๐ณ๐ด
202.50.55.150
22 Jul 2026
(mod_security) mod_security (id:920350) triggered by 202.50.55.150 (NO/Norway/-): 1 in the last 3600 ...
show more
(mod_security) mod_security (id:920350) triggered by 202.50.55.150 (NO/Norway/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Wed Jul 22 15:00:12.802381 2026] [security2:error] [pid 757116:tid 757485] [client 202.50.55.150:53177] ModSecurity: Access denied with code 406 (phase 1). Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at REQUEST_HEADERS:Host. [file "/etc/modsecurity.d/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "773"] [id "920350"] [msg "Host header is a numeric IP address"] [redacted] [severity "WARNING"] [ver "OWASP_CRS/4.28.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [redacted] [uri "/.env"] [unique_id "amETPAzwcgGTyYxe1txnogAAASc"]
show less
Port Scan
๐บ๐ธ
50.116.55.27
22 Jul 2026
(mod_security) mod_security (id:920350) triggered by 50.116.55.27 (US/United States/50-116-55-27.ip. ...
show more
(mod_security) mod_security (id:920350) triggered by 50.116.55.27 (US/United States/50-116-55-27.ip.linodeusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Wed Jul 22 14:59:24.901224 2026] [security2:error] [pid 757116:tid 757490] [client 50.116.55.27:18058] ModSecurity: Access denied with code 406 (phase 1). Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at REQUEST_HEADERS:Host. [file "/etc/modsecurity.d/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "773"] [id "920350"] [msg "Host header is a numeric IP address"] [redacted] [severity "WARNING"] [ver "OWASP_CRS/4.28.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [redacted] [uri "/"] [unique_id "amETDAzwcgGTyYxe1txnRAAAASw"]
show less
Port Scan
๐ฐ๐ท
152.32.139.190
22 Jul 2026
(eximsyntax) Exim syntax errors from 152.32.139.190 (KR/South Korea/iafrssh.cn): 1 in the last 3600 ...
show more
(eximsyntax) Exim syntax errors from 152.32.139.190 (KR/South Korea/iafrssh.cn): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: 2026-07-22 14:31:20 SMTP call from [152.32.139.190] dropped: too many syntax or protocol errors (last command was "?", NULL)
show less
Port Scan
๐ธ๐ฌ
43.98.175.156
22 Jul 2026
(mod_security) mod_security (id:930130) triggered by 43.98.175.156 (SG/Singapore/-): 1 in the last 3 ...
show more
(mod_security) mod_security (id:930130) triggered by 43.98.175.156 (SG/Singapore/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Wed Jul 22 14:14:56.462235 2026] [security2:error] [pid 306847:tid 307579] [client 43.98.175.156:0] ModSecurity: Access denied with code 406 (phase 1). Matched phrase "config.php" at REQUEST_FILENAME. [file "/etc/modsecurity.d/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "150"] [id "930130"] [msg "Restricted File Access Attempt"] [redacted] [severity "CRITICAL"] [ver "OWASP_CRS/4.28.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/ATTACK-LFI"] [tag "capec/1000/255/153/126"] [redacted] [uri "/wordpress/wp-admin/setup-config.php"] [unique_id "amEIoB48i1CZTU5K4yRyvwAAAHY"]
show less
Port Scan
๐ฎ๐ณ
152.32.159.177
22 Jul 2026
(ftpd) Failed FTP login from 152.32.159.177 (IN/India/-): 1 in the last 3600 secs; Ports: *; Directi ...
show more
(ftpd) Failed FTP login from 152.32.159.177 (IN/India/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: Jul 22 14:13:39 web pure-ftpd: ([email protected] ) [WARNING] Authentication failed for user [anonymous]
show less
Port Scan
๐ฉ๐ช
49.51.132.100
22 Jul 2026
(mod_security) mod_security (id:920210) triggered by 49.51.132.100 (DE/Germany/-): 1 in the last 360 ...
