|
๐ณ๐ฑ
159.223.211.139
|
|
[Sat Jul 25 01:36:27.776226 2026] [security2:error] [pid 469691:tid 469691] [client 159.223.211.139: ...
show more
[Sat Jul 25 01:36:27.776226 2026] [security2:error] [pid 469691:tid 469691] [client 159.223.211.139:37528] [client 159.223.211.139] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "fambus.nl"] [uri "/.env"] [unique_id "amQTG4SiiigeOvW4P3qGCgAAAAQ"], referer: http://94-209-38-171.cable.dynamic.v4.ziggo.nl/.env
[Sat Jul 25 01:37:47.813265 2026] [security2:error] [pid 469756:tid 469756] [client 159.223.211.139:44402] [client 159.223.211.139] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"
...
show less
|
Hacking
Web App Attack
|
|
๐ณ๐ฑ
185.132.133.88
|
|
[Sat Jul 25 00:45:46.876381 2026] [security2:error] [pid 469687:tid 469687] [client 185.132.133.88:5 ...
show more
[Sat Jul 25 00:45:46.876381 2026] [security2:error] [pid 469687:tid 469687] [client 185.132.133.88:54190] [client 185.132.133.88] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [data "94.209.38.171"] [severity "WARNING"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "94.209.38.171"] [uri "/.env"] [unique_id "amQHOrwenvNOWcTiBODcuQAAABI"]
[Sat Jul 25 00:45:46.876957 2026] [security2:error] [pid 469687:tid 469687] [client 185.132.133.88:54190] [client 185.132.133.88] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [li
...
show less
|
Hacking
Web App Attack
|
|
๐ณ๐ฑ
91.92.47.125
|
|
[Fri Jul 24 21:50:34.592510 2026] [security2:error] [pid 332968:tid 332968] [client 91.92.47.125:0] ...
show more
[Fri Jul 24 21:50:34.592510 2026] [security2:error] [pid 332968:tid 332968] [client 91.92.47.125:0] [client 91.92.47.125] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "pop-the-slots.com"] [uri "/.env"] [unique_id "amPeKuGn_NQp5tTaHKetkgAAAAg"]
[Fri Jul 24 21:50:38.594482 2026] [security2:error] [pid 332968:tid 332968] [client 91.92.47.125:0] [client 91.92.47.125] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITI
...
show less
|
Hacking
Web App Attack
|
|
๐ณ๐ฑ
91.92.241.196
|
|
[Fri Jul 24 21:11:21.061965 2026] [security2:error] [pid 332968:tid 332968] [client 91.92.241.196:0] ...
show more
[Fri Jul 24 21:11:21.061965 2026] [security2:error] [pid 332968:tid 332968] [client 91.92.241.196:0] [client 91.92.241.196] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.fambus.nl"] [uri "/.env"] [unique_id "amPU-eGn_NQp5tTaHKetjAAAAAg"]
[Fri Jul 24 21:11:23.813065 2026] [security2:error] [pid 332968:tid 332968] [client 91.92.241.196:0] [client 91.92.241.196] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITI
...
show less
|
Hacking
Web App Attack
|
|
๐บ๐ธ
34.74.242.206
|
|
[Fri Jul 24 18:39:36.723980 2026] [security2:error] [pid 160120:tid 160120] [client 34.74.242.206:0] ...
show more
[Fri Jul 24 18:39:36.723980 2026] [security2:error] [pid 160120:tid 160120] [client 34.74.242.206:0] [client 34.74.242.206] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.pop-the-slots.com"] [uri "/robots.txt"] [unique_id "amOxaMUE3vjBrLIGG2yNjwAAAAc"]
[Fri Jul 24 18:39:36.899468 2026] [security2:error] [pid 160120:tid 160120] [client 34.74.242.206:0] [client 34.74.242.206] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [s
...
show less
|
Hacking
Web App Attack
|
|
๐ณ๐ฑ
45.148.10.200
|
|
[Fri Jul 24 14:35:08.531424 2026] [security2:error] [pid 25606:tid 25606] [client 45.148.10.200:3815 ...
