|
๐ณ๐ฑ
2001:1c00:5:b400:cf7:7c3f:b61d:8a31
|
|
[Tue Sep 08 15:57:44.148106 2026] [security2:error] [pid 3506770:tid 3506770] [client 2001:1c00:5:b4 ...
show more
[Tue Sep 08 15:57:44.148106 2026] [security2:error] [pid 3506770:tid 3506770] [client 2001:1c00:5:b400:cf7:7c3f:b61d:8a31:50769] [client 2001:1c00:5:b400:cf7:7c3f:b61d:8a31] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "fambus.nl"] [uri "/wpad.dat"] [unique_id "aqAweMvNn43dYNbymyyIrAAAAAA"]
[Tue Sep 08 15:57:45.125984 2026] [security2:error] [pid 3506770:tid 3506770] [client 2001:1c00:5:b400:cf7:7c3f:b61d:8a31:51782] [client 2001:1c00:5:b400:cf7:7c3f:b61d:8a31] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"
...
show less
|
Hacking
Web App Attack
|
|
๐ท๐ด
80.94.95.29
|
|
[Tue Sep 08 15:37:06.502203 2026] [security2:error] [pid 3479438:tid 3479438] [client 80.94.95.29:40 ...
show more
[Tue Sep 08 15:37:06.502203 2026] [security2:error] [pid 3479438:tid 3479438] [client 80.94.95.29:40709] [client 80.94.95.29] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [data "94.209.38.171"] [severity "WARNING"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "94.209.38.171"] [uri "/remote/login"] [unique_id "aqAromaU8snpQ2_2pIeYhgAAAA8"]
[Tue Sep 08 15:37:06.660966 2026] [security2:error] [pid 3479455:tid 3479455] [client 80.94.95.29:40720] [client 80.94.95.29] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920
...
show less
|
Hacking
Web App Attack
|
|
๐ธ๐ฎ
102.220.161.87
|
|
[Tue Sep 08 15:27:38.133455 2026] [security2:error] [pid 3479433:tid 3479433] [client 102.220.161.87 ...
show more
[Tue Sep 08 15:27:38.133455 2026] [security2:error] [pid 3479433:tid 3479433] [client 102.220.161.87:58736] [client 102.220.161.87] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [data "94.209.38.171"] [severity "WARNING"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "94.209.38.171"] [uri "/.env"] [unique_id "aqApauE2Z84Af_76MTEzqQAAAAQ"]
[Tue Sep 08 15:27:38.135038 2026] [security2:error] [pid 3479433:tid 3479433] [client 102.220.161.87:58736] [client 102.220.161.87] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"]
...
show less
|
Hacking
Web App Attack
|
|
๐ณ๐ฑ
2001:1c00:5:b400:1099:cc60:397b:8e09
|
|
[Tue Sep 08 14:41:07.287612 2026] [security2:error] [pid 3386331:tid 3386331] [client 2001:1c00:5:b4 ...
show more
[Tue Sep 08 14:41:07.287612 2026] [security2:error] [pid 3386331:tid 3386331] [client 2001:1c00:5:b400:1099:cc60:397b:8e09:7164] [client 2001:1c00:5:b400:1099:cc60:397b:8e09] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "fambus.nl"] [uri "/wpad.dat"] [unique_id "aqAeg8sI3XEm9t_VeYqgDQAAABQ"]
[Tue Sep 08 14:41:07.289218 2026] [security2:error] [pid 3437990:tid 3437990] [client 2001:1c00:5:b400:1099:cc60:397b:8e09:7163] [client 2001:1c00:5:b400:1099:cc60:397b:8e09] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.con
...
show less
|
Hacking
Web App Attack
|
|
๐ฟ๐ฆ
34.35.49.114
|
|
[Tue Sep 08 13:42:45.059230 2026] [security2:error] [pid 3386331:tid 3386331] [client 34.35.49.114:5 ...
