🇩🇪
165.154.164.24
1 hour ago
(ftpd) Failed FTP login from 165.154.164.24 (DE/Germany/-): 1 in the last 3600 secs; Ports: *; Direc ...
show more
(ftpd) Failed FTP login from 165.154.164.24 (DE/Germany/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: Jul 22 18:30:39 web pure-ftpd: ([email protected] ) [WARNING] Authentication failed for user [anonymous]
show less
Port Scan
🇩🇪
49.51.141.76
1 hour ago
(mod_security) mod_security (id:920210) triggered by 49.51.141.76 (DE/Germany/-): 1 in the last 3600 ...
show more
(mod_security) mod_security (id:920210) triggered by 49.51.141.76 (DE/Germany/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Wed Jul 22 18:21:25.626087 2026] [security2:error] [pid 763403:tid 763478] [client 49.51.141.76:52154] ModSecurity: Access denied with code 406 (phase 1). Pattern match "\\\\b(?:keep-alive|close),\\\\s?(?:keep-alive|close)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/modsecurity.d/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "402"] [id "920210"] [msg "Multiple/Conflicting Connection Header Data Found"] [redacted] [severity "WARNING"] [ver "OWASP_CRS/4.28.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [redacted] [uri "/"] [unique_id "amFCZdeuEQ8BCz8kmmEA3wAAAEg"]
show less
Port Scan
🇸🇬
45.82.78.105
2 hours ago
(eximsyntax) Exim syntax errors from 45.82.78.105 (SG/Singapore/-): 1 in the last 3600 secs; Ports: ...
show more
(eximsyntax) Exim syntax errors from 45.82.78.105 (SG/Singapore/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: 2026-07-22 17:54:31 SMTP call from [45.82.78.105] dropped: too many syntax or protocol errors (last command was "\021ì?\035?\027?\030?\031?\r?\026?\024\b\004\004\003\b\007\b\005\b\006\004\001\005\001\006\001\005\003\006\003?2?\032?\030\b\004\004\003\b\007\b\005\b\006\004\001\005\001\006\001\005\003\006\003\002\001\002\003?+?\005\004\003\004\003\003?3\004ê\004è\021ì\004À½QphË\024\021&&\036س4^\veLe>X\036Çp~°u#Ù]z]Ñ@ù#ZbÔ\005ò~l'¥&y¡]\025¡¨´\0330Ù\007N3Uv\034\bøEL÷ñ¯Ö¥tÔ*Cr¢ÃJÖZdëKDË\f\005\fo\v,\024\034,\0334hâäMÎv%m@\006È\023y~«ÇK\024;Wôw4!¿%§¿\177\tÌByGÈ*m&W§¾3Y!¹\026=@%\v ÷\020Ç?\021)L«\002\021È_ê41¡1ãuÄLa¥÷\002\007å\031>7³|7°<\026¨\024·É
ÂTB@ä\027Ö×HH¦ë7éÊÚó\t=Ãf§vs", NULL)
show less
Port Scan
🇲🇾
47.250.47.28
2 hours ago
(mod_security) mod_security (id:920350) triggered by 47.250.47.28 (MY/Malaysia/-): 1 in the last 360 ...
show more
(mod_security) mod_security (id:920350) triggered by 47.250.47.28 (MY/Malaysia/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Wed Jul 22 17:09:04.129797 2026] [security2:error] [pid 757117:tid 757398] [client 47.250.47.28:39076] ModSecurity: Access denied with code 406 (phase 1). Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at REQUEST_HEADERS:Host. [file "/etc/modsecurity.d/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "773"] [id "920350"] [msg "Host header is a numeric IP address"] [redacted] [severity "WARNING"] [ver "OWASP_CRS/4.28.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [redacted] [uri "/"] [unique_id "amExcKIXiMJD9PK5CuICMgAAAVE"]
show less
Port Scan
🇺🇸
2602:80d:1007::30
2 hours ago
(mod_security) mod_security (id:920350) triggered by 2602:80d:1007::30 (Unknown): 1 in the last 3600 ...