show more
(mod_security) mod_security (id:920210) triggered by 49.51.132.100 (DE/Germany/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Wed Jul 22 13:53:40.139620 2026] [security2:error] [pid 143709:tid 144444] [client 49.51.132.100:46292] ModSecurity: Access denied with code 406 (phase 1). Pattern match "\\\\b(?:keep-alive|close),\\\\s?(?:keep-alive|close)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/modsecurity.d/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "402"] [id "920210"] [msg "Multiple/Conflicting Connection Header Data Found"] [redacted] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [redacted] [uri "/"] [unique_id "amEDpFcfBhzJyypYHHR0HQAAAJU"]
show less
Port Scan
๐ง๐ช
34.53.192.169
22 Jul 2026
(ftpd) Failed FTP login from 34.53.192.169 (BE/Belgium/169.192.53.34.bc.googleusercontent.com): 1 in ...
show more
(ftpd) Failed FTP login from 34.53.192.169 (BE/Belgium/169.192.53.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: Jul 22 13:05:03 web pure-ftpd: ([email protected] ) [WARNING] Authentication failed for user [anonymous]
show less
Port Scan
๐ฌ๐ง
185.248.85.29
22 Jul 2026
(mod_security) mod_security (id:920350) triggered by 185.248.85.29 (GB/United Kingdom/-): 1 in the l ...
show more
(mod_security) mod_security (id:920350) triggered by 185.248.85.29 (GB/United Kingdom/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Wed Jul 22 13:04:15.259847 2026] [security2:error] [pid 139793:tid 139862] [client 185.248.85.29:62791] ModSecurity: Access denied with code 406 (phase 1). Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at REQUEST_HEADERS:Host. [file "/etc/modsecurity.d/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "773"] [id "920350"] [msg "Host header is a numeric IP address"] [redacted] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [redacted] [uri "/"] [unique_id "amD4Dwwl64X9Ye6nxE5obgAAAEI"]
show less
Port Scan
๐บ๐ธ
34.143.67.109
22 Jul 2026
(mod_security) mod_security (id:920350) triggered by 34.143.67.109 (US/United States/109.67.143.34.b ...
show more
(mod_security) mod_security (id:920350) triggered by 34.143.67.109 (US/United States/109.67.143.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Wed Jul 22 11:53:32.986497 2026] [security2:error] [pid 138507:tid 138648] [client 34.143.67.109:46188] ModSecurity: Access denied with code 406 (phase 1). Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at REQUEST_HEADERS:Host. [file "/etc/modsecurity.d/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "773"] [id "920350"] [msg "Host header is a numeric IP address"] [redacted] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [redacted] [uri "/.env"] [unique_id "amDnfLNOMy5iDfrZ7aEaEAAAADo"]
show less
Port Scan
๐ต๐ฐ
110.38.250.23
22 Jul 2026
(mod_security) mod_security (id:920280) triggered by 110.38.250.23 (PK/Pakistan/GPONUser38250-23.wat ...
show more
(mod_security) mod_security (id:920280) triggered by 110.38.250.23 (PK/Pakistan/GPONUser38250-23.wateen.net): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Wed Jul 22 11:17:55.313503 2026] [security2:error] [pid 135159:tid 135258] [client 110.38.250.23:63073] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/modsecurity.d/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "566"] [id "920280"] [msg "Request Missing a Host Header"] [severity "CRITICAL"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [redacted] [uri "/boaform/admin/formLogin"] [unique_id "amDfI5ahJDI0oYPypbcxQwAAAFA"]
show less
Port Scan
๐บ๐ธ
49.51.196.42
22 Jul 2026
(mod_security) mod_security (id:920210) triggered by 49.51.196.42 (US/United States/-): 1 in the las ...
show more
(mod_security) mod_security (id:920210) triggered by 49.51.196.42 (US/United States/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Wed Jul 22 11:14:54.249195 2026] [security2:error] [pid 135159:tid 135265] [client 49.51.196.42:32952] ModSecurity: Access denied with code 406 (phase 1). Pattern match "\\\\b(?:keep-alive|close),\\\\s?(?:keep-alive|close)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/modsecurity.d/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "402"] [id "920210"] [msg "Multiple/Conflicting Connection Header Data Found"] [redacted] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [redacted] [uri "/"] [unique_id "amDebpahJDI0oYPypbcu8QAAAFc"]
show less
Port Scan
๐ฏ๐ต
152.32.146.202
22 Jul 2026
(mod_security) mod_security (id:920350) triggered by 152.32.146.202 (JP/Japan/-): 1 in the last 3600 ...
