|
π§πͺ
34.156.22.151
|
|
[Thu Oct 01 16:24:43.283490 2026] [security2:error] [pid 571061:tid 571061] [client 34.156.22.151:60 ...
show more
[Thu Oct 01 16:24:43.283490 2026] [security2:error] [pid 571061:tid 571061] [client 34.156.22.151:60446] [client 34.156.22.151] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "fambus.nl"] [uri "/wp-content/debug.log"] [unique_id "ar6JS5xgLD8sfiVzeLUxVQAAAC0"]
[Thu Oct 01 16:24:43.304063 2026] [security2:error] [pid 571061:tid 571061] [client 34.156.22.151:60446] [client 34.156.22.151] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 1
...
show less
|
Hacking
Web App Attack
|
|
π³π±
2001:1c00:5:b400:10d5:7daf:6fcb:f73d
|
|
[Thu Oct 01 16:10:48.335442 2026] [security2:error] [pid 571044:tid 571044] [client 2001:1c00:5:b400 ...
show more
[Thu Oct 01 16:10:48.335442 2026] [security2:error] [pid 571044:tid 571044] [client 2001:1c00:5:b400:10d5:7daf:6fcb:f73d:53703] [client 2001:1c00:5:b400:10d5:7daf:6fcb:f73d] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "fambus.nl"] [uri "/wpad.dat"] [unique_id "ar6GCPwt_Nlvsu2GS6EgxwAAABs"]
[Thu Oct 01 16:10:48.371817 2026] [security2:error] [pid 571055:tid 571055] [client 2001:1c00:5:b400:10d5:7daf:6fcb:f73d:53704] [client 2001:1c00:5:b400:10d5:7daf:6fcb:f73d] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"
...
show less
|
Hacking
Web App Attack
|
|
π³π±
2001:1c00:5:b400:6812:7146:d991:fa3d
|
|
[Thu Oct 01 16:10:11.373811 2026] [security2:error] [pid 559798:tid 559798] [client 2001:1c00:5:b400 ...
show more
[Thu Oct 01 16:10:11.373811 2026] [security2:error] [pid 559798:tid 559798] [client 2001:1c00:5:b400:6812:7146:d991:fa3d:62335] [client 2001:1c00:5:b400:6812:7146:d991:fa3d] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "fambus.nl"] [uri "/wpad.dat"] [unique_id "ar6F4_RjjLyGpf8qnwj0NwAAAA4"]
[Thu Oct 01 16:10:11.815673 2026] [security2:error] [pid 559801:tid 559801] [client 2001:1c00:5:b400:6812:7146:d991:fa3d:62336] [client 2001:1c00:5:b400:6812:7146:d991:fa3d] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"
...
show less
|
Hacking
Web App Attack
|
|
π³π±
2001:1c00:5:b400:6d27:58cc:1cd6:2e50
|
|
[Thu Oct 01 15:26:52.947622 2026] [security2:error] [pid 500446:tid 500446] [client 2001:1c00:5:b400 ...
show more
[Thu Oct 01 15:26:52.947622 2026] [security2:error] [pid 500446:tid 500446] [client 2001:1c00:5:b400:6d27:58cc:1cd6:2e50:6261] [client 2001:1c00:5:b400:6d27:58cc:1cd6:2e50] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "fambus.nl"] [uri "/wpad.dat"] [unique_id "ar57vLVQoQbikmyKYz853wAAAAo"]
[Thu Oct 01 15:26:52.947769 2026] [security2:error] [pid 500442:tid 500442] [client 2001:1c00:5:b400:6d27:58cc:1cd6:2e50:13838] [client 2001:1c00:5:b400:6d27:58cc:1cd6:2e50] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"]
...
show less
|
Hacking
Web App Attack
|
|
π«π·
2a02:8434:da62:7d01:f49d:4904:5305:f53c
|
|
[Thu Oct 01 15:09:16.503853 2026] [security2:error] [pid 500446:tid 500446] [client 2a02:8434:da62:7 ...
