|
๐ธ๐ฌ
136.110.12.76
|
|
[Thu Sep 17 00:54:35.402398 2026] [security2:error] [pid 585480:tid 585480] [client 136.110.12.76:0] ...
show more
[Thu Sep 17 00:54:35.402398 2026] [security2:error] [pid 585480:tid 585480] [client 136.110.12.76:0] [client 136.110.12.76] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "pop-the-slots.com"] [uri "/server.key"] [unique_id "aqs6S_o_qii4bErY6xnfpAAAAAE"]
[Thu Sep 17 00:54:35.414259 2026] [security2:error] [pid 574892:tid 574892] [client 136.110.12.76:0] [client 136.110.12.76] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [sever
...
show less
|
Hacking
Web App Attack
|
|
๐บ๐ธ
65.49.1.122
|
|
[Thu Sep 17 00:12:17.762749 2026] [security2:error] [pid 561521:tid 561521] [client 65.49.1.122:6234 ...
show more
[Thu Sep 17 00:12:17.762749 2026] [security2:error] [pid 561521:tid 561521] [client 65.49.1.122:62346] [client 65.49.1.122] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [data "94.209.38.171"] [severity "WARNING"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "94.209.38.171"] [uri "/"] [unique_id "aqswYeOJBDmolwP3kibe3wAAAAE"]
[Thu Sep 17 00:27:34.793591 2026] [security2:error] [pid 574892:tid 574892] [client 65.49.1.122:21561] [client 65.49.1.122] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host
...
show less
|
Hacking
Web App Attack
|
|
๐ณ๐ฑ
2001:1c00:5:b400:c57c:3094:3f4b:a773
|
|
[Thu Sep 17 00:41:23.882697 2026] [security2:error] [pid 574892:tid 574892] [client 2001:1c00:5:b400 ...
show more
[Thu Sep 17 00:41:23.882697 2026] [security2:error] [pid 574892:tid 574892] [client 2001:1c00:5:b400:c57c:3094:3f4b:a773:1599] [client 2001:1c00:5:b400:c57c:3094:3f4b:a773] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "fambus.nl"] [uri "/wpad.dat"] [unique_id "aqs3M0OZ2fi0Cg-FITHnRQAAAAk"]
[Thu Sep 17 00:41:23.882741 2026] [security2:error] [pid 563602:tid 563602] [client 2001:1c00:5:b400:c57c:3094:3f4b:a773:1598] [client 2001:1c00:5:b400:c57c:3094:3f4b:a773] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"]
...
show less
|
Hacking
Web App Attack
|
|
๐ฎ๐ฉ
103.46.186.148
|
|
[Wed Sep 16 22:48:39.711731 2026] [security2:error] [pid 422881:tid 422881] [client 103.46.186.148:4 ...
show more
[Wed Sep 16 22:48:39.711731 2026] [security2:error] [pid 422881:tid 422881] [client 103.46.186.148:42164] [client 103.46.186.148] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [data "94.209.38.171:443"] [severity "WARNING"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "94.209.38.171"] [uri "/hello.world"] [unique_id "aqscx5BUVz4cX33T-B5ZkAAAABQ"]
[Wed Sep 16 22:48:39.715992 2026] [security2:error] [pid 422881:tid 422881] [client 103.46.186.148:42164] [client 103.46.186.148] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION
...
show less
|
Hacking
Web App Attack
|
|
๐ฉ๐ช
94.183.174.95
|
|
[Wed Sep 16 22:13:33.517526 2026] [security2:error] [pid 306749:tid 306749] [client 94.183.174.95:41 ...
show more
[Wed Sep 16 22:13:33.517526 2026] [security2:error] [pid 306749:tid 306749] [client 94.183.174.95:41058] [client 94.183.174.95] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [data "94.209.38.171:443"] [severity "WARNING"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "94.209.38.171"] [uri "/"] [unique_id "aqsUjRUW0nGikld5tM_1rAAAAAM"]
[Wed Sep 16 22:13:33.616188 2026] [security2:error] [pid 423546:tid 423546] [client 94.183.174.95:41062] [client 94.183.174.95] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"
...
