|
๐ณ๐ฑ
85.11.167.199
|
|
[Sun Sep 06 09:33:46.216612 2026] [security2:error] [pid 1077883:tid 1077883] [client 85.11.167.199: ...
show more
[Sun Sep 06 09:33:46.216612 2026] [security2:error] [pid 1077883:tid 1077883] [client 85.11.167.199:51984] ModSecurity: Warning. Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at REQUEST_HEADERS:Host. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "773"] [id "920350"] [msg "Host header is a numeric IP address"] [data "186.32.240.17:80"] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [hostname "186.32.240.17"] [uri "/boaform/admin/formLogin"] [unique_id "ap2H2qSdOpFea0uY2za7FgAAAA8"], referer: http://186.32.240.17:80/admin/login.asp
[Sun Sep 06 09:33:46.219086 2026] [security2:error] [pid 1077883:tid 1077883] [client 85.11.167.199:51984] ModSecurity: Warning. Unconditional match in SecAction. [file "/etc/modsecu
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
๐ญ๐ฐ
43.161.233.190
|
|
[Sun Sep 06 09:32:28.977211 2026] [security2:error] [pid 1077678:tid 1077678] [client 43.161.233.190 ...
show more
[Sun Sep 06 09:32:28.977211 2026] [security2:error] [pid 1077678:tid 1077678] [client 43.161.233.190:44662] ModSecurity: Warning. Pattern match "\\\\b(?:keep-alive|close),\\\\s?(?:keep-alive|close)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "402"] [id "920210"] [msg "Multiple/Conflicting Connection Header Data Found"] [data "keep-alive, close"] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [hostname "186.32.240.17"] [uri "/"] [unique_id "ap2HjHkAf80tvL535jbOngAAAAk"]
[Sun Sep 06 09:32:28.977356 2026] [security2:error] [pid 1077678:tid 1077678] [client 43.161.233.190:44662] ModSecurity: Warning. Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at REQUEST_HEADERS:Host. [fil
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
๐บ๐ธ
74.7.227.137
|
|
[Sun Sep 06 09:26:47.038937 2026] [security2:error] [pid 1077679:tid 1077679] [client 74.7.227.137:3 ...
show more
[Sun Sep 06 09:26:47.038937 2026] [security2:error] [pid 1077679:tid 1077679] [client 74.7.227.137:36836] ModSecurity: Warning. Matched phrase "(inclusive)" at RESPONSE_BODY. [file "/etc/modsecurity/crs/current/rules/RESPONSE-953-DATA-LEAKAGES-PHP.conf"] [line "53"] [id "953100"] [msg "PHP Information Leakage"] [data "Matched Data: (inclusive) found within RESPONSE_BODY"] [severity "ERROR"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-php"] [tag "platform-multi"] [tag "attack-disclosure"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/DATA-LEAKAGES-PHP"] [tag "capec/1000/118/116"] [hostname "fotos.robertomurillo.net"] [uri "/index.php"] [unique_id "ap2GNg0x2kxw5Zix05q8WgAAAAs"], referer: https://fotos.robertomurillo.net/search.php
[Sun Sep 06 09:26:47.044948 2026] [security2:error] [pid 1077679:tid 1077679] [client 74.7.227.137:36836] ModSecurity: Access denied with code 403 (phase 4). Operator GE matched 4 at TX:blocking_outbound_anomaly_score. [file "
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
๐น๐ท
94.154.43.203
|
|
[Sun Sep 06 08:13:43.809243 2026] [security2:error] [pid 1077883:tid 1077883] [client 94.154.43.203: ...
show more
[Sun Sep 06 08:13:43.809243 2026] [security2:error] [pid 1077883:tid 1077883] [client 94.154.43.203:29396] ModSecurity: Warning. Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at REQUEST_HEADERS:Host. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "773"] [id "920350"] [msg "Host header is a numeric IP address"] [data "186.32.240.17:443"] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [hostname "186.32.240.17"] [uri "/"] [unique_id "ap11F6SdOpFea0uY2za6qgAAAA8"]
[Sun Sep 06 08:13:43.811004 2026] [security2:error] [pid 1077883:tid 1077883] [client 94.154.43.203:29396] ModSecurity: Warning. Unconditional match in SecAction. [file "/etc/modsecurity/crs/current/rules/RESPONSE-980-CORRELATION.conf"] [line "99"] [id "
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
๐บ๐ธ
137.184.179.94
|
|
[Sun Sep 06 08:13:31.739180 2026] [security2:error] [pid 1052624:tid 1052624] [client 137.184.179.94 ...
