|
๐บ๐ธ
43.162.109.249
|
|
[Sun Sep 06 04:53:58.363133 2026] [security2:error] [pid 1045346:tid 1045346] [client 43.162.109.249 ...
show more
[Sun Sep 06 04:53:58.363133 2026] [security2:error] [pid 1045346:tid 1045346] [client 43.162.109.249:54766] ModSecurity: Warning. Pattern match "\\\\b(?:keep-alive|close),\\\\s?(?:keep-alive|close)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "402"] [id "920210"] [msg "Multiple/Conflicting Connection Header Data Found"] [data "keep-alive, close"] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [hostname "186.32.240.17"] [uri "/"] [unique_id "ap1GRhxlfFSNgHqWyXVgKgAAAAg"]
[Sun Sep 06 04:53:58.363292 2026] [security2:error] [pid 1045346:tid 1045346] [client 43.162.109.249:54766] ModSecurity: Warning. Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at REQUEST_HEADERS:Host. [fil
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
๐ณ๐ฑ
195.178.110.132
|
|
[Sun Sep 06 04:49:49.686956 2026] [security2:error] [pid 1025895:tid 1025895] [client 195.178.110.13 ...
show more
[Sun Sep 06 04:49:49.686956 2026] [security2:error] [pid 1025895:tid 1025895] [client 195.178.110.132:36562] ModSecurity: Warning. String match within "/content-encoding/ /proxy/ /lock-token/ /content-range/ /if/ /x-http-method-override/ /x-http-method/ /x-method-override/ /x-middleware-subrequest/ /expect/" at TX:header_name_920450_x-http-method-override. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920450"] [msg "HTTP header is restricted by policy (/x-http-method-override/)"] [data "Restricted header detected: /x-http-method-override/"] [severity "CRITICAL"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [hostname "robertomurillo.net"] [uri "/index.php"] [unique_id "ap1FTbXePdWRJTMKWfG6cQAAAAk"], referer: https://robertomurillo.net/wp-admin/
[Sun S
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
๐ง๐ท
168.195.171.254
|
|
[Sun Sep 06 04:48:51.270088 2026] [security2:error] [pid 1045342:tid 1045342] [client 168.195.171.25 ...
show more
[Sun Sep 06 04:48:51.270088 2026] [security2:error] [pid 1045342:tid 1045342] [client 168.195.171.254:60946] ModSecurity: Warning. Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at REQUEST_HEADERS:Host. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "773"] [id "920350"] [msg "Host header is a numeric IP address"] [data "186.32.240.17"] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [hostname "186.32.240.17"] [uri "/admin/config.php"] [unique_id "ap1FE1UV2aRPCFxb90Ic8AAAAAM"]
[Sun Sep 06 04:48:54.523038 2026] [security2:error] [pid 1045342:tid 1045342] [client 168.195.171.254:60946] ModSecurity: Warning. Unconditional match in SecAction. [file "/etc/modsecurity/crs/current/rules/RESPONSE-980-CORRELATION.conf"] [
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
๐ฉ๐ช
178.105.81.165
|
|
[Sun Sep 06 04:47:47.543021 2026] [security2:error] [pid 990766:tid 990766] [client 178.105.81.165:6 ...
show more
[Sun Sep 06 04:47:47.543021 2026] [security2:error] [pid 990766:tid 990766] [client 178.105.81.165:61739] ModSecurity: Warning. Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at REQUEST_HEADERS:Host. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "773"] [id "920350"] [msg "Host header is a numeric IP address"] [data "186.32.240.17"] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [hostname "186.32.240.17"] [uri "/admin/config.php"] [unique_id "ap1E01ZQxvTxzRXa822OngAAAAs"]
[Sun Sep 06 04:48:17.906671 2026] [security2:error] [pid 990766:tid 990766] [client 178.105.81.165:61739] ModSecurity: Warning. Unconditional match in SecAction. [file "/etc/modsecurity/crs/current/rules/RESPONSE-980-CORRELATION.conf"] [line "
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
๐จ๐ณ
43.136.86.241
|
|
[Sun Sep 06 04:27:57.653474 2026] [security2:error] [pid 1019809:tid 1019809] [client 43.136.86.241: ...