show more
(mod_security) mod_security (id:920350) triggered by 152.32.146.202 (JP/Japan/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Wed Jul 22 11:00:36.870051 2026] [security2:error] [pid 135159:tid 135300] [client 152.32.146.202:55798] ModSecurity: Access denied with code 406 (phase 1). Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at REQUEST_HEADERS:Host. [file "/etc/modsecurity.d/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "773"] [id "920350"] [msg "Host header is a numeric IP address"] [redacted] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [redacted] [uri "/"] [unique_id "amDbFJahJDI0oYPypbckugAAAHo"]
show less
Port Scan
๐ฌ๐ง
2a06:4883:9000::97
22 Jul 2026
(mod_security) mod_security (id:920350) triggered by 2a06:4883:9000::97 (r4-151-97.monitoring.intern ...
show more
(mod_security) mod_security (id:920350) triggered by 2a06:4883:9000::97 (r4-151-97.monitoring.internet-measurement.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Wed Jul 22 10:46:27.311422 2026] [security2:error] [pid 135159:tid 135291] [client 2a06:4883:9000::97:38935] ModSecurity: Access denied with code 406 (phase 1). Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at REQUEST_HEADERS:Host. [file "/etc/modsecurity.d/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "773"] [id "920350"] [msg "Host header is a numeric IP address"] [redacted]"] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [redacted] [uri "/"] [unique_id "amDXw5ahJDI0oYPypbchVQAAAHE"]
show less
Port Scan
๐ฌ๐ง
2a06:4883:5000::51
22 Jul 2026
(mod_security) mod_security (id:920350) triggered by 2a06:4883:5000::51 (r4-81-51.monitoring.interne ...
show more
(mod_security) mod_security (id:920350) triggered by 2a06:4883:5000::51 (r4-81-51.monitoring.internet-measurement.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Wed Jul 22 10:35:52.323954 2026] [security2:error] [pid 135159:tid 135255] [client 2a06:4883:5000::51:54999] ModSecurity: Access denied with code 406 (phase 1). Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at REQUEST_HEADERS:Host. [file "/etc/modsecurity.d/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "773"] [id "920350"] [msg "Host header is a numeric IP address"] [redacted]"] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [redacted] [uri "/"] [unique_id "amDVSJahJDI0oYPypbcesgAAAE0"]
show less
Port Scan
๐ฏ๐ต
8.209.236.193
22 Jul 2026
(mod_security) mod_security (id:920350) triggered by 8.209.236.193 (JP/Japan/-): 1 in the last 3600 ...
show more
(mod_security) mod_security (id:920350) triggered by 8.209.236.193 (JP/Japan/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Wed Jul 22 10:03:13.462083 2026] [security2:error] [pid 135159:tid 135288] [client 8.209.236.193:51020] ModSecurity: Access denied with code 406 (phase 1). Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at REQUEST_HEADERS:Host. [file "/etc/modsecurity.d/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "773"] [id "920350"] [msg "Host header is a numeric IP address"] [redacted] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [redacted] [uri "/"] [unique_id "amDNoZahJDI0oYPypbcH7AAAAG4"]
show less
Port Scan
๐ฐ๐ช
197.248.233.55
22 Jul 2026
(mod_security) mod_security (id:920350) triggered by 197.248.233.55 (KE/Kenya/197-248-233-55.safaric ...