show more
[Fri Jul 24 14:35:08.531424 2026] [security2:error] [pid 25606:tid 25606] [client 45.148.10.200:38152] [client 45.148.10.200] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [data "94.209.38.171"] [severity "WARNING"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "94.209.38.171"] [uri "/"] [unique_id "amN4HNgJM5lt0TIn5h7UpAAAABE"]
[Fri Jul 24 14:35:08.618689 2026] [security2:error] [pid 25716:tid 25716] [client 45.148.10.200:38162] [client 45.148.10.200] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "
...
show less
|
Hacking
Web App Attack
|
|
๐ฎ๐ณ
34.180.48.181
|
|
[Fri Jul 24 12:51:28.365364 2026] [security2:error] [pid 25539:tid 25539] [client 34.180.48.181:5164 ...
show more
[Fri Jul 24 12:51:28.365364 2026] [security2:error] [pid 25539:tid 25539] [client 34.180.48.181:51648] [client 34.180.48.181] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "dashboard.fambus.nl"] [uri "/.git/HEAD"] [unique_id "amNf0EJBNVFrbHo2DnPnVQAAAAY"]
[Fri Jul 24 12:51:28.563544 2026] [security2:error] [pid 25600:tid 25600] [client 34.180.48.181:51696] [client 34.180.48.181] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [
...
show less
|
Hacking
Web App Attack
|
|
๐บ๐ธ
216.244.66.227
|
|
[Fri Jul 24 10:50:34.228791 2026] [security2:error] [pid 4132250:tid 4132250] [client 216.244.66.227 ...
show more
[Fri Jul 24 10:50:34.228791 2026] [security2:error] [pid 4132250:tid 4132250] [client 216.244.66.227:0] [client 216.244.66.227] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.pop-the-slots.com"] [uri "/robots.txt"] [unique_id "amNDeghKkQ4E9MqbMbGo0gAAAAo"]
[Fri Jul 24 11:42:08.418355 2026] [security2:error] [pid 4132236:tid 4132236] [client 216.244.66.227:0] [client 216.244.66.227] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score:
...
show less
|
Hacking
Web App Attack
|
|
๐ณ๐ฑ
2001:1c00:3:400:7538:90f3:3469:b458
|
|
[Fri Jul 24 10:53:22.216400 2026] [security2:error] [pid 3976571:tid 3976571] [client 2001:1c00:3:40 ...
show more
[Fri Jul 24 10:53:22.216400 2026] [security2:error] [pid 3976571:tid 3976571] [client 2001:1c00:3:400:7538:90f3:3469:b458:9324] [client 2001:1c00:3:400:7538:90f3:3469:b458] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "fambus.nl"] [uri "/wpad.dat"] [unique_id "amNEIu4YDTe-MdxIodFCVQAAAAc"]
[Fri Jul 24 11:03:22.292246 2026] [security2:error] [pid 4132236:tid 4132236] [client 2001:1c00:3:400:7538:90f3:3469:b458:9428] [client 2001:1c00:3:400:7538:90f3:3469:b458] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"]
...
show less
|
Hacking
Web App Attack
|
|
๐บ๐ธ
184.105.139.69
|
|
[Fri Jul 24 08:55:59.212730 2026] [security2:error] [pid 4057826:tid 4057826] [client 184.105.139.69 ...
show more
[Fri Jul 24 08:55:59.212730 2026] [security2:error] [pid 4057826:tid 4057826] [client 184.105.139.69:32256] [client 184.105.139.69] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [data "94.209.38.171"] [severity "WARNING"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "94.209.38.171"] [uri "/"] [unique_id "amMon_7gIzQ9FJyyyg68uwAAAAQ"]
[Fri Jul 24 09:14:37.992580 2026] [security2:error] [pid 4072777:tid 4072777] [client 184.105.139.69:44330] [client 184.105.139.69] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920
...
show less
|
Hacking
Web App Attack
|
|
๐บ๐ธ
34.148.90.16
|
|
[Fri Jul 24 08:47:34.214030 2026] [security2:error] [pid 4057801:tid 4057801] [client 34.148.90.16:3 ...