show more
[Sun Sep 06 04:27:57.653474 2026] [security2:error] [pid 1019809:tid 1019809] [client 43.136.86.241:40738] ModSecurity: Warning. Pattern match "\\\\b(?:keep-alive|close),\\\\s?(?:keep-alive|close)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "402"] [id "920210"] [msg "Multiple/Conflicting Connection Header Data Found"] [data "keep-alive, close"] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [hostname "robertomurillo.net"] [uri "/"] [unique_id "ap1ALR-b5WC2EGNWbtVywgAAAAY"]
[Sun Sep 06 04:27:57.655429 2026] [security2:error] [pid 1019809:tid 1019809] [client 43.136.86.241:40738] ModSecurity: Warning. Unconditional match in SecAction. [file "/etc/modsecurity/crs/current/rules/RESPONSE-980-CORRELATION.conf"]
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
๐บ๐ธ
40.124.186.88
|
|
[Sun Sep 06 04:20:46.825727 2026] [security2:error] [pid 1008525:tid 1008525] [client 40.124.186.88: ...
show more
[Sun Sep 06 04:20:46.825727 2026] [security2:error] [pid 1008525:tid 1008525] [client 40.124.186.88:40812] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/crs/current/rules/REQUEST-913-SCANNER-DETECTION.conf"] [line "56"] [id "913100"] [msg "Found User-Agent associated with security scanner"] [data "Matched Data: zgrab found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 zgrab/0.x"] [severity "CRITICAL"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-reputation-scanner"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/SCANNER-DETECTION"] [tag "capec/1000/118/224/541/310"] [hostname "186.32.240.17"] [uri "/"] [unique_id "ap0-fowmVKQOYFlGqIJIegAAAAo"]
[Sun Sep 06 04:20:46.825978 2026] [security2:error] [pid 1008525:tid 1008525] [client 40.124.186.88:40812] ModSecurity: Warning. Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at RE
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
๐บ๐ธ
85.208.96.210
|
|
[Sun Sep 06 04:14:03.759293 2026] [security2:error] [pid 1025884:tid 1025884] [client 85.208.96.210: ...
show more
[Sun Sep 06 04:14:03.759293 2026] [security2:error] [pid 1025884:tid 1025884] [client 85.208.96.210:13826] ModSecurity: Warning. Matched phrase "openvpn/" at ARGS:redirect_to. [file "/etc/modsecurity/crs/current/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "123"] [id "930120"] [msg "OS File Access Attempt"] [data "Matched Data: openvpn/ found within ARGS:redirect_to: https:/robertomurillo.net/videos-y-cursos/pfsense-enrutamiento-estatico-y-vpn-con-openvpn/"] [severity "CRITICAL"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/ATTACK-LFI"] [tag "capec/1000/255/153/126"] [hostname "robertomurillo.net"] [uri "/wp-login.php"] [unique_id "ap086y3h8aGfrVDxQ52LJQAAAAQ"]
[Sun Sep 06 04:14:03.761047 2026] [security2:error] [pid 1025884:tid 1025884] [client 85.208.96.210:13826] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:bloc
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
๐บ๐ธ
66.132.195.120
|
|
[Sun Sep 06 04:04:00.528427 2026] [security2:error] [pid 1025895:tid 1025895] [client 66.132.195.120 ...