show more
[Sun Sep 06 08:13:31.739180 2026] [security2:error] [pid 1052624:tid 1052624] [client 137.184.179.94:44676] ModSecurity: Warning. Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at REQUEST_HEADERS:Host. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "773"] [id "920350"] [msg "Host header is a numeric IP address"] [data "186.32.240.17"] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [hostname "186.32.240.17"] [uri "/"] [unique_id "ap11C4ZKDA5xKmCJsZtLFQAAAAU"]
[Sun Sep 06 08:13:31.916052 2026] [security2:error] [pid 1052624:tid 1052624] [client 137.184.179.94:44676] ModSecurity: Warning. Unconditional match in SecAction. [file "/etc/modsecurity/crs/current/rules/RESPONSE-980-CORRELATION.conf"] [line "99"] [id "98
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
๐ฉ๐ช
43.131.39.179
|
|
[Sun Sep 06 07:57:20.354052 2026] [security2:error] [pid 1081481:tid 1081481] [client 43.131.39.179: ...
show more
[Sun Sep 06 07:57:20.354052 2026] [security2:error] [pid 1081481:tid 1081481] [client 43.131.39.179:52748] ModSecurity: Warning. Pattern match "\\\\b(?:keep-alive|close),\\\\s?(?:keep-alive|close)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "402"] [id "920210"] [msg "Multiple/Conflicting Connection Header Data Found"] [data "keep-alive, close"] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [hostname "robertomurillo.net"] [uri "/"] [unique_id "ap1xQHVvCVZnsjyH1-Y5UwAAAAA"]
[Sun Sep 06 07:57:20.355907 2026] [security2:error] [pid 1081481:tid 1081481] [client 43.131.39.179:52748] ModSecurity: Warning. Unconditional match in SecAction. [file "/etc/modsecurity/crs/current/rules/RESPONSE-980-CORRELATION.conf"]
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
๐ฎ๐ณ
103.69.88.38
|
|
[Sun Sep 06 07:51:37.145557 2026] [security2:error] [pid 1077741:tid 1077741] [client 103.69.88.38:6 ...
show more
[Sun Sep 06 07:51:37.145557 2026] [security2:error] [pid 1077741:tid 1077741] [client 103.69.88.38:63505] ModSecurity: Warning. Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at REQUEST_HEADERS:Host. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "773"] [id "920350"] [msg "Host header is a numeric IP address"] [data "0.0.0.0"] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [hostname "0.0.0.0"] [uri "/admin/config.php"] [unique_id "ap1v6UxkXwLAJGjjExz9ogAAAAw"]
[Sun Sep 06 07:51:37.147343 2026] [security2:error] [pid 1077741:tid 1077741] [client 103.69.88.38:63505] ModSecurity: Warning. Unconditional match in SecAction. [file "/etc/modsecurity/crs/current/rules/RESPONSE-980-CORRELATION.conf"] [line "99"] [id "98
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
๐ง๐ช
35.240.10.173
|
|
[Sun Sep 06 07:38:28.952951 2026] [security2:error] [pid 1076953:tid 1076953] [client 35.240.10.173: ...
show more
[Sun Sep 06 07:38:28.952951 2026] [security2:error] [pid 1076953:tid 1076953] [client 35.240.10.173:58648] ModSecurity: Warning. String match within ".ani/ .asa/ .asax/ .ascx/ .back/ .backup/ .bak/ .bck/ .bk/ .bkp/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .cnf/ .com/ .compositefont/ .config/ .conf/ .copy/ .crt/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dist/ .dll/ .dos/ .dpkg-dist/ .drv/ .gadget/ .hta/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .inf/ .ini/ .jks/ .jse/ .key/ .licx/ .lnk/ .log/ .mdb/ .msc/ .ocx/ .old/ .pass/ .pdb/ .pfx/ .pif/ .pem/ .pol/ .prf/ .printer/ .pwd/ .rdb/ .rdp/ .reg/ .resources/ .resx/ .sav/ .save/ .scr/ .sct/ .sh/ .shs/ .sql/ .sqlite/ .sqlite3/ .swap/ .swo/ .swp/ .sys/ .temp/ .tfstate/ .tlb/ .tmp/ .vb/ .vbe/ .vbs/ .vbproj/ .vsdisco/ .vxd/ .webinfo/ .ws/ .wsc/ .wsf/ .wsh/ .xsd/ .xsx/" at TX:extension. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1146"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
๐บ๐ธ
135.119.113.224
|
|
[Sun Sep 06 07:37:42.315715 2026] [security2:error] [pid 1052624:tid 1052624] [client 135.119.113.22 ...
