{"level":"info","ts":1780928052.8082616,"logger":"http.log.access.log1","msg":"handled request","req ...
show more{"level":"info","ts":1780928052.8082616,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.179.169.61","remote_port":"34832","client_ip":"34.179.169.61","proto":"HTTP/1.1","method":"GET","host":"www.www.en.cvbqnwww.159.89.98.98.nip.io","uri":"/actuator/threaddump","headers":{"User-Agent":["Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Safari/537.36"],"Accept-Charset":["utf-8"],"Accept-Encoding":["gzip"],"Connection":["close"]}},"bytes_read":0,"user_id":"","duration":0.000057229,"size":0,"status":308,"resp_headers":{"Server":["Caddy"],"Connection":["close"],"Location":["https://www.www.en.cvbqnwww.159.89.98.98.nip.io/actuator/threaddump"],"Content-Type":[]}}
{"level":"info","ts":1780928052.8141122,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.179.169.61","remote_port":"34848","client_ip":"34.179.169.61","proto":"HTTP/1.1","method":"GET","host":"www.www.en.cv
...
show less
Aggressive web search of vulnerable pages: /debug.php /php.php /info.php /api/phpinfo.php /admin/php ...
show moreAggressive web search of vulnerable pages: /debug.php /php.php /info.php /api/phpinfo.php /admin/phpinfo.php /test.php /phpinfo.php /config.php ...
show less
[MonJun0809:55:15.2639532026][security2:error][pid3195932:tid3196341][client34.179.169.61:0]ModSecur ...
show more[MonJun0809:55:15.2639532026][security2:error][pid3195932:tid3196341][client34.179.169.61:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.9\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"www.avvnicolaurbani.ch.81-17-25-250.cpanel.site\"][uri\"/actuator/logfile\"][unique_id\"aiZ1YyZOxGuMuJzUxKd-gQAAAJI\"]
show less
[MonJun0809:22:53.2955722026][security2:error][pid857673:tid857823][client34.179.169.61:0]ModSecurit ...
show more[MonJun0809:22:53.2955722026][security2:error][pid857673:tid857823][client34.179.169.61:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"cpcalendars.danielasilvia.ch\"][uri\"/dump.sql\"][unique_id\"aiZtzWivz0YVvvCTUAidbQAAARg\"]
show less
http-probing - IP: 34.179.169.61 - time="2026-06-08T06:51:20+02:00" level=info msg="(555f66b4f6a745 ...
show morehttp-probing - IP: 34.179.169.61 - time="2026-06-08T06:51:20+02:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/http-probing by ip 34.179.169.61 (DE/396982) : 4h ban on Ip 34.179.169.61" module=db
show less