|
π³π±
2001:1c00:5:b400:98da:34b6:5a3e:aecc
|
|
[Sun Aug 16 14:24:19.117506 2026] [security2:error] [pid 269326:tid 269326] [client 2001:1c00:5:b400 ...
show more
[Sun Aug 16 14:24:19.117506 2026] [security2:error] [pid 269326:tid 269326] [client 2001:1c00:5:b400:98da:34b6:5a3e:aecc:2505] [client 2001:1c00:5:b400:98da:34b6:5a3e:aecc] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "fambus.nl"] [uri "/wpad.dat"] [unique_id "aoHIExvmiKcfy_VRXAm31gAAAAI"]
[Sun Aug 16 14:24:19.126767 2026] [security2:error] [pid 268603:tid 268603] [client 2001:1c00:5:b400:98da:34b6:5a3e:aecc:2508] [client 2001:1c00:5:b400:98da:34b6:5a3e:aecc] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"]
...
show less
|
Hacking
Web App Attack
|
|
πΈπ¬
34.21.245.188
|
|
[Sun Aug 16 14:46:12.064218 2026] [security2:error] [pid 269326:tid 269326] [client 34.21.245.188:48 ...
show more
[Sun Aug 16 14:46:12.064218 2026] [security2:error] [pid 269326:tid 269326] [client 34.21.245.188:48980] [client 34.21.245.188] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "fambus.nl"] [uri "/.git/HEAD"] [unique_id "aoHNNBvmiKcfy_VRXAm33QAAAAI"]
[Sun Aug 16 14:46:12.262069 2026] [security2:error] [pid 269326:tid 269326] [client 34.21.245.188:48980] [client 34.21.245.188] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severi
...
show less
|
Hacking
Web App Attack
|
|
π³π±
45.142.193.167
|
|
[Sun Aug 16 14:08:15.669813 2026] [security2:error] [pid 268601:tid 268601] [client 45.142.193.167:2 ...
show more
[Sun Aug 16 14:08:15.669813 2026] [security2:error] [pid 268601:tid 268601] [client 45.142.193.167:27476] [client 45.142.193.167] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [data "94.209.38.171"] [severity "WARNING"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "94.209.38.171"] [uri "/+CSCOE+/logon.html"] [unique_id "aoHET8fvb4CMY-3n6tUVTwAAAAA"]
[Sun Aug 16 14:08:15.688858 2026] [security2:error] [pid 268601:tid 268601] [client 45.142.193.167:27476] [client 45.142.193.167] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "
...
show less
|
Hacking
Web App Attack
|
|
πΊπΈ
207.90.244.14
|
|
[Sun Aug 16 11:39:25.654526 2026] [security2:error] [pid 152901:tid 152901] [client 207.90.244.14:53 ...
show more
[Sun Aug 16 11:39:25.654526 2026] [security2:error] [pid 152901:tid 152901] [client 207.90.244.14:53354] [client 207.90.244.14] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [data "94.209.38.171"] [severity "WARNING"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "94.209.38.171"] [uri "/"] [unique_id "aoGhbd_rNOCifxe1PYaxZQAAAAk"]
[Sun Aug 16 11:39:48.427307 2026] [security2:error] [pid 128514:tid 128514] [client 207.90.244.14:35530] [client 207.90.244.14] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [m
...
show less
|
Hacking
Web App Attack
|
|
π©πͺ
130.12.180.77
|
|
[Sun Aug 16 06:51:33.401623 2026] [security2:error] [pid 4012943:tid 4012943] [client 130.12.180.77: ...
show more
[Sun Aug 16 06:51:33.401623 2026] [security2:error] [pid 4012943:tid 4012943] [client 130.12.180.77:56164] [client 130.12.180.77] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [data "94.209.38.171:443"] [severity "WARNING"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "94.209.38.171"] [uri "/.env"] [unique_id "aoFd9RBdLCmC9TwU09_F5AAAAAQ"]
[Sun Aug 16 06:51:33.402108 2026] [security2:error] [pid 4012943:tid 4012943] [client 130.12.180.77:56164] [client 130.12.180.77] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"]
...