show more
(mod_security) mod_security (id:920350) triggered by 2602:80d:1007::30 (Unknown): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Wed Jul 22 17:07:47.820112 2026] [security2:error] [pid 757116:tid 757477] [client 2602:80d:1007::30:54012] ModSecurity: Access denied with code 406 (phase 1). Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at REQUEST_HEADERS:Host. [file "/etc/modsecurity.d/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "773"] [id "920350"] [msg "Host header is a numeric IP address"] [redacted]"] [severity "WARNING"] [ver "OWASP_CRS/4.28.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [redacted] [uri "/"] [unique_id "amExIwzwcgGTyYxe1ty8qQAAAR8"]
show less
Port Scan
🇺🇸
172.239.32.185
3 hours ago
(mod_security) mod_security (id:920350) triggered by 172.239.32.185 (US/United States/172-239-32-185 ...
show more
(mod_security) mod_security (id:920350) triggered by 172.239.32.185 (US/United States/172-239-32-185.ip.linodeusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Wed Jul 22 16:50:02.444129 2026] [security2:error] [pid 757116:tid 757470] [client 172.239.32.185:60898] ModSecurity: Access denied with code 406 (phase 1). Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at REQUEST_HEADERS:Host. [file "/etc/modsecurity.d/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "773"] [id "920350"] [msg "Host header is a numeric IP address"] [redacted] [severity "WARNING"] [ver "OWASP_CRS/4.28.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [redacted] [uri "/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh"] [unique_id "amEs-gzwcgGTyYxe1ty0FAAAARg"]
show less
Port Scan
🇯🇵
8.216.16.104
3 hours ago
(mod_security) mod_security (id:920350) triggered by 8.216.16.104 (JP/Japan/-): 1 in the last 3600 s ...
show more
(mod_security) mod_security (id:920350) triggered by 8.216.16.104 (JP/Japan/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Wed Jul 22 16:10:30.343302 2026] [security2:error] [pid 757116:tid 757470] [client 8.216.16.104:38634] ModSecurity: Access denied with code 406 (phase 1). Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at REQUEST_HEADERS:Host. [file "/etc/modsecurity.d/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "773"] [id "920350"] [msg "Host header is a numeric IP address"] [redacted] [severity "WARNING"] [ver "OWASP_CRS/4.28.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [redacted] [uri "/"] [unique_id "amEjtgzwcgGTyYxe1tyaRgAAARg"]
show less
Port Scan
🇺🇸
20.10.203.190
4 hours ago
(mod_security) mod_security (id:930130) triggered by 20.10.203.190 (US/United States/-): 1 in the la ...
show more
(mod_security) mod_security (id:930130) triggered by 20.10.203.190 (US/United States/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Wed Jul 22 15:51:47.293534 2026] [security2:error] [pid 757116:tid 757431] [client 20.10.203.190:0] ModSecurity: Access denied with code 406 (phase 1). Matched phrase "wp-config-" at REQUEST_FILENAME. [file "/etc/modsecurity.d/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "150"] [id "930130"] [msg "Restricted File Access Attempt"] [redacted] [severity "CRITICAL"] [ver "OWASP_CRS/4.28.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/ATTACK-LFI"] [tag "capec/1000/255/153/126"] [redacted] [uri "/wp-config-sample.php"] [unique_id "amEfUwzwcgGTyYxe1tyN4AAAAQE"]
show less
Port Scan
🇳🇴
202.50.55.150
5 hours ago
(mod_security) mod_security (id:920350) triggered by 202.50.55.150 (NO/Norway/-): 1 in the last 3600 ...
show more
(mod_security) mod_security (id:920350) triggered by 202.50.55.150 (NO/Norway/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Wed Jul 22 15:00:12.802381 2026] [security2:error] [pid 757116:tid 757485] [client 202.50.55.150:53177] ModSecurity: Access denied with code 406 (phase 1). Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at REQUEST_HEADERS:Host. [file "/etc/modsecurity.d/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "773"] [id "920350"] [msg "Host header is a numeric IP address"] [redacted] [severity "WARNING"] [ver "OWASP_CRS/4.28.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [redacted] [uri "/.env"] [unique_id "amETPAzwcgGTyYxe1txnogAAASc"]
show less
Port Scan
🇺🇸
50.116.55.27
5 hours ago
(mod_security) mod_security (id:920350) triggered by 50.116.55.27 (US/United States/50-116-55-27.ip. ...