show more
[Fri Jul 24 08:47:34.214030 2026] [security2:error] [pid 4057801:tid 4057801] [client 34.148.90.16:38656] [client 34.148.90.16] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "manage.fambus.nl"] [uri "/.ssh/authorized_keys"] [unique_id "amMmpri4VYBbMiq6Ycrp4wAAAA4"]
[Fri Jul 24 08:47:34.229026 2026] [security2:error] [pid 3976571:tid 3976571] [client 34.148.90.16:38672] [client 34.148.90.16] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total S
...
show less
|
Hacking
Web App Attack
|
|
๐ฎ๐ณ
34.180.48.181
|
|
[Fri Jul 24 06:45:45.126811 2026] [security2:error] [pid 3669394:tid 3669394] [client 34.180.48.181: ...
show more
[Fri Jul 24 06:45:45.126811 2026] [security2:error] [pid 3669394:tid 3669394] [client 34.180.48.181:57566] [client 34.180.48.181] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "auth.fambus.nl"] [uri "/.env"] [unique_id "amMKGUQm8Hq8XfXCnuvM5AAAABI"]
[Fri Jul 24 06:45:45.143669 2026] [security2:error] [pid 3668787:tid 3668787] [client 34.180.48.181:60490] [client 34.180.48.181] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [se
...
show less
|
Hacking
Web App Attack
|
|
๐ป๐ณ
152.32.255.94
|
|
[Fri Jul 24 05:39:56.784995 2026] [security2:error] [pid 3668787:tid 3668787] [client 152.32.255.94: ...
show more
[Fri Jul 24 05:39:56.784995 2026] [security2:error] [pid 3668787:tid 3668787] [client 152.32.255.94:47272] [client 152.32.255.94] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [data "94.209.38.171"] [severity "WARNING"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "94.209.38.171"] [uri "/"] [unique_id "amL6rIgCkAURX7jHbZ_CHAAAAAs"]
[Fri Jul 24 05:40:03.020795 2026] [security2:error] [pid 3670031:tid 3670031] [client 152.32.255.94:47278] [client 152.32.255.94] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"
...
show less
|
Hacking
Web App Attack
|
|
๐จ๐ฆ
2607:fea8:21e:d980:d46d:de52:91fd:6ed8
|
|
[Fri Jul 24 05:02:47.000749 2026] [security2:error] [pid 3668787:tid 3668787] [client 2607:fea8:21e: ...
show more
[Fri Jul 24 05:02:47.000749 2026] [security2:error] [pid 3668787:tid 3668787] [client 2607:fea8:21e:d980:d46d:de52:91fd:6ed8:0] [client 2607:fea8:21e:d980:d46d:de52:91fd:6ed8] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "pop-the-slots.com"] [uri "/free-chips/pop-slots"] [unique_id "amLx9ogCkAURX7jHbZ_CFgAAAAs"]
[Fri Jul 24 05:02:48.814218 2026] [security2:error] [pid 3668787:tid 3668787] [client 2607:fea8:21e:d980:d46d:de52:91fd:6ed8:0] [client 2607:fea8:21e:d980:d46d:de52:91fd:6ed8] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-B
...
show less
|
Hacking
Web App Attack
|
|
๐ณ๐ฑ
2001:1c00:3:400:7538:90f3:3469:b458
|
|
[Fri Jul 24 03:52:06.336777 2026] [security2:error] [pid 3654014:tid 3654014] [client 2001:1c00:3:40 ...
show more
[Fri Jul 24 03:52:06.336777 2026] [security2:error] [pid 3654014:tid 3654014] [client 2001:1c00:3:400:7538:90f3:3469:b458:5024] [client 2001:1c00:3:400:7538:90f3:3469:b458] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "fambus.nl"] [uri "/wpad.dat"] [unique_id "amLhZoqughrqLin1JV8-bwAAAAE"]
[Fri Jul 24 04:02:05.946197 2026] [security2:error] [pid 3668787:tid 3668787] [client 2001:1c00:3:400:7538:90f3:3469:b458:5285] [client 2001:1c00:3:400:7538:90f3:3469:b458] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"]
...