show more
[Sun Sep 06 04:04:00.528427 2026] [security2:error] [pid 1025895:tid 1025895] [client 66.132.195.120:32906] ModSecurity: Warning. Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at REQUEST_HEADERS:Host. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "773"] [id "920350"] [msg "Host header is a numeric IP address"] [data "186.32.240.17"] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [hostname "186.32.240.17"] [uri "/"] [unique_id "ap06kLXePdWRJTMKWfG6TAAAAAk"]
[Sun Sep 06 04:04:00.728445 2026] [security2:error] [pid 1025895:tid 1025895] [client 66.132.195.120:32906] ModSecurity: Warning. Unconditional match in SecAction. [file "/etc/modsecurity/crs/current/rules/RESPONSE-980-CORRELATION.conf"] [line "99"] [id "98
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
๐บ๐ธ
172.110.223.109
|
|
[Sun Sep 06 04:01:43.013046 2026] [security2:error] [pid 1023796:tid 1023796] [client 172.110.223.10 ...
show more
[Sun Sep 06 04:01:43.013046 2026] [security2:error] [pid 1023796:tid 1023796] [client 172.110.223.109:63136] ModSecurity: Warning. Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at REQUEST_HEADERS:Host. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "773"] [id "920350"] [msg "Host header is a numeric IP address"] [data "186.32.240.17"] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [hostname "186.32.240.17"] [uri "/"] [unique_id "ap06B6hf-mq8i7ftgaFb1QAAAAI"]
[Sun Sep 06 04:01:43.014080 2026] [security2:error] [pid 1023796:tid 1023796] [client 172.110.223.109:63136] ModSecurity: Warning. Unconditional match in SecAction. [file "/etc/modsecurity/crs/current/rules/RESPONSE-980-CORRELATION.conf"] [line "99"] [id "
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
๐จ๐ณ
106.75.186.101
|
|
106.75.186.101 - - [06/Sep/2026:03:50:11 -0600] "GET /dqgqoeCXckuwPtxov HTTP/1.1" 403 5552 "-" "-"
. ...
show more
106.75.186.101 - - [06/Sep/2026:03:50:11 -0600] "GET /dqgqoeCXckuwPtxov HTTP/1.1" 403 5552 "-" "-"
...
show less
|
Bad Web Bot
|
|
๐ฎ๐ณ
106.212.140.174
|
|
106.212.140.174 - - [06/Sep/2026:03:28:32 -0600] "POST /xmlrpc.php HTTP/1.1" 403 5567 "-" "Mozilla/5 ...
show more
106.212.140.174 - - [06/Sep/2026:03:28:32 -0600] "POST /xmlrpc.php HTTP/1.1" 403 5567 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7; x64) AppleWebKit/537.36 (KHTML, like Gecko) Edge/81.0.0.0 Safari/537.36"
...
show less
|
Web Spam
Brute-Force
Web App Attack
|
|
๐บ๐ธ
34.83.222.46
|
|
34.83.222.46 - - [06/Sep/2026:03:21:18 -0600] "POST //xmlrpc.php HTTP/1.1" 403 1585 "-" "Mozilla/5.0 ...
show more
34.83.222.46 - - [06/Sep/2026:03:21:18 -0600] "POST //xmlrpc.php HTTP/1.1" 403 1585 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
...
show less
|
Web Spam
Brute-Force
Web App Attack
|
|
๐ญ๐ฐ
101.32.15.141
|
|
[Sun Sep 06 03:19:22.317069 2026] [security2:error] [pid 1008525:tid 1008525] [client 101.32.15.141: ...
show more
[Sun Sep 06 03:19:22.317069 2026] [security2:error] [pid 1008525:tid 1008525] [client 101.32.15.141:59172] ModSecurity: Warning. Pattern match "\\\\b(?:keep-alive|close),\\\\s?(?:keep-alive|close)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "402"] [id "920210"] [msg "Multiple/Conflicting Connection Header Data Found"] [data "keep-alive, close"] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [hostname "www.robertomurillo.net"] [uri "/"] [unique_id "ap0wGowmVKQOYFlGqIJISwAAAAo"]
[Sun Sep 06 03:19:22.318954 2026] [security2:error] [pid 1008525:tid 1008525] [client 101.32.15.141:59172] ModSecurity: Warning. Unconditional match in SecAction. [file "/etc/modsecurity/crs/current/rules/RESPONSE-980-CORRELATION.con
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
๐บ๐ธ
35.236.240.125
|
|
35.236.240.125 - - [06/Sep/2026:03:09:50 -0600] "POST //xmlrpc.php HTTP/1.1" 403 1585 "-" "Mozilla/5 ...