show less
|
Hacking
Web App Attack
|
|
πΊπΈ
192.155.89.211
|
|
[Sun Aug 16 06:24:16.140659 2026] [security2:error] [pid 4017028:tid 4017028] [client 192.155.89.211 ...
show more
[Sun Aug 16 06:24:16.140659 2026] [security2:error] [pid 4017028:tid 4017028] [client 192.155.89.211:53070] [client 192.155.89.211] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 20)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "fambus.nl"] [uri "/+CSCOT+/oem-customization"] [unique_id "aoFXkAumjjUg2xurBujafQAAAAE"]
[Sun Aug 16 06:24:25.588770 2026] [security2:error] [pid 4012944:tid 4012944] [client 192.155.89.211:47162] [client 192.155.89.211] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (
...
show less
|
Hacking
Web App Attack
|
|
π³π±
2001:1c00:3:400:98da:34b6:5a3e:aecc
|
|
[Sun Aug 16 03:14:31.372129 2026] [security2:error] [pid 3866395:tid 3866395] [client 2001:1c00:3:40 ...
show more
[Sun Aug 16 03:14:31.372129 2026] [security2:error] [pid 3866395:tid 3866395] [client 2001:1c00:3:400:98da:34b6:5a3e:aecc:7143] [client 2001:1c00:3:400:98da:34b6:5a3e:aecc] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "fambus.nl"] [uri "/wpad.dat"] [unique_id "aoErF7Jowoj2v3Arkk3SVwAAAAA"]
[Sun Aug 16 03:14:31.372341 2026] [security2:error] [pid 3867516:tid 3867516] [client 2001:1c00:3:400:98da:34b6:5a3e:aecc:7144] [client 2001:1c00:3:400:98da:34b6:5a3e:aecc] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"]
...
show less
|
Hacking
Web App Attack
|
|
ππ°
123.58.212.238
|
|
[Sun Aug 16 01:29:18.549125 2026] [security2:error] [pid 3768684:tid 3768684] [client 123.58.212.238 ...
show more
[Sun Aug 16 01:29:18.549125 2026] [security2:error] [pid 3768684:tid 3768684] [client 123.58.212.238:31278] [client 123.58.212.238] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [data "94.209.38.171:443"] [severity "WARNING"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "94.209.38.171"] [uri "/"] [unique_id "aoESbhWBvLBOYMHOGBGyhwAAAAc"]
[Sun Aug 16 01:29:28.090671 2026] [security2:error] [pid 3768809:tid 3768809] [client 123.58.212.238:40428] [client 123.58.212.238] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id
...
show less
|
Hacking
Web App Attack
|
|
πΊπΈ
64.62.156.192
|
|
[Sun Aug 16 00:11:44.029773 2026] [security2:error] [pid 3768808:tid 3768808] [client 64.62.156.192: ...
show more
[Sun Aug 16 00:11:44.029773 2026] [security2:error] [pid 3768808:tid 3768808] [client 64.62.156.192:49600] [client 64.62.156.192] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [data "94.209.38.171"] [severity "WARNING"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "94.209.38.171"] [uri "/"] [unique_id "aoEAQN58hRw6gMUQPYVqgQAAABk"]
[Sun Aug 16 00:27:16.538401 2026] [security2:error] [pid 3768811:tid 3768811] [client 64.62.156.192:21911] [client 64.62.156.192] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"
...
show less
|
Hacking
Web App Attack
|
|
π¬π§
18.168.150.165
|
|
[Sun Aug 16 00:22:43.524586 2026] [security2:error] [pid 3768812:tid 3768812] [client 18.168.150.165 ...
show more
[Sun Aug 16 00:22:43.524586 2026] [security2:error] [pid 3768812:tid 3768812] [client 18.168.150.165:58090] [client 18.168.150.165] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "fambus.nl"] [uri "/"] [unique_id "aoEC09FgU9erTtt2VZcb-gAAAB0"]
[Sun Aug 16 00:22:43.548222 2026] [security2:error] [pid 3768812:tid 3768812] [client 18.168.150.165:58090] [client 18.168.150.165] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severit
...