show more
[Sun Sep 06 07:37:42.315715 2026] [security2:error] [pid 1052624:tid 1052624] [client 135.119.113.224:58346] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/crs/current/rules/REQUEST-913-SCANNER-DETECTION.conf"] [line "56"] [id "913100"] [msg "Found User-Agent associated with security scanner"] [data "Matched Data: zgrab found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 zgrab/0.x"] [severity "CRITICAL"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-reputation-scanner"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/SCANNER-DETECTION"] [tag "capec/1000/118/224/541/310"] [hostname "186.32.240.17"] [uri "/developmentserver/metadatauploader"] [unique_id "ap1spoZKDA5xKmCJsZtK_AAAAAU"]
[Sun Sep 06 07:37:42.315912 2026] [security2:error] [pid 1052624:tid 1052624] [client 135.119.113.224:58346] ModSecurity: Warning. Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
๐ซ๐ท
45.77.61.56
|
|
[Sun Sep 06 07:01:05.090194 2026] [security2:error] [pid 1052625:tid 1052625] [client 45.77.61.56:35 ...
show more
[Sun Sep 06 07:01:05.090194 2026] [security2:error] [pid 1052625:tid 1052625] [client 45.77.61.56:35814] ModSecurity: Warning. Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at REQUEST_HEADERS:Host. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "773"] [id "920350"] [msg "Host header is a numeric IP address"] [data "186.32.240.17"] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [hostname "186.32.240.17"] [uri "/"] [unique_id "ap1kEZN2ytO3uCgaMy8nFgAAAAo"]
[Sun Sep 06 07:01:05.266970 2026] [security2:error] [pid 1052625:tid 1052625] [client 45.77.61.56:35814] ModSecurity: Warning. Unconditional match in SecAction. [file "/etc/modsecurity/crs/current/rules/RESPONSE-980-CORRELATION.conf"] [line "99"] [id "980170"]
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
๐ธ๐ฌ
128.199.255.160
|
|
[Sun Sep 06 06:52:27.476635 2026] [security2:error] [pid 1052624:tid 1052624] [client 128.199.255.16 ...
show more
[Sun Sep 06 06:52:27.476635 2026] [security2:error] [pid 1052624:tid 1052624] [client 128.199.255.160:40324] ModSecurity: Warning. Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at REQUEST_HEADERS:Host. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "773"] [id "920350"] [msg "Host header is a numeric IP address"] [data "186.32.240.17:80"] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [hostname "186.32.240.17"] [uri "/"] [unique_id "ap1iC4ZKDA5xKmCJsZtK1QAAAAU"]
[Sun Sep 06 06:52:27.478771 2026] [security2:error] [pid 1052624:tid 1052624] [client 128.199.255.160:40324] ModSecurity: Warning. Unconditional match in SecAction. [file "/etc/modsecurity/crs/current/rules/RESPONSE-980-CORRELATION.conf"] [line "99"] [i
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
๐ฏ๐ต
43.165.174.53
|
|
[Sun Sep 06 06:41:45.368147 2026] [security2:error] [pid 1052624:tid 1052624] [client 43.165.174.53: ...
show more
[Sun Sep 06 06:41:45.368147 2026] [security2:error] [pid 1052624:tid 1052624] [client 43.165.174.53:43988] ModSecurity: Warning. Pattern match "\\\\b(?:keep-alive|close),\\\\s?(?:keep-alive|close)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "402"] [id "920210"] [msg "Multiple/Conflicting Connection Header Data Found"] [data "keep-alive, close"] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [hostname "186.32.240.17"] [uri "/"] [unique_id "ap1fiYZKDA5xKmCJsZtKzgAAAAU"]
[Sun Sep 06 06:41:45.368287 2026] [security2:error] [pid 1052624:tid 1052624] [client 43.165.174.53:43988] ModSecurity: Warning. Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at REQUEST_HEADERS:Host. [file
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
๐น๐ท
94.154.43.196
|
|
[Sun Sep 06 06:24:06.286705 2026] [security2:error] [pid 1052633:tid 1052633] [client 94.154.43.196: ...
