" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.npmrc||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "ajutam.ro"] [uri "/.npmrc"] [unique_id "apTyktmUuou1H8H2UKXBUgAAAM4"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ajutam.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788146322534872 480471 (- - -) Stopwatch2: 1788146322534872 480471; combined=33966, p1=362, p2=33548, p3=0, p4=0, p5=55, sr=175, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --25874a28-Z-- --3d6edc59-A-- [31/Aug/2026:06:18:43.156299 +0300] apTykm7fDIutYTwcPOkZ7AAAAEQ 81.171.72.135 45486 127.0.0.1 7081 --3d6edc59-B-- GET /backup.zip HTTP/1.1 Host: ajutam.ro X-Real-IP: 81.171.72.135 X-Accel-Internal: /internal-nginx-static-location User-Agent: Go-http-client/1.1 Accept-Encoding: gzip --3d6edc59-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/7.3.33 Expires: Wed, 11 Jan 1984 05:00:00 GMT Cache-Control: no-cache, must-revalidate, max-age=0, no-store, private Link: ; rel="https://api.w.org/" X-TEC-API-VERSION: v1 X-TEC-API-ROOT: https://ajutam.ro/wp-json/tribe/events/v1/ X-TEC-API-ORIGIN: https://ajutam.ro Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --3d6edc59-H-- Message: Warning. Matched phrase "/backup." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/backup.zip||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Matched phrase "/backup." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/backup.zip||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "/backup." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/backup.zip||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "ajutam.ro"] [uri "/backup.zip"] [unique_id "apTykm7fDIutYTwcPOkZ7AAAAEQ"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "/backup." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/backup.zip||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "ajutam.ro"] [uri "/backup.zip"] [unique_id "apTykm7fDIutYTwcPOkZ7AAAAEQ"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ajutam.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788146322638064 518312 (- - -) Stopwatch2: 1788146322638064 518312; combined=36877, p1=166, p2=36654, p3=0, p4=0, p5=56, sr=65, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --3d6edc59-Z-- --3b1af431-A-- [31/Aug/2026:06:18:43.368403 +0300] apTykm7fDIutYTwcPOkZ7QAAAEk 81.171.72.135 45492 127.0.0.1 7081 --3b1af431-B-- GET /.ssh/id_ed25519 HTTP/1.1 Host: ajutam.ro X-Real-IP: 81.171.72.135 X-Accel-Internal: /internal-nginx-static-location User-Agent: Go-http-client/1.1 Accept-Encoding: gzip --3b1af431-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/7.3.33 Expires: Wed, 11 Jan 1984 05:00:00 GMT Cache-Control: no-cache, must-revalidate, max-age=0, no-store, private Link: ; rel="https://api.w.org/" X-TEC-API-VERSION: v1 X-TEC-API-ROOT: https://ajutam.ro/wp-json/tribe/events/v1/ X-TEC-API-ORIGIN: https://ajutam.ro Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --3b1af431-H-- Message: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.ssh/id_ed25519||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.ssh/id_ed25519||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.ssh/id_ed25519||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "ajutam.ro"] [uri "/.ssh/id_ed25519"] [unique_id "apTykm7fDIutYTwcPOkZ7QAAAEk"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.ssh/id_ed25519||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "ajutam.ro"] [uri "/.ssh/id_ed25519"] [unique_id "apTykm7fDIutYTwcPOkZ7QAAAEk"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ajutam.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788146322915826 452636 (- - -) Stopwatch2: 1788146322915826 452636; combined=32530, p1=238, p2=32233, p3=0, p4=0, p5=58, sr=125, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --3b1af431-Z-- --8d0fff34-A-- [31/Aug/2026:06:18:43.854479 +0300] apTyk9mUuou1H8H2UKXBVAAAANY 81.171.72.135 45514 127.0.0.1 7081 --8d0fff34-B-- GET /config.php HTTP/1.1 Host: ajutam.ro X-Real-IP: 81.171.72.135 X-Accel-Internal: /internal-nginx-static-location User-Agent: Go-http-client/1.1 Accept-Encoding: gzip --8d0fff34-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/7.3.33 Expires: Wed, 11 Jan 1984 05:00:00 GMT Cache-Control: no-cache, must-revalidate, max-age=0, no-store, private Link: ; rel="https://api.w.org/" X-TEC-API-VERSION: v1 X-TEC-API-ROOT: https://ajutam.ro/wp-json/tribe/events/v1/ X-TEC-API-ORIGIN: https://ajutam.ro Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --8d0fff34-H-- Message: Warning. Matched phrase "/config.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "/config.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "ajutam.ro"] [uri "/config.php"] [unique_id "apTyk9mUuou1H8H2UKXBVAAAANY"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ajutam.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788146323471566 382982 (- - -) Stopwatch2: 1788146323471566 382982; combined=13246, p1=228, p2=12968, p3=0, p4=0, p5=49, sr=112, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --8d0fff34-Z-- --559c7c78-A-- [31/Aug/2026:06:18:43.871529 +0300] apTyk9mUuou1H8H2UKXBVQAAANc 81.171.72.135 45530 127.0.0.1 7081 --559c7c78-B-- GET /.svn/wc.db HTTP/1.1 Host: ajutam.ro X-Real-IP: 81.171.72.135 X-Accel-Internal: /internal-nginx-static-location User-Agent: Go-http-client/1.1 Accept-Encoding: gzip --559c7c78-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/7.3.33 Expires: Wed, 11 Jan 1984 05:00:00 GMT Cache-Control: no-cache, must-revalidate, max-age=0, no-store, private Link: ; rel="https://api.w.org/" X-TEC-API-VERSION: v1 X-TEC-API-ROOT: https://ajutam.ro/wp-json/tribe/events/v1/ X-TEC-API-ORIGIN: https://ajutam.ro Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --559c7c78-H-- Message: Warning. Matched phrase ".svn/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.svn/wc.db||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Matched phrase ".svn/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.svn/wc.db||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".svn/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.svn/wc.db||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "ajutam.ro"] [uri "/.svn/wc.db"] [unique_id "apTyk9mUuou1H8H2UKXBVQAAANc"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".svn/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.svn/wc.db||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "ajutam.ro"] [uri "/.svn/wc.db"] [unique_id "apTyk9mUuou1H8H2UKXBVQAAANc"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ajutam.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788146323483415 388238 (- - -) Stopwatch2: 1788146323483415 388238; combined=33241, p1=194, p2=32981, p3=0, p4=0, p5=66, sr=68, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --559c7c78-Z-- --cc644f03-A-- [31/Aug/2026:06:18:44.077667 +0300] apTyk9mUuou1H8H2UKXBVgAAAM8 81.171.72.135 45542 127.0.0.1 7081 --cc644f03-B-- GET /backup.sql HTTP/1.1 Host: ajutam.ro X-Real-IP: 81.171.72.135 X-Accel-Internal: /internal-nginx-static-location User-Agent: Go-http-client/1.1 Accept-Encoding: gzip --cc644f03-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/7.3.33 Expires: Wed, 11 Jan 1984 05:00:00 GMT Cache-Control: no-cache, must-revalidate, max-age=0, no-store, private Link: ; rel="https://api.w.org/" X-TEC-API-VERSION: v1 X-TEC-API-ROOT: https://ajutam.ro/wp-json/tribe/events/v1/ X-TEC-API-ORIGIN: https://ajutam.ro Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --cc644f03-H-- Message: Warning. Matched phrase "/backup." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/backup.sql||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Matched phrase "/backup." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/backup.sql||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "/backup." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/backup.sql||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "ajutam.ro"] [uri "/backup.sql"] [unique_id "apTyk9mUuou1H8H2UKXBVgAAAM8"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "/backup." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/backup.sql||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "ajutam.ro"] [uri "/backup.sql"] [unique_id "apTyk9mUuou1H8H2UKXBVgAAAM8"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ajutam.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788146323758393 319341 (- - -) Stopwatch2: 1788146323758393 319341; combined=31236, p1=281, p2=30888, p3=0, p4=0, p5=66, sr=117, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --cc644f03-Z-- --5acf943e-A-- [31/Aug/2026:06:19:41.656415 +0300] apTyzW7fDIutYTwcPOkZ7gAAAE8 207.154.219.81 55532 127.0.0.1 7081 --5acf943e-B-- POST /wp-login.php HTTP/1.1 Host: ajutam.ro X-Real-IP: 207.154.219.81 X-Accel-Internal: /internal-nginx-static-location Content-Length: 108 Accept: */* User-Agent: Mozilla/5.0 Content-Type: application/x-www-form-urlencoded Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818 --5acf943e-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --5acf943e-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:06-19.207.154.219.81"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788146381432788 223719 (- - -) Stopwatch2: 1788146381432788 223719; combined=214003, p1=2297, p2=210970, p3=0, p4=0, p5=570, sr=192, sw=166, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --5acf943e-Z-- --71f54c01-A-- [31/Aug/2026:06:26:23.945400 +0300] apT0X9mUuou1H8H2UKXBeAAAAMA 207.154.219.81 60682 127.0.0.1 7081 --71f54c01-B-- POST /wp-login.php HTTP/1.1 Host: ajutam.ro X-Real-IP: 207.154.219.81 X-Accel-Internal: /internal-nginx-static-location Content-Length: 110 Accept: */* User-Agent: Mozilla/5.0 Content-Type: application/x-www-form-urlencoded Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818 --71f54c01-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --71f54c01-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:06-26.207.154.219.81"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788146783882308 63148 (- - -) Stopwatch2: 1788146783882308 63148; combined=61290, p1=460, p2=60240, p3=0, p4=0, p5=447, sr=158, sw=143, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --71f54c01-Z-- --78c8584d-A-- [31/Aug/2026:06:31:22.840325 +0300] apT1itmUuou1H8H2UKXBjAAAAMs 138.197.193.77 46962 127.0.0.1 7081 --78c8584d-B-- POST /wp-login.php HTTP/1.1 Host: ajutam.ro X-Real-IP: 138.197.193.77 X-Accel-Internal: /internal-nginx-static-location Content-Length: 105 Accept: */* User-Agent: Mozilla/5.0 Content-Type: application/x-www-form-urlencoded Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818 --78c8584d-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --78c8584d-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:06-31.138.197.193.77"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788147082777068 63406 (- - -) Stopwatch2: 1788147082777068 63406; combined=58769, p1=298, p2=57042, p3=0, p4=0, p5=1040, sr=109, sw=389, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --78c8584d-Z-- --6659a052-A-- [31/Aug/2026:06:33:06.468117 +0300] apT18n7glkZrdsSdRApI1wAAAIo 207.154.219.81 33312 127.0.0.1 7081 --6659a052-B-- POST /wp-login.php HTTP/1.1 Host: ajutam.ro X-Real-IP: 207.154.219.81 X-Accel-Internal: /internal-nginx-static-location Content-Length: 111 Accept: */* User-Agent: Mozilla/5.0 Content-Type: application/x-www-form-urlencoded Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818 --6659a052-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --6659a052-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:06-33.207.154.219.81"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788147186406485 61716 (- - -) Stopwatch2: 1788147186406485 61716; combined=59131, p1=362, p2=57834, p3=0, p4=0, p5=672, sr=99, sw=263, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --6659a052-Z-- --ebd7b367-A-- [31/Aug/2026:06:33:15.423751 +0300] apT1@9mUuou1H8H2UKXBpAAAAMk 216.73.217.35 33358 127.0.0.1 7081 --ebd7b367-B-- GET /img/ufo_fm.php?p=%27+.+urlencode%28%24bp%29+.+%27 HTTP/1.1 Host: ihelp.ro X-Real-IP: 216.73.217.35 X-Accel-Internal: /internal-nginx-static-location accept: */* user-agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com) accept-encoding: gzip, br, zstd, deflate --ebd7b367-F-- HTTP/1.1 200 OK X-Powered-By: PHP/8.1.34 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --ebd7b367-H-- Message: Warning. Pattern match "(?i)\\b(?:s(?:e(?:t(?:_(?:e(?:xception|rror)_handler|magic_quotes_runtime|include_path)|defaultstub)|ssion_s(?:et_save_handler|tart))|qlite_(?:(?:(?:unbuffered|single|array)_)?query|create_(?:aggregate|function)|p?open|exec)|tr(?:eam_(?:context_create| ..." at ARGS:p. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "63"] [id "77134464"] [msg "IM360 WAF: Infectors: PHP Injection High-Risk PHP Function||T:APACHE||MVN:ARGS:p||MV:' . urlencode($bp) . '||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_o"] [tag "service_i360"] Message: Warning. Pattern match "(?i)\\b(?:s(?:e(?:t(?:_(?:e(?:xception|rror)_handler|magic_quotes_runtime|include_path)|defaultstub)|ssion_s(?:et_save_handler|tart))|qlite_(?:(?:(?:unbuffered|single|array)_)?query|create_(?:aggregate|function)|p?open|exec)|tr(?:eam_(?:context_create| ..." at ARGS:p. [file "/etc/httpd/conf/modsecurity.d/rules/custom/012_i360_1_generic.conf"] [line "19"] [id "77134463"] [msg "IM360 WAF: PHP Injection Attack: High-Risk PHP Function Call Found||T:APACHE||MVN:ARGS:p||MV:' . urlencode($bp) . '||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "NOTICE"] [tag "service_o"] [tag "service_i360"] [tag "noshow"] [tag "service_rbl_infectors"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(?i)\\\\\\\\b(?:s(?:e(?:t(?:_(?:e(?:xception|rror)_handler|magic_quotes_runtime|include_path)|defaultstub)|ssion_s(?:et_save_handler|tart))|qlite_(?:(?:(?:unbuffered|single|array)_)?query|create_(?:aggregate|function)|p?open|exec)|tr(?:eam_(?:context_create| ..." at ARGS:p. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "63"] [id "77134464"] [msg "IM360 WAF: Infectors: PHP Injection High-Risk PHP Function||T:APACHE||MVN:ARGS:p||MV:' . urlencode($bp) . '||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_o"] [tag "service_i360"] [hostname "ihelp.ro"] [uri "/img/ufo_fm.php"] [unique_id "apT1@9mUuou1H8H2UKXBpAAAAMk"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(?i)\\\\\\\\b(?:s(?:e(?:t(?:_(?:e(?:xception|rror)_handler|magic_quotes_runtime|include_path)|defaultstub)|ssion_s(?:et_save_handler|tart))|qlite_(?:(?:(?:unbuffered|single|array)_)?query|create_(?:aggregate|function)|p?open|exec)|tr(?:eam_(?:context_create| ..." at ARGS:p. [file "/etc/httpd/conf/modsecurity.d/rules/custom/012_i360_1_generic.conf"] [line "19"] [id "77134463"] [msg "IM360 WAF: PHP Injection Attack: High-Risk PHP Function Call Found||T:APACHE||MVN:ARGS:p||MV:' . urlencode($bp) . '||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "NOTICE"] [tag "service_o"] [tag "service_i360"] [tag "noshow"] [tag "service_rbl_infectors"] [hostname "ihelp.ro"] [uri "/img/ufo_fm.php"] [unique_id "apT1@9mUuou1H8H2UKXBpAAAAMk"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788147195388110 35685 (- - -) Stopwatch2: 1788147195388110 35685; combined=33022, p1=239, p2=32728, p3=0, p4=0, p5=54, sr=110, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "DETECTION_ONLY" --ebd7b367-Z-- --4c9ada32-A-- [31/Aug/2026:06:33:42.334179 +0300] apT2FtmUuou1H8H2UKXBtAAAANA 216.73.217.35 42272 127.0.0.1 7081 --4c9ada32-B-- GET /img/ufo_fm.php?p=%27.urlencode%28%24acc%29.%27 HTTP/1.1 Host: ihelp.ro X-Real-IP: 216.73.217.35 X-Accel-Internal: /internal-nginx-static-location accept: */* user-agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com) accept-encoding: gzip, br, zstd, deflate --4c9ada32-F-- HTTP/1.1 200 OK X-Powered-By: PHP/8.1.34 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --4c9ada32-H-- Message: Warning. Pattern match "(?i)\\b(?:s(?:e(?:t(?:_(?:e(?:xception|rror)_handler|magic_quotes_runtime|include_path)|defaultstub)|ssion_s(?:et_save_handler|tart))|qlite_(?:(?:(?:unbuffered|single|array)_)?query|create_(?:aggregate|function)|p?open|exec)|tr(?:eam_(?:context_create| ..." at ARGS:p. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "63"] [id "77134464"] [msg "IM360 WAF: Infectors: PHP Injection High-Risk PHP Function||T:APACHE||MVN:ARGS:p||MV:'.urlencode($acc).'||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_o"] [tag "service_i360"] Message: Warning. Pattern match "(?i)\\b(?:s(?:e(?:t(?:_(?:e(?:xception|rror)_handler|magic_quotes_runtime|include_path)|defaultstub)|ssion_s(?:et_save_handler|tart))|qlite_(?:(?:(?:unbuffered|single|array)_)?query|create_(?:aggregate|function)|p?open|exec)|tr(?:eam_(?:context_create| ..." at ARGS:p. [file "/etc/httpd/conf/modsecurity.d/rules/custom/012_i360_1_generic.conf"] [line "19"] [id "77134463"] [msg "IM360 WAF: PHP Injection Attack: High-Risk PHP Function Call Found||T:APACHE||MVN:ARGS:p||MV:'.urlencode($acc).'||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "NOTICE"] [tag "service_o"] [tag "service_i360"] [tag "noshow"] [tag "service_rbl_infectors"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(?i)\\\\\\\\b(?:s(?:e(?:t(?:_(?:e(?:xception|rror)_handler|magic_quotes_runtime|include_path)|defaultstub)|ssion_s(?:et_save_handler|tart))|qlite_(?:(?:(?:unbuffered|single|array)_)?query|create_(?:aggregate|function)|p?open|exec)|tr(?:eam_(?:context_create| ..." at ARGS:p. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "63"] [id "77134464"] [msg "IM360 WAF: Infectors: PHP Injection High-Risk PHP Function||T:APACHE||MVN:ARGS:p||MV:'.urlencode($acc).'||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_o"] [tag "service_i360"] [hostname "ihelp.ro"] [uri "/img/ufo_fm.php"] [unique_id "apT2FtmUuou1H8H2UKXBtAAAANA"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(?i)\\\\\\\\b(?:s(?:e(?:t(?:_(?:e(?:xception|rror)_handler|magic_quotes_runtime|include_path)|defaultstub)|ssion_s(?:et_save_handler|tart))|qlite_(?:(?:(?:unbuffered|single|array)_)?query|create_(?:aggregate|function)|p?open|exec)|tr(?:eam_(?:context_create| ..." at ARGS:p. [file "/etc/httpd/conf/modsecurity.d/rules/custom/012_i360_1_generic.conf"] [line "19"] [id "77134463"] [msg "IM360 WAF: PHP Injection Attack: High-Risk PHP Function Call Found||T:APACHE||MVN:ARGS:p||MV:'.urlencode($acc).'||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "NOTICE"] [tag "service_o"] [tag "service_i360"] [tag "noshow"] [tag "service_rbl_infectors"] [hostname "ihelp.ro"] [uri "/img/ufo_fm.php"] [unique_id "apT2FtmUuou1H8H2UKXBtAAAANA"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788147222299416 34810 (- - -) Stopwatch2: 1788147222299416 34810; combined=31357, p1=252, p2=31039, p3=0, p4=0, p5=66, sr=91, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "DETECTION_ONLY" --4c9ada32-Z-- --61d28665-A-- [31/Aug/2026:06:34:01.083844 +0300] apT2KdmUuou1H8H2UKXBxAAAAMA 138.197.193.77 41028 127.0.0.1 7081 --61d28665-B-- POST /wp-login.php HTTP/1.1 Host: ajutam.ro X-Real-IP: 138.197.193.77 X-Accel-Internal: /internal-nginx-static-location Content-Length: 108 Accept: */* User-Agent: Mozilla/5.0 Content-Type: application/x-www-form-urlencoded Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818 --61d28665-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --61d28665-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "42"] [id "33302"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:1"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788147241081871 2042 (- - -) Stopwatch2: 1788147241081871 2042; combined=670, p1=275, p2=74, p3=0, p4=0, p5=321, sr=104, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --61d28665-Z-- --6209bb50-A-- [31/Aug/2026:06:34:10.857892 +0300] apT2Mn7glkZrdsSdRApI7QAAAIE 216.73.217.35 49202 127.0.0.1 7081 --6209bb50-B-- GET /img/ufo_fm.php?f=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2F.htaccess&p=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs HTTP/1.1 Host: ihelp.ro X-Real-IP: 216.73.217.35 X-Accel-Internal: /internal-nginx-static-location accept: */* user-agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com) accept-encoding: gzip, br, zstd, deflate --6209bb50-F-- HTTP/1.1 200 OK X-Powered-By: PHP/8.1.34 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --6209bb50-H-- Message: Warning. Match of "pm cpanel AdminTranslations" against "REQUEST_URI" required. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "65"] [id "77140882"] [msg "IM360 WAF: Infectors: Remote File Access Attempt||MVN:REQUEST_URI||MV:/img/ufo_fm.php?f=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2F.htaccess&p=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs||T:APACHE||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Match of "pm cpanel AdminTranslations" against "REQUEST_URI" required. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "65"] [id "77140882"] [msg "IM360 WAF: Infectors: Remote File Access Attempt||MVN:REQUEST_URI||MV:/img/ufo_fm.php?f=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2F.htaccess&p=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs||T:APACHE||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [hostname "ihelp.ro"] [uri "/img/ufo_fm.php"] [unique_id "apT2Mn7glkZrdsSdRApI7QAAAIE"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788147250822547 35393 (- - -) Stopwatch2: 1788147250822547 35393; combined=31347, p1=330, p2=30975, p3=0, p4=0, p5=42, sr=154, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "DETECTION_ONLY" --6209bb50-Z-- --9096fa5d-A-- [31/Aug/2026:06:35:54.784664 +0300] apT2mtmUuou1H8H2UKXB3AAAANU 216.73.217.35 45148 127.0.0.1 7081 --9096fa5d-B-- GET /img/ufo_fm.php?f=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2F.htaccess&p=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs&rm=1 HTTP/1.1 Host: ihelp.ro X-Real-IP: 216.73.217.35 X-Accel-Internal: /internal-nginx-static-location accept: */* user-agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com) accept-encoding: gzip, br, zstd, deflate --9096fa5d-F-- HTTP/1.1 200 OK X-Powered-By: PHP/8.1.34 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --9096fa5d-H-- Message: Warning. Match of "pm cpanel AdminTranslations" against "REQUEST_URI" required. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "65"] [id "77140882"] [msg "IM360 WAF: Infectors: Remote File Access Attempt||MVN:REQUEST_URI||MV:/img/ufo_fm.php?f=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2F.htaccess&p=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs&rm=1||T:APACHE||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Match of "pm cpanel AdminTranslations" against "REQUEST_URI" required. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "65"] [id "77140882"] [msg "IM360 WAF: Infectors: Remote File Access Attempt||MVN:REQUEST_URI||MV:/img/ufo_fm.php?f=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2F.htaccess&p=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs&rm=1||T:APACHE||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [hostname "ihelp.ro"] [uri "/img/ufo_fm.php"] [unique_id "apT2mtmUuou1H8H2UKXB3AAAANU"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788147354747689 37025 (- - -) Stopwatch2: 1788147354747689 37025; combined=33760, p1=378, p2=33328, p3=0, p4=0, p5=53, sr=129, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "DETECTION_ONLY" --9096fa5d-Z-- --c31cca52-A-- [31/Aug/2026:06:36:09.255535 +0300] apT2qW7fDIutYTwcPOkaEgAAAEc 216.73.217.35 54010 127.0.0.1 7081 --c31cca52-B-- GET /img/ufo_fm.php?dl=1&f=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2F.htaccess&p=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs HTTP/1.1 Host: ihelp.ro X-Real-IP: 216.73.217.35 X-Accel-Internal: /internal-nginx-static-location accept: */* user-agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com) accept-encoding: gzip, br, zstd, deflate --c31cca52-F-- HTTP/1.1 200 OK X-Powered-By: PHP/8.1.34 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --c31cca52-H-- Message: Warning. Match of "pm cpanel AdminTranslations" against "REQUEST_URI" required. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "65"] [id "77140882"] [msg "IM360 WAF: Infectors: Remote File Access Attempt||MVN:REQUEST_URI||MV:/img/ufo_fm.php?dl=1&f=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2F.htaccess&p=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs||T:APACHE||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Match of "pm cpanel AdminTranslations" against "REQUEST_URI" required. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "65"] [id "77140882"] [msg "IM360 WAF: Infectors: Remote File Access Attempt||MVN:REQUEST_URI||MV:/img/ufo_fm.php?dl=1&f=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2F.htaccess&p=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs||T:APACHE||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [hostname "ihelp.ro"] [uri "/img/ufo_fm.php"] [unique_id "apT2qW7fDIutYTwcPOkaEgAAAEc"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788147369218464 37119 (- - -) Stopwatch2: 1788147369218464 37119; combined=34546, p1=268, p2=34223, p3=0, p4=0, p5=55, sr=128, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "DETECTION_ONLY" --c31cca52-Z-- --cf618e21-A-- [31/Aug/2026:06:36:10.034061 +0300] apT2qtmUuou1H8H2UKXB7wAAAMc 216.73.217.35 54092 127.0.0.1 7081 --cf618e21-B-- GET /img/ufo_fm.php?f=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2Fwebroot%2F.htaccess&p=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2Fwebroot HTTP/1.1 Host: ihelp.ro X-Real-IP: 216.73.217.35 X-Accel-Internal: /internal-nginx-static-location accept: */* user-agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com) accept-encoding: gzip, br, zstd, deflate --cf618e21-F-- HTTP/1.1 200 OK X-Powered-By: PHP/8.1.34 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --cf618e21-H-- Message: Warning. Match of "pm cpanel AdminTranslations" against "REQUEST_URI" required. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "65"] [id "77140882"] [msg "IM360 WAF: Infectors: Remote File Access Attempt||MVN:REQUEST_URI||MV:/img/ufo_fm.php?f=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2Fwebroot%2F.htaccess&p=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2Fwebroot||T:APACHE||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Match of "pm cpanel AdminTranslations" against "REQUEST_URI" required. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "65"] [id "77140882"] [msg "IM360 WAF: Infectors: Remote File Access Attempt||MVN:REQUEST_URI||MV:/img/ufo_fm.php?f=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2Fwebroot%2F.htaccess&p=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2Fwebroot||T:APACHE||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [hostname "ihelp.ro"] [uri "/img/ufo_fm.php"] [unique_id "apT2qtmUuou1H8H2UKXB7wAAAMc"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788147370001236 32873 (- - -) Stopwatch2: 1788147370001236 32873; combined=30483, p1=203, p2=30232, p3=0, p4=0, p5=47, sr=78, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "DETECTION_ONLY" --cf618e21-Z-- --ebd6563c-A-- [31/Aug/2026:06:36:36.014925 +0300] apT2w37glkZrdsSdRApJCwAAAII 138.197.193.77 43740 127.0.0.1 7081 --ebd6563c-B-- POST /wp-login.php HTTP/1.1 Host: ajutam.ro X-Real-IP: 138.197.193.77 X-Accel-Internal: /internal-nginx-static-location Content-Length: 108 Accept: */* User-Agent: Mozilla/5.0 Content-Type: application/x-www-form-urlencoded Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818 --ebd6563c-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --ebd6563c-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:06-36.138.197.193.77"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788147395946407 68577 (- - -) Stopwatch2: 1788147395946407 68577; combined=67062, p1=322, p2=66096, p3=0, p4=0, p5=478, sr=129, sw=166, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --ebd6563c-Z-- --37873b20-A-- [31/Aug/2026:06:37:52.038879 +0300] apT3D9mUuou1H8H2UKXCFwAAAM8 216.73.217.35 53192 127.0.0.1 7081 --37873b20-B-- GET /img/ufo_fm.php?f=%27.%24enc.%27&p=%27.urlencode%28%24p%29.%27 HTTP/1.1 Host: ihelp.ro X-Real-IP: 216.73.217.35 X-Accel-Internal: /internal-nginx-static-location accept: */* user-agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com) accept-encoding: gzip, br, zstd, deflate --37873b20-F-- HTTP/1.1 200 OK X-Powered-By: PHP/8.1.34 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --37873b20-H-- Message: Warning. Pattern match "(?i)\\b(?:s(?:e(?:t(?:_(?:e(?:xception|rror)_handler|magic_quotes_runtime|include_path)|defaultstub)|ssion_s(?:et_save_handler|tart))|qlite_(?:(?:(?:unbuffered|single|array)_)?query|create_(?:aggregate|function)|p?open|exec)|tr(?:eam_(?:context_create| ..." at ARGS:p. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "63"] [id "77134464"] [msg "IM360 WAF: Infectors: PHP Injection High-Risk PHP Function||T:APACHE||MVN:ARGS:p||MV:'.urlencode($p).'||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_o"] [tag "service_i360"] Message: Warning. Pattern match "(?i)\\b(?:s(?:e(?:t(?:_(?:e(?:xception|rror)_handler|magic_quotes_runtime|include_path)|defaultstub)|ssion_s(?:et_save_handler|tart))|qlite_(?:(?:(?:unbuffered|single|array)_)?query|create_(?:aggregate|function)|p?open|exec)|tr(?:eam_(?:context_create| ..." at ARGS:p. [file "/etc/httpd/conf/modsecurity.d/rules/custom/012_i360_1_generic.conf"] [line "19"] [id "77134463"] [msg "IM360 WAF: PHP Injection Attack: High-Risk PHP Function Call Found||T:APACHE||MVN:ARGS:p||MV:'.urlencode($p).'||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "NOTICE"] [tag "service_o"] [tag "service_i360"] [tag "noshow"] [tag "service_rbl_infectors"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(?i)\\\\\\\\b(?:s(?:e(?:t(?:_(?:e(?:xception|rror)_handler|magic_quotes_runtime|include_path)|defaultstub)|ssion_s(?:et_save_handler|tart))|qlite_(?:(?:(?:unbuffered|single|array)_)?query|create_(?:aggregate|function)|p?open|exec)|tr(?:eam_(?:context_create| ..." at ARGS:p. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "63"] [id "77134464"] [msg "IM360 WAF: Infectors: PHP Injection High-Risk PHP Function||T:APACHE||MVN:ARGS:p||MV:'.urlencode($p).'||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_o"] [tag "service_i360"] [hostname "ihelp.ro"] [uri "/img/ufo_fm.php"] [unique_id "apT3D9mUuou1H8H2UKXCFwAAAM8"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(?i)\\\\\\\\b(?:s(?:e(?:t(?:_(?:e(?:xception|rror)_handler|magic_quotes_runtime|include_path)|defaultstub)|ssion_s(?:et_save_handler|tart))|qlite_(?:(?:(?:unbuffered|single|array)_)?query|create_(?:aggregate|function)|p?open|exec)|tr(?:eam_(?:context_create| ..." at ARGS:p. [file "/etc/httpd/conf/modsecurity.d/rules/custom/012_i360_1_generic.conf"] [line "19"] [id "77134463"] [msg "IM360 WAF: PHP Injection Attack: High-Risk PHP Function Call Found||T:APACHE||MVN:ARGS:p||MV:'.urlencode($p).'||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "NOTICE"] [tag "service_o"] [tag "service_i360"] [tag "noshow"] [tag "service_rbl_infectors"] [hostname "ihelp.ro"] [uri "/img/ufo_fm.php"] [unique_id "apT3D9mUuou1H8H2UKXCFwAAAM8"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788147471993993 44935 (- - -) Stopwatch2: 1788147471993993 44935; combined=38612, p1=275, p2=38231, p3=0, p4=0, p5=106, sr=114, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "DETECTION_ONLY" --37873b20-Z-- --050e0b57-A-- [31/Aug/2026:06:38:18.710033 +0300] apT3KtmUuou1H8H2UKXCHgAAANA 216.73.217.35 50862 127.0.0.1 7081 --050e0b57-B-- GET /img/ufo_fm.php?f=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2Fwebroot%2F.htaccess&p=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2Fwebroot&rm=1 HTTP/1.1 Host: ihelp.ro X-Real-IP: 216.73.217.35 X-Accel-Internal: /internal-nginx-static-location accept: */* user-agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com) accept-encoding: gzip, br, zstd, deflate --050e0b57-F-- HTTP/1.1 200 OK X-Powered-By: PHP/8.1.34 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --050e0b57-H-- Message: Warning. Match of "pm cpanel AdminTranslations" against "REQUEST_URI" required. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "65"] [id "77140882"] [msg "IM360 WAF: Infectors: Remote File Access Attempt||MVN:REQUEST_URI||MV:/img/ufo_fm.php?f=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2Fwebroot%2F.htaccess&p=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2Fwebroot&rm=1||T:APACHE||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Match of "pm cpanel AdminTranslations" against "REQUEST_URI" required. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "65"] [id "77140882"] [msg "IM360 WAF: Infectors: Remote File Access Attempt||MVN:REQUEST_URI||MV:/img/ufo_fm.php?f=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2Fwebroot%2F.htaccess&p=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2Fwebroot&rm=1||T:APACHE||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [hostname "ihelp.ro"] [uri "/img/ufo_fm.php"] [unique_id "apT3KtmUuou1H8H2UKXCHgAAANA"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788147498673823 36268 (- - -) Stopwatch2: 1788147498673823 36268; combined=33337, p1=281, p2=33010, p3=0, p4=0, p5=45, sr=130, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "DETECTION_ONLY" --050e0b57-Z-- --7f95b030-A-- [31/Aug/2026:06:38:19.979048 +0300] apT3K9mUuou1H8H2UKXCIwAAANY 216.73.217.35 50962 127.0.0.1 7081 --7f95b030-B-- GET /img/ufo_fm.php?dl=1&f=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2Fwebroot%2F.htaccess&p=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2Fwebroot HTTP/1.1 Host: ihelp.ro X-Real-IP: 216.73.217.35 X-Accel-Internal: /internal-nginx-static-location accept: */* user-agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com) accept-encoding: gzip, br, zstd, deflate --7f95b030-F-- HTTP/1.1 200 OK X-Powered-By: PHP/8.1.34 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --7f95b030-H-- Message: Warning. Match of "pm cpanel AdminTranslations" against "REQUEST_URI" required. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "65"] [id "77140882"] [msg "IM360 WAF: Infectors: Remote File Access Attempt||MVN:REQUEST_URI||MV:/img/ufo_fm.php?dl=1&f=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2Fwebroot%2F.htaccess&p=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2Fwebroot||T:APACHE||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Match of "pm cpanel AdminTranslations" against "REQUEST_URI" required. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "65"] [id "77140882"] [msg "IM360 WAF: Infectors: Remote File Access Attempt||MVN:REQUEST_URI||MV:/img/ufo_fm.php?dl=1&f=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2Fwebroot%2F.htaccess&p=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2Fwebroot||T:APACHE||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [hostname "ihelp.ro"] [uri "/img/ufo_fm.php"] [unique_id "apT3K9mUuou1H8H2UKXCIwAAANY"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788147499945526 33571 (- - -) Stopwatch2: 1788147499945526 33571; combined=31148, p1=230, p2=30867, p3=0, p4=0, p5=51, sr=87, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "DETECTION_ONLY" --7f95b030-Z-- --ecd73067-A-- [31/Aug/2026:06:38:43.164179 +0300] apT3Q37glkZrdsSdRApJKAAAAII 216.73.217.35 54824 127.0.0.1 7081 --ecd73067-B-- GET /img/ufo_fm.php?f=%27.%24enc.%27&p=%27.urlencode%28%24p%29.%27&rm=1 HTTP/1.1 Host: ihelp.ro X-Real-IP: 216.73.217.35 X-Accel-Internal: /internal-nginx-static-location accept: */* user-agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com) accept-encoding: gzip, br, zstd, deflate --ecd73067-F-- HTTP/1.1 200 OK X-Powered-By: PHP/8.1.34 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --ecd73067-H-- Message: Warning. Pattern match "(?i)\\b(?:s(?:e(?:t(?:_(?:e(?:xception|rror)_handler|magic_quotes_runtime|include_path)|defaultstub)|ssion_s(?:et_save_handler|tart))|qlite_(?:(?:(?:unbuffered|single|array)_)?query|create_(?:aggregate|function)|p?open|exec)|tr(?:eam_(?:context_create| ..." at ARGS:p. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "63"] [id "77134464"] [msg "IM360 WAF: Infectors: PHP Injection High-Risk PHP Function||T:APACHE||MVN:ARGS:p||MV:'.urlencode($p).'||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_o"] [tag "service_i360"] Message: Warning. Pattern match "(?i)\\b(?:s(?:e(?:t(?:_(?:e(?:xception|rror)_handler|magic_quotes_runtime|include_path)|defaultstub)|ssion_s(?:et_save_handler|tart))|qlite_(?:(?:(?:unbuffered|single|array)_)?query|create_(?:aggregate|function)|p?open|exec)|tr(?:eam_(?:context_create| ..." at ARGS:p. [file "/etc/httpd/conf/modsecurity.d/rules/custom/012_i360_1_generic.conf"] [line "19"] [id "77134463"] [msg "IM360 WAF: PHP Injection Attack: High-Risk PHP Function Call Found||T:APACHE||MVN:ARGS:p||MV:'.urlencode($p).'||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "NOTICE"] [tag "service_o"] [tag "service_i360"] [tag "noshow"] [tag "service_rbl_infectors"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(?i)\\\\\\\\b(?:s(?:e(?:t(?:_(?:e(?:xception|rror)_handler|magic_quotes_runtime|include_path)|defaultstub)|ssion_s(?:et_save_handler|tart))|qlite_(?:(?:(?:unbuffered|single|array)_)?query|create_(?:aggregate|function)|p?open|exec)|tr(?:eam_(?:context_create| ..." at ARGS:p. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "63"] [id "77134464"] [msg "IM360 WAF: Infectors: PHP Injection High-Risk PHP Function||T:APACHE||MVN:ARGS:p||MV:'.urlencode($p).'||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_o"] [tag "service_i360"] [hostname "ihelp.ro"] [uri "/img/ufo_fm.php"] [unique_id "apT3Q37glkZrdsSdRApJKAAAAII"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(?i)\\\\\\\\b(?:s(?:e(?:t(?:_(?:e(?:xception|rror)_handler|magic_quotes_runtime|include_path)|defaultstub)|ssion_s(?:et_save_handler|tart))|qlite_(?:(?:(?:unbuffered|single|array)_)?query|create_(?:aggregate|function)|p?open|exec)|tr(?:eam_(?:context_create| ..." at ARGS:p. [file "/etc/httpd/conf/modsecurity.d/rules/custom/012_i360_1_generic.conf"] [line "19"] [id "77134463"] [msg "IM360 WAF: PHP Injection Attack: High-Risk PHP Function Call Found||T:APACHE||MVN:ARGS:p||MV:'.urlencode($p).'||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "NOTICE"] [tag "service_o"] [tag "service_i360"] [tag "noshow"] [tag "service_rbl_infectors"] [hostname "ihelp.ro"] [uri "/img/ufo_fm.php"] [unique_id "apT3Q37glkZrdsSdRApJKAAAAII"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788147523129051 35174 (- - -) Stopwatch2: 1788147523129051 35174; combined=32591, p1=196, p2=32294, p3=0, p4=0, p5=101, sr=82, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "DETECTION_ONLY" --ecd73067-Z-- --3ff26137-A-- [31/Aug/2026:06:39:15.969288 +0300] apT3Y37glkZrdsSdRApJKQAAAJM 138.197.193.77 56892 127.0.0.1 7081 --3ff26137-B-- POST /wp-login.php HTTP/1.1 Host: ajutam.ro X-Real-IP: 138.197.193.77 X-Accel-Internal: /internal-nginx-static-location Content-Length: 110 Accept: */* User-Agent: Mozilla/5.0 Content-Type: application/x-www-form-urlencoded Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818 --3ff26137-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --3ff26137-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "42"] [id "33302"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:1"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788147555967468 1890 (- - -) Stopwatch2: 1788147555967468 1890; combined=595, p1=257, p2=84, p3=0, p4=0, p5=254, sr=108, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --3ff26137-Z-- --2a0ce25c-A-- [31/Aug/2026:06:39:39.472364 +0300] apT3e9mUuou1H8H2UKXCMQAAANY 216.73.217.35 55910 127.0.0.1 7081 --2a0ce25c-B-- GET /img/ufo_fm.php?dl=1&f=%27.