show more
[Tue Sep 08 13:42:45.059230 2026] [security2:error] [pid 3386331:tid 3386331] [client 34.35.49.114:50828] [client 34.35.49.114] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "onderdelen.fambus.nl"] [uri "/"] [unique_id "aqAQ1csI3XEm9t_VeYqeswAAABQ"]
[Tue Sep 08 13:42:45.238070 2026] [security2:error] [pid 3386331:tid 3386331] [client 34.35.49.114:50828] [client 34.35.49.114] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [seve
...
show less
|
Hacking
Web App Attack
|
|
๐ฏ๐ต
35.200.124.139
|
|
[Tue Sep 08 13:26:08.882278 2026] [security2:error] [pid 3386333:tid 3386333] [client 35.200.124.139 ...
show more
[Tue Sep 08 13:26:08.882278 2026] [security2:error] [pid 3386333:tid 3386333] [client 35.200.124.139:0] [client 35.200.124.139] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.fambus.nl"] [uri "/.git/config"] [unique_id "aqAM8Flj6YeZzPtrN0b31gAAABY"]
[Tue Sep 08 13:26:09.414428 2026] [security2:error] [pid 3386325:tid 3386325] [client 35.200.124.139:0] [client 35.200.124.139] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [
...
show less
|
Hacking
Web App Attack
|
|
๐บ๐ธ
66.132.172.136
|
|
[Tue Sep 08 13:20:53.865342 2026] [security2:error] [pid 3386331:tid 3386331] [client 66.132.172.136 ...
show more
[Tue Sep 08 13:20:53.865342 2026] [security2:error] [pid 3386331:tid 3386331] [client 66.132.172.136:13864] [client 66.132.172.136] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [data "94.209.38.171"] [severity "WARNING"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "94.209.38.171"] [uri "/"] [unique_id "aqALtcsI3XEm9t_VeYqeIQAAABQ"]
[Tue Sep 08 13:20:56.100285 2026] [security2:error] [pid 3386328:tid 3386328] [client 66.132.172.136:13892] [client 66.132.172.136] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920
...
show less
|
Hacking
Web App Attack
|
|
๐บ๐ธ
136.67.110.190
|
|
[Tue Sep 08 13:07:39.474873 2026] [security2:error] [pid 3267258:tid 3267258] [client 136.67.110.190 ...
show more
[Tue Sep 08 13:07:39.474873 2026] [security2:error] [pid 3267258:tid 3267258] [client 136.67.110.190:8900] [client 136.67.110.190] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "mail.fambus.nl"] [uri "/@fs/.env"] [unique_id "aqAIm1akQsBGyCTRsnS64QAAAB4"]
[Tue Sep 08 13:07:39.525064 2026] [security2:error] [pid 3267271:tid 3267271] [client 136.67.110.190:8926] [client 136.67.110.190] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)
...
show less
|
Hacking
Web App Attack
|
|
๐น๐ท
94.154.43.196
|
|
[Tue Sep 08 10:34:37.664530 2026] [security2:error] [pid 3267261:tid 3267261] [client 94.154.43.196: ...
show more
[Tue Sep 08 10:34:37.664530 2026] [security2:error] [pid 3267261:tid 3267261] [client 94.154.43.196:34856] [client 94.154.43.196] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [data "94.209.38.171:443"] [severity "WARNING"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "94.209.38.171"] [uri "/"] [unique_id "ap_kvTQEFzzatt8oT9mZ0QAAACE"]
[Tue Sep 08 10:34:37.756848 2026] [security2:error] [pid 3267271:tid 3267271] [client 94.154.43.196:34872] [client 94.154.43.196] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920
...
show less
|
Hacking
Web App Attack
|
|
๐ณ๐ฑ
91.92.47.125
|
|
[Tue Sep 08 10:19:02.095953 2026] [security2:error] [pid 3206397:tid 3206397] [client 91.92.47.125:0 ...
show more
[Tue Sep 08 10:19:02.095953 2026] [security2:error] [pid 3206397:tid 3206397] [client 91.92.47.125:0] [client 91.92.47.125] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "pop-the-slots.com"] [uri "/.env.swp"] [unique_id "ap_hFnBHmQxiDSbj9G4wKQAAAAE"]
[Tue Sep 08 10:19:02.292536 2026] [security2:error] [pid 3232401:tid 3232401] [client 91.92.47.125:0] [client 91.92.47.125] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [sever
...