show less
|
Hacking
Web App Attack
|
|
๐ณ๐ฑ
195.178.110.15
|
|
[Wed Sep 16 21:35:40.800624 2026] [security2:error] [pid 422881:tid 422881] [client 195.178.110.15:6 ...
show more
[Wed Sep 16 21:35:40.800624 2026] [security2:error] [pid 422881:tid 422881] [client 195.178.110.15:61046] [client 195.178.110.15] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "mail.fambus.nl"] [uri "/.env.backup"] [unique_id "aqsLrJBUVz4cX33T-B5YIAAAABQ"]
[Wed Sep 16 21:35:40.812938 2026] [security2:error] [pid 422881:tid 422881] [client 195.178.110.15:61046] [client 195.178.110.15] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score:
...
show less
|
Hacking
Web App Attack
|
|
๐บ๐ธ
66.132.224.230
|
|
[Wed Sep 16 19:48:46.683714 2026] [security2:error] [pid 306749:tid 306749] [client 66.132.224.230:5 ...
show more
[Wed Sep 16 19:48:46.683714 2026] [security2:error] [pid 306749:tid 306749] [client 66.132.224.230:57110] [client 66.132.224.230] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [data "94.209.38.171"] [severity "WARNING"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "94.209.38.171"] [uri "/"] [unique_id "aqrynhUW0nGikld5tM_ydAAAAAM"]
[Wed Sep 16 19:48:54.471054 2026] [security2:error] [pid 306763:tid 306763] [client 66.132.224.230:3524] [client 66.132.224.230] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"]
...
show less
|
Hacking
Web App Attack
|
|
๐ณ๐ฑ
176.65.148.54
|
|
[Wed Sep 16 16:39:21.243683 2026] [security2:error] [pid 248159:tid 248159] [client 176.65.148.54:41 ...
show more
[Wed Sep 16 16:39:21.243683 2026] [security2:error] [pid 248159:tid 248159] [client 176.65.148.54:41584] [client 176.65.148.54] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [data "94.209.38.171"] [severity "WARNING"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "94.209.38.171"] [uri "/"] [unique_id "aqrGOdOfB_d6BVLKM5qgVAAAAAo"]
[Wed Sep 16 16:39:21.244664 2026] [security2:error] [pid 248159:tid 248159] [client 176.65.148.54:41584] [client 176.65.148.54] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"]
...
show less
|
Hacking
Web App Attack
|
|
๐ฉ๐ช
213.209.159.154
|
|
[Wed Sep 16 17:03:06.288739 2026] [security2:error] [pid 256521:tid 256521] [client 213.209.159.154: ...
show more
[Wed Sep 16 17:03:06.288739 2026] [security2:error] [pid 256521:tid 256521] [client 213.209.159.154:21459] [client 213.209.159.154] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [data "94.209.38.171:443"] [severity "WARNING"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "94.209.38.171"] [uri "/"] [unique_id "aqrLylbIrudUn5YOpw9GTgAAAAM"]
[Wed Sep 16 17:03:06.344430 2026] [security2:error] [pid 256521:tid 256521] [client 213.209.159.154:21459] [client 213.209.159.154] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id
...
show less
|
Hacking
Web App Attack
|
|
๐ณ๐ฑ
91.92.241.196
|
|
[Wed Sep 16 14:49:40.542723 2026] [security2:error] [pid 92716:tid 92716] [client 91.92.241.196:1233 ...
show more
[Wed Sep 16 14:49:40.542723 2026] [security2:error] [pid 92716:tid 92716] [client 91.92.241.196:12338] [client 91.92.241.196] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "fambus.nl"] [uri "/.git/HEAD"] [unique_id "aqqshDbrNBILTDrSnQ6roAAAABE"]
[Wed Sep 16 14:49:41.030219 2026] [security2:error] [pid 35593:tid 35593] [client 91.92.241.196:12350] [client 91.92.241.196] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "
...
