|
π¨π±
34.176.92.129
|
|
[Sat Sep 05 06:01:28.202418 2026] [security2:error] [pid 715462:tid 715462] [client 34.176.92.129:46 ...
show more
[Sat Sep 05 06:01:28.202418 2026] [security2:error] [pid 715462:tid 715462] [client 34.176.92.129:46064] ModSecurity: Warning. Pattern match "(?i)(?:b[\\"'\\\\)\\\\[\\\\x5c]*(?:(?:(?:\\\\|\\\\||&&)[\\\\s\\\\x0b]*)?\\\\$[!#\\\\(\\\\*\\\\-0-9\\\\?@_a-\\\\{]*)?\\\\x5c?u[\\"'\\\\)\\\\[\\\\x5c]*(?:(?:(?:\\\\|\\\\||&&)[\\\\s\\\\x0b]*)?\\\\$[!#\\\\(\\\\*\\\\-0-9\\\\?@_a-\\\\{]*)?\\\\x5c?s[\\"'\\\\)\\\\[\\\\x5c]*(?:(?:(?:\\\\|\\\\||&&)[\\\\s\\\\x0b]*)?\\\\$[!#\\\\(\\\\*\\\\-0-9\\ ..." at ARGS:0. [file "/etc/modsecurity/crs/current/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "205"] [id "932235"] [msg "Remote Command Execution: Unix Command Injection (command without evasion)"] [data "Matched Data: | base64 found within ARGS:0: {\\x22then\\x22: \\x22$1:__proto__:then\\x22, \\x22status\\x22: \\x22resolved_model\\x22, \\x22reason\\x22: -1, \\x22value\\x22: \\x22{\\x5c\\x22then\\x5c\\x22:\\x5c\\x22$B1337\\x5c\\x22}\\x22, \\x22_response\\x22: {\\x22_prefix\\x22: \\x22var res=process.mainMo
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
π―π΅
43.130.228.73
|
|
[Sat Sep 05 05:51:18.774013 2026] [security2:error] [pid 716377:tid 716377] [client 43.130.228.73:58 ...
show more
[Sat Sep 05 05:51:18.774013 2026] [security2:error] [pid 716377:tid 716377] [client 43.130.228.73:58880] ModSecurity: Warning. Pattern match "\\\\b(?:keep-alive|close),\\\\s?(?:keep-alive|close)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "402"] [id "920210"] [msg "Multiple/Conflicting Connection Header Data Found"] [data "keep-alive, close"] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [hostname "fotos.robertomurillo.net"] [uri "/"] [unique_id "apwCNllnmVZA8bqtwJkyFgAAAAM"]
[Sat Sep 05 05:51:18.776031 2026] [security2:error] [pid 716377:tid 716377] [client 43.130.228.73:58880] ModSecurity: Warning. Unconditional match in SecAction. [file "/etc/modsecurity/crs/current/rules/RESPONSE-980-CORRELATION.conf"
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
π³π±
89.42.231.200
|
|
...
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
π³π±
93.174.93.12
|
|
...
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
π§π·
16.5.0.245
|
|
...
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
π©πͺ
43.158.91.71
|
|
[Sat Sep 05 04:32:41.630897 2026] [security2:error] [pid 643338:tid 643338] [client 43.158.91.71:464 ...
show more
[Sat Sep 05 04:32:41.630897 2026] [security2:error] [pid 643338:tid 643338] [client 43.158.91.71:46492] ModSecurity: Warning. Pattern match "\\\\b(?:keep-alive|close),\\\\s?(?:keep-alive|close)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "402"] [id "920210"] [msg "Multiple/Conflicting Connection Header Data Found"] [data "keep-alive, close"] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [hostname "186.32.240.17"] [uri "/"] [unique_id "apvvyfs-RgO8jLJFpLuVUwAAAAg"]
[Sat Sep 05 04:32:41.631079 2026] [security2:error] [pid 643338:tid 643338] [client 43.158.91.71:46492] ModSecurity: Warning. Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at REQUEST_HEADERS:Host. [file "/etc/
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
π¨π±
119.8.148.253
|
|
119.8.148.253 - - [05/Sep/2026:04:06:25 -0600] "POST /xmlrpc.php HTTP/1.1" 403 5347 "-" "Mozilla/5.0 ...
show more
119.8.148.253 - - [05/Sep/2026:04:06:25 -0600] "POST /xmlrpc.php HTTP/1.1" 403 5347 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:84.0) Gecko/20100101 Firefox/84.0"
...
show less
|
Web Spam
Brute-Force
Web App Attack
|
|
πΊπΈ
66.132.195.95
|
|
[Sat Sep 05 03:51:21.825446 2026] [security2:error] [pid 672777:tid 672777] [client 66.132.195.95:60 ...