show less
|
Hacking
Web App Attack
|
|
๐ณ๐ฑ
88.151.33.203
|
|
[Fri Jul 24 02:54:17.291279 2026] [security2:error] [pid 3668801:tid 3668801] [client 88.151.33.203: ...
show more
[Fri Jul 24 02:54:17.291279 2026] [security2:error] [pid 3668801:tid 3668801] [client 88.151.33.203:45464] [client 88.151.33.203] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [data "94.209.38.171:443"] [severity "WARNING"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "94.209.38.171"] [uri "/hello.world"] [unique_id "amLT2X55f2l3c07BTQZvbQAAAA0"]
[Fri Jul 24 02:54:17.293468 2026] [security2:error] [pid 3668801:tid 3668801] [client 88.151.33.203:45464] [client 88.151.33.203] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION
...
show less
|
Hacking
Web App Attack
|
|
๐ญ๐ฐ
199.45.155.73
|
|
[Fri Jul 24 02:20:46.335662 2026] [security2:error] [pid 3654014:tid 3654014] [client 199.45.155.73: ...
show more
[Fri Jul 24 02:20:46.335662 2026] [security2:error] [pid 3654014:tid 3654014] [client 199.45.155.73:56574] [client 199.45.155.73] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [data "94.209.38.171"] [severity "WARNING"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "94.209.38.171"] [uri "/"] [unique_id "amLL_oqughrqLin1JV8-YgAAAAE"]
[Fri Jul 24 02:20:48.066616 2026] [security2:error] [pid 3651565:tid 3651565] [client 199.45.155.73:40964] [client 199.45.155.73] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"
...
show less
|
Hacking
Web App Attack
|
|
๐บ๐ธ
84.233.212.29
|
|
[Fri Jul 24 01:39:39.734291 2026] [security2:error] [pid 3562799:tid 3562799] [client 84.233.212.29: ...
show more
[Fri Jul 24 01:39:39.734291 2026] [security2:error] [pid 3562799:tid 3562799] [client 84.233.212.29:58447] [client 84.233.212.29] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "fambus.nl"] [uri "/.env"] [unique_id "amLCW9u-3L1dm6jBwLShLgAAAAA"]
[Fri Jul 24 01:39:42.001713 2026] [security2:error] [pid 3562507:tid 3562507] [client 84.233.212.29:59653] [client 84.233.212.29] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severit
...
show less
|
Hacking
Web App Attack
|
|
๐บ๐ธ
66.132.172.128
|
|
[Thu Jul 23 23:55:49.716508 2026] [security2:error] [pid 3521886:tid 3521886] [client 66.132.172.128 ...
show more
[Thu Jul 23 23:55:49.716508 2026] [security2:error] [pid 3521886:tid 3521886] [client 66.132.172.128:8444] [client 66.132.172.128] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [data "94.209.38.171"] [severity "WARNING"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "94.209.38.171"] [uri "/"] [unique_id "amKqBbKM72_oCVFVni6WOAAAAAQ"]
[Thu Jul 23 23:55:55.415200 2026] [security2:error] [pid 3521904:tid 3521904] [client 66.132.172.128:48034] [client 66.132.172.128] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "9203
...
show less
|
Hacking
Web App Attack
|
|
๐ซ๐ท
185.190.142.132
|
|
[Thu Jul 23 23:56:44.786733 2026] [security2:error] [pid 3521907:tid 3521907] [client 185.190.142.13 ...
show more
[Thu Jul 23 23:56:44.786733 2026] [security2:error] [pid 3521907:tid 3521907] [client 185.190.142.132:33348] [client 185.190.142.132] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 25)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "fambus.nl"] [uri "/"] [unique_id "amKqPL48jK-OcCRwfP-JqAAAAAg"]
[Thu Jul 23 23:56:44.830009 2026] [security2:error] [pid 3521907:tid 3521907] [client 185.190.142.132:33348] [client 185.190.142.132] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 25)"] [s
...