show more
(mod_security) mod_security (id:920350) triggered by 50.116.55.27 (US/United States/50-116-55-27.ip.linodeusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Wed Jul 22 14:59:24.901224 2026] [security2:error] [pid 757116:tid 757490] [client 50.116.55.27:18058] ModSecurity: Access denied with code 406 (phase 1). Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at REQUEST_HEADERS:Host. [file "/etc/modsecurity.d/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "773"] [id "920350"] [msg "Host header is a numeric IP address"] [redacted] [severity "WARNING"] [ver "OWASP_CRS/4.28.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [redacted] [uri "/"] [unique_id "amETDAzwcgGTyYxe1txnRAAAASw"]
show less
Port Scan
🇰🇷
152.32.139.190
5 hours ago
(eximsyntax) Exim syntax errors from 152.32.139.190 (KR/South Korea/iafrssh.cn): 1 in the last 3600 ...
show more
(eximsyntax) Exim syntax errors from 152.32.139.190 (KR/South Korea/iafrssh.cn): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: 2026-07-22 14:31:20 SMTP call from [152.32.139.190] dropped: too many syntax or protocol errors (last command was "?", NULL)
show less
Port Scan
🇸🇬
43.98.175.156
5 hours ago
(mod_security) mod_security (id:930130) triggered by 43.98.175.156 (SG/Singapore/-): 1 in the last 3 ...
show more
(mod_security) mod_security (id:930130) triggered by 43.98.175.156 (SG/Singapore/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Wed Jul 22 14:14:56.462235 2026] [security2:error] [pid 306847:tid 307579] [client 43.98.175.156:0] ModSecurity: Access denied with code 406 (phase 1). Matched phrase "config.php" at REQUEST_FILENAME. [file "/etc/modsecurity.d/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "150"] [id "930130"] [msg "Restricted File Access Attempt"] [redacted] [severity "CRITICAL"] [ver "OWASP_CRS/4.28.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/ATTACK-LFI"] [tag "capec/1000/255/153/126"] [redacted] [uri "/wordpress/wp-admin/setup-config.php"] [unique_id "amEIoB48i1CZTU5K4yRyvwAAAHY"]
show less
Port Scan
🇮🇳
152.32.159.177
5 hours ago
(ftpd) Failed FTP login from 152.32.159.177 (IN/India/-): 1 in the last 3600 secs; Ports: *; Directi ...
show more
(ftpd) Failed FTP login from 152.32.159.177 (IN/India/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: Jul 22 14:13:39 web pure-ftpd: ([email protected] ) [WARNING] Authentication failed for user [anonymous]
show less
Port Scan
🇩🇪
49.51.132.100
6 hours ago
(mod_security) mod_security (id:920210) triggered by 49.51.132.100 (DE/Germany/-): 1 in the last 360 ...
show more
(mod_security) mod_security (id:920210) triggered by 49.51.132.100 (DE/Germany/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Wed Jul 22 13:53:40.139620 2026] [security2:error] [pid 143709:tid 144444] [client 49.51.132.100:46292] ModSecurity: Access denied with code 406 (phase 1). Pattern match "\\\\b(?:keep-alive|close),\\\\s?(?:keep-alive|close)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/modsecurity.d/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "402"] [id "920210"] [msg "Multiple/Conflicting Connection Header Data Found"] [redacted] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [redacted] [uri "/"] [unique_id "amEDpFcfBhzJyypYHHR0HQAAAJU"]
show less
Port Scan
🇧🇪
34.53.192.169
6 hours ago
(ftpd) Failed FTP login from 34.53.192.169 (BE/Belgium/169.192.53.34.bc.googleusercontent.com): 1 in ...
show more
(ftpd) Failed FTP login from 34.53.192.169 (BE/Belgium/169.192.53.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: Jul 22 13:05:03 web pure-ftpd: ([email protected] ) [WARNING] Authentication failed for user [anonymous]
show less
Port Scan
🇬🇧
185.248.85.29
6 hours ago
(mod_security) mod_security (id:920350) triggered by 185.248.85.29 (GB/United Kingdom/-): 1 in the l ...
