[ThuJun1117:02:53.4329342026][security2:error][pid2217252:tid2217280][client34.39.171.15:0]ModSecuri ...
show more[ThuJun1117:02:53.4329342026][security2:error][pid2217252:tid2217280][client34.39.171.15:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:10\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.9\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"alessandrolucchini.ch\"][uri\"/api/.env.local\"][unique_id\"airOHQ10YiTKGkLv_goOQQAAAA0\"]
show less
(mod_security) mod_security triggered on hostname [redacted] 34.39.171.15 (BR/Brazil/15.171.39.34.bc ...
show more(mod_security) mod_security triggered on hostname [redacted] 34.39.171.15 (BR/Brazil/15.171.39.34.bc.googleusercontent.com)
show less
{"level":"info","ts":1781181736.452883,"logger":"http.log.access.log1","msg":"handled request","requ ...
show more{"level":"info","ts":1781181736.452883,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.39.171.15","remote_port":"56800","client_ip":"34.39.171.15","proto":"HTTP/1.1","method":"GET","host":"status.tinylytics.app","uri":"/.env.qa","headers":{"Connection":["close"],"User-Agent":["Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/67.0.3396.62 Safari/537.36"],"Accept-Charset":["utf-8"],"Accept-Encoding":["gzip"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"","server_name":"status.tinylytics.app","ech":false}},"bytes_read":0,"user_id":"","duration":0.000297829,"size":0,"status":429,"resp_headers":{"Server":["Caddy"],"Alt-Svc":["h3=\":443\"; ma=2592000"],"Retry-After":["1"]}}
{"level":"info","ts":1781181736.724479,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.39.171.15","remote_port":"56812","client_ip":"34.39.171.15","proto":"HTTP/1.1","method":"GET","host":"sta
...
show less
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show moreAuto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-06-09.
show less
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.39.171.15 (BR/Brazil/15.171.39.34. ...
show more(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.39.171.15 (BR/Brazil/15.171.39.34.bc.googleusercontent.com): 1 in the last 3600 secs (0-195)
show less
37 requests, including :
GET /.env.old HTTP/1.1
GET /api/v3/.env HTTP/1.1
GET /app/.env.old HTTP/1. ...
show more37 requests, including :
GET /.env.old HTTP/1.1
GET /api/v3/.env HTTP/1.1
GET /app/.env.old HTTP/1.1
GET /.env.sample HTTP/1.1
GET /.env.qa HTTP/1.1
GET /symfony/.env HTTP/1.1
GET /.env.live HTTP/1.1
GET /.env.development HTTP/1.1
GET /.env.docker HTTP/1.1
GET /.env.pre-production HTTP/1.1
GET /api/backend/.env HTTP/1.1
GET /env HTTP/1.1
GET /.env.local HTTP/1.1
GET /.env.staging HTTP/1.1
GET /data/.env HTTP/1.1
GET /.env.prod.bak HTTP/1.1
GET /services/api/.env HTTP/1.1
GET /env.txt HTTP/1.1
GET /.env.production HTTP/1.1
show less
Hacking
Bad Web Bot
Web App Attack
Showing 1 to
15
of 35 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