show less
|
Hacking
Web App Attack
|
|
๐ณ๐ฑ
2001:1c00:3:400:a04a:1382:5d1c:d4d4
|
|
[Thu Jul 23 23:31:15.222261 2026] [security2:error] [pid 3521906:tid 3521906] [client 2001:1c00:3:40 ...
show more
[Thu Jul 23 23:31:15.222261 2026] [security2:error] [pid 3521906:tid 3521906] [client 2001:1c00:3:400:a04a:1382:5d1c:d4d4:64571] [client 2001:1c00:3:400:a04a:1382:5d1c:d4d4] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "fambus.nl"] [uri "/wpad.dat"] [unique_id "amKkQwf-rsFpKiGgS8kh_AAAAAc"]
[Thu Jul 23 23:41:15.353403 2026] [security2:error] [pid 3521886:tid 3521886] [client 2001:1c00:3:400:a04a:1382:5d1c:d4d4:56915] [client 2001:1c00:3:400:a04a:1382:5d1c:d4d4] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"
...
show less
|
Hacking
Web App Attack
|
|
๐ฐ๐ท
34.64.238.31
|
|
[Thu Jul 23 22:59:26.052982 2026] [security2:error] [pid 3471687:tid 3471687] [client 34.64.238.31:3 ...
show more
[Thu Jul 23 22:59:26.052982 2026] [security2:error] [pid 3471687:tid 3471687] [client 34.64.238.31:33300] [client 34.64.238.31] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "oauth.fambus.nl"] [uri "/rclone.conf"] [unique_id "amKczr9GIHG5IfH8WdbD1wAAAAA"]
[Thu Jul 23 22:59:26.568279 2026] [security2:error] [pid 3471687:tid 3471687] [client 34.64.238.31:33300] [client 34.64.238.31] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"]
...
show less
|
Hacking
Web App Attack
|
|
๐ธ๐ฌ
157.230.36.199
|
|
[Thu Jul 23 21:32:04.573471 2026] [security2:error] [pid 3379534:tid 3379534] [client 157.230.36.199 ...
show more
[Thu Jul 23 21:32:04.573471 2026] [security2:error] [pid 3379534:tid 3379534] [client 157.230.36.199:56572] [client 157.230.36.199] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "fambus.nl"] [uri "/.git/config"] [unique_id "amKIVGFdcvM19mMEZ985fAAAAAU"], referer: http://tipmap.fambus.nl/.git/config
[Thu Jul 23 21:32:04.945371 2026] [security2:error] [pid 3379527:tid 3379527] [client 157.230.36.199:56582] [client 157.230.36.199] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "I
...
show less
|
Hacking
Web App Attack
|
|
๐บ๐ธ
168.144.243.111
|
|
[Thu Jul 23 19:23:06.617609 2026] [security2:error] [pid 3375745:tid 3375745] [client 168.144.243.11 ...
show more
[Thu Jul 23 19:23:06.617609 2026] [security2:error] [pid 3375745:tid 3375745] [client 168.144.243.111:43148] [client 168.144.243.111] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "wildcard.fambus.nl"] [uri "/.git/config"] [unique_id "amJqGvuLlyuKbn48jRhSuAAAAB4"]
[Thu Jul 23 19:23:06.715013 2026] [security2:error] [pid 3375749:tid 3375749] [client 168.144.243.111:43154] [client 168.144.243.111] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (To
...
show less
|
Hacking
Web App Attack
|
|
๐บ๐ธ
45.45.237.7
|
|
[Thu Jul 23 19:19:16.109419 2026] [security2:error] [pid 3311659:tid 3311659] [client 45.45.237.7:0] ...
show more
[Thu Jul 23 19:19:16.109419 2026] [security2:error] [pid 3311659:tid 3311659] [client 45.45.237.7:0] [client 45.45.237.7] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "pop-the-slots.com"] [uri "/.git/HEAD"] [unique_id "amJpNAxhRnjGbUapgvmN5AAAAAI"]
[Thu Jul 23 19:19:16.129044 2026] [security2:error] [pid 3302217:tid 3302217] [client 45.45.237.7:0] [client 45.45.237.7] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "
...
show less
|
Hacking
Web App Attack
|