show more
[Thu Oct 01 15:09:16.503853 2026] [security2:error] [pid 500446:tid 500446] [client 2a02:8434:da62:7d01:f49d:4904:5305:f53c:0] [client 2a02:8434:da62:7d01:f49d:4904:5305:f53c] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "pop-the-slots.com"] [uri "/free-chips/pop-slots"] [unique_id "ar53nLVQoQbikmyKYz85JwAAAAo"], referer: https://www.google.com/
[Thu Oct 01 15:09:17.035496 2026] [security2:error] [pid 471697:tid 471697] [client 2a02:8434:da62:7d01:f49d:4904:5305:f53c:0] [client 2a02:8434:da62:7d01:f49d:4904:5305:f53c] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/m
...
show less
|
Hacking
Web App Attack
|
|
πΊπΈ
216.180.246.141
|
|
[Thu Oct 01 14:59:44.765486 2026] [security2:error] [pid 500445:tid 500445] [client 216.180.246.141: ...
show more
[Thu Oct 01 14:59:44.765486 2026] [security2:error] [pid 500445:tid 500445] [client 216.180.246.141:49276] [client 216.180.246.141] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [data "94.209.38.171"] [severity "WARNING"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "94.209.38.171"] [uri "/"] [unique_id "ar51YKlp_c4edHeLZOLQCgAAAAk"]
[Thu Oct 01 14:59:46.188479 2026] [security2:error] [pid 500445:tid 500445] [client 216.180.246.141:49276] [client 216.180.246.141] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920
...
show less
|
Hacking
Web App Attack
|
|
π³π±
45.153.34.43
|
|
[Thu Oct 01 14:32:22.563596 2026] [security2:error] [pid 468161:tid 468161] [client 45.153.34.43:0] ...
show more
[Thu Oct 01 14:32:22.563596 2026] [security2:error] [pid 468161:tid 468161] [client 45.153.34.43:0] [client 45.153.34.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.pop-the-slots.com"] [uri "/.aws/credentials"] [unique_id "ar5u9iKJcK4-LOfAP3gQTAAAAA0"], referer: http://www.pop-the-slots.com/.aws/credentials
[Thu Oct 01 14:32:24.770850 2026] [security2:error] [pid 468161:tid 468161] [client 45.153.34.43:0] [client 45.153.34.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"]
...
show less
|
Hacking
Web App Attack
|
|
π§πͺ
34.78.54.48
|
|
[Thu Oct 01 12:41:18.194771 2026] [security2:error] [pid 417970:tid 417970] [client 34.78.54.48:4622 ...
show more
[Thu Oct 01 12:41:18.194771 2026] [security2:error] [pid 417970:tid 417970] [client 34.78.54.48:46220] [client 34.78.54.48] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 15)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "94-209-38-171.cable.dynamic.v4.ziggo.nl"] [uri "/"] [unique_id "ar5U7miQhZjXLYJCIwyBkgAAAAA"]
[Thu Oct 01 12:41:18.248929 2026] [security2:error] [pid 417981:tid 417981] [client 34.78.54.48:46234] [client 34.78.54.48] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score
...
show less
|
Hacking
Web App Attack
|
|
πΊπΈ
104.131.32.216
|
|
[Thu Oct 01 11:55:25.947473 2026] [security2:error] [pid 227134:tid 227134] [client 104.131.32.216:4 ...
show more
[Thu Oct 01 11:55:25.947473 2026] [security2:error] [pid 227134:tid 227134] [client 104.131.32.216:48544] [client 104.131.32.216] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [data "94.209.38.171"] [severity "WARNING"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "94.209.38.171"] [uri "/"] [unique_id "ar5KLc14zpW8LSfG6SS1qQAAABE"]
[Thu Oct 01 11:55:25.948276 2026] [security2:error] [pid 227134:tid 227134] [client 104.131.32.216:48544] [client 104.131.32.216] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "
...
show less
|
Hacking
Web App Attack
|
|
π³π±
94.154.43.196
|
|
[Thu Oct 01 11:46:03.715398 2026] [security2:error] [pid 264316:tid 264316] [client 94.154.43.196:57 ...
