/
var
/
log
/
/var/log
mkdir
upload
Name
Size
Mode
Actions
audit/
-
0700
rm
chrony/
-
0750
rm
httpd/
-
0700
rm
imunify360/
-
0700
rm
imunify360_user_logs/
-
1777
rm
mailman/
-
0775
rm
mariadb/
-
0750
rm
nginx/
-
0750
rm
passenger/
-
0750
rm
passenger-analytics/
-
0755
rm
pcp/
-
0775
rm
plesk/
-
0750
rm
plesk-php71-fpm/
-
0750
rm
plesk-php72-fpm/
-
0750
rm
plesk-php73-fpm/
-
0750
rm
plesk-php74-fpm/
-
0750
rm
plesk-php80-fpm/
-
0750
rm
plesk-php81-fpm/
-
0700
rm
plesk-php82-fpm/
-
0700
rm
plesk-php83-fpm/
-
0700
rm
plesk-php84-fpm/
-
0700
rm
plesk-php85-fpm/
-
0700
rm
plesk-roundcube/
-
0750
rm
private/
-
0700
rm
qemu-ga/
-
0755
rm
rear/
-
0755
rm
sa/
-
0755
rm
sssd/
-
0750
rm
sw-cp-server/
-
0750
rm
tuned/
-
0755
rm
boot.log
717
0650
edit
dl
rm
btmp
0
0660
edit
dl
rm
btmp-20260801
0
0660
edit
dl
rm
cloud-init-output.log
631746
0650
edit
dl
rm
cloud-init.log
783625
0640
edit
dl
rm
cron
988213
0650
edit
dl
rm
cron-20260809
6498680
0650
edit
dl
rm
cron-20260816
6477566
0650
edit
dl
rm
cron-20260823
6415805
0650
edit
dl
rm
cron-20260830
6214919
0650
edit
dl
rm
dnf.librepo.log
55284
0654
edit
dl
rm
dnf.librepo.log.1
1048394
0654
edit
dl
rm
dnf.librepo.log.2
1048486
0654
edit
dl
rm
dnf.librepo.log.3
1048494
0654
edit
dl
rm
dnf.librepo.log.4
1048412
0654
edit
dl
rm
dnf.log
278284
0654
edit
dl
rm
dnf.log-20241020
992972
0654
edit
dl
rm
dnf.log-20241027
909028
0654
edit
dl
rm
dnf.log.1
1048521
0654
edit
dl
rm
dnf.log.2
1048494
0654
edit
dl
rm
dnf.log.3
1048560
0654
edit
dl
rm
dnf.log.4
1048486
0654
edit
dl
rm
dnf.rpm.log
817709
0654
edit
dl
rm
dnf.rpm.log.1
1048560
0654
edit
dl
rm
dnf.rpm.log.2
1048561
0654
edit
dl
rm
dnf.rpm.log.3
1048572
0654
edit
dl
rm
dnf.rpm.log.4
1048550
0654
edit
dl
rm
firewalld
0
0650
edit
dl
rm
firewalld-20241020
186
0640
edit
dl
rm
firewalld-20241027
0
0640
edit
dl
rm
hawkey.log
1020
0654
edit
dl
rm
hawkey.log-20260809
9360
0654
edit
dl
rm
hawkey.log-20260816
8880
0654
edit
dl
rm
hawkey.log-20260823
7380
0654
edit
dl
rm
hawkey.log-20260830
8880
0654
edit
dl
rm
imav-deploy.log
40617
0600
edit
dl
rm
imunify-agent-proxy.log
413057
0644
edit
dl
rm
lastlog
2926424
0664
edit
dl
rm
lfd.log
63349
0650
edit
dl
rm
lfd.log-20260830.gz
37751
0650
edit
dl
rm
maillog
495336
0640
edit
dl
rm
maillog-20241020
2337077
0640
edit
dl
rm
maillog-20241027
2777085
0640
edit
dl
rm
maillog.processed
11707768
0640
edit
dl
rm
maillog.processed.1.gz
712153
0640
edit
dl
rm
maillog.processed.2.gz
781382
0640
edit
dl
rm
maillog.processed.3.gz
701943
0640
edit
dl
rm
messages
14311370
0650
edit
dl
rm
messages-20260809
334173074
0650
edit
dl
rm
messages-20260816
166676382
0650
edit
dl
rm
messages-20260823
69446086
0650
edit
dl
rm
messages-20260830
70180755
0650
edit
dl
rm
modsec_audit.log
546063
0654
edit
dl
rm
modsec_audit.log-20260825.gz
415338
0654
edit
dl
rm
modsec_audit.log-20260826.gz
209583
0654
edit
dl
rm
modsec_audit.log-20260827.gz
607029
0654
edit
dl
rm
modsec_audit.log-20260828.gz
320601
0654
edit
dl
rm
modsec_audit.log-20260829.gz
667203
0654
edit
dl
rm
modsec_audit.log-20260830.gz
496891
0654
edit
dl
rm
modsec_audit.log-20260831.gz
595737
0654
edit
dl
rm
mysql-slow.log
0
0654
edit
dl
rm
mysqld.log
6414
0650
edit
dl
rm
mysqld.log-20241020
41639300
0644
edit
dl
rm
mysqld.log-20241027
0
0644
edit
dl
rm
mysqld.log-20260831.gz
11177
0650
edit
dl
rm
mysqld.log.1.gz
853
0600
edit
dl
rm
restic.log
500584
0644
edit
dl
rm
rkhunter.log
127869
0650
edit
dl
rm
rkhunter.log.old
6406
0650
edit
dl
rm
sa-update.log
145580
0654
edit
dl
rm
sa-update.log-20260501
145480
0654
edit
dl
rm
sa-update.log-20260601
150563
0654
edit
dl
rm
sa-update.log-20260701
145410
0654
edit
dl
rm
sa-update.log-20260801
149853
0654
edit
dl
rm
secure
340843
0650
edit
dl
rm
secure-20260809
1787871
0650
edit
dl
rm
secure-20260816
1839351
0650
edit
dl
rm
secure-20260823
1811716
0650
edit
dl
rm
secure-20260830
1948379
0650
edit
dl
rm
spooler
0
0650
edit
dl
rm
spooler-20260809
0
0650
edit
dl
rm
spooler-20260816
0
0650
edit
dl
rm
spooler-20260823
0
0650
edit
dl
rm
spooler-20260830
0
0650
edit
dl
rm
wtmp
295680
0664
edit
dl
rm
wtmp-20260403
1049472
0664
edit
dl
rm
Edit:
/var/log/modsec_audit.log
(546063B)
--babed52b-A-- [31/Aug/2026:04:05:40.384691 +0300] apTTZCfaLSuAj0yzdueSCAAAAAQ 34.28.26.247 57832 127.0.0.1 7081 --babed52b-B-- GET /.git/config HTTP/1.1 Host: mediabuy.ro X-Real-IP: 34.28.26.247 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 Accept: */* --babed52b-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/7.3.33 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --babed52b-H-- Message: Warning. Matched phrase "/.git/config" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.git/config||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Matched phrase "/.git/config" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.git/config||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Message: Warning. String match "/.git/" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "656"] [id "77318034"] [msg "IM360 WAF: Blocked access to git folder||T:APACHE||MV:/.git/config||"] [severity "NOTICE"] [tag "service_i360custom"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "/.git/config" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.git/config||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "mediabuy.ro"] [uri "/.git/config"] [unique_id "apTTZCfaLSuAj0yzdueSCAAAAAQ"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "/.git/config" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.git/config||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "mediabuy.ro"] [uri "/.git/config"] [unique_id "apTTZCfaLSuAj0yzdueSCAAAAAQ"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.git/" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "656"] [id "77318034"] [msg "IM360 WAF: Blocked access to git folder||T:APACHE||MV:/.git/config||"] [severity "NOTICE"] [tag "service_i360custom"] [hostname "mediabuy.ro"] [uri "/.git/config"] [unique_id "apTTZCfaLSuAj0yzdueSCAAAAAQ"] Apache-Handler: proxy:unix:/var/www/vhosts/system/mediabuy.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788138340124313 260432 (- - -) Stopwatch2: 1788138340124313 260432; combined=37056, p1=264, p2=36711, p3=0, p4=0, p5=81, sr=96, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --babed52b-Z-- --5e40c140-A-- [31/Aug/2026:04:07:54.536517 +0300] apTT6tmUuou1H8H2UKW93wAAAMA 38.141.62.235 52668 127.0.0.1 7081 --5e40c140-B-- POST /contact HTTP/1.1 Host: ihelp.ro X-Real-IP: 38.141.62.235 X-Accel-Internal: /internal-nginx-static-location Content-Length: 593 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) obsidian/1.8.10 Chrome/132.0.6834.196 Electron/34.2.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7 Accept-Language: en-US,en;q=0.9 Accept-Encoding: gzip, deflate, br Referer: https://ihelp.ro/contact Sec-Fetch-Dest: document Sec-Fetch-Mode: same-origin Sec-Fetch-Site: same-origin Sec-Fetch-User: ?1 Cookie: csrfToken=oJYjXqYj%2BvnXD3zOpYXIHmZiMWQ3YjJiODRmNjE0NTY1YTA4ZjRjMmE2N2VmZmFiOTRkZjc1MzY%3D Content-Type: application/x-www-form-urlencoded Sec-CH-UA: "Google Chrome";v="132", "Chromium";v="132", "Not)A;Brand";v="24" Sec-CH-UA-Mobile: ?0 Sec-CH-UA-Platform: "Windows" --5e40c140-F-- HTTP/1.1 200 OK X-Powered-By: PHP/8.1.34 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache X-DEBUGKIT-ID: a3e26ee0-c901-459b-b9a7-f90c5167e904 Set-Cookie: PHPSESSID=dkmfrqmsubkgnffq9qrjg1ljlb; path=/; secure; HttpOnly; SameSite=Lax Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --5e40c140-H-- Message: Match of "rbl nxdomain.v2.rbl.imunify.com." against "TX:rbl_ip" required. [file "/etc/httpd/conf/modsecurity.d/rules/custom/011_i360_8_spam.conf"] [line "102"] [id "77141095"] [msg "IM360 WAF: Block spam in PrestaShop||T:APACHE||MVN:TX:rbl_ip||MV:04-07.38.141.62.235||"] [severity "CRITICAL"] [tag "other_apps"] Message: Matched phrase "/contact" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/011_i360_8_spam.conf"] [line "182"] [id "77142192"] [msg "IM360 WAF: Track spam attempts||T:APACHE||MVN:REQUEST_FILENAME||MV:/contact||"] [severity "NOTICE"] [tag "other_apps"] [tag "noshow"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788138474359394 177366 (- - -) Stopwatch2: 1788138474359394 177366; combined=63503, p1=392, p2=63035, p3=0, p4=0, p5=76, sr=133, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "DETECTION_ONLY" --5e40c140-Z-- --79955f09-A-- [31/Aug/2026:04:09:24.022367 +0300] apTUQ9mUuou1H8H2UKW95QAAAMw 64.227.61.137 59018 127.0.0.1 7081 --79955f09-B-- GET /?author=1 HTTP/1.1 Host: axapres.ro X-Real-IP: 64.227.61.137 X-Accel-Internal: /internal-nginx-static-location Accept: */* User-Agent: Mozilla/5.0 Accept-Encoding: gzip,deflate --79955f09-F-- HTTP/1.1 301 Moved Permanently X-Powered-By: PHP/7.1.33 X-Redirect-By: WordPress Location: https://axapres.ro/author/cosmin/ Content-Length: 0 Content-Type: text/html; charset=UTF-8 --79955f09-E-- --79955f09-H-- Message: Operator GE matched 1 at ARGS:author. [file "/etc/httpd/conf/modsecurity.d/rules/custom/007_i360_4_wordpress.conf"] [line "59"] [id "77140876"] [msg "IM360 WAF: Track WordPress users enumeration||MVN:ARGS:author||MV:1||T:APACHE||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Apache-Handler: proxy:unix:/var/www/vhosts/system/axapres.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788138563708456 314019 (- - -) Stopwatch2: 1788138563708456 314019; combined=4577, p1=369, p2=3978, p3=135, p4=10, p5=85, sr=124, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --79955f09-Z-- --f7be3f65-A-- [31/Aug/2026:04:09:24.511911 +0300] apTURNmUuou1H8H2UKW95gAAAM4 64.227.61.137 59024 127.0.0.1 7081 --f7be3f65-B-- GET /?author=2 HTTP/1.1 Host: axapres.ro X-Real-IP: 64.227.61.137 X-Accel-Internal: /internal-nginx-static-location Accept: */* User-Agent: Mozilla/5.0 Accept-Encoding: gzip,deflate --f7be3f65-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/7.1.33 Expires: Wed, 11 Jan 1984 05:00:00 GMT Cache-Control: no-cache, must-revalidate, max-age=0 Link: <https://axapres.ro/wp-json/>; rel="https://api.w.org/" Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --f7be3f65-E-- --f7be3f65-H-- Message: Operator GE matched 1 at ARGS:author. [file "/etc/httpd/conf/modsecurity.d/rules/custom/007_i360_4_wordpress.conf"] [line "59"] [id "77140876"] [msg "IM360 WAF: Track WordPress users enumeration||MVN:ARGS:author||MV:2||T:APACHE||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Apache-Handler: proxy:unix:/var/www/vhosts/system/axapres.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788138564194746 317236 (- - -) Stopwatch2: 1788138564194746 317236; combined=3681, p1=276, p2=3241, p3=102, p4=25, p5=36, sr=91, sw=1, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --f7be3f65-Z-- --babed52b-A-- [31/Aug/2026:04:13:12.015280 +0300] apTVJ37glkZrdsSdRApHEgAAAIY 114.16.206.169 50522 127.0.0.1 7081 --babed52b-B-- POST /wp-login.php HTTP/1.1 Host: axapres.ro X-Real-IP: 114.16.206.169 X-Accel-Internal: /internal-nginx-static-location Content-Length: 125 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7 Accept-Language: ru-RU,ru;q=0.9,en-US;q=0.8,en;q=0.7 Cache-Control: max-age=0 Content-Type: application/x-www-form-urlencoded Origin: https://axapres.ro Referer: https://axapres.ro/wp-login.php Sec-Ch-Ua: "Not=A?Brand";v="99", "Google Chrome";v="151", "Chromium";v="151" Sec-Ch-Ua-Mobile: ?0 Sec-Ch-Ua-Platform: "Windows" Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: same-origin Sec-Fetch-User: ?1 Upgrade-Insecure-Requests: 1 User-Agent: 114.16.206.169 Accept-Encoding: gzip, deflate, br Cookie: wordpress_test_cookie=WP%20Cookie%20check --babed52b-F-- HTTP/1.1 403 Forbidden Content-Length: 199 Content-Type: text/html; charset=iso-8859-1 --babed52b-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:04-13.114.16.206.169"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Apache-Handler: proxy:unix:/var/www/vhosts/system/axapres.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788138791954546 60822 (- - -) Stopwatch2: 1788138791954546 60822; combined=59528, p1=347, p2=58593, p3=0, p4=0, p5=446, sr=155, sw=142, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --babed52b-Z-- --babed52b-A-- [31/Aug/2026:04:23:35.015749 +0300] apTXlm7fDIutYTwcPOkZJgAAAEI 216.73.217.35 47890 127.0.0.1 7081 --babed52b-B-- GET /img/ufo19w_831.php HTTP/1.1 Host: ihelp.ro X-Real-IP: 216.73.217.35 X-Accel-Internal: /internal-nginx-static-location accept: */* user-agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com) accept-encoding: gzip, br, zstd, deflate --babed52b-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.1.34 X-DEBUGKIT-ID: 7d4b16b8-cb24-43c4-928c-0552402eae7e Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --babed52b-H-- Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19w_831.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19w_831.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19w_831.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "ihelp.ro"] [uri "/img/ufo19w_831.php"] [unique_id "apTXlm7fDIutYTwcPOkZJgAAAEI"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19w_831.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] [hostname "ihelp.ro"] [uri "/img/ufo19w_831.php"] [unique_id "apTXlm7fDIutYTwcPOkZJgAAAEI"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788139414642301 373536 (- - -) Stopwatch2: 1788139414642301 373536; combined=37448, p1=377, p2=36945, p3=0, p4=0, p5=125, sr=195, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "DETECTION_ONLY" --babed52b-Z-- --c6dd5143-A-- [31/Aug/2026:04:23:47.105284 +0300] apTXotmUuou1H8H2UKW@EQAAANY 216.73.217.35 45342 127.0.0.1 7081 --c6dd5143-B-- GET /img/ufo19_shell_30207.php HTTP/1.1 Host: ihelp.ro X-Real-IP: 216.73.217.35 X-Accel-Internal: /internal-nginx-static-location accept: */* user-agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com) accept-encoding: gzip, br, zstd, deflate --c6dd5143-F-- HTTP/1.1 200 OK X-Powered-By: PHP/8.1.34 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --c6dd5143-H-- Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19_shell_30207.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19_shell_30207.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19_shell_30207.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "ihelp.ro"] [uri "/img/ufo19_shell_30207.php"] [unique_id "apTXotmUuou1H8H2UKW@EQAAANY"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19_shell_30207.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] [hostname "ihelp.ro"] [uri "/img/ufo19_shell_30207.php"] [unique_id "apTXotmUuou1H8H2UKW@EQAAANY"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788139426882432 222908 (- - -) Stopwatch2: 1788139426882432 222908; combined=34493, p1=311, p2=34118, p3=0, p4=0, p5=64, sr=152, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "DETECTION_ONLY" --c6dd5143-Z-- --f58f7b59-A-- [31/Aug/2026:04:24:09.085453 +0300] apTXuH7glkZrdsSdRApHIgAAAIw 216.73.217.35 37236 127.0.0.1 7081 --f58f7b59-B-- GET /img/ufo19p_20539.php HTTP/1.1 Host: ihelp.ro X-Real-IP: 216.73.217.35 X-Accel-Internal: /internal-nginx-static-location accept: */* user-agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com) accept-encoding: gzip, br, zstd, deflate --f58f7b59-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.1.34 X-DEBUGKIT-ID: cbe7d303-1d38-414a-b80f-c00c590637af Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --f58f7b59-H-- Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19p_20539.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19p_20539.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19p_20539.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "ihelp.ro"] [uri "/img/ufo19p_20539.php"] [unique_id "apTXuH7glkZrdsSdRApHIgAAAIw"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19p_20539.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] [hostname "ihelp.ro"] [uri "/img/ufo19p_20539.php"] [unique_id "apTXuH7glkZrdsSdRApHIgAAAIw"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788139448853010 232493 (- - -) Stopwatch2: 1788139448853010 232493; combined=33918, p1=329, p2=33463, p3=0, p4=0, p5=126, sr=116, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "DETECTION_ONLY" --f58f7b59-Z-- --a43cbc2c-A-- [31/Aug/2026:04:26:23.925576 +0300] apTYP37glkZrdsSdRApHJQAAAJA 103.119.98.55 38614 127.0.0.1 7081 --a43cbc2c-B-- GET /xmlrpc.php HTTP/1.1 Host: ajutam.ro X-Real-IP: 103.119.98.55 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36 Accept-Encoding: gzip, deflate, zstd Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en-US,en;q=0.5 --a43cbc2c-F-- HTTP/1.1 405 Method Not Allowed X-Powered-By: PHP/7.3.33 Allow: POST Transfer-Encoding: chunked Content-Type: text/plain;charset=UTF-8 --a43cbc2c-E-- --a43cbc2c-H-- Message: Warning. String match "xmlrpc.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "290"] [id "77141064"] [msg "IM360 WAF: CMS Recon Bot detected||MVN:REQUEST_FILENAME||T:APACHE||MV:/xmlrpc.php||RM:GET"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "xmlrpc.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "290"] [id "77141064"] [msg "IM360 WAF: CMS Recon Bot detected||MVN:REQUEST_FILENAME||T:APACHE||MV:/xmlrpc.php||RM:GET"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "ajutam.ro"] [uri "/xmlrpc.php"] [unique_id "apTYP37glkZrdsSdRApHJQAAAJA"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ajutam.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788139583595333 330336 (- - -) Stopwatch2: 1788139583595333 330336; combined=4228, p1=230, p2=3849, p3=95, p4=9, p5=45, sr=89, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --a43cbc2c-Z-- --854be211-A-- [31/Aug/2026:04:26:29.009001 +0300] apTYRNmUuou1H8H2UKW@GQAAAM4 103.119.98.55 45936 127.0.0.1 7081 --854be211-B-- GET /xmlrpc.php?rsd HTTP/1.1 Host: ajutam.ro X-Real-IP: 103.119.98.55 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36 Accept-Encoding: gzip, deflate, zstd Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en-US,en;q=0.5 --854be211-F-- HTTP/1.1 200 OK X-Powered-By: PHP/7.3.33 Transfer-Encoding: chunked Content-Type: text/xml; charset=UTF-8 --854be211-E-- --854be211-H-- Message: Warning. String match "xmlrpc.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "290"] [id "77141064"] [msg "IM360 WAF: CMS Recon Bot detected||MVN:REQUEST_FILENAME||T:APACHE||MV:/xmlrpc.php||RM:GET"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Message: Warning. Operator GT matched 0 at ARGS. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "529"] [id "77317945"] [msg "IM360 WAF: Really Simple Discovery to xmlrpc||MVN:ARGS||MV:1||T:APACHE||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "xmlrpc.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "290"] [id "77141064"] [msg "IM360 WAF: CMS Recon Bot detected||MVN:REQUEST_FILENAME||T:APACHE||MV:/xmlrpc.php||RM:GET"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "ajutam.ro"] [uri "/xmlrpc.php"] [unique_id "apTYRNmUuou1H8H2UKW@GQAAAM4"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Operator GT matched 0 at ARGS. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "529"] [id "77317945"] [msg "IM360 WAF: Really Simple Discovery to xmlrpc||MVN:ARGS||MV:1||T:APACHE||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "ajutam.ro"] [uri "/xmlrpc.php"] [unique_id "apTYRNmUuou1H8H2UKW@GQAAAM4"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ajutam.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788139588746104 262972 (- - -) Stopwatch2: 1788139588746104 262972; combined=3456, p1=206, p2=3083, p3=107, p4=8, p5=52, sr=76, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --854be211-Z-- --a722263d-A-- [31/Aug/2026:04:26:37.583403 +0300] apTYTdmUuou1H8H2UKW@IgAAAMk 216.73.217.35 45808 127.0.0.1 7081 --a722263d-B-- GET /img/ufo_fm.php HTTP/1.1 Host: ihelp.ro X-Real-IP: 216.73.217.35 X-Accel-Internal: /internal-nginx-static-location accept: */* user-agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com) accept-encoding: gzip, br, zstd, deflate --a722263d-F-- HTTP/1.1 200 OK X-Powered-By: PHP/8.1.34 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --a722263d-H-- Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo_fm.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo_fm.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo_fm.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "ihelp.ro"] [uri "/img/ufo_fm.php"] [unique_id "apTYTdmUuou1H8H2UKW@IgAAAMk"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo_fm.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] [hostname "ihelp.ro"] [uri "/img/ufo_fm.php"] [unique_id "apTYTdmUuou1H8H2UKW@IgAAAMk"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788139597529008 54458 (- - -) Stopwatch2: 1788139597529008 54458; combined=35584, p1=209, p2=35298, p3=0, p4=0, p5=76, sr=76, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "DETECTION_ONLY" --a722263d-Z-- --7140f16d-A-- [31/Aug/2026:04:26:42.025410 +0300] apTYUX7glkZrdsSdRApHMAAAAI0 216.73.217.35 45878 127.0.0.1 7081 --7140f16d-B-- GET /img/ufo19b_6243.php HTTP/1.1 Host: ihelp.ro X-Real-IP: 216.73.217.35 X-Accel-Internal: /internal-nginx-static-location accept: */* user-agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com) accept-encoding: gzip, br, zstd, deflate --7140f16d-F-- HTTP/1.1 200 OK X-Powered-By: PHP/8.1.34 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --7140f16d-H-- Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19b_6243.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19b_6243.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19b_6243.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "ihelp.ro"] [uri "/img/ufo19b_6243.php"] [unique_id "apTYUX7glkZrdsSdRApHMAAAAI0"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19b_6243.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] [hostname "ihelp.ro"] [uri "/img/ufo19b_6243.php"] [unique_id "apTYUX7glkZrdsSdRApHMAAAAI0"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788139601991037 34418 (- - -) Stopwatch2: 1788139601991037 34418; combined=32238, p1=241, p2=31949, p3=0, p4=0, p5=47, sr=105, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "DETECTION_ONLY" --7140f16d-Z-- --ecaa8622-A-- [31/Aug/2026:04:27:30.391857 +0300] apTYgtmUuou1H8H2UKW@LwAAAMo 216.73.217.35 58106 127.0.0.1 7081 --ecaa8622-B-- GET /img/ufo19c_20960.php HTTP/1.1 Host: ihelp.ro X-Real-IP: 216.73.217.35 X-Accel-Internal: /internal-nginx-static-location accept: */* user-agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com) accept-encoding: gzip, br, zstd, deflate --ecaa8622-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.1.34 X-DEBUGKIT-ID: b1af37c5-45e7-4aa1-8a6e-7aaa11de5adf Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --ecaa8622-H-- Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19c_20960.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19c_20960.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19c_20960.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "ihelp.ro"] [uri "/img/ufo19c_20960.php"] [unique_id "apTYgtmUuou1H8H2UKW@LwAAAMo"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19c_20960.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] [hostname "ihelp.ro"] [uri "/img/ufo19c_20960.php"] [unique_id "apTYgtmUuou1H8H2UKW@LwAAAMo"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788139650172543 219383 (- - -) Stopwatch2: 1788139650172543 219383; combined=33329, p1=252, p2=32961, p3=0, p4=0, p5=116, sr=96, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "DETECTION_ONLY" --ecaa8622-Z-- --f58f7b59-A-- [31/Aug/2026:04:27:30.425802 +0300] apTYgifaLSuAj0yzdueSFwAAABI 216.73.217.35 58118 127.0.0.1 7081 --f58f7b59-B-- GET /img/wso_ufo19.php HTTP/1.1 Host: ihelp.ro X-Real-IP: 216.73.217.35 X-Accel-Internal: /internal-nginx-static-location accept: */* user-agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com) accept-encoding: gzip, br, zstd, deflate --f58f7b59-F-- HTTP/1.1 200 OK X-Powered-By: PHP/8.1.34 Set-Cookie: 646109d53af43c125a937b56d9f339f0key=fac378ac3b3d3886829021b3309d4fd1 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --f58f7b59-H-- Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/wso_ufo19.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/wso_ufo19.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/wso_ufo19.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "ihelp.ro"] [uri "/img/wso_ufo19.php"] [unique_id "apTYgifaLSuAj0yzdueSFwAAABI"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/wso_ufo19.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] [hostname "ihelp.ro"] [uri "/img/wso_ufo19.php"] [unique_id "apTYgifaLSuAj0yzdueSFwAAABI"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788139650384706 41143 (- - -) Stopwatch2: 1788139650384706 41143; combined=32055, p1=231, p2=31760, p3=0, p4=0, p5=63, sr=90, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "DETECTION_ONLY" --f58f7b59-Z-- --29e80a3f-A-- [31/Aug/2026:04:28:29.968365 +0300] apTYvX7glkZrdsSdRApHPAAAAIs 216.73.217.35 43546 127.0.0.1 7081 --29e80a3f-B-- GET /img/ufo19_20982.php HTTP/1.1 Host: ihelp.ro X-Real-IP: 216.73.217.35 X-Accel-Internal: /internal-nginx-static-location accept: */* user-agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com) accept-encoding: gzip, br, zstd, deflate --29e80a3f-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.1.34 X-DEBUGKIT-ID: c3c26b04-0f45-43b9-9708-0f7e4d2dc127 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --29e80a3f-H-- Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19_20982.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19_20982.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19_20982.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "ihelp.ro"] [uri "/img/ufo19_20982.php"] [unique_id "apTYvX7glkZrdsSdRApHPAAAAIs"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19_20982.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] [hostname "ihelp.ro"] [uri "/img/ufo19_20982.php"] [unique_id "apTYvX7glkZrdsSdRApHPAAAAIs"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788139709702642 265775 (- - -) Stopwatch2: 1788139709702642 265775; combined=34921, p1=222, p2=34628, p3=0, p4=0, p5=71, sr=84, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "DETECTION_ONLY" --29e80a3f-Z-- --d0b8c902-A-- [31/Aug/2026:04:30:40.728783 +0300] apTZQNmUuou1H8H2UKW@PwAAAM0 120.133.60.156 58146 127.0.0.1 7081 --d0b8c902-B-- POST /wp-login.php HTTP/1.1 Host: axapres.ro X-Real-IP: 120.133.60.156 X-Accel-Internal: /internal-nginx-static-location Content-Length: 110 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8 Accept-Language: en-US,en;q=0.5 Content-Type: application/x-www-form-urlencoded Cookie: wordpress_test_cookie=WP+Cookie+check Origin: https://axapres.ro Referer: https://axapres.ro/wp-login.php --d0b8c902-F-- HTTP/1.1 403 Forbidden Content-Length: 199 Content-Type: text/html; charset=iso-8859-1 --d0b8c902-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:04-30.120.133.60.156"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Apache-Handler: proxy:unix:/var/www/vhosts/system/axapres.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788139840668086 60755 (- - -) Stopwatch2: 1788139840668086 60755; combined=59641, p1=324, p2=58588, p3=0, p4=0, p5=522, sr=102, sw=207, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --d0b8c902-Z-- --2d6c6e20-A-- [31/Aug/2026:04:31:28.347937 +0300] apTZcNmUuou1H8H2UKW@QwAAANc 43.156.13.166 55200 127.0.0.1 7081 --2d6c6e20-B-- POST /wp-login.php HTTP/1.1 Host: axapres.ro X-Real-IP: 43.156.13.166 X-Accel-Internal: /internal-nginx-static-location Content-Length: 104 Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.36 Edg/142.0.0.0 Accept-Encoding: gzip, deflate Accept: */* Cookie: wordpress_test_cookie=WP+Cookie+check --2d6c6e20-F-- HTTP/1.1 403 Forbidden Content-Length: 199 Content-Type: text/html; charset=iso-8859-1 --2d6c6e20-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:04-31.43.156.13.166"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Apache-Handler: proxy:unix:/var/www/vhosts/system/axapres.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788139888286034 62057 (- - -) Stopwatch2: 1788139888286034 62057; combined=60357, p1=423, p2=58533, p3=0, p4=0, p5=1022, sr=152, sw=379, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --2d6c6e20-Z-- --a43cbc2c-A-- [31/Aug/2026:04:32:01.848761 +0300] apTZkSfaLSuAj0yzdueSGQAAAAA 207.154.219.81 56588 127.0.0.1 7081 --a43cbc2c-B-- GET /?author=1 HTTP/1.1 Host: ajutam.ro X-Real-IP: 207.154.219.81 X-Accel-Internal: /internal-nginx-static-location Accept: */* User-Agent: Mozilla/5.0 Accept-Encoding: gzip,deflate --a43cbc2c-F-- HTTP/1.1 301 Moved Permanently X-Powered-By: PHP/7.3.33 X-Redirect-By: WordPress Location: https://ajutam.ro/author/admin/ Content-Length: 0 Content-Type: text/html; charset=UTF-8 --a43cbc2c-E-- --a43cbc2c-H-- Message: Operator GE matched 1 at ARGS:author. [file "/etc/httpd/conf/modsecurity.d/rules/custom/007_i360_4_wordpress.conf"] [line "59"] [id "77140876"] [msg "IM360 WAF: Track WordPress users enumeration||MVN:ARGS:author||MV:1||T:APACHE||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ajutam.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788139921325196 523635 (- - -) Stopwatch2: 1788139921325196 523635; combined=5796, p1=620, p2=4969, p3=144, p4=13, p5=49, sr=221, sw=1, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --a43cbc2c-Z-- --1cd0f101-A-- [31/Aug/2026:04:32:02.418495 +0300] apTZkdmUuou1H8H2UKW@RgAAAME 207.154.219.81 56598 127.0.0.1 7081 --1cd0f101-B-- GET /?author=2 HTTP/1.1 Host: ajutam.ro X-Real-IP: 207.154.219.81 X-Accel-Internal: /internal-nginx-static-location Accept: */* User-Agent: Mozilla/5.0 Accept-Encoding: gzip,deflate --1cd0f101-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/7.3.33 Expires: Wed, 11 Jan 1984 05:00:00 GMT Cache-Control: no-cache, must-revalidate, max-age=0, no-store, private Link: <https://ajutam.ro/wp-json/>; rel="https://api.w.org/" X-TEC-API-VERSION: v1 X-TEC-API-ROOT: https://ajutam.ro/wp-json/tribe/events/v1/ X-TEC-API-ORIGIN: https://ajutam.ro Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --1cd0f101-E-- --1cd0f101-H-- Message: Operator GE matched 1 at ARGS:author. [file "/etc/httpd/conf/modsecurity.d/rules/custom/007_i360_4_wordpress.conf"] [line "59"] [id "77140876"] [msg "IM360 WAF: Track WordPress users enumeration||MVN:ARGS:author||MV:2||T:APACHE||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ajutam.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788139921885045 533628 (- - -) Stopwatch2: 1788139921885045 533628; combined=5354, p1=336, p2=4786, p3=174, p4=13, p5=45, sr=150, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --1cd0f101-Z-- --a23cf107-A-- [31/Aug/2026:04:37:14.207976 +0300] apTaydmUuou1H8H2UKW@WwAAANM 137.184.233.53 55776 127.0.0.1 7081 --a23cf107-B-- GET /?author=1 HTTP/1.1 Host: chania24.taxi X-Real-IP: 137.184.233.53 Accept: */* User-Agent: Mozilla/5.0 Accept-Encoding: gzip,deflate --a23cf107-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/7.4.33 Expires: Wed, 11 Jan 1984 05:00:00 GMT Cache-Control: no-cache, must-revalidate, max-age=0 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --a23cf107-E-- --a23cf107-H-- Message: Operator GE matched 1 at ARGS:author. [file "/etc/httpd/conf/modsecurity.d/rules/custom/007_i360_4_wordpress.conf"] [line "59"] [id "77140876"] [msg "IM360 WAF: Track WordPress users enumeration||MVN:ARGS:author||MV:1||T:APACHE||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Apache-Handler: proxy:unix:/var/www/vhosts/system/chania24.taxi/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788140233624027 584021 (- - -) Stopwatch2: 1788140233624027 584021; combined=9784, p1=957, p2=8671, p3=96, p4=21, p5=39, sr=98, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --a23cf107-Z-- --a9d8211b-A-- [31/Aug/2026:04:42:02.408404 +0300] apTb6tmUuou1H8H2UKW@dAAAAM8 163.61.60.30 52118 127.0.0.1 7081 --a9d8211b-B-- POST /wp-login.php HTTP/1.1 Host: axapres.ro X-Real-IP: 163.61.60.30 X-Accel-Internal: /internal-nginx-static-location Content-Length: 117 Cookie: wordpress_test_cookie=WP+Cookie+check Content-Type: application/x-www-form-urlencoded Accept-Encoding: gzip, deflate Accept: */* User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.36 Edg/142.0.0.0 --a9d8211b-F-- HTTP/1.1 403 Forbidden Content-Length: 199 Content-Type: text/html; charset=iso-8859-1 --a9d8211b-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:04-42.163.61.60.30"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Apache-Handler: proxy:unix:/var/www/vhosts/system/axapres.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788140522344297 64181 (- - -) Stopwatch2: 1788140522344297 64181; combined=62659, p1=403, p2=61315, p3=0, p4=0, p5=696, sr=139, sw=245, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --a9d8211b-Z-- --6515330e-A-- [31/Aug/2026:04:43:17.898857 +0300] apTcNdmUuou1H8H2UKW@dgAAANg 59.125.102.226 34186 127.0.0.1 7081 --6515330e-B-- POST /wp-login.php HTTP/1.1 Host: axapres.ro X-Real-IP: 59.125.102.226 X-Accel-Internal: /internal-nginx-static-location Content-Length: 126 Accept-Encoding: gzip, deflate Content-Type: application/x-www-form-urlencoded Accept: */* User-Agent: Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.36 Edg/142.0.0.0 Cookie: wordpress_test_cookie=WP+Cookie+check --6515330e-F-- HTTP/1.1 403 Forbidden Content-Length: 199 Content-Type: text/html; charset=iso-8859-1 --6515330e-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:04-43.59.125.102.226"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Apache-Handler: proxy:unix:/var/www/vhosts/system/axapres.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788140597829870 69103 (- - -) Stopwatch2: 1788140597829870 69103; combined=59973, p1=1374, p2=57768, p3=0, p4=0, p5=559, sr=633, sw=272, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --6515330e-Z-- --02b7aa2e-A-- [31/Aug/2026:04:49:57.989304 +0300] apTdxdmUuou1H8H2UKW@mQAAAM4 137.184.225.216 46128 127.0.0.1 7081 --02b7aa2e-B-- POST /wp-login.php HTTP/1.1 Host: axapres.ro X-Real-IP: 137.184.225.216 X-Accel-Internal: /internal-nginx-static-location Content-Length: 108 Accept-Encoding: gzip, deflate Accept: */* User-Agent: Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/140.0.0.0 Safari/537.36 Edg/140.0.0.0 Cookie: wordpress_test_cookie=WP+Cookie+check Content-Type: application/x-www-form-urlencoded --02b7aa2e-F-- HTTP/1.1 403 Forbidden Content-Length: 199 Content-Type: text/html; charset=iso-8859-1 --02b7aa2e-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:04-49.137.184.225.216"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Apache-Handler: proxy:unix:/var/www/vhosts/system/axapres.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788140997929755 59615 (- - -) Stopwatch2: 1788140997929755 59615; combined=57486, p1=443, p2=56401, p3=0, p4=0, p5=460, sr=189, sw=182, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --02b7aa2e-Z-- --c959a14c-A-- [31/Aug/2026:05:13:04.903603 +0300] apTjMH7glkZrdsSdRApH0QAAAII 168.144.111.201 53912 127.0.0.1 7081 --c959a14c-B-- POST /wp-json/batch/v1 HTTP/1.1 Host: chania24.taxi X-Real-IP: 168.144.111.201 Content-Length: 15 sec-ch-ua: "Not_A Brand";v="8", "Chromium";v="120", "Google Chrome";v="120" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "macOS" Upgrade-Insecure-Requests: 1 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 Chrome/119.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8 Sec-Fetch-Site: none Sec-Fetch-Mode: navigate Sec-Fetch-User: ?1 Sec-Fetch-Dest: document Accept-Encoding: gzip, deflate, br Accept-Language: id-ID,id;q=0.9,en-US;q=0.8,en;q=0.7 Cache-Control: max-age=0 DNT: 1 Content-Type: application/json --c959a14c-F-- HTTP/1.1 403 Forbidden X-Powered-By: PHP/7.4.33 Pragma: no-cache Cache-Control: no-cache, must-revalidate, private, max-age=0 Expires: Sat, 26 Jul 1997 05:00:00 GMT Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --c959a14c-H-- Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Apache-Handler: proxy:unix:/var/www/vhosts/system/chania24.taxi/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788142384794114 109625 (- - -) Stopwatch2: 1788142384794114 109625; combined=6654, p1=311, p2=5966, p3=0, p4=0, p5=377, sr=131, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --c959a14c-Z-- --ac894c49-A-- [31/Aug/2026:05:13:05.187346 +0300] apTjMdmUuou1H8H2UKW-dgAAAMM 168.144.111.201 53928 127.0.0.1 7081 --ac894c49-B-- POST /?rest_route=/batch/v1 HTTP/1.1 Host: chania24.taxi X-Real-IP: 168.144.111.201 Content-Length: 16 sec-ch-ua: "Not_A Brand";v="8", "Chromium";v="120", "Google Chrome";v="120" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "macOS" Upgrade-Insecure-Requests: 1 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/121.