%24enc.%27&p=%27.urlencode%28%24p%29.%27 HTTP/1.1 Host: ihelp.ro X-Real-IP: 216.73.217.35 X-Accel-Internal: /internal-nginx-static-location accept: */* user-agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com) accept-encoding: gzip, br, zstd, deflate --2a0ce25c-F-- HTTP/1.1 200 OK X-Powered-By: PHP/8.1.34 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --2a0ce25c-H-- Message: Warning. Pattern match "(?i)\\b(?:s(?:e(?:t(?:_(?:e(?:xception|rror)_handler|magic_quotes_runtime|include_path)|defaultstub)|ssion_s(?:et_save_handler|tart))|qlite_(?:(?:(?:unbuffered|single|array)_)?query|create_(?:aggregate|function)|p?open|exec)|tr(?:eam_(?:context_create| ..." at ARGS:p. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "63"] [id "77134464"] [msg "IM360 WAF: Infectors: PHP Injection High-Risk PHP Function||T:APACHE||MVN:ARGS:p||MV:'.urlencode($p).'||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_o"] [tag "service_i360"] Message: Warning. Pattern match "(?i)\\b(?:s(?:e(?:t(?:_(?:e(?:xception|rror)_handler|magic_quotes_runtime|include_path)|defaultstub)|ssion_s(?:et_save_handler|tart))|qlite_(?:(?:(?:unbuffered|single|array)_)?query|create_(?:aggregate|function)|p?open|exec)|tr(?:eam_(?:context_create| ..." at ARGS:p. [file "/etc/httpd/conf/modsecurity.d/rules/custom/012_i360_1_generic.conf"] [line "19"] [id "77134463"] [msg "IM360 WAF: PHP Injection Attack: High-Risk PHP Function Call Found||T:APACHE||MVN:ARGS:p||MV:'.urlencode($p).'||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "NOTICE"] [tag "service_o"] [tag "service_i360"] [tag "noshow"] [tag "service_rbl_infectors"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(?i)\\\\\\\\b(?:s(?:e(?:t(?:_(?:e(?:xception|rror)_handler|magic_quotes_runtime|include_path)|defaultstub)|ssion_s(?:et_save_handler|tart))|qlite_(?:(?:(?:unbuffered|single|array)_)?query|create_(?:aggregate|function)|p?open|exec)|tr(?:eam_(?:context_create| ..." at ARGS:p. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "63"] [id "77134464"] [msg "IM360 WAF: Infectors: PHP Injection High-Risk PHP Function||T:APACHE||MVN:ARGS:p||MV:'.urlencode($p).'||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_o"] [tag "service_i360"] [hostname "ihelp.ro"] [uri "/img/ufo_fm.php"] [unique_id "apT3e9mUuou1H8H2UKXCMQAAANY"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(?i)\\\\\\\\b(?:s(?:e(?:t(?:_(?:e(?:xception|rror)_handler|magic_quotes_runtime|include_path)|defaultstub)|ssion_s(?:et_save_handler|tart))|qlite_(?:(?:(?:unbuffered|single|array)_)?query|create_(?:aggregate|function)|p?open|exec)|tr(?:eam_(?:context_create| ..." at ARGS:p. [file "/etc/httpd/conf/modsecurity.d/rules/custom/012_i360_1_generic.conf"] [line "19"] [id "77134463"] [msg "IM360 WAF: PHP Injection Attack: High-Risk PHP Function Call Found||T:APACHE||MVN:ARGS:p||MV:'.urlencode($p).'||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "NOTICE"] [tag "service_o"] [tag "service_i360"] [tag "noshow"] [tag "service_rbl_infectors"] [hostname "ihelp.ro"] [uri "/img/ufo_fm.php"] [unique_id "apT3e9mUuou1H8H2UKXCMQAAANY"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788147579435229 37192 (- - -) Stopwatch2: 1788147579435229 37192; combined=33980, p1=389, p2=33525, p3=0, p4=0, p5=65, sr=160, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "DETECTION_ONLY" --2a0ce25c-Z-- --27f8364d-A-- [31/Aug/2026:06:39:52.134583 +0300] apT3iH7glkZrdsSdRApJNwAAAI8 207.154.219.81 52340 127.0.0.1 7081 --27f8364d-B-- POST /wp-login.php HTTP/1.1 Host: ajutam.ro X-Real-IP: 207.154.219.81 X-Accel-Internal: /internal-nginx-static-location Content-Length: 110 Accept: */* User-Agent: Mozilla/5.0 Content-Type: application/x-www-form-urlencoded Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818 --27f8364d-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --27f8364d-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:06-39.207.154.219.81"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788147592074826 59879 (- - -) Stopwatch2: 1788147592074826 59879; combined=58193, p1=246, p2=57181, p3=0, p4=0, p5=553, sr=92, sw=213, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --27f8364d-Z-- --ec426506-A-- [31/Aug/2026:06:40:33.059710 +0300] apT3sH7glkZrdsSdRApJPAAAAJc 45.79.180.146 54096 127.0.0.1 7081 --ec426506-B-- POST /wp-login.php HTTP/1.1 Host: axapres.ro X-Real-IP: 45.79.180.146 X-Accel-Internal: /internal-nginx-static-location Content-Length: 98 Accept: */* Accept-Encoding: gzip, deflate Cookie: wordpress_test_cookie=WP+Cookie+check User-Agent: Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.43 (KHTML, like Gecko) Chrome/139.0.0.0 Safari/537.36 OPR/123.0.0.0 Content-Type: application/x-www-form-urlencoded --ec426506-F-- HTTP/1.1 403 Forbidden Content-Length: 199 Content-Type: text/html; charset=iso-8859-1 --ec426506-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:06-40.45.79.180.146"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Apache-Handler: proxy:unix:/var/www/vhosts/system/axapres.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788147632995695 64071 (- - -) Stopwatch2: 1788147632995695 64071; combined=62215, p1=523, p2=60937, p3=0, p4=0, p5=526, sr=254, sw=229, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --ec426506-Z-- --f9b03763-A-- [31/Aug/2026:06:44:44.762206 +0300] apT4rH7glkZrdsSdRApJSwAAAJA 138.197.193.77 51650 127.0.0.1 7081 --f9b03763-B-- POST /wp-login.php HTTP/1.1 Host: ajutam.ro X-Real-IP: 138.197.193.77 X-Accel-Internal: /internal-nginx-static-location Content-Length: 111 Accept: */* User-Agent: Mozilla/5.0 Content-Type: application/x-www-form-urlencoded Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818 --f9b03763-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --f9b03763-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:06-44.138.197.193.77"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788147884692831 69450 (- - -) Stopwatch2: 1788147884692831 69450; combined=76813, p1=262, p2=58315, p3=0, p4=0, p5=9266, sr=110, sw=148, l=0, gc=8822 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --f9b03763-Z-- --1c88b226-A-- [31/Aug/2026:06:46:37.830846 +0300] apT5HX7glkZrdsSdRApJUAAAAI8 207.154.219.81 36712 127.0.0.1 7081 --1c88b226-B-- POST /wp-login.php HTTP/1.1 Host: ajutam.ro X-Real-IP: 207.154.219.81 X-Accel-Internal: /internal-nginx-static-location Content-Length: 109 Accept: */* User-Agent: Mozilla/5.0 Content-Type: application/x-www-form-urlencoded Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818 --1c88b226-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --1c88b226-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:06-46.207.154.219.81"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788147997769009 61900 (- - -) Stopwatch2: 1788147997769009 61900; combined=60041, p1=261, p2=58836, p3=0, p4=0, p5=664, sr=114, sw=280, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --1c88b226-Z-- --1ea68b55-A-- [31/Aug/2026:06:52:06.470030 +0300] apT6Zm7fDIutYTwcPOkaMwAAAFM 138.197.193.77 38052 127.0.0.1 7081 --1ea68b55-B-- POST /wp-login.php HTTP/1.1 Host: ajutam.ro X-Real-IP: 138.197.193.77 X-Accel-Internal: /internal-nginx-static-location Content-Length: 108 Accept: */* User-Agent: Mozilla/5.0 Content-Type: application/x-www-form-urlencoded Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818 --1ea68b55-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --1ea68b55-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:06-52.138.197.193.77"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788148326406234 63866 (- - -) Stopwatch2: 1788148326406234 63866; combined=62168, p1=349, p2=61283, p3=0, p4=0, p5=409, sr=140, sw=127, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --1ea68b55-Z-- --1cc20c58-A-- [31/Aug/2026:06:53:12.666337 +0300] apT6qNmUuou1H8H2UKXCjAAAANI 207.154.219.81 45260 127.0.0.1 7081 --1cc20c58-B-- POST /wp-login.php HTTP/1.1 Host: ajutam.ro X-Real-IP: 207.154.219.81 X-Accel-Internal: /internal-nginx-static-location Content-Length: 108 Accept: */* User-Agent: Mozilla/5.0 Content-Type: application/x-www-form-urlencoded Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818 --1cc20c58-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --1cc20c58-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:06-53.207.154.219.81"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788148392603552 62871 (- - -) Stopwatch2: 1788148392603552 62871; combined=60050, p1=262, p2=59081, p3=0, p4=0, p5=520, sr=109, sw=187, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --1cc20c58-Z-- --d8a1f45a-A-- [31/Aug/2026:06:53:43.149580 +0300] apT6x9mUuou1H8H2UKXCjgAAAM8 167.86.74.74 57124 127.0.0.1 7081 --d8a1f45a-B-- GET /.env HTTP/1.1 Host: funshop.ro X-Real-IP: 167.86.74.74 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36 Accept-Encoding: gzip, deflate Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,image/apng,*/*;q=0.8 Cache-Control: max-age=0 Upgrade-Insecure-Requests: 1 Accept-Language: en-US,en;q=0.9,fr;q=0.8 --d8a1f45a-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --d8a1f45a-E-- --d8a1f45a-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "funshop.ro"] [uri "/.env"] [unique_id "apT6x9mUuou1H8H2UKXCjgAAAM8"] Stopwatch: 1788148423142296 7424 (- - -) Stopwatch2: 1788148423142296 7424; combined=5214, p1=385, p2=4716, p3=61, p4=7, p5=45, sr=123, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --d8a1f45a-Z-- --82a6bb27-A-- [31/Aug/2026:06:59:33.015303 +0300] apT8JNmUuou1H8H2UKXCrQAAAMI 138.197.193.77 44908 127.0.0.1 7081 --82a6bb27-B-- POST /wp-login.php HTTP/1.1 Host: ajutam.ro X-Real-IP: 138.197.193.77 X-Accel-Internal: /internal-nginx-static-location Content-Length: 123 Accept: */* User-Agent: Mozilla/5.0 Content-Type: application/x-www-form-urlencoded Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818 --82a6bb27-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --82a6bb27-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:06-59.138.197.193.77"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788148772957215 58163 (- - -) Stopwatch2: 1788148772957215 58163; combined=56605, p1=261, p2=55735, p3=0, p4=0, p5=452, sr=105, sw=157, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --82a6bb27-Z-- --362db907-A-- [31/Aug/2026:06:59:49.057166 +0300] apT8NNmUuou1H8H2UKXCsQAAANc 207.154.219.81 42046 127.0.0.1 7081 --362db907-B-- POST /wp-login.php HTTP/1.1 Host: ajutam.ro X-Real-IP: 207.154.219.81 X-Accel-Internal: /internal-nginx-static-location Content-Length: 126 Accept: */* User-Agent: Mozilla/5.0 Content-Type: application/x-www-form-urlencoded Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818 --362db907-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --362db907-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:06-59.207.154.219.81"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788148788998178 59045 (- - -) Stopwatch2: 1788148788998178 59045; combined=57671, p1=235, p2=56944, p3=0, p4=0, p5=363, sr=92, sw=129, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --362db907-Z-- --dd37854e-A-- [31/Aug/2026:07:05:50.012376 +0300] apT9ndmUuou1H8H2UKXC8AAAAMI 129.213.185.111 40292 127.0.0.1 7081 --dd37854e-B-- GET /wp-json/wp/v2/users/me HTTP/1.1 Host: ajutam.ro X-Real-IP: 129.213.185.111 X-Accel-Internal: /internal-nginx-static-location Authorization: Basic YWRtaW46YWRtaW4yMDEw Accept: application/json Accept-Language: en-US,en;q=0.9 Sec-Ch-Ua: "Not=A?Brand";v="99", "Google Chrome";v="151", "Chromium";v="151" Sec-Ch-Ua-Mobile: ?0 Sec-Ch-Ua-Platform: "Windows" User-Agent: 129.213.185.111 Accept-Encoding: gzip, deflate, br --dd37854e-F-- HTTP/1.1 401 Unauthorized X-Powered-By: PHP/7.3.33 X-Robots-Tag: noindex Link: ; rel="https://api.w.org/" X-Content-Type-Options: nosniff Access-Control-Expose-Headers: X-WP-Total, X-WP-TotalPages, Link Access-Control-Allow-Headers: Authorization, X-WP-Nonce, Content-Disposition, Content-MD5, Content-Type Allow: GET Vary: Origin Transfer-Encoding: chunked Content-Type: application/json; charset=UTF-8 --dd37854e-H-- Message: String match "wp-json/wp/v2/users" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "80"] [id "77140942"] [msg "IM360 WAF: Block WordPress 5.3 User Enumeration attempts||T:APACHE||MV:/wp-json/wp/v2/users/me||"] [severity "DEBUG"] [tag "service_i360custom"] [tag "wp_core"] Message: Operator EQ matched 0 at REQUEST_COOKIES. [file "/etc/httpd/conf/modsecurity.d/rules/custom/007_i360_4_wordpress.conf"] [line "426"] [id "77316783"] [msg "IM360 WAF: Monitoring WordPress 5.3 User Enumeration attempts||T:APACHE||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "wp_core"] [tag "noshow"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ajutam.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788149149639599 372866 (- - -) Stopwatch2: 1788149149639599 372866; combined=34092, p1=314, p2=33726, p3=0, p4=0, p5=51, sr=109, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --dd37854e-Z-- --affea921-A-- [31/Aug/2026:07:06:43.457590 +0300] apT909mUuou1H8H2UKXC@AAAAMo 207.154.219.81 48528 127.0.0.1 7081 --affea921-B-- POST /wp-login.php HTTP/1.1 Host: ajutam.ro X-Real-IP: 207.154.219.81 X-Accel-Internal: /internal-nginx-static-location Content-Length: 111 Accept: */* User-Agent: Mozilla/5.0 Content-Type: application/x-www-form-urlencoded Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818 --affea921-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --affea921-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:07-06.207.154.219.81"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788149203394192 63498 (- - -) Stopwatch2: 1788149203394192 63498; combined=62081, p1=257, p2=61319, p3=0, p4=0, p5=376, sr=84, sw=129, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --affea921-Z-- --907f2133-A-- [31/Aug/2026:07:07:38.530316 +0300] apT@Cn7glkZrdsSdRApJgQAAAIg 138.197.193.77 36694 127.0.0.1 7081 --907f2133-B-- POST /wp-login.php HTTP/1.1 Host: ajutam.ro X-Real-IP: 138.197.193.77 X-Accel-Internal: /internal-nginx-static-location Content-Length: 105 Accept: */* User-Agent: Mozilla/5.0 Content-Type: application/x-www-form-urlencoded Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818 --907f2133-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --907f2133-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:07-07.138.197.193.77"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788149258466383 63993 (- - -) Stopwatch2: 1788149258466383 63993; combined=60481, p1=364, p2=59569, p3=0, p4=0, p5=408, sr=133, sw=140, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --907f2133-Z-- --c779ad40-A-- [31/Aug/2026:07:11:58.878858 +0300] apT-DtmUuou1H8H2UKXDFwAAANA 82.223.5.23 49652 127.0.0.1 7081 --c779ad40-B-- POST / HTTP/1.1 Host: www.ihelp.ro X-Real-IP: 82.223.5.23 X-Accel-Internal: /internal-nginx-static-location Content-Length: 0 User-agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36 Accept-Encoding: gzip, deflate Accept: */* --c779ad40-F-- HTTP/1.1 403 Forbidden X-Powered-By: PHP/8.1.34 X-DEBUGKIT-ID: a0c0409b-70cd-40b2-aecd-04c53a601f20 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --c779ad40-H-- Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788149518698777 180157 (- - -) Stopwatch2: 1788149518698777 180157; combined=10573, p1=429, p2=9764, p3=0, p4=0, p5=379, sr=188, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "DETECTION_ONLY" --c779ad40-Z-- --6af12851-A-- [31/Aug/2026:07:11:59.696280 +0300] apT-D37glkZrdsSdRApJigAAAIQ 82.223.5.23 49654 127.0.0.1 7081 --6af12851-B-- POST /debug/default/view?panel=config HTTP/1.1 Host: www.ihelp.ro X-Real-IP: 82.223.5.23 X-Accel-Internal: /internal-nginx-static-location Content-Length: 0 User-agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36 Accept-Encoding: gzip, deflate Accept: */* --6af12851-F-- HTTP/1.1 403 Forbidden X-Powered-By: PHP/8.1.34 X-DEBUGKIT-ID: 01a10848-fbaa-40c9-92b3-5b6586c24bb4 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --6af12851-H-- Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G:panel=config& P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788149519555346 141024 (- - -) Stopwatch2: 1788149519555346 141024; combined=10895, p1=2453, p2=8049, p3=0, p4=0, p5=393, sr=299, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "DETECTION_ONLY" --6af12851-Z-- --7b83c96d-A-- [31/Aug/2026:07:12:00.499373 +0300] apT-ENmUuou1H8H2UKXDGAAAAMI 82.223.5.23 49658 127.0.0.1 7081 --7b83c96d-B-- POST /tool/view/phpinfo.view.php HTTP/1.1 Host: www.ihelp.ro X-Real-IP: 82.223.5.23 X-Accel-Internal: /internal-nginx-static-location Content-Length: 0 User-agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36 Accept-Encoding: gzip, deflate Accept: */* --7b83c96d-F-- HTTP/1.1 403 Forbidden X-Powered-By: PHP/8.1.34 X-DEBUGKIT-ID: 5e88358a-3801-425b-9e9a-38ae1d3e8a01 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --7b83c96d-H-- Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788149520363845 135593 (- - -) Stopwatch2: 1788149520363845 135593; combined=6798, p1=1770, p2=4695, p3=0, p4=0, p5=332, sr=190, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "DETECTION_ONLY" --7b83c96d-Z-- --ee575677-A-- [31/Aug/2026:07:12:01.216848 +0300] apT-EW7fDIutYTwcPOkaTQAAAFQ 82.223.5.23 49666 127.0.0.1 7081 --ee575677-B-- POST /wp-config.php-backup HTTP/1.1 Host: www.ihelp.ro X-Real-IP: 82.223.5.23 X-Accel-Internal: /internal-nginx-static-location Content-Length: 0 User-agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36 Accept-Encoding: gzip, deflate Accept: */* --ee575677-F-- HTTP/1.1 403 Forbidden X-Powered-By: PHP/8.1.34 X-DEBUGKIT-ID: 51f9f82c-e500-445a-b838-c47b0d10fc03 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --ee575677-H-- Message: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "www.ihelp.ro"] [uri "/wp-config.php-backup"] [unique_id "apT-EW7fDIutYTwcPOkaTQAAAFQ"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788149521089838 127074 (- - -) Stopwatch2: 1788149521089838 127074; combined=7112, p1=534, p2=6190, p3=0, p4=0, p5=388, sr=153, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "DETECTION_ONLY" --ee575677-Z-- --49fadb5d-A-- [31/Aug/2026:07:13:31.176583 +0300] apT-a9mUuou1H8H2UKXDHgAAAMQ 207.154.219.81 40214 127.0.0.1 7081 --49fadb5d-B-- POST /wp-login.php HTTP/1.1 Host: ajutam.ro X-Real-IP: 207.154.219.81 X-Accel-Internal: /internal-nginx-static-location Content-Length: 111 Accept: */* User-Agent: Mozilla/5.0 Content-Type: application/x-www-form-urlencoded Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818 --49fadb5d-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --49fadb5d-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:07-13.207.154.219.81"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788149611115485 61305 (- - -) Stopwatch2: 1788149611115485 61305; combined=58220, p1=729, p2=56453, p3=0, p4=0, p5=784, sr=333, sw=254, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --49fadb5d-Z-- --31de385b-A-- [31/Aug/2026:07:15:45.271723 +0300] apT-8dmUuou1H8H2UKXDJQAAAMI 138.197.193.77 60782 127.0.0.1 7081 --31de385b-B-- POST /wp-login.php HTTP/1.1 Host: ajutam.ro X-Real-IP: 138.197.193.77 X-Accel-Internal: /internal-nginx-static-location Content-Length: 108 Accept: */* User-Agent: Mozilla/5.0 Content-Type: application/x-www-form-urlencoded Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818 --31de385b-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --31de385b-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:07-15.138.197.193.77"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788149745202938 68862 (- - -) Stopwatch2: 1788149745202938 68862; combined=60549, p1=1008, p2=58667, p3=0, p4=0, p5=610, sr=776, sw=264, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --31de385b-Z-- --586c565d-A-- [31/Aug/2026:07:20:16.338771 +0300] apUBANmUuou1H8H2UKXDcQAAANE 207.154.219.81 55996 127.0.0.1 7081 --586c565d-B-- POST /wp-login.php HTTP/1.1 Host: ajutam.ro X-Real-IP: 207.154.219.81 X-Accel-Internal: /internal-nginx-static-location Content-Length: 109 Accept: */* User-Agent: Mozilla/5.0 Content-Type: application/x-www-form-urlencoded Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818 --586c565d-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --586c565d-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:07-20.207.154.219.81"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788150016276103 62740 (- - -) Stopwatch2: 1788150016276103 62740; combined=61065, p1=364, p2=59933, p3=0, p4=0, p5=560, sr=168, sw=208, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --586c565d-Z-- --4670bd65-A-- [31/Aug/2026:07:23:50.532405 +0300] apUB1n7glkZrdsSdRApJqgAAAJM 138.197.193.77 42428 127.0.0.1 7081 --4670bd65-B-- POST /wp-login.php HTTP/1.1 Host: ajutam.ro X-Real-IP: 138.197.193.77 X-Accel-Internal: /internal-nginx-static-location Content-Length: 110 Accept: */* User-Agent: Mozilla/5.0 Content-Type: application/x-www-form-urlencoded Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818 --4670bd65-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --4670bd65-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:07-23.138.197.193.77"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788150230467385 65095 (- - -) Stopwatch2: 1788150230467385 65095; combined=62275, p1=555, p2=60732, p3=0, p4=0, p5=749, sr=269, sw=239, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --4670bd65-Z-- --cdd3540e-A-- [31/Aug/2026:07:27:14.068113 +0300] apUCotmUuou1H8H2UKXDigAAANE 207.154.219.81 42546 127.0.0.1 7081 --cdd3540e-B-- POST /wp-login.php HTTP/1.1 Host: ajutam.ro X-Real-IP: 207.154.219.81 X-Accel-Internal: /internal-nginx-static-location Content-Length: 109 Accept: */* User-Agent: Mozilla/5.0 Content-Type: application/x-www-form-urlencoded Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818 --cdd3540e-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --cdd3540e-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:07-27.207.154.219.81"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788150434006496 61728 (- - -) Stopwatch2: 1788150434006496 61728; combined=59381, p1=373, p2=58266, p3=0, p4=0, p5=581, sr=128, sw=161, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --cdd3540e-Z-- --6df58a70-A-- [31/Aug/2026:07:27:45.301112 +0300] apUCwCfaLSuAj0yzdueTCgAAABA 137.131.61.214 58094 127.0.0.1 7081 --6df58a70-B-- GET /xmlrpc.php HTTP/1.1 Host: ajutam.ro X-Real-IP: 137.131.61.214 X-Accel-Internal: /internal-nginx-static-location User-Agent: AteveSearchSourceUrlDiscovery/0.1 (+mailto:crawler@example.com) Accept: */* Accept-Encoding: gzip, deflate --6df58a70-F-- HTTP/1.1 405 Method Not Allowed X-Powered-By: PHP/7.3.33 Allow: POST Transfer-Encoding: chunked Content-Type: text/plain;charset=UTF-8 --6df58a70-E-- --6df58a70-H-- Message: Warning. String match "xmlrpc.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "290"] [id "77141064"] [msg "IM360 WAF: CMS Recon Bot detected||MVN:REQUEST_FILENAME||T:APACHE||MV:/xmlrpc.php||RM:GET"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "xmlrpc.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "290"] [id "77141064"] [msg "IM360 WAF: CMS Recon Bot detected||MVN:REQUEST_FILENAME||T:APACHE||MV:/xmlrpc.php||RM:GET"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "ajutam.ro"] [uri "/xmlrpc.php"] [unique_id "apUCwCfaLSuAj0yzdueTCgAAABA"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ajutam.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150464940461 360768 (- - -) Stopwatch2: 1788150464940461 360768; combined=10875, p1=3025, p2=7552, p3=205, p4=15, p5=78, sr=245, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --6df58a70-Z-- --59d9c27f-A-- [31/Aug/2026:07:28:00.213224 +0300] apUCz37glkZrdsSdRApJtgAAAIs 137.131.61.214 44832 127.0.0.1 7081 --59d9c27f-B-- GET /xmlrpc.php?rsd= HTTP/1.1 Host: ajutam.ro X-Real-IP: 137.131.61.214 X-Accel-Internal: /internal-nginx-static-location User-Agent: AteveSearchSourceUrlDiscovery/0.1 (+mailto:crawler@example.com) Accept: */* Accept-Encoding: gzip, deflate --59d9c27f-F-- HTTP/1.1 200 OK X-Powered-By: PHP/7.3.33 Transfer-Encoding: chunked Content-Type: text/xml; charset=UTF-8 --59d9c27f-E-- --59d9c27f-H-- Message: Warning. String match "xmlrpc.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "290"] [id "77141064"] [msg "IM360 WAF: CMS Recon Bot detected||MVN:REQUEST_FILENAME||T:APACHE||MV:/xmlrpc.php||RM:GET"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Message: Warning. Operator GT matched 0 at ARGS. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "529"] [id "77317945"] [msg "IM360 WAF: Really Simple Discovery to xmlrpc||MVN:ARGS||MV:1||T:APACHE||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "xmlrpc.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "290"] [id "77141064"] [msg "IM360 WAF: CMS Recon Bot detected||MVN:REQUEST_FILENAME||T:APACHE||MV:/xmlrpc.php||RM:GET"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "ajutam.ro"] [uri "/xmlrpc.php"] [unique_id "apUCz37glkZrdsSdRApJtgAAAIs"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Operator GT matched 0 at ARGS. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "529"] [id "77317945"] [msg "IM360 WAF: Really Simple Discovery to xmlrpc||MVN:ARGS||MV:1||T:APACHE||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "ajutam.ro"] [uri "/xmlrpc.php"] [unique_id "apUCz37glkZrdsSdRApJtgAAAIs"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ajutam.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150479938092 275243 (- - -) Stopwatch2: 1788150479938092 275243; combined=7404, p1=667, p2=6374, p3=182, p4=75, p5=106, sr=231, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --59d9c27f-Z-- --9af7f705-A-- [31/Aug/2026:07:30:10.735649 +0300] apUDUm7fDIutYTwcPOkabQAAAEQ 120.133.60.156 54968 127.0.0.1 7081 --9af7f705-B-- POST /wp-login.php HTTP/1.1 Host: axapres.ro X-Real-IP: 120.133.60.156 X-Accel-Internal: /internal-nginx-static-location Content-Length: 107 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8 Accept-Language: en-US,en;q=0.5 Content-Type: application/x-www-form-urlencoded Cookie: wordpress_test_cookie=WP+Cookie+check Origin: https://axapres.ro Referer: https://axapres.ro/wp-login.php --9af7f705-F-- HTTP/1.1 403 Forbidden Content-Length: 199 Content-Type: text/html; charset=iso-8859-1 --9af7f705-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:07-30.120.133.60.156"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Apache-Handler: proxy:unix:/var/www/vhosts/system/axapres.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150610658910 76859 (- - -) Stopwatch2: 1788150610658910 76859; combined=76077, p1=680, p2=59572, p3=0, p4=0, p5=8099, sr=377, sw=238, l=0, gc=7488 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --9af7f705-Z-- --d1310e0f-A-- [31/Aug/2026:07:31:19.726606 +0300] apUDl9mUuou1H8H2UKXD6AAAAM0 34.73.181.25 43486 127.0.0.1 7081 --d1310e0f-B-- GET /.git/config HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 172.26.241.90 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 172.26.241.90 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 172.26.241.90 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 172.26.241.90 Upgrade-Insecure-Requests: 1 X-Client-Ip: 172.26.241.90 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 172.26.241.90 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --d1310e0f-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --d1310e0f-H-- Message: Warning. Matched phrase "/.git/config" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.git/config||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Matched phrase "/.git/config" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.git/config||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Message: Warning. String match "/.git/" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "656"] [id "77318034"] [msg "IM360 WAF: Blocked access to git folder||T:APACHE||MV:/.git/config||"] [severity "NOTICE"] [tag "service_i360custom"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "/.git/config" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.git/config||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/.git/config"] [unique_id "apUDl9mUuou1H8H2UKXD6AAAAM0"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "/.git/config" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.git/config||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/.git/config"] [unique_id "apUDl9mUuou1H8H2UKXD6AAAAM0"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.git/" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "656"] [id "77318034"] [msg "IM360 WAF: Blocked access to git folder||T:APACHE||MV:/.git/config||"] [severity "NOTICE"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/.git/config"] [unique_id "apUDl9mUuou1H8H2UKXD6AAAAM0"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150679486485 240285 (- - -) Stopwatch2: 1788150679486485 240285; combined=34445, p1=327, p2=34044, p3=0, p4=0, p5=74, sr=110, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --d1310e0f-Z-- --9df72169-A-- [31/Aug/2026:07:31:19.880502 +0300] apUDl9mUuou1H8H2UKXD4wAAANQ 34.73.181.25 43410 127.0.0.1 7081 --9df72169-B-- GET /.git/HEAD HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 172.30.50.136 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 172.30.50.136 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 172.30.50.136 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 172.30.50.136 Upgrade-Insecure-Requests: 1 X-Client-Ip: 172.30.50.136 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 172.30.50.136 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --9df72169-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --9df72169-H-- Message: Warning. String match "/.git/" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "656"] [id "77318034"] [msg "IM360 WAF: Blocked access to git folder||T:APACHE||MV:/.git/head||"] [severity "NOTICE"] [tag "service_i360custom"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.git/" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "656"] [id "77318034"] [msg "IM360 WAF: Blocked access to git folder||T:APACHE||MV:/.git/head||"] [severity "NOTICE"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/.git/HEAD"] [unique_id "apUDl9mUuou1H8H2UKXD4wAAANQ"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150679342114 538480 (- - -) Stopwatch2: 1788150679342114 538480; combined=7236, p1=273, p2=6904, p3=0, p4=0, p5=59, sr=82, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --9df72169-Z-- --39a0cb12-A-- [31/Aug/2026:07:31:19.900591 +0300] apUDl9mUuou1H8H2UKXD6QAAANU 34.73.181.25 43498 127.0.0.1 7081 --39a0cb12-B-- POST /graphql HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Accel-Internal: /internal-nginx-static-location Content-Length: 86 User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: */* Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Content-Type: application/json Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Origin: https://alexandervodka.com Referer: https://alexandervodka.com Sec-Fetch-Dest: empty Sec-Fetch-Mode: cors Sec-Fetch-Site: same-origin sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --39a0cb12-F-- HTTP/1.1 403 Forbidden X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --39a0cb12-H-- Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150679527968 372725 (- - -) Stopwatch2: 1788150679527968 372725; combined=5718, p1=274, p2=5168, p3=0, p4=0, p5=276, sr=93, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --39a0cb12-Z-- --bc460e5a-A-- [31/Aug/2026:07:31:19.940423 +0300] apUDl37glkZrdsSdRApJ1gAAAJA 34.73.181.25 43552 127.0.0.1 7081 --bc460e5a-B-- GET /.git-credentials HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 172.17.3.147 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 172.17.3.147 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 172.17.3.147 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 172.17.3.147 Upgrade-Insecure-Requests: 1 X-Client-Ip: 172.17.3.147 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 172.17.3.147 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --bc460e5a-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --bc460e5a-H-- Message: Warning. Matched phrase "/.git-credentials" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.git-credentials||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Matched phrase "/.git-credentials" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.git-credentials||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "/.git-credentials" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.git-credentials||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/.git-credentials"] [unique_id "apUDl37glkZrdsSdRApJ1gAAAJA"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "/.git-credentials" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.git-credentials||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/.git-credentials"] [unique_id "apUDl37glkZrdsSdRApJ1gAAAJA"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150679847592 92942 (- - -) Stopwatch2: 1788150679847592 92942; combined=35051, p1=296, p2=34689, p3=0, p4=0, p5=65, sr=84, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --bc460e5a-Z-- --3d6edc59-A-- [31/Aug/2026:07:31:20.167319 +0300] apUDmCfaLSuAj0yzdueTFgAAABY 34.73.181.25 43618 127.0.0.1 7081 --3d6edc59-B-- POST /api/graphql HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Accel-Internal: /internal-nginx-static-location Content-Length: 86 User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: */* Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Content-Type: application/json Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Origin: https://alexandervodka.com Referer: https://alexandervodka.com Sec-Fetch-Dest: empty Sec-Fetch-Mode: cors Sec-Fetch-Site: same-origin sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --3d6edc59-F-- HTTP/1.1 403 Forbidden X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --3d6edc59-H-- Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150680087042 80380 (- - -) Stopwatch2: 1788150680087042 80380; combined=7681, p1=227, p2=7169, p3=0, p4=0, p5=285, sr=80, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --3d6edc59-Z-- --d5d10130-A-- [31/Aug/2026:07:31:20.283693 +0300] apUDl27fDIutYTwcPOkacgAAAFM 34.73.181.25 43578 127.0.0.1 7081 --d5d10130-B-- GET /.gitconfig HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 192.168.206.250 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 192.168.206.250 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 192.168.206.250 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 192.168.206.250 Upgrade-Insecure-Requests: 1 X-Client-Ip: 192.168.206.250 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 192.168.206.250 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --d5d10130-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --d5d10130-H-- Message: Warning. Matched phrase "/.gitconfig" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.gitconfig||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Matched phrase "/.gitconfig" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.gitconfig||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "/.gitconfig" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.gitconfig||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/.gitconfig"] [unique_id "apUDl27fDIutYTwcPOkacgAAAFM"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "/.gitconfig" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.gitconfig||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/.gitconfig"] [unique_id "apUDl27fDIutYTwcPOkacgAAAFM"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150679986778 297110 (- - -) Stopwatch2: 1788150679986778 297110; combined=62272, p1=261, p2=61900, p3=0, p4=0, p5=110, sr=81, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --d5d10130-Z-- --3b1af431-A-- [31/Aug/2026:07:31:20.285993 +0300] apUDmCfaLSuAj0yzdueTFQAAAAw 34.73.181.25 43608 127.0.0.1 7081 --3b1af431-B-- GET /.env HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 172.29.251.105 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 172.29.251.105 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 172.29.251.105 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 172.29.251.105 Upgrade-Insecure-Requests: 1 X-Client-Ip: 172.29.251.105 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 172.29.251.105 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --3b1af431-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --3b1af431-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/.env"] [unique_id "apUDmCfaLSuAj0yzdueTFQAAAAw"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150680082519 203560 (- - -) Stopwatch2: 1788150680082519 203560; combined=4950, p1=293, p2=4605, p3=0, p4=0, p5=51, sr=99, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --3b1af431-Z-- --62e26f73-A-- [31/Aug/2026:07:31:20.566942 +0300] apUDmNmUuou1H8H2UKXD8gAAANc 34.73.181.25 43640 127.0.0.1 7081 --62e26f73-B-- GET /.env.local HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 100.107.80.230 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 100.107.80.230 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 100.107.80.230 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 100.107.80.230 Upgrade-Insecure-Requests: 1 X-Client-Ip: 100.107.80.230 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 100.107.80.230 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --62e26f73-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --62e26f73-H-- Message: Warning. Matched phrase ".local" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.env.local||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Matched phrase ".local" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.env.local||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".local" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.env.local||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/.env.local"] [unique_id "apUDmNmUuou1H8H2UKXD8gAAANc"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".local" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.env.local||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/.env.local"] [unique_id "apUDmNmUuou1H8H2UKXD8gAAANc"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150680294591 272442 (- - -) Stopwatch2: 1788150680294591 272442; combined=34640, p1=265, p2=34309, p3=0, p4=0, p5=65, sr=96, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --62e26f73-Z-- --c37e6c11-A-- [31/Aug/2026:07:31:20.580933 +0300] apUDmNmUuou1H8H2UKXD9gAAANg 34.73.181.25 43710 127.0.0.1 7081 --c37e6c11-B-- GET /api/.env HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 172.25.84.73 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 172.25.84.73 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 172.25.84.73 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 172.25.84.73 Upgrade-Insecure-Requests: 1 X-Client-Ip: 172.25.84.73 