show more
[Sun Sep 06 06:24:06.286705 2026] [security2:error] [pid 1052633:tid 1052633] [client 94.154.43.196:36580] ModSecurity: Warning. Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at REQUEST_HEADERS:Host. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "773"] [id "920350"] [msg "Host header is a numeric IP address"] [data "186.32.240.17:443"] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [hostname "186.32.240.17"] [uri "/"] [unique_id "ap1bZkmhhGRUR1p3Hx4EugAAABA"]
[Sun Sep 06 06:24:06.288559 2026] [security2:error] [pid 1052633:tid 1052633] [client 94.154.43.196:36580] ModSecurity: Warning. Unconditional match in SecAction. [file "/etc/modsecurity/crs/current/rules/RESPONSE-980-CORRELATION.conf"] [line "99"] [id "
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
๐บ๐ธ
47.88.90.156
|
|
[Sun Sep 06 06:17:55.721713 2026] [security2:error] [pid 1051093:tid 1051093] [client 47.88.90.156:4 ...
show more
[Sun Sep 06 06:17:55.721713 2026] [security2:error] [pid 1051093:tid 1051093] [client 47.88.90.156:42799] ModSecurity: Warning. Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at REQUEST_HEADERS:Host. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "773"] [id "920350"] [msg "Host header is a numeric IP address"] [data "186.32.240.17"] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [hostname "186.32.240.17"] [uri "/static/admin/javascript/hetong.js"] [unique_id "ap1Z81YXNnX9h1YqIZz_YAAAAAA"]
[Sun Sep 06 06:17:55.999384 2026] [security2:error] [pid 1051093:tid 1051093] [client 47.88.90.156:42799] ModSecurity: Warning. Unconditional match in SecAction. [file "/etc/modsecurity/crs/current/rules/RESPONSE-980-CORRELATI
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
๐บ๐ธ
71.6.134.204
|
|
[Sun Sep 06 06:16:48.573711 2026] [security2:error] [pid 1045342:tid 1045342] [client 71.6.134.204:5 ...
show more
[Sun Sep 06 06:16:48.573711 2026] [security2:error] [pid 1045342:tid 1045342] [client 71.6.134.204:58114] ModSecurity: Warning. Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at REQUEST_HEADERS:Host. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "773"] [id "920350"] [msg "Host header is a numeric IP address"] [data "186.32.240.17"] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [hostname "186.32.240.17"] [uri "/"] [unique_id "ap1ZsFUV2aRPCFxb90IdQgAAAAM"]
[Sun Sep 06 06:16:48.575515 2026] [security2:error] [pid 1045342:tid 1045342] [client 71.6.134.204:58114] ModSecurity: Warning. Unconditional match in SecAction. [file "/etc/modsecurity/crs/current/rules/RESPONSE-980-CORRELATION.conf"] [line "99"] [id "980170
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
๐บ๐ธ
47.88.94.28
|
|
[Sun Sep 06 06:16:33.976580 2026] [security2:error] [pid 1045346:tid 1045346] [client 47.88.94.28:55 ...
show more
[Sun Sep 06 06:16:33.976580 2026] [security2:error] [pid 1045346:tid 1045346] [client 47.88.94.28:55952] ModSecurity: Warning. Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at REQUEST_HEADERS:Host. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "773"] [id "920350"] [msg "Host header is a numeric IP address"] [data "186.32.240.17"] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [hostname "186.32.240.17"] [uri "/Public/home/js/check.js"] [unique_id "ap1ZoRxlfFSNgHqWyXVgdgAAAAg"]
[Sun Sep 06 06:16:34.200450 2026] [security2:error] [pid 1045346:tid 1045346] [client 47.88.94.28:55952] ModSecurity: Warning. Unconditional match in SecAction. [file "/etc/modsecurity/crs/current/rules/RESPONSE-980-CORRELATION.conf"] [l
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
๐บ๐ธ
47.251.14.232
|
|
[Sun Sep 06 06:16:29.425502 2026] [security2:error] [pid 1025884:tid 1025884] [client 47.251.14.232: ...