show more
35.236.240.125 - - [06/Sep/2026:03:09:50 -0600] "POST //xmlrpc.php HTTP/1.1" 403 1585 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
...
show less
|
Web Spam
Brute-Force
Web App Attack
|
|
๐บ๐ธ
74.82.47.5
|
|
[Sun Sep 06 02:56:06.693208 2026] [security2:error] [pid 1017417:tid 1017417] [client 74.82.47.5:497 ...
show more
[Sun Sep 06 02:56:06.693208 2026] [security2:error] [pid 1017417:tid 1017417] [client 74.82.47.5:49790] ModSecurity: Warning. Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at REQUEST_HEADERS:Host. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "773"] [id "920350"] [msg "Host header is a numeric IP address"] [data "186.32.240.17"] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [hostname "186.32.240.17"] [uri "/"] [unique_id "ap0qps1yUIWBz7dihrRHMwAAAA4"]
[Sun Sep 06 02:56:06.870327 2026] [security2:error] [pid 1017417:tid 1017417] [client 74.82.47.5:49790] ModSecurity: Warning. Unconditional match in SecAction. [file "/etc/modsecurity/crs/current/rules/RESPONSE-980-CORRELATION.conf"] [line "99"] [id "980170"] [
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
๐บ๐ธ
216.180.246.169
|
|
[Sun Sep 06 02:43:18.038427 2026] [security2:error] [pid 990767:tid 990767] [client 216.180.246.169: ...
show more
[Sun Sep 06 02:43:18.038427 2026] [security2:error] [pid 990767:tid 990767] [client 216.180.246.169:21197] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "566"] [id "920280"] [msg "Request Missing a Host Header"] [severity "CRITICAL"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [hostname "cursos.robertomurillo.net"] [uri "/"] [unique_id "ap0npr92MEjpiD_0H6jVkgAAAAA"]
[Sun Sep 06 02:43:18.040005 2026] [security2:error] [pid 990767:tid 990767] [client 216.180.246.169:21197] ModSecurity: Warning. Unconditional match in SecAction. [file "/etc/modsecurity/crs/current/rules/RESPONSE-980-CORRELATION.conf"] [line "99"] [id "980170"] [msg "Anomaly Scores: (Inbound Scores: blocking=5, detection=5, per_pl=5-0-0
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
๐ฆ๐ช
151.245.151.237
|
|
[Sun Sep 06 02:41:01.192212 2026] [security2:error] [pid 1019809:tid 1019809] [client 151.245.151.23 ...
show more
[Sun Sep 06 02:41:01.192212 2026] [security2:error] [pid 1019809:tid 1019809] [client 151.245.151.237:48062] ModSecurity: Warning. Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at REQUEST_HEADERS:Host. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "773"] [id "920350"] [msg "Host header is a numeric IP address"] [data "186.32.240.17"] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [hostname "186.32.240.17"] [uri "/"] [unique_id "ap0nHR-b5WC2EGNWbtVybQAAAAY"]
[Sun Sep 06 02:41:01.194165 2026] [security2:error] [pid 1019809:tid 1019809] [client 151.245.151.237:48062] ModSecurity: Warning. Unconditional match in SecAction. [file "/etc/modsecurity/crs/current/rules/RESPONSE-980-CORRELATION.conf"] [line "99"] [id "
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
๐ฆ๐ช
151.245.151.56
|
|
[Sun Sep 06 02:03:34.150275 2026] [security2:error] [pid 1008525:tid 1008525] [client 151.245.151.56 ...