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 172.25.84.73 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --c37e6c11-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --c37e6c11-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/api/.env"] [unique_id "apUDmNmUuou1H8H2UKXD9gAAANg"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150680448950 132083 (- - -) Stopwatch2: 1788150680448950 132083; combined=4583, p1=245, p2=4284, p3=0, p4=0, p5=54, sr=82, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --c37e6c11-Z-- --be2ae37c-A-- [31/Aug/2026:07:31:20.663837 +0300] apUDmH7glkZrdsSdRApJ1wAAAIE 34.73.181.25 43656 127.0.0.1 7081 --be2ae37c-B-- POST /v1/graphql HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Accel-Internal: /internal-nginx-static-location Content-Length: 86 User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: */* Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Content-Type: application/json Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Origin: https://alexandervodka.com Referer: https://alexandervodka.com Sec-Fetch-Dest: empty Sec-Fetch-Mode: cors Sec-Fetch-Site: same-origin sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --be2ae37c-F-- HTTP/1.1 403 Forbidden X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --be2ae37c-H-- Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150680317225 346693 (- - -) Stopwatch2: 1788150680317225 346693; combined=5583, p1=283, p2=4931, p3=0, p4=0, p5=369, sr=117, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --be2ae37c-Z-- --c6afca47-A-- [31/Aug/2026:07:31:20.691510 +0300] apUDmNmUuou1H8H2UKXD@AAAAMY 34.73.181.25 43734 127.0.0.1 7081 --c6afca47-B-- GET /admin/.env HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 172.27.43.39 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 172.27.43.39 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 172.27.43.39 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 172.27.43.39 Upgrade-Insecure-Requests: 1 X-Client-Ip: 172.27.43.39 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 172.27.43.39 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --c6afca47-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --c6afca47-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/admin/.env"] [unique_id "apUDmNmUuou1H8H2UKXD@AAAAMY"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150680477040 214604 (- - -) Stopwatch2: 1788150680477040 214604; combined=5282, p1=243, p2=4980, p3=0, p4=0, p5=59, sr=81, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --c6afca47-Z-- --5acf943e-A-- [31/Aug/2026:07:31:20.886961 +0300] apUDmCfaLSuAj0yzdueTFwAAABc 34.73.181.25 43770 127.0.0.1 7081 --5acf943e-B-- GET /config/.env HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 100.81.34.110 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 100.81.34.110 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 100.81.34.110 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 100.81.34.110 Upgrade-Insecure-Requests: 1 X-Client-Ip: 100.81.34.110 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 100.81.34.110 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --5acf943e-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --5acf943e-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/config/.env"] [unique_id "apUDmCfaLSuAj0yzdueTFwAAABc"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150680766132 120919 (- - -) Stopwatch2: 1788150680766132 120919; combined=5858, p1=275, p2=5526, p3=0, p4=0, p5=57, sr=94, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --5acf943e-Z-- --b77eec6b-A-- [31/Aug/2026:07:31:20.940064 +0300] apUDmNmUuou1H8H2UKXD@gAAANQ 34.73.181.25 43756 127.0.0.1 7081 --b77eec6b-B-- GET /backend/.env HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 100.107.79.54 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 100.107.79.54 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 100.107.79.54 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 100.107.79.54 Upgrade-Insecure-Requests: 1 X-Client-Ip: 100.107.79.54 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 100.107.79.54 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --b77eec6b-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --b77eec6b-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/backend/.env"] [unique_id "apUDmNmUuou1H8H2UKXD@gAAANQ"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150680742148 198003 (- - -) Stopwatch2: 1788150680742148 198003; combined=6098, p1=325, p2=5718, p3=0, p4=0, p5=54, sr=110, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --b77eec6b-Z-- --8fe3bb14-A-- [31/Aug/2026:07:31:21.537531 +0300] apUDmdmUuou1H8H2UKXEAQAAAMc 34.73.181.25 43902 127.0.0.1 7081 --8fe3bb14-B-- GET /.github/.env HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 10.188.56.58 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 10.188.56.58 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 10.188.56.58 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 10.188.56.58 Upgrade-Insecure-Requests: 1 X-Client-Ip: 10.188.56.58 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 10.188.56.58 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --8fe3bb14-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --8fe3bb14-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/.github/.env"] [unique_id "apUDmdmUuou1H8H2UKXEAQAAAMc"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150681474845 62813 (- - -) Stopwatch2: 1788150681474845 62813; combined=4918, p1=284, p2=4577, p3=0, p4=0, p5=56, sr=108, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --8fe3bb14-Z-- --37a51749-A-- [31/Aug/2026:07:31:21.684163 +0300] apUDmdmUuou1H8H2UKXEAgAAAMk 34.73.181.25 43910 127.0.0.1 7081 --37a51749-B-- GET /.npmrc HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 10.109.48.131 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 10.109.48.131 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 10.109.48.131 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 10.109.48.131 Upgrade-Insecure-Requests: 1 X-Client-Ip: 10.109.48.131 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 10.109.48.131 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --37a51749-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --37a51749-H-- Message: Warning. Matched phrase ".npmrc" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.npmrc||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Matched phrase ".npmrc" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.npmrc||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".npmrc" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.npmrc||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/.npmrc"] [unique_id "apUDmdmUuou1H8H2UKXEAgAAAMk"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".npmrc" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.npmrc||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/.npmrc"] [unique_id "apUDmdmUuou1H8H2UKXEAgAAAMk"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150681583184 101176 (- - -) Stopwatch2: 1788150681583184 101176; combined=33207, p1=219, p2=32890, p3=0, p4=0, p5=97, sr=69, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --37a51749-Z-- --2f474539-A-- [31/Aug/2026:07:31:21.822768 +0300] apUDmdmUuou1H8H2UKXEBgAAANM 34.73.181.25 43962 127.0.0.1 7081 --2f474539-B-- GET /.svn/entries HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 100.111.65.1 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 100.111.65.1 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 100.111.65.1 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 100.111.65.1 Upgrade-Insecure-Requests: 1 X-Client-Ip: 100.111.65.1 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 100.111.65.1 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --2f474539-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --2f474539-H-- Message: Warning. Matched phrase ".svn/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.svn/entries||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Matched phrase ".svn/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.svn/entries||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".svn/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.svn/entries||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/.svn/entries"] [unique_id "apUDmdmUuou1H8H2UKXEBgAAANM"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".svn/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.svn/entries||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/.svn/entries"] [unique_id "apUDmdmUuou1H8H2UKXEBgAAANM"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150681721834 101024 (- - -) Stopwatch2: 1788150681721834 101024; combined=32372, p1=241, p2=32066, p3=0, p4=0, p5=64, sr=80, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --2f474539-Z-- --7abb6f7c-A-- [31/Aug/2026:07:31:23.098967 +0300] apUDmtmUuou1H8H2UKXEGQAAAM8 34.73.181.25 44266 127.0.0.1 7081 --7abb6f7c-B-- GET /.idea/WebServers.xml HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 172.28.235.57 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 172.28.235.57 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 172.28.235.57 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 172.28.235.57 Upgrade-Insecure-Requests: 1 X-Client-Ip: 172.28.235.57 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 172.28.235.57 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --7abb6f7c-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --7abb6f7c-H-- Message: Warning. Matched phrase ".idea/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.idea/webservers.xml||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Matched phrase ".idea/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.idea/webservers.xml||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".idea/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.idea/webservers.xml||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/.idea/WebServers.xml"] [unique_id "apUDmtmUuou1H8H2UKXEGQAAAM8"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".idea/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.idea/webservers.xml||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/.idea/WebServers.xml"] [unique_id "apUDmtmUuou1H8H2UKXEGQAAAM8"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150682931115 167954 (- - -) Stopwatch2: 1788150682931115 167954; combined=36322, p1=255, p2=36003, p3=0, p4=0, p5=64, sr=77, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --7abb6f7c-Z-- --c61c9922-A-- [31/Aug/2026:07:31:23.119130 +0300] apUDmn7glkZrdsSdRApJ5QAAAIw 34.73.181.25 44294 127.0.0.1 7081 --c61c9922-B-- GET /.ssh/id_rsa HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 172.23.126.205 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 172.23.126.205 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 172.23.126.205 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 172.23.126.205 Upgrade-Insecure-Requests: 1 X-Client-Ip: 172.23.126.205 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 172.23.126.205 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --c61c9922-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --c61c9922-H-- Message: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.ssh/id_rsa||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.ssh/id_rsa||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.ssh/id_rsa||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/.ssh/id_rsa"] [unique_id "apUDmn7glkZrdsSdRApJ5QAAAIw"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.ssh/id_rsa||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/.ssh/id_rsa"] [unique_id "apUDmn7glkZrdsSdRApJ5QAAAIw"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150682986604 132625 (- - -) Stopwatch2: 1788150682986604 132625; combined=37692, p1=252, p2=37378, p3=0, p4=0, p5=62, sr=91, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --c61c9922-Z-- --843ff27b-A-- [31/Aug/2026:07:31:23.265264 +0300] apUDm9mUuou1H8H2UKXEHQAAAM4 34.73.181.25 44320 127.0.0.1 7081 --843ff27b-B-- GET /.ssh/id_ecdsa HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 192.168.134.198 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 192.168.134.198 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 192.168.134.198 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 192.168.134.198 Upgrade-Insecure-Requests: 1 X-Client-Ip: 192.168.134.198 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 192.168.134.198 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --843ff27b-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --843ff27b-H-- Message: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.ssh/id_ecdsa||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.ssh/id_ecdsa||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.ssh/id_ecdsa||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/.ssh/id_ecdsa"] [unique_id "apUDm9mUuou1H8H2UKXEHQAAAM4"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.ssh/id_ecdsa||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/.ssh/id_ecdsa"] [unique_id "apUDm9mUuou1H8H2UKXEHQAAAM4"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150683136393 128960 (- - -) Stopwatch2: 1788150683136393 128960; combined=49718, p1=312, p2=49342, p3=0, p4=0, p5=63, sr=102, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --843ff27b-Z-- --9019cc1e-A-- [31/Aug/2026:07:31:23.393975 +0300] apUDm9mUuou1H8H2UKXEIAAAANM 34.73.181.25 44342 127.0.0.1 7081 --9019cc1e-B-- GET /.ssh/config HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 172.17.16.18 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 172.17.16.18 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 172.17.16.18 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 172.17.16.18 Upgrade-Insecure-Requests: 1 X-Client-Ip: 172.17.16.18 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 172.17.16.18 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --9019cc1e-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --9019cc1e-H-- Message: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.ssh/config||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.ssh/config||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.ssh/config||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/.ssh/config"] [unique_id "apUDm9mUuou1H8H2UKXEIAAAANM"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.ssh/config||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/.ssh/config"] [unique_id "apUDm9mUuou1H8H2UKXEIAAAANM"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150683303115 90971 (- - -) Stopwatch2: 1788150683303115 90971; combined=34006, p1=245, p2=33694, p3=0, p4=0, p5=66, sr=80, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --9019cc1e-Z-- --0a526a5a-A-- [31/Aug/2026:07:31:23.410967 +0300] apUDm9mUuou1H8H2UKXEHAAAAMQ 34.73.181.25 44308 127.0.0.1 7081 --0a526a5a-B-- GET /.ssh/id_ed25519 HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 10.232.245.241 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 10.232.245.241 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 10.232.245.241 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 10.232.245.241 Upgrade-Insecure-Requests: 1 X-Client-Ip: 10.232.245.241 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 10.232.245.241 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --0a526a5a-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --0a526a5a-H-- Message: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.ssh/id_ed25519||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.ssh/id_ed25519||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.ssh/id_ed25519||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/.ssh/id_ed25519"] [unique_id "apUDm9mUuou1H8H2UKXEHAAAAMQ"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.ssh/id_ed25519||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/.ssh/id_ed25519"] [unique_id "apUDm9mUuou1H8H2UKXEHAAAAMQ"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150683133588 277469 (- - -) Stopwatch2: 1788150683133588 277469; combined=70153, p1=258, p2=69829, p3=0, p4=0, p5=65, sr=91, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --0a526a5a-Z-- --53a1801d-A-- [31/Aug/2026:07:31:23.429221 +0300] apUDm9mUuou1H8H2UKXEGwAAAMM 34.73.181.25 44310 127.0.0.1 7081 --53a1801d-B-- GET /.ssh/id_dsa HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 10.51.159.196 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 10.51.159.196 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 10.51.159.196 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 10.51.159.196 Upgrade-Insecure-Requests: 1 X-Client-Ip: 10.51.159.196 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 10.51.159.196 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --53a1801d-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --53a1801d-H-- Message: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.ssh/id_dsa||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.ssh/id_dsa||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.ssh/id_dsa||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/.ssh/id_dsa"] [unique_id "apUDm9mUuou1H8H2UKXEGwAAAMM"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.ssh/id_dsa||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/.ssh/id_dsa"] [unique_id "apUDm9mUuou1H8H2UKXEGwAAAMM"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150683128580 300767 (- - -) Stopwatch2: 1788150683128580 300767; combined=73399, p1=280, p2=73053, p3=0, p4=0, p5=66, sr=82, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --53a1801d-Z-- --c8a0073f-A-- [31/Aug/2026:07:31:23.430890 +0300] apUDm9mUuou1H8H2UKXEHwAAANU 34.73.181.25 44332 127.0.0.1 7081 --c8a0073f-B-- GET /.ssh/known_hosts HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 172.16.159.63 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 172.16.159.63 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 172.16.159.63 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 172.16.159.63 Upgrade-Insecure-Requests: 1 X-Client-Ip: 172.16.159.63 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 172.16.159.63 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --c8a0073f-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --c8a0073f-H-- Message: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.ssh/known_hosts||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.ssh/known_hosts||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.ssh/known_hosts||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/.ssh/known_hosts"] [unique_id "apUDm9mUuou1H8H2UKXEHwAAANU"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.ssh/known_hosts||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/.ssh/known_hosts"] [unique_id "apUDm9mUuou1H8H2UKXEHwAAANU"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150683280354 150631 (- - -) Stopwatch2: 1788150683280354 150631; combined=34147, p1=251, p2=33847, p3=0, p4=0, p5=49, sr=80, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --c8a0073f-Z-- --0f607531-A-- [31/Aug/2026:07:31:23.455410 +0300] apUDm9mUuou1H8H2UKXEHgAAANQ 34.73.181.25 44324 127.0.0.1 7081 --0f607531-B-- GET /.ssh/authorized_keys HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 10.248.73.111 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 10.248.73.111 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 10.248.73.111 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 10.248.73.111 Upgrade-Insecure-Requests: 1 X-Client-Ip: 10.248.73.111 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 10.248.73.111 