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8 Sec-Fetch-Site: none Sec-Fetch-Mode: navigate Sec-Fetch-User: ?1 Sec-Fetch-Dest: document Accept-Encoding: gzip, deflate, br Accept-Language: id-ID,id;q=0.9,en-US;q=0.8,en;q=0.7 Cache-Control: max-age=0 DNT: 1 Content-Type: application/json --ac894c49-F-- HTTP/1.1 403 Forbidden X-Powered-By: PHP/7.4.33 Pragma: no-cache Cache-Control: no-cache, must-revalidate, private, max-age=0 Expires: Sat, 26 Jul 1997 05:00:00 GMT Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --ac894c49-E-- --ac894c49-H-- Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G:rest_route=/batch/v1& P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Apache-Handler: proxy:unix:/var/www/vhosts/system/chania24.taxi/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788142385099814 87621 (- - -) Stopwatch2: 1788142385099814 87621; combined=5538, p1=521, p2=4521, p3=181, p4=23, p5=291, sr=316, sw=1, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --ac894c49-Z-- --d5bd142f-A-- [31/Aug/2026:05:20:55.096407 +0300] apTlB9mUuou1H8H2UKW-qwAAAMo 23.94.77.36 53756 127.0.0.1 7081 --d5bd142f-B-- GET /american-humane-association/ HTTP/1.1 Host: ajutam.ro X-Real-IP: 23.94.77.36 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html) Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7 Accept-Language: en-US,en;q=0.9 Accept-Encoding: gzip, deflate, br Referer: http://ajutam.ro/american-humane-association/ --d5bd142f-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --d5bd142f-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "81"] [id "33311"] [msg "IM360 WAF: Found crawler not in whitelist||T:APACHE||User-Agent:Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)||MV:05-20.23.94.77.36"] [severity "CRITICAL"] [tag "service_i360"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788142855061911 34579 (- - -) Stopwatch2: 1788142855061911 34579; combined=28428, p1=352, p2=27455, p3=0, p4=0, p5=620, sr=117, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --d5bd142f-Z-- --7140f16d-A-- [31/Aug/2026:05:20:57.331289 +0300] apTlCSfaLSuAj0yzdueSVwAAABI 191.101.110.76 46040 127.0.0.1 7081 --7140f16d-B-- GET /american-humane-association/ HTTP/1.1 Host: ajutam.ro X-Real-IP: 191.101.110.76 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html) Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7 Accept-Language: en-US,en;q=0.9 Accept-Encoding: gzip, deflate, br --7140f16d-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --7140f16d-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "81"] [id "33311"] [msg "IM360 WAF: Found crawler not in whitelist||T:APACHE||User-Agent:Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)||MV:05-20.191.101.110.76"] [severity "CRITICAL"] [tag "service_i360"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788142857299179 32191 (- - -) Stopwatch2: 1788142857299179 32191; combined=30471, p1=203, p2=29994, p3=0, p4=0, p5=274, sr=83, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --7140f16d-Z-- --76e14709-A-- [31/Aug/2026:05:20:59.413038 +0300] apTlC9mUuou1H8H2UKW-rAAAANE 172.245.60.137 46056 127.0.0.1 7081 --76e14709-B-- GET /american-humane-association/ HTTP/1.1 Host: ajutam.ro X-Real-IP: 172.245.60.137 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html) Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7 Accept-Language: en-US,en;q=0.9 Accept-Encoding: gzip, deflate, br --76e14709-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --76e14709-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "81"] [id "33311"] [msg "IM360 WAF: Found crawler not in whitelist||T:APACHE||User-Agent:Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)||MV:05-20.172.245.60.137"] [severity "CRITICAL"] [tag "service_i360"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788142859378974 34141 (- - -) Stopwatch2: 1788142859378974 34141; combined=31124, p1=351, p2=30401, p3=0, p4=0, p5=371, sr=149, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --76e14709-Z-- --99b5b32b-A-- [31/Aug/2026:05:21:01.635949 +0300] apTlDdmUuou1H8H2UKW-rQAAAMI 172.245.60.182 46066 127.0.0.1 7081 --99b5b32b-B-- GET /american-humane-association/ HTTP/1.1 Host: ajutam.ro X-Real-IP: 172.245.60.182 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html) Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7 Accept-Language: en-US,en;q=0.9 Accept-Encoding: gzip, deflate, br --99b5b32b-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --99b5b32b-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "81"] [id "33311"] [msg "IM360 WAF: Found crawler not in whitelist||T:APACHE||User-Agent:Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)||MV:05-21.172.245.60.182"] [severity "CRITICAL"] [tag "service_i360"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788142861599538 36561 (- - -) Stopwatch2: 1788142861599538 36561; combined=33943, p1=901, p2=28095, p3=0, p4=0, p5=4947, sr=123, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --99b5b32b-Z-- --5155e508-A-- [31/Aug/2026:05:23:15.755773 +0300] apTlk37glkZrdsSdRApH6QAAAIM 23.94.77.36 44080 127.0.0.1 7081 --5155e508-B-- GET /american-humane-association/ HTTP/1.1 Host: ajutam.ro X-Real-IP: 23.94.77.36 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html) Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7 Accept-Language: en-US,en;q=0.9 Accept-Encoding: gzip, deflate, br Referer: http://ajutam.ro/american-humane-association/ --5155e508-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --5155e508-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "81"] [id "33311"] [msg "IM360 WAF: Found crawler not in whitelist||T:APACHE||User-Agent:Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)||MV:05-23.23.94.77.36"] [severity "CRITICAL"] [tag "service_i360"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788142995723174 32676 (- - -) Stopwatch2: 1788142995723174 32676; combined=30498, p1=940, p2=29236, p3=0, p4=0, p5=322, sr=166, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --5155e508-Z-- --6ca34342-A-- [31/Aug/2026:05:23:17.718481 +0300] apTlldmUuou1H8H2UKW-tAAAAME 198.46.222.253 44094 127.0.0.1 7081 --6ca34342-B-- GET /american-humane-association/ HTTP/1.1 Host: ajutam.ro X-Real-IP: 198.46.222.253 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html) Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7 Accept-Language: en-US,en;q=0.9 Accept-Encoding: gzip, deflate, br --6ca34342-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --6ca34342-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "81"] [id "33311"] [msg "IM360 WAF: Found crawler not in whitelist||T:APACHE||User-Agent:Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)||MV:05-23.198.46.222.253"] [severity "CRITICAL"] [tag "service_i360"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788142997685518 33028 (- - -) Stopwatch2: 1788142997685518 33028; combined=31152, p1=703, p2=30148, p3=0, p4=0, p5=301, sr=135, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --6ca34342-Z-- --d9179761-A-- [31/Aug/2026:05:23:19.926164 +0300] apTll9mUuou1H8H2UKW-tQAAAMM 191.101.110.188 44110 127.0.0.1 7081 --d9179761-B-- GET /american-humane-association/ HTTP/1.1 Host: ajutam.ro X-Real-IP: 191.101.110.188 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html) Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7 Accept-Language: en-US,en;q=0.9 Accept-Encoding: gzip, deflate, br --d9179761-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --d9179761-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "81"] [id "33311"] [msg "IM360 WAF: Found crawler not in whitelist||T:APACHE||User-Agent:Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)||MV:05-23.191.101.110.188"] [severity "CRITICAL"] [tag "service_i360"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788142999892198 34058 (- - -) Stopwatch2: 1788142999892198 34058; combined=30824, p1=503, p2=29932, p3=0, p4=0, p5=388, sr=233, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --d9179761-Z-- --3f9d4850-A-- [31/Aug/2026:05:23:22.078530 +0300] apTlmtmUuou1H8H2UKW-tgAAAMc 191.101.110.60 44122 127.0.0.1 7081 --3f9d4850-B-- GET /american-humane-association/ HTTP/1.1 Host: ajutam.ro X-Real-IP: 191.101.110.60 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html) Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7 Accept-Language: en-US,en;q=0.9 Accept-Encoding: gzip, deflate, br --3f9d4850-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --3f9d4850-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "81"] [id "33311"] [msg "IM360 WAF: Found crawler not in whitelist||T:APACHE||User-Agent:Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)||MV:05-23.191.101.110.60"] [severity "CRITICAL"] [tag "service_i360"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788143002046367 32234 (- - -) Stopwatch2: 1788143002046367 32234; combined=29508, p1=549, p2=28606, p3=0, p4=0, p5=352, sr=252, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --3f9d4850-Z-- --78ba2517-A-- [31/Aug/2026:05:36:15.636204 +0300] apTon37glkZrdsSdRApIJQAAAJI 207.154.219.81 58222 127.0.0.1 7081 --78ba2517-B-- POST /wp-login.php HTTP/1.1 Host: ajutam.ro X-Real-IP: 207.154.219.81 X-Accel-Internal: /internal-nginx-static-location Content-Length: 105 Accept: */* User-Agent: Mozilla/5.0 Content-Type: application/x-www-form-urlencoded Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818 --78ba2517-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --78ba2517-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:05-36.207.154.219.81"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788143775573307 62953 (- - -) Stopwatch2: 1788143775573307 62953; combined=61208, p1=461, p2=60158, p3=0, p4=0, p5=445, sr=191, sw=144, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --78ba2517-Z-- --eadd4674-A-- [31/Aug/2026:05:36:17.160029 +0300] apToodmUuou1H8H2UKXAIgAAANI 35.254.196.10 58238 127.0.0.1 7081 --eadd4674-B-- GET /.git/config HTTP/1.1 Host: breveleyendatequila.com X-Real-IP: 35.254.196.10 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 Accept: */* --eadd4674-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --eadd4674-E-- --eadd4674-H-- Message: Warning. Matched phrase "/.git/config" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.git/config||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Matched phrase "/.git/config" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.git/config||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Message: Warning. String match "/.git/" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "656"] [id "77318034"] [msg "IM360 WAF: Blocked access to git folder||T:APACHE||MV:/.git/config||"] [severity "NOTICE"] [tag "service_i360custom"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "/.git/config" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.git/config||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "breveleyendatequila.com"] [uri "/.git/config"] [unique_id "apToodmUuou1H8H2UKXAIgAAANI"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "/.git/config" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.git/config||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "breveleyendatequila.com"] [uri "/.git/config"] [unique_id "apToodmUuou1H8H2UKXAIgAAANI"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.git/" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "656"] [id "77318034"] [msg "IM360 WAF: Blocked access to git folder||T:APACHE||MV:/.git/config||"] [severity "NOTICE"] [tag "service_i360custom"] [hostname "breveleyendatequila.com"] [uri "/.git/config"] [unique_id "apToodmUuou1H8H2UKXAIgAAANI"] Stopwatch: 1788143777122473 37602 (- - -) Stopwatch2: 1788143777122473 37602; combined=36081, p1=344, p2=35560, p3=111, p4=8, p5=58, sr=105, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --eadd4674-Z-- --36ef4919-A-- [31/Aug/2026:05:38:38.149143 +0300] apTpLtmUuou1H8H2UKXAKQAAAMs 207.154.219.81 45162 127.0.0.1 7081 --36ef4919-B-- POST /wp-login.php HTTP/1.1 Host: ajutam.ro X-Real-IP: 207.154.219.81 X-Accel-Internal: /internal-nginx-static-location Content-Length: 108 Accept: */* User-Agent: Mozilla/5.0 Content-Type: application/x-www-form-urlencoded Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818 --36ef4919-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --36ef4919-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "42"] [id "33302"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:1"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788143918146738 2492 (- - -) Stopwatch2: 1788143918146738 2492; combined=713, p1=389, p2=95, p3=0, p4=0, p5=229, sr=111, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --36ef4919-Z-- --67a23e1c-A-- [31/Aug/2026:05:41:44.547918 +0300] apTp6NmUuou1H8H2UKXALwAAANI 207.154.219.81 56512 127.0.0.1 7081 --67a23e1c-B-- POST /wp-login.php HTTP/1.1 Host: ajutam.ro X-Real-IP: 207.154.219.81 X-Accel-Internal: /internal-nginx-static-location Content-Length: 108 Accept: */* User-Agent: Mozilla/5.0 Content-Type: application/x-www-form-urlencoded Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818 --67a23e1c-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --67a23e1c-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:05-41.207.154.219.81"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788144104480666 67392 (- - -) Stopwatch2: 1788144104480666 67392; combined=61003, p1=275, p2=59322, p3=0, p4=0, p5=1220, sr=115, sw=186, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --67a23e1c-Z-- --f58f7b59-A-- [31/Aug/2026:05:44:30.282253 +0300] apTqjm7fDIutYTwcPOkZtAAAAFY 138.197.193.77 48556 127.0.0.1 7081 --f58f7b59-B-- GET /?author=1 HTTP/1.1 Host: ajutam.ro X-Real-IP: 138.197.193.77 X-Accel-Internal: /internal-nginx-static-location Accept: */* User-Agent: Mozilla/5.0 Accept-Encoding: gzip,deflate --f58f7b59-F-- HTTP/1.1 301 Moved Permanently X-Powered-By: PHP/7.3.33 X-Redirect-By: WordPress Location: https://ajutam.ro/author/admin/ Content-Length: 0 Content-Type: text/html; charset=UTF-8 --f58f7b59-E-- --f58f7b59-H-- Message: Operator GE matched 1 at ARGS:author. [file "/etc/httpd/conf/modsecurity.d/rules/custom/007_i360_4_wordpress.conf"] [line "59"] [id "77140876"] [msg "IM360 WAF: Track WordPress users enumeration||MVN:ARGS:author||MV:1||T:APACHE||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ajutam.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788144270007605 274701 (- - -) Stopwatch2: 1788144270007605 274701; combined=3452, p1=277, p2=3042, p3=93, p4=8, p5=32, sr=105, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --f58f7b59-Z-- --e8f2fd53-A-- [31/Aug/2026:05:44:30.831609 +0300] apTqjtmUuou1H8H2UKXANwAAAMQ 138.197.193.77 48558 127.0.0.1 7081 --e8f2fd53-B-- GET /?author=2 HTTP/1.1 Host: ajutam.ro X-Real-IP: 138.197.193.77 X-Accel-Internal: /internal-nginx-static-location Accept: */* User-Agent: Mozilla/5.0 Accept-Encoding: gzip,deflate --e8f2fd53-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/7.3.33 Expires: Wed, 11 Jan 1984 05:00:00 GMT Cache-Control: no-cache, must-revalidate, max-age=0, no-store, private Link: <https://ajutam.ro/wp-json/>; rel="https://api.w.org/" X-TEC-API-VERSION: v1 X-TEC-API-ROOT: https://ajutam.ro/wp-json/tribe/events/v1/ X-TEC-API-ORIGIN: https://ajutam.ro Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --e8f2fd53-E-- --e8f2fd53-H-- Message: Operator GE matched 1 at ARGS:author. [file "/etc/httpd/conf/modsecurity.d/rules/custom/007_i360_4_wordpress.conf"] [line "59"] [id "77140876"] [msg "IM360 WAF: Track WordPress users enumeration||MVN:ARGS:author||MV:2||T:APACHE||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ajutam.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788144270480910 350830 (- - -) Stopwatch2: 1788144270480910 350830; combined=3307, p1=247, p2=2869, p3=141, p4=11, p5=38, sr=106, sw=1, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --e8f2fd53-Z-- --29e80a3f-A-- [31/Aug/2026:05:47:47.636727 +0300] apTrUyfaLSuAj0yzdueSbgAAABg 207.154.219.81 33108 127.0.0.1 7081 --29e80a3f-B-- POST /wp-login.php HTTP/1.1 Host: ajutam.ro X-Real-IP: 207.154.219.81 X-Accel-Internal: /internal-nginx-static-location Content-Length: 110 Accept: */* User-Agent: Mozilla/5.0 Content-Type: application/x-www-form-urlencoded Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818 --29e80a3f-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --29e80a3f-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:05-47.207.154.219.81"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788144467563740 73081 (- - -) Stopwatch2: 1788144467563740 73081; combined=65983, p1=471, p2=64003, p3=0, p4=0, p5=1110, sr=196, sw=399, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --29e80a3f-Z-- --f05c8c30-A-- [31/Aug/2026:05:53:41.323477 +0300] apTstdmUuou1H8H2UKXAngAAAMQ 207.154.219.81 40972 127.0.0.1 7081 --f05c8c30-B-- POST /wp-login.php HTTP/1.1 Host: ajutam.ro X-Real-IP: 207.154.219.81 X-Accel-Internal: /internal-nginx-static-location Content-Length: 111 Accept: */* User-Agent: Mozilla/5.0 Content-Type: application/x-www-form-urlencoded Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818 --f05c8c30-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --f05c8c30-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:05-53.207.154.219.81"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788144821261955 61784 (- - -) Stopwatch2: 1788144821261955 61784; combined=60219, p1=272, p2=58828, p3=0, p4=0, p5=878, sr=88, sw=241, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --f05c8c30-Z-- --e0fb7e1c-A-- [31/Aug/2026:05:59:45.339900 +0300] apTuIdmUuou1H8H2UKXArgAAAMo 207.154.219.81 41674 127.0.0.1 7081 --e0fb7e1c-B-- POST /wp-login.php HTTP/1.1 Host: ajutam.ro X-Real-IP: 207.154.219.81 X-Accel-Internal: /internal-nginx-static-location Content-Length: 108 Accept: */* User-Agent: Mozilla/5.0 Content-Type: application/x-www-form-urlencoded Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818 --e0fb7e1c-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --e0fb7e1c-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:05-59.207.154.219.81"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788145185280305 59700 (- - -) Stopwatch2: 1788145185280305 59700; combined=58222, p1=316, p2=57354, p3=0, p4=0, p5=422, sr=94, sw=130, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --e0fb7e1c-Z-- --6c43d622-A-- [31/Aug/2026:06:03:49.932688 +0300] apTvFX7glkZrdsSdRApIZgAAAI4 35.81.82.181 59344 127.0.0.1 7081 --6c43d622-B-- GET /img/ufo_fm.php HTTP/1.1 Host: ihelp.ro X-Real-IP: 35.81.82.181 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: https://ihelp.ro/ Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cookie: csrfToken=mPvE2njAl36rBABWojKSTDJjOWZkNjQ2MTA5NmVkM2IzY2QxMmFmM2Q3YjE2YjJiMTE4ZjY5ZWM%3D --6c43d622-F-- HTTP/1.1 200 OK X-Powered-By: PHP/8.1.34 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --6c43d622-H-- Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo_fm.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo_fm.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo_fm.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "ihelp.ro"] [uri "/img/ufo_fm.php"] [unique_id "apTvFX7glkZrdsSdRApIZgAAAI4"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo_fm.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] [hostname "ihelp.ro"] [uri "/img/ufo_fm.php"] [unique_id "apTvFX7glkZrdsSdRApIZgAAAI4"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788145429918353 14396 (- - -) Stopwatch2: 1788145429918353 14396; combined=8145, p1=285, p2=7792, p3=0, p4=0, p5=68, sr=103, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "DETECTION_ONLY" --6c43d622-Z-- --21438830-A-- [31/Aug/2026:06:03:50.375794 +0300] apTvFtmUuou1H8H2UKXAxQAAAMs 35.81.82.181 59440 127.0.0.1 7081 --21438830-B-- GET /img/wso_ufo19.php HTTP/1.1 Host: ihelp.ro X-Real-IP: 35.81.82.181 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: https://ihelp.ro/ Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cookie: csrfToken=mPvE2njAl36rBABWojKSTDJjOWZkNjQ2MTA5NmVkM2IzY2QxMmFmM2Q3YjE2YjJiMTE4ZjY5ZWM%3D --21438830-F-- HTTP/1.1 200 OK X-Powered-By: PHP/8.1.34 Set-Cookie: 646109d53af43c125a937b56d9f339f0key=7a804c056f2d36c3c44be5f3d648e096 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --21438830-H-- Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/wso_ufo19.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/wso_ufo19.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/wso_ufo19.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "ihelp.ro"] [uri "/img/wso_ufo19.php"] [unique_id "apTvFtmUuou1H8H2UKXAxQAAAMs"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/wso_ufo19.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] [hostname "ihelp.ro"] [uri "/img/wso_ufo19.php"] [unique_id "apTvFtmUuou1H8H2UKXAxQAAAMs"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788145430368637 7221 (- - -) Stopwatch2: 1788145430368637 7221; combined=4391, p1=214, p2=4117, p3=0, p4=0, p5=59, sr=86, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "DETECTION_ONLY" --21438830-Z-- --c4eb1a14-A-- [31/Aug/2026:06:03:50.422087 +0300] apTvFtmUuou1H8H2UKXAxgAAAMg 35.81.82.181 59454 127.0.0.1 7081 --c4eb1a14-B-- GET /img/ufo19_shell_30207.php HTTP/1.1 Host: ihelp.ro X-Real-IP: 35.81.82.181 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: https://ihelp.ro/ Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cookie: csrfToken=mPvE2njAl36rBABWojKSTDJjOWZkNjQ2MTA5NmVkM2IzY2QxMmFmM2Q3YjE2YjJiMTE4ZjY5ZWM%3D --c4eb1a14-F-- HTTP/1.1 200 OK X-Powered-By: PHP/8.1.34 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --c4eb1a14-H-- Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19_shell_30207.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19_shell_30207.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19_shell_30207.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "ihelp.ro"] [uri "/img/ufo19_shell_30207.php"] [unique_id "apTvFtmUuou1H8H2UKXAxgAAAMg"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19_shell_30207.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] [hostname "ihelp.ro"] [uri "/img/ufo19_shell_30207.php"] [unique_id "apTvFtmUuou1H8H2UKXAxgAAAMg"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788145430415007 7142 (- - -) Stopwatch2: 1788145430415007 7142; combined=4459, p1=225, p2=4176, p3=0, p4=0, p5=57, sr=91, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "DETECTION_ONLY" --c4eb1a14-Z-- --a6dd045b-A-- [31/Aug/2026:06:03:50.725322 +0300] apTvFtmUuou1H8H2UKXAywAAAMo 35.81.82.181 59508 127.0.0.1 7081 --a6dd045b-B-- GET /img/ufo19b_6243.php HTTP/1.1 Host: ihelp.ro X-Real-IP: 35.81.82.181 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: https://ihelp.ro/ Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cookie: 646109d53af43c125a937b56d9f339f0key=7a804c056f2d36c3c44be5f3d648e096; csrfToken=mPvE2njAl36rBABWojKSTDJjOWZkNjQ2MTA5NmVkM2IzY2QxMmFmM2Q3YjE2YjJiMTE4ZjY5ZWM%3D --a6dd045b-F-- HTTP/1.1 200 OK X-Powered-By: PHP/8.1.34 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --a6dd045b-H-- Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19b_6243.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19b_6243.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19b_6243.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "ihelp.ro"] [uri "/img/ufo19b_6243.php"] [unique_id "apTvFtmUuou1H8H2UKXAywAAAMo"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19b_6243.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] [hostname "ihelp.ro"] [uri "/img/ufo19b_6243.php"] [unique_id "apTvFtmUuou1H8H2UKXAywAAAMo"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788145430668079 57329 (- - -) Stopwatch2: 1788145430668079 57329; combined=4616, p1=237, p2=4300, p3=0, p4=0, p5=79, sr=88, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "DETECTION_ONLY" --a6dd045b-Z-- --e4e54d4c-A-- [31/Aug/2026:06:03:50.755389 +0300] apTvFtmUuou1H8H2UKXAxwAAAMA 35.81.82.181 59470 127.0.0.1 7081 --e4e54d4c-B-- GET /img/ufo19c_20960.php HTTP/1.1 Host: ihelp.ro X-Real-IP: 35.81.82.181 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: https://ihelp.ro/ Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cookie: csrfToken=mPvE2njAl36rBABWojKSTDJjOWZkNjQ2MTA5NmVkM2IzY2QxMmFmM2Q3YjE2YjJiMTE4ZjY5ZWM%3D --e4e54d4c-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.1.34 X-DEBUGKIT-ID: 204a8bcc-983e-4457-8c19-cf9124e13b87 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --e4e54d4c-H-- Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19c_20960.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19c_20960.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19c_20960.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "ihelp.ro"] [uri "/img/ufo19c_20960.php"] [unique_id "apTvFtmUuou1H8H2UKXAxwAAAMA"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19c_20960.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] [hostname "ihelp.ro"] [uri "/img/ufo19c_20960.php"] [unique_id "apTvFtmUuou1H8H2UKXAxwAAAMA"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788145430494736 260717 (- - -) Stopwatch2: 1788145430494736 260717; combined=4083, p1=234, p2=3772, p3=0, p4=0, p5=76, sr=90, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "DETECTION_ONLY" --e4e54d4c-Z-- --a43cbc2c-A-- [31/Aug/2026:06:03:50.878066 +0300] apTvFm7fDIutYTwcPOkZzAAAAFM 35.81.82.181 59476 127.0.0.1 7081 --a43cbc2c-B-- GET /img/ufo19p_20539.php HTTP/1.1 Host: ihelp.ro X-Real-IP: 35.81.82.181 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: https://ihelp.ro/ Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cookie: csrfToken=mPvE2njAl36rBABWojKSTDJjOWZkNjQ2MTA5NmVkM2IzY2QxMmFmM2Q3YjE2YjJiMTE4ZjY5ZWM%3D --a43cbc2c-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.1.34 X-DEBUGKIT-ID: 4e11523c-08d4-4c80-a30b-164d0da593ce Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --a43cbc2c-H-- Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19p_20539.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19p_20539.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19p_20539.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "ihelp.ro"] [uri "/img/ufo19p_20539.php"] [unique_id "apTvFm7fDIutYTwcPOkZzAAAAFM"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19p_20539.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] [hostname "ihelp.ro"] [uri "/img/ufo19p_20539.php"] [unique_id "apTvFm7fDIutYTwcPOkZzAAAAFM"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788145430542420 335710 (- - -) Stopwatch2: 1788145430542420 335710; combined=4770, p1=268, p2=4437, p3=0, p4=0, p5=65, sr=104, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "DETECTION_ONLY" --a43cbc2c-Z-- --232cdc54-A-- [31/Aug/2026:06:03:50.961047 +0300] apTvFtmUuou1H8H2UKXAyQAAANM 35.81.82.181 59492 127.0.0.1 7081 --232cdc54-B-- GET /img/ufo19w_831.php HTTP/1.1 Host: ihelp.ro X-Real-IP: 35.81.82.181 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: https://ihelp.ro/ Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cookie: 646109d53af43c125a937b56d9f339f0key=7a804c056f2d36c3c44be5f3d648e096; csrfToken=mPvE2njAl36rBABWojKSTDJjOWZkNjQ2MTA5NmVkM2IzY2QxMmFmM2Q3YjE2YjJiMTE4ZjY5ZWM%3D --232cdc54-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.1.34 X-DEBUGKIT-ID: 5e065ffc-3662-4f2b-baaa-0eefb8f09ef6 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --232cdc54-H-- Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19w_831.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19w_831.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19w_831.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "ihelp.ro"] [uri "/img/ufo19w_831.php"] [unique_id "apTvFtmUuou1H8H2UKXAyQAAANM"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19w_831.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] [hostname "ihelp.ro"] [uri "/img/ufo19w_831.php"] [unique_id "apTvFtmUuou1H8H2UKXAyQAAANM"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788145430554836 406287 (- - -) Stopwatch2: 1788145430554836 406287; combined=4354, p1=204, p2=4084, p3=0, p4=0, p5=66, sr=73, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "DETECTION_ONLY" --232cdc54-Z-- --1f736464-A-- [31/Aug/2026:06:03:51.120054 +0300] apTvFtmUuou1H8H2UKXAzQAAAMY 35.81.82.181 59544 127.0.0.1 7081 --1f736464-B-- GET /img/ufo19_20982.php HTTP/1.1 Host: ihelp.ro X-Real-IP: 35.81.82.181 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: https://ihelp.ro/ Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cookie: 646109d53af43c125a937b56d9f339f0key=7a804c056f2d36c3c44be5f3d648e096; csrfToken=mPvE2njAl36rBABWojKSTDJjOWZkNjQ2MTA5NmVkM2IzY2QxMmFmM2Q3YjE2YjJiMTE4ZjY5ZWM%3D --1f736464-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.1.34 X-DEBUGKIT-ID: 03b3eb98-ecbc-46a5-8666-1e13378b293a Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --1f736464-H-- Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19_20982.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19_20982.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19_20982.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "ihelp.ro"] [uri "/img/ufo19_20982.php"] [unique_id "apTvFtmUuou1H8H2UKXAzQAAAMY"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo19_20982.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] [hostname "ihelp.ro"] [uri "/img/ufo19_20982.php"] [unique_id "apTvFtmUuou1H8H2UKXAzQAAAMY"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788145430906356 213770 (- - -) Stopwatch2: 1788145430906356 213770; combined=4891, p1=281, p2=4487, p3=0, p4=0, p5=123, sr=84, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "DETECTION_ONLY" --1f736464-Z-- --dba48d31-A-- [31/Aug/2026:06:03:51.131150 +0300] apTvF9mUuou1H8H2UKXAzwAAAMk 35.81.82.181 59566 127.0.0.1 7081 --dba48d31-B-- GET /img/ufo_fm.php HTTP/1.1 Host: ihelp.ro X-Real-IP: 35.81.82.181 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: no-cors Sec-Fetch-Dest: image Referer: https://ihelp.ro/ Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cookie: 646109d53af43c125a937b56d9f339f0key=7a804c056f2d36c3c44be5f3d648e096; csrfToken=mPvE2njAl36rBABWojKSTDJjOWZkNjQ2MTA5NmVkM2IzY2QxMmFmM2Q3YjE2YjJiMTE4ZjY5ZWM%3D --dba48d31-F-- HTTP/1.1 200 OK X-Powered-By: PHP/8.1.34 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --dba48d31-H-- Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo_fm.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Pattern match "(\\/(images|img(s)?|pictures|upload(s)?)\\/[^\\.]{0,108}\\.(pht|phtml|php\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo_fm.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "54"] [id "77140878"] [msg "IM360 WAF: Infectors: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo_fm.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "ihelp.ro"] [uri "/img/ufo_fm.php"] [unique_id "apTvF9mUuou1H8H2UKXAzwAAAMk"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\/(images|img(s)?|pictures|upload(s)?)\\\\\\\\/[^\\\\\\\\.]{0,108}\\\\\\\\.(pht|phtml|php\\\\\\\\d?$))" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "23"] [id "77140735"] [msg "IM360 WAF: Suspicious access attempt (webshell)!||MVN:REQUEST_URI||T:APACHE||MV:/img/ufo_fm.php||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [tag "service_i360custom"] [tag "noshow"] [tag "service_rbl_infectors"] [hostname "ihelp.ro"] [uri "/img/ufo_fm.php"] [unique_id "apTvF9mUuou1H8H2UKXAzwAAAMk"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788145431117968 13242 (- - -) Stopwatch2: 1788145431117968 13242; combined=9500, p1=257, p2=9187, p3=0, p4=0, p5=55, sr=114, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "DETECTION_ONLY" --dba48d31-Z-- --7140f16d-A-- [31/Aug/2026:06:04:15.764553 +0300] apTvL27fDIutYTwcPOkZ0AAAAEE 120.133.60.156 34272 127.0.0.1 7081 --7140f16d-B-- POST /wp-login.php HTTP/1.1 Host: axapres.ro X-Real-IP: 120.133.60.156 X-Accel-Internal: /internal-nginx-static-location Content-Length: 108 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8 Accept-Language: en-US,en;q=0.5 Content-Type: application/x-www-form-urlencoded Cookie: wordpress_test_cookie=WP+Cookie+check Origin: https://axapres.ro Referer: https://axapres.ro/wp-login.php --7140f16d-F-- HTTP/1.1 403 Forbidden Content-Length: 199 Content-Type: text/html; charset=iso-8859-1 --7140f16d-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:06-04.120.133.60.156"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Apache-Handler: proxy:unix:/var/www/vhosts/system/axapres.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788145455702143 62500 (- - -) Stopwatch2: 1788145455702143 62500; combined=61518, p1=239, p2=60566, p3=0, p4=0, p5=483, sr=81, sw=230, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --7140f16d-Z-- --c959a14c-A-- [31/Aug/2026:06:06:22.605534 +0300] apTvrifaLSuAj0yzdueSfQAAAA0 207.154.219.81 43842 127.0.0.1 7081 --c959a14c-B-- POST /wp-login.php HTTP/1.1 Host: ajutam.ro X-Real-IP: 207.154.219.81 X-Accel-Internal: /internal-nginx-static-location Content-Length: 123 Accept: */* User-Agent: Mozilla/5.0 Content-Type: application/x-www-form-urlencoded Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818 --c959a14c-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --c959a14c-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:06-06.207.154.219.81"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788145582542740 62869 (- - -) Stopwatch2: 1788145582542740 62869; combined=61179, p1=858, p2=59801, p3=0, p4=0, p5=388, sr=101, sw=132, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --c959a14c-Z-- --e9092e18-A-- [31/Aug/2026:06:13:01.194919 +0300] apTxPdmUuou1H8H2UKXA8QAAAME 207.154.219.81 47156 127.0.0.1 7081 --e9092e18-B-- POST /wp-login.php HTTP/1.1 Host: ajutam.ro X-Real-IP: 207.154.219.81 X-Accel-Internal: /internal-nginx-static-location Content-Length: 105 Accept: */* User-Agent: Mozilla/5.0 Content-Type: application/x-www-form-urlencoded Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818 --e9092e18-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --e9092e18-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:06-13.207.154.219.81"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788145981128333 66727 (- - -) Stopwatch2: 1788145981128333 66727; combined=64624, p1=482, p2=60690, p3=0, p4=0, p5=2060, sr=222, sw=1392, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --e9092e18-Z-- --5155e508-A-- [31/Aug/2026:06:18:08.604947 +0300] apTycCfaLSuAj0yzdueSkQAAAAw 34.24.95.24 37350 127.0.0.1 7081 --5155e508-B-- GET /@fs/app/.env?raw?? HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 172.28.181.196 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 172.28.181.196 Fastly-Client-Ip: 172.28.181.196 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 172.28.181.196 Upgrade-Insecure-Requests: 1 X-Client-Ip: 172.28.181.196 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 172.28.181.196 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --5155e508-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --5155e508-E-- --5155e508-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/@fs/app/.env"] [unique_id "apTycCfaLSuAj0yzdueSkQAAAAw"] Stopwatch: 1788146288595552 9479 (- - -) Stopwatch2: 1788146288595552 9479; combined=7887, p1=341, p2=7352, p3=134, p4=9, p5=50, sr=129, sw=1, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --5155e508-Z-- --761ef133-A-- [31/Aug/2026:06:18:08.811724 +0300] apTycH7glkZrdsSdRApIkQAAAJg 34.24.95.24 37370 127.0.0.1 7081 --761ef133-B-- GET /@fs/..%252f..%252f..%252f..%252f..%252froot/.env?raw?? HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 192.168.75.173 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 192.168.75.173 Fastly-Client-Ip: 192.168.75.173 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 192.168.75.173 Upgrade-Insecure-Requests: 1 X-Client-Ip: 192.168.75.173 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 192.168.75.173 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --761ef133-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --761ef133-E-- --761ef133-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/@fs/..%2f..%2f..%2f..%2f..%2froot/.env"] [unique_id "apTycH7glkZrdsSdRApIkQAAAJg"] Stopwatch: 1788146288804922 6908 (- - -) Stopwatch2: 1788146288804922 6908; combined=5268, p1=327, p2=4776, p3=84, p4=10, p5=71, sr=118, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --761ef133-Z-- --a4be4676-A-- [31/Aug/2026:06:18:08.993888 +0300] apTycNmUuou1H8H2UKXBFwAAANQ 34.24.95.24 37382 127.0.0.1 7081 --a4be4676-B-- GET /@fs/..%252f..%252f..%252f..%252f..%252fproc/self/environ?raw?? HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 172.17.127.58 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 172.17.127.58 Fastly-Client-Ip: 172.17.127.58 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 172.17.127.58 Upgrade-Insecure-Requests: 1 X-Client-Ip: 172.17.127.58 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 172.17.127.58 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --a4be4676-F-- HTTP/1.1 403 Forbidden Content-Length: 199 Content-Type: text/html; charset=iso-8859-1 --a4be4676-H-- Message: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at MATCHED_VAR. [file "/etc/httpd/conf/modsecurity.d/rules/custom/012_i360_1_generic.conf"] [line "22"] [id "77140166"] [msg "IM360 WAF: Blocking directory traversal attempt||MVN:MATCHED_VAR||MV:/proc/self/environ?raw??||T:APACHE||"] [severity "CRITICAL"] [tag "service_gen"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G:raw??=& P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at MATCHED_VAR. [file "/etc/httpd/conf/modsecurity.d/rules/custom/012_i360_1_generic.conf"] [line "22"] [id "77140166"] [msg "IM360 WAF: Blocking directory traversal attempt||MVN:MATCHED_VAR||MV:/proc/self/environ?raw??||T:APACHE||"] [severity "CRITICAL"] [tag "service_gen"] [hostname "webmail.chania24.taxi"] [uri "/@fs/..%2f..%2f..%2f..%2f..