show less
|
Hacking
Web App Attack
|
|
π³π±
93.123.109.228
|
|
[Sat Aug 15 23:42:46.830053 2026] [security2:error] [pid 3633286:tid 3633286] [client 93.123.109.228 ...
show more
[Sat Aug 15 23:42:46.830053 2026] [security2:error] [pid 3633286:tid 3633286] [client 93.123.109.228:41640] [client 93.123.109.228] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [data "94.209.38.171"] [severity "WARNING"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "94.209.38.171"] [uri "/"] [unique_id "aoD5ds39BysMjvmEZ0EtOAAAAA4"]
[Sat Aug 15 23:42:46.891413 2026] [security2:error] [pid 3633287:tid 3633287] [client 93.123.109.228:41646] [client 93.123.109.228] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920
...
show less
|
Hacking
Web App Attack
|
|
πΊπΈ
165.154.163.39
|
|
[Sat Aug 15 22:58:04.730391 2026] [security2:error] [pid 3642346:tid 3642346] [client 165.154.163.39 ...
show more
[Sat Aug 15 22:58:04.730391 2026] [security2:error] [pid 3642346:tid 3642346] [client 165.154.163.39:51774] [client 165.154.163.39] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [data "94.209.38.171"] [severity "WARNING"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "94.209.38.171"] [uri "/"] [unique_id "aoDu_PxLg4BdcnDJEaesNAAAAAE"]
[Sat Aug 15 22:58:04.730916 2026] [security2:error] [pid 3642346:tid 3642346] [client 165.154.163.39:51774] [client 165.154.163.39] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [li
...
show less
|
Hacking
Web App Attack
|
|
π¦πΊ
34.40.183.157
|
|
[Sat Aug 15 22:26:11.400789 2026] [security2:error] [pid 3690967:tid 3690967] [client 34.40.183.157: ...
show more
[Sat Aug 15 22:26:11.400789 2026] [security2:error] [pid 3690967:tid 3690967] [client 34.40.183.157:50532] [client 34.40.183.157] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "staff.fambus.nl"] [uri "/.git/config"] [unique_id "aoDng5KgmHdDiHRVaF7C-QAAAAs"]
[Sat Aug 15 22:26:11.681844 2026] [security2:error] [pid 3690967:tid 3690967] [client 34.40.183.157:50532] [client 34.40.183.157] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score:
...
show less
|
Hacking
Web App Attack
|
|
π³π±
2001:1c00:3:400:98da:34b6:5a3e:aecc
|
|
[Sat Aug 15 21:12:59.859459 2026] [security2:error] [pid 3633351:tid 3633351] [client 2001:1c00:3:40 ...
show more
[Sat Aug 15 21:12:59.859459 2026] [security2:error] [pid 3633351:tid 3633351] [client 2001:1c00:3:400:98da:34b6:5a3e:aecc:5931] [client 2001:1c00:3:400:98da:34b6:5a3e:aecc] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "fambus.nl"] [uri "/wpad.dat"] [unique_id "aoDWW86WuqKrJbOgPp2cOAAAABU"]
[Sat Aug 15 21:12:59.861433 2026] [security2:error] [pid 3633286:tid 3633286] [client 2001:1c00:3:400:98da:34b6:5a3e:aecc:5930] [client 2001:1c00:3:400:98da:34b6:5a3e:aecc] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"]
...
show less
|
Hacking
Web App Attack
|
|
πΈπͺ
81.226.129.67
|
|
[Sat Aug 15 16:24:54.801602 2026] [security2:error] [pid 3420908:tid 3420908] [client 81.226.129.67: ...
show more
[Sat Aug 15 16:24:54.801602 2026] [security2:error] [pid 3420908:tid 3420908] [client 81.226.129.67:43970] [client 81.226.129.67] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [data "94.209.38.171:443"] [severity "WARNING"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "94.209.38.171"] [uri "/hello.world"] [unique_id "aoCS1pdIeL1qz5HwJVQ_swAAAAU"]
[Sat Aug 15 16:24:54.806773 2026] [security2:error] [pid 3420908:tid 3420908] [client 81.226.129.67:43970] [client 81.226.129.67] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION
...