show more
[Sat Sep 05 03:51:21.825446 2026] [security2:error] [pid 672777:tid 672777] [client 66.132.195.95:60254] ModSecurity: Warning. Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at REQUEST_HEADERS:Host. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "773"] [id "920350"] [msg "Host header is a numeric IP address"] [data "186.32.240.17"] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [hostname "186.32.240.17"] [uri "/"] [unique_id "apvmGQybct7R-TwT7sGr4AAAAAc"]
[Sat Sep 05 03:51:21.827323 2026] [security2:error] [pid 672777:tid 672777] [client 66.132.195.95:60254] ModSecurity: Warning. Unconditional match in SecAction. [file "/etc/modsecurity/crs/current/rules/RESPONSE-980-CORRELATION.conf"] [line "99"] [id "980170"]
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
πΊπΈ
170.106.35.137
|
|
170.106.35.137 - - [05/Sep/2026:03:34:53 -0600] "GET / HTTP/1.0" 400 744 "-" "-"
...
|
Bad Web Bot
|
|
πΊπΈ
66.132.172.184
|
|
[Sat Sep 05 03:25:14.268985 2026] [security2:error] [pid 679155:tid 679155] [client 66.132.172.184:4 ...
show more
[Sat Sep 05 03:25:14.268985 2026] [security2:error] [pid 679155:tid 679155] [client 66.132.172.184:40544] ModSecurity: Warning. Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at REQUEST_HEADERS:Host. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "773"] [id "920350"] [msg "Host header is a numeric IP address"] [data "186.32.240.17"] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [hostname "186.32.240.17"] [uri "/"] [unique_id "apvf-vijwoF8U0lJdEMTtAAAAAU"]
[Sat Sep 05 03:25:14.270822 2026] [security2:error] [pid 679155:tid 679155] [client 66.132.172.184:40544] ModSecurity: Warning. Unconditional match in SecAction. [file "/etc/modsecurity/crs/current/rules/RESPONSE-980-CORRELATION.conf"] [line "99"] [id "980170
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
πΈπ¬
47.128.96.17
|
|
47.128.96.17 - - [05/Sep/2026:03:24:55 -0600] "GET /robots.txt HTTP/1.1" 403 4551 "-" "-"
...
|
Bad Web Bot
|
|
π³π±
167.71.6.60
|
|
[Sat Sep 05 03:16:32.011244 2026] [security2:error] [pid 636980:tid 636980] [client 167.71.6.60:1556 ...
show more
[Sat Sep 05 03:16:32.011244 2026] [security2:error] [pid 636980:tid 636980] [client 167.71.6.60:15564] ModSecurity: Warning. String match within "/content-encoding/ /proxy/ /lock-token/ /content-range/ /if/ /x-http-method-override/ /x-http-method/ /x-method-override/ /x-middleware-subrequest/ /expect/" at TX:header_name_920450_content-encoding. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920450"] [msg "HTTP header is restricted by policy (/content-encoding/)"] [data "Restricted header detected: /content-encoding/"] [severity "CRITICAL"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [hostname "myserver.robertomurillo.net"] [uri "/"] [unique_id "apvd8OUEEZ-RctB6tlh8ZAAAAAA"], referer: https://myserver.robertomurillo.net/
[Sat Sep 05 03:16:32.014194 20
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
π²π½
132.248.15.189
|
|
[Sat Sep 05 03:16:15.416833 2026] [security2:error] [pid 637343:tid 637343] [client 132.248.15.189:3 ...
show more
[Sat Sep 05 03:16:15.416833 2026] [security2:error] [pid 637343:tid 637343] [client 132.248.15.189:35022] ModSecurity: Warning. Match of "within %{tx.allowed_request_content_type}" against "TX:content_type" required. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1002"] [id "920420"] [msg "Request content type is not allowed by policy"] [data "|text/html|"] [severity "CRITICAL"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/255/153"] [hostname "robertomurillo.net"] [uri "/wp-json/acf/v3/options/a"] [unique_id "apvd38s2Zk784iitAstHqwAAAAM"]
[Sat Sep 05 03:16:15.421708 2026] [security2:error] [pid 637343:tid 637343] [client 132.248.15.189:35022] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/etc/modsecur
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
πΊπΈ
65.49.20.67
|
|
[Sat Sep 05 03:05:28.189048 2026] [security2:error] [pid 667127:tid 667127] [client 65.49.20.67:6494 ...