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --0f607531-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --0f607531-H-- Message: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.ssh/authorized_keys||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.ssh/authorized_keys||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.ssh/authorized_keys||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/.ssh/authorized_keys"] [unique_id "apUDm9mUuou1H8H2UKXEHgAAANQ"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.ssh/authorized_keys||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/.ssh/authorized_keys"] [unique_id "apUDm9mUuou1H8H2UKXEHgAAANQ"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150683247032 208468 (- - -) Stopwatch2: 1788150683247032 208468; combined=31760, p1=247, p2=31446, p3=0, p4=0, p5=67, sr=81, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --0f607531-Z-- --d236314e-A-- [31/Aug/2026:07:31:23.525262 +0300] apUDm9mUuou1H8H2UKXEIQAAANc 34.73.181.25 44356 127.0.0.1 7081 --d236314e-B-- GET /id_rsa HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 172.22.52.138 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 172.22.52.138 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 172.22.52.138 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 172.22.52.138 Upgrade-Insecure-Requests: 1 X-Client-Ip: 172.22.52.138 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 172.22.52.138 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --d236314e-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --d236314e-H-- Message: Warning. Matched phrase "id_rsa" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/id_rsa||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Matched phrase "id_rsa" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/id_rsa||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "id_rsa" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/id_rsa||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/id_rsa"] [unique_id "apUDm9mUuou1H8H2UKXEIQAAANc"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "id_rsa" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/id_rsa||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/id_rsa"] [unique_id "apUDm9mUuou1H8H2UKXEIQAAANc"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150683431503 93899 (- - -) Stopwatch2: 1788150683431503 93899; combined=32509, p1=469, p2=31974, p3=0, p4=0, p5=65, sr=290, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --d236314e-Z-- --f2ace91b-A-- [31/Aug/2026:07:31:23.891893 +0300] apUDm9mUuou1H8H2UKXEJgAAAM0 34.73.181.25 44372 127.0.0.1 7081 --f2ace91b-B-- GET /id_dsa HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 100.81.93.248 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 100.81.93.248 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 100.81.93.248 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 100.81.93.248 Upgrade-Insecure-Requests: 1 X-Client-Ip: 100.81.93.248 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 100.81.93.248 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --f2ace91b-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --f2ace91b-H-- Message: Warning. Matched phrase "id_dsa" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/id_dsa||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Matched phrase "id_dsa" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/id_dsa||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "id_dsa" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/id_dsa||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/id_dsa"] [unique_id "apUDm9mUuou1H8H2UKXEJgAAAM0"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "id_dsa" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/id_dsa||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/id_dsa"] [unique_id "apUDm9mUuou1H8H2UKXEJgAAAM0"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150683627203 264780 (- - -) Stopwatch2: 1788150683627203 264780; combined=32471, p1=250, p2=32155, p3=0, p4=0, p5=65, sr=93, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --f2ace91b-Z-- --2c228209-A-- [31/Aug/2026:07:31:24.453300 +0300] apUDnNmUuou1H8H2UKXELAAAAMg 34.73.181.25 44496 127.0.0.1 7081 --2c228209-B-- GET /@fs/app/.env?raw?? HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 100.66.184.74 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 100.66.184.74 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 100.66.184.74 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 100.66.184.74 Upgrade-Insecure-Requests: 1 X-Client-Ip: 100.66.184.74 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 100.66.184.74 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --2c228209-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --2c228209-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/@fs/app/.env"] [unique_id "apUDnNmUuou1H8H2UKXELAAAAMg"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150684386859 66543 (- - -) Stopwatch2: 1788150684386859 66543; combined=4352, p1=313, p2=3980, p3=0, p4=0, p5=59, sr=143, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --2c228209-Z-- --aad82529-A-- [31/Aug/2026:07:31:24.520025 +0300] apUDnNmUuou1H8H2UKXELgAAAMc 34.73.181.25 44536 127.0.0.1 7081 --aad82529-B-- GET /@fs/..%252f..%252f..%252f..%252f..%252fproc/self/environ?raw?? HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 172.20.201.113 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 172.20.201.113 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 172.20.201.113 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 172.20.201.113 Upgrade-Insecure-Requests: 1 X-Client-Ip: 172.20.201.113 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 172.20.201.113 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --aad82529-F-- HTTP/1.1 403 Forbidden Content-Length: 199 Content-Type: text/html; charset=iso-8859-1 --aad82529-H-- Message: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at MATCHED_VAR. [file "/etc/httpd/conf/modsecurity.d/rules/custom/012_i360_1_generic.conf"] [line "22"] [id "77140166"] [msg "IM360 WAF: Blocking directory traversal attempt||MVN:MATCHED_VAR||MV:/proc/self/environ?raw??||T:APACHE||"] [severity "CRITICAL"] [tag "service_gen"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G:raw??=& P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at MATCHED_VAR. [file "/etc/httpd/conf/modsecurity.d/rules/custom/012_i360_1_generic.conf"] [line "22"] [id "77140166"] [msg "IM360 WAF: Blocking directory traversal attempt||MVN:MATCHED_VAR||MV:/proc/self/environ?raw??||T:APACHE||"] [severity "CRITICAL"] [tag "service_gen"] [hostname "alexandervodka.com"] [uri "/@fs/..%2f..%2f..%2f..%2f..%2fproc/self/environ"] [unique_id "apUDnNmUuou1H8H2UKXELgAAAMc"] Action: Intercepted (phase 2) Stopwatch: 1788150684514720 5388 (- - -) Stopwatch2: 1788150684514720 5388; combined=3892, p1=260, p2=3304, p3=0, p4=0, p5=328, sr=89, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --aad82529-Z-- --7453a543-A-- [31/Aug/2026:07:31:24.539349 +0300] apUDnNmUuou1H8H2UKXELwAAAMA 34.73.181.25 44540 127.0.0.1 7081 --7453a543-B-- GET /@fs/..%252f..%252f..%252f..%252f..%252froot/.env?raw?? HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 172.16.149.242 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 172.16.149.242 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 172.16.149.242 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 172.16.149.242 Upgrade-Insecure-Requests: 1 X-Client-Ip: 172.16.149.242 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 172.16.149.242 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --7453a543-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --7453a543-E-- --7453a543-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/@fs/..%2f..%2f..%2f..%2f..%2froot/.env"] [unique_id "apUDnNmUuou1H8H2UKXELwAAAMA"] Stopwatch: 1788150684533865 5587 (- - -) Stopwatch2: 1788150684533865 5587; combined=4146, p1=267, p2=3759, p3=73, p4=7, p5=40, sr=89, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --7453a543-Z-- --c31cca52-A-- [31/Aug/2026:07:31:24.549999 +0300] apUDnCfaLSuAj0yzdueTHQAAABI 34.73.181.25 44510 127.0.0.1 7081 --c31cca52-B-- GET /@fs/../.env?raw?? HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 192.168.148.47 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 192.168.148.47 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 192.168.148.47 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 192.168.148.47 Upgrade-Insecure-Requests: 1 X-Client-Ip: 192.168.148.47 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 192.168.148.47 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --c31cca52-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --c31cca52-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/.env"] [unique_id "apUDnCfaLSuAj0yzdueTHQAAABI"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150684460091 90012 (- - -) Stopwatch2: 1788150684460091 90012; combined=5194, p1=332, p2=4803, p3=0, p4=0, p5=58, sr=125, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --c31cca52-Z-- --624f3b11-A-- [31/Aug/2026:07:31:24.561052 +0300] apUDnNmUuou1H8H2UKXELQAAANg 34.73.181.25 44520 127.0.0.1 7081 --624f3b11-B-- GET /@fs/src/.env?raw?? HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 10.44.215.84 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 10.44.215.84 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 10.44.215.84 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 10.44.215.84 Upgrade-Insecure-Requests: 1 X-Client-Ip: 10.44.215.84 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 10.44.215.84 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --624f3b11-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --624f3b11-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/@fs/src/.env"] [unique_id "apUDnNmUuou1H8H2UKXELQAAANg"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150684476381 84771 (- - -) Stopwatch2: 1788150684476381 84771; combined=5060, p1=380, p2=4623, p3=0, p4=0, p5=57, sr=161, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --624f3b11-Z-- --1ea68b55-A-- [31/Aug/2026:07:31:24.623635 +0300] apUDnCfaLSuAj0yzdueTHgAAABI 34.73.181.25 44550 127.0.0.1 7081 --1ea68b55-B-- GET /_nuxt/../.env HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 192.168.117.76 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 192.168.117.76 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 192.168.117.76 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 192.168.117.76 Upgrade-Insecure-Requests: 1 X-Client-Ip: 192.168.117.76 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 192.168.117.76 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --1ea68b55-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --1ea68b55-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/.env"] [unique_id "apUDnCfaLSuAj0yzdueTHgAAABI"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150684559832 63981 (- - -) Stopwatch2: 1788150684559832 63981; combined=5809, p1=272, p2=5478, p3=0, p4=0, p5=59, sr=91, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --1ea68b55-Z-- --8710ab77-A-- [31/Aug/2026:07:31:24.719222 +0300] apUDnNmUuou1H8H2UKXEMAAAAMY 34.73.181.25 44560 127.0.0.1 7081 --8710ab77-B-- GET /static../.env HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 172.23.34.44 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 172.23.34.44 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 172.23.34.44 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 172.23.34.44 Upgrade-Insecure-Requests: 1 X-Client-Ip: 172.23.34.44 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 172.23.34.44 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --8710ab77-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --8710ab77-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/static../.env"] [unique_id "apUDnNmUuou1H8H2UKXEMAAAAMY"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150684642010 77303 (- - -) Stopwatch2: 1788150684642010 77303; combined=7379, p1=271, p2=7044, p3=0, p4=0, p5=64, sr=101, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --8710ab77-Z-- --3265ff0d-A-- [31/Aug/2026:07:31:24.807124 +0300] apUDnH7glkZrdsSdRApJ6AAAAIo 34.73.181.25 44564 127.0.0.1 7081 --3265ff0d-B-- GET /files../.env HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 100.106.20.19 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 100.106.20.19 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 100.106.20.19 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 100.106.20.19 Upgrade-Insecure-Requests: 1 X-Client-Ip: 100.106.20.19 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 100.106.20.19 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --3265ff0d-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --3265ff0d-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/files../.env"] [unique_id "apUDnH7glkZrdsSdRApJ6AAAAIo"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150684732982 74231 (- - -) Stopwatch2: 1788150684732982 74231; combined=5196, p1=302, p2=4837, p3=0, p4=0, p5=56, sr=117, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --3265ff0d-Z-- --23524f65-A-- [31/Aug/2026:07:31:24.881847 +0300] apUDnNmUuou1H8H2UKXEMQAAAM4 34.73.181.25 44576 127.0.0.1 7081 --23524f65-B-- GET /static//app/.env HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 100.96.181.137 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 100.96.181.137 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 100.96.181.137 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 100.96.181.137 Upgrade-Insecure-Requests: 1 X-Client-Ip: 100.96.181.137 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 100.96.181.137 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --23524f65-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --23524f65-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/static/app/.env"] [unique_id "apUDnNmUuou1H8H2UKXEMQAAAM4"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150684735405 146556 (- - -) Stopwatch2: 1788150684735405 146556; combined=6537, p1=457, p2=6022, p3=0, p4=0, p5=57, sr=175, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --23524f65-Z-- --29c9e851-A-- [31/Aug/2026:07:31:24.908042 +0300] apUDnNmUuou1H8H2UKXEMwAAANM 34.73.181.25 44606 127.0.0.1 7081 --29c9e851-B-- GET /static//home/user/.env HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 10.39.142.71 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 10.39.142.71 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 10.39.142.71 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 10.39.142.71 Upgrade-Insecure-Requests: 1 X-Client-Ip: 10.39.142.71 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 10.39.142.71 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --29c9e851-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --29c9e851-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/static/home/user/.env"] [unique_id "apUDnNmUuou1H8H2UKXEMwAAANM"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150684829165 78966 (- - -) Stopwatch2: 1788150684829165 78966; combined=5177, p1=247, p2=4868, p3=0, p4=0, p5=62, sr=79, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --29c9e851-Z-- --02947465-A-- [31/Aug/2026:07:31:24.918992 +0300] apUDnNmUuou1H8H2UKXEMgAAANA 34.73.181.25 44588 127.0.0.1 7081 --02947465-B-- GET /static//.env HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 10.230.237.85 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 10.230.237.85 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 10.230.237.85 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 10.230.237.85 Upgrade-Insecure-Requests: 1 X-Client-Ip: 10.230.237.85 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 10.230.237.85 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --02947465-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --02947465-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/static/.env"] [unique_id "apUDnNmUuou1H8H2UKXEMgAAANA"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150684751053 168088 (- - -) Stopwatch2: 1788150684751053 168088; combined=4774, p1=281, p2=4438, p3=0, p4=0, p5=55, sr=86, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --02947465-Z-- --6659a052-A-- [31/Aug/2026:07:31:24.937893 +0300] apUDnG7fDIutYTwcPOkaeAAAAEo 34.73.181.25 44590 127.0.0.1 7081 --6659a052-B-- GET /media../.env HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 100.106.214.148 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 100.106.214.148 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 100.106.214.148 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 100.106.214.148 Upgrade-Insecure-Requests: 1 X-Client-Ip: 100.106.214.148 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 100.106.214.148 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --6659a052-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --6659a052-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/media../.env"] [unique_id "apUDnG7fDIutYTwcPOkaeAAAAEo"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150684801316 136665 (- - -) Stopwatch2: 1788150684801316 136665; combined=16222, p1=287, p2=15878, p3=0, p4=0, p5=57, sr=93, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --6659a052-Z-- --6209bb50-A-- [31/Aug/2026:07:31:24.966259 +0300] apUDnG7fDIutYTwcPOkaeQAAAEc 34.73.181.25 44610 127.0.0.1 7081 --6209bb50-B-- GET /.