show more
(mod_security) mod_security (id:920350) triggered by 185.248.85.29 (GB/United Kingdom/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Wed Jul 22 13:04:15.259847 2026] [security2:error] [pid 139793:tid 139862] [client 185.248.85.29:62791] ModSecurity: Access denied with code 406 (phase 1). Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at REQUEST_HEADERS:Host. [file "/etc/modsecurity.d/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "773"] [id "920350"] [msg "Host header is a numeric IP address"] [redacted] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [redacted] [uri "/"] [unique_id "amD4Dwwl64X9Ye6nxE5obgAAAEI"]
show less
Port Scan
🇺🇸
34.143.67.109
8 hours ago
(mod_security) mod_security (id:920350) triggered by 34.143.67.109 (US/United States/109.67.143.34.b ...
show more
(mod_security) mod_security (id:920350) triggered by 34.143.67.109 (US/United States/109.67.143.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Wed Jul 22 11:53:32.986497 2026] [security2:error] [pid 138507:tid 138648] [client 34.143.67.109:46188] ModSecurity: Access denied with code 406 (phase 1). Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at REQUEST_HEADERS:Host. [file "/etc/modsecurity.d/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "773"] [id "920350"] [msg "Host header is a numeric IP address"] [redacted] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [redacted] [uri "/.env"] [unique_id "amDnfLNOMy5iDfrZ7aEaEAAAADo"]
show less
Port Scan
🇵🇰
110.38.250.23
8 hours ago
(mod_security) mod_security (id:920280) triggered by 110.38.250.23 (PK/Pakistan/GPONUser38250-23.wat ...
show more
(mod_security) mod_security (id:920280) triggered by 110.38.250.23 (PK/Pakistan/GPONUser38250-23.wateen.net): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Wed Jul 22 11:17:55.313503 2026] [security2:error] [pid 135159:tid 135258] [client 110.38.250.23:63073] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/modsecurity.d/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "566"] [id "920280"] [msg "Request Missing a Host Header"] [severity "CRITICAL"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [redacted] [uri "/boaform/admin/formLogin"] [unique_id "amDfI5ahJDI0oYPypbcxQwAAAFA"]
show less
Port Scan
🇺🇸
49.51.196.42
8 hours ago
(mod_security) mod_security (id:920210) triggered by 49.51.196.42 (US/United States/-): 1 in the las ...
show more
(mod_security) mod_security (id:920210) triggered by 49.51.196.42 (US/United States/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Wed Jul 22 11:14:54.249195 2026] [security2:error] [pid 135159:tid 135265] [client 49.51.196.42:32952] ModSecurity: Access denied with code 406 (phase 1). Pattern match "\\\\b(?:keep-alive|close),\\\\s?(?:keep-alive|close)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/modsecurity.d/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "402"] [id "920210"] [msg "Multiple/Conflicting Connection Header Data Found"] [redacted] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [redacted] [uri "/"] [unique_id "amDebpahJDI0oYPypbcu8QAAAFc"]
show less
Port Scan
🇯🇵
152.32.146.202
9 hours ago
(mod_security) mod_security (id:920350) triggered by 152.32.146.202 (JP/Japan/-): 1 in the last 3600 ...
show more
(mod_security) mod_security (id:920350) triggered by 152.32.146.202 (JP/Japan/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Wed Jul 22 11:00:36.870051 2026] [security2:error] [pid 135159:tid 135300] [client 152.32.146.202:55798] ModSecurity: Access denied with code 406 (phase 1). Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at REQUEST_HEADERS:Host. [file "/etc/modsecurity.d/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "773"] [id "920350"] [msg "Host header is a numeric IP address"] [redacted] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [redacted] [uri "/"] [unique_id "amDbFJahJDI0oYPypbckugAAAHo"]
show less
Port Scan
🇬🇧
2a06:4883:9000::97
9 hours ago
(mod_security) mod_security (id:920350) triggered by 2a06:4883:9000::97 (r4-151-97.monitoring.intern ...