show more
[Sun Sep 06 02:03:34.150275 2026] [security2:error] [pid 1008525:tid 1008525] [client 151.245.151.56:56312] ModSecurity: Warning. Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at REQUEST_HEADERS:Host. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "773"] [id "920350"] [msg "Host header is a numeric IP address"] [data "186.32.240.17:80"] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [hostname "186.32.240.17"] [uri "/"] [unique_id "ap0eVowmVKQOYFlGqIJIFAAAAAo"]
[Sun Sep 06 02:03:34.152507 2026] [security2:error] [pid 1008525:tid 1008525] [client 151.245.151.56:56312] ModSecurity: Warning. Unconditional match in SecAction. [file "/etc/modsecurity/crs/current/rules/RESPONSE-980-CORRELATION.conf"] [line "99"] [id
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
๐น๐ญ
43.164.0.21
|
|
[Sun Sep 06 02:00:21.565370 2026] [security2:error] [pid 993082:tid 993082] [client 43.164.0.21:4131 ...
show more
[Sun Sep 06 02:00:21.565370 2026] [security2:error] [pid 993082:tid 993082] [client 43.164.0.21:41318] ModSecurity: Warning. Pattern match "\\\\b(?:keep-alive|close),\\\\s?(?:keep-alive|close)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "402"] [id "920210"] [msg "Multiple/Conflicting Connection Header Data Found"] [data "keep-alive, close"] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [hostname "robertomurillo.net"] [uri "/"] [unique_id "ap0dlYx6pOlY1q8e1y2vIwAAAAg"]
[Sun Sep 06 02:00:21.567263 2026] [security2:error] [pid 993082:tid 993082] [client 43.164.0.21:41318] ModSecurity: Warning. Unconditional match in SecAction. [file "/etc/modsecurity/crs/current/rules/RESPONSE-980-CORRELATION.conf"] [line "9
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
๐ฑ๐น
45.227.254.52
|
|
[Sun Sep 06 01:58:52.149697 2026] [security2:error] [pid 993082:tid 993082] [client 45.227.254.52:45 ...
show more
[Sun Sep 06 01:58:52.149697 2026] [security2:error] [pid 993082:tid 993082] [client 45.227.254.52:45070] ModSecurity: Warning. Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at REQUEST_HEADERS:Host. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "773"] [id "920350"] [msg "Host header is a numeric IP address"] [data "186.32.240.17"] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [hostname "186.32.240.17"] [uri "/"] [unique_id "ap0dPIx6pOlY1q8e1y2vIgAAAAg"]
[Sun Sep 06 01:58:52.151591 2026] [security2:error] [pid 993082:tid 993082] [client 45.227.254.52:45070] ModSecurity: Warning. Unconditional match in SecAction. [file "/etc/modsecurity/crs/current/rules/RESPONSE-980-CORRELATION.conf"] [line "99"] [id "980170"]
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
๐ณ๐ฑ
104.28.249.137
|
|
[Sun Sep 06 01:56:59.763709 2026] [security2:error] [pid 990768:tid 990768] [client 104.28.249.137:1 ...
show more
[Sun Sep 06 01:56:59.763709 2026] [security2:error] [pid 990768:tid 990768] [client 104.28.249.137:18674] ModSecurity: Warning. String match within "/content-encoding/ /proxy/ /lock-token/ /content-range/ /if/ /x-http-method-override/ /x-http-method/ /x-method-override/ /x-middleware-subrequest/ /expect/" at TX:header_name_920450_x-middleware-subrequest. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1228"] [id "920450"] [msg "HTTP header is restricted by policy (/x-middleware-subrequest/)"] [data "Restricted header detected: /x-middleware-subrequest/"] [severity "CRITICAL"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [hostname "robertomurillo.net"] [uri "/"] [unique_id "ap0cyypwknBJkyfzvw7vxAAAAAI"]
[Sun Sep 06 01:56:59.765513 2026] [security2:error] [pid 99076
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
๐บ๐ธ
170.106.37.134
|
|
[Sun Sep 06 01:46:17.235753 2026] [security2:error] [pid 993082:tid 993082] [client 170.106.37.134:5 ...