%2fproc/self/environ"] [unique_id "apTycNmUuou1H8H2UKXBFwAAANQ"] Action: Intercepted (phase 2) Stopwatch: 1788146288987897 6073 (- - -) Stopwatch2: 1788146288987897 6073; combined=4435, p1=300, p2=3777, p3=0, p4=0, p5=358, sr=117, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --a4be4676-Z-- --78ba2517-A-- [31/Aug/2026:06:18:09.219186 +0300] apTycSfaLSuAj0yzdueSkgAAABY 34.24.95.24 37434 127.0.0.1 7081 --78ba2517-B-- GET /static../.env HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 172.17.65.186 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 172.17.65.186 Fastly-Client-Ip: 172.17.65.186 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 172.17.65.186 Upgrade-Insecure-Requests: 1 X-Client-Ip: 172.17.65.186 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 172.17.65.186 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --78ba2517-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --78ba2517-E-- --78ba2517-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/static../.env"] [unique_id "apTycSfaLSuAj0yzdueSkgAAABY"] Stopwatch: 1788146289209648 9651 (- - -) Stopwatch2: 1788146289209648 9651; combined=7986, p1=447, p2=7385, p3=92, p4=9, p5=53, sr=207, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --78ba2517-Z-- --82c7b36e-A-- [31/Aug/2026:06:18:09.229674 +0300] apTycdmUuou1H8H2UKXBGQAAAMc 34.24.95.24 37456 127.0.0.1 7081 --82c7b36e-B-- GET /@fs/src/.env?raw?? HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 192.168.218.248 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 192.168.218.248 Fastly-Client-Ip: 192.168.218.248 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 192.168.218.248 Upgrade-Insecure-Requests: 1 X-Client-Ip: 192.168.218.248 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 192.168.218.248 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --82c7b36e-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --82c7b36e-E-- --82c7b36e-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/@fs/src/.env"] [unique_id "apTycdmUuou1H8H2UKXBGQAAAMc"] Stopwatch: 1788146289223425 6335 (- - -) Stopwatch2: 1788146289223425 6335; combined=4753, p1=346, p2=4266, p3=84, p4=9, p5=47, sr=166, sw=1, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --82c7b36e-Z-- --29e80a3f-A-- [31/Aug/2026:06:18:09.232685 +0300] apTycW7fDIutYTwcPOkZ1wAAAFE 34.24.95.24 37446 127.0.0.1 7081 --29e80a3f-B-- GET /@fs/../.env?raw?? HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 192.168.132.70 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 192.168.132.70 Fastly-Client-Ip: 192.168.132.70 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 192.168.132.70 Upgrade-Insecure-Requests: 1 X-Client-Ip: 192.168.132.70 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 192.168.132.70 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --29e80a3f-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --29e80a3f-E-- --29e80a3f-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/.env"] [unique_id "apTycW7fDIutYTwcPOkZ1wAAAFE"] Stopwatch: 1788146289217261 15620 (- - -) Stopwatch2: 1788146289217261 15620; combined=7829, p1=559, p2=7029, p3=154, p4=12, p5=74, sr=161, sw=1, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --29e80a3f-Z-- --6c43d622-A-- [31/Aug/2026:06:18:09.254146 +0300] apTycSfaLSuAj0yzdueSkwAAABc 34.24.95.24 37468 127.0.0.1 7081 --6c43d622-B-- GET /_nuxt/../.env HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 192.168.29.181 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 192.168.29.181 Fastly-Client-Ip: 192.168.29.181 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 192.168.29.181 Upgrade-Insecure-Requests: 1 X-Client-Ip: 192.168.29.181 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 192.168.29.181 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --6c43d622-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --6c43d622-E-- --6c43d622-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/.env"] [unique_id "apTycSfaLSuAj0yzdueSkwAAABc"] Stopwatch: 1788146289246687 7544 (- - -) Stopwatch2: 1788146289246687 7544; combined=5854, p1=315, p2=5406, p3=82, p4=10, p5=41, sr=104, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --6c43d622-Z-- --c959a14c-A-- [31/Aug/2026:06:18:09.526338 +0300] apTycW7fDIutYTwcPOkZ2AAAAEw 34.24.95.24 37472 127.0.0.1 7081 --c959a14c-B-- GET /static//app/.env HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 10.233.245.68 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 10.233.245.68 Fastly-Client-Ip: 10.233.245.68 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 10.233.245.68 Upgrade-Insecure-Requests: 1 X-Client-Ip: 10.233.245.68 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 10.233.245.68 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --c959a14c-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --c959a14c-E-- --c959a14c-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/static/app/.env"] [unique_id "apTycW7fDIutYTwcPOkZ2AAAAEw"] Stopwatch: 1788146289517107 9316 (- - -) Stopwatch2: 1788146289517107 9316; combined=7949, p1=265, p2=7558, p3=68, p4=7, p5=50, sr=100, sw=1, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --c959a14c-Z-- --d6b4b43a-A-- [31/Aug/2026:06:18:09.533443 +0300] apTycdmUuou1H8H2UKXBGgAAAMw 34.24.95.24 37482 127.0.0.1 7081 --d6b4b43a-B-- GET /media../.env HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 100.107.189.187 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 100.107.189.187 Fastly-Client-Ip: 100.107.189.187 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 100.107.189.187 Upgrade-Insecure-Requests: 1 X-Client-Ip: 100.107.189.187 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 100.107.189.187 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --d6b4b43a-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --d6b4b43a-E-- --d6b4b43a-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/media../.env"] [unique_id "apTycdmUuou1H8H2UKXBGgAAAMw"] Stopwatch: 1788146289527195 6330 (- - -) Stopwatch2: 1788146289527195 6330; combined=4965, p1=303, p2=4540, p3=75, p4=7, p5=40, sr=125, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --d6b4b43a-Z-- --75771079-A-- [31/Aug/2026:06:18:09.554772 +0300] apTycdmUuou1H8H2UKXBGwAAANg 34.24.95.24 37502 127.0.0.1 7081 --75771079-B-- GET /files../.env HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 100.118.234.89 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 100.118.234.89 Fastly-Client-Ip: 100.118.234.89 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 100.118.234.89 Upgrade-Insecure-Requests: 1 X-Client-Ip: 100.118.234.89 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 100.118.234.89 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --75771079-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --75771079-E-- --75771079-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/files../.env"] [unique_id "apTycdmUuou1H8H2UKXBGwAAANg"] Stopwatch: 1788146289547589 7265 (- - -) Stopwatch2: 1788146289547589 7265; combined=5302, p1=371, p2=4801, p3=84, p4=7, p5=39, sr=113, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --75771079-Z-- --5155e508-A-- [31/Aug/2026:06:18:09.555041 +0300] apTycW7fDIutYTwcPOkZ2QAAAFM 34.24.95.24 37496 127.0.0.1 7081 --5155e508-B-- GET /.//.env HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 10.216.139.92 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 10.216.139.92 Fastly-Client-Ip: 10.216.139.92 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 10.216.139.92 Upgrade-Insecure-Requests: 1 X-Client-Ip: 10.216.139.92 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 10.216.139.92 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --5155e508-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --5155e508-E-- --5155e508-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/.env"] [unique_id "apTycW7fDIutYTwcPOkZ2QAAAFM"] Stopwatch: 1788146289535242 19921 (- - -) Stopwatch2: 1788146289535242 19921; combined=7316, p1=278, p2=6876, p3=108, p4=9, p5=45, sr=106, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --5155e508-Z-- --83ef5677-A-- [31/Aug/2026:06:18:09.567126 +0300] apTycX7glkZrdsSdRApIlAAAAIc 34.24.95.24 37516 127.0.0.1 7081 --83ef5677-B-- GET /static//.env HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 192.168.41.6 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 192.168.41.6 Fastly-Client-Ip: 192.168.41.6 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 192.168.41.6 Upgrade-Insecure-Requests: 1 X-Client-Ip: 192.168.41.6 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 192.168.41.6 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --83ef5677-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --83ef5677-E-- --83ef5677-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/static/.env"] [unique_id "apTycX7glkZrdsSdRApIlAAAAIc"] Stopwatch: 1788146289561088 6121 (- - -) Stopwatch2: 1788146289561088 6121; combined=4785, p1=298, p2=4372, p3=69, p4=7, p5=39, sr=104, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --83ef5677-Z-- --78ba2517-A-- [31/Aug/2026:06:18:09.726822 +0300] apTycW7fDIutYTwcPOkZ2gAAAFY 34.24.95.24 37518 127.0.0.1 7081 --78ba2517-B-- GET /static//home/user/.env HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 10.42.236.25 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 10.42.236.25 Fastly-Client-Ip: 10.42.236.25 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 10.42.236.25 Upgrade-Insecure-Requests: 1 X-Client-Ip: 10.42.236.25 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 10.42.236.25 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --78ba2517-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --78ba2517-E-- --78ba2517-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/static/home/user/.env"] [unique_id "apTycW7fDIutYTwcPOkZ2gAAAFY"] Stopwatch: 1788146289720117 6798 (- - -) Stopwatch2: 1788146289720117 6798; combined=5312, p1=268, p2=4929, p3=65, p4=7, p5=43, sr=105, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --78ba2517-Z-- --1c98420c-A-- [31/Aug/2026:06:18:10.012023 +0300] apTycn7glkZrdsSdRApIlQAAAIw 34.24.95.24 37528 127.0.0.1 7081 --1c98420c-B-- GET /api/.env/public/.env HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 10.93.33.68 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 10.93.33.68 Fastly-Client-Ip: 10.93.33.68 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 10.93.33.68 Upgrade-Insecure-Requests: 1 X-Client-Ip: 10.93.33.68 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 10.93.33.68 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --1c98420c-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --1c98420c-E-- --1c98420c-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/api/.env/public/.env"] [unique_id "apTycn7glkZrdsSdRApIlQAAAIw"] Stopwatch: 1788146290005596 6523 (- - -) Stopwatch2: 1788146290005596 6523; combined=5008, p1=313, p2=4574, p3=74, p4=8, p5=39, sr=127, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --1c98420c-Z-- --761ef133-A-- [31/Aug/2026:06:18:10.019779 +0300] apTycifaLSuAj0yzdueSlAAAABE 34.24.95.24 37540 127.0.0.1 7081 --761ef133-B-- GET //.env HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 192.168.3.21 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 192.168.3.21 Fastly-Client-Ip: 192.168.3.21 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 192.168.3.21 Upgrade-Insecure-Requests: 1 X-Client-Ip: 192.168.3.21 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 192.168.3.21 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --761ef133-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --761ef133-E-- --761ef133-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/.env"] [unique_id "apTycifaLSuAj0yzdueSlAAAABE"] Stopwatch: 1788146290012880 6999 (- - -) Stopwatch2: 1788146290012880 6999; combined=5499, p1=245, p2=5073, p3=76, p4=54, p5=50, sr=96, sw=1, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --761ef133-Z-- --d5370b71-A-- [31/Aug/2026:06:18:10.020179 +0300] apTycn7glkZrdsSdRApIlgAAAIU 34.24.95.24 37546 127.0.0.1 7081 --d5370b71-B-- GET /%2eenv HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 10.56.223.24 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 10.56.223.24 Fastly-Client-Ip: 10.56.223.24 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 10.56.223.24 Upgrade-Insecure-Requests: 1 X-Client-Ip: 10.56.223.24 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 10.56.223.24 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --d5370b71-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --d5370b71-E-- --d5370b71-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/.env"] [unique_id "apTycn7glkZrdsSdRApIlgAAAIU"] Stopwatch: 1788146290013045 7235 (- - -) Stopwatch2: 1788146290013045 7235; combined=5798, p1=325, p2=5344, p3=77, p4=8, p5=44, sr=122, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --d5370b71-Z-- --b033220f-A-- [31/Aug/2026:06:18:10.201936 +0300] apTyctmUuou1H8H2UKXBHAAAAMo 34.24.95.24 37570 127.0.0.1 7081 --b033220f-B-- GET /images../.env HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 100.77.204.197 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 100.77.204.197 Fastly-Client-Ip: 100.77.204.197 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 100.77.204.197 Upgrade-Insecure-Requests: 1 X-Client-Ip: 100.77.204.197 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 100.77.204.197 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --b033220f-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --b033220f-E-- --b033220f-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/images../.env"] [unique_id "apTyctmUuou1H8H2UKXBHAAAAMo"] Stopwatch: 1788146290195634 6395 (- - -) Stopwatch2: 1788146290195634 6395; combined=5118, p1=308, p2=4672, p3=83, p4=8, p5=47, sr=103, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --b033220f-Z-- --f284a63c-A-- [31/Aug/2026:06:18:10.208347 +0300] apTyctmUuou1H8H2UKXBHQAAAM0 34.24.95.24 37582 127.0.0.1 7081 --f284a63c-B-- GET /uploads../.env HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 192.168.188.130 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 192.168.188.130 Fastly-Client-Ip: 192.168.188.130 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 192.168.188.130 Upgrade-Insecure-Requests: 1 X-Client-Ip: 192.168.188.130 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 192.168.188.130 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --f284a63c-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --f284a63c-E-- --f284a63c-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/uploads../.env"] [unique_id "apTyctmUuou1H8H2UKXBHQAAAM0"] Stopwatch: 1788146290202493 5936 (- - -) Stopwatch2: 1788146290202493 5936; combined=4647, p1=286, p2=4264, p3=54, p4=7, p5=36, sr=122, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --f284a63c-Z-- --17b40101-A-- [31/Aug/2026:06:18:10.215392 +0300] apTyctmUuou1H8H2UKXBHgAAANU 34.24.95.24 37556 127.0.0.1 7081 --17b40101-B-- GET /img../.env HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 172.31.10.90 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 172.31.10.90 Fastly-Client-Ip: 172.31.10.90 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 172.31.10.90 Upgrade-Insecure-Requests: 1 X-Client-Ip: 172.31.10.90 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 172.31.10.90 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --17b40101-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --17b40101-E-- --17b40101-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/img../.env"] [unique_id "apTyctmUuou1H8H2UKXBHgAAANU"] Stopwatch: 1788146290204485 11188 (- - -) Stopwatch2: 1788146290204485 11188; combined=9393, p1=567, p2=8146, p3=604, p4=12, p5=63, sr=188, sw=1, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --17b40101-Z-- --590c442a-A-- [31/Aug/2026:06:18:10.394101 +0300] apTyctmUuou1H8H2UKXBHwAAAMQ 34.24.95.24 37624 127.0.0.1 7081 --590c442a-B-- GET /assets../.env HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 100.87.155.24 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 100.87.155.24 Fastly-Client-Ip: 100.87.155.24 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 100.87.155.24 Upgrade-Insecure-Requests: 1 X-Client-Ip: 100.87.155.24 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 100.87.155.24 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --590c442a-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --590c442a-E-- --590c442a-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/assets../.env"] [unique_id "apTyctmUuou1H8H2UKXBHwAAAMQ"] Stopwatch: 1788146290383070 11317 (- - -) Stopwatch2: 1788146290383070 11317; combined=9181, p1=535, p2=8371, p3=148, p4=56, p5=71, sr=161, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --590c442a-Z-- --589ad94a-A-- [31/Aug/2026:06:18:10.455217 +0300] apTyctmUuou1H8H2UKXBIAAAAM4 34.24.95.24 37636 127.0.0.1 7081 --589ad94a-B-- GET /@fs/var/task/.env?raw?? HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 10.224.20.36 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 10.224.20.36 Fastly-Client-Ip: 10.224.20.36 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 10.224.20.36 Upgrade-Insecure-Requests: 1 X-Client-Ip: 10.224.20.36 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 10.224.20.36 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --589ad94a-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --589ad94a-E-- --589ad94a-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/@fs/var/task/.env"] [unique_id "apTyctmUuou1H8H2UKXBIAAAAM4"] Stopwatch: 1788146290449950 5350 (- - -) Stopwatch2: 1788146290449950 5350; combined=4012, p1=285, p2=3618, p3=64, p4=7, p5=37, sr=103, sw=1, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --589ad94a-Z-- --1a6bac2f-A-- [31/Aug/2026:06:18:10.485112 +0300] apTyctmUuou1H8H2UKXBIQAAAME 34.24.95.24 37646 127.0.0.1 7081 --1a6bac2f-B-- GET /@fs/proc/self/cwd/.env?raw?? HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 172.26.80.199 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 172.26.80.199 Fastly-Client-Ip: 172.26.80.199 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 172.26.80.199 Upgrade-Insecure-Requests: 1 X-Client-Ip: 172.26.80.199 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 172.26.80.199 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --1a6bac2f-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --1a6bac2f-E-- --1a6bac2f-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/@fs/proc/self/cwd/.env"] [unique_id "apTyctmUuou1H8H2UKXBIQAAAME"] Stopwatch: 1788146290462379 22932 (- - -) Stopwatch2: 1788146290462379 22932; combined=21011, p1=529, p2=20145, p3=241, p4=11, p5=85, sr=259, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --1a6bac2f-Z-- --83ef5677-A-- [31/Aug/2026:06:18:11.226528 +0300] apTycyfaLSuAj0yzdueSlQAAAAU 34.24.95.24 37690 127.0.0.1 7081 --83ef5677-B-- GET /@fs/.env?raw&url?? HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 100.89.48.229 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 100.89.48.229 Fastly-Client-Ip: 100.89.48.229 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 100.89.48.229 Upgrade-Insecure-Requests: 1 X-Client-Ip: 100.89.48.229 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 100.89.48.229 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --83ef5677-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --83ef5677-E-- --83ef5677-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw&url??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw&url??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/@fs/.env"] [unique_id "apTycyfaLSuAj0yzdueSlQAAAAU"] Stopwatch: 1788146291219638 6999 (- - -) Stopwatch2: 1788146291219638 6999; combined=3932, p1=200, p2=3623, p3=64, p4=6, p5=39, sr=74, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --83ef5677-Z-- --6c43d622-A-- [31/Aug/2026:06:18:11.227515 +0300] apTyc27fDIutYTwcPOkZ3AAAAEI 34.24.95.24 37674 127.0.0.1 7081 --6c43d622-B-- GET /@fs/.env?url&raw?? HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 10.193.243.14 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 10.193.243.14 Fastly-Client-Ip: 10.193.243.14 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 10.193.243.14 Upgrade-Insecure-Requests: 1 X-Client-Ip: 10.193.243.14 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 10.193.243.14 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --6c43d622-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --6c43d622-E-- --6c43d622-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:url&raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:url&raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/@fs/.env"] [unique_id "apTyc27fDIutYTwcPOkZ3AAAAEI"] Stopwatch: 1788146291219139 8493 (- - -) Stopwatch2: 1788146291219139 8493; combined=4063, p1=291, p2=3623, p3=99, p4=3, p5=46, sr=108, sw=1, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --6c43d622-Z-- --761ef133-A-- [31/Aug/2026:06:18:11.764499 +0300] apTyc27fDIutYTwcPOkZ3QAAAEM 34.24.95.24 37744 127.0.0.1 7081 --761ef133-B-- GET /@fs/.env?import&?raw?? HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 10.3.184.21 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 10.3.184.21 Fastly-Client-Ip: 10.3.184.21 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 10.3.184.21 Upgrade-Insecure-Requests: 1 X-Client-Ip: 10.3.184.21 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 10.3.184.21 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --761ef133-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --761ef133-E-- --761ef133-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:import&?raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:import&?raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/@fs/.env"] [unique_id "apTyc27fDIutYTwcPOkZ3QAAAEM"] Stopwatch: 1788146291758670 5913 (- - -) Stopwatch2: 1788146291758670 5913; combined=4653, p1=229, p2=4298, p3=76, p4=8, p5=41, sr=74, sw=1, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --761ef133-Z-- --05969073-A-- [31/Aug/2026:06:18:11.791062 +0300] apTyc9mUuou1H8H2UKXBJQAAAMU 34.24.95.24 37732 127.0.0.1 7081 --05969073-B-- GET /config/.env.php HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 172.22.142.141 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 172.22.142.141 Fastly-Client-Ip: 172.22.142.141 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 172.22.142.141 Upgrade-Insecure-Requests: 1 X-Client-Ip: 172.22.142.141 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 172.22.142.141 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --05969073-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --05969073-E-- --05969073-H-- Message: Warning. Matched phrase ".env.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/config/.env.php||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Matched phrase ".env.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/config/.env.php||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".env.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/config/.env.php||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "webmail.chania24.taxi"] [uri "/config/.env.php"] [unique_id "apTyc9mUuou1H8H2UKXBJQAAAMU"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".env.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/config/.env.php||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/config/.env.php"] [unique_id "apTyc9mUuou1H8H2UKXBJQAAAMU"] Stopwatch: 1788146291752398 38758 (- - -) Stopwatch2: 1788146291752398 38758; combined=37508, p1=301, p2=37089, p3=65, p4=7, p5=46, sr=136, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --05969073-Z-- --2d58ee79-A-- [31/Aug/2026:06:18:11.791664 +0300] apTyc9mUuou1H8H2UKXBJgAAAMY 34.24.95.24 37742 127.0.0.1 7081 --2d58ee79-B-- GET /wp-config.php.bak HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 100.110.233.113 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 100.110.233.113 Fastly-Client-Ip: 100.110.233.113 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 100.110.233.113 Upgrade-Insecure-Requests: 1 X-Client-Ip: 100.110.233.113 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 100.110.233.113 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --2d58ee79-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --2d58ee79-E-- --2d58ee79-H-- Message: Warning. Matched phrase "wp-config.php." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/wp-config.php.bak||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Matched phrase "wp-config.php." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/wp-config.php.bak||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Message: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "wp-config.php." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/wp-config.php.bak||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "webmail.chania24.taxi"] [uri "/wp-config.php.bak"] [unique_id "apTyc9mUuou1H8H2UKXBJgAAAMY"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "wp-config.php." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/wp-config.php.bak||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/wp-config.php.bak"] [unique_id "apTyc9mUuou1H8H2UKXBJgAAAMY"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/wp-config.php.bak"] [unique_id "apTyc9mUuou1H8H2UKXBJgAAAMY"] Stopwatch: 1788146291756159 35587 (- - -) Stopwatch2: 1788146291756159 35587; combined=34398, p1=278, p2=34014, p3=37, p4=5, p5=64, sr=121, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --2d58ee79-Z-- --40b18017-A-- [31/Aug/2026:06:18:11.963201 +0300] apTyc37glkZrdsSdRApImwAAAJM 34.24.95.24 37768 127.0.0.1 7081 --40b18017-B-- GET /laravel/.env HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 192.168.154.2 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 192.168.154.2 Fastly-Client-Ip: 192.168.154.2 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 192.168.154.2 Upgrade-Insecure-Requests: 1 X-Client-Ip: 192.168.154.2 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 192.168.154.2 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --40b18017-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --40b18017-E-- --40b18017-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/laravel/.env"] [unique_id "apTyc37glkZrdsSdRApImwAAAJM"] Stopwatch: 1788146291949816 13478 (- - -) Stopwatch2: 1788146291949816 13478; combined=6316, p1=1594, p2=4606, p3=66, p4=7, p5=42, sr=102, sw=1, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --40b18017-Z-- --904cf438-A-- [31/Aug/2026:06:18:12.061086 +0300] apTydNmUuou1H8H2UKXBJwAAAMw 34.24.95.24 37784 127.0.0.1 7081 --904cf438-B-- GET /wp-config.php.old HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 10.116.49.63 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 10.116.49.63 Fastly-Client-Ip: 10.116.49.63 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 10.116.49.63 Upgrade-Insecure-Requests: 1 X-Client-Ip: 10.116.49.63 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 10.116.49.63 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --904cf438-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --904cf438-E-- --904cf438-H-- Message: Warning. Matched phrase "wp-config.php." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/wp-config.php.old||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Matched phrase "wp-config.php." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/wp-config.php.old||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Message: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "wp-config.php." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/wp-config.php.old||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "webmail.chania24.taxi"] [uri "/wp-config.php.old"] [unique_id "apTydNmUuou1H8H2UKXBJwAAAMw"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "wp-config.php." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/wp-config.php.old||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/wp-config.php.old"] [unique_id "apTydNmUuou1H8H2UKXBJwAAAMw"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/wp-config.php.old"] [unique_id "apTydNmUuou1H8H2UKXBJwAAAMw"] Stopwatch: 1788146292027588 33581 (- - -) Stopwatch2: 1788146292027588 33581; combined=32260, p1=240, p2=31899, p3=61, p4=7, p5=52, sr=83, sw=1, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --904cf438-Z-- --1c98420c-A-- [31/Aug/2026:06:18:12.149572 +0300] apTydCfaLSuAj0yzdueSmAAAAA0 34.24.95.24 37802 127.0.0.1 7081 --1c98420c-B-- GET /core/.env HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 172.30.60.95 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 172.30.60.95 Fastly-Client-Ip: 172.30.60.95 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 172.30.60.95 Upgrade-Insecure-Requests: 1 X-Client-Ip: 172.30.60.95 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 172.30.60.95 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --1c98420c-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --1c98420c-E-- --1c98420c-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/core/.env"] [unique_id "apTydCfaLSuAj0yzdueSmAAAAA0"] Stopwatch: 1788146292141121 8560 (- - -) Stopwatch2: 1788146292141121 8560; combined=7031, p1=280, p2=6621, p3=78, p4=9, p5=43, sr=96, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --1c98420c-Z-- --d5370b71-A-- [31/Aug/2026:06:18:12.169745 +0300] apTydCfaLSuAj0yzdueSlwAAABI 34.24.95.24 37800 127.0.0.1 7081 --d5370b71-B-- GET /.env.php.bak HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 10.53.117.228 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 10.53.117.228 Fastly-Client-Ip: 10.53.117.228 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 10.53.117.228 Upgrade-Insecure-Requests: 1 X-Client-Ip: 10.53.117.228 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 10.53.117.228 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --d5370b71-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --d5370b71-E-- --d5370b71-H-- Message: Warning. Matched phrase ".env.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.env.php.bak||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Matched phrase ".env.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.env.php.bak||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".env.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.env.php.bak||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "webmail.chania24.taxi"] [uri "/.env.php.bak"] [unique_id "apTydCfaLSuAj0yzdueSlwAAABI"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".env.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.env.php.bak||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/.env.php.bak"] [unique_id "apTydCfaLSuAj0yzdueSlwAAABI"] Stopwatch: 1788146292132811 37042 (- - -) Stopwatch2: 1788146292132811 37042; combined=35376, p1=339, p2=34893, p3=87, p4=8, p5=48, sr=123, sw=1, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --d5370b71-Z-- --83ef5677-A-- [31/Aug/2026:06:18:12.348283 +0300] apTydG7fDIutYTwcPOkZ3gAAAEY 34.24.95.24 37816 127.0.0.1 7081 --83ef5677-B-- GET /.env.swp HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 10.27.17.157 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 10.27.17.157 Fastly-Client-Ip: 10.27.17.157 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 10.27.17.157 Upgrade-Insecure-Requests: 1 X-Client-Ip: 10.27.17.157 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 10.27.17.157 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --83ef5677-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --83ef5677-E-- --83ef5677-H-- Message: Warning. Pattern match "(\\.swp|~)$" at REQUEST_BASENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "309"] [id "77142201"] [msg "IM360 WAF: Possible enumeration of sensitive data (dirb)||MVN:REQUEST_BASENAME||T:APACHE||MV:.env.swp||"] [severity "NOTICE"] [tag "service_i360custom"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\.swp|~)$" at REQUEST_BASENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "309"] [id "77142201"] [msg "IM360 WAF: Possible enumeration of sensitive data (dirb)||MVN:REQUEST_BASENAME||T:APACHE||MV:.env.swp||"] [severity "NOTICE"] [tag "service_i360custom"] [hostname "webmail.chania24.taxi"] [uri "/.env.swp"] [unique_id "apTydG7fDIutYTwcPOkZ3gAAAEY"] Stopwatch: 1788146292338396 9990 (- - -) Stopwatch2: 1788146292338396 9990; combined=7695, p1=327, p2=7194, p3=96, p4=9, p5=69, sr=137, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --83ef5677-Z-- --9e4b441f-A-- [31/Aug/2026:06:18:12.365798 +0300] apTydNmUuou1H8H2UKXBKAAAAMM 34.24.95.24 37824 127.0.0.1 7081 --9e4b441f-B-- GET /config.php.bak HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 192.168.119.7 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 192.168.119.7 Fastly-Client-Ip: 192.168.119.7 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 192.168.119.7 Upgrade-Insecure-Requests: 1 X-Client-Ip: 192.168.119.7 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 192.168.119.7 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --9e4b441f-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --9e4b441f-E-- --9e4b441f-H-- Message: Warning. Matched phrase "/config.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "/config.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/config.php.bak"] [unique_id "apTydNmUuou1H8H2UKXBKAAAAMM"] Stopwatch: 1788146292357293 8625 (- - -) Stopwatch2: 1788146292357293 8625; combined=6908, p1=378, p2=6372, p3=96, p4=10, p5=52, sr=120, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --9e4b441f-Z-- --40b18017-A-- [31/Aug/2026:06:18:12.383399 +0300] apTydCfaLSuAj0yzdueSmQAAAAc 34.24.95.24 37836 127.0.0.1 7081 --40b18017-B-- GET /configuration.php.bak HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 172.22.147.122 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 172.22.147.122 Fastly-Client-Ip: 172.22.147.122 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 172.22.147.122 Upgrade-Insecure-Requests: 1 X-Client-Ip: 172.22.147.122 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 172.22.147.122 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --40b18017-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --40b18017-E-- --40b18017-H-- Message: Warning. Matched phrase "/configuration.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "/configuration.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/configuration.php.bak"] [unique_id "apTydCfaLSuAj0yzdueSmQAAAAc"] Stopwatch: 1788146292375308 8201 (- - -) Stopwatch2: 1788146292375308 8201; combined=6451, p1=367, p2=5936, p3=88, p4=10, p5=50, sr=118, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --40b18017-Z-- --1f538b55-A-- [31/Aug/2026:06:18:12.401999 +0300] apTydCfaLSuAj0yzdueSmgAAAA4 34.24.95.24 37846 127.0.0.1 7081 --1f538b55-B-- GET /public/.env HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 100.95.78.93 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 100.95.78.93 Fastly-Client-Ip: 100.95.78.93 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 100.95.78.93 Upgrade-Insecure-Requests: 1 X-Client-Ip: 100.95.78.93 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 100.95.78.93 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --1f538b55-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --1f538b55-E-- --1f538b55-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/public/.env"] [unique_id "apTydCfaLSuAj0yzdueSmgAAAA4"] Stopwatch: 1788146292393549 8556 (- - -) Stopwatch2: 1788146292393549 8556; combined=6915, p1=351, p2=6366, p3=138, p4=11, p5=49, sr=124, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --1f538b55-Z-- --9afb313c-A-- [31/Aug/2026:06:18:12.683125 +0300] apTydNmUuou1H8H2UKXBKgAAAMA 34.24.95.24 37876 127.0.0.1 7081 --9afb313c-B-- GET /wp/.env HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 100.67.9.215 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 100.67.9.215 Fastly-Client-Ip: 100.67.9.215 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 100.67.9.215 Upgrade-Insecure-Requests: 1 X-Client-Ip: 100.67.9.215 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 100.67.9.215 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --9afb313c-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --9afb313c-E-- --9afb313c-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/wp/.env"] [unique_id "apTydNmUuou1H8H2UKXBKgAAAMA"] Stopwatch: 1788146292676181 7037 (- - -) Stopwatch2: 1788146292676181 7037; combined=4611, p1=256, p2=4239, p3=62, p4=7, p5=47, sr=100, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --9afb313c-Z-- --1c98420c-A-- [31/Aug/2026:06:18:12.714216 +0300] apTydG7fDIutYTwcPOkZ3wAAAEc 34.24.95.24 37904 127.0.0.1 7081 --1c98420c-B-- GET /web/.env HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 172.20.118.49 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 172.20.118.49 Fastly-Client-Ip: 172.20.118.49 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 172.20.118.49 Upgrade-Insecure-Requests: 1 X-Client-Ip: 172.20.118.49 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 172.20.118.49 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --1c98420c-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --1c98420c-E-- --1c98420c-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/web/.env"] [unique_id "apTydG7fDIutYTwcPOkZ3wAAAEc"] Stopwatch: 1788146292704411 9888 (- - -) Stopwatch2: 1788146292704411 9888; combined=8500, p1=337, p2=8060, p3=59, p4=7, p5=37, sr=151, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --1c98420c-Z-- --6a648b1a-A-- [31/Aug/2026:06:18:12.740687 +0300] apTydNmUuou1H8H2UKXBLAAAAMA 34.24.95.24 37884 127.0.0.1 7081 --6a648b1a-B-- GET /wp-config.php~ HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 192.168.85.77 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 192.168.85.77 Fastly-Client-Ip: 192.168.85.77 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 192.168.85.77 Upgrade-Insecure-Requests: 1 X-Client-Ip: 192.168.85.77 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 192.168.85.77 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --6a648b1a-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --6a648b1a-E-- --6a648b1a-H-- Message: Warning. Matched phrase "wp-config.php~" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/wp-config.php~||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Matched phrase "wp-config.php~" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/wp-config.php~||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Message: Warning. Pattern match "(\\.swp|~)$" at REQUEST_BASENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "309"] [id "77142201"] [msg "IM360 WAF: Possible enumeration of sensitive data (dirb)||MVN:REQUEST_BASENAME||T:APACHE||MV:wp-config.php~||"] [severity "NOTICE"] [tag "service_i360custom"] Message: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "wp-config.php~" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/wp-config.php~||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "webmail.chania24.taxi"] [uri "/wp-config.php~"] [unique_id "apTydNmUuou1H8H2UKXBLAAAAMA"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "wp-config.php~" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/wp-config.php~||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/wp-config.php~"] [unique_id "apTydNmUuou1H8H2UKXBLAAAAMA"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\.swp|~)$" at REQUEST_BASENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "309"] [id "77142201"] [msg "IM360 WAF: Possible enumeration of sensitive data (dirb)||MVN:REQUEST_BASENAME||T:APACHE||MV:wp-config.php~||"] [severity "NOTICE"] [tag "service_i360custom"] [hostname "webmail.chania24.taxi"] [uri "/wp-config.php~"] [unique_id "apTydNmUuou1H8H2UKXBLAAAAMA"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/wp-config.php~"] [unique_id "apTydNmUuou1H8H2UKXBLAAAAMA"] Stopwatch: 1788146292708494 32280 (- - -) Stopwatch2: 1788146292708494 32280; combined=30855, p1=387, p2=30317, p3=65, p4=6, p5=80, sr=127, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --6a648b1a-Z-- --d5370b71-A-- [31/Aug/2026:06:18:13.273278 +0300] apTydW7fDIutYTwcPOkZ4AAAAEo 34.24.95.24 37906 127.0.0.1 7081 --d5370b71-B-- GET /wp-config.php.swp HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 100.90.25.186 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 100.90.25.186 Fastly-Client-Ip: 100.90.25.186 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 100.90.25.186 Upgrade-Insecure-Requests: 1 X-Client-Ip: 100.90.25.186 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 100.90.25.186 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --d5370b71-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --d5370b71-E-- --d5370b71-H-- Message: Warning. Matched phrase "wp-config.php." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/wp-config.php.swp||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Matched phrase "wp-config.php." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/wp-config.php.swp||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Message: Warning. Pattern match "(\\.swp|~)$" at REQUEST_BASENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "309"] [id "77142201"] [msg "IM360 WAF: Possible enumeration of sensitive data (dirb)||MVN:REQUEST_BASENAME||T:APACHE||MV:wp-config.php.swp||"] [severity "NOTICE"] [tag "service_i360custom"] Message: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "wp-config.php." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/wp-config.php.swp||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "webmail.chania24.taxi"] [uri "/wp-config.php.swp"] [unique_id "apTydW7fDIutYTwcPOkZ4AAAAEo"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "wp-config.php." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/wp-config.php.swp||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/wp-config.php.swp"] [unique_id "apTydW7fDIutYTwcPOkZ4AAAAEo"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\.swp|~)$" at REQUEST_BASENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "309"] [id "77142201"] [msg "IM360 WAF: Possible enumeration of sensitive data (dirb)||MVN:REQUEST_BASENAME||T:APACHE||MV:wp-config.php.swp||"] [severity "NOTICE"] [tag "service_i360custom"] [hostname "webmail.chania24.taxi"] [uri "/wp-config.php.swp"] [unique_id "apTydW7fDIutYTwcPOkZ4AAAAEo"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/wp-config.php.swp"] [unique_id "apTydW7fDIutYTwcPOkZ4AAAAEo"] Stopwatch: 1788146293238851 34551 (- - -) Stopwatch2: 1788146293238851 34551; combined=33115, p1=256, p2=32745, p3=56, p4=6, p5=52, sr=98, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --d5370b71-Z-- --1f538b55-A-- [31/Aug/2026:06:18:13.447552 +0300] apTydX7glkZrdsSdRApInQAAAJA 34.24.95.24 37934 127.0.0.1 7081 --1f538b55-B-- GET /storage/.env HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 192.168.23.223 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 192.168.23.223 Fastly-Client-Ip: 192.168.23.223 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 192.168.23.223 Upgrade-Insecure-Requests: 1 X-Client-Ip: 192.168.23.223 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 192.168.23.223 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --1f538b55-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --1f538b55-E-- --1f538b55-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/storage/.env"] [unique_id "apTydX7glkZrdsSdRApInQAAAJA"] Stopwatch: 1788146293440235 7432 (- - -) Stopwatch2: 1788146293440235 7432; combined=5827, p1=325, p2=5366, p3=83, p4=8, p5=45, sr=112, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --1f538b55-Z-- --6df58a70-A-- [31/Aug/2026:06:18:14.355511 +0300] apTydn7glkZrdsSdRApIoQAAAIE 34.24.95.24 38050 127.0.0.1 7081 --6df58a70-B-- GET /web.config HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 192.168.230.247 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 192.168.230.247 Fastly-Client-Ip: 192.168.230.247 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 192.168.230.247 Upgrade-Insecure-Requests: 1 X-Client-Ip: 192.168.230.247 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 192.168.230.247 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --6df58a70-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --6df58a70-E-- --6df58a70-H-- Message: Warning. Matched phrase "/web.config" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "/web.config" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/web.config"] [unique_id "apTydn7glkZrdsSdRApIoQAAAIE"] Stopwatch: 1788146294349456 6180 (- - -) Stopwatch2: 1788146294349456 6180; combined=4875, p1=336, p2=4429, p3=61, p4=7, p5=41, sr=155, sw=1, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --6df58a70-Z-- --3d6edc59-A-- [31/Aug/2026:06:18:16.612527 +0300] apTyeH7glkZrdsSdRApIpgAAAI8 34.24.95.24 55498 127.0.0.1 7081 --3d6edc59-B-- GET /production/.env HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 100.98.232.217 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 100.98.232.217 Fastly-Client-Ip: 100.98.232.217 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 100.98.232.217 Upgrade-Insecure-Requests: 1 X-Client-Ip: 100.98.232.217 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 100.98.232.217 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --3d6edc59-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --3d6edc59-E-- --3d6edc59-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/production/.env"] [unique_id "apTyeH7glkZrdsSdRApIpgAAAI8"] Stopwatch: 1788146296604462 8148 (- - -) Stopwatch2: 1788146296604462 8148; combined=6655, p1=336, p2=6144, p3=116, p4=15, p5=44, sr=148, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --3d6edc59-Z-- --3b1af431-A-- [31/Aug/2026:06:18:16.660588 +0300] apTyeH7glkZrdsSdRApIpwAAAJM 34.24.95.24 55520 127.0.0.1 7081 --3b1af431-B-- GET /src/.env HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 10.18.140.53 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 10.18.140.53 Fastly-Client-Ip: 10.18.140.53 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 10.18.140.53 Upgrade-Insecure-Requests: 1 X-Client-Ip: 10.18.140.53 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 10.18.140.53 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --3b1af431-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --3b1af431-E-- --3b1af431-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/src/.env"] [unique_id "apTyeH7glkZrdsSdRApIpwAAAJM"] Stopwatch: 1788146296654866 5854 (- - -) Stopwatch2: 1788146296654866 5854; combined=4516, p1=275, p2=4135, p3=62, p4=7, p5=37, sr=114, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --3b1af431-Z-- --5acf943e-A-- [31/Aug/2026:06:18:16.668487 +0300] apTyeH7glkZrdsSdRApIqAAAAI4 34.24.95.24 55514 127.0.0.1 7081 --5acf943e-B-- GET /app/.env HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 172.18.156.47 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 172.18.156.47 Fastly-Client-Ip: 172.18.156.47 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 172.18.156.47 Upgrade-Insecure-Requests: 1 X-Client-Ip: 172.18.156.47 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 172.18.156.47 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --5acf943e-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --5acf943e-E-- --5acf943e-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/app/.env"] [unique_id "apTyeH7glkZrdsSdRApIqAAAAI4"] Stopwatch: 1788146296662215 6356 (- - -) Stopwatch2: 1788146296662215 6356; combined=5053, p1=251, p2=4696, p3=60, p4=6, p5=40, sr=99, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --5acf943e-Z-- --40b18017-A-- [31/Aug/2026:06:18:16.813292 +0300] apTyeG7fDIutYTwcPOkZ5gAAAFU 34.24.95.24 55530 127.0.0.1 7081 --40b18017-B-- GET /server/.env HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 10.127.65.47 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 10.127.65.47 Fastly-Client-Ip: 10.127.65.47 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 10.127.65.47 Upgrade-Insecure-Requests: 1 X-Client-Ip: 10.127.65.47 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 10.127.65.47 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --40b18017-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --40b18017-E-- --40b18017-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/server/.env"] [unique_id "apTyeG7fDIutYTwcPOkZ5gAAAFU"] Stopwatch: 1788146296807126 6260 (- - -) Stopwatch2: 1788146296807126 6260; combined=4883, p1=287, p2=4489, p3=61, p4=7, p5=38, sr=101, sw=1, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --40b18017-Z-- --1f538b55-A-- [31/Aug/2026:06:18:16.851397 +0300] apTyeG7fDIutYTwcPOkZ5wAAAFc 34.24.95.24 55532 127.0.0.1 7081 --1f538b55-B-- GET /frontend/.env HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 172.23.151.239 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 172.23.151.239 Fastly-Client-Ip: 172.23.151.239 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 172.23.151.239 Upgrade-Insecure-Requests: 1 X-Client-Ip: 172.23.151.239 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 172.23.151.239 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --1f538b55-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --1f538b55-E-- --1f538b55-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/frontend/.env"] [unique_id "apTyeG7fDIutYTwcPOkZ5wAAAFc"] Stopwatch: 1788146296845539 5965 (- - -) Stopwatch2: 1788146296845539 5965; combined=4584, p1=259, p2=4208, p3=64, p4=8, p5=45, sr=100, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --1f538b55-Z-- --dde88c6f-A-- [31/Aug/2026:06:18:16.855816 +0300] apTyeNmUuou1H8H2UKXBOwAAANE 34.24.95.24 55534 127.0.0.1 7081 --dde88c6f-B-- GET /staging/.env HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 10.180.250.39 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 10.180.250.39 Fastly-Client-Ip: 10.180.250.39 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 10.180.250.39 Upgrade-Insecure-Requests: 1 X-Client-Ip: 10.180.250.39 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 10.180.250.39 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --dde88c6f-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --dde88c6f-E-- --dde88c6f-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/staging/.env"] [unique_id "apTyeNmUuou1H8H2UKXBOwAAANE"] Stopwatch: 1788146296848798 7116 (- - -) Stopwatch2: 1788146296848798 7116; combined=5918, p1=259, p2=5530, p3=77, p4=8, p5=43, sr=95, sw=1, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --dde88c6f-Z-- --84d97830-A-- [31/Aug/2026:06:18:16.865150 +0300] apTyeNmUuou1H8H2UKXBPAAAAM8 34.24.95.24 55550 127.0.0.1 7081 --84d97830-B-- GET /docker/.env HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 172.23.154.108 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 172.23.154.108 Fastly-Client-Ip: 172.23.154.108 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 172.23.154.108 Upgrade-Insecure-Requests: 1 X-Client-Ip: 172.23.154.108 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 172.23.154.108 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --84d97830-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --84d97830-E-- --84d97830-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/docker/.env"] [unique_id "apTyeNmUuou1H8H2UKXBPAAAAM8"] Stopwatch: 1788146296859348 5885 (- - -) Stopwatch2: 1788146296859348 5885; combined=4564, p1=278, p2=4180, p3=60, p4=8, p5=38, sr=95, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --84d97830-Z-- --6df58a70-A-- [31/Aug/2026:06:18:16.923073 +0300] apTyeG7fDIutYTwcPOkZ6AAAAEA 34.24.95.24 55556 127.0.0.1 7081 --6df58a70-B-- GET /dev/.env HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 10.201.112.26 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 10.201.112.26 Fastly-Client-Ip: 10.201.112.26 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 10.201.112.26 Upgrade-Insecure-Requests: 1 X-Client-Ip: 10.201.112.26 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 10.201.112.26 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --6df58a70-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --6df58a70-E-- --6df58a70-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/dev/.env"] [unique_id "apTyeG7fDIutYTwcPOkZ6AAAAEA"] Stopwatch: 1788146296916732 6436 (- - -) Stopwatch2: 1788146296916732 6436; combined=4922, p1=337, p2=4480, p3=59, p4=8, p5=38, sr=144, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --6df58a70-Z-- --c31cca52-A-- [31/Aug/2026:06:18:17.036011 +0300] apTyeX7glkZrdsSdRApIqQAAAJY 34.24.95.24 55562 127.0.0.1 7081 --c31cca52-B-- GET /apps/.env HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 192.168.58.51 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 192.168.58.51 Fastly-Client-Ip: 192.168.58.51 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 192.168.58.51 Upgrade-Insecure-Requests: 1 X-Client-Ip: 192.168.58.51 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 192.168.58.51 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --c31cca52-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --c31cca52-E-- --c31cca52-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/apps/.env"] [unique_id "apTyeX7glkZrdsSdRApIqQAAAJY"] Stopwatch: 1788146297029982 6119 (- - -) Stopwatch2: 1788146297029982 6119; combined=4856, p1=263, p2=4477, p3=63, p4=8, p5=44, sr=93, sw=1, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --c31cca52-Z-- --1ea68b55-A-- [31/Aug/2026:06:18:17.359323 +0300] apTyeX7glkZrdsSdRApIqgAAAJg 34.24.95.24 55598 127.0.0.1 7081 --1ea68b55-B-- GET /.git/HEAD HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 172.20.101.121 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 172.20.101.121 Fastly-Client-Ip: 172.20.101.121 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 172.20.101.121 Upgrade-Insecure-Requests: 1 X-Client-Ip: 172.20.101.121 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 172.20.101.121 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --1ea68b55-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --1ea68b55-E-- --1ea68b55-H-- Message: Warning. String match "/.git/" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "656"] [id "77318034"] [msg "IM360 WAF: Blocked access to git folder||T:APACHE||MV:/.git/head||"] [severity "NOTICE"] [tag "service_i360custom"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.git/" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "656"] [id "77318034"] [msg "IM360 WAF: Blocked access to git folder||T:APACHE||MV:/.git/head||"] [severity "NOTICE"] [tag "service_i360custom"] [hostname "webmail.chania24.taxi"] [uri "/.git/HEAD"] [unique_id "apTyeX7glkZrdsSdRApIqgAAAJg"] Stopwatch: 1788146297353309 6121 (- - -) Stopwatch2: 1788146297353309 6121; combined=4820, p1=286, p2=4416, p3=69, p4=6, p5=42, sr=103, sw=1, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --1ea68b55-Z-- --a053d533-A-- [31/Aug/2026:06:18:17.473773 +0300] apTyedmUuou1H8H2UKXBPwAAAMw 34.24.95.24 55602 127.0.0.1 7081 --a053d533-B-- GET /v2/.env HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 192.168.89.16 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 192.168.89.16 Fastly-Client-Ip: 192.168.89.16 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 192.168.89.16 Upgrade-Insecure-Requests: 1 X-Client-Ip: 192.168.89.16 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 192.168.89.16 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --a053d533-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --a053d533-E-- --a053d533-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/v2/.env"] [unique_id "apTyedmUuou1H8H2UKXBPwAAAMw"] Stopwatch: 1788146297467877 5981 (- - -) Stopwatch2: 1788146297467877 5981; combined=4611, p1=317, p2=4173, p3=61, p4=7, p5=53, sr=125, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --a053d533-Z-- --ee575677-A-- [31/Aug/2026:06:18:17.556327 +0300] apTyeX7glkZrdsSdRApIqwAAAIQ 34.24.95.24 55608 127.0.0.1 7081 --ee575677-B-- GET /old/.env HTTP/1.1 Host: webmail.chania24.taxi X-Real-IP: 34.24.95.24 X-Forwarded-For: 192.168.58.243 User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 192.168.58.243 Fastly-Client-Ip: 192.168.58.243 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 192.168.58.243 Upgrade-Insecure-Requests: 1 X-Client-Ip: 192.168.58.243 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 192.168.58.243 sec-ch-ua: "Chromium";v="147", "Google Chrome";v="147", "Not.A/Brand";v="8" sec-ch-ua-mobile: ?1 sec-ch-ua-platform: "Android" --ee575677-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --ee575677-E-- --ee575677-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "webmail.chania24.taxi"] [uri "/old/.env"] [unique_id "apTyeX7glkZrdsSdRApIqwAAAIQ"] Stopwatch: 1788146297550242 6193 (- - -) Stopwatch2: 1788146297550242 6193; combined=4848, p1=291, p2=4447, p3=62, p4=7, p5=41, sr=116, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --ee575677-Z-- --458bcb0b-A-- [31/Aug/2026:06:18:39.711453 +0300] apTyjtmUuou1H8H2UKXBRgAAAM4 81.171.72.135 45334 127.0.0.1 7081 --458bcb0b-B-- GET /.ssh/id_rsa HTTP/1.1 Host: ajutam.ro X-Real-IP: 81.171.72.135 X-Accel-Internal: /internal-nginx-static-location User-Agent: Go-http-client/1.1 Accept-Encoding: gzip --458bcb0b-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/7.3.33 Expires: Wed, 11 Jan 1984 05:00:00 GMT Cache-Control: no-cache, must-revalidate, max-age=0, no-store, private Link: <https://ajutam.ro/wp-json/>; rel="https://api.w.org/" X-TEC-API-VERSION: v1 X-TEC-API-ROOT: https://ajutam.ro/wp-json/tribe/events/v1/ X-TEC-API-ORIGIN: https://ajutam.ro Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --458bcb0b-H-- Message: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.ssh/id_rsa||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.ssh/id_rsa||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.ssh/id_rsa||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "ajutam.ro"] [uri "/.ssh/id_rsa"] [unique_id "apTyjtmUuou1H8H2UKXBRgAAAM4"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.ssh/id_rsa||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "ajutam.ro"] [uri "/.ssh/id_rsa"] [unique_id "apTyjtmUuou1H8H2UKXBRgAAAM4"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ajutam.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788146318994356 717164 (- - -) Stopwatch2: 1788146318994356 717164; combined=41607, p1=247, p2=41303, p3=0, p4=0, p5=57, sr=95, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --458bcb0b-Z-- --6ccc7604-A-- [31/Aug/2026:06:18:40.454980 +0300] apTykNmUuou1H8H2UKXBSwAAANQ 81.171.72.135 45376 127.0.0.1 7081 --6ccc7604-B-- GET /.git/HEAD HTTP/1.1 Host: ajutam.ro X-Real-IP: 81.171.72.135 X-Accel-Internal: /internal-nginx-static-location User-Agent: Go-http-client/1.1 Accept-Encoding: gzip --6ccc7604-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/7.3.33 Expires: Wed, 11 Jan 1984 05:00:00 GMT Cache-Control: no-cache, must-revalidate, max-age=0, no-store, private Link: <https://ajutam.ro/wp-json/>; rel="https://api.w.org/" X-TEC-API-VERSION: v1 X-TEC-API-ROOT: https://ajutam.ro/wp-json/tribe/events/v1/ X-TEC-API-ORIGIN: https://ajutam.ro Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --6ccc7604-H-- Message: Warning. String match "/.git/" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "656"] [id "77318034"] [msg "IM360 WAF: Blocked access to git folder||T:APACHE||MV:/.git/head||"] [severity "NOTICE"] [tag "service_i360custom"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.git/" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "656"] [id "77318034"] [msg "IM360 WAF: Blocked access to git folder||T:APACHE||MV:/.git/head||"] [severity "NOTICE"] [tag "service_i360custom"] [hostname "ajutam.ro"] [uri "/.git/HEAD"] [unique_id "apTykNmUuou1H8H2UKXBSwAAANQ"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ajutam.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788146320112532 342506 (- - -) Stopwatch2: 1788146320112532 342506; combined=3568, p1=234, p2=3282, p3=0, p4=0, p5=52, sr=86, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --6ccc7604-Z-- --9af7f705-A-- [31/Aug/2026:06:18:40.785324 +0300] apTykH7glkZrdsSdRApIrQAAAIc 81.171.72.135 45380 127.0.0.1 7081 --9af7f705-B-- GET /.env HTTP/1.1 Host: ajutam.ro X-Real-IP: 81.171.72.135 X-Accel-Internal: /internal-nginx-static-location User-Agent: Go-http-client/1.1 Accept-Encoding: gzip --9af7f705-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/7.3.33 Expires: Wed, 11 Jan 1984 05:00:00 GMT Cache-Control: no-cache, must-revalidate, max-age=0, no-store, private Link: <https://ajutam.ro/wp-json/>; rel="https://api.w.org/" X-TEC-API-VERSION: v1 X-TEC-API-ROOT: https://ajutam.ro/wp-json/tribe/events/v1/ X-TEC-API-ORIGIN: https://ajutam.ro Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --9af7f705-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "ajutam.ro"] [uri "/.env"] [unique_id "apTykH7glkZrdsSdRApIrQAAAIc"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ajutam.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788146320495255 290137 (- - -) Stopwatch2: 1788146320495255 290137; combined=3730, p1=197, p2=3479, p3=0, p4=0, p5=54, sr=85, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --9af7f705-Z-- --90b06164-A-- [31/Aug/2026:06:18:41.057730 +0300] apTykNmUuou1H8H2UKXBTAAAAMw 81.171.72.135 45392 127.0.0.1 7081 --90b06164-B-- GET /api/.env HTTP/1.1 Host: ajutam.ro X-Real-IP: 81.171.72.135 X-Accel-Internal: /internal-nginx-static-location User-Agent: Go-http-client/1.1 Accept-Encoding: gzip --90b06164-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/7.3.33 Expires: Wed, 11 Jan 1984 05:00:00 GMT Cache-Control: no-cache, must-revalidate, max-age=0, no-store, private Link: <https://ajutam.ro/wp-json/>; rel="https://api.w.org/" X-TEC-API-VERSION: v1 X-TEC-API-ROOT: https://ajutam.ro/wp-json/tribe/events/v1/ X-TEC-API-ORIGIN: https://ajutam.ro Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --90b06164-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "ajutam.ro"] [uri "/api/.env"] [unique_id "apTykNmUuou1H8H2UKXBTAAAAMw"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ajutam.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788146320699311 358491 (- - -) Stopwatch2: 1788146320699311 358491; combined=3640, p1=200, p2=3391, p3=0, p4=0, p5=49, sr=86, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --90b06164-Z-- --d5d10130-A-- [31/Aug/2026:06:18:42.475332 +0300] apTykn7glkZrdsSdRApIrwAAAIs 81.171.72.135 45452 127.0.0.1 7081 --d5d10130-B-- GET /backup.tar.gz HTTP/1.1 Host: ajutam.ro X-Real-IP: 81.171.72.135 X-Accel-Internal: /internal-nginx-static-location User-Agent: Go-http-client/1.1 Accept-Encoding: gzip --d5d10130-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/7.3.33 Expires: Wed, 11 Jan 1984 05:00:00 GMT Cache-Control: no-cache, must-revalidate, max-age=0, no-store, private Link: <https://ajutam.ro/wp-json/>; rel="https://api.w.org/" X-TEC-API-VERSION: v1 X-TEC-API-ROOT: https://ajutam.ro/wp-json/tribe/events/v1/ X-TEC-API-ORIGIN: https://ajutam.ro Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --d5d10130-H-- Message: Warning. Matched phrase "/backup." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/backup.tar.gz||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Matched phrase "/backup." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/backup.tar.gz||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "/backup." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/backup.tar.gz||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "ajutam.ro"] [uri "/backup.tar.gz"] [unique_id "apTykn7glkZrdsSdRApIrwAAAIs"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "/backup." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/backup.tar.gz||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "ajutam.ro"] [uri "/backup.tar.gz"] [unique_id "apTykn7glkZrdsSdRApIrwAAAIs"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ajutam.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788146322066117 409273 (- - -) Stopwatch2: 1788146322066117 409273; combined=37959, p1=184, p2=37720, p3=0, p4=0, p5=55, sr=73, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --d5d10130-Z-- --25874a28-A-- [31/Aug/2026:06:18:43.015279 +0300] apTyktmUuou1H8H2UKXBUgAAAM4 81.171.72.135 45470 127.0.0.1 7081 --25874a28-B-- GET /.npmrc HTTP/1.1 Host: ajutam.ro X-Real-IP: 81.171.72.135 X-Accel-Internal: /internal-nginx-static-location User-Agent: Go-http-client/1.1 Accept-Encoding: gzip --25874a28-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/7.3.33 Expires: Wed, 11 Jan 1984 05:00:00 GMT Cache-Control: no-cache, must-revalidate, max-age=0, no-store, private Link: <https://ajutam.ro/wp-json/>; rel="https://api.w.org/" X-TEC-API-VERSION: v1 X-TEC-API-ROOT: https://ajutam.ro/wp-json/tribe/events/v1/ X-TEC-API-ORIGIN: https://ajutam.ro Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --25874a28-H-- Message: Warning. Matched phrase ".npmrc" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.npmrc||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Matched phrase ".npmrc" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.npmrc||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".npmrc" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.npmrc||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "ajutam.ro"] [uri "/.npmrc"] [unique_id "apTyktmUuou1H8H2UKXBUgAAAM4"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".npmrc" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.npmrc||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "ajutam.ro"] [uri "/.npmrc"] [unique_id "apTyktmUuou1H8H2UKXBUgAAAM4"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ajutam.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788146322534872 480471 (- - -) Stopwatch2: 1788146322534872 480471; combined=33966, p1=362, p2=33548, p3=0, p4=0, p5=55, sr=175, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --25874a28-Z-- --3d6edc59-A-- [31/Aug/2026:06:18:43.156299 +0300] apTykm7fDIutYTwcPOkZ7AAAAEQ 81.171.72.135 45486 127.0.0.1 7081 --3d6edc59-B-- GET /backup.zip HTTP/1.1 Host: ajutam.ro X-Real-IP: 81.171.72.135 X-Accel-Internal: /internal-nginx-static-location User-Agent: Go-http-client/1.1 Accept-Encoding: gzip --3d6edc59-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/7.3.33 Expires: Wed, 11 Jan 1984 05:00:00 GMT Cache-Control: no-cache, must-revalidate, max-age=0, no-store, private Link: <https://ajutam.ro/wp-json/>; rel="https://api.w.org/" X-TEC-API-VERSION: v1 X-TEC-API-ROOT: https://ajutam.ro/wp-json/tribe/events/v1/ X-TEC-API-ORIGIN: https://ajutam.ro Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --3d6edc59-H-- Message: Warning. Matched phrase "/backup." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/backup.zip||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Matched phrase "/backup." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/backup.zip||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "/backup." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/backup.zip||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "ajutam.ro"] [uri "/backup.zip"] [unique_id "apTykm7fDIutYTwcPOkZ7AAAAEQ"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "/backup." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/backup.zip||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "ajutam.ro"] [uri "/backup.zip"] [unique_id "apTykm7fDIutYTwcPOkZ7AAAAEQ"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ajutam.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788146322638064 518312 (- - -) Stopwatch2: 1788146322638064 518312; combined=36877, p1=166, p2=36654, p3=0, p4=0, p5=56, sr=65, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --3d6edc59-Z-- --3b1af431-A-- [31/Aug/2026:06:18:43.368403 +0300] apTykm7fDIutYTwcPOkZ7QAAAEk 81.171.72.135 45492 127.0.0.1 7081 --3b1af431-B-- GET /.ssh/id_ed25519 HTTP/1.1 Host: ajutam.ro X-Real-IP: 81.171.72.135 X-Accel-Internal: /internal-nginx-static-location User-Agent: Go-http-client/1.1 Accept-Encoding: gzip --3b1af431-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/7.3.33 Expires: Wed, 11 Jan 1984 05:00:00 GMT Cache-Control: no-cache, must-revalidate, max-age=0, no-store, private Link: <https://ajutam.ro/wp-json/>; rel="https://api.w.org/" X-TEC-API-VERSION: v1 X-TEC-API-ROOT: https://ajutam.ro/wp-json/tribe/events/v1/ X-TEC-API-ORIGIN: https://ajutam.ro Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --3b1af431-H-- Message: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.ssh/id_ed25519||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.ssh/id_ed25519||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.ssh/id_ed25519||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "ajutam.ro"] [uri "/.ssh/id_ed25519"] [unique_id "apTykm7fDIutYTwcPOkZ7QAAAEk"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.ssh/id_ed25519||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "ajutam.ro"] [uri "/.ssh/id_ed25519"] [unique_id "apTykm7fDIutYTwcPOkZ7QAAAEk"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ajutam.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788146322915826 452636 (- - -) Stopwatch2: 1788146322915826 452636; combined=32530, p1=238, p2=32233, p3=0, p4=0, p5=58, sr=125, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --3b1af431-Z-- --8d0fff34-A-- [31/Aug/2026:06:18:43.854479 +0300] apTyk9mUuou1H8H2UKXBVAAAANY 81.171.72.135 45514 127.0.0.1 7081 --8d0fff34-B-- GET /config.php HTTP/1.1 Host: ajutam.ro X-Real-IP: 81.171.72.135 X-Accel-Internal: /internal-nginx-static-location User-Agent: Go-http-client/1.1 Accept-Encoding: gzip --8d0fff34-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/7.3.33 Expires: Wed, 11 Jan 1984 05:00:00 GMT Cache-Control: no-cache, must-revalidate, max-age=0, no-store, private Link: <https://ajutam.ro/wp-json/>; rel="https://api.w.org/" X-TEC-API-VERSION: v1 X-TEC-API-ROOT: https://ajutam.ro/wp-json/tribe/events/v1/ X-TEC-API-ORIGIN: https://ajutam.ro Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --8d0fff34-H-- Message: Warning. Matched phrase "/config.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "/config.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "ajutam.ro"] [uri "/config.php"] [unique_id "apTyk9mUuou1H8H2UKXBVAAAANY"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ajutam.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788146323471566 382982 (- - -) Stopwatch2: 1788146323471566 382982; combined=13246, p1=228, p2=12968, p3=0, p4=0, p5=49, sr=112, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --8d0fff34-Z-- --559c7c78-A-- [31/Aug/2026:06:18:43.871529 +0300] apTyk9mUuou1H8H2UKXBVQAAANc 81.171.72.135 45530 127.0.0.1 7081 --559c7c78-B-- GET /.svn/wc.db HTTP/1.1 Host: ajutam.ro X-Real-IP: 81.171.72.135 X-Accel-Internal: /internal-nginx-static-location User-Agent: Go-http-client/1.1 Accept-Encoding: gzip --559c7c78-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/7.3.33 Expires: Wed, 11 Jan 1984 05:00:00 GMT Cache-Control: no-cache, must-revalidate, max-age=0, no-store, private Link: <https://ajutam.ro/wp-json/>; rel="https://api.w.org/" X-TEC-API-VERSION: v1 X-TEC-API-ROOT: https://ajutam.ro/wp-json/tribe/events/v1/ X-TEC-API-ORIGIN: https://ajutam.ro Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --559c7c78-H-- Message: Warning. Matched phrase ".svn/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.svn/wc.db||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Matched phrase ".svn/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.svn/wc.db||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".svn/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.svn/wc.db||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "ajutam.ro"] [uri "/.svn/wc.db"] [unique_id "apTyk9mUuou1H8H2UKXBVQAAANc"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".svn/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.svn/wc.db||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "ajutam.ro"] [uri "/.svn/wc.db"] [unique_id "apTyk9mUuou1H8H2UKXBVQAAANc"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ajutam.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788146323483415 388238 (- - -) Stopwatch2: 1788146323483415 388238; combined=33241, p1=194, p2=32981, p3=0, p4=0, p5=66, sr=68, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --559c7c78-Z-- --cc644f03-A-- [31/Aug/2026:06:18:44.077667 +0300] apTyk9mUuou1H8H2UKXBVgAAAM8 81.171.72.135 45542 127.0.0.1 7081 --cc644f03-B-- GET /backup.sql HTTP/1.1 Host: ajutam.ro X-Real-IP: 81.171.72.135 X-Accel-Internal: /internal-nginx-static-location User-Agent: Go-http-client/1.1 Accept-Encoding: gzip --cc644f03-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/7.3.33 Expires: Wed, 11 Jan 1984 05:00:00 GMT Cache-Control: no-cache, must-revalidate, max-age=0, no-store, private Link: <https://ajutam.ro/wp-json/>; rel="https://api.w.org/" X-TEC-API-VERSION: v1 X-TEC-API-ROOT: https://ajutam.ro/wp-json/tribe/events/v1/ X-TEC-API-ORIGIN: https://ajutam.ro Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --cc644f03-H-- Message: Warning. Matched phrase "/backup." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/backup.sql||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Matched phrase "/backup." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/backup.sql||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "/backup." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/backup.sql||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "ajutam.ro"] [uri "/backup.sql"] [unique_id "apTyk9mUuou1H8H2UKXBVgAAAM8"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "/backup." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/backup.sql||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "ajutam.ro"] [uri "/backup.sql"] [unique_id "apTyk9mUuou1H8H2UKXBVgAAAM8"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ajutam.