show less
|
Hacking
Web App Attack
|
|
๐ธ๐ฌ
43.156.233.168
|
|
[Wed Sep 16 15:37:22.922541 2026] [security2:error] [pid 178289:tid 178289] [client 43.156.233.168:3 ...
show more
[Wed Sep 16 15:37:22.922541 2026] [security2:error] [pid 178289:tid 178289] [client 43.156.233.168:37852] [client 43.156.233.168] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [data "94.209.38.171"] [severity "WARNING"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "94.209.38.171"] [uri "/xmlrpc/2/common"] [unique_id "aqq3suRWdGA3kp2qqP_MKwAAAA4"]
[Wed Sep 16 15:37:22.924862 2026] [security2:error] [pid 178298:tid 178298] [client 43.156.233.168:37856] [client 43.156.233.168] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736
...
show less
|
Hacking
Web App Attack
|
|
๐ช๐ธ
34.175.68.128
|
|
[Wed Sep 16 15:35:18.706615 2026] [security2:error] [pid 178288:tid 178288] [client 34.175.68.128:56 ...
show more
[Wed Sep 16 15:35:18.706615 2026] [security2:error] [pid 178288:tid 178288] [client 34.175.68.128:56944] [client 34.175.68.128] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "fambus.nl"] [uri "/"] [unique_id "aqq3NvL8z-DARKuld6avKgAAAAw"]
[Wed Sep 16 15:35:18.822403 2026] [security2:error] [pid 178288:tid 178288] [client 34.175.68.128:56944] [client 34.175.68.128] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITI
...
show less
|
Hacking
Web App Attack
|
|
๐ฉ๐ช
34.32.123.213
|
|
[Wed Sep 16 15:34:54.639653 2026] [security2:error] [pid 178299:tid 178299] [client 34.32.123.213:42 ...
show more
[Wed Sep 16 15:34:54.639653 2026] [security2:error] [pid 178299:tid 178299] [client 34.32.123.213:42210] [client 34.32.123.213] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "mail.fambus.nl"] [uri "/"] [unique_id "aqq3HiAdn6bWXzEDbsn8GwAAABo"]
[Wed Sep 16 15:34:54.669965 2026] [security2:error] [pid 178299:tid 178299] [client 34.32.123.213:42210] [client 34.32.123.213] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "
...
show less
|
Hacking
Web App Attack
|
|
๐ฏ๐ต
35.200.54.92
|
|
[Wed Sep 16 15:17:36.723496 2026] [security2:error] [pid 178289:tid 178289] [client 35.200.54.92:0] ...
show more
[Wed Sep 16 15:17:36.723496 2026] [security2:error] [pid 178289:tid 178289] [client 35.200.54.92:0] [client 35.200.54.92] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.fambus.nl"] [uri "/.git/config"] [unique_id "aqqzEORWdGA3kp2qqP_LawAAAA4"]
[Wed Sep 16 15:17:38.261732 2026] [security2:error] [pid 93391:tid 93391] [client 35.200.54.92:0] [client 35.200.54.92] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRIT
...
show less
|
Hacking
Web App Attack
|
|
๐บ๐ธ
144.172.99.12
|
|
[Wed Sep 16 15:11:46.554030 2026] [security2:error] [pid 178300:tid 178300] [client 144.172.99.12:12 ...
show more
[Wed Sep 16 15:11:46.554030 2026] [security2:error] [pid 178300:tid 178300] [client 144.172.99.12:12500] [client 144.172.99.12] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [data "94.209.38.171"] [severity "WARNING"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "94.209.38.171"] [uri "/.env"] [unique_id "aqqxsoRX28PJ2xl0PG5VggAAABs"]
[Wed Sep 16 15:11:46.554788 2026] [security2:error] [pid 178300:tid 178300] [client 144.172.99.12:12500] [client 144.172.99.12] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "
...
show less
|
Hacking
Web App Attack
|
|
๐ธ๐ฎ
102.220.161.102
|
|
[Wed Sep 16 14:17:59.273622 2026] [security2:error] [pid 35593:tid 35593] [client 102.220.161.102:60 ...