show more
[Thu Oct 01 11:46:03.715398 2026] [security2:error] [pid 264316:tid 264316] [client 94.154.43.196:57060] [client 94.154.43.196] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [data "94.209.38.171:443"] [severity "WARNING"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "94.209.38.171"] [uri "/"] [unique_id "ar5H-6RGKjrPBqWA2ba5RgAAAAk"]
[Thu Oct 01 11:46:03.793157 2026] [security2:error] [pid 312457:tid 312457] [client 94.154.43.196:57076] [client 94.154.43.196] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"
...
show less
|
Hacking
Web App Attack
|
|
π΅π±
45.138.12.51
|
|
[Thu Oct 01 11:07:01.434147 2026] [security2:error] [pid 250178:tid 250178] [client 45.138.12.51:539 ...
show more
[Thu Oct 01 11:07:01.434147 2026] [security2:error] [pid 250178:tid 250178] [client 45.138.12.51:53946] [client 45.138.12.51] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [data "94.209.38.171"] [severity "WARNING"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "94.209.38.171"] [uri "/"] [unique_id "ar4-1XtK40DNMdOdnwOyoQAAAAA"]
[Thu Oct 01 11:07:01.624082 2026] [security2:error] [pid 264316:tid 264316] [client 45.138.12.51:53976] [client 45.138.12.51] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "
...
show less
|
Hacking
Web App Attack
|
|
π΅π±
45.138.12.16
|
|
[Thu Oct 01 10:06:15.251218 2026] [security2:error] [pid 250178:tid 250178] [client 45.138.12.16:437 ...
show more
[Thu Oct 01 10:06:15.251218 2026] [security2:error] [pid 250178:tid 250178] [client 45.138.12.16:43796] [client 45.138.12.16] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "fambus.nl"] [uri "/"] [unique_id "ar4wl3tK40DNMdOdnwOyYQAAAAA"]
[Thu Oct 01 10:10:30.125135 2026] [security2:error] [pid 250178:tid 250178] [client 45.138.12.16:56694] [client 45.138.12.16] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL
...
show less
|
Hacking
Web App Attack
|
|
π³π±
85.11.167.138
|
|
[Thu Oct 01 09:11:03.787312 2026] [security2:error] [pid 254972:tid 254972] [client 85.11.167.138:59 ...
show more
[Thu Oct 01 09:11:03.787312 2026] [security2:error] [pid 254972:tid 254972] [client 85.11.167.138:59602] [client 85.11.167.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "fambus.nl"] [uri "/.aws/credentials"] [unique_id "ar4jp9Brku-ih_-zftKm9QAAAAQ"], referer: http://www.fambus.nl/.aws/credentials
[Thu Oct 01 09:11:48.769966 2026] [security2:error] [pid 250178:tid 250178] [client 85.11.167.138:62505] [client 85.11.167.138] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "In
...
show less
|
Hacking
Web App Attack
|
|
π³π±
34.13.232.159
|
|
[Thu Oct 01 08:50:05.102198 2026] [security2:error] [pid 227134:tid 227134] [client 34.13.232.159:36 ...
show more
[Thu Oct 01 08:50:05.102198 2026] [security2:error] [pid 227134:tid 227134] [client 34.13.232.159:36664] [client 34.13.232.159] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 15)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "fambus.nl"] [uri "/"] [unique_id "ar4evc14zpW8LSfG6SSylAAAABE"]
[Thu Oct 01 08:50:05.195586 2026] [security2:error] [pid 227524:tid 227524] [client 34.13.232.159:36682] [client 34.13.232.159] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 15)"] [severity "CRI
...
show less
|
Hacking
Web App Attack
|
|
π³π±
2001:1c00:5:b400:6d27:58cc:1cd6:2e50
|
|
[Thu Oct 01 06:36:53.281283 2026] [security2:error] [pid 621:tid 621] [client 2001:1c00:5:b400:6d27: ...
show more
[Thu Oct 01 06:36:53.281283 2026] [security2:error] [pid 621:tid 621] [client 2001:1c00:5:b400:6d27:58cc:1cd6:2e50:2170] [client 2001:1c00:5:b400:6d27:58cc:1cd6:2e50] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "fambus.nl"] [uri "/wpad.dat"] [unique_id "ar3_hWM1vYkyQuJQnTBvpwAAAAI"]
[Thu Oct 01 06:36:53.284597 2026] [security2:error] [pid 626:tid 626] [client 2001:1c00:5:b400:6d27:58cc:1cd6:2e50:2435] [client 2001:1c00:5:b400:6d27:58cc:1cd6:2e50] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"]
...