//.env HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 10.9.252.225 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 10.9.252.225 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 10.9.252.225 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 10.9.252.225 Upgrade-Insecure-Requests: 1 X-Client-Ip: 10.9.252.225 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 10.9.252.225 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --6209bb50-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --6209bb50-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/.env"] [unique_id "apUDnG7fDIutYTwcPOkaeQAAAEc"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150684885466 80883 (- - -) Stopwatch2: 1788150684885466 80883; combined=5110, p1=269, p2=4783, p3=0, p4=0, p5=58, sr=109, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --6209bb50-Z-- --ebd6563c-A-- [31/Aug/2026:07:31:25.038905 +0300] apUDnG7fDIutYTwcPOkaegAAAEQ 34.73.181.25 44624 127.0.0.1 7081 --ebd6563c-B-- GET //.env HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 172.20.111.144 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 172.20.111.144 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 172.20.111.144 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 172.20.111.144 Upgrade-Insecure-Requests: 1 X-Client-Ip: 172.20.111.144 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 172.20.111.144 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --ebd6563c-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --ebd6563c-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/.env"] [unique_id "apUDnG7fDIutYTwcPOkaegAAAEQ"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150684966271 72841 (- - -) Stopwatch2: 1788150684966271 72841; combined=4881, p1=241, p2=4551, p3=0, p4=0, p5=88, sr=71, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --ebd6563c-Z-- --6d4c2b43-A-- [31/Aug/2026:07:31:25.152952 +0300] apUDndmUuou1H8H2UKXENAAAAMU 34.73.181.25 44638 127.0.0.1 7081 --6d4c2b43-B-- GET /api/.env/public/.env HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 100.111.57.59 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 100.111.57.59 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 100.111.57.59 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 100.111.57.59 Upgrade-Insecure-Requests: 1 X-Client-Ip: 100.111.57.59 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 100.111.57.59 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --6d4c2b43-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --6d4c2b43-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/api/.env/public/.env"] [unique_id "apUDndmUuou1H8H2UKXENAAAAMU"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150685070253 82788 (- - -) Stopwatch2: 1788150685070253 82788; combined=6962, p1=434, p2=6469, p3=0, p4=0, p5=59, sr=122, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --6d4c2b43-Z-- --5aa7212d-A-- [31/Aug/2026:07:31:25.178738 +0300] apUDndmUuou1H8H2UKXENQAAAMQ 34.73.181.25 44640 127.0.0.1 7081 --5aa7212d-B-- GET /%2eenv HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 100.72.98.143 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 100.72.98.143 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 100.72.98.143 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 100.72.98.143 Upgrade-Insecure-Requests: 1 X-Client-Ip: 100.72.98.143 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 100.72.98.143 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --5aa7212d-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --5aa7212d-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/.env"] [unique_id "apUDndmUuou1H8H2UKXENQAAAMQ"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150685106096 72766 (- - -) Stopwatch2: 1788150685106096 72766; combined=4974, p1=256, p2=4635, p3=0, p4=0, p5=82, sr=84, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --5aa7212d-Z-- --411a3a74-A-- [31/Aug/2026:07:31:25.256975 +0300] apUDnX7glkZrdsSdRApJ6QAAAJM 34.73.181.25 44642 127.0.0.1 7081 --411a3a74-B-- GET /assets../.env HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 172.16.44.181 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 172.16.44.181 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 172.16.44.181 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 172.16.44.181 Upgrade-Insecure-Requests: 1 X-Client-Ip: 172.16.44.181 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 172.16.44.181 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --411a3a74-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --411a3a74-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/assets../.env"] [unique_id "apUDnX7glkZrdsSdRApJ6QAAAJM"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150685194881 62178 (- - -) Stopwatch2: 1788150685194881 62178; combined=5018, p1=277, p2=4685, p3=0, p4=0, p5=55, sr=88, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --411a3a74-Z-- --e2b4db2e-A-- [31/Aug/2026:07:31:25.406805 +0300] apUDnX7glkZrdsSdRApJ6gAAAJU 34.73.181.25 44668 127.0.0.1 7081 --e2b4db2e-B-- GET /img../.env HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 192.168.129.29 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 192.168.129.29 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 192.168.129.29 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 192.168.129.29 Upgrade-Insecure-Requests: 1 X-Client-Ip: 192.168.129.29 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 192.168.129.29 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --e2b4db2e-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --e2b4db2e-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/img../.env"] [unique_id "apUDnX7glkZrdsSdRApJ6gAAAJU"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150685305944 100950 (- - -) Stopwatch2: 1788150685305944 100950; combined=5802, p1=282, p2=5460, p3=0, p4=0, p5=60, sr=91, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --e2b4db2e-Z-- --ecd73067-A-- [31/Aug/2026:07:31:25.485904 +0300] apUDnW7fDIutYTwcPOkaewAAAEs 34.73.181.25 44660 127.0.0.1 7081 --ecd73067-B-- GET /uploads../.env HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 100.114.221.197 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 100.114.221.197 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 100.114.221.197 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 100.114.221.197 Upgrade-Insecure-Requests: 1 X-Client-Ip: 100.114.221.197 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 100.114.221.197 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --ecd73067-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --ecd73067-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/uploads../.env"] [unique_id "apUDnW7fDIutYTwcPOkaewAAAEs"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150685281322 204672 (- - -) Stopwatch2: 1788150685281322 204672; combined=5014, p1=163, p2=4793, p3=0, p4=0, p5=58, sr=57, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --ecd73067-Z-- --5a00cb42-A-- [31/Aug/2026:07:31:25.494548 +0300] apUDndmUuou1H8H2UKXENgAAANU 34.73.181.25 44648 127.0.0.1 7081 --5a00cb42-B-- GET /images../.env HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 10.98.22.165 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 10.98.22.165 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 10.98.22.165 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 10.98.22.165 Upgrade-Insecure-Requests: 1 X-Client-Ip: 10.98.22.165 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 10.98.22.165 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --5a00cb42-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --5a00cb42-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/images../.env"] [unique_id "apUDndmUuou1H8H2UKXENgAAANU"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150685280812 213914 (- - -) Stopwatch2: 1788150685280812 213914; combined=5029, p1=302, p2=4671, p3=0, p4=0, p5=56, sr=104, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --5a00cb42-Z-- --3a208051-A-- [31/Aug/2026:07:31:25.642342 +0300] apUDndmUuou1H8H2UKXENwAAAMo 34.73.181.25 55428 127.0.0.1 7081 --3a208051-B-- GET /@fs/var/task/.env?raw?? HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 100.88.75.84 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 100.88.75.84 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 100.88.75.84 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 100.88.75.84 Upgrade-Insecure-Requests: 1 X-Client-Ip: 100.88.75.84 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 100.88.75.84 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --3a208051-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --3a208051-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/@fs/var/task/.env"] [unique_id "apUDndmUuou1H8H2UKXENwAAAMo"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150685568530 73930 (- - -) Stopwatch2: 1788150685568530 73930; combined=3983, p1=294, p2=3626, p3=0, p4=0, p5=62, sr=96, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --3a208051-Z-- --ee575677-A-- [31/Aug/2026:07:31:25.691923 +0300] apUDnSfaLSuAj0yzdueTHwAAAAg 34.73.181.25 55430 127.0.0.1 7081 --ee575677-B-- GET /@fs/proc/self/cwd/.env?raw?? HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 10.60.252.134 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 10.60.252.134 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 10.60.252.134 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 10.60.252.134 Upgrade-Insecure-Requests: 1 X-Client-Ip: 10.60.252.134 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 10.60.252.134 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --ee575677-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --ee575677-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/@fs/proc/self/cwd/.env"] [unique_id "apUDnSfaLSuAj0yzdueTHwAAAAg"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150685624484 67548 (- - -) Stopwatch2: 1788150685624484 67548; combined=4560, p1=360, p2=4131, p3=0, p4=0, p5=69, sr=99, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --ee575677-Z-- --079d0a7f-A-- [31/Aug/2026:07:31:25.859521 +0300] apUDnX7glkZrdsSdRApJ7gAAAIU 172.69.223.200 55436 127.0.0.1 7081 --079d0a7f-B-- GET /.git/HEAD HTTP/1.1 Host: funshop.ro X-Real-IP: 172.69.223.200 X-Forwarded-For: 2a06:98c0:3600::103 X-Accel-Internal: /internal-nginx-static-location cf-ray: a3394e38f8536f05-CDG CF-EW-Via: 15 CDN-Loop: cloudflare; loops=1 Upgrade-Insecure-Requests: 1 Sec-Fetch-User: ?1 Accept-Language: en-US,en;q=0.9 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8 Cache-Control: no-cache User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36 Pragma: no-cache Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none cf-worker: jx1akqrgxx5exg.workers.dev CF-Visitor: {"scheme":"https"} X-Forwarded-Proto: https accept-encoding: gzip --079d0a7f-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --079d0a7f-E-- --079d0a7f-H-- Message: Warning. String match "/.git/" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "656"] [id "77318034"] [msg "IM360 WAF: Blocked access to git folder||T:APACHE||MV:/.git/head||"] [severity "NOTICE"] [tag "service_i360custom"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.git/" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "656"] [id "77318034"] [msg "IM360 WAF: Blocked access to git folder||T:APACHE||MV:/.git/head||"] [severity "NOTICE"] [tag "service_i360custom"] [hostname "funshop.ro"] [uri "/.git/HEAD"] [unique_id "apUDnX7glkZrdsSdRApJ7gAAAIU"] Stopwatch: 1788150685852216 7389 (- - -) Stopwatch2: 1788150685852216 7389; combined=5898, p1=391, p2=5331, p3=72, p4=7, p5=97, sr=153, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --079d0a7f-Z-- --81cbba0b-A-- [31/Aug/2026:07:31:25.894711 +0300] apUDnX7glkZrdsSdRApJ7wAAAJc 172.69.223.200 55438 127.0.0.1 7081 --81cbba0b-B-- GET /.git/config HTTP/1.1 Host: funshop.ro X-Real-IP: 172.69.223.200 X-Forwarded-For: 2a06:98c0:3600::103 X-Accel-Internal: /internal-nginx-static-location cf-ray: a3394e38f8546f05-CDG CF-EW-Via: 15 CDN-Loop: cloudflare; loops=1 Upgrade-Insecure-Requests: 1 Sec-Fetch-User: ?1 Accept-Language: en-US,en;q=0.9 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8 Cache-Control: no-cache User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36 Pragma: no-cache Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none cf-worker: jx1akqrgxx5exg.workers.dev CF-Visitor: {"scheme":"https"} X-Forwarded-Proto: https accept-encoding: gzip --81cbba0b-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --81cbba0b-E-- --81cbba0b-H-- Message: Warning. Matched phrase "/.git/config" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.git/config||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Matched phrase "/.git/config" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.git/config||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Message: Warning. String match "/.git/" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "656"] [id "77318034"] [msg "IM360 WAF: Blocked access to git folder||T:APACHE||MV:/.git/config||"] [severity "NOTICE"] [tag "service_i360custom"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "/.git/config" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.git/config||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "funshop.ro"] [uri "/.git/config"] [unique_id "apUDnX7glkZrdsSdRApJ7wAAAJc"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "/.git/config" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.git/config||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "funshop.ro"] [uri "/.git/config"] [unique_id "apUDnX7glkZrdsSdRApJ7wAAAJc"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.git/" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "656"] [id "77318034"] [msg "IM360 WAF: Blocked access to git folder||T:APACHE||MV:/.git/config||"] [severity "NOTICE"] [tag "service_i360custom"] [hostname "funshop.ro"] [uri "/.git/config"] [unique_id "apUDnX7glkZrdsSdRApJ7wAAAJc"] Stopwatch: 1788150685854167 40756 (- - -) Stopwatch2: 1788150685854167 40756; combined=38890, p1=588, p2=38073, p3=90, p4=10, p5=129, sr=228, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --81cbba0b-Z-- --02086704-A-- [31/Aug/2026:07:31:25.976746 +0300] apUDnX7glkZrdsSdRApJ8AAAAIc 34.73.181.25 55450 127.0.0.1 7081 --02086704-B-- GET /@fs/.env?url&raw?? HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 10.7.156.211 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 10.7.156.211 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 10.7.156.211 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 10.7.156.211 Upgrade-Insecure-Requests: 1 X-Client-Ip: 10.7.156.211 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 10.7.156.211 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --02086704-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --02086704-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:url&raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:url&raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/@fs/.env"] [unique_id "apUDnX7glkZrdsSdRApJ8AAAAIc"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150685875088 101758 (- - -) Stopwatch2: 1788150685875088 101758; combined=13613, p1=295, p2=13261, p3=0, p4=0, p5=57, sr=104, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --02086704-Z-- --2cd92f3c-A-- [31/Aug/2026:07:31:26.060951 +0300] apUDndmUuou1H8H2UKXEOwAAAMk 34.73.181.25 55498 127.0.0.1 7081 --2cd92f3c-B-- GET /@fs/.env?raw&url?? HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 172.23.46.20 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 172.23.46.20 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 172.23.46.20 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 172.23.46.20 Upgrade-Insecure-Requests: 1 X-Client-Ip: 172.23.46.20 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 172.23.46.20 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --2cd92f3c-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --2cd92f3c-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw&url??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw&url??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/@fs/.env"] [unique_id "apUDndmUuou1H8H2UKXEOwAAAMk"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150685982809 78228 (- - -) Stopwatch2: 1788150685982809 78228; combined=3936, p1=251, p2=3644, p3=0, p4=0, p5=41, sr=89, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --2cd92f3c-Z-- --f8f7ec2b-A-- [31/Aug/2026:07:31:26.218176 +0300] apUDntmUuou1H8H2UKXEPAAAANg 34.73.181.25 55508 127.0.0.1 7081 --f8f7ec2b-B-- GET /wp-config.php.bak HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 172.30.242.199 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 172.30.242.199 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 172.30.242.199 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 172.30.242.199 Upgrade-Insecure-Requests: 1 X-Client-Ip: 172.30.242.199 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 172.30.242.199 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --f8f7ec2b-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --f8f7ec2b-H-- Message: Warning. Matched phrase "wp-config.php." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/wp-config.php.bak||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Matched phrase "wp-config.php." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/wp-config.php.bak||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Message: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "wp-config.php." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/wp-config.php.bak||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/wp-config.php.bak"] [unique_id "apUDntmUuou1H8H2UKXEPAAAANg"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "wp-config.php." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/wp-config.php.bak||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/wp-config.php.bak"] [unique_id "apUDntmUuou1H8H2UKXEPAAAANg"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/wp-config.php.bak"] [unique_id "apUDntmUuou1H8H2UKXEPAAAANg"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150686058394 159935 (- - -) Stopwatch2: 1788150686058394 159935; combined=31863, p1=274, p2=31459, p3=0, p4=0, p5=129, sr=81, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --f8f7ec2b-Z-- --3ff26137-A-- [31/Aug/2026:07:31:26.228542 +0300] apUDnm7fDIutYTwcPOkafAAAAE0 34.73.181.25 55524 127.0.0.1 7081 --3ff26137-B-- GET /@fs/.env?import&?raw?? HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 10.190.150.154 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 10.190.150.154 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 10.190.150.154 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 10.190.150.154 Upgrade-Insecure-Requests: 1 X-Client-Ip: 10.190.150.154 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 10.190.150.154 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --3ff26137-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --3ff26137-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:import&?raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:import&?raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/@fs/.env"] [unique_id "apUDnm7fDIutYTwcPOkafAAAAE0"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150686093108 136644 (- - -) Stopwatch2: 1788150686093108 136644; combined=24967, p1=224, p2=3820, p3=0, p4=0, p5=10497, sr=77, sw=1, l=0, gc=10425 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --3ff26137-Z-- --74c04b64-A-- [31/Aug/2026:07:31:26.285846 +0300] apUDntmUuou1H8H2UKXEPgAAAM4 34.73.181.25 55530 127.0.0.1 7081 --74c04b64-B-- GET /wp-config.php.old HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 172.27.214.248 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 172.27.214.248 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 172.27.214.248 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 172.27.214.248 Upgrade-Insecure-Requests: 1 X-Client-Ip: 172.27.214.248 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 172.27.214.248 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --74c04b64-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --74c04b64-H-- Message: Warning. Matched phrase "wp-config.php." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/wp-config.php.old||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Matched phrase "wp-config.php." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/wp-config.php.old||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Message: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "wp-config.php." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/wp-config.php.old||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/wp-config.php.old"] [unique_id "apUDntmUuou1H8H2UKXEPgAAAM4"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "wp-config.php." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/wp-config.php.old||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/wp-config.php.old"] [unique_id "apUDntmUuou1H8H2UKXEPgAAAM4"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/wp-config.php.old"] [unique_id "apUDntmUuou1H8H2UKXEPgAAAM4"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150686191118 94841 (- - -) Stopwatch2: 1788150686191118 94841; combined=31934, p1=276, p2=31576, p3=0, p4=0, p5=81, sr=78, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --74c04b64-Z-- --8ebb9f2f-A-- [31/Aug/2026:07:31:26.480284 +0300] apUDntmUuou1H8H2UKXEQQAAANI 34.73.181.25 55566 127.0.0.1 7081 --8ebb9f2f-B-- GET /core/.env HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 100.107.100.135 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 100.107.100.135 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 100.107.100.135 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 100.107.100.135 Upgrade-Insecure-Requests: 1 X-Client-Ip: 100.107.100.135 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 100.107.100.135 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --8ebb9f2f-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --8ebb9f2f-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/core/.env"] [unique_id "apUDntmUuou1H8H2UKXEQQAAANI"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150686409376 71017 (- - -) Stopwatch2: 1788150686409376 71017; combined=4890, p1=287, p2=4544, p3=0, p4=0, p5=58, sr=95, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --8ebb9f2f-Z-- --7492956f-A-- [31/Aug/2026:07:31:26.503093 +0300] apUDnn7glkZrdsSdRApJ8wAAAII 34.73.181.25 55556 127.0.0.1 7081 --7492956f-B-- GET /laravel/.env HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 100.125.45.109 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 100.125.45.109 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 100.125.45.109 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 100.125.45.109 Upgrade-Insecure-Requests: 1 X-Client-Ip: 100.125.45.109 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 100.125.45.109 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --7492956f-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --7492956f-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/laravel/.env"] [unique_id "apUDnn7glkZrdsSdRApJ8wAAAII"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150686349240 153955 (- - -) Stopwatch2: 1788150686349240 153955; combined=6642, p1=292, p2=6287, p3=0, p4=0, p5=62, sr=102, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --7492956f-Z-- --bb76593d-A-- [31/Aug/2026:07:31:26.511978 +0300] apUDntmUuou1H8H2UKXEPwAAANA 34.73.181.25 55544 127.0.0.1 7081 --bb76593d-B-- GET /config/.env.php HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 172.17.188.36 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 172.17.188.36 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 172.17.188.36 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 172.17.188.36 Upgrade-Insecure-Requests: 1 X-Client-Ip: 172.17.188.36 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 172.17.188.36 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --bb76593d-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --bb76593d-H-- Message: Warning. Matched phrase ".env.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/config/.env.php||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Matched phrase ".env.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/config/.env.php||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".env.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/config/.env.php||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/config/.env.php"] [unique_id "apUDntmUuou1H8H2UKXEPwAAANA"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".env.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/config/.env.php||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/config/.env.php"] [unique_id "apUDntmUuou1H8H2UKXEPwAAANA"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150686348462 163622 (- - -) Stopwatch2: 1788150686348462 163622; combined=35449, p1=359, p2=35020, p3=0, p4=0, p5=70, sr=155, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --bb76593d-Z-- --3a70162c-A-- [31/Aug/2026:07:31:26.541748 +0300] apUDntmUuou1H8H2UKXEQAAAANE 34.73.181.25 55562 127.0.0.1 7081 --3a70162c-B-- GET /.env.php.bak HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 172.25.37.10 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 172.25.37.10 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 172.25.37.10 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 172.25.37.10 Upgrade-Insecure-Requests: 1 X-Client-Ip: 172.25.37.10 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 172.25.37.10 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --3a70162c-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --3a70162c-H-- Message: Warning. Matched phrase ".env.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.env.php.bak||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Matched phrase ".env.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.env.php.bak||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".env.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.env.php.bak||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/.env.php.bak"] [unique_id "apUDntmUuou1H8H2UKXEQAAAANE"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".env.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.env.php.bak||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/.env.php.bak"] [unique_id "apUDntmUuou1H8H2UKXEQAAAANE"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150686403683 138154 (- - -) Stopwatch2: 1788150686403683 138154; combined=37492, p1=260, p2=37169, p3=0, p4=0, p5=63, sr=96, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --3a70162c-Z-- --27f8364d-A-- [31/Aug/2026:07:31:26.709199 +0300] apUDnm7fDIutYTwcPOkafQAAAFE 34.73.181.25 55592 127.0.0.1 7081 --27f8364d-B-- GET /configuration.php.bak HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 100.83.50.152 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 100.83.50.152 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 100.83.50.152 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 100.83.50.152 Upgrade-Insecure-Requests: 1 X-Client-Ip: 100.83.50.152 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 100.83.50.152 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --27f8364d-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --27f8364d-H-- Message: Warning. Matched phrase "/configuration.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "/configuration.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/configuration.php.bak"] [unique_id "apUDnm7fDIutYTwcPOkafQAAAFE"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150686643121 66189 (- - -) Stopwatch2: 1788150686643121 66189; combined=4428, p1=238, p2=4127, p3=0, p4=0, p5=62, sr=80, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --27f8364d-Z-- --453a8c1b-A-- [31/Aug/2026:07:31:26.789982 +0300] apUDntmUuou1H8H2UKXEQgAAAMI 34.73.181.25 55610 127.0.0.1 7081 --453a8c1b-B-- GET /.env.swp HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 192.168.148.213 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 192.168.148.213 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 192.168.148.213 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 192.168.148.213 Upgrade-Insecure-Requests: 1 X-Client-Ip: 192.168.148.213 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 192.168.148.213 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --453a8c1b-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --453a8c1b-H-- Message: Warning. Pattern match "(\\.swp|~)$" at REQUEST_BASENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "309"] [id "77142201"] [msg "IM360 WAF: Possible enumeration of sensitive data (dirb)||MVN:REQUEST_BASENAME||T:APACHE||MV:.env.swp||"] [severity "NOTICE"] [tag "service_i360custom"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\.swp|~)$" at REQUEST_BASENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "309"] [id "77142201"] [msg "IM360 WAF: Possible enumeration of sensitive data (dirb)||MVN:REQUEST_BASENAME||T:APACHE||MV:.env.swp||"] [severity "NOTICE"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/.env.swp"] [unique_id "apUDntmUuou1H8H2UKXEQgAAAMI"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150686698077 92018 (- - -) Stopwatch2: 1788150686698077 92018; combined=4719, p1=236, p2=4418, p3=0, p4=0, p5=65, sr=77, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --453a8c1b-Z-- --9af7f705-A-- [31/Aug/2026:07:31:26.821212 +0300] apUDnifaLSuAj0yzdueTIAAAAAM 34.73.181.25 55584 127.0.0.1 7081 --9af7f705-B-- GET /config.php.bak HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 100.104.9.168 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 100.104.9.168 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 100.104.9.168 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 100.104.9.168 Upgrade-Insecure-Requests: 1 X-Client-Ip: 100.104.9.168 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 100.104.9.168 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --9af7f705-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --9af7f705-H-- Message: Warning. Matched phrase "/config.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "/config.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/config.php.bak"] [unique_id "apUDnifaLSuAj0yzdueTIAAAAAM"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150686614770 206556 (- - -) Stopwatch2: 1788150686614770 206556; combined=5072, p1=231, p2=4786, p3=0, p4=0, p5=55, sr=86, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --9af7f705-Z-- --4a5a1552-A-- [31/Aug/2026:07:31:26.870921 +0300] apUDntmUuou1H8H2UKXEQwAAANU 34.73.181.25 55616 127.0.0.1 7081 --4a5a1552-B-- GET /public/.env HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 10.211.70.244 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 10.211.70.244 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 10.211.70.244 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 10.211.70.244 Upgrade-Insecure-Requests: 1 X-Client-Ip: 10.211.70.244 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 10.211.70.244 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --4a5a1552-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --4a5a1552-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/public/.env"] [unique_id "apUDntmUuou1H8H2UKXEQwAAANU"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150686720916 150117 (- - -) Stopwatch2: 1788150686720916 150117; combined=4835, p1=266, p2=4511, p3=0, p4=0, p5=57, sr=84, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --4a5a1552-Z-- --be399765-A-- [31/Aug/2026:07:31:26.971427 +0300] apUDnn7glkZrdsSdRApJ9QAAAIs 34.73.181.25 55620 127.0.0.1 7081 --be399765-B-- GET /web/.env HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 10.18.76.71 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 10.18.76.71 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 10.18.76.71 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 10.18.76.71 Upgrade-Insecure-Requests: 1 X-Client-Ip: 10.18.76.71 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 10.18.76.71 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --be399765-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --be399765-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/web/.env"] [unique_id "apUDnn7glkZrdsSdRApJ9QAAAIs"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150686902609 68907 (- - -) Stopwatch2: 1788150686902609 68907; combined=5107, p1=297, p2=4753, p3=0, p4=0, p5=57, sr=92, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --be399765-Z-- --3d225b36-A-- [31/Aug/2026:07:31:27.023888 +0300] apUDnn7glkZrdsSdRApJ9gAAAJM 34.73.181.25 55628 127.0.0.1 7081 --3d225b36-B-- GET /storage/.env HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 100.89.221.10 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 100.89.221.10 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 100.89.221.10 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 100.89.221.10 Upgrade-Insecure-Requests: 1 X-Client-Ip: 100.89.221.10 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 100.89.221.10 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --3d225b36-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --3d225b36-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/storage/.env"] [unique_id "apUDnn7glkZrdsSdRApJ9gAAAJM"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150686956235 67740 (- - -) Stopwatch2: 1788150686956235 67740; combined=5545, p1=322, p2=5177, p3=0, p4=0, p5=46, sr=89, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --3d225b36-Z-- --cf612a2e-A-- [31/Aug/2026:07:31:27.085770 +0300] apUDnn7glkZrdsSdRApJ9wAAAJU 34.73.181.25 55634 127.0.0.1 7081 --cf612a2e-B-- GET /wp/.env HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 192.168.22.52 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 192.168.22.52 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 192.168.22.52 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 192.168.22.52 Upgrade-Insecure-Requests: 1 X-Client-Ip: 192.168.22.52 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 192.168.22.52 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --cf612a2e-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --cf612a2e-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/wp/.env"] [unique_id "apUDnn7glkZrdsSdRApJ9wAAAJU"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150686982651 103208 (- - -) Stopwatch2: 1788150686982651 103208; combined=4655, p1=243, p2=4352, p3=0, p4=0, p5=59, sr=79, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --cf612a2e-Z-- --ec426506-A-- [31/Aug/2026:07:31:27.156144 +0300] apUDn27fDIutYTwcPOkafgAAAEw 34.73.181.25 55646 127.0.0.1 7081 --ec426506-B-- GET /wp-config.php~ HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 10.199.79.64 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 10.199.79.64 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 10.199.79.64 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 10.199.79.64 Upgrade-Insecure-Requests: 1 X-Client-Ip: 10.199.79.64 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 10.199.79.64 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --ec426506-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --ec426506-H-- Message: Warning. Matched phrase "wp-config.php~" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/wp-config.php~||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Matched phrase "wp-config.php~" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/wp-config.php~||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Message: Warning. Pattern match "(\\.swp|~)$" at REQUEST_BASENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "309"] [id "77142201"] [msg "IM360 WAF: Possible enumeration of sensitive data (dirb)||MVN:REQUEST_BASENAME||T:APACHE||MV:wp-config.php~||"] [severity "NOTICE"] [tag "service_i360custom"] Message: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "wp-config.php~" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/wp-config.php~||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/wp-config.php~"] [unique_id "apUDn27fDIutYTwcPOkafgAAAEw"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "wp-config.php~" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/wp-config.php~||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/wp-config.php~"] [unique_id "apUDn27fDIutYTwcPOkafgAAAEw"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\.swp|~)$" at REQUEST_BASENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "309"] [id "77142201"] [msg "IM360 WAF: Possible enumeration of sensitive data (dirb)||MVN:REQUEST_BASENAME||T:APACHE||MV:wp-config.php~||"] [severity "NOTICE"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/wp-config.php~"] [unique_id "apUDn27fDIutYTwcPOkafgAAAEw"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/wp-config.php~"] [unique_id "apUDn27fDIutYTwcPOkafgAAAEw"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150687021543 134690 (- - -) Stopwatch2: 1788150687021543 134690; combined=38069, p1=255, p2=37737, p3=0, p4=0, p5=77, sr=78, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --ec426506-Z-- --81566138-A-- [31/Aug/2026:07:31:27.162923 +0300] apUDn37glkZrdsSdRApJ@AAAAI4 34.73.181.25 55664 127.0.0.1 7081 --81566138-B-- GET /wp-config.php.swp HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 172.17.143.31 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 172.17.143.31 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 172.17.143.31 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 172.17.143.31 Upgrade-Insecure-Requests: 1 X-Client-Ip: 172.17.143.31 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 172.17.143.31 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --81566138-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --81566138-H-- Message: Warning. Matched phrase "wp-config.php." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/wp-config.php.swp||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Matched phrase "wp-config.php." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/wp-config.php.swp||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Message: Warning. Pattern match "(\\.swp|~)$" at REQUEST_BASENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "309"] [id "77142201"] [msg "IM360 WAF: Possible enumeration of sensitive data (dirb)||MVN:REQUEST_BASENAME||T:APACHE||MV:wp-config.php.swp||"] [severity "NOTICE"] [tag "service_i360custom"] Message: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "wp-config.php." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/wp-config.php.swp||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/wp-config.php.swp"] [unique_id "apUDn37glkZrdsSdRApJ@AAAAI4"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "wp-config.php." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/wp-config.php.swp||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/wp-config.php.swp"] [unique_id "apUDn37glkZrdsSdRApJ@AAAAI4"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\.swp|~)$" at REQUEST_BASENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "309"] [id "77142201"] [msg "IM360 WAF: Possible enumeration of sensitive data (dirb)||MVN:REQUEST_BASENAME||T:APACHE||MV:wp-config.php.swp||"] [severity "NOTICE"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/wp-config.php.swp"] [unique_id "apUDn37glkZrdsSdRApJ@AAAAI4"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/wp-config.php.swp"] [unique_id "apUDn37glkZrdsSdRApJ@AAAAI4"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150687037359 125652 (- - -) Stopwatch2: 1788150687037359 125652; combined=32258, p1=302, p2=31883, p3=0, p4=0, p5=73, sr=96, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --81566138-Z-- --72152e75-A-- [31/Aug/2026:07:32:04.784701 +0300] apUDxNmUuou1H8H2UKXEcgAAAMU 138.197.193.77 40658 127.0.0.1 7081 --72152e75-B-- POST /wp-login.php HTTP/1.1 Host: ajutam.ro X-Real-IP: 138.197.193.77 X-Accel-Internal: /internal-nginx-static-location Content-Length: 111 Accept: */* User-Agent: Mozilla/5.0 Content-Type: application/x-www-form-urlencoded Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818 --72152e75-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --72152e75-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:07-32.138.197.193.77"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788150724724259 60501 (- - -) Stopwatch2: 1788150724724259 60501; combined=59135, p1=268, p2=58241, p3=0, p4=0, p5=442, sr=108, sw=184, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --72152e75-Z-- --f9b03763-A-- [31/Aug/2026:07:34:13.196495 +0300] apUERW7fDIutYTwcPOkaqAAAAFg 207.154.219.81 45234 127.0.0.1 7081 --f9b03763-B-- POST /wp-login.php HTTP/1.1 Host: ajutam.ro X-Real-IP: 207.154.219.81 X-Accel-Internal: /internal-nginx-static-location Content-Length: 109 Accept: */* User-Agent: Mozilla/5.0 Content-Type: application/x-www-form-urlencoded Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818 --f9b03763-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --f9b03763-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:07-34.207.154.219.81"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788150853132856 63723 (- - -) Stopwatch2: 1788150853132856 63723; combined=61208, p1=416, p2=60009, p3=0, p4=0, p5=573, sr=161, sw=210, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --f9b03763-Z--