show more
[Sat Sep 05 03:05:28.189048 2026] [security2:error] [pid 667127:tid 667127] [client 65.49.20.67:64946] ModSecurity: Warning. Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at REQUEST_HEADERS:Host. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "773"] [id "920350"] [msg "Host header is a numeric IP address"] [data "186.32.240.17"] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [hostname "186.32.240.17"] [uri "/"] [unique_id "apvbWMcE6FEcek7XLRrypgAAAAQ"]
[Sat Sep 05 03:05:28.190875 2026] [security2:error] [pid 667127:tid 667127] [client 65.49.20.67:64946] ModSecurity: Warning. Unconditional match in SecAction. [file "/etc/modsecurity/crs/current/rules/RESPONSE-980-CORRELATION.conf"] [line "99"] [id "980170"] [ms
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
πΊπΈ
66.132.195.67
|
|
[Sat Sep 05 02:52:02.533554 2026] [security2:error] [pid 636982:tid 636982] [client 66.132.195.67:32 ...
show more
[Sat Sep 05 02:52:02.533554 2026] [security2:error] [pid 636982:tid 636982] [client 66.132.195.67:32914] ModSecurity: Warning. Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at REQUEST_HEADERS:Host. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "773"] [id "920350"] [msg "Host header is a numeric IP address"] [data "186.32.240.17"] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [hostname "186.32.240.17"] [uri "/"] [unique_id "apvYMnUVQpmUhPzeN5tTjAAAAAE"]
[Sat Sep 05 02:52:02.684360 2026] [security2:error] [pid 636982:tid 636982] [client 66.132.195.67:32914] ModSecurity: Warning. Unconditional match in SecAction. [file "/etc/modsecurity/crs/current/rules/RESPONSE-980-CORRELATION.conf"] [line "99"] [id "980170"]
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
πΈπ¬
43.133.60.94
|
|
[Sat Sep 05 02:47:57.948409 2026] [security2:error] [pid 667127:tid 667127] [client 43.133.60.94:383 ...
show more
[Sat Sep 05 02:47:57.948409 2026] [security2:error] [pid 667127:tid 667127] [client 43.133.60.94:38354] ModSecurity: Warning. Pattern match "\\\\b(?:keep-alive|close),\\\\s?(?:keep-alive|close)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "402"] [id "920210"] [msg "Multiple/Conflicting Connection Header Data Found"] [data "keep-alive, close"] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [hostname "186.32.240.17"] [uri "/"] [unique_id "apvXPccE6FEcek7XLRrylgAAAAQ"]
[Sat Sep 05 02:47:57.948545 2026] [security2:error] [pid 667127:tid 667127] [client 43.133.60.94:38354] ModSecurity: Warning. Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at REQUEST_HEADERS:Host. [file "/etc/
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
π©πͺ
164.92.200.106
|
|
[Sat Sep 05 02:44:54.998285 2026] [security2:error] [pid 643338:tid 643338] [client 164.92.200.106:2 ...
show more
[Sat Sep 05 02:44:54.998285 2026] [security2:error] [pid 643338:tid 643338] [client 164.92.200.106:20694] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "566"] [id "920280"] [msg "Request Missing a Host Header"] [severity "CRITICAL"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [hostname "cursos.robertomurillo.net"] [uri "/"] [unique_id "apvWhvs-RgO8jLJFpLuU6AAAAAg"]
[Sat Sep 05 02:44:54.999740 2026] [security2:error] [pid 643338:tid 643338] [client 164.92.200.106:20694] ModSecurity: Warning. Unconditional match in SecAction. [file "/etc/modsecurity/crs/current/rules/RESPONSE-980-CORRELATION.conf"] [line "99"] [id "980170"] [msg "Anomaly Scores: (Inbound Scores: blocking=5, detection=5, per_pl=5-0-0-0
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
π©πͺ
46.101.234.147
|
|
46.101.234.147 - - [05/Sep/2026:02:44:52 -0600] "GET / HTTP/1.0" 400 744 "-" "-"
...
|
Bad Web Bot
|
|
π©πͺ
64.227.115.180
|
|
64.227.115.180 - - [05/Sep/2026:02:44:52 -0600] "GET / HTTP/1.0" 400 744 "-" "-"
...
|
Bad Web Bot
|
|
π©πͺ
142.93.171.97
|
|
[Sat Sep 05 02:44:52.163526 2026] [security2:error] [pid 637343:tid 637343] [client 142.93.171.97:32 ...
show more
[Sat Sep 05 02:44:52.163526 2026] [security2:error] [pid 637343:tid 637343] [client 142.93.171.97:32806] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "566"] [id "920280"] [msg "Request Missing a Host Header"] [severity "CRITICAL"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [hostname "cursos.robertomurillo.net"] [uri "/"] [unique_id "apvWhMs2Zk784iitAstHjAAAAAM"]
[Sat Sep 05 02:44:52.164769 2026] [security2:error] [pid 637343:tid 637343] [client 142.93.171.97:32806] ModSecurity: Warning. Unconditional match in SecAction. [file "/etc/modsecurity/crs/current/rules/RESPONSE-980-CORRELATION.conf"] [line "99"] [id "980170"] [msg "Anomaly Scores: (Inbound Scores: blocking=5, detection=5, per_pl=5-0-0-0,
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
π©πͺ
165.22.19.100
|
|
[Sat Sep 05 02:44:52.158388 2026] [security2:error] [pid 636984:tid 636984] [client 165.22.19.100:24 ...