show more
(mod_security) mod_security (id:920350) triggered by 197.248.233.55 (KE/Kenya/197-248-233-55.safaricombusiness.co.ke): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Wed Jul 22 09:48:51.912817 2026] [security2:error] [pid 135159:tid 135294] [client 197.248.233.55:56472] ModSecurity: Access denied with code 406 (phase 1). Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at REQUEST_HEADERS:Host. [file "/etc/modsecurity.d/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "773"] [id "920350"] [msg "Host header is a numeric IP address"] [redacted] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [redacted] [uri "/wsman"] [unique_id "amDKQ5ahJDI0oYPypbcDFgAAAHQ"]
show less
Port Scan
๐ท๐ด
92.118.39.86
22 Jul 2026
(mod_security) mod_security (id:913100) triggered by 92.118.39.86 (NL/The Netherlands/-): 1 in the l ...
show more
(mod_security) mod_security (id:913100) triggered by 92.118.39.86 (NL/The Netherlands/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Wed Jul 22 09:44:31.843195 2026] [security2:error] [pid 135159:tid 135260] [client 92.118.39.86:42904] ModSecurity: Access denied with code 406 (phase 1). Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity.d/REQUEST-913-SCANNER-DETECTION.conf"] [line "56"] [id "913100"] [msg "Found User-Agent associated with security scanner"] [redacted] [severity "CRITICAL"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-reputation-scanner"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/SCANNER-DETECTION"] [tag "capec/1000/118/224/541/310"] [redacted] [uri "/op/7_md/9/1/2/3/4"] [unique_id "amDJP5ahJDI0oYPypbcCPwAAAFI"]
show less
Port Scan
๐บ๐ธ
43.159.132.207
22 Jul 2026
(mod_security) mod_security (id:920210) triggered by 43.159.132.207 (US/United States/-): 1 in the l ...
show more
(mod_security) mod_security (id:920210) triggered by 43.159.132.207 (US/United States/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Wed Jul 22 09:23:58.143532 2026] [security2:error] [pid 131896:tid 131979] [client 43.159.132.207:56864] ModSecurity: Access denied with code 406 (phase 1). Pattern match "\\\\b(?:keep-alive|close),\\\\s?(?:keep-alive|close)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/modsecurity.d/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "402"] [id "920210"] [msg "Multiple/Conflicting Connection Header Data Found"] [redacted] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [redacted] [uri "/"] [unique_id "amDEbg4BBWYBF6qHvo-r6QAAAAA"]
show less
Port Scan
๐บ๐ธ
128.203.204.25
22 Jul 2026
(mod_security) mod_security (id:913100) triggered by 128.203.204.25 (US/United States/azpdcg1tehht.s ...
show more
(mod_security) mod_security (id:913100) triggered by 128.203.204.25 (US/United States/azpdcg1tehht.stretchoid.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Wed Jul 22 09:13:09.873707 2026] [security2:error] [pid 131896:tid 131993] [client 128.203.204.25:43792] ModSecurity: Access denied with code 406 (phase 1). Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity.d/REQUEST-913-SCANNER-DETECTION.conf"] [line "56"] [id "913100"] [msg "Found User-Agent associated with security scanner"] [redacted] [severity "CRITICAL"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-reputation-scanner"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/SCANNER-DETECTION"] [tag "capec/1000/118/224/541/310"] [redacted] [uri "/developmentserver/metadatauploader"] [unique_id "amDB5Q4BBWYBF6qHvo-kQQAAAA4"]
show less
Port Scan
๐บ๐ธ
66.132.172.47
22 Jul 2026
(mod_security) mod_security (id:920350) triggered by 66.132.172.47 (US/United States/47.172.132.66.c ...
show more
(mod_security) mod_security (id:920350) triggered by 66.132.172.47 (US/United States/47.172.132.66.censys-scanner.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Wed Jul 22 08:55:54.359800 2026] [security2:error] [pid 131896:tid 131981] [client 66.132.172.47:16436] ModSecurity: Access denied with code 406 (phase 1). Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at REQUEST_HEADERS:Host. [file "/etc/modsecurity.d/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "773"] [id "920350"] [msg "Host header is a numeric IP address"] [redacted] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [redacted] [uri "/"] [unique_id "amC92g4BBWYBF6qHvo-Z-AAAAAI"]
show less
Port Scan
๐ฒ๐ณ
180.149.126.8
22 Jul 2026
(mod_security) mod_security (id:920350) triggered by 180.149.126.8 (MN/Mongolia/-): 1 in the last 36 ...