show less
|
Hacking
Web App Attack
|
|
π³π±
80.82.77.139
|
|
[Sat Aug 15 15:16:36.734019 2026] [security2:error] [pid 3410749:tid 3410749] [client 80.82.77.139:4 ...
show more
[Sat Aug 15 15:16:36.734019 2026] [security2:error] [pid 3410749:tid 3410749] [client 80.82.77.139:42144] [client 80.82.77.139] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [data "94.209.38.171"] [severity "WARNING"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "94.209.38.171"] [uri "/"] [unique_id "aoCC1LfZpIKFSuXks3lsmwAAAAc"]
[Sat Aug 15 15:16:42.044594 2026] [security2:error] [pid 3413724:tid 3413724] [client 80.82.77.139:45120] [client 80.82.77.139] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [m
...
show less
|
Hacking
Web App Attack
|
|
π³π±
91.92.40.175
|
|
[Sat Aug 15 15:11:33.994846 2026] [security2:error] [pid 3410744:tid 3410744] [client 91.92.40.175:4 ...
show more
[Sat Aug 15 15:11:33.994846 2026] [security2:error] [pid 3410744:tid 3410744] [client 91.92.40.175:47968] [client 91.92.40.175] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [data "94.209.38.171"] [severity "WARNING"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "94.209.38.171"] [uri "/.env"] [unique_id "aoCBpfOGNMu5uyMtrLarSQAAAAA"]
[Sat Aug 15 15:11:33.995886 2026] [security2:error] [pid 3410744:tid 3410744] [client 91.92.40.175:47968] [client 91.92.40.175] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "
...
show less
|
Hacking
Web App Attack
|
|
πΊπΈ
66.132.195.122
|
|
[Sat Aug 15 12:27:07.066879 2026] [security2:error] [pid 3278134:tid 3278134] [client 66.132.195.122 ...
show more
[Sat Aug 15 12:27:07.066879 2026] [security2:error] [pid 3278134:tid 3278134] [client 66.132.195.122:57592] [client 66.132.195.122] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [data "94.209.38.171"] [severity "WARNING"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "94.209.38.171"] [uri "/"] [unique_id "aoBbGxssVQwjPohw3OvGKwAAAAM"]
[Sat Aug 15 12:27:12.805124 2026] [security2:error] [pid 3124532:tid 3124532] [client 66.132.195.122:3584] [client 66.132.195.122] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "9203
...
show less
|
Hacking
Web App Attack
|
|
πΊπΈ
65.49.1.152
|
|
[Sat Aug 15 11:21:32.970429 2026] [security2:error] [pid 3121129:tid 3121129] [client 65.49.1.152:31 ...
show more
[Sat Aug 15 11:21:32.970429 2026] [security2:error] [pid 3121129:tid 3121129] [client 65.49.1.152:31058] [client 65.49.1.152] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [data "94.209.38.171"] [severity "WARNING"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "94.209.38.171"] [uri "/"] [unique_id "aoBLvBg4KS2cOEtF-2juqwAAABA"]
[Sat Aug 15 11:44:58.623393 2026] [security2:error] [pid 3265999:tid 3265999] [client 65.49.1.152:11682] [client 65.49.1.152] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "
...
show less
|
Hacking
Web App Attack
|
|
π§πͺ
34.79.242.244
|
|
[Sat Aug 15 10:39:49.567512 2026] [security2:error] [pid 3150735:tid 3150735] [client 34.79.242.244: ...
show more
[Sat Aug 15 10:39:49.567512 2026] [security2:error] [pid 3150735:tid 3150735] [client 34.79.242.244:0] [client 34.79.242.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "pop-the-slots.com"] [uri "/ads.txt"] [unique_id "aoBB9Re4GlwCTXAtA0uhDwAAAAE"]
[Sat Aug 15 10:39:49.639559 2026] [security2:error] [pid 3150735:tid 3150735] [client 34.79.242.244:0] [client 34.79.242.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [se
...