show less
|
Hacking
Web App Attack
|
|
π³π±
2001:1c00:5:b400:ec86:bdee:c770:314b
|
|
[Thu Oct 01 06:14:32.272528 2026] [security2:error] [pid 4097049:tid 4097049] [client 2001:1c00:5:b4 ...
show more
[Thu Oct 01 06:14:32.272528 2026] [security2:error] [pid 4097049:tid 4097049] [client 2001:1c00:5:b400:ec86:bdee:c770:314b:61833] [client 2001:1c00:5:b400:ec86:bdee:c770:314b] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "fambus.nl"] [uri "/wpad.dat"] [unique_id "ar36SOR1WNNhQDilEs7OxgAAACY"]
[Thu Oct 01 06:14:32.434759 2026] [security2:error] [pid 4167381:tid 4167381] [client 2001:1c00:5:b400:ec86:bdee:c770:314b:61835] [client 2001:1c00:5:b400:ec86:bdee:c770:314b] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.c
...
show less
|
Hacking
Web App Attack
|
|
πΊπΈ
66.132.172.128
|
|
[Thu Oct 01 04:47:16.831548 2026] [security2:error] [pid 4097049:tid 4097049] [client 66.132.172.128 ...
show more
[Thu Oct 01 04:47:16.831548 2026] [security2:error] [pid 4097049:tid 4097049] [client 66.132.172.128:41912] [client 66.132.172.128] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [data "94.209.38.171"] [severity "WARNING"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "94.209.38.171"] [uri "/"] [unique_id "ar3l1OR1WNNhQDilEs7NeAAAACY"]
[Thu Oct 01 04:47:21.603108 2026] [security2:error] [pid 4097052:tid 4097052] [client 66.132.172.128:30492] [client 66.132.172.128] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920
...
show less
|
Hacking
Web App Attack
|
|
πΊπΈ
35.222.244.189
|
|
[Thu Oct 01 03:56:51.155774 2026] [security2:error] [pid 4096508:tid 4096508] [client 35.222.244.189 ...
show more
[Thu Oct 01 03:56:51.155774 2026] [security2:error] [pid 4096508:tid 4096508] [client 35.222.244.189:0] [client 35.222.244.189] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "pop-the-slots.com"] [uri "/z9x8c7v6b5-debug-trigger-pop-the-slots.com"] [unique_id "ar3aA1M1Re6P9N7LTcua6gAAAAU"]
[Thu Oct 01 03:56:53.329905 2026] [security2:error] [pid 4096998:tid 4096998] [client 35.222.244.189:0] [client 35.222.244.189] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly
...
show less
|
Hacking
Web App Attack
|
|
πΊπΈ
65.49.1.152
|
|
[Thu Oct 01 03:05:21.350669 2026] [security2:error] [pid 3968881:tid 3968881] [client 65.49.1.152:37 ...
show more
[Thu Oct 01 03:05:21.350669 2026] [security2:error] [pid 3968881:tid 3968881] [client 65.49.1.152:3758] [client 65.49.1.152] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [data "94.209.38.171"] [severity "WARNING"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "94.209.38.171"] [uri "/"] [unique_id "ar3N8XaFMEzZqzLHQU4n6gAAAAM"]
[Thu Oct 01 03:35:12.523615 2026] [security2:error] [pid 3968122:tid 3968122] [client 65.49.1.152:32248] [client 65.49.1.152] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "H
...
show less
|
Hacking
Web App Attack
|
|
π§πͺ
34.53.230.88
|
|
[Thu Oct 01 02:38:22.350016 2026] [security2:error] [pid 3968122:tid 3968122] [client 34.53.230.88:3 ...
show more
[Thu Oct 01 02:38:22.350016 2026] [security2:error] [pid 3968122:tid 3968122] [client 34.53.230.88:38130] [client 34.53.230.88] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [data "94.209.38.171"] [severity "WARNING"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "94.209.38.171"] [uri "/"] [unique_id "ar3HnuA2P9PW6gJP7LIP7wAAAAI"]
[Thu Oct 01 02:38:31.553545 2026] [security2:error] [pid 3976702:tid 3976702] [client 34.53.230.88:4014] [client 34.53.230.88] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [ms
...