show less
|
Hacking
Web App Attack
|
|
๐บ๐ธ
65.49.1.10
|
|
[Tue Sep 08 09:01:59.646778 2026] [security2:error] [pid 3170274:tid 3170274] [client 65.49.1.10:246 ...
show more
[Tue Sep 08 09:01:59.646778 2026] [security2:error] [pid 3170274:tid 3170274] [client 65.49.1.10:24666] [client 65.49.1.10] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [data "94.209.38.171"] [severity "WARNING"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "94.209.38.171"] [uri "/"] [unique_id "ap_PB3ytPViy_QtrdB0d-wAAAAM"]
[Tue Sep 08 09:30:55.471114 2026] [security2:error] [pid 3206438:tid 3206438] [client 65.49.1.10:34742] [client 65.49.1.10] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host
...
show less
|
Hacking
Web App Attack
|
|
๐บ๐ธ
199.85.8.115
|
|
[Tue Sep 08 08:16:23.152863 2026] [security2:error] [pid 3146828:tid 3146828] [client 199.85.8.115:3 ...
show more
[Tue Sep 08 08:16:23.152863 2026] [security2:error] [pid 3146828:tid 3146828] [client 199.85.8.115:39228] [client 199.85.8.115] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 25)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "fambus.nl"] [uri "/"] [unique_id "ap_EVyWV_rFo7PA1X61osQAAAAA"]
[Tue Sep 08 08:16:23.368164 2026] [security2:error] [pid 3146828:tid 3146828] [client 199.85.8.115:39228] [client 199.85.8.115] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 25)"] [severity "CRI
...
show less
|
Hacking
Web App Attack
|
|
๐ฉ๐ช
213.209.159.133
|
|
[Tue Sep 08 07:05:44.133665 2026] [security2:error] [pid 2957081:tid 2957081] [client 213.209.159.13 ...
show more
[Tue Sep 08 07:05:44.133665 2026] [security2:error] [pid 2957081:tid 2957081] [client 213.209.159.133:57890] [client 213.209.159.133] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "fambus.nl"] [uri "/.git/config"] [unique_id "ap-zyOUjzi1MsWviUMqbCwAAAAs"]
[Tue Sep 08 07:05:48.198733 2026] [security2:error] [pid 2957081:tid 2957081] [client 213.209.159.133:57890] [client 213.209.159.133] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score
...
show less
|
Hacking
Web App Attack
|
|
๐บ๐ธ
136.109.41.174
|
|
[Tue Sep 08 07:18:48.912416 2026] [security2:error] [pid 3140055:tid 3140055] [client 136.109.41.174 ...
show more
[Tue Sep 08 07:18:48.912416 2026] [security2:error] [pid 3140055:tid 3140055] [client 136.109.41.174:0] [client 136.109.41.174] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.fambus.nl"] [uri "/.env.local"] [unique_id "ap-22Iwxc9HJDKZLzk7xVQAAAC0"]
[Tue Sep 08 07:18:48.913272 2026] [security2:error] [pid 3140163:tid 3140163] [client 136.109.41.174:0] [client 136.109.41.174] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [s
...
show less
|
Hacking
Web App Attack
|
|
๐ฉ๐ช
213.209.159.154
|
|
[Tue Sep 08 07:11:03.817480 2026] [security2:error] [pid 2957029:tid 2957029] [client 213.209.159.15 ...
show more
[Tue Sep 08 07:11:03.817480 2026] [security2:error] [pid 2957029:tid 2957029] [client 213.209.159.154:25855] [client 213.209.159.154] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [data "94.209.38.171:443"] [severity "WARNING"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "94.209.38.171"] [uri "/"] [unique_id "ap-1BzG9FXYVH51VdpK4gwAAAAg"]
[Tue Sep 08 07:11:03.833507 2026] [security2:error] [pid 2957029:tid 2957029] [client 213.209.159.154:25855] [client 213.209.159.154] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"]
...