show more
(mod_security) mod_security (id:920350) triggered by 180.149.126.8 (MN/Mongolia/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Wed Jul 22 07:25:42.308858 2026] [security2:error] [pid 128185:tid 128320] [client 180.149.126.8:55285] ModSecurity: Access denied with code 406 (phase 1). Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at REQUEST_HEADERS:Host. [file "/etc/modsecurity.d/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "773"] [id "920350"] [msg "Host header is a numeric IP address"] [redacted] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [redacted] [uri "/stalker_portal/server/tools/auth_simple.php"] [unique_id "amCottJVvaq9ehlkjEjfOgAAAHQ"]
show less
Port Scan
๐บ๐ธ
20.163.15.238
22 Jul 2026
(mod_security) mod_security (id:913100) triggered by 20.163.15.238 (US/United States/azpdwsp7exl1.st ...
show more
(mod_security) mod_security (id:913100) triggered by 20.163.15.238 (US/United States/azpdwsp7exl1.stretchoid.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Wed Jul 22 07:14:57.332022 2026] [security2:error] [pid 128185:tid 128274] [client 20.163.15.238:42476] ModSecurity: Access denied with code 406 (phase 1). Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity.d/REQUEST-913-SCANNER-DETECTION.conf"] [line "56"] [id "913100"] [msg "Found User-Agent associated with security scanner"] [redacted] [severity "CRITICAL"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-reputation-scanner"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/SCANNER-DETECTION"] [tag "capec/1000/118/224/541/310"] [redacted] [uri "/ReportServer"] [unique_id "amCmMdJVvaq9ehlkjEjXBQAAAEY"]
show less
Port Scan
๐ป๐ณ
58.186.224.192
22 Jul 2026
(mod_security) mod_security (id:920280) triggered by 58.186.224.192 (VN/Vietnam/-): 1 in the last 36 ...
show more
(mod_security) mod_security (id:920280) triggered by 58.186.224.192 (VN/Vietnam/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Wed Jul 22 07:08:41.818122 2026] [security2:error] [pid 128185:tid 128300] [client 58.186.224.192:56069] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/modsecurity.d/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "566"] [id "920280"] [msg "Request Missing a Host Header"] [severity "CRITICAL"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [redacted] [uri "/"] [unique_id "amCkudJVvaq9ehlkjEjSxAAAAGA"]
show less
Port Scan
๐ฌ๐ง
64.227.35.6
22 Jul 2026
(mod_security) mod_security (id:920350) triggered by 64.227.35.6 (GB/United Kingdom/-): 1 in the las ...
show more
(mod_security) mod_security (id:920350) triggered by 64.227.35.6 (GB/United Kingdom/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Wed Jul 22 04:43:54.366882 2026] [security2:error] [pid 124909:tid 125046] [client 64.227.35.6:60832] ModSecurity: Access denied with code 406 (phase 1). Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at REQUEST_HEADERS:Host. [file "/etc/modsecurity.d/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "773"] [id "920350"] [msg "Host header is a numeric IP address"] [redacted] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [redacted] [uri "/"] [unique_id "amCCys5aeSZ1cZjU8ZSKjAAAADY"]
show less
Port Scan
๐จ๐ณ
115.49.200.94
22 Jul 2026
(mod_security) mod_security (id:920340) triggered by 115.49.200.94 (CN/China/hn.kd.ny.adsl): 1 in th ...
show more
(mod_security) mod_security (id:920340) triggered by 115.49.200.94 (CN/China/hn.kd.ny.adsl): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Wed Jul 22 04:27:59.222314 2026] [security2:error] [pid 124909:tid 125011] [client 115.49.200.94:55588] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/modsecurity.d/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "728"] [id "920340"] [msg "Content-Type header missing from request with non-zero Content-Length"] [severity "CRITICAL"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [redacted] [uri "/GponForm/diag_Form"] [unique_id "amB_D85aeSZ1cZjU8ZSC0wAAABM"]
show less
Port Scan