show less
|
Hacking
Web App Attack
|
|
πΊπΈ
34.138.26.238
|
|
[Wed Sep 30 23:44:46.975937 2026] [security2:error] [pid 3817465:tid 3817465] [client 34.138.26.238: ...
show more
[Wed Sep 30 23:44:46.975937 2026] [security2:error] [pid 3817465:tid 3817465] [client 34.138.26.238:33486] [client 34.138.26.238] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 15)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "prod.fambus.nl"] [uri "/"] [unique_id "ar2e7oOtjVujGHskIyn4bAAAAAI"]
[Wed Sep 30 23:44:47.227396 2026] [security2:error] [pid 3826384:tid 3826384] [client 34.138.26.238:33510] [client 34.138.26.238] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 15)"] [seve
...
show less
|
Hacking
Web App Attack
|
|
π¨π
170.231.236.98
|
|
[Wed Sep 30 21:56:40.405543 2026] [security2:error] [pid 3812944:tid 3812944] [client 170.231.236.98 ...
show more
[Wed Sep 30 21:56:40.405543 2026] [security2:error] [pid 3812944:tid 3812944] [client 170.231.236.98:27260] [client 170.231.236.98] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [data "94.209.38.171"] [severity "WARNING"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "94.209.38.171"] [uri "/robots.txt"] [unique_id "ar2FmPLV2XOZN1g9TA3KaAAAAFg"]
[Wed Sep 30 21:56:41.538827 2026] [security2:error] [pid 3817465:tid 3817465] [client 170.231.236.98:27272] [client 170.231.236.98] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"
...
show less
|
Hacking
Web App Attack
|
|
π³π±
195.178.110.108
|
|
[Wed Sep 30 21:51:59.038414 2026] [security2:error] [pid 3826387:tid 3826387] [client 195.178.110.10 ...
show more
[Wed Sep 30 21:51:59.038414 2026] [security2:error] [pid 3826387:tid 3826387] [client 195.178.110.108:2598] [client 195.178.110.108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 25)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "ziggo.fambus.nl"] [uri "/"] [unique_id "ar2Ef6pCjg2xdOG7elYwpQAAAA0"]
[Wed Sep 30 21:52:07.509375 2026] [security2:error] [pid 3817528:tid 3817528] [client 195.178.110.108:9796] [client 195.178.110.108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 25)"
...
show less
|
Hacking
Web App Attack
|
|
π³π±
45.148.10.238
|
|
[Wed Sep 30 21:15:38.615561 2026] [security2:error] [pid 3812841:tid 3812841] [client 45.148.10.238: ...
show more
[Wed Sep 30 21:15:38.615561 2026] [security2:error] [pid 3812841:tid 3812841] [client 45.148.10.238:36758] [client 45.148.10.238] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "fambus.nl"] [uri "/.env.bak"] [unique_id "ar17-iRE4rYAsAw45Zt4rwAAAAM"], referer: http://94.209.38.171/.env.bak
[Wed Sep 30 21:15:38.626206 2026] [security2:error] [pid 3812840:tid 3812840] [client 45.148.10.238:36750] [client 45.148.10.238] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anoma
...
show less
|
Hacking
Web App Attack
|
|
π©πͺ
64.226.65.160
|
|
[Wed Sep 30 19:45:12.199534 2026] [security2:error] [pid 3726899:tid 3726899] [client 64.226.65.160: ...
show more
[Wed Sep 30 19:45:12.199534 2026] [security2:error] [pid 3726899:tid 3726899] [client 64.226.65.160:38698] [client 64.226.65.160] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [data "94.209.38.171"] [severity "WARNING"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "94.209.38.171"] [uri "/"] [unique_id "ar1myECQndHHWZ7bTl6aowAAABE"]
[Wed Sep 30 19:45:13.168015 2026] [security2:error] [pid 3726846:tid 3726846] [client 64.226.65.160:38708] [client 64.226.65.160] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"
...
show less
|
Hacking
Web App Attack
|