show less
|
Hacking
Web App Attack
|
|
๐ง๐ช
91.148.244.131
|
|
[Tue Sep 08 05:06:00.449502 2026] [security2:error] [pid 2841329:tid 2841329] [client 91.148.244.131 ...
show more
[Tue Sep 08 05:06:00.449502 2026] [security2:error] [pid 2841329:tid 2841329] [client 91.148.244.131:36870] [client 91.148.244.131] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "fambus.nl"] [uri "/.ssh/id_rsa"] [unique_id "ap-XuLeCPVzclpxSGh4jJwAAABQ"]
[Tue Sep 08 05:06:00.462699 2026] [security2:error] [pid 2827005:tid 2827005] [client 91.148.244.131:36880] [client 91.148.244.131] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)
...
show less
|
Hacking
Web App Attack
|
|
๐ท๐บ
45.91.64.7
|
|
[Tue Sep 08 04:02:21.195619 2026] [security2:error] [pid 2841335:tid 2841335] [client 45.91.64.7:537 ...
show more
[Tue Sep 08 04:02:21.195619 2026] [security2:error] [pid 2841335:tid 2841335] [client 45.91.64.7:53746] [client 45.91.64.7] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [data "94.209.38.171:443"] [severity "WARNING"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "94.209.38.171"] [uri "/aaa9"] [unique_id "ap-IzbfKs2SbU8PLxBZJeAAAABs"]
[Tue Sep 08 04:02:21.530133 2026] [security2:error] [pid 2841346:tid 2841346] [client 45.91.64.7:53758] [client 45.91.64.7] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [m
...
show less
|
Hacking
Web App Attack
|
|
๐บ๐ธ
151.243.18.111
|
|
[Tue Sep 08 03:38:22.796209 2026] [security2:error] [pid 2826982:tid 2826982] [client 151.243.18.111 ...
show more
[Tue Sep 08 03:38:22.796209 2026] [security2:error] [pid 2826982:tid 2826982] [client 151.243.18.111:48184] [client 151.243.18.111] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [data "94.209.38.171"] [severity "WARNING"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "94.209.38.171"] [uri "/.git/config"] [unique_id "ap-DLhy3L3OI9q8RBDPuKgAAAA8"]
[Tue Sep 08 03:38:22.796970 2026] [security2:error] [pid 2826982:tid 2826982] [client 151.243.18.111:48184] [client 151.243.18.111] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION
...
show less
|
Hacking
Web App Attack
|
|
๐ซ๐ท
185.177.72.17
|
|
[Tue Sep 08 02:42:15.300230 2026] [security2:error] [pid 2687161:tid 2687161] [client 185.177.72.17: ...
show more
[Tue Sep 08 02:42:15.300230 2026] [security2:error] [pid 2687161:tid 2687161] [client 185.177.72.17:0] [client 185.177.72.17] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "pop-the-slots.com"] [uri "/.env"] [unique_id "ap92B--Mqsjk9r6EjJFNoAAAABs"]
[Tue Sep 08 02:42:15.417016 2026] [security2:error] [pid 2799760:tid 2799760] [client 185.177.72.17:0] [client 185.177.72.17] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severit
...
show less
|
Hacking
Web App Attack
|
|
๐ณ๐ฑ
81.171.74.60
|
|
[Mon Sep 07 23:44:46.215587 2026] [security2:error] [pid 2613230:tid 2613230] [client 81.171.74.60:0 ...
show more
[Mon Sep 07 23:44:46.215587 2026] [security2:error] [pid 2613230:tid 2613230] [client 81.171.74.60:0] [client 81.171.74.60] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "pop-the-slots.com"] [uri "/.env.production"] [unique_id "ap9Mbgbm_o5LPgNR1N_CtQAAAAA"]
[Mon Sep 07 23:44:46.216436 2026] [security2:error] [pid 2570341:tid 2570341] [client 81.171.74.60:0] [client 81.171.74.60] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [
...