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788146323758393 319341 (- - -) Stopwatch2: 1788146323758393 319341; combined=31236, p1=281, p2=30888, p3=0, p4=0, p5=66, sr=117, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --cc644f03-Z-- --5acf943e-A-- [31/Aug/2026:06:19:41.656415 +0300] apTyzW7fDIutYTwcPOkZ7gAAAE8 207.154.219.81 55532 127.0.0.1 7081 --5acf943e-B-- POST /wp-login.php HTTP/1.1 Host: ajutam.ro X-Real-IP: 207.154.219.81 X-Accel-Internal: /internal-nginx-static-location Content-Length: 108 Accept: */* User-Agent: Mozilla/5.0 Content-Type: application/x-www-form-urlencoded Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818 --5acf943e-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --5acf943e-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:06-19.207.154.219.81"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788146381432788 223719 (- - -) Stopwatch2: 1788146381432788 223719; combined=214003, p1=2297, p2=210970, p3=0, p4=0, p5=570, sr=192, sw=166, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --5acf943e-Z-- --71f54c01-A-- [31/Aug/2026:06:26:23.945400 +0300] apT0X9mUuou1H8H2UKXBeAAAAMA 207.154.219.81 60682 127.0.0.1 7081 --71f54c01-B-- POST /wp-login.php HTTP/1.1 Host: ajutam.ro X-Real-IP: 207.154.219.81 X-Accel-Internal: /internal-nginx-static-location Content-Length: 110 Accept: */* User-Agent: Mozilla/5.0 Content-Type: application/x-www-form-urlencoded Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818 --71f54c01-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --71f54c01-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:06-26.207.154.219.81"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788146783882308 63148 (- - -) Stopwatch2: 1788146783882308 63148; combined=61290, p1=460, p2=60240, p3=0, p4=0, p5=447, sr=158, sw=143, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --71f54c01-Z-- --78c8584d-A-- [31/Aug/2026:06:31:22.840325 +0300] apT1itmUuou1H8H2UKXBjAAAAMs 138.197.193.77 46962 127.0.0.1 7081 --78c8584d-B-- POST /wp-login.php HTTP/1.1 Host: ajutam.ro X-Real-IP: 138.197.193.77 X-Accel-Internal: /internal-nginx-static-location Content-Length: 105 Accept: */* User-Agent: Mozilla/5.0 Content-Type: application/x-www-form-urlencoded Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818 --78c8584d-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --78c8584d-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:06-31.138.197.193.77"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788147082777068 63406 (- - -) Stopwatch2: 1788147082777068 63406; combined=58769, p1=298, p2=57042, p3=0, p4=0, p5=1040, sr=109, sw=389, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --78c8584d-Z-- --6659a052-A-- [31/Aug/2026:06:33:06.468117 +0300] apT18n7glkZrdsSdRApI1wAAAIo 207.154.219.81 33312 127.0.0.1 7081 --6659a052-B-- POST /wp-login.php HTTP/1.1 Host: ajutam.ro X-Real-IP: 207.154.219.81 X-Accel-Internal: /internal-nginx-static-location Content-Length: 111 Accept: */* User-Agent: Mozilla/5.0 Content-Type: application/x-www-form-urlencoded Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818 --6659a052-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --6659a052-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:06-33.207.154.219.81"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788147186406485 61716 (- - -) Stopwatch2: 1788147186406485 61716; combined=59131, p1=362, p2=57834, p3=0, p4=0, p5=672, sr=99, sw=263, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --6659a052-Z-- --ebd7b367-A-- [31/Aug/2026:06:33:15.423751 +0300] apT1@9mUuou1H8H2UKXBpAAAAMk 216.73.217.35 33358 127.0.0.1 7081 --ebd7b367-B-- GET /img/ufo_fm.php?p=%27+.+urlencode%28%24bp%29+.+%27 HTTP/1.1 Host: ihelp.ro X-Real-IP: 216.73.217.35 X-Accel-Internal: /internal-nginx-static-location accept: */* user-agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com) accept-encoding: gzip, br, zstd, deflate --ebd7b367-F-- HTTP/1.1 200 OK X-Powered-By: PHP/8.1.34 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --ebd7b367-H-- Message: Warning. Pattern match "(?i)\\b(?:s(?:e(?:t(?:_(?:e(?:xception|rror)_handler|magic_quotes_runtime|include_path)|defaultstub)|ssion_s(?:et_save_handler|tart))|qlite_(?:(?:(?:unbuffered|single|array)_)?query|create_(?:aggregate|function)|p?open|exec)|tr(?:eam_(?:context_create| ..." at ARGS:p. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "63"] [id "77134464"] [msg "IM360 WAF: Infectors: PHP Injection High-Risk PHP Function||T:APACHE||MVN:ARGS:p||MV:' . urlencode($bp) . '||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_o"] [tag "service_i360"] Message: Warning. Pattern match "(?i)\\b(?:s(?:e(?:t(?:_(?:e(?:xception|rror)_handler|magic_quotes_runtime|include_path)|defaultstub)|ssion_s(?:et_save_handler|tart))|qlite_(?:(?:(?:unbuffered|single|array)_)?query|create_(?:aggregate|function)|p?open|exec)|tr(?:eam_(?:context_create| ..." at ARGS:p. [file "/etc/httpd/conf/modsecurity.d/rules/custom/012_i360_1_generic.conf"] [line "19"] [id "77134463"] [msg "IM360 WAF: PHP Injection Attack: High-Risk PHP Function Call Found||T:APACHE||MVN:ARGS:p||MV:' . urlencode($bp) . '||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "NOTICE"] [tag "service_o"] [tag "service_i360"] [tag "noshow"] [tag "service_rbl_infectors"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(?i)\\\\\\\\b(?:s(?:e(?:t(?:_(?:e(?:xception|rror)_handler|magic_quotes_runtime|include_path)|defaultstub)|ssion_s(?:et_save_handler|tart))|qlite_(?:(?:(?:unbuffered|single|array)_)?query|create_(?:aggregate|function)|p?open|exec)|tr(?:eam_(?:context_create| ..." at ARGS:p. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "63"] [id "77134464"] [msg "IM360 WAF: Infectors: PHP Injection High-Risk PHP Function||T:APACHE||MVN:ARGS:p||MV:' . urlencode($bp) . '||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_o"] [tag "service_i360"] [hostname "ihelp.ro"] [uri "/img/ufo_fm.php"] [unique_id "apT1@9mUuou1H8H2UKXBpAAAAMk"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(?i)\\\\\\\\b(?:s(?:e(?:t(?:_(?:e(?:xception|rror)_handler|magic_quotes_runtime|include_path)|defaultstub)|ssion_s(?:et_save_handler|tart))|qlite_(?:(?:(?:unbuffered|single|array)_)?query|create_(?:aggregate|function)|p?open|exec)|tr(?:eam_(?:context_create| ..." at ARGS:p. [file "/etc/httpd/conf/modsecurity.d/rules/custom/012_i360_1_generic.conf"] [line "19"] [id "77134463"] [msg "IM360 WAF: PHP Injection Attack: High-Risk PHP Function Call Found||T:APACHE||MVN:ARGS:p||MV:' . urlencode($bp) . '||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "NOTICE"] [tag "service_o"] [tag "service_i360"] [tag "noshow"] [tag "service_rbl_infectors"] [hostname "ihelp.ro"] [uri "/img/ufo_fm.php"] [unique_id "apT1@9mUuou1H8H2UKXBpAAAAMk"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788147195388110 35685 (- - -) Stopwatch2: 1788147195388110 35685; combined=33022, p1=239, p2=32728, p3=0, p4=0, p5=54, sr=110, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "DETECTION_ONLY" --ebd7b367-Z-- --4c9ada32-A-- [31/Aug/2026:06:33:42.334179 +0300] apT2FtmUuou1H8H2UKXBtAAAANA 216.73.217.35 42272 127.0.0.1 7081 --4c9ada32-B-- GET /img/ufo_fm.php?p=%27.urlencode%28%24acc%29.%27 HTTP/1.1 Host: ihelp.ro X-Real-IP: 216.73.217.35 X-Accel-Internal: /internal-nginx-static-location accept: */* user-agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com) accept-encoding: gzip, br, zstd, deflate --4c9ada32-F-- HTTP/1.1 200 OK X-Powered-By: PHP/8.1.34 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --4c9ada32-H-- Message: Warning. Pattern match "(?i)\\b(?:s(?:e(?:t(?:_(?:e(?:xception|rror)_handler|magic_quotes_runtime|include_path)|defaultstub)|ssion_s(?:et_save_handler|tart))|qlite_(?:(?:(?:unbuffered|single|array)_)?query|create_(?:aggregate|function)|p?open|exec)|tr(?:eam_(?:context_create| ..." at ARGS:p. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "63"] [id "77134464"] [msg "IM360 WAF: Infectors: PHP Injection High-Risk PHP Function||T:APACHE||MVN:ARGS:p||MV:'.urlencode($acc).'||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_o"] [tag "service_i360"] Message: Warning. Pattern match "(?i)\\b(?:s(?:e(?:t(?:_(?:e(?:xception|rror)_handler|magic_quotes_runtime|include_path)|defaultstub)|ssion_s(?:et_save_handler|tart))|qlite_(?:(?:(?:unbuffered|single|array)_)?query|create_(?:aggregate|function)|p?open|exec)|tr(?:eam_(?:context_create| ..." at ARGS:p. [file "/etc/httpd/conf/modsecurity.d/rules/custom/012_i360_1_generic.conf"] [line "19"] [id "77134463"] [msg "IM360 WAF: PHP Injection Attack: High-Risk PHP Function Call Found||T:APACHE||MVN:ARGS:p||MV:'.urlencode($acc).'||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "NOTICE"] [tag "service_o"] [tag "service_i360"] [tag "noshow"] [tag "service_rbl_infectors"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(?i)\\\\\\\\b(?:s(?:e(?:t(?:_(?:e(?:xception|rror)_handler|magic_quotes_runtime|include_path)|defaultstub)|ssion_s(?:et_save_handler|tart))|qlite_(?:(?:(?:unbuffered|single|array)_)?query|create_(?:aggregate|function)|p?open|exec)|tr(?:eam_(?:context_create| ..." at ARGS:p. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "63"] [id "77134464"] [msg "IM360 WAF: Infectors: PHP Injection High-Risk PHP Function||T:APACHE||MVN:ARGS:p||MV:'.urlencode($acc).'||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_o"] [tag "service_i360"] [hostname "ihelp.ro"] [uri "/img/ufo_fm.php"] [unique_id "apT2FtmUuou1H8H2UKXBtAAAANA"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(?i)\\\\\\\\b(?:s(?:e(?:t(?:_(?:e(?:xception|rror)_handler|magic_quotes_runtime|include_path)|defaultstub)|ssion_s(?:et_save_handler|tart))|qlite_(?:(?:(?:unbuffered|single|array)_)?query|create_(?:aggregate|function)|p?open|exec)|tr(?:eam_(?:context_create| ..." at ARGS:p. [file "/etc/httpd/conf/modsecurity.d/rules/custom/012_i360_1_generic.conf"] [line "19"] [id "77134463"] [msg "IM360 WAF: PHP Injection Attack: High-Risk PHP Function Call Found||T:APACHE||MVN:ARGS:p||MV:'.urlencode($acc).'||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "NOTICE"] [tag "service_o"] [tag "service_i360"] [tag "noshow"] [tag "service_rbl_infectors"] [hostname "ihelp.ro"] [uri "/img/ufo_fm.php"] [unique_id "apT2FtmUuou1H8H2UKXBtAAAANA"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788147222299416 34810 (- - -) Stopwatch2: 1788147222299416 34810; combined=31357, p1=252, p2=31039, p3=0, p4=0, p5=66, sr=91, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "DETECTION_ONLY" --4c9ada32-Z-- --61d28665-A-- [31/Aug/2026:06:34:01.083844 +0300] apT2KdmUuou1H8H2UKXBxAAAAMA 138.197.193.77 41028 127.0.0.1 7081 --61d28665-B-- POST /wp-login.php HTTP/1.1 Host: ajutam.ro X-Real-IP: 138.197.193.77 X-Accel-Internal: /internal-nginx-static-location Content-Length: 108 Accept: */* User-Agent: Mozilla/5.0 Content-Type: application/x-www-form-urlencoded Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818 --61d28665-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --61d28665-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "42"] [id "33302"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:1"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788147241081871 2042 (- - -) Stopwatch2: 1788147241081871 2042; combined=670, p1=275, p2=74, p3=0, p4=0, p5=321, sr=104, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --61d28665-Z-- --6209bb50-A-- [31/Aug/2026:06:34:10.857892 +0300] apT2Mn7glkZrdsSdRApI7QAAAIE 216.73.217.35 49202 127.0.0.1 7081 --6209bb50-B-- GET /img/ufo_fm.php?f=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2F.htaccess&p=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs HTTP/1.1 Host: ihelp.ro X-Real-IP: 216.73.217.35 X-Accel-Internal: /internal-nginx-static-location accept: */* user-agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com) accept-encoding: gzip, br, zstd, deflate --6209bb50-F-- HTTP/1.1 200 OK X-Powered-By: PHP/8.1.34 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --6209bb50-H-- Message: Warning. Match of "pm cpanel AdminTranslations" against "REQUEST_URI" required. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "65"] [id "77140882"] [msg "IM360 WAF: Infectors: Remote File Access Attempt||MVN:REQUEST_URI||MV:/img/ufo_fm.php?f=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2F.htaccess&p=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs||T:APACHE||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Match of "pm cpanel AdminTranslations" against "REQUEST_URI" required. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "65"] [id "77140882"] [msg "IM360 WAF: Infectors: Remote File Access Attempt||MVN:REQUEST_URI||MV:/img/ufo_fm.php?f=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2F.htaccess&p=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs||T:APACHE||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [hostname "ihelp.ro"] [uri "/img/ufo_fm.php"] [unique_id "apT2Mn7glkZrdsSdRApI7QAAAIE"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788147250822547 35393 (- - -) Stopwatch2: 1788147250822547 35393; combined=31347, p1=330, p2=30975, p3=0, p4=0, p5=42, sr=154, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "DETECTION_ONLY" --6209bb50-Z-- --9096fa5d-A-- [31/Aug/2026:06:35:54.784664 +0300] apT2mtmUuou1H8H2UKXB3AAAANU 216.73.217.35 45148 127.0.0.1 7081 --9096fa5d-B-- GET /img/ufo_fm.php?f=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2F.htaccess&p=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs&rm=1 HTTP/1.1 Host: ihelp.ro X-Real-IP: 216.73.217.35 X-Accel-Internal: /internal-nginx-static-location accept: */* user-agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com) accept-encoding: gzip, br, zstd, deflate --9096fa5d-F-- HTTP/1.1 200 OK X-Powered-By: PHP/8.1.34 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --9096fa5d-H-- Message: Warning. Match of "pm cpanel AdminTranslations" against "REQUEST_URI" required. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "65"] [id "77140882"] [msg "IM360 WAF: Infectors: Remote File Access Attempt||MVN:REQUEST_URI||MV:/img/ufo_fm.php?f=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2F.htaccess&p=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs&rm=1||T:APACHE||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Match of "pm cpanel AdminTranslations" against "REQUEST_URI" required. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "65"] [id "77140882"] [msg "IM360 WAF: Infectors: Remote File Access Attempt||MVN:REQUEST_URI||MV:/img/ufo_fm.php?f=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2F.htaccess&p=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs&rm=1||T:APACHE||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [hostname "ihelp.ro"] [uri "/img/ufo_fm.php"] [unique_id "apT2mtmUuou1H8H2UKXB3AAAANU"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788147354747689 37025 (- - -) Stopwatch2: 1788147354747689 37025; combined=33760, p1=378, p2=33328, p3=0, p4=0, p5=53, sr=129, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "DETECTION_ONLY" --9096fa5d-Z-- --c31cca52-A-- [31/Aug/2026:06:36:09.255535 +0300] apT2qW7fDIutYTwcPOkaEgAAAEc 216.73.217.35 54010 127.0.0.1 7081 --c31cca52-B-- GET /img/ufo_fm.php?dl=1&f=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2F.htaccess&p=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs HTTP/1.1 Host: ihelp.ro X-Real-IP: 216.73.217.35 X-Accel-Internal: /internal-nginx-static-location accept: */* user-agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com) accept-encoding: gzip, br, zstd, deflate --c31cca52-F-- HTTP/1.1 200 OK X-Powered-By: PHP/8.1.34 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --c31cca52-H-- Message: Warning. Match of "pm cpanel AdminTranslations" against "REQUEST_URI" required. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "65"] [id "77140882"] [msg "IM360 WAF: Infectors: Remote File Access Attempt||MVN:REQUEST_URI||MV:/img/ufo_fm.php?dl=1&f=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2F.htaccess&p=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs||T:APACHE||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Match of "pm cpanel AdminTranslations" against "REQUEST_URI" required. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "65"] [id "77140882"] [msg "IM360 WAF: Infectors: Remote File Access Attempt||MVN:REQUEST_URI||MV:/img/ufo_fm.php?dl=1&f=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2F.htaccess&p=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs||T:APACHE||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [hostname "ihelp.ro"] [uri "/img/ufo_fm.php"] [unique_id "apT2qW7fDIutYTwcPOkaEgAAAEc"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788147369218464 37119 (- - -) Stopwatch2: 1788147369218464 37119; combined=34546, p1=268, p2=34223, p3=0, p4=0, p5=55, sr=128, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "DETECTION_ONLY" --c31cca52-Z-- --cf618e21-A-- [31/Aug/2026:06:36:10.034061 +0300] apT2qtmUuou1H8H2UKXB7wAAAMc 216.73.217.35 54092 127.0.0.1 7081 --cf618e21-B-- GET /img/ufo_fm.php?f=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2Fwebroot%2F.htaccess&p=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2Fwebroot HTTP/1.1 Host: ihelp.ro X-Real-IP: 216.73.217.35 X-Accel-Internal: /internal-nginx-static-location accept: */* user-agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com) accept-encoding: gzip, br, zstd, deflate --cf618e21-F-- HTTP/1.1 200 OK X-Powered-By: PHP/8.1.34 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --cf618e21-H-- Message: Warning. Match of "pm cpanel AdminTranslations" against "REQUEST_URI" required. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "65"] [id "77140882"] [msg "IM360 WAF: Infectors: Remote File Access Attempt||MVN:REQUEST_URI||MV:/img/ufo_fm.php?f=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2Fwebroot%2F.htaccess&p=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2Fwebroot||T:APACHE||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Match of "pm cpanel AdminTranslations" against "REQUEST_URI" required. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "65"] [id "77140882"] [msg "IM360 WAF: Infectors: Remote File Access Attempt||MVN:REQUEST_URI||MV:/img/ufo_fm.php?f=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2Fwebroot%2F.htaccess&p=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2Fwebroot||T:APACHE||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [hostname "ihelp.ro"] [uri "/img/ufo_fm.php"] [unique_id "apT2qtmUuou1H8H2UKXB7wAAAMc"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788147370001236 32873 (- - -) Stopwatch2: 1788147370001236 32873; combined=30483, p1=203, p2=30232, p3=0, p4=0, p5=47, sr=78, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "DETECTION_ONLY" --cf618e21-Z-- --ebd6563c-A-- [31/Aug/2026:06:36:36.014925 +0300] apT2w37glkZrdsSdRApJCwAAAII 138.197.193.77 43740 127.0.0.1 7081 --ebd6563c-B-- POST /wp-login.php HTTP/1.1 Host: ajutam.ro X-Real-IP: 138.197.193.77 X-Accel-Internal: /internal-nginx-static-location Content-Length: 108 Accept: */* User-Agent: Mozilla/5.0 Content-Type: application/x-www-form-urlencoded Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818 --ebd6563c-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --ebd6563c-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:06-36.138.197.193.77"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788147395946407 68577 (- - -) Stopwatch2: 1788147395946407 68577; combined=67062, p1=322, p2=66096, p3=0, p4=0, p5=478, sr=129, sw=166, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --ebd6563c-Z-- --37873b20-A-- [31/Aug/2026:06:37:52.038879 +0300] apT3D9mUuou1H8H2UKXCFwAAAM8 216.73.217.35 53192 127.0.0.1 7081 --37873b20-B-- GET /img/ufo_fm.php?f=%27.%24enc.%27&p=%27.urlencode%28%24p%29.%27 HTTP/1.1 Host: ihelp.ro X-Real-IP: 216.73.217.35 X-Accel-Internal: /internal-nginx-static-location accept: */* user-agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com) accept-encoding: gzip, br, zstd, deflate --37873b20-F-- HTTP/1.1 200 OK X-Powered-By: PHP/8.1.34 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --37873b20-H-- Message: Warning. Pattern match "(?i)\\b(?:s(?:e(?:t(?:_(?:e(?:xception|rror)_handler|magic_quotes_runtime|include_path)|defaultstub)|ssion_s(?:et_save_handler|tart))|qlite_(?:(?:(?:unbuffered|single|array)_)?query|create_(?:aggregate|function)|p?open|exec)|tr(?:eam_(?:context_create| ..." at ARGS:p. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "63"] [id "77134464"] [msg "IM360 WAF: Infectors: PHP Injection High-Risk PHP Function||T:APACHE||MVN:ARGS:p||MV:'.urlencode($p).'||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_o"] [tag "service_i360"] Message: Warning. Pattern match "(?i)\\b(?:s(?:e(?:t(?:_(?:e(?:xception|rror)_handler|magic_quotes_runtime|include_path)|defaultstub)|ssion_s(?:et_save_handler|tart))|qlite_(?:(?:(?:unbuffered|single|array)_)?query|create_(?:aggregate|function)|p?open|exec)|tr(?:eam_(?:context_create| ..." at ARGS:p. [file "/etc/httpd/conf/modsecurity.d/rules/custom/012_i360_1_generic.conf"] [line "19"] [id "77134463"] [msg "IM360 WAF: PHP Injection Attack: High-Risk PHP Function Call Found||T:APACHE||MVN:ARGS:p||MV:'.urlencode($p).'||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "NOTICE"] [tag "service_o"] [tag "service_i360"] [tag "noshow"] [tag "service_rbl_infectors"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(?i)\\\\\\\\b(?:s(?:e(?:t(?:_(?:e(?:xception|rror)_handler|magic_quotes_runtime|include_path)|defaultstub)|ssion_s(?:et_save_handler|tart))|qlite_(?:(?:(?:unbuffered|single|array)_)?query|create_(?:aggregate|function)|p?open|exec)|tr(?:eam_(?:context_create| ..." at ARGS:p. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "63"] [id "77134464"] [msg "IM360 WAF: Infectors: PHP Injection High-Risk PHP Function||T:APACHE||MVN:ARGS:p||MV:'.urlencode($p).'||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_o"] [tag "service_i360"] [hostname "ihelp.ro"] [uri "/img/ufo_fm.php"] [unique_id "apT3D9mUuou1H8H2UKXCFwAAAM8"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(?i)\\\\\\\\b(?:s(?:e(?:t(?:_(?:e(?:xception|rror)_handler|magic_quotes_runtime|include_path)|defaultstub)|ssion_s(?:et_save_handler|tart))|qlite_(?:(?:(?:unbuffered|single|array)_)?query|create_(?:aggregate|function)|p?open|exec)|tr(?:eam_(?:context_create| ..." at ARGS:p. [file "/etc/httpd/conf/modsecurity.d/rules/custom/012_i360_1_generic.conf"] [line "19"] [id "77134463"] [msg "IM360 WAF: PHP Injection Attack: High-Risk PHP Function Call Found||T:APACHE||MVN:ARGS:p||MV:'.urlencode($p).'||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "NOTICE"] [tag "service_o"] [tag "service_i360"] [tag "noshow"] [tag "service_rbl_infectors"] [hostname "ihelp.ro"] [uri "/img/ufo_fm.php"] [unique_id "apT3D9mUuou1H8H2UKXCFwAAAM8"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788147471993993 44935 (- - -) Stopwatch2: 1788147471993993 44935; combined=38612, p1=275, p2=38231, p3=0, p4=0, p5=106, sr=114, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "DETECTION_ONLY" --37873b20-Z-- --050e0b57-A-- [31/Aug/2026:06:38:18.710033 +0300] apT3KtmUuou1H8H2UKXCHgAAANA 216.73.217.35 50862 127.0.0.1 7081 --050e0b57-B-- GET /img/ufo_fm.php?f=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2Fwebroot%2F.htaccess&p=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2Fwebroot&rm=1 HTTP/1.1 Host: ihelp.ro X-Real-IP: 216.73.217.35 X-Accel-Internal: /internal-nginx-static-location accept: */* user-agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com) accept-encoding: gzip, br, zstd, deflate --050e0b57-F-- HTTP/1.1 200 OK X-Powered-By: PHP/8.1.34 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --050e0b57-H-- Message: Warning. Match of "pm cpanel AdminTranslations" against "REQUEST_URI" required. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "65"] [id "77140882"] [msg "IM360 WAF: Infectors: Remote File Access Attempt||MVN:REQUEST_URI||MV:/img/ufo_fm.php?f=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2Fwebroot%2F.htaccess&p=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2Fwebroot&rm=1||T:APACHE||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Match of "pm cpanel AdminTranslations" against "REQUEST_URI" required. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "65"] [id "77140882"] [msg "IM360 WAF: Infectors: Remote File Access Attempt||MVN:REQUEST_URI||MV:/img/ufo_fm.php?f=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2Fwebroot%2F.htaccess&p=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2Fwebroot&rm=1||T:APACHE||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [hostname "ihelp.ro"] [uri "/img/ufo_fm.php"] [unique_id "apT3KtmUuou1H8H2UKXCHgAAANA"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788147498673823 36268 (- - -) Stopwatch2: 1788147498673823 36268; combined=33337, p1=281, p2=33010, p3=0, p4=0, p5=45, sr=130, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "DETECTION_ONLY" --050e0b57-Z-- --7f95b030-A-- [31/Aug/2026:06:38:19.979048 +0300] apT3K9mUuou1H8H2UKXCIwAAANY 216.73.217.35 50962 127.0.0.1 7081 --7f95b030-B-- GET /img/ufo_fm.php?dl=1&f=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2Fwebroot%2F.htaccess&p=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2Fwebroot HTTP/1.1 Host: ihelp.ro X-Real-IP: 216.73.217.35 X-Accel-Internal: /internal-nginx-static-location accept: */* user-agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com) accept-encoding: gzip, br, zstd, deflate --7f95b030-F-- HTTP/1.1 200 OK X-Powered-By: PHP/8.1.34 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --7f95b030-H-- Message: Warning. Match of "pm cpanel AdminTranslations" against "REQUEST_URI" required. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "65"] [id "77140882"] [msg "IM360 WAF: Infectors: Remote File Access Attempt||MVN:REQUEST_URI||MV:/img/ufo_fm.php?dl=1&f=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2Fwebroot%2F.htaccess&p=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2Fwebroot||T:APACHE||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Match of "pm cpanel AdminTranslations" against "REQUEST_URI" required. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "65"] [id "77140882"] [msg "IM360 WAF: Infectors: Remote File Access Attempt||MVN:REQUEST_URI||MV:/img/ufo_fm.php?dl=1&f=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2Fwebroot%2F.htaccess&p=%2Fvar%2Fwww%2Fvhosts%2Fihelp.ro%2Fhttpdocs%2Fwebroot||T:APACHE||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [hostname "ihelp.ro"] [uri "/img/ufo_fm.php"] [unique_id "apT3K9mUuou1H8H2UKXCIwAAANY"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788147499945526 33571 (- - -) Stopwatch2: 1788147499945526 33571; combined=31148, p1=230, p2=30867, p3=0, p4=0, p5=51, sr=87, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "DETECTION_ONLY" --7f95b030-Z-- --ecd73067-A-- [31/Aug/2026:06:38:43.164179 +0300] apT3Q37glkZrdsSdRApJKAAAAII 216.73.217.35 54824 127.0.0.1 7081 --ecd73067-B-- GET /img/ufo_fm.php?f=%27.%24enc.%27&p=%27.urlencode%28%24p%29.%27&rm=1 HTTP/1.1 Host: ihelp.ro X-Real-IP: 216.73.217.35 X-Accel-Internal: /internal-nginx-static-location accept: */* user-agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com) accept-encoding: gzip, br, zstd, deflate --ecd73067-F-- HTTP/1.1 200 OK X-Powered-By: PHP/8.1.34 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --ecd73067-H-- Message: Warning. Pattern match "(?i)\\b(?:s(?:e(?:t(?:_(?:e(?:xception|rror)_handler|magic_quotes_runtime|include_path)|defaultstub)|ssion_s(?:et_save_handler|tart))|qlite_(?:(?:(?:unbuffered|single|array)_)?query|create_(?:aggregate|function)|p?open|exec)|tr(?:eam_(?:context_create| ..." at ARGS:p. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "63"] [id "77134464"] [msg "IM360 WAF: Infectors: PHP Injection High-Risk PHP Function||T:APACHE||MVN:ARGS:p||MV:'.urlencode($p).'||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_o"] [tag "service_i360"] Message: Warning. Pattern match "(?i)\\b(?:s(?:e(?:t(?:_(?:e(?:xception|rror)_handler|magic_quotes_runtime|include_path)|defaultstub)|ssion_s(?:et_save_handler|tart))|qlite_(?:(?:(?:unbuffered|single|array)_)?query|create_(?:aggregate|function)|p?open|exec)|tr(?:eam_(?:context_create| ..." at ARGS:p. [file "/etc/httpd/conf/modsecurity.d/rules/custom/012_i360_1_generic.conf"] [line "19"] [id "77134463"] [msg "IM360 WAF: PHP Injection Attack: High-Risk PHP Function Call Found||T:APACHE||MVN:ARGS:p||MV:'.urlencode($p).'||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "NOTICE"] [tag "service_o"] [tag "service_i360"] [tag "noshow"] [tag "service_rbl_infectors"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(?i)\\\\\\\\b(?:s(?:e(?:t(?:_(?:e(?:xception|rror)_handler|magic_quotes_runtime|include_path)|defaultstub)|ssion_s(?:et_save_handler|tart))|qlite_(?:(?:(?:unbuffered|single|array)_)?query|create_(?:aggregate|function)|p?open|exec)|tr(?:eam_(?:context_create| ..." at ARGS:p. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "63"] [id "77134464"] [msg "IM360 WAF: Infectors: PHP Injection High-Risk PHP Function||T:APACHE||MVN:ARGS:p||MV:'.urlencode($p).'||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_o"] [tag "service_i360"] [hostname "ihelp.ro"] [uri "/img/ufo_fm.php"] [unique_id "apT3Q37glkZrdsSdRApJKAAAAII"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(?i)\\\\\\\\b(?:s(?:e(?:t(?:_(?:e(?:xception|rror)_handler|magic_quotes_runtime|include_path)|defaultstub)|ssion_s(?:et_save_handler|tart))|qlite_(?:(?:(?:unbuffered|single|array)_)?query|create_(?:aggregate|function)|p?open|exec)|tr(?:eam_(?:context_create| ..." at ARGS:p. [file "/etc/httpd/conf/modsecurity.d/rules/custom/012_i360_1_generic.conf"] [line "19"] [id "77134463"] [msg "IM360 WAF: PHP Injection Attack: High-Risk PHP Function Call Found||T:APACHE||MVN:ARGS:p||MV:'.urlencode($p).'||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "NOTICE"] [tag "service_o"] [tag "service_i360"] [tag "noshow"] [tag "service_rbl_infectors"] [hostname "ihelp.ro"] [uri "/img/ufo_fm.php"] [unique_id "apT3Q37glkZrdsSdRApJKAAAAII"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788147523129051 35174 (- - -) Stopwatch2: 1788147523129051 35174; combined=32591, p1=196, p2=32294, p3=0, p4=0, p5=101, sr=82, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "DETECTION_ONLY" --ecd73067-Z-- --3ff26137-A-- [31/Aug/2026:06:39:15.969288 +0300] apT3Y37glkZrdsSdRApJKQAAAJM 138.197.193.77 56892 127.0.0.1 7081 --3ff26137-B-- POST /wp-login.php HTTP/1.1 Host: ajutam.ro X-Real-IP: 138.197.193.77 X-Accel-Internal: /internal-nginx-static-location Content-Length: 110 Accept: */* User-Agent: Mozilla/5.0 Content-Type: application/x-www-form-urlencoded Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818 --3ff26137-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --3ff26137-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "42"] [id "33302"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:1"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788147555967468 1890 (- - -) Stopwatch2: 1788147555967468 1890; combined=595, p1=257, p2=84, p3=0, p4=0, p5=254, sr=108, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --3ff26137-Z-- --2a0ce25c-A-- [31/Aug/2026:06:39:39.472364 +0300] apT3e9mUuou1H8H2UKXCMQAAANY 216.73.217.35 55910 127.0.0.1 7081 --2a0ce25c-B-- GET /img/ufo_fm.php?dl=1&f=%27.%24enc.%27&p=%27.urlencode%28%24p%29.%27 HTTP/1.1 Host: ihelp.ro X-Real-IP: 216.73.217.35 X-Accel-Internal: /internal-nginx-static-location accept: */* user-agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com) accept-encoding: gzip, br, zstd, deflate --2a0ce25c-F-- HTTP/1.1 200 OK X-Powered-By: PHP/8.1.34 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --2a0ce25c-H-- Message: Warning. Pattern match "(?i)\\b(?:s(?:e(?:t(?:_(?:e(?:xception|rror)_handler|magic_quotes_runtime|include_path)|defaultstub)|ssion_s(?:et_save_handler|tart))|qlite_(?:(?:(?:unbuffered|single|array)_)?query|create_(?:aggregate|function)|p?open|exec)|tr(?:eam_(?:context_create| ..." at ARGS:p. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "63"] [id "77134464"] [msg "IM360 WAF: Infectors: PHP Injection High-Risk PHP Function||T:APACHE||MVN:ARGS:p||MV:'.urlencode($p).'||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_o"] [tag "service_i360"] Message: Warning. Pattern match "(?i)\\b(?:s(?:e(?:t(?:_(?:e(?:xception|rror)_handler|magic_quotes_runtime|include_path)|defaultstub)|ssion_s(?:et_save_handler|tart))|qlite_(?:(?:(?:unbuffered|single|array)_)?query|create_(?:aggregate|function)|p?open|exec)|tr(?:eam_(?:context_create| ..." at ARGS:p. [file "/etc/httpd/conf/modsecurity.d/rules/custom/012_i360_1_generic.conf"] [line "19"] [id "77134463"] [msg "IM360 WAF: PHP Injection Attack: High-Risk PHP Function Call Found||T:APACHE||MVN:ARGS:p||MV:'.urlencode($p).'||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "NOTICE"] [tag "service_o"] [tag "service_i360"] [tag "noshow"] [tag "service_rbl_infectors"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(?i)\\\\\\\\b(?:s(?:e(?:t(?:_(?:e(?:xception|rror)_handler|magic_quotes_runtime|include_path)|defaultstub)|ssion_s(?:et_save_handler|tart))|qlite_(?:(?:(?:unbuffered|single|array)_)?query|create_(?:aggregate|function)|p?open|exec)|tr(?:eam_(?:context_create| ..." at ARGS:p. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "63"] [id "77134464"] [msg "IM360 WAF: Infectors: PHP Injection High-Risk PHP Function||T:APACHE||MVN:ARGS:p||MV:'.urlencode($p).'||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "DEBUG"] [tag "service_o"] [tag "service_i360"] [hostname "ihelp.ro"] [uri "/img/ufo_fm.php"] [unique_id "apT3e9mUuou1H8H2UKXCMQAAANY"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(?i)\\\\\\\\b(?:s(?:e(?:t(?:_(?:e(?:xception|rror)_handler|magic_quotes_runtime|include_path)|defaultstub)|ssion_s(?:et_save_handler|tart))|qlite_(?:(?:(?:unbuffered|single|array)_)?query|create_(?:aggregate|function)|p?open|exec)|tr(?:eam_(?:context_create| ..." at ARGS:p. [file "/etc/httpd/conf/modsecurity.d/rules/custom/012_i360_1_generic.conf"] [line "19"] [id "77134463"] [msg "IM360 WAF: PHP Injection Attack: High-Risk PHP Function Call Found||T:APACHE||MVN:ARGS:p||MV:'.urlencode($p).'||SC:/var/www/vhosts/ihelp.ro/httpdocs/img"] [severity "NOTICE"] [tag "service_o"] [tag "service_i360"] [tag "noshow"] [tag "service_rbl_infectors"] [hostname "ihelp.ro"] [uri "/img/ufo_fm.php"] [unique_id "apT3e9mUuou1H8H2UKXCMQAAANY"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788147579435229 37192 (- - -) Stopwatch2: 1788147579435229 37192; combined=33980, p1=389, p2=33525, p3=0, p4=0, p5=65, sr=160, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "DETECTION_ONLY" --2a0ce25c-Z-- --27f8364d-A-- [31/Aug/2026:06:39:52.134583 +0300] apT3iH7glkZrdsSdRApJNwAAAI8 207.154.219.81 52340 127.0.0.1 7081 --27f8364d-B-- POST /wp-login.php HTTP/1.1 Host: ajutam.ro X-Real-IP: 207.154.219.81 X-Accel-Internal: /internal-nginx-static-location Content-Length: 110 Accept: */* User-Agent: Mozilla/5.0 Content-Type: application/x-www-form-urlencoded Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818 --27f8364d-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --27f8364d-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:06-39.207.154.219.81"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788147592074826 59879 (- - -) Stopwatch2: 1788147592074826 59879; combined=58193, p1=246, p2=57181, p3=0, p4=0, p5=553, sr=92, sw=213, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --27f8364d-Z-- --ec426506-A-- [31/Aug/2026:06:40:33.059710 +0300] apT3sH7glkZrdsSdRApJPAAAAJc 45.79.180.146 54096 127.0.0.1 7081 --ec426506-B-- POST /wp-login.php HTTP/1.1 Host: axapres.ro X-Real-IP: 45.79.180.146 X-Accel-Internal: /internal-nginx-static-location Content-Length: 98 Accept: */* Accept-Encoding: gzip, deflate Cookie: wordpress_test_cookie=WP+Cookie+check User-Agent: Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.43 (KHTML, like Gecko) Chrome/139.0.0.0 Safari/537.36 OPR/123.0.0.0 Content-Type: application/x-www-form-urlencoded --ec426506-F-- HTTP/1.1 403 Forbidden Content-Length: 199 Content-Type: text/html; charset=iso-8859-1 --ec426506-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:06-40.45.79.180.146"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Apache-Handler: proxy:unix:/var/www/vhosts/system/axapres.