show more
[Wed Sep 16 14:17:59.273622 2026] [security2:error] [pid 35593:tid 35593] [client 102.220.161.102:60316] [client 102.220.161.102] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [data "94.209.38.171"] [severity "WARNING"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "94.209.38.171"] [uri "/.env"] [unique_id "aqqlF6l6iqwQ7KFqppnrGAAAAAo"]
[Wed Sep 16 14:17:59.274605 2026] [security2:error] [pid 35593:tid 35593] [client 102.220.161.102:60316] [client 102.220.161.102] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [li
...
show less
|
Hacking
Web App Attack
|
|
๐ณ๐ฑ
2001:1c00:5:b400:85a:1238:d49f:572b
|
|
[Wed Sep 16 12:58:34.689590 2026] [security2:error] [pid 35593:tid 35593] [client 2001:1c00:5:b400:8 ...
show more
[Wed Sep 16 12:58:34.689590 2026] [security2:error] [pid 35593:tid 35593] [client 2001:1c00:5:b400:85a:1238:d49f:572b:53594] [client 2001:1c00:5:b400:85a:1238:d49f:572b] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "fambus.nl"] [uri "/wpad.dat"] [unique_id "aqqSeql6iqwQ7KFqppnp7wAAAAo"]
[Wed Sep 16 12:58:35.179198 2026] [security2:error] [pid 92716:tid 92716] [client 2001:1c00:5:b400:85a:1238:d49f:572b:57324] [client 2001:1c00:5:b400:85a:1238:d49f:572b] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line
...
show less
|
Hacking
Web App Attack
|
|
๐ง๐ท
43.135.199.250
|
|
[Wed Sep 16 11:30:17.870617 2026] [security2:error] [pid 30192:tid 30192] [client 43.135.199.250:609 ...
show more
[Wed Sep 16 11:30:17.870617 2026] [security2:error] [pid 30192:tid 30192] [client 43.135.199.250:60984] [client 43.135.199.250] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [data "94.209.38.171"] [severity "WARNING"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "94.209.38.171"] [uri "/dns-query"] [unique_id "aqp9yTr_r8I279WEhXod6gAAAAM"]
[Wed Sep 16 11:30:17.872045 2026] [security2:error] [pid 30192:tid 30192] [client 43.135.199.250:60984] [client 43.135.199.250] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [l
...
show less
|
Hacking
Web App Attack
|
|
๐บ๐ธ
161.35.182.166
|
|
[Wed Sep 16 11:19:20.591237 2026] [security2:error] [pid 14414:tid 14414] [client 161.35.182.166:185 ...
show more
[Wed Sep 16 11:19:20.591237 2026] [security2:error] [pid 14414:tid 14414] [client 161.35.182.166:18562] [client 161.35.182.166] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 20)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "mail.fambus.nl"] [uri "/"] [unique_id "aqp7OCsth0V3kwxu25ulugAAAAM"], referer: https://mail.fambus.nl/
[Wed Sep 16 11:19:20.707877 2026] [security2:error] [pid 14414:tid 14414] [client 161.35.182.166:18562] [client 161.35.182.166] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exce
...
show less
|
Hacking
Web App Attack
|
|
๐ธ๐ฎ
102.220.161.87
|
|
[Wed Sep 16 11:17:53.150643 2026] [security2:error] [pid 4176774:tid 4176774] [client 102.220.161.87 ...
show more
[Wed Sep 16 11:17:53.150643 2026] [security2:error] [pid 4176774:tid 4176774] [client 102.220.161.87:40482] [client 102.220.161.87] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "fambus.nl"] [uri "/.env"] [unique_id "aqp64eE76VHhTB7A_jUi6gAAAEg"], referer: http://94.209.38.171/.env
[Wed Sep 16 11:17:53.336739 2026] [security2:error] [pid 18105:tid 18105] [client 102.220.161.87:40486] [client 102.220.161.87] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [
...
show less
|
Hacking
Web App Attack
|
|
๐ฉ๐ช
172.105.64.199
|
|
[Wed Sep 16 10:40:47.251735 2026] [security2:error] [pid 4176759:tid 4176759] [client 172.105.64.199 ...