show less
|
Hacking
Web App Attack
|
|
๐ณ๐ฑ
91.92.241.196
|
|
[Mon Sep 07 21:32:36.860623 2026] [security2:error] [pid 2570384:tid 2570384] [client 91.92.241.196: ...
show more
[Mon Sep 07 21:32:36.860623 2026] [security2:error] [pid 2570384:tid 2570384] [client 91.92.241.196:7362] [client 91.92.241.196] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "fambus.nl"] [uri "/.git/HEAD"] [unique_id "ap8tdIheOdb_dxrmMySx6gAAAA4"]
[Mon Sep 07 21:32:37.280832 2026] [security2:error] [pid 2570382:tid 2570382] [client 91.92.241.196:7374] [client 91.92.241.196] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [seve
...
show less
|
Hacking
Web App Attack
|
|
๐ง๐ช
34.79.242.244
|
|
[Mon Sep 07 21:19:19.565022 2026] [security2:error] [pid 2570385:tid 2570385] [client 34.79.242.244: ...
show more
[Mon Sep 07 21:19:19.565022 2026] [security2:error] [pid 2570385:tid 2570385] [client 34.79.242.244:0] [client 34.79.242.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "pop-the-slots.com"] [uri "/ads.txt"] [unique_id "ap8qVx08hv70Ow-odN9UtQAAAA8"]
[Mon Sep 07 21:19:19.641436 2026] [security2:error] [pid 2570385:tid 2570385] [client 34.79.242.244:0] [client 34.79.242.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [se
...
show less
|
Hacking
Web App Attack
|
|
๐ณ๐ฑ
2001:1c00:5:b400:6033:65f7:18e1:48a3
|
|
[Mon Sep 07 20:20:04.490994 2026] [security2:error] [pid 2464651:tid 2464651] [client 2001:1c00:5:b4 ...
show more
[Mon Sep 07 20:20:04.490994 2026] [security2:error] [pid 2464651:tid 2464651] [client 2001:1c00:5:b400:6033:65f7:18e1:48a3:3115] [client 2001:1c00:5:b400:6033:65f7:18e1:48a3] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "fambus.nl"] [uri "/wpad.dat"] [unique_id "ap8cdAaGmkL-V1xKwP8nFwAAABA"]
[Mon Sep 07 20:20:04.491157 2026] [security2:error] [pid 2475453:tid 2475453] [client 2001:1c00:5:b400:6033:65f7:18e1:48a3:3116] [client 2001:1c00:5:b400:6033:65f7:18e1:48a3] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.con
...
show less
|
Hacking
Web App Attack
|
|
๐ฆ๐บ
34.40.192.128
|
|
[Mon Sep 07 18:30:00.558289 2026] [security2:error] [pid 2364484:tid 2364484] [client 34.40.192.128: ...
show more
[Mon Sep 07 18:30:00.558289 2026] [security2:error] [pid 2364484:tid 2364484] [client 34.40.192.128:0] [client 34.40.192.128] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "pop-the-slots.com"] [uri "/.git/config"] [unique_id "ap8CqJVtEVn8QJd7xjzEiQAAAAM"]
[Mon Sep 07 18:30:03.157008 2026] [security2:error] [pid 2404604:tid 2404604] [client 34.40.192.128:0] [client 34.40.192.128] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [
...
show less
|
Hacking
Web App Attack
|
|
๐จ๐ณ
106.75.10.60
|
|
[Mon Sep 07 18:15:33.300892 2026] [security2:error] [pid 2404604:tid 2404604] [client 106.75.10.60:4 ...
show more
[Mon Sep 07 18:15:33.300892 2026] [security2:error] [pid 2404604:tid 2404604] [client 106.75.10.60:49100] [client 106.75.10.60] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [data "94.209.38.171:443"] [severity "WARNING"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "94.209.38.171"] [uri "/"] [unique_id "ap7_Re9HUpnn2liw9u9fiQAAABE"]
[Mon Sep 07 18:15:34.566811 2026] [security2:error] [pid 2362778:tid 2362778] [client 106.75.10.60:49370] [client 106.75.10.60] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"
...
show less
|
Hacking
Web App Attack
|