๐ซ๐ฎ
oh.mg
2026-06-26 22:42:12
(1 hour ago)
[Sat Jun 27 00:42:08.386330 2026] [security2:error] [pid 1186615:tid 1186633] [client 43.152.24.44:6 ...
show more
[Sat Jun 27 00:42:08.386330 2026] [security2:error] [pid 1186615:tid 1186633] [client 43.152.24.44:64652] [client 43.152.24.44] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.10.0-dev"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "archive.mmn.on.ca"] [uri "/.env.local"] [unique_id "aj8AQG9rjDtGFjNjqE97HAAAAFA"]
...
show less
Web App Attack
Bad Web Bot
๐ซ๐ฎ
oh.mg
2026-06-24 04:54:57
(2 days ago)
[Wed Jun 24 06:54:56.288987 2026] [security2:error] [pid 679725:tid 679734] [client 43.152.24.44:558 ...
show more
[Wed Jun 24 06:54:56.288987 2026] [security2:error] [pid 679725:tid 679734] [client 43.152.24.44:55873] [client 43.152.24.44] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.10.0-dev"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "archive.mmn.on.ca"] [uri "/.envrc.sample"] [unique_id "ajtjIG1hyrwjtA0l7BU6-wAAAEc"]
...
show less
Web App Attack
Bad Web Bot
๐ซ๐ฎ
oh.mg
2026-06-19 12:12:39
(1 week ago)
[Fri Jun 19 14:12:39.312862 2026] [security2:error] [pid 4000670:tid 4000691] [client 43.152.24.44:8 ...
show more
[Fri Jun 19 14:12:39.312862 2026] [security2:error] [pid 4000670:tid 4000691] [client 43.152.24.44:8492] [client 43.152.24.44] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.10.0-dev"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "archive.mmn.on.ca"] [uri "/.aws/credentials"] [unique_id "ajUyN7b8HogpFylfhDJN7AAAAFI"]
...
show less
Web App Attack
Bad Web Bot
๐ซ๐ฎ
oh.mg
2026-06-17 07:01:19
(1 week ago)
[Wed Jun 17 09:01:19.116050 2026] [security2:error] [pid 3590499:tid 3590547] [client 43.152.24.44:4 ...
show more
[Wed Jun 17 09:01:19.116050 2026] [security2:error] [pid 3590499:tid 3590547] [client 43.152.24.44:41722] [client 43.152.24.44] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.10.0-dev"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "archive.mmn.on.ca"] [uri "/images/images/images/images/images/images/cache.php"] [unique_id "ajJGP-ZCjHB810MXzTHPRQAAANM"], referer: www.google.com
...
show less
Web App Attack
Bad Web Bot
๐ซ๐ฎ
oh.mg
2026-06-16 11:42:48
(1 week ago)
[Tue Jun 16 13:42:46.781702 2026] [security2:error] [pid 3445405:tid 3445418] [client 43.152.24.44:5 ...
show more
[Tue Jun 16 13:42:46.781702 2026] [security2:error] [pid 3445405:tid 3445418] [client 43.152.24.44:5669] [client 43.152.24.44] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.10.0-dev"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "archive.mmn.on.ca"] [uri "/.git/info"] [unique_id "ajE2tilGQm-5ESXVAbypawAAAAs"]
...
show less
Web App Attack
Bad Web Bot
๐ซ๐ฎ
oh.mg
2026-06-16 02:35:05
(1 week ago)
[Tue Jun 16 04:35:04.747721 2026] [security2:error] [pid 3375449:tid 3375475] [client 43.152.24.44:5 ...
show more
[Tue Jun 16 04:35:04.747721 2026] [security2:error] [pid 3375449:tid 3375475] [client 43.152.24.44:55703] [client 43.152.24.44] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [ver "OWASP_CRS/4.10.0-dev"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "archive.mmn.on.ca"] [uri "/.env.old"] [unique_id "ajC2WDDOqJguVECH5zd3sAAAAJc"]
...
show less
Web App Attack
Bad Web Bot
๐ซ๐ฎ
oh.mg
2026-06-14 23:14:03
(1 week ago)
43.152.24.44 - - [15/Jun/2026:01:13:58 +0200] "GET /.env.local.bak HTTP/1.1" 403 2251 "-" "Mozilla/5 ...
show more
43.152.24.44 - - [15/Jun/2026:01:13:58 +0200] "GET /.env.local.bak HTTP/1.1" 403 2251 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/65.0.3325.146 Safari/537.36"
43.152.24.44 - - [15/Jun/2026:01:13:58 +0200] "GET /dev/.env HTTP/1.1" 403 2251 "-" "Mozilla/5.0 (X11; CrOS x86_64 12239.67.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.102 Safari/537.36"
43.152.24.44 - - [15/Jun/2026:01:13:58 +0200] "GET /backend/.env.backup HTTP/1.1" 403 2251 "-" "Mozilla/5.0 (compatible; archive.org_bot +http://www.archive.org/details/archive.org_bot)"
43.152.24.44 - - [15/Jun/2026:01:13:58 +0200] "GET /frontend/.env.backup HTTP/1.1" 403 2251 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/67.0.3396.99 Safari/537.36"
43.152.24.44 - - [15/Jun/2026:01:13:59 +0200] "GET /app/sendgrid.env HTTP/1.1" 403 561 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 11_0 like Mac OS X) AppleWebKit/604.1.38 (KHTML, like Gecko) Version
...
show less
Bad Web Bot
Web App Attack