[FriJun1203:05:11.0347692026][security2:error][pid2888694:tid2888831][client34.73.204.166:0]ModSecur ...
show more[FriJun1203:05:11.0347692026][security2:error][pid2888694:tid2888831][client34.73.204.166:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"cpcalendars.archi-box.ch\"][uri\"/backup.sql\"][unique_id\"aitbR5isw4x6zxi6ey56awAAAQ4\"]
show less
TCP SYN flood detected by MikroTik RouterOS filter (sustained half-open connection rate from single ...
show moreTCP SYN flood detected by MikroTik RouterOS filter (sustained half-open connection rate from single source). Source automatically blacklisted.
show less
DDoS Attack
Anonymous
Multiple web server 400 error codes from same source ip
Auto-ban: 280 malicious requests on 2026-06-09 (e.g., env/backup probes, brute-force, or error burst ...
show moreAuto-ban: 280 malicious requests on 2026-06-09 (e.g., env/backup probes, brute-force, or error bursts).
show less
Aggressive web search of vulnerable pages: /phptest.php /phpinfo.php /info.php /php.php /test.php /d ...
show moreAggressive web search of vulnerable pages: /phptest.php /phpinfo.php /info.php /php.php /test.php /debug.php /admin/phpinfo.php /api/phpinfo.ph ...
show less
(CT) IP 34.73.204.166 (US/United States/166.204.73.34.bc.googleusercontent.com) found to have 346 co ...
show more(CT) IP 34.73.204.166 (US/United States/166.204.73.34.bc.googleusercontent.com) found to have 346 connections; Ports: *; Direction: inout; Trigger: CT_LIMIT; Logs:
show less