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788147632995695 64071 (- - -) Stopwatch2: 1788147632995695 64071; combined=62215, p1=523, p2=60937, p3=0, p4=0, p5=526, sr=254, sw=229, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --ec426506-Z-- --f9b03763-A-- [31/Aug/2026:06:44:44.762206 +0300] apT4rH7glkZrdsSdRApJSwAAAJA 138.197.193.77 51650 127.0.0.1 7081 --f9b03763-B-- POST /wp-login.php HTTP/1.1 Host: ajutam.ro X-Real-IP: 138.197.193.77 X-Accel-Internal: /internal-nginx-static-location Content-Length: 111 Accept: */* User-Agent: Mozilla/5.0 Content-Type: application/x-www-form-urlencoded Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818 --f9b03763-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --f9b03763-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:06-44.138.197.193.77"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788147884692831 69450 (- - -) Stopwatch2: 1788147884692831 69450; combined=76813, p1=262, p2=58315, p3=0, p4=0, p5=9266, sr=110, sw=148, l=0, gc=8822 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --f9b03763-Z-- --1c88b226-A-- [31/Aug/2026:06:46:37.830846 +0300] apT5HX7glkZrdsSdRApJUAAAAI8 207.154.219.81 36712 127.0.0.1 7081 --1c88b226-B-- POST /wp-login.php HTTP/1.1 Host: ajutam.ro X-Real-IP: 207.154.219.81 X-Accel-Internal: /internal-nginx-static-location Content-Length: 109 Accept: */* User-Agent: Mozilla/5.0 Content-Type: application/x-www-form-urlencoded Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818 --1c88b226-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --1c88b226-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:06-46.207.154.219.81"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788147997769009 61900 (- - -) Stopwatch2: 1788147997769009 61900; combined=60041, p1=261, p2=58836, p3=0, p4=0, p5=664, sr=114, sw=280, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --1c88b226-Z-- --1ea68b55-A-- [31/Aug/2026:06:52:06.470030 +0300] apT6Zm7fDIutYTwcPOkaMwAAAFM 138.197.193.77 38052 127.0.0.1 7081 --1ea68b55-B-- POST /wp-login.php HTTP/1.1 Host: ajutam.ro X-Real-IP: 138.197.193.77 X-Accel-Internal: /internal-nginx-static-location Content-Length: 108 Accept: */* User-Agent: Mozilla/5.0 Content-Type: application/x-www-form-urlencoded Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818 --1ea68b55-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --1ea68b55-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:06-52.138.197.193.77"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788148326406234 63866 (- - -) Stopwatch2: 1788148326406234 63866; combined=62168, p1=349, p2=61283, p3=0, p4=0, p5=409, sr=140, sw=127, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --1ea68b55-Z-- --1cc20c58-A-- [31/Aug/2026:06:53:12.666337 +0300] apT6qNmUuou1H8H2UKXCjAAAANI 207.154.219.81 45260 127.0.0.1 7081 --1cc20c58-B-- POST /wp-login.php HTTP/1.1 Host: ajutam.ro X-Real-IP: 207.154.219.81 X-Accel-Internal: /internal-nginx-static-location Content-Length: 108 Accept: */* User-Agent: Mozilla/5.0 Content-Type: application/x-www-form-urlencoded Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818 --1cc20c58-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --1cc20c58-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:06-53.207.154.219.81"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788148392603552 62871 (- - -) Stopwatch2: 1788148392603552 62871; combined=60050, p1=262, p2=59081, p3=0, p4=0, p5=520, sr=109, sw=187, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --1cc20c58-Z-- --d8a1f45a-A-- [31/Aug/2026:06:53:43.149580 +0300] apT6x9mUuou1H8H2UKXCjgAAAM8 167.86.74.74 57124 127.0.0.1 7081 --d8a1f45a-B-- GET /.env HTTP/1.1 Host: funshop.ro X-Real-IP: 167.86.74.74 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36 Accept-Encoding: gzip, deflate Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,image/apng,*/*;q=0.8 Cache-Control: max-age=0 Upgrade-Insecure-Requests: 1 Accept-Language: en-US,en;q=0.9,fr;q=0.8 --d8a1f45a-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --d8a1f45a-E-- --d8a1f45a-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "funshop.ro"] [uri "/.env"] [unique_id "apT6x9mUuou1H8H2UKXCjgAAAM8"] Stopwatch: 1788148423142296 7424 (- - -) Stopwatch2: 1788148423142296 7424; combined=5214, p1=385, p2=4716, p3=61, p4=7, p5=45, sr=123, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --d8a1f45a-Z-- --82a6bb27-A-- [31/Aug/2026:06:59:33.015303 +0300] apT8JNmUuou1H8H2UKXCrQAAAMI 138.197.193.77 44908 127.0.0.1 7081 --82a6bb27-B-- POST /wp-login.php HTTP/1.1 Host: ajutam.ro X-Real-IP: 138.197.193.77 X-Accel-Internal: /internal-nginx-static-location Content-Length: 123 Accept: */* User-Agent: Mozilla/5.0 Content-Type: application/x-www-form-urlencoded Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818 --82a6bb27-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --82a6bb27-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:06-59.138.197.193.77"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788148772957215 58163 (- - -) Stopwatch2: 1788148772957215 58163; combined=56605, p1=261, p2=55735, p3=0, p4=0, p5=452, sr=105, sw=157, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --82a6bb27-Z-- --362db907-A-- [31/Aug/2026:06:59:49.057166 +0300] apT8NNmUuou1H8H2UKXCsQAAANc 207.154.219.81 42046 127.0.0.1 7081 --362db907-B-- POST /wp-login.php HTTP/1.1 Host: ajutam.ro X-Real-IP: 207.154.219.81 X-Accel-Internal: /internal-nginx-static-location Content-Length: 126 Accept: */* User-Agent: Mozilla/5.0 Content-Type: application/x-www-form-urlencoded Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818 --362db907-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --362db907-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:06-59.207.154.219.81"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788148788998178 59045 (- - -) Stopwatch2: 1788148788998178 59045; combined=57671, p1=235, p2=56944, p3=0, p4=0, p5=363, sr=92, sw=129, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --362db907-Z-- --dd37854e-A-- [31/Aug/2026:07:05:50.012376 +0300] apT9ndmUuou1H8H2UKXC8AAAAMI 129.213.185.111 40292 127.0.0.1 7081 --dd37854e-B-- GET /wp-json/wp/v2/users/me HTTP/1.1 Host: ajutam.ro X-Real-IP: 129.213.185.111 X-Accel-Internal: /internal-nginx-static-location Authorization: Basic YWRtaW46YWRtaW4yMDEw Accept: application/json Accept-Language: en-US,en;q=0.9 Sec-Ch-Ua: "Not=A?Brand";v="99", "Google Chrome";v="151", "Chromium";v="151" Sec-Ch-Ua-Mobile: ?0 Sec-Ch-Ua-Platform: "Windows" User-Agent: 129.213.185.111 Accept-Encoding: gzip, deflate, br --dd37854e-F-- HTTP/1.1 401 Unauthorized X-Powered-By: PHP/7.3.33 X-Robots-Tag: noindex Link: <https://ajutam.ro/wp-json/>; rel="https://api.w.org/" X-Content-Type-Options: nosniff Access-Control-Expose-Headers: X-WP-Total, X-WP-TotalPages, Link Access-Control-Allow-Headers: Authorization, X-WP-Nonce, Content-Disposition, Content-MD5, Content-Type Allow: GET Vary: Origin Transfer-Encoding: chunked Content-Type: application/json; charset=UTF-8 --dd37854e-H-- Message: String match "wp-json/wp/v2/users" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "80"] [id "77140942"] [msg "IM360 WAF: Block WordPress 5.3 User Enumeration attempts||T:APACHE||MV:/wp-json/wp/v2/users/me||"] [severity "DEBUG"] [tag "service_i360custom"] [tag "wp_core"] Message: Operator EQ matched 0 at REQUEST_COOKIES. [file "/etc/httpd/conf/modsecurity.d/rules/custom/007_i360_4_wordpress.conf"] [line "426"] [id "77316783"] [msg "IM360 WAF: Monitoring WordPress 5.3 User Enumeration attempts||T:APACHE||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "wp_core"] [tag "noshow"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ajutam.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788149149639599 372866 (- - -) Stopwatch2: 1788149149639599 372866; combined=34092, p1=314, p2=33726, p3=0, p4=0, p5=51, sr=109, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --dd37854e-Z-- --affea921-A-- [31/Aug/2026:07:06:43.457590 +0300] apT909mUuou1H8H2UKXC@AAAAMo 207.154.219.81 48528 127.0.0.1 7081 --affea921-B-- POST /wp-login.php HTTP/1.1 Host: ajutam.ro X-Real-IP: 207.154.219.81 X-Accel-Internal: /internal-nginx-static-location Content-Length: 111 Accept: */* User-Agent: Mozilla/5.0 Content-Type: application/x-www-form-urlencoded Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818 --affea921-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --affea921-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:07-06.207.154.219.81"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788149203394192 63498 (- - -) Stopwatch2: 1788149203394192 63498; combined=62081, p1=257, p2=61319, p3=0, p4=0, p5=376, sr=84, sw=129, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --affea921-Z-- --907f2133-A-- [31/Aug/2026:07:07:38.530316 +0300] apT@Cn7glkZrdsSdRApJgQAAAIg 138.197.193.77 36694 127.0.0.1 7081 --907f2133-B-- POST /wp-login.php HTTP/1.1 Host: ajutam.ro X-Real-IP: 138.197.193.77 X-Accel-Internal: /internal-nginx-static-location Content-Length: 105 Accept: */* User-Agent: Mozilla/5.0 Content-Type: application/x-www-form-urlencoded Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818 --907f2133-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --907f2133-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:07-07.138.197.193.77"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788149258466383 63993 (- - -) Stopwatch2: 1788149258466383 63993; combined=60481, p1=364, p2=59569, p3=0, p4=0, p5=408, sr=133, sw=140, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --907f2133-Z-- --c779ad40-A-- [31/Aug/2026:07:11:58.878858 +0300] apT-DtmUuou1H8H2UKXDFwAAANA 82.223.5.23 49652 127.0.0.1 7081 --c779ad40-B-- POST / HTTP/1.1 Host: www.ihelp.ro X-Real-IP: 82.223.5.23 X-Accel-Internal: /internal-nginx-static-location Content-Length: 0 User-agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36 Accept-Encoding: gzip, deflate Accept: */* --c779ad40-F-- HTTP/1.1 403 Forbidden X-Powered-By: PHP/8.1.34 X-DEBUGKIT-ID: a0c0409b-70cd-40b2-aecd-04c53a601f20 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --c779ad40-H-- Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788149518698777 180157 (- - -) Stopwatch2: 1788149518698777 180157; combined=10573, p1=429, p2=9764, p3=0, p4=0, p5=379, sr=188, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "DETECTION_ONLY" --c779ad40-Z-- --6af12851-A-- [31/Aug/2026:07:11:59.696280 +0300] apT-D37glkZrdsSdRApJigAAAIQ 82.223.5.23 49654 127.0.0.1 7081 --6af12851-B-- POST /debug/default/view?panel=config HTTP/1.1 Host: www.ihelp.ro X-Real-IP: 82.223.5.23 X-Accel-Internal: /internal-nginx-static-location Content-Length: 0 User-agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36 Accept-Encoding: gzip, deflate Accept: */* --6af12851-F-- HTTP/1.1 403 Forbidden X-Powered-By: PHP/8.1.34 X-DEBUGKIT-ID: 01a10848-fbaa-40c9-92b3-5b6586c24bb4 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --6af12851-H-- Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G:panel=config& P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788149519555346 141024 (- - -) Stopwatch2: 1788149519555346 141024; combined=10895, p1=2453, p2=8049, p3=0, p4=0, p5=393, sr=299, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "DETECTION_ONLY" --6af12851-Z-- --7b83c96d-A-- [31/Aug/2026:07:12:00.499373 +0300] apT-ENmUuou1H8H2UKXDGAAAAMI 82.223.5.23 49658 127.0.0.1 7081 --7b83c96d-B-- POST /tool/view/phpinfo.view.php HTTP/1.1 Host: www.ihelp.ro X-Real-IP: 82.223.5.23 X-Accel-Internal: /internal-nginx-static-location Content-Length: 0 User-agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36 Accept-Encoding: gzip, deflate Accept: */* --7b83c96d-F-- HTTP/1.1 403 Forbidden X-Powered-By: PHP/8.1.34 X-DEBUGKIT-ID: 5e88358a-3801-425b-9e9a-38ae1d3e8a01 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --7b83c96d-H-- Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788149520363845 135593 (- - -) Stopwatch2: 1788149520363845 135593; combined=6798, p1=1770, p2=4695, p3=0, p4=0, p5=332, sr=190, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "DETECTION_ONLY" --7b83c96d-Z-- --ee575677-A-- [31/Aug/2026:07:12:01.216848 +0300] apT-EW7fDIutYTwcPOkaTQAAAFQ 82.223.5.23 49666 127.0.0.1 7081 --ee575677-B-- POST /wp-config.php-backup HTTP/1.1 Host: www.ihelp.ro X-Real-IP: 82.223.5.23 X-Accel-Internal: /internal-nginx-static-location Content-Length: 0 User-agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36 Accept-Encoding: gzip, deflate Accept: */* --ee575677-F-- HTTP/1.1 403 Forbidden X-Powered-By: PHP/8.1.34 X-DEBUGKIT-ID: 51f9f82c-e500-445a-b838-c47b0d10fc03 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --ee575677-H-- Message: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "www.ihelp.ro"] [uri "/wp-config.php-backup"] [unique_id "apT-EW7fDIutYTwcPOkaTQAAAFQ"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ihelp.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788149521089838 127074 (- - -) Stopwatch2: 1788149521089838 127074; combined=7112, p1=534, p2=6190, p3=0, p4=0, p5=388, sr=153, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "DETECTION_ONLY" --ee575677-Z-- --49fadb5d-A-- [31/Aug/2026:07:13:31.176583 +0300] apT-a9mUuou1H8H2UKXDHgAAAMQ 207.154.219.81 40214 127.0.0.1 7081 --49fadb5d-B-- POST /wp-login.php HTTP/1.1 Host: ajutam.ro X-Real-IP: 207.154.219.81 X-Accel-Internal: /internal-nginx-static-location Content-Length: 111 Accept: */* User-Agent: Mozilla/5.0 Content-Type: application/x-www-form-urlencoded Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818 --49fadb5d-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --49fadb5d-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:07-13.207.154.219.81"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788149611115485 61305 (- - -) Stopwatch2: 1788149611115485 61305; combined=58220, p1=729, p2=56453, p3=0, p4=0, p5=784, sr=333, sw=254, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --49fadb5d-Z-- --31de385b-A-- [31/Aug/2026:07:15:45.271723 +0300] apT-8dmUuou1H8H2UKXDJQAAAMI 138.197.193.77 60782 127.0.0.1 7081 --31de385b-B-- POST /wp-login.php HTTP/1.1 Host: ajutam.ro X-Real-IP: 138.197.193.77 X-Accel-Internal: /internal-nginx-static-location Content-Length: 108 Accept: */* User-Agent: Mozilla/5.0 Content-Type: application/x-www-form-urlencoded Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818 --31de385b-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --31de385b-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:07-15.138.197.193.77"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788149745202938 68862 (- - -) Stopwatch2: 1788149745202938 68862; combined=60549, p1=1008, p2=58667, p3=0, p4=0, p5=610, sr=776, sw=264, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --31de385b-Z-- --586c565d-A-- [31/Aug/2026:07:20:16.338771 +0300] apUBANmUuou1H8H2UKXDcQAAANE 207.154.219.81 55996 127.0.0.1 7081 --586c565d-B-- POST /wp-login.php HTTP/1.1 Host: ajutam.ro X-Real-IP: 207.154.219.81 X-Accel-Internal: /internal-nginx-static-location Content-Length: 109 Accept: */* User-Agent: Mozilla/5.0 Content-Type: application/x-www-form-urlencoded Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818 --586c565d-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --586c565d-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:07-20.207.154.219.81"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788150016276103 62740 (- - -) Stopwatch2: 1788150016276103 62740; combined=61065, p1=364, p2=59933, p3=0, p4=0, p5=560, sr=168, sw=208, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --586c565d-Z-- --4670bd65-A-- [31/Aug/2026:07:23:50.532405 +0300] apUB1n7glkZrdsSdRApJqgAAAJM 138.197.193.77 42428 127.0.0.1 7081 --4670bd65-B-- POST /wp-login.php HTTP/1.1 Host: ajutam.ro X-Real-IP: 138.197.193.77 X-Accel-Internal: /internal-nginx-static-location Content-Length: 110 Accept: */* User-Agent: Mozilla/5.0 Content-Type: application/x-www-form-urlencoded Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818 --4670bd65-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --4670bd65-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:07-23.138.197.193.77"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788150230467385 65095 (- - -) Stopwatch2: 1788150230467385 65095; combined=62275, p1=555, p2=60732, p3=0, p4=0, p5=749, sr=269, sw=239, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --4670bd65-Z-- --cdd3540e-A-- [31/Aug/2026:07:27:14.068113 +0300] apUCotmUuou1H8H2UKXDigAAANE 207.154.219.81 42546 127.0.0.1 7081 --cdd3540e-B-- POST /wp-login.php HTTP/1.1 Host: ajutam.ro X-Real-IP: 207.154.219.81 X-Accel-Internal: /internal-nginx-static-location Content-Length: 109 Accept: */* User-Agent: Mozilla/5.0 Content-Type: application/x-www-form-urlencoded Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818 --cdd3540e-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --cdd3540e-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:07-27.207.154.219.81"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788150434006496 61728 (- - -) Stopwatch2: 1788150434006496 61728; combined=59381, p1=373, p2=58266, p3=0, p4=0, p5=581, sr=128, sw=161, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --cdd3540e-Z-- --6df58a70-A-- [31/Aug/2026:07:27:45.301112 +0300] apUCwCfaLSuAj0yzdueTCgAAABA 137.131.61.214 58094 127.0.0.1 7081 --6df58a70-B-- GET /xmlrpc.php HTTP/1.1 Host: ajutam.ro X-Real-IP: 137.131.61.214 X-Accel-Internal: /internal-nginx-static-location User-Agent: AteveSearchSourceUrlDiscovery/0.1 (+mailto:crawler@example.com) Accept: */* Accept-Encoding: gzip, deflate --6df58a70-F-- HTTP/1.1 405 Method Not Allowed X-Powered-By: PHP/7.3.33 Allow: POST Transfer-Encoding: chunked Content-Type: text/plain;charset=UTF-8 --6df58a70-E-- --6df58a70-H-- Message: Warning. String match "xmlrpc.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "290"] [id "77141064"] [msg "IM360 WAF: CMS Recon Bot detected||MVN:REQUEST_FILENAME||T:APACHE||MV:/xmlrpc.php||RM:GET"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "xmlrpc.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "290"] [id "77141064"] [msg "IM360 WAF: CMS Recon Bot detected||MVN:REQUEST_FILENAME||T:APACHE||MV:/xmlrpc.php||RM:GET"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "ajutam.ro"] [uri "/xmlrpc.php"] [unique_id "apUCwCfaLSuAj0yzdueTCgAAABA"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ajutam.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150464940461 360768 (- - -) Stopwatch2: 1788150464940461 360768; combined=10875, p1=3025, p2=7552, p3=205, p4=15, p5=78, sr=245, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --6df58a70-Z-- --59d9c27f-A-- [31/Aug/2026:07:28:00.213224 +0300] apUCz37glkZrdsSdRApJtgAAAIs 137.131.61.214 44832 127.0.0.1 7081 --59d9c27f-B-- GET /xmlrpc.php?rsd= HTTP/1.1 Host: ajutam.ro X-Real-IP: 137.131.61.214 X-Accel-Internal: /internal-nginx-static-location User-Agent: AteveSearchSourceUrlDiscovery/0.1 (+mailto:crawler@example.com) Accept: */* Accept-Encoding: gzip, deflate --59d9c27f-F-- HTTP/1.1 200 OK X-Powered-By: PHP/7.3.33 Transfer-Encoding: chunked Content-Type: text/xml; charset=UTF-8 --59d9c27f-E-- --59d9c27f-H-- Message: Warning. String match "xmlrpc.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "290"] [id "77141064"] [msg "IM360 WAF: CMS Recon Bot detected||MVN:REQUEST_FILENAME||T:APACHE||MV:/xmlrpc.php||RM:GET"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Message: Warning. Operator GT matched 0 at ARGS. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "529"] [id "77317945"] [msg "IM360 WAF: Really Simple Discovery to xmlrpc||MVN:ARGS||MV:1||T:APACHE||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "xmlrpc.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "290"] [id "77141064"] [msg "IM360 WAF: CMS Recon Bot detected||MVN:REQUEST_FILENAME||T:APACHE||MV:/xmlrpc.php||RM:GET"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "ajutam.ro"] [uri "/xmlrpc.php"] [unique_id "apUCz37glkZrdsSdRApJtgAAAIs"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Operator GT matched 0 at ARGS. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "529"] [id "77317945"] [msg "IM360 WAF: Really Simple Discovery to xmlrpc||MVN:ARGS||MV:1||T:APACHE||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "ajutam.ro"] [uri "/xmlrpc.php"] [unique_id "apUCz37glkZrdsSdRApJtgAAAIs"] Apache-Handler: proxy:unix:/var/www/vhosts/system/ajutam.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150479938092 275243 (- - -) Stopwatch2: 1788150479938092 275243; combined=7404, p1=667, p2=6374, p3=182, p4=75, p5=106, sr=231, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --59d9c27f-Z-- --9af7f705-A-- [31/Aug/2026:07:30:10.735649 +0300] apUDUm7fDIutYTwcPOkabQAAAEQ 120.133.60.156 54968 127.0.0.1 7081 --9af7f705-B-- POST /wp-login.php HTTP/1.1 Host: axapres.ro X-Real-IP: 120.133.60.156 X-Accel-Internal: /internal-nginx-static-location Content-Length: 107 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8 Accept-Language: en-US,en;q=0.5 Content-Type: application/x-www-form-urlencoded Cookie: wordpress_test_cookie=WP+Cookie+check Origin: https://axapres.ro Referer: https://axapres.ro/wp-login.php --9af7f705-F-- HTTP/1.1 403 Forbidden Content-Length: 199 Content-Type: text/html; charset=iso-8859-1 --9af7f705-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:07-30.120.133.60.156"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Apache-Handler: proxy:unix:/var/www/vhosts/system/axapres.ro/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150610658910 76859 (- - -) Stopwatch2: 1788150610658910 76859; combined=76077, p1=680, p2=59572, p3=0, p4=0, p5=8099, sr=377, sw=238, l=0, gc=7488 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --9af7f705-Z-- --d1310e0f-A-- [31/Aug/2026:07:31:19.726606 +0300] apUDl9mUuou1H8H2UKXD6AAAAM0 34.73.181.25 43486 127.0.0.1 7081 --d1310e0f-B-- GET /.git/config HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 172.26.241.90 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 172.26.241.90 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 172.26.241.90 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 172.26.241.90 Upgrade-Insecure-Requests: 1 X-Client-Ip: 172.26.241.90 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 172.26.241.90 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --d1310e0f-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --d1310e0f-H-- Message: Warning. Matched phrase "/.git/config" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.git/config||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Matched phrase "/.git/config" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.git/config||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Message: Warning. String match "/.git/" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "656"] [id "77318034"] [msg "IM360 WAF: Blocked access to git folder||T:APACHE||MV:/.git/config||"] [severity "NOTICE"] [tag "service_i360custom"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "/.git/config" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.git/config||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/.git/config"] [unique_id "apUDl9mUuou1H8H2UKXD6AAAAM0"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "/.git/config" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.git/config||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/.git/config"] [unique_id "apUDl9mUuou1H8H2UKXD6AAAAM0"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.git/" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "656"] [id "77318034"] [msg "IM360 WAF: Blocked access to git folder||T:APACHE||MV:/.git/config||"] [severity "NOTICE"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/.git/config"] [unique_id "apUDl9mUuou1H8H2UKXD6AAAAM0"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150679486485 240285 (- - -) Stopwatch2: 1788150679486485 240285; combined=34445, p1=327, p2=34044, p3=0, p4=0, p5=74, sr=110, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --d1310e0f-Z-- --9df72169-A-- [31/Aug/2026:07:31:19.880502 +0300] apUDl9mUuou1H8H2UKXD4wAAANQ 34.73.181.25 43410 127.0.0.1 7081 --9df72169-B-- GET /.git/HEAD HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 172.30.50.136 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 172.30.50.136 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 172.30.50.136 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 172.30.50.136 Upgrade-Insecure-Requests: 1 X-Client-Ip: 172.30.50.136 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 172.30.50.136 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --9df72169-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --9df72169-H-- Message: Warning. String match "/.git/" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "656"] [id "77318034"] [msg "IM360 WAF: Blocked access to git folder||T:APACHE||MV:/.git/head||"] [severity "NOTICE"] [tag "service_i360custom"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.git/" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "656"] [id "77318034"] [msg "IM360 WAF: Blocked access to git folder||T:APACHE||MV:/.git/head||"] [severity "NOTICE"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/.git/HEAD"] [unique_id "apUDl9mUuou1H8H2UKXD4wAAANQ"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150679342114 538480 (- - -) Stopwatch2: 1788150679342114 538480; combined=7236, p1=273, p2=6904, p3=0, p4=0, p5=59, sr=82, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --9df72169-Z-- --39a0cb12-A-- [31/Aug/2026:07:31:19.900591 +0300] apUDl9mUuou1H8H2UKXD6QAAANU 34.73.181.25 43498 127.0.0.1 7081 --39a0cb12-B-- POST /graphql HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Accel-Internal: /internal-nginx-static-location Content-Length: 86 User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: */* Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Content-Type: application/json Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Origin: https://alexandervodka.com Referer: https://alexandervodka.com Sec-Fetch-Dest: empty Sec-Fetch-Mode: cors Sec-Fetch-Site: same-origin sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --39a0cb12-F-- HTTP/1.1 403 Forbidden X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --39a0cb12-H-- Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150679527968 372725 (- - -) Stopwatch2: 1788150679527968 372725; combined=5718, p1=274, p2=5168, p3=0, p4=0, p5=276, sr=93, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --39a0cb12-Z-- --bc460e5a-A-- [31/Aug/2026:07:31:19.940423 +0300] apUDl37glkZrdsSdRApJ1gAAAJA 34.73.181.25 43552 127.0.0.1 7081 --bc460e5a-B-- GET /.git-credentials HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 172.17.3.147 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 172.17.3.147 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 172.17.3.147 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 172.17.3.147 Upgrade-Insecure-Requests: 1 X-Client-Ip: 172.17.3.147 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 172.17.3.147 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --bc460e5a-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --bc460e5a-H-- Message: Warning. Matched phrase "/.git-credentials" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.git-credentials||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Matched phrase "/.git-credentials" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.git-credentials||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "/.git-credentials" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.git-credentials||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/.git-credentials"] [unique_id "apUDl37glkZrdsSdRApJ1gAAAJA"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "/.git-credentials" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.git-credentials||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/.git-credentials"] [unique_id "apUDl37glkZrdsSdRApJ1gAAAJA"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150679847592 92942 (- - -) Stopwatch2: 1788150679847592 92942; combined=35051, p1=296, p2=34689, p3=0, p4=0, p5=65, sr=84, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --bc460e5a-Z-- --3d6edc59-A-- [31/Aug/2026:07:31:20.167319 +0300] apUDmCfaLSuAj0yzdueTFgAAABY 34.73.181.25 43618 127.0.0.1 7081 --3d6edc59-B-- POST /api/graphql HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Accel-Internal: /internal-nginx-static-location Content-Length: 86 User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: */* Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Content-Type: application/json Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Origin: https://alexandervodka.com Referer: https://alexandervodka.com Sec-Fetch-Dest: empty Sec-Fetch-Mode: cors Sec-Fetch-Site: same-origin sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --3d6edc59-F-- HTTP/1.1 403 Forbidden X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --3d6edc59-H-- Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150680087042 80380 (- - -) Stopwatch2: 1788150680087042 80380; combined=7681, p1=227, p2=7169, p3=0, p4=0, p5=285, sr=80, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --3d6edc59-Z-- --d5d10130-A-- [31/Aug/2026:07:31:20.283693 +0300] apUDl27fDIutYTwcPOkacgAAAFM 34.73.181.25 43578 127.0.0.1 7081 --d5d10130-B-- GET /.gitconfig HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 192.168.206.250 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 192.168.206.250 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 192.168.206.250 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 192.168.206.250 Upgrade-Insecure-Requests: 1 X-Client-Ip: 192.168.206.250 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 192.168.206.250 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --d5d10130-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --d5d10130-H-- Message: Warning. Matched phrase "/.gitconfig" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.gitconfig||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Matched phrase "/.gitconfig" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.gitconfig||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "/.gitconfig" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.gitconfig||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/.gitconfig"] [unique_id "apUDl27fDIutYTwcPOkacgAAAFM"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "/.gitconfig" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.gitconfig||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/.gitconfig"] [unique_id "apUDl27fDIutYTwcPOkacgAAAFM"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150679986778 297110 (- - -) Stopwatch2: 1788150679986778 297110; combined=62272, p1=261, p2=61900, p3=0, p4=0, p5=110, sr=81, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --d5d10130-Z-- --3b1af431-A-- [31/Aug/2026:07:31:20.285993 +0300] apUDmCfaLSuAj0yzdueTFQAAAAw 34.73.181.25 43608 127.0.0.1 7081 --3b1af431-B-- GET /.env HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 172.29.251.105 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 172.29.251.105 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 172.29.251.105 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 172.29.251.105 Upgrade-Insecure-Requests: 1 X-Client-Ip: 172.29.251.105 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 172.29.251.105 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --3b1af431-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --3b1af431-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/.env"] [unique_id "apUDmCfaLSuAj0yzdueTFQAAAAw"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150680082519 203560 (- - -) Stopwatch2: 1788150680082519 203560; combined=4950, p1=293, p2=4605, p3=0, p4=0, p5=51, sr=99, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --3b1af431-Z-- --62e26f73-A-- [31/Aug/2026:07:31:20.566942 +0300] apUDmNmUuou1H8H2UKXD8gAAANc 34.73.181.25 43640 127.0.0.1 7081 --62e26f73-B-- GET /.env.local HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 100.107.80.230 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 100.107.80.230 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 100.107.80.230 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 100.107.80.230 Upgrade-Insecure-Requests: 1 X-Client-Ip: 100.107.80.230 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 100.107.80.230 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --62e26f73-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --62e26f73-H-- Message: Warning. Matched phrase ".local" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.env.local||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Matched phrase ".local" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.env.local||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".local" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.env.local||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/.env.local"] [unique_id "apUDmNmUuou1H8H2UKXD8gAAANc"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".local" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.env.local||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/.env.local"] [unique_id "apUDmNmUuou1H8H2UKXD8gAAANc"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150680294591 272442 (- - -) Stopwatch2: 1788150680294591 272442; combined=34640, p1=265, p2=34309, p3=0, p4=0, p5=65, sr=96, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --62e26f73-Z-- --c37e6c11-A-- [31/Aug/2026:07:31:20.580933 +0300] apUDmNmUuou1H8H2UKXD9gAAANg 34.73.181.25 43710 127.0.0.1 7081 --c37e6c11-B-- GET /api/.env HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 172.25.84.73 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 172.25.84.73 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 172.25.84.73 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 172.25.84.73 Upgrade-Insecure-Requests: 1 X-Client-Ip: 172.25.84.73 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 172.25.84.73 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --c37e6c11-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --c37e6c11-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/api/.env"] [unique_id "apUDmNmUuou1H8H2UKXD9gAAANg"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150680448950 132083 (- - -) Stopwatch2: 1788150680448950 132083; combined=4583, p1=245, p2=4284, p3=0, p4=0, p5=54, sr=82, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --c37e6c11-Z-- --be2ae37c-A-- [31/Aug/2026:07:31:20.663837 +0300] apUDmH7glkZrdsSdRApJ1wAAAIE 34.73.181.25 43656 127.0.0.1 7081 --be2ae37c-B-- POST /v1/graphql HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Accel-Internal: /internal-nginx-static-location Content-Length: 86 User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: */* Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Content-Type: application/json Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Origin: https://alexandervodka.com Referer: https://alexandervodka.com Sec-Fetch-Dest: empty Sec-Fetch-Mode: cors Sec-Fetch-Site: same-origin sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --be2ae37c-F-- HTTP/1.1 403 Forbidden X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --be2ae37c-H-- Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150680317225 346693 (- - -) Stopwatch2: 1788150680317225 346693; combined=5583, p1=283, p2=4931, p3=0, p4=0, p5=369, sr=117, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --be2ae37c-Z-- --c6afca47-A-- [31/Aug/2026:07:31:20.691510 +0300] apUDmNmUuou1H8H2UKXD@AAAAMY 34.73.181.25 43734 127.0.0.1 7081 --c6afca47-B-- GET /admin/.env HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 172.27.43.39 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 172.27.43.39 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 172.27.43.39 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 172.27.43.39 Upgrade-Insecure-Requests: 1 X-Client-Ip: 172.27.43.39 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 172.27.43.39 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --c6afca47-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --c6afca47-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/admin/.env"] [unique_id "apUDmNmUuou1H8H2UKXD@AAAAMY"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150680477040 214604 (- - -) Stopwatch2: 1788150680477040 214604; combined=5282, p1=243, p2=4980, p3=0, p4=0, p5=59, sr=81, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --c6afca47-Z-- --5acf943e-A-- [31/Aug/2026:07:31:20.886961 +0300] apUDmCfaLSuAj0yzdueTFwAAABc 34.73.181.25 43770 127.0.0.1 7081 --5acf943e-B-- GET /config/.env HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 100.81.34.110 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 100.81.34.110 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 100.81.34.110 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 100.81.34.110 Upgrade-Insecure-Requests: 1 X-Client-Ip: 100.81.34.110 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 100.81.34.110 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --5acf943e-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --5acf943e-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/config/.env"] [unique_id "apUDmCfaLSuAj0yzdueTFwAAABc"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150680766132 120919 (- - -) Stopwatch2: 1788150680766132 120919; combined=5858, p1=275, p2=5526, p3=0, p4=0, p5=57, sr=94, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --5acf943e-Z-- --b77eec6b-A-- [31/Aug/2026:07:31:20.940064 +0300] apUDmNmUuou1H8H2UKXD@gAAANQ 34.73.181.25 43756 127.0.0.1 7081 --b77eec6b-B-- GET /backend/.env HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 100.107.79.54 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 100.107.79.54 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 100.107.79.54 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 100.107.79.54 Upgrade-Insecure-Requests: 1 X-Client-Ip: 100.107.79.54 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 100.107.79.54 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --b77eec6b-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --b77eec6b-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/backend/.env"] [unique_id "apUDmNmUuou1H8H2UKXD@gAAANQ"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150680742148 198003 (- - -) Stopwatch2: 1788150680742148 198003; combined=6098, p1=325, p2=5718, p3=0, p4=0, p5=54, sr=110, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --b77eec6b-Z-- --8fe3bb14-A-- [31/Aug/2026:07:31:21.537531 +0300] apUDmdmUuou1H8H2UKXEAQAAAMc 34.73.181.25 43902 127.0.0.1 7081 --8fe3bb14-B-- GET /.github/.env HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 10.188.56.58 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 10.188.56.58 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 10.188.56.58 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 10.188.56.58 Upgrade-Insecure-Requests: 1 X-Client-Ip: 10.188.56.58 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 10.188.56.58 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --8fe3bb14-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --8fe3bb14-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/.github/.env"] [unique_id "apUDmdmUuou1H8H2UKXEAQAAAMc"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150681474845 62813 (- - -) Stopwatch2: 1788150681474845 62813; combined=4918, p1=284, p2=4577, p3=0, p4=0, p5=56, sr=108, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --8fe3bb14-Z-- --37a51749-A-- [31/Aug/2026:07:31:21.684163 +0300] apUDmdmUuou1H8H2UKXEAgAAAMk 34.73.181.25 43910 127.0.0.1 7081 --37a51749-B-- GET /.npmrc HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 10.109.48.131 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 