show more
[Wed Sep 16 10:40:47.251735 2026] [security2:error] [pid 4176759:tid 4176759] [client 172.105.64.199:50886] [client 172.105.64.199] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "fambus.nl"] [uri "/fambus.nl:80.key"] [unique_id "aqpyL0HNummNMVEiUtNywAAAADk"], referer: http://fambus.nl:80/fambus.nl:80.key
[Wed Sep 16 10:40:48.315035 2026] [security2:error] [pid 4176751:tid 4176751] [client 172.105.64.199:50928] [client 172.105.64.199] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [
...
show less
|
Hacking
Web App Attack
|
|
๐ฉ๐ช
94.154.46.244
|
|
[Wed Sep 16 10:24:36.951427 2026] [security2:error] [pid 4173642:tid 4173642] [client 94.154.46.244: ...
show more
[Wed Sep 16 10:24:36.951427 2026] [security2:error] [pid 4173642:tid 4173642] [client 94.154.46.244:37562] [client 94.154.46.244] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [data "94.209.38.171"] [severity "WARNING"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "94.209.38.171"] [uri "/.git/config"] [unique_id "aqpuZKHF0HZKBkZCdib32wAAABI"]
[Wed Sep 16 10:24:36.952436 2026] [security2:error] [pid 4173642:tid 4173642] [client 94.154.46.244:37562] [client 94.154.46.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.con
...
show less
|
Hacking
Web App Attack
|
|
๐ณ๐ฑ
34.32.198.209
|
|
[Wed Sep 16 08:52:03.061502 2026] [security2:error] [pid 4077093:tid 4077093] [client 34.32.198.209: ...
show more
[Wed Sep 16 08:52:03.061502 2026] [security2:error] [pid 4077093:tid 4077093] [client 34.32.198.209:0] [client 34.32.198.209] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "pop-the-slots.com"] [uri "/ads.txt"] [unique_id "aqpYs2bQWdeUx8PdmEix-AAAAAQ"]
[Wed Sep 16 08:52:03.297525 2026] [security2:error] [pid 4077094:tid 4077094] [client 34.32.198.209:0] [client 34.32.198.209] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [seve
...
show less
|
Hacking
Web App Attack
|
|
๐ณ๐ฑ
45.148.10.5
|
|
[Wed Sep 16 08:47:16.342908 2026] [security2:error] [pid 4074933:tid 4074933] [client 45.148.10.5:32 ...
show more
[Wed Sep 16 08:47:16.342908 2026] [security2:error] [pid 4074933:tid 4074933] [client 45.148.10.5:32320] [client 45.148.10.5] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [data "94.209.38.171"] [severity "WARNING"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "94.209.38.171"] [uri "/"] [unique_id "aqpXlKBUyx994vv_rLRdVwAAAAA"]
[Wed Sep 16 08:47:57.261753 2026] [security2:error] [pid 4074932:tid 4074932] [client 45.148.10.5:62402] [client 45.148.10.5] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "
...
show less
|
Hacking
Web App Attack
|
|
๐ณ๐ฑ
2001:1c00:5:b400:2902:1181:fbb8:8492
|
|
[Wed Sep 16 07:50:35.215497 2026] [security2:error] [pid 3834560:tid 3834560] [client 2001:1c00:5:b4 ...
show more
[Wed Sep 16 07:50:35.215497 2026] [security2:error] [pid 3834560:tid 3834560] [client 2001:1c00:5:b400:2902:1181:fbb8:8492:3665] [client 2001:1c00:5:b400:2902:1181:fbb8:8492] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "fambus.nl"] [uri "/wpad.dat"] [unique_id "aqpKS3qldAoftp6Gb9oIjwAAAAw"]
[Wed Sep 16 07:50:35.661317 2026] [security2:error] [pid 4050664:tid 4050664] [client 2001:1c00:5:b400:2902:1181:fbb8:8492:3667] [client 2001:1c00:5:b400:2902:1181:fbb8:8492] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.con
...
show less
|
Hacking
Web App Attack
|