show more
[Sat Sep 05 02:44:52.158388 2026] [security2:error] [pid 636984:tid 636984] [client 165.22.19.100:24570] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "566"] [id "920280"] [msg "Request Missing a Host Header"] [severity "CRITICAL"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [hostname "cursos.robertomurillo.net"] [uri "/"] [unique_id "apvWhLBEXUJXVD2yVnx4EgAAAAs"]
[Sat Sep 05 02:44:52.159618 2026] [security2:error] [pid 636984:tid 636984] [client 165.22.19.100:24570] ModSecurity: Warning. Unconditional match in SecAction. [file "/etc/modsecurity/crs/current/rules/RESPONSE-980-CORRELATION.conf"] [line "99"] [id "980170"] [msg "Anomaly Scores: (Inbound Scores: blocking=5, detection=5, per_pl=5-0-0-0,
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
π©πͺ
142.93.102.227
|
|
[Sat Sep 05 02:44:52.154838 2026] [security2:error] [pid 636982:tid 636982] [client 142.93.102.227:4 ...
show more
[Sat Sep 05 02:44:52.154838 2026] [security2:error] [pid 636982:tid 636982] [client 142.93.102.227:46150] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "566"] [id "920280"] [msg "Request Missing a Host Header"] [severity "CRITICAL"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [hostname "cursos.robertomurillo.net"] [uri "/"] [unique_id "apvWhHUVQpmUhPzeN5tThAAAAAE"]
[Sat Sep 05 02:44:52.156267 2026] [security2:error] [pid 636982:tid 636982] [client 142.93.102.227:46150] ModSecurity: Warning. Unconditional match in SecAction. [file "/etc/modsecurity/crs/current/rules/RESPONSE-980-CORRELATION.conf"] [line "99"] [id "980170"] [msg "Anomaly Scores: (Inbound Scores: blocking=5, detection=5, per_pl=5-0-0-0
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
π©πͺ
167.172.169.129
|
|
167.172.169.129 - - [05/Sep/2026:02:44:36 -0600] "GET / HTTP/1.0" 403 5449 "-" "-"
...
|
Bad Web Bot
|
|
ππ°
101.32.49.171
|
|
[Sat Sep 05 02:30:31.148308 2026] [security2:error] [pid 658165:tid 658165] [client 101.32.49.171:53 ...
show more
[Sat Sep 05 02:30:31.148308 2026] [security2:error] [pid 658165:tid 658165] [client 101.32.49.171:53142] ModSecurity: Warning. Pattern match "\\\\b(?:keep-alive|close),\\\\s?(?:keep-alive|close)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "402"] [id "920210"] [msg "Multiple/Conflicting Connection Header Data Found"] [data "keep-alive, close"] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [hostname "www.robertomurillo.net"] [uri "/"] [unique_id "apvTJ60rmht-hOuXFiABCwAAAAo"]
[Sat Sep 05 02:30:31.150245 2026] [security2:error] [pid 658165:tid 658165] [client 101.32.49.171:53142] ModSecurity: Warning. Unconditional match in SecAction. [file "/etc/modsecurity/crs/current/rules/RESPONSE-980-CORRELATION.conf"]
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
π©πͺ
85.215.108.97
|
|
[Sat Sep 05 02:01:35.889036 2026] [security2:error] [pid 637048:tid 637048] [client 85.215.108.97:55 ...
show more
[Sat Sep 05 02:01:35.889036 2026] [security2:error] [pid 637048:tid 637048] [client 85.215.108.97:55056] ModSecurity: Warning. Matched phrase "Mozlila" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/crs/current/rules/REQUEST-913-SCANNER-DETECTION.conf"] [line "56"] [id "913100"] [msg "Found User-Agent associated with security scanner"] [data "Matched Data: Mozlila found within REQUEST_HEADERS:User-Agent: Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36"] [severity "CRITICAL"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-reputation-scanner"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/SCANNER-DETECTION"] [tag "capec/1000/118/224/541/310"] [hostname "robertomurillo.net"] [uri "/wp-admin/includes/includes/cache.php"] [unique_id "apvMXzS2H47pEeEhjilkUAAAAAI"], referer: www.google.com
[Sat Sep 05 02:01
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|