10.109.48.131 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 10.109.48.131 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 10.109.48.131 Upgrade-Insecure-Requests: 1 X-Client-Ip: 10.109.48.131 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 10.109.48.131 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --37a51749-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --37a51749-H-- Message: Warning. Matched phrase ".npmrc" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.npmrc||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Matched phrase ".npmrc" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.npmrc||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".npmrc" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.npmrc||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/.npmrc"] [unique_id "apUDmdmUuou1H8H2UKXEAgAAAMk"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".npmrc" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.npmrc||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/.npmrc"] [unique_id "apUDmdmUuou1H8H2UKXEAgAAAMk"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150681583184 101176 (- - -) Stopwatch2: 1788150681583184 101176; combined=33207, p1=219, p2=32890, p3=0, p4=0, p5=97, sr=69, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --37a51749-Z-- --2f474539-A-- [31/Aug/2026:07:31:21.822768 +0300] apUDmdmUuou1H8H2UKXEBgAAANM 34.73.181.25 43962 127.0.0.1 7081 --2f474539-B-- GET /.svn/entries HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 100.111.65.1 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 100.111.65.1 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 100.111.65.1 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 100.111.65.1 Upgrade-Insecure-Requests: 1 X-Client-Ip: 100.111.65.1 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 100.111.65.1 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --2f474539-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --2f474539-H-- Message: Warning. Matched phrase ".svn/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.svn/entries||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Matched phrase ".svn/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.svn/entries||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".svn/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.svn/entries||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/.svn/entries"] [unique_id "apUDmdmUuou1H8H2UKXEBgAAANM"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".svn/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.svn/entries||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/.svn/entries"] [unique_id "apUDmdmUuou1H8H2UKXEBgAAANM"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150681721834 101024 (- - -) Stopwatch2: 1788150681721834 101024; combined=32372, p1=241, p2=32066, p3=0, p4=0, p5=64, sr=80, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --2f474539-Z-- --7abb6f7c-A-- [31/Aug/2026:07:31:23.098967 +0300] apUDmtmUuou1H8H2UKXEGQAAAM8 34.73.181.25 44266 127.0.0.1 7081 --7abb6f7c-B-- GET /.idea/WebServers.xml HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 172.28.235.57 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 172.28.235.57 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 172.28.235.57 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 172.28.235.57 Upgrade-Insecure-Requests: 1 X-Client-Ip: 172.28.235.57 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 172.28.235.57 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --7abb6f7c-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --7abb6f7c-H-- Message: Warning. Matched phrase ".idea/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.idea/webservers.xml||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Matched phrase ".idea/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.idea/webservers.xml||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".idea/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.idea/webservers.xml||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/.idea/WebServers.xml"] [unique_id "apUDmtmUuou1H8H2UKXEGQAAAM8"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".idea/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.idea/webservers.xml||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/.idea/WebServers.xml"] [unique_id "apUDmtmUuou1H8H2UKXEGQAAAM8"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150682931115 167954 (- - -) Stopwatch2: 1788150682931115 167954; combined=36322, p1=255, p2=36003, p3=0, p4=0, p5=64, sr=77, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --7abb6f7c-Z-- --c61c9922-A-- [31/Aug/2026:07:31:23.119130 +0300] apUDmn7glkZrdsSdRApJ5QAAAIw 34.73.181.25 44294 127.0.0.1 7081 --c61c9922-B-- GET /.ssh/id_rsa HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 172.23.126.205 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 172.23.126.205 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 172.23.126.205 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 172.23.126.205 Upgrade-Insecure-Requests: 1 X-Client-Ip: 172.23.126.205 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 172.23.126.205 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --c61c9922-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --c61c9922-H-- Message: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.ssh/id_rsa||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.ssh/id_rsa||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.ssh/id_rsa||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/.ssh/id_rsa"] [unique_id "apUDmn7glkZrdsSdRApJ5QAAAIw"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.ssh/id_rsa||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/.ssh/id_rsa"] [unique_id "apUDmn7glkZrdsSdRApJ5QAAAIw"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150682986604 132625 (- - -) Stopwatch2: 1788150682986604 132625; combined=37692, p1=252, p2=37378, p3=0, p4=0, p5=62, sr=91, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --c61c9922-Z-- --843ff27b-A-- [31/Aug/2026:07:31:23.265264 +0300] apUDm9mUuou1H8H2UKXEHQAAAM4 34.73.181.25 44320 127.0.0.1 7081 --843ff27b-B-- GET /.ssh/id_ecdsa HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 192.168.134.198 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 192.168.134.198 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 192.168.134.198 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 192.168.134.198 Upgrade-Insecure-Requests: 1 X-Client-Ip: 192.168.134.198 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 192.168.134.198 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --843ff27b-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --843ff27b-H-- Message: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.ssh/id_ecdsa||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.ssh/id_ecdsa||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.ssh/id_ecdsa||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/.ssh/id_ecdsa"] [unique_id "apUDm9mUuou1H8H2UKXEHQAAAM4"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.ssh/id_ecdsa||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/.ssh/id_ecdsa"] [unique_id "apUDm9mUuou1H8H2UKXEHQAAAM4"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150683136393 128960 (- - -) Stopwatch2: 1788150683136393 128960; combined=49718, p1=312, p2=49342, p3=0, p4=0, p5=63, sr=102, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --843ff27b-Z-- --9019cc1e-A-- [31/Aug/2026:07:31:23.393975 +0300] apUDm9mUuou1H8H2UKXEIAAAANM 34.73.181.25 44342 127.0.0.1 7081 --9019cc1e-B-- GET /.ssh/config HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 172.17.16.18 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 172.17.16.18 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 172.17.16.18 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 172.17.16.18 Upgrade-Insecure-Requests: 1 X-Client-Ip: 172.17.16.18 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 172.17.16.18 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --9019cc1e-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --9019cc1e-H-- Message: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.ssh/config||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.ssh/config||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.ssh/config||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/.ssh/config"] [unique_id "apUDm9mUuou1H8H2UKXEIAAAANM"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.ssh/config||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/.ssh/config"] [unique_id "apUDm9mUuou1H8H2UKXEIAAAANM"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150683303115 90971 (- - -) Stopwatch2: 1788150683303115 90971; combined=34006, p1=245, p2=33694, p3=0, p4=0, p5=66, sr=80, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --9019cc1e-Z-- --0a526a5a-A-- [31/Aug/2026:07:31:23.410967 +0300] apUDm9mUuou1H8H2UKXEHAAAAMQ 34.73.181.25 44308 127.0.0.1 7081 --0a526a5a-B-- GET /.ssh/id_ed25519 HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 10.232.245.241 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 10.232.245.241 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 10.232.245.241 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 10.232.245.241 Upgrade-Insecure-Requests: 1 X-Client-Ip: 10.232.245.241 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 10.232.245.241 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --0a526a5a-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --0a526a5a-H-- Message: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.ssh/id_ed25519||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.ssh/id_ed25519||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.ssh/id_ed25519||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/.ssh/id_ed25519"] [unique_id "apUDm9mUuou1H8H2UKXEHAAAAMQ"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.ssh/id_ed25519||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/.ssh/id_ed25519"] [unique_id "apUDm9mUuou1H8H2UKXEHAAAAMQ"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150683133588 277469 (- - -) Stopwatch2: 1788150683133588 277469; combined=70153, p1=258, p2=69829, p3=0, p4=0, p5=65, sr=91, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --0a526a5a-Z-- --53a1801d-A-- [31/Aug/2026:07:31:23.429221 +0300] apUDm9mUuou1H8H2UKXEGwAAAMM 34.73.181.25 44310 127.0.0.1 7081 --53a1801d-B-- GET /.ssh/id_dsa HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 10.51.159.196 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 10.51.159.196 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 10.51.159.196 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 10.51.159.196 Upgrade-Insecure-Requests: 1 X-Client-Ip: 10.51.159.196 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 10.51.159.196 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --53a1801d-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --53a1801d-H-- Message: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.ssh/id_dsa||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.ssh/id_dsa||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.ssh/id_dsa||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/.ssh/id_dsa"] [unique_id "apUDm9mUuou1H8H2UKXEGwAAAMM"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.ssh/id_dsa||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/.ssh/id_dsa"] [unique_id "apUDm9mUuou1H8H2UKXEGwAAAMM"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150683128580 300767 (- - -) Stopwatch2: 1788150683128580 300767; combined=73399, p1=280, p2=73053, p3=0, p4=0, p5=66, sr=82, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --53a1801d-Z-- --c8a0073f-A-- [31/Aug/2026:07:31:23.430890 +0300] apUDm9mUuou1H8H2UKXEHwAAANU 34.73.181.25 44332 127.0.0.1 7081 --c8a0073f-B-- GET /.ssh/known_hosts HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 172.16.159.63 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 172.16.159.63 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 172.16.159.63 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 172.16.159.63 Upgrade-Insecure-Requests: 1 X-Client-Ip: 172.16.159.63 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 172.16.159.63 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --c8a0073f-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --c8a0073f-H-- Message: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.ssh/known_hosts||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.ssh/known_hosts||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.ssh/known_hosts||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/.ssh/known_hosts"] [unique_id "apUDm9mUuou1H8H2UKXEHwAAANU"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.ssh/known_hosts||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/.ssh/known_hosts"] [unique_id "apUDm9mUuou1H8H2UKXEHwAAANU"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150683280354 150631 (- - -) Stopwatch2: 1788150683280354 150631; combined=34147, p1=251, p2=33847, p3=0, p4=0, p5=49, sr=80, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --c8a0073f-Z-- --0f607531-A-- [31/Aug/2026:07:31:23.455410 +0300] apUDm9mUuou1H8H2UKXEHgAAANQ 34.73.181.25 44324 127.0.0.1 7081 --0f607531-B-- GET /.ssh/authorized_keys HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 10.248.73.111 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 10.248.73.111 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 10.248.73.111 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 10.248.73.111 Upgrade-Insecure-Requests: 1 X-Client-Ip: 10.248.73.111 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 10.248.73.111 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --0f607531-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --0f607531-H-- Message: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.ssh/authorized_keys||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.ssh/authorized_keys||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.ssh/authorized_keys||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/.ssh/authorized_keys"] [unique_id "apUDm9mUuou1H8H2UKXEHgAAANQ"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".ssh/" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.ssh/authorized_keys||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/.ssh/authorized_keys"] [unique_id "apUDm9mUuou1H8H2UKXEHgAAANQ"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150683247032 208468 (- - -) Stopwatch2: 1788150683247032 208468; combined=31760, p1=247, p2=31446, p3=0, p4=0, p5=67, sr=81, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --0f607531-Z-- --d236314e-A-- [31/Aug/2026:07:31:23.525262 +0300] apUDm9mUuou1H8H2UKXEIQAAANc 34.73.181.25 44356 127.0.0.1 7081 --d236314e-B-- GET /id_rsa HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 172.22.52.138 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 172.22.52.138 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 172.22.52.138 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 172.22.52.138 Upgrade-Insecure-Requests: 1 X-Client-Ip: 172.22.52.138 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 172.22.52.138 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --d236314e-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --d236314e-H-- Message: Warning. Matched phrase "id_rsa" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/id_rsa||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Matched phrase "id_rsa" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/id_rsa||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "id_rsa" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/id_rsa||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/id_rsa"] [unique_id "apUDm9mUuou1H8H2UKXEIQAAANc"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "id_rsa" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/id_rsa||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/id_rsa"] [unique_id "apUDm9mUuou1H8H2UKXEIQAAANc"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150683431503 93899 (- - -) Stopwatch2: 1788150683431503 93899; combined=32509, p1=469, p2=31974, p3=0, p4=0, p5=65, sr=290, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --d236314e-Z-- --f2ace91b-A-- [31/Aug/2026:07:31:23.891893 +0300] apUDm9mUuou1H8H2UKXEJgAAAM0 34.73.181.25 44372 127.0.0.1 7081 --f2ace91b-B-- GET /id_dsa HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 100.81.93.248 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 100.81.93.248 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 100.81.93.248 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 100.81.93.248 Upgrade-Insecure-Requests: 1 X-Client-Ip: 100.81.93.248 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 100.81.93.248 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --f2ace91b-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --f2ace91b-H-- Message: Warning. Matched phrase "id_dsa" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/id_dsa||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Matched phrase "id_dsa" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/id_dsa||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "id_dsa" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/id_dsa||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/id_dsa"] [unique_id "apUDm9mUuou1H8H2UKXEJgAAAM0"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "id_dsa" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/id_dsa||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/id_dsa"] [unique_id "apUDm9mUuou1H8H2UKXEJgAAAM0"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150683627203 264780 (- - -) Stopwatch2: 1788150683627203 264780; combined=32471, p1=250, p2=32155, p3=0, p4=0, p5=65, sr=93, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --f2ace91b-Z-- --2c228209-A-- [31/Aug/2026:07:31:24.453300 +0300] apUDnNmUuou1H8H2UKXELAAAAMg 34.73.181.25 44496 127.0.0.1 7081 --2c228209-B-- GET /@fs/app/.env?raw?? HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 100.66.184.74 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 100.66.184.74 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 100.66.184.74 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 100.66.184.74 Upgrade-Insecure-Requests: 1 X-Client-Ip: 100.66.184.74 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 100.66.184.74 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --2c228209-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --2c228209-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/@fs/app/.env"] [unique_id "apUDnNmUuou1H8H2UKXELAAAAMg"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150684386859 66543 (- - -) Stopwatch2: 1788150684386859 66543; combined=4352, p1=313, p2=3980, p3=0, p4=0, p5=59, sr=143, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --2c228209-Z-- --aad82529-A-- [31/Aug/2026:07:31:24.520025 +0300] apUDnNmUuou1H8H2UKXELgAAAMc 34.73.181.25 44536 127.0.0.1 7081 --aad82529-B-- GET /@fs/..%252f..%252f..%252f..%252f..%252fproc/self/environ?raw?? HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 172.20.201.113 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 172.20.201.113 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 172.20.201.113 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 172.20.201.113 Upgrade-Insecure-Requests: 1 X-Client-Ip: 172.20.201.113 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 172.20.201.113 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --aad82529-F-- HTTP/1.1 403 Forbidden Content-Length: 199 Content-Type: text/html; charset=iso-8859-1 --aad82529-H-- Message: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at MATCHED_VAR. [file "/etc/httpd/conf/modsecurity.d/rules/custom/012_i360_1_generic.conf"] [line "22"] [id "77140166"] [msg "IM360 WAF: Blocking directory traversal attempt||MVN:MATCHED_VAR||MV:/proc/self/environ?raw??||T:APACHE||"] [severity "CRITICAL"] [tag "service_gen"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G:raw??=& P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at MATCHED_VAR. [file "/etc/httpd/conf/modsecurity.d/rules/custom/012_i360_1_generic.conf"] [line "22"] [id "77140166"] [msg "IM360 WAF: Blocking directory traversal attempt||MVN:MATCHED_VAR||MV:/proc/self/environ?raw??||T:APACHE||"] [severity "CRITICAL"] [tag "service_gen"] [hostname "alexandervodka.com"] [uri "/@fs/..%2f..%2f..%2f..%2f..%2fproc/self/environ"] [unique_id "apUDnNmUuou1H8H2UKXELgAAAMc"] Action: Intercepted (phase 2) Stopwatch: 1788150684514720 5388 (- - -) Stopwatch2: 1788150684514720 5388; combined=3892, p1=260, p2=3304, p3=0, p4=0, p5=328, sr=89, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --aad82529-Z-- --7453a543-A-- [31/Aug/2026:07:31:24.539349 +0300] apUDnNmUuou1H8H2UKXELwAAAMA 34.73.181.25 44540 127.0.0.1 7081 --7453a543-B-- GET /@fs/..%252f..%252f..%252f..%252f..%252froot/.env?raw?? HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 172.16.149.242 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 172.16.149.242 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 172.16.149.242 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 172.16.149.242 Upgrade-Insecure-Requests: 1 X-Client-Ip: 172.16.149.242 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 172.16.149.242 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --7453a543-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --7453a543-E-- --7453a543-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/@fs/..%2f..%2f..%2f..%2f..%2froot/.env"] [unique_id "apUDnNmUuou1H8H2UKXELwAAAMA"] Stopwatch: 1788150684533865 5587 (- - -) Stopwatch2: 1788150684533865 5587; combined=4146, p1=267, p2=3759, p3=73, p4=7, p5=40, sr=89, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --7453a543-Z-- --c31cca52-A-- [31/Aug/2026:07:31:24.549999 +0300] apUDnCfaLSuAj0yzdueTHQAAABI 34.73.181.25 44510 127.0.0.1 7081 --c31cca52-B-- GET /@fs/../.env?raw?? HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 192.168.148.47 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 192.168.148.47 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 192.168.148.47 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 192.168.148.47 Upgrade-Insecure-Requests: 1 X-Client-Ip: 192.168.148.47 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 192.168.148.47 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --c31cca52-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --c31cca52-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/.env"] [unique_id "apUDnCfaLSuAj0yzdueTHQAAABI"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150684460091 90012 (- - -) Stopwatch2: 1788150684460091 90012; combined=5194, p1=332, p2=4803, p3=0, p4=0, p5=58, sr=125, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --c31cca52-Z-- --624f3b11-A-- [31/Aug/2026:07:31:24.561052 +0300] apUDnNmUuou1H8H2UKXELQAAANg 34.73.181.25 44520 127.0.0.1 7081 --624f3b11-B-- GET /@fs/src/.env?raw?? HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 10.44.215.84 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 10.44.215.84 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 10.44.215.84 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 10.44.215.84 Upgrade-Insecure-Requests: 1 X-Client-Ip: 10.44.215.84 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 10.44.215.84 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --624f3b11-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --624f3b11-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/@fs/src/.env"] [unique_id "apUDnNmUuou1H8H2UKXELQAAANg"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150684476381 84771 (- - -) Stopwatch2: 1788150684476381 84771; combined=5060, p1=380, p2=4623, p3=0, p4=0, p5=57, sr=161, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --624f3b11-Z-- --1ea68b55-A-- [31/Aug/2026:07:31:24.623635 +0300] apUDnCfaLSuAj0yzdueTHgAAABI 34.73.181.25 44550 127.0.0.1 7081 --1ea68b55-B-- GET /_nuxt/../.env HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 192.168.117.76 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 192.168.117.76 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 192.168.117.76 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 192.168.117.76 Upgrade-Insecure-Requests: 1 X-Client-Ip: 192.168.117.76 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 192.168.117.76 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --1ea68b55-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --1ea68b55-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/.env"] [unique_id "apUDnCfaLSuAj0yzdueTHgAAABI"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150684559832 63981 (- - -) Stopwatch2: 1788150684559832 63981; combined=5809, p1=272, p2=5478, p3=0, p4=0, p5=59, sr=91, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --1ea68b55-Z-- --8710ab77-A-- [31/Aug/2026:07:31:24.719222 +0300] apUDnNmUuou1H8H2UKXEMAAAAMY 34.73.181.25 44560 127.0.0.1 7081 --8710ab77-B-- GET /static../.env HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 172.23.34.44 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 172.23.34.44 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 172.23.34.44 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 172.23.34.44 Upgrade-Insecure-Requests: 1 X-Client-Ip: 172.23.34.44 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 172.23.34.44 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --8710ab77-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --8710ab77-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/static../.env"] [unique_id "apUDnNmUuou1H8H2UKXEMAAAAMY"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150684642010 77303 (- - -) Stopwatch2: 1788150684642010 77303; combined=7379, p1=271, p2=7044, p3=0, p4=0, p5=64, sr=101, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --8710ab77-Z-- --3265ff0d-A-- [31/Aug/2026:07:31:24.807124 +0300] apUDnH7glkZrdsSdRApJ6AAAAIo 34.73.181.25 44564 127.0.0.1 7081 --3265ff0d-B-- GET /files../.env HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 100.106.20.19 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 100.106.20.19 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 100.106.20.19 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 100.106.20.19 Upgrade-Insecure-Requests: 1 X-Client-Ip: 100.106.20.19 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 100.106.20.19 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --3265ff0d-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --3265ff0d-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/files../.env"] [unique_id "apUDnH7glkZrdsSdRApJ6AAAAIo"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150684732982 74231 (- - -) Stopwatch2: 1788150684732982 74231; combined=5196, p1=302, p2=4837, p3=0, p4=0, p5=56, sr=117, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --3265ff0d-Z-- --23524f65-A-- [31/Aug/2026:07:31:24.881847 +0300] apUDnNmUuou1H8H2UKXEMQAAAM4 34.73.181.25 44576 127.0.0.1 7081 --23524f65-B-- GET /static//app/.env HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 100.96.181.137 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 100.96.181.137 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 100.96.181.137 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 100.96.181.137 Upgrade-Insecure-Requests: 1 X-Client-Ip: 100.96.181.137 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 100.96.181.137 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --23524f65-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --23524f65-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/static/app/.env"] [unique_id "apUDnNmUuou1H8H2UKXEMQAAAM4"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150684735405 146556 (- - -) Stopwatch2: 1788150684735405 146556; combined=6537, p1=457, p2=6022, p3=0, p4=0, p5=57, sr=175, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --23524f65-Z-- --29c9e851-A-- [31/Aug/2026:07:31:24.908042 +0300] apUDnNmUuou1H8H2UKXEMwAAANM 34.73.181.25 44606 127.0.0.1 7081 --29c9e851-B-- GET /static//home/user/.env HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 10.39.142.71 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 10.39.142.71 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 10.39.142.71 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 10.39.142.71 Upgrade-Insecure-Requests: 1 X-Client-Ip: 10.39.142.71 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 10.39.142.71 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --29c9e851-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --29c9e851-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/static/home/user/.env"] [unique_id "apUDnNmUuou1H8H2UKXEMwAAANM"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150684829165 78966 (- - -) Stopwatch2: 1788150684829165 78966; combined=5177, p1=247, p2=4868, p3=0, p4=0, p5=62, sr=79, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --29c9e851-Z-- --02947465-A-- [31/Aug/2026:07:31:24.918992 +0300] apUDnNmUuou1H8H2UKXEMgAAANA 34.73.181.25 44588 127.0.0.1 7081 --02947465-B-- GET /static//.env HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 10.230.237.85 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 10.230.237.85 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 10.230.237.85 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 10.230.237.85 Upgrade-Insecure-Requests: 1 X-Client-Ip: 10.230.237.85 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 10.230.237.85 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --02947465-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --02947465-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/static/.env"] [unique_id "apUDnNmUuou1H8H2UKXEMgAAANA"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150684751053 168088 (- - -) Stopwatch2: 1788150684751053 168088; combined=4774, p1=281, p2=4438, p3=0, p4=0, p5=55, sr=86, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --02947465-Z-- --6659a052-A-- [31/Aug/2026:07:31:24.937893 +0300] apUDnG7fDIutYTwcPOkaeAAAAEo 34.73.181.25 44590 127.0.0.1 7081 --6659a052-B-- GET /media../.env HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 100.106.214.148 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 100.106.214.148 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 100.106.214.148 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 100.106.214.148 Upgrade-Insecure-Requests: 1 X-Client-Ip: 100.106.214.148 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 100.106.214.148 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --6659a052-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --6659a052-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/media../.env"] [unique_id "apUDnG7fDIutYTwcPOkaeAAAAEo"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150684801316 136665 (- - -) Stopwatch2: 1788150684801316 136665; combined=16222, p1=287, p2=15878, p3=0, p4=0, p5=57, sr=93, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --6659a052-Z-- --6209bb50-A-- [31/Aug/2026:07:31:24.966259 +0300] apUDnG7fDIutYTwcPOkaeQAAAEc 34.73.181.25 44610 127.0.0.1 7081 --6209bb50-B-- GET /.//.env HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 10.9.252.225 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 10.9.252.225 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 10.9.252.225 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 10.9.252.225 Upgrade-Insecure-Requests: 1 X-Client-Ip: 10.9.252.225 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 10.9.252.225 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --6209bb50-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --6209bb50-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/.env"] [unique_id "apUDnG7fDIutYTwcPOkaeQAAAEc"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150684885466 80883 (- - -) Stopwatch2: 1788150684885466 80883; combined=5110, p1=269, p2=4783, p3=0, p4=0, p5=58, sr=109, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --6209bb50-Z-- --ebd6563c-A-- [31/Aug/2026:07:31:25.038905 +0300] apUDnG7fDIutYTwcPOkaegAAAEQ 34.73.181.25 44624 127.0.0.1 7081 --ebd6563c-B-- GET //.env HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 172.20.111.144 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 172.20.111.144 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 172.20.111.144 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 172.20.111.144 Upgrade-Insecure-Requests: 1 X-Client-Ip: 172.20.111.144 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 172.20.111.144 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --ebd6563c-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --ebd6563c-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/.env"] [unique_id "apUDnG7fDIutYTwcPOkaegAAAEQ"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150684966271 72841 (- - -) Stopwatch2: 1788150684966271 72841; combined=4881, p1=241, p2=4551, p3=0, p4=0, p5=88, sr=71, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --ebd6563c-Z-- --6d4c2b43-A-- [31/Aug/2026:07:31:25.152952 +0300] apUDndmUuou1H8H2UKXENAAAAMU 34.73.181.25 44638 127.0.0.1 7081 --6d4c2b43-B-- GET /api/.env/public/.env HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 100.111.57.59 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 100.111.57.59 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 100.111.57.59 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 100.111.57.59 Upgrade-Insecure-Requests: 1 X-Client-Ip: 100.111.57.59 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 100.111.57.59 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --6d4c2b43-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --6d4c2b43-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/api/.env/public/.env"] [unique_id "apUDndmUuou1H8H2UKXENAAAAMU"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150685070253 82788 (- - -) Stopwatch2: 1788150685070253 82788; combined=6962, p1=434, p2=6469, p3=0, p4=0, p5=59, sr=122, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --6d4c2b43-Z-- --5aa7212d-A-- [31/Aug/2026:07:31:25.178738 +0300] apUDndmUuou1H8H2UKXENQAAAMQ 34.73.181.25 44640 127.0.0.1 7081 --5aa7212d-B-- GET /%2eenv HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 100.72.98.143 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 100.72.98.143 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 100.72.98.143 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 100.72.98.143 Upgrade-Insecure-Requests: 1 X-Client-Ip: 100.72.98.143 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 100.72.98.143 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --5aa7212d-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --5aa7212d-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/.env"] [unique_id "apUDndmUuou1H8H2UKXENQAAAMQ"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150685106096 72766 (- - -) Stopwatch2: 1788150685106096 72766; combined=4974, p1=256, p2=4635, p3=0, p4=0, p5=82, sr=84, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --5aa7212d-Z-- --411a3a74-A-- [31/Aug/2026:07:31:25.256975 +0300] apUDnX7glkZrdsSdRApJ6QAAAJM 34.73.181.25 44642 127.0.0.1 7081 --411a3a74-B-- GET /assets../.env HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 172.16.44.181 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 172.16.44.181 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 172.16.44.181 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 172.16.44.181 Upgrade-Insecure-Requests: 1 X-Client-Ip: 172.16.44.181 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 172.16.44.181 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --411a3a74-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --411a3a74-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/assets../.env"] [unique_id "apUDnX7glkZrdsSdRApJ6QAAAJM"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150685194881 62178 (- - -) Stopwatch2: 1788150685194881 62178; combined=5018, p1=277, p2=4685, p3=0, p4=0, p5=55, sr=88, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --411a3a74-Z-- --e2b4db2e-A-- [31/Aug/2026:07:31:25.406805 +0300] apUDnX7glkZrdsSdRApJ6gAAAJU 34.73.181.25 44668 127.0.0.1 7081 --e2b4db2e-B-- GET /img../.env HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 192.168.129.29 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 192.168.129.29 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 192.168.129.29 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 192.168.129.29 Upgrade-Insecure-Requests: 1 X-Client-Ip: 192.168.129.29 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 192.168.129.29 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --e2b4db2e-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --e2b4db2e-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/img../.env"] [unique_id "apUDnX7glkZrdsSdRApJ6gAAAJU"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150685305944 100950 (- - -) Stopwatch2: 1788150685305944 100950; combined=5802, p1=282, p2=5460, p3=0, p4=0, p5=60, sr=91, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --e2b4db2e-Z-- --ecd73067-A-- [31/Aug/2026:07:31:25.485904 +0300] apUDnW7fDIutYTwcPOkaewAAAEs 34.73.181.25 44660 127.0.0.1 7081 --ecd73067-B-- GET /uploads../.env HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 100.114.221.197 