show more
(mod_security) mod_security (id:920350) triggered by 2a06:4883:9000::97 (r4-151-97.monitoring.internet-measurement.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Wed Jul 22 10:46:27.311422 2026] [security2:error] [pid 135159:tid 135291] [client 2a06:4883:9000::97:38935] ModSecurity: Access denied with code 406 (phase 1). Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at REQUEST_HEADERS:Host. [file "/etc/modsecurity.d/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "773"] [id "920350"] [msg "Host header is a numeric IP address"] [redacted]"] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [redacted] [uri "/"] [unique_id "amDXw5ahJDI0oYPypbchVQAAAHE"]
show less
Port Scan
🇬🇧
2a06:4883:5000::51
9 hours ago
(mod_security) mod_security (id:920350) triggered by 2a06:4883:5000::51 (r4-81-51.monitoring.interne ...
show more
(mod_security) mod_security (id:920350) triggered by 2a06:4883:5000::51 (r4-81-51.monitoring.internet-measurement.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Wed Jul 22 10:35:52.323954 2026] [security2:error] [pid 135159:tid 135255] [client 2a06:4883:5000::51:54999] ModSecurity: Access denied with code 406 (phase 1). Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at REQUEST_HEADERS:Host. [file "/etc/modsecurity.d/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "773"] [id "920350"] [msg "Host header is a numeric IP address"] [redacted]"] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [redacted] [uri "/"] [unique_id "amDVSJahJDI0oYPypbcesgAAAE0"]
show less
Port Scan
🇯🇵
8.209.236.193
9 hours ago
(mod_security) mod_security (id:920350) triggered by 8.209.236.193 (JP/Japan/-): 1 in the last 3600 ...
show more
(mod_security) mod_security (id:920350) triggered by 8.209.236.193 (JP/Japan/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Wed Jul 22 10:03:13.462083 2026] [security2:error] [pid 135159:tid 135288] [client 8.209.236.193:51020] ModSecurity: Access denied with code 406 (phase 1). Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at REQUEST_HEADERS:Host. [file "/etc/modsecurity.d/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "773"] [id "920350"] [msg "Host header is a numeric IP address"] [redacted] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [redacted] [uri "/"] [unique_id "amDNoZahJDI0oYPypbcH7AAAAG4"]
show less
Port Scan
🇰🇪
197.248.233.55
10 hours ago
(mod_security) mod_security (id:920350) triggered by 197.248.233.55 (KE/Kenya/197-248-233-55.safaric ...
show more
(mod_security) mod_security (id:920350) triggered by 197.248.233.55 (KE/Kenya/197-248-233-55.safaricombusiness.co.ke): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Wed Jul 22 09:48:51.912817 2026] [security2:error] [pid 135159:tid 135294] [client 197.248.233.55:56472] ModSecurity: Access denied with code 406 (phase 1). Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at REQUEST_HEADERS:Host. [file "/etc/modsecurity.d/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "773"] [id "920350"] [msg "Host header is a numeric IP address"] [redacted] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [redacted] [uri "/wsman"] [unique_id "amDKQ5ahJDI0oYPypbcDFgAAAHQ"]
show less
Port Scan
🇷🇴
92.118.39.86
10 hours ago
(mod_security) mod_security (id:913100) triggered by 92.118.39.86 (NL/The Netherlands/-): 1 in the l ...
show more
(mod_security) mod_security (id:913100) triggered by 92.118.39.86 (NL/The Netherlands/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Wed Jul 22 09:44:31.843195 2026] [security2:error] [pid 135159:tid 135260] [client 92.118.39.86:42904] ModSecurity: Access denied with code 406 (phase 1). Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity.d/REQUEST-913-SCANNER-DETECTION.conf"] [line "56"] [id "913100"] [msg "Found User-Agent associated with security scanner"] [redacted] [severity "CRITICAL"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-reputation-scanner"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/SCANNER-DETECTION"] [tag "capec/1000/118/224/541/310"] [redacted] [uri "/op/7_md/9/1/2/3/4"] [unique_id "amDJP5ahJDI0oYPypbcCPwAAAFI"]
show less
Port Scan