show less
|
Hacking
Web App Attack
|
|
π³π±
195.178.110.199
|
|
[Sat Aug 15 07:52:59.789087 2026] [security2:error] [pid 3069519:tid 3069519] [client 195.178.110.19 ...
show more
[Sat Aug 15 07:52:59.789087 2026] [security2:error] [pid 3069519:tid 3069519] [client 195.178.110.199:34828] [client 195.178.110.199] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "fambus.nl"] [uri "/.aws/credentials"] [unique_id "aoAa2x9ODSH-JxYCJNb07QAAACI"]
[Sat Aug 15 07:52:59.814843 2026] [security2:error] [pid 3069519:tid 3069519] [client 195.178.110.199:34828] [client 195.178.110.199] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total
...
show less
|
Hacking
Web App Attack
|
|
πΊπΈ
34.169.242.187
|
|
[Sat Aug 15 07:47:15.684146 2026] [security2:error] [pid 3069506:tid 3069506] [client 34.169.242.187 ...
show more
[Sat Aug 15 07:47:15.684146 2026] [security2:error] [pid 3069506:tid 3069506] [client 34.169.242.187:0] [client 34.169.242.187] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.pop-the-slots.com"] [uri "/.aws/credentials"] [unique_id "aoAZgw0Zn6tzhqE-I6oxsgAAABY"]
[Sat Aug 15 07:47:16.267112 2026] [security2:error] [pid 3069510:tid 3069510] [client 34.169.242.187:0] [client 34.169.242.187] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total
...
show less
|
Hacking
Web App Attack
|
|
πΊπΈ
34.16.249.132
|
|
[Sat Aug 15 06:29:28.986309 2026] [security2:error] [pid 2846147:tid 2846147] [client 34.16.249.132: ...
show more
[Sat Aug 15 06:29:28.986309 2026] [security2:error] [pid 2846147:tid 2846147] [client 34.16.249.132:47964] [client 34.16.249.132] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "fambus.nl"] [uri "/@fs/.env"] [unique_id "aoAHSDnqZaVu6JPp4bR46AAAAAQ"]
[Sat Aug 15 06:29:29.027009 2026] [security2:error] [pid 2846190:tid 2846190] [client 34.16.249.132:47980] [client 34.16.249.132] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [sev
...
show less
|
Hacking
Web App Attack
|
|
π³π±
2001:1c00:3:400:79c8:111b:6381:9c81
|
|
[Sat Aug 15 03:36:21.464459 2026] [security2:error] [pid 2801814:tid 2801814] [client 2001:1c00:3:40 ...
show more
[Sat Aug 15 03:36:21.464459 2026] [security2:error] [pid 2801814:tid 2801814] [client 2001:1c00:3:400:79c8:111b:6381:9c81:3129] [client 2001:1c00:3:400:79c8:111b:6381:9c81] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "fambus.nl"] [uri "/wpad.dat"] [unique_id "an_etRoDdv9IvqBL4ehB8QAAAAE"]
[Sat Aug 15 03:36:24.017571 2026] [security2:error] [pid 2799582:tid 2799582] [client 2001:1c00:3:400:79c8:111b:6381:9c81:3131] [client 2001:1c00:3:400:79c8:111b:6381:9c81] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"]
...
show less
|
Hacking
Web App Attack
|
|
πΊπΈ
35.255.125.217
|
|
[Sat Aug 15 03:20:13.735172 2026] [security2:error] [pid 2668835:tid 2668835] [client 35.255.125.217 ...
show more
[Sat Aug 15 03:20:13.735172 2026] [security2:error] [pid 2668835:tid 2668835] [client 35.255.125.217:0] [client 35.255.125.217] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.pop-the-slots.com"] [uri "/.aws/credentials"] [unique_id "an_a7U6BSvgTf_uKdRAM7QAAABM"]
[Sat Aug 15 03:20:13.735173 2026] [security2:error] [pid 2666475:tid 2666475] [client 35.255.125.217:0] [client 35.255.125.217] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total
...
show less
|
Hacking
Web App Attack
|