show more
[Sun Sep 06 06:16:29.425502 2026] [security2:error] [pid 1025884:tid 1025884] [client 47.251.14.232:58025] ModSecurity: Warning. Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at REQUEST_HEADERS:Host. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "773"] [id "920350"] [msg "Host header is a numeric IP address"] [data "186.32.240.17"] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [hostname "186.32.240.17"] [uri "/"] [unique_id "ap1ZnS3h8aGfrVDxQ52LigAAAAQ"]
[Sun Sep 06 06:16:29.674151 2026] [security2:error] [pid 1025884:tid 1025884] [client 47.251.14.232:58025] ModSecurity: Warning. Unconditional match in SecAction. [file "/etc/modsecurity/crs/current/rules/RESPONSE-980-CORRELATION.conf"] [line "99"] [id "9801
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
๐ธ๐ฌ
43.134.68.29
|
|
[Sun Sep 06 05:51:33.493282 2026] [security2:error] [pid 1045342:tid 1045342] [client 43.134.68.29:3 ...
show more
[Sun Sep 06 05:51:33.493282 2026] [security2:error] [pid 1045342:tid 1045342] [client 43.134.68.29:33504] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "566"] [id "920280"] [msg "Request Missing a Host Header"] [severity "CRITICAL"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [hostname "cursos.robertomurillo.net"] [uri "/"] [unique_id "ap1TxVUV2aRPCFxb90IdLwAAAAM"]
[Sun Sep 06 05:51:33.494710 2026] [security2:error] [pid 1045342:tid 1045342] [client 43.134.68.29:33504] ModSecurity: Warning. Unconditional match in SecAction. [file "/etc/modsecurity/crs/current/rules/RESPONSE-980-CORRELATION.conf"] [line "99"] [id "980170"] [msg "Anomaly Scores: (Inbound Scores: blocking=5, detection=5, per_pl=5-0-0-0
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
๐บ๐ธ
47.89.231.26
|
|
[Sun Sep 06 05:45:38.602326 2026] [security2:error] [pid 1025884:tid 1025884] [client 47.89.231.26:5 ...
show more
[Sun Sep 06 05:45:38.602326 2026] [security2:error] [pid 1025884:tid 1025884] [client 47.89.231.26:53630] ModSecurity: Warning. Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at REQUEST_HEADERS:Host. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "773"] [id "920350"] [msg "Host header is a numeric IP address"] [data "186.32.240.17:443"] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [hostname "186.32.240.17"] [uri "/"] [unique_id "ap1SYi3h8aGfrVDxQ52LdAAAAAQ"]
[Sun Sep 06 05:45:38.604144 2026] [security2:error] [pid 1025884:tid 1025884] [client 47.89.231.26:53630] ModSecurity: Warning. Unconditional match in SecAction. [file "/etc/modsecurity/crs/current/rules/RESPONSE-980-CORRELATION.conf"] [line "99"] [id "98
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
๐ซ๐ท
143.244.57.82
|
|
143.244.57.82 - - [06/Sep/2026:05:29:12 -0600] "POST //xmlrpc.php HTTP/1.1" 403 1593 "-" "Mozilla/5. ...
show more
143.244.57.82 - - [06/Sep/2026:05:29:12 -0600] "POST //xmlrpc.php HTTP/1.1" 403 1593 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
...
show less
|
Web Spam
Brute-Force
Web App Attack
|
|
๐ฉ๐ช
69.5.169.196
|
|
[Sun Sep 06 05:24:45.004664 2026] [security2:error] [pid 1052625:tid 1052625] [client 69.5.169.196:1 ...
show more
[Sun Sep 06 05:24:45.004664 2026] [security2:error] [pid 1052625:tid 1052625] [client 69.5.169.196:13646] ModSecurity: Warning. Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at REQUEST_HEADERS:Host. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "773"] [id "920350"] [msg "Host header is a numeric IP address"] [data "186.32.240.17"] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [hostname "186.32.240.17"] [uri "/"] [unique_id "ap1NfZN2ytO3uCgaMy8mzAAAAAo"]
[Sun Sep 06 05:24:45.156487 2026] [security2:error] [pid 1052625:tid 1052625] [client 69.5.169.196:13646] ModSecurity: Warning. Unconditional match in SecAction. [file "/etc/modsecurity/crs/current/rules/RESPONSE-980-CORRELATION.conf"] [line "99"] [id "980170
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
๐ฌ๐ง
5.252.83.222
|
|
[Sun Sep 06 05:22:06.051854 2026] [security2:error] [pid 1052624:tid 1052624] [client 5.252.83.222:1 ...