show more
[Sun Sep 06 01:46:17.235753 2026] [security2:error] [pid 993082:tid 993082] [client 170.106.37.134:59690] ModSecurity: Warning. Pattern match "\\\\b(?:keep-alive|close),\\\\s?(?:keep-alive|close)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "402"] [id "920210"] [msg "Multiple/Conflicting Connection Header Data Found"] [data "keep-alive, close"] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [hostname "186.32.240.17"] [uri "/"] [unique_id "ap0aSYx6pOlY1q8e1y2vGQAAAAg"]
[Sun Sep 06 01:46:17.235893 2026] [security2:error] [pid 993082:tid 993082] [client 170.106.37.134:59690] ModSecurity: Warning. Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at REQUEST_HEADERS:Host. [file "/
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
๐บ๐ธ
3.95.169.233
|
|
[Sun Sep 06 01:00:56.677437 2026] [security2:error] [pid 990768:tid 990768] [client 3.95.169.233:304 ...
show more
[Sun Sep 06 01:00:56.677437 2026] [security2:error] [pid 990768:tid 990768] [client 3.95.169.233:30490] ModSecurity: Warning. Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at REQUEST_HEADERS:Host. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "773"] [id "920350"] [msg "Host header is a numeric IP address"] [data "186.32.240.17"] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [hostname "186.32.240.17"] [uri "/robots.txt"] [unique_id "ap0PqCpwknBJkyfzvw7vmAAAAAI"]
[Sun Sep 06 01:00:56.679275 2026] [security2:error] [pid 990768:tid 990768] [client 3.95.169.233:30490] ModSecurity: Warning. Unconditional match in SecAction. [file "/etc/modsecurity/crs/current/rules/RESPONSE-980-CORRELATION.conf"] [line "99"] [id "
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
๐ณ๐ฑ
89.248.168.227
|
|
[Sun Sep 06 01:00:18.352885 2026] [security2:error] [pid 990895:tid 990895] [client 89.248.168.227:4 ...
show more
[Sun Sep 06 01:00:18.352885 2026] [security2:error] [pid 990895:tid 990895] [client 89.248.168.227:48028] ModSecurity: Warning. Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at REQUEST_HEADERS:Host. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "773"] [id "920350"] [msg "Host header is a numeric IP address"] [data "186.32.240.17"] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [hostname "186.32.240.17"] [uri "/logged.jsp"] [unique_id "ap0PgkiuJcvodNuAVBVPiQAAAAQ"]
[Sun Sep 06 01:00:18.355056 2026] [security2:error] [pid 990895:tid 990895] [client 89.248.168.227:48028] ModSecurity: Warning. Unconditional match in SecAction. [file "/etc/modsecurity/crs/current/rules/RESPONSE-980-CORRELATION.conf"] [line "99"] [
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|
|
๐บ๐ธ
54.172.145.72
|
|
[Sun Sep 06 01:00:05.960244 2026] [security2:error] [pid 990769:tid 990769] [client 54.172.145.72:38 ...
show more
[Sun Sep 06 01:00:05.960244 2026] [security2:error] [pid 990769:tid 990769] [client 54.172.145.72:38482] ModSecurity: Warning. Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at REQUEST_HEADERS:Host. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "773"] [id "920350"] [msg "Host header is a numeric IP address"] [data "186.32.240.17"] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [hostname "186.32.240.17"] [uri "/"] [unique_id "ap0PdX3VqNGZTTnSV3zreAAAAAM"]
[Sun Sep 06 01:00:05.962112 2026] [security2:error] [pid 990769:tid 990769] [client 54.172.145.72:38482] ModSecurity: Warning. Unconditional match in SecAction. [file "/etc/modsecurity/crs/current/rules/RESPONSE-980-CORRELATION.conf"] [line "99"] [id "980170"]
...
show less
|
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
|