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 100.114.221.197 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 100.114.221.197 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 100.114.221.197 Upgrade-Insecure-Requests: 1 X-Client-Ip: 100.114.221.197 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 100.114.221.197 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --ecd73067-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --ecd73067-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/uploads../.env"] [unique_id "apUDnW7fDIutYTwcPOkaewAAAEs"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150685281322 204672 (- - -) Stopwatch2: 1788150685281322 204672; combined=5014, p1=163, p2=4793, p3=0, p4=0, p5=58, sr=57, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --ecd73067-Z-- --5a00cb42-A-- [31/Aug/2026:07:31:25.494548 +0300] apUDndmUuou1H8H2UKXENgAAANU 34.73.181.25 44648 127.0.0.1 7081 --5a00cb42-B-- GET /images../.env HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 10.98.22.165 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 10.98.22.165 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 10.98.22.165 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 10.98.22.165 Upgrade-Insecure-Requests: 1 X-Client-Ip: 10.98.22.165 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 10.98.22.165 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --5a00cb42-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --5a00cb42-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/images../.env"] [unique_id "apUDndmUuou1H8H2UKXENgAAANU"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150685280812 213914 (- - -) Stopwatch2: 1788150685280812 213914; combined=5029, p1=302, p2=4671, p3=0, p4=0, p5=56, sr=104, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --5a00cb42-Z-- --3a208051-A-- [31/Aug/2026:07:31:25.642342 +0300] apUDndmUuou1H8H2UKXENwAAAMo 34.73.181.25 55428 127.0.0.1 7081 --3a208051-B-- GET /@fs/var/task/.env?raw?? HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 100.88.75.84 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 100.88.75.84 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 100.88.75.84 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 100.88.75.84 Upgrade-Insecure-Requests: 1 X-Client-Ip: 100.88.75.84 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 100.88.75.84 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --3a208051-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --3a208051-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/@fs/var/task/.env"] [unique_id "apUDndmUuou1H8H2UKXENwAAAMo"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150685568530 73930 (- - -) Stopwatch2: 1788150685568530 73930; combined=3983, p1=294, p2=3626, p3=0, p4=0, p5=62, sr=96, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --3a208051-Z-- --ee575677-A-- [31/Aug/2026:07:31:25.691923 +0300] apUDnSfaLSuAj0yzdueTHwAAAAg 34.73.181.25 55430 127.0.0.1 7081 --ee575677-B-- GET /@fs/proc/self/cwd/.env?raw?? HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 10.60.252.134 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 10.60.252.134 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 10.60.252.134 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 10.60.252.134 Upgrade-Insecure-Requests: 1 X-Client-Ip: 10.60.252.134 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 10.60.252.134 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --ee575677-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --ee575677-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/@fs/proc/self/cwd/.env"] [unique_id "apUDnSfaLSuAj0yzdueTHwAAAAg"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150685624484 67548 (- - -) Stopwatch2: 1788150685624484 67548; combined=4560, p1=360, p2=4131, p3=0, p4=0, p5=69, sr=99, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --ee575677-Z-- --079d0a7f-A-- [31/Aug/2026:07:31:25.859521 +0300] apUDnX7glkZrdsSdRApJ7gAAAIU 172.69.223.200 55436 127.0.0.1 7081 --079d0a7f-B-- GET /.git/HEAD HTTP/1.1 Host: funshop.ro X-Real-IP: 172.69.223.200 X-Forwarded-For: 2a06:98c0:3600::103 X-Accel-Internal: /internal-nginx-static-location cf-ray: a3394e38f8536f05-CDG CF-EW-Via: 15 CDN-Loop: cloudflare; loops=1 Upgrade-Insecure-Requests: 1 Sec-Fetch-User: ?1 Accept-Language: en-US,en;q=0.9 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8 Cache-Control: no-cache User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36 Pragma: no-cache Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none cf-worker: jx1akqrgxx5exg.workers.dev CF-Visitor: {"scheme":"https"} X-Forwarded-Proto: https accept-encoding: gzip --079d0a7f-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --079d0a7f-E-- --079d0a7f-H-- Message: Warning. String match "/.git/" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "656"] [id "77318034"] [msg "IM360 WAF: Blocked access to git folder||T:APACHE||MV:/.git/head||"] [severity "NOTICE"] [tag "service_i360custom"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.git/" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "656"] [id "77318034"] [msg "IM360 WAF: Blocked access to git folder||T:APACHE||MV:/.git/head||"] [severity "NOTICE"] [tag "service_i360custom"] [hostname "funshop.ro"] [uri "/.git/HEAD"] [unique_id "apUDnX7glkZrdsSdRApJ7gAAAIU"] Stopwatch: 1788150685852216 7389 (- - -) Stopwatch2: 1788150685852216 7389; combined=5898, p1=391, p2=5331, p3=72, p4=7, p5=97, sr=153, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --079d0a7f-Z-- --81cbba0b-A-- [31/Aug/2026:07:31:25.894711 +0300] apUDnX7glkZrdsSdRApJ7wAAAJc 172.69.223.200 55438 127.0.0.1 7081 --81cbba0b-B-- GET /.git/config HTTP/1.1 Host: funshop.ro X-Real-IP: 172.69.223.200 X-Forwarded-For: 2a06:98c0:3600::103 X-Accel-Internal: /internal-nginx-static-location cf-ray: a3394e38f8546f05-CDG CF-EW-Via: 15 CDN-Loop: cloudflare; loops=1 Upgrade-Insecure-Requests: 1 Sec-Fetch-User: ?1 Accept-Language: en-US,en;q=0.9 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8 Cache-Control: no-cache User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36 Pragma: no-cache Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none cf-worker: jx1akqrgxx5exg.workers.dev CF-Visitor: {"scheme":"https"} X-Forwarded-Proto: https accept-encoding: gzip --81cbba0b-F-- HTTP/1.1 404 Not Found Content-Length: 196 Content-Type: text/html; charset=iso-8859-1 --81cbba0b-E-- --81cbba0b-H-- Message: Warning. Matched phrase "/.git/config" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.git/config||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Matched phrase "/.git/config" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.git/config||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Message: Warning. String match "/.git/" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "656"] [id "77318034"] [msg "IM360 WAF: Blocked access to git folder||T:APACHE||MV:/.git/config||"] [severity "NOTICE"] [tag "service_i360custom"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "/.git/config" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.git/config||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "funshop.ro"] [uri "/.git/config"] [unique_id "apUDnX7glkZrdsSdRApJ7wAAAJc"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "/.git/config" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.git/config||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "funshop.ro"] [uri "/.git/config"] [unique_id "apUDnX7glkZrdsSdRApJ7wAAAJc"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.git/" at REQUEST_URI. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "656"] [id "77318034"] [msg "IM360 WAF: Blocked access to git folder||T:APACHE||MV:/.git/config||"] [severity "NOTICE"] [tag "service_i360custom"] [hostname "funshop.ro"] [uri "/.git/config"] [unique_id "apUDnX7glkZrdsSdRApJ7wAAAJc"] Stopwatch: 1788150685854167 40756 (- - -) Stopwatch2: 1788150685854167 40756; combined=38890, p1=588, p2=38073, p3=90, p4=10, p5=129, sr=228, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --81cbba0b-Z-- --02086704-A-- [31/Aug/2026:07:31:25.976746 +0300] apUDnX7glkZrdsSdRApJ8AAAAIc 34.73.181.25 55450 127.0.0.1 7081 --02086704-B-- GET /@fs/.env?url&raw?? HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 10.7.156.211 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 10.7.156.211 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 10.7.156.211 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 10.7.156.211 Upgrade-Insecure-Requests: 1 X-Client-Ip: 10.7.156.211 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 10.7.156.211 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --02086704-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --02086704-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:url&raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:url&raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/@fs/.env"] [unique_id "apUDnX7glkZrdsSdRApJ8AAAAIc"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150685875088 101758 (- - -) Stopwatch2: 1788150685875088 101758; combined=13613, p1=295, p2=13261, p3=0, p4=0, p5=57, sr=104, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --02086704-Z-- --2cd92f3c-A-- [31/Aug/2026:07:31:26.060951 +0300] apUDndmUuou1H8H2UKXEOwAAAMk 34.73.181.25 55498 127.0.0.1 7081 --2cd92f3c-B-- GET /@fs/.env?raw&url?? HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 172.23.46.20 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 172.23.46.20 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 172.23.46.20 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 172.23.46.20 Upgrade-Insecure-Requests: 1 X-Client-Ip: 172.23.46.20 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 172.23.46.20 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --2cd92f3c-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --2cd92f3c-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw&url??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:raw&url??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/@fs/.env"] [unique_id "apUDndmUuou1H8H2UKXEOwAAAMk"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150685982809 78228 (- - -) Stopwatch2: 1788150685982809 78228; combined=3936, p1=251, p2=3644, p3=0, p4=0, p5=41, sr=89, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --2cd92f3c-Z-- --f8f7ec2b-A-- [31/Aug/2026:07:31:26.218176 +0300] apUDntmUuou1H8H2UKXEPAAAANg 34.73.181.25 55508 127.0.0.1 7081 --f8f7ec2b-B-- GET /wp-config.php.bak HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 172.30.242.199 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 172.30.242.199 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 172.30.242.199 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 172.30.242.199 Upgrade-Insecure-Requests: 1 X-Client-Ip: 172.30.242.199 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 172.30.242.199 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --f8f7ec2b-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --f8f7ec2b-H-- Message: Warning. Matched phrase "wp-config.php." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/wp-config.php.bak||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Matched phrase "wp-config.php." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/wp-config.php.bak||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Message: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "wp-config.php." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/wp-config.php.bak||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/wp-config.php.bak"] [unique_id "apUDntmUuou1H8H2UKXEPAAAANg"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "wp-config.php." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/wp-config.php.bak||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/wp-config.php.bak"] [unique_id "apUDntmUuou1H8H2UKXEPAAAANg"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/wp-config.php.bak"] [unique_id "apUDntmUuou1H8H2UKXEPAAAANg"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150686058394 159935 (- - -) Stopwatch2: 1788150686058394 159935; combined=31863, p1=274, p2=31459, p3=0, p4=0, p5=129, sr=81, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --f8f7ec2b-Z-- --3ff26137-A-- [31/Aug/2026:07:31:26.228542 +0300] apUDnm7fDIutYTwcPOkafAAAAE0 34.73.181.25 55524 127.0.0.1 7081 --3ff26137-B-- GET /@fs/.env?import&?raw?? HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 10.190.150.154 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 10.190.150.154 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 10.190.150.154 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 10.190.150.154 Upgrade-Insecure-Requests: 1 X-Client-Ip: 10.190.150.154 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 10.190.150.154 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --3ff26137-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --3ff26137-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:import&?raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:import&?raw??"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/@fs/.env"] [unique_id "apUDnm7fDIutYTwcPOkafAAAAE0"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150686093108 136644 (- - -) Stopwatch2: 1788150686093108 136644; combined=24967, p1=224, p2=3820, p3=0, p4=0, p5=10497, sr=77, sw=1, l=0, gc=10425 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --3ff26137-Z-- --74c04b64-A-- [31/Aug/2026:07:31:26.285846 +0300] apUDntmUuou1H8H2UKXEPgAAAM4 34.73.181.25 55530 127.0.0.1 7081 --74c04b64-B-- GET /wp-config.php.old HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 172.27.214.248 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 172.27.214.248 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 172.27.214.248 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 172.27.214.248 Upgrade-Insecure-Requests: 1 X-Client-Ip: 172.27.214.248 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 172.27.214.248 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --74c04b64-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --74c04b64-H-- Message: Warning. Matched phrase "wp-config.php." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/wp-config.php.old||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Matched phrase "wp-config.php." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/wp-config.php.old||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Message: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "wp-config.php." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/wp-config.php.old||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/wp-config.php.old"] [unique_id "apUDntmUuou1H8H2UKXEPgAAAM4"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "wp-config.php." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/wp-config.php.old||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/wp-config.php.old"] [unique_id "apUDntmUuou1H8H2UKXEPgAAAM4"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/wp-config.php.old"] [unique_id "apUDntmUuou1H8H2UKXEPgAAAM4"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150686191118 94841 (- - -) Stopwatch2: 1788150686191118 94841; combined=31934, p1=276, p2=31576, p3=0, p4=0, p5=81, sr=78, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --74c04b64-Z-- --8ebb9f2f-A-- [31/Aug/2026:07:31:26.480284 +0300] apUDntmUuou1H8H2UKXEQQAAANI 34.73.181.25 55566 127.0.0.1 7081 --8ebb9f2f-B-- GET /core/.env HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 100.107.100.135 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 100.107.100.135 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 100.107.100.135 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 100.107.100.135 Upgrade-Insecure-Requests: 1 X-Client-Ip: 100.107.100.135 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 100.107.100.135 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --8ebb9f2f-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --8ebb9f2f-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/core/.env"] [unique_id "apUDntmUuou1H8H2UKXEQQAAANI"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150686409376 71017 (- - -) Stopwatch2: 1788150686409376 71017; combined=4890, p1=287, p2=4544, p3=0, p4=0, p5=58, sr=95, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --8ebb9f2f-Z-- --7492956f-A-- [31/Aug/2026:07:31:26.503093 +0300] apUDnn7glkZrdsSdRApJ8wAAAII 34.73.181.25 55556 127.0.0.1 7081 --7492956f-B-- GET /laravel/.env HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 100.125.45.109 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 100.125.45.109 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 100.125.45.109 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 100.125.45.109 Upgrade-Insecure-Requests: 1 X-Client-Ip: 100.125.45.109 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 100.125.45.109 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --7492956f-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --7492956f-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/laravel/.env"] [unique_id "apUDnn7glkZrdsSdRApJ8wAAAII"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150686349240 153955 (- - -) Stopwatch2: 1788150686349240 153955; combined=6642, p1=292, p2=6287, p3=0, p4=0, p5=62, sr=102, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --7492956f-Z-- --bb76593d-A-- [31/Aug/2026:07:31:26.511978 +0300] apUDntmUuou1H8H2UKXEPwAAANA 34.73.181.25 55544 127.0.0.1 7081 --bb76593d-B-- GET /config/.env.php HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 172.17.188.36 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 172.17.188.36 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 172.17.188.36 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 172.17.188.36 Upgrade-Insecure-Requests: 1 X-Client-Ip: 172.17.188.36 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 172.17.188.36 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --bb76593d-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --bb76593d-H-- Message: Warning. Matched phrase ".env.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/config/.env.php||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Matched phrase ".env.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/config/.env.php||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".env.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/config/.env.php||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/config/.env.php"] [unique_id "apUDntmUuou1H8H2UKXEPwAAANA"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".env.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/config/.env.php||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/config/.env.php"] [unique_id "apUDntmUuou1H8H2UKXEPwAAANA"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150686348462 163622 (- - -) Stopwatch2: 1788150686348462 163622; combined=35449, p1=359, p2=35020, p3=0, p4=0, p5=70, sr=155, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --bb76593d-Z-- --3a70162c-A-- [31/Aug/2026:07:31:26.541748 +0300] apUDntmUuou1H8H2UKXEQAAAANE 34.73.181.25 55562 127.0.0.1 7081 --3a70162c-B-- GET /.env.php.bak HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 172.25.37.10 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 172.25.37.10 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 172.25.37.10 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 172.25.37.10 Upgrade-Insecure-Requests: 1 X-Client-Ip: 172.25.37.10 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 172.25.37.10 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --3a70162c-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --3a70162c-H-- Message: Warning. Matched phrase ".env.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.env.php.bak||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Matched phrase ".env.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.env.php.bak||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".env.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/.env.php.bak||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/.env.php.bak"] [unique_id "apUDntmUuou1H8H2UKXEQAAAANE"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase ".env.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/.env.php.bak||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/.env.php.bak"] [unique_id "apUDntmUuou1H8H2UKXEQAAAANE"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150686403683 138154 (- - -) Stopwatch2: 1788150686403683 138154; combined=37492, p1=260, p2=37169, p3=0, p4=0, p5=63, sr=96, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --3a70162c-Z-- --27f8364d-A-- [31/Aug/2026:07:31:26.709199 +0300] apUDnm7fDIutYTwcPOkafQAAAFE 34.73.181.25 55592 127.0.0.1 7081 --27f8364d-B-- GET /configuration.php.bak HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 100.83.50.152 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 100.83.50.152 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 100.83.50.152 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 100.83.50.152 Upgrade-Insecure-Requests: 1 X-Client-Ip: 100.83.50.152 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 100.83.50.152 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --27f8364d-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --27f8364d-H-- Message: Warning. Matched phrase "/configuration.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "/configuration.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/configuration.php.bak"] [unique_id "apUDnm7fDIutYTwcPOkafQAAAFE"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150686643121 66189 (- - -) Stopwatch2: 1788150686643121 66189; combined=4428, p1=238, p2=4127, p3=0, p4=0, p5=62, sr=80, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --27f8364d-Z-- --453a8c1b-A-- [31/Aug/2026:07:31:26.789982 +0300] apUDntmUuou1H8H2UKXEQgAAAMI 34.73.181.25 55610 127.0.0.1 7081 --453a8c1b-B-- GET /.env.swp HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 192.168.148.213 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 192.168.148.213 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 192.168.148.213 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 192.168.148.213 Upgrade-Insecure-Requests: 1 X-Client-Ip: 192.168.148.213 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 192.168.148.213 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --453a8c1b-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --453a8c1b-H-- Message: Warning. Pattern match "(\\.swp|~)$" at REQUEST_BASENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "309"] [id "77142201"] [msg "IM360 WAF: Possible enumeration of sensitive data (dirb)||MVN:REQUEST_BASENAME||T:APACHE||MV:.env.swp||"] [severity "NOTICE"] [tag "service_i360custom"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\.swp|~)$" at REQUEST_BASENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "309"] [id "77142201"] [msg "IM360 WAF: Possible enumeration of sensitive data (dirb)||MVN:REQUEST_BASENAME||T:APACHE||MV:.env.swp||"] [severity "NOTICE"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/.env.swp"] [unique_id "apUDntmUuou1H8H2UKXEQgAAAMI"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150686698077 92018 (- - -) Stopwatch2: 1788150686698077 92018; combined=4719, p1=236, p2=4418, p3=0, p4=0, p5=65, sr=77, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --453a8c1b-Z-- --9af7f705-A-- [31/Aug/2026:07:31:26.821212 +0300] apUDnifaLSuAj0yzdueTIAAAAAM 34.73.181.25 55584 127.0.0.1 7081 --9af7f705-B-- GET /config.php.bak HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 100.104.9.168 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 100.104.9.168 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 100.104.9.168 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 100.104.9.168 Upgrade-Insecure-Requests: 1 X-Client-Ip: 100.104.9.168 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 100.104.9.168 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --9af7f705-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --9af7f705-H-- Message: Warning. Matched phrase "/config.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "/config.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/config.php.bak"] [unique_id "apUDnifaLSuAj0yzdueTIAAAAAM"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150686614770 206556 (- - -) Stopwatch2: 1788150686614770 206556; combined=5072, p1=231, p2=4786, p3=0, p4=0, p5=55, sr=86, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --9af7f705-Z-- --4a5a1552-A-- [31/Aug/2026:07:31:26.870921 +0300] apUDntmUuou1H8H2UKXEQwAAANU 34.73.181.25 55616 127.0.0.1 7081 --4a5a1552-B-- GET /public/.env HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 10.211.70.244 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 10.211.70.244 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 10.211.70.244 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 10.211.70.244 Upgrade-Insecure-Requests: 1 X-Client-Ip: 10.211.70.244 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 10.211.70.244 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --4a5a1552-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --4a5a1552-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/public/.env"] [unique_id "apUDntmUuou1H8H2UKXEQwAAANU"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150686720916 150117 (- - -) Stopwatch2: 1788150686720916 150117; combined=4835, p1=266, p2=4511, p3=0, p4=0, p5=57, sr=84, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --4a5a1552-Z-- --be399765-A-- [31/Aug/2026:07:31:26.971427 +0300] apUDnn7glkZrdsSdRApJ9QAAAIs 34.73.181.25 55620 127.0.0.1 7081 --be399765-B-- GET /web/.env HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 10.18.76.71 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 10.18.76.71 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 10.18.76.71 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 10.18.76.71 Upgrade-Insecure-Requests: 1 X-Client-Ip: 10.18.76.71 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 10.18.76.71 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --be399765-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --be399765-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/web/.env"] [unique_id "apUDnn7glkZrdsSdRApJ9QAAAIs"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150686902609 68907 (- - -) Stopwatch2: 1788150686902609 68907; combined=5107, p1=297, p2=4753, p3=0, p4=0, p5=57, sr=92, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --be399765-Z-- --3d225b36-A-- [31/Aug/2026:07:31:27.023888 +0300] apUDnn7glkZrdsSdRApJ9gAAAJM 34.73.181.25 55628 127.0.0.1 7081 --3d225b36-B-- GET /storage/.env HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 100.89.221.10 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 100.89.221.10 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 100.89.221.10 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 100.89.221.10 Upgrade-Insecure-Requests: 1 X-Client-Ip: 100.89.221.10 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 100.89.221.10 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --3d225b36-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --3d225b36-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/storage/.env"] [unique_id "apUDnn7glkZrdsSdRApJ9gAAAJM"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150686956235 67740 (- - -) Stopwatch2: 1788150686956235 67740; combined=5545, p1=322, p2=5177, p3=0, p4=0, p5=46, sr=89, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --3d225b36-Z-- --cf612a2e-A-- [31/Aug/2026:07:31:27.085770 +0300] apUDnn7glkZrdsSdRApJ9wAAAJU 34.73.181.25 55634 127.0.0.1 7081 --cf612a2e-B-- GET /wp/.env HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 192.168.22.52 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 192.168.22.52 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 192.168.22.52 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 192.168.22.52 Upgrade-Insecure-Requests: 1 X-Client-Ip: 192.168.22.52 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 192.168.22.52 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --cf612a2e-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --cf612a2e-H-- Message: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. String match "/.env" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "423"] [id "77316757"] [msg "IM360 WAF: Laravel env file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/wp/.env"] [unique_id "apUDnn7glkZrdsSdRApJ9wAAAJU"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150686982651 103208 (- - -) Stopwatch2: 1788150686982651 103208; combined=4655, p1=243, p2=4352, p3=0, p4=0, p5=59, sr=79, sw=1, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --cf612a2e-Z-- --ec426506-A-- [31/Aug/2026:07:31:27.156144 +0300] apUDn27fDIutYTwcPOkafgAAAEw 34.73.181.25 55646 127.0.0.1 7081 --ec426506-B-- GET /wp-config.php~ HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 10.199.79.64 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 10.199.79.64 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 10.199.79.64 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 10.199.79.64 Upgrade-Insecure-Requests: 1 X-Client-Ip: 10.199.79.64 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 10.199.79.64 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --ec426506-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --ec426506-H-- Message: Warning. Matched phrase "wp-config.php~" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/wp-config.php~||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Matched phrase "wp-config.php~" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/wp-config.php~||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Message: Warning. Pattern match "(\\.swp|~)$" at REQUEST_BASENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "309"] [id "77142201"] [msg "IM360 WAF: Possible enumeration of sensitive data (dirb)||MVN:REQUEST_BASENAME||T:APACHE||MV:wp-config.php~||"] [severity "NOTICE"] [tag "service_i360custom"] Message: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "wp-config.php~" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/wp-config.php~||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/wp-config.php~"] [unique_id "apUDn27fDIutYTwcPOkafgAAAEw"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "wp-config.php~" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/wp-config.php~||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/wp-config.php~"] [unique_id "apUDn27fDIutYTwcPOkafgAAAEw"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\.swp|~)$" at REQUEST_BASENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "309"] [id "77142201"] [msg "IM360 WAF: Possible enumeration of sensitive data (dirb)||MVN:REQUEST_BASENAME||T:APACHE||MV:wp-config.php~||"] [severity "NOTICE"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/wp-config.php~"] [unique_id "apUDn27fDIutYTwcPOkafgAAAEw"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/wp-config.php~"] [unique_id "apUDn27fDIutYTwcPOkafgAAAEw"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150687021543 134690 (- - -) Stopwatch2: 1788150687021543 134690; combined=38069, p1=255, p2=37737, p3=0, p4=0, p5=77, sr=78, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --ec426506-Z-- --81566138-A-- [31/Aug/2026:07:31:27.162923 +0300] apUDn37glkZrdsSdRApJ@AAAAI4 34.73.181.25 55664 127.0.0.1 7081 --81566138-B-- GET /wp-config.php.swp HTTP/1.1 Host: alexandervodka.com X-Real-IP: 34.73.181.25 X-Forwarded-For: 172.17.143.31 X-Accel-Internal: /internal-nginx-static-location User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: en-US,en;q=0.9 Cf-Connecting-Ip: 172.17.143.31 Cookie: csrfToken=vdFMns3Nx3j7av%2BSxRroYjE3ZDQ0Njg3ZWM3OTBhNzcyZmJkMjgzYTA0NjA1ODljMWQzM2UxMWY%3D Fastly-Client-Ip: 172.17.143.31 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 True-Client-Ip: 172.17.143.31 Upgrade-Insecure-Requests: 1 X-Client-Ip: 172.17.143.31 X-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware X-Originating-Ip: 172.17.143.31 sec-ch-ua: "Brave";v="149", "Chromium";v="149", "Not)A;Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Linux" --81566138-F-- HTTP/1.1 404 Not Found X-Powered-By: PHP/8.5.9 Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 --81566138-H-- Message: Warning. Matched phrase "wp-config.php." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/wp-config.php.swp||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] Message: Warning. Matched phrase "wp-config.php." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/wp-config.php.swp||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] Message: Warning. Pattern match "(\\.swp|~)$" at REQUEST_BASENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "309"] [id "77142201"] [msg "IM360 WAF: Possible enumeration of sensitive data (dirb)||MVN:REQUEST_BASENAME||T:APACHE||MV:wp-config.php.swp||"] [severity "NOTICE"] [tag "service_i360custom"] Message: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "wp-config.php." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_infectors.conf"] [line "58"] [id "77142160"] [msg "IM360 WAF: Infectors. Dirb like fuzzing||MVN:REQUEST_FILENAME||MV:/wp-config.php.swp||T:APACHE||"] [severity "DEBUG"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/wp-config.php.swp"] [unique_id "apUDn37glkZrdsSdRApJ@AAAAI4"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "wp-config.php." at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "27"] [id "77140739"] [msg "IM360 WAF: Dirb like fuzzing||MVN:REQUEST_FILENAME||T:APACHE||MV:/wp-config.php.swp||"] [severity "NOTICE"] [tag "service_i360custom"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/wp-config.php.swp"] [unique_id "apUDn37glkZrdsSdRApJ@AAAAI4"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Pattern match "(\\\\\\\\.swp|~)$" at REQUEST_BASENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "309"] [id "77142201"] [msg "IM360 WAF: Possible enumeration of sensitive data (dirb)||MVN:REQUEST_BASENAME||T:APACHE||MV:wp-config.php.swp||"] [severity "NOTICE"] [tag "service_i360custom"] [hostname "alexandervodka.com"] [uri "/wp-config.php.swp"] [unique_id "apUDn37glkZrdsSdRApJ@AAAAI4"] Apache-Error: [file "apache2_util.c"] [line 287] [level 3] ModSecurity: Warning. Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/etc/httpd/conf/modsecurity.d/rules/custom/006_i360_4_custom.conf"] [line "426"] [id "77316758"] [msg "IM360 WAF: Private file access||T:APACHE||QS:"] [severity "NOTICE"] [tag "service_i360custom"] [tag "service_i360"] [tag "noshow"] [hostname "alexandervodka.com"] [uri "/wp-config.php.swp"] [unique_id "apUDn37glkZrdsSdRApJ@AAAAI4"] Apache-Handler: proxy:unix:/var/www/vhosts/system/alexandervodka.com/php-fpm.sock|fcgi://127.0.0.1:9000 Stopwatch: 1788150687037359 125652 (- - -) Stopwatch2: 1788150687037359 125652; combined=32258, p1=302, p2=31883, p3=0, p4=0, p5=73, sr=96, sw=0, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --81566138-Z-- --72152e75-A-- [31/Aug/2026:07:32:04.784701 +0300] apUDxNmUuou1H8H2UKXEcgAAAMU 138.197.193.77 40658 127.0.0.1 7081 --72152e75-B-- POST /wp-login.php HTTP/1.1 Host: ajutam.ro X-Real-IP: 138.197.193.77 X-Accel-Internal: /internal-nginx-static-location Content-Length: 111 Accept: */* User-Agent: Mozilla/5.0 Content-Type: application/x-www-form-urlencoded Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818 --72152e75-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --72152e75-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:07-32.138.197.193.77"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788150724724259 60501 (- - -) Stopwatch2: 1788150724724259 60501; combined=59135, p1=268, p2=58241, p3=0, p4=0, p5=442, sr=108, sw=184, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --72152e75-Z-- --f9b03763-A-- [31/Aug/2026:07:34:13.196495 +0300] apUERW7fDIutYTwcPOkaqAAAAFg 207.154.219.81 45234 127.0.0.1 7081 --f9b03763-B-- POST /wp-login.php HTTP/1.1 Host: ajutam.ro X-Real-IP: 207.154.219.81 X-Accel-Internal: /internal-nginx-static-location Content-Length: 109 Accept: */* User-Agent: Mozilla/5.0 Content-Type: application/x-www-form-urlencoded Cookie: wp-settings-time-1=1390368100; wordpress_test_cookie=WP+Cookie+check; bdshare_firstime=1388392036818 --f9b03763-F-- HTTP/1.1 403 Forbidden Last-Modified: Fri, 01 May 2020 21:00:27 GMT ETag: "31b-5a49c787f10c0" Accept-Ranges: bytes Content-Length: 795 Content-Type: text/html --f9b03763-H-- Message: Access denied with code 403 (phase 2). [file "/etc/httpd/conf/modsecurity.d/rules/custom/003_i360_2_bruteforce.conf"] [line "196"] [id "33303"] [msg "IM360 WAF: WordPress Bruteforce RBL block||T:APACHE||MV:07-34.207.154.219.81"] [severity "CRITICAL"] [tag "wp_core"] Message: Operator EQ matched 1 at TX:trapped. [file "/etc/httpd/conf/modsecurity.d/rules/custom/000_i360_0.conf"] [line "127"] [id "33329"] [msg "IPRec: G: P: F:||T:APACHE||R:403"] [severity "DEBUG"] [tag "service_i360"] [tag "noshow"] Action: Intercepted (phase 2) Stopwatch: 1788150853132856 63723 (- - -) Stopwatch2: 1788150853132856 63723; combined=61208, p1=416, p2=60009, p3=0, p4=0, p5=573, sr=161, sw=210, l=0, gc=0 Producer: ModSecurity for Apache/2.9.14 (http://www.modsecurity.org/). Server: Apache Engine-Mode: "ENABLED" --f9b03763-Z--
Save
cmd:
run