show more
[Sun Sep 06 05:22:06.051854 2026] [security2:error] [pid 1052624:tid 1052624] [client 5.252.83.222:14934] ModSecurity: Warning. Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at REQUEST_HEADERS:Host. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "773"] [id "920350"] [msg "Host header is a numeric IP address"] [data "186.32.240.17"] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [hostname "186.32.240.17"] [uri "/"] [unique_id "ap1M3oZKDA5xKmCJsZtKiwAAAAU"]
[Sun Sep 06 05:22:06.162773 2026] [security2:error] [pid 1052624:tid 1052624] [client 5.252.83.222:14934] ModSecurity: Warning. Unconditional match in SecAction. [file "/etc/modsecurity/crs/current/rules/RESPONSE-980-CORRELATION.conf"] [line "99"] [id "980170
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
๐ฌ๐ง
89.37.172.137
|
|
[Sun Sep 06 05:21:53.467331 2026] [security2:error] [pid 1045347:tid 1045347] [client 89.37.172.137: ...
show more
[Sun Sep 06 05:21:53.467331 2026] [security2:error] [pid 1045347:tid 1045347] [client 89.37.172.137:16668] ModSecurity: Warning. Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at REQUEST_HEADERS:Host. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "773"] [id "920350"] [msg "Host header is a numeric IP address"] [data "192.0.2.1"] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [hostname "192.0.2.1"] [uri "/"] [unique_id "ap1M0SPLF87GkszHtefCWwAAAAw"]
[Sun Sep 06 05:21:53.646809 2026] [security2:error] [pid 1045347:tid 1045347] [client 89.37.172.137:16668] ModSecurity: Warning. Unconditional match in SecAction. [file "/etc/modsecurity/crs/current/rules/RESPONSE-980-CORRELATION.conf"] [line "99"] [id "980170"] [ms
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
๐บ๐ธ
71.6.134.234
|
|
[Sun Sep 06 05:16:13.173133 2026] [security2:error] [pid 1025884:tid 1025884] [client 71.6.134.234:5 ...
show more
[Sun Sep 06 05:16:13.173133 2026] [security2:error] [pid 1025884:tid 1025884] [client 71.6.134.234:57650] ModSecurity: Warning. Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at REQUEST_HEADERS:Host. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "773"] [id "920350"] [msg "Host header is a numeric IP address"] [data "186.32.240.17"] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [hostname "186.32.240.17"] [uri "/"] [unique_id "ap1LfS3h8aGfrVDxQ52LWgAAAAQ"]
[Sun Sep 06 05:16:13.437206 2026] [security2:error] [pid 1025884:tid 1025884] [client 71.6.134.234:57650] ModSecurity: Warning. Unconditional match in SecAction. [file "/etc/modsecurity/crs/current/rules/RESPONSE-980-CORRELATION.conf"] [line "99"] [id "980170
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
๐ง๐ช
34.78.114.97
|
|
[Sun Sep 06 04:54:40.593561 2026] [security2:error] [pid 1045347:tid 1045347] [client 34.78.114.97:3 ...
show more
[Sun Sep 06 04:54:40.593561 2026] [security2:error] [pid 1045347:tid 1045347] [client 34.78.114.97:33144] ModSecurity: Warning. Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at REQUEST_HEADERS:Host. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "773"] [id "920350"] [msg "Host header is a numeric IP address"] [data "186.32.240.17"] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [hostname "186.32.240.17"] [uri "/"] [unique_id "ap1GcCPLF87GkszHtefCQwAAAAw"]
[Sun Sep 06 04:54:40.595650 2026] [security2:error] [pid 1045347:tid 1045347] [client 34.78.114.97:33144] ModSecurity: Warning. Unconditional match in SecAction. [file "/etc/modsecurity/crs/current/rules/RESPONSE-980-CORRELATION.conf"] [line "99"] [id "980170
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|