๐ต๐ฑ
194.180.49.173
18 Dec 2025
[Thu Dec 18 01:50:12.734300 2025] [authz_core:error] [pid 746:tid 746] [client 194.180.49.173:5666] ...
show more
[Thu Dec 18 01:50:12.734300 2025] [authz_core:error] [pid 746:tid 746] [client 194.180.49.173:5666] AH01630: client denied by server configuration: proxy:http://10.74.0.1:10082/
[Thu Dec 18 01:50:12.926575 2025] [authz_core:error] [pid 783:tid 783] [client 194.180.49.173:5676] AH01630: client denied by server configuration: proxy:http://10.74.0.1:10082/.git/config
[Thu Dec 18 01:50:13.041986 2025] [authz_core:error] [pid 792:tid 792] [client 194.180.49.173:5686] AH01630: client denied by server configuration: proxy:http://10.74.0.1:10082/.env
...
show less
Hacking
๐ฎ๐ณ
202.78.236.11
17 Dec 2025
202.78.236.11 - - [17/Dec/2025:19:53:23 +0100] "POST /xmlrpc.php HTTP/1.1" 301 3226 "-" "Mozilla/5.0 ...
show more
202.78.236.11 - - [17/Dec/2025:19:53:23 +0100] "POST /xmlrpc.php HTTP/1.1" 301 3226 "-" "Mozilla/5.0 (Windows NT 6.3; arm64) AppleWebKit/537.36 (KHTML, like Gecko) Firefox/91.0.0.0 Safari/537.36"
202.78.236.11 - - [17/Dec/2025:19:53:31 +0100] "POST /xmlrpc.php HTTP/1.1" 301 3227 "-" "Mozilla/5.0 (Linux; Android 10; arm64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.0.0 Safari/537.36"
202.78.236.11 - - [17/Dec/2025:19:53:32 +0100] "GET /xmlrpc.php HTTP/1.1" 301 3226 "-" "Mozilla/5.0 (Linux; Android 10; arm64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐ฎ๐ช
34.242.82.125
17 Dec 2025
[Wed Dec 17 08:22:48.429827 2025] [authz_core:error] [pid 288:tid 288] [client 34.242.82.125:59344] ...
show more
[Wed Dec 17 08:22:48.429827 2025] [authz_core:error] [pid 288:tid 288] [client 34.242.82.125:59344] AH01630: client denied by server configuration: proxy:http://10.74.0.1:10082/
[Wed Dec 17 08:22:48.461929 2025] [authz_core:error] [pid 288:tid 288] [client 34.242.82.125:59344] AH01630: client denied by server configuration: proxy:http://10.74.0.1:10082/apps
[Wed Dec 17 08:22:48.493634 2025] [authz_core:error] [pid 288:tid 288] [client 34.242.82.125:59344] AH01630: client denied by server configuration: proxy:http://10.74.0.1:10082/api/action
...
show less
Hacking
๐บ๐ธ
13.221.250.214
17 Dec 2025
[Wed Dec 17 06:25:25.725232 2025] [authz_core:error] [pid 381:tid 381] [client 13.221.250.214:33236] ...
show more
[Wed Dec 17 06:25:25.725232 2025] [authz_core:error] [pid 381:tid 381] [client 13.221.250.214:33236] AH01630: client denied by server configuration: proxy:http://10.74.0.1:10082/
[Wed Dec 17 06:25:25.828992 2025] [authz_core:error] [pid 381:tid 381] [client 13.221.250.214:33236] AH01630: client denied by server configuration: proxy:http://10.74.0.1:10082/apps
[Wed Dec 17 06:25:25.931097 2025] [authz_core:error] [pid 381:tid 381] [client 13.221.250.214:33236] AH01630: client denied by server configuration: proxy:http://10.74.0.1:10082/api/action
...
show less
Hacking
๐ธ๐ช
16.170.167.174
17 Dec 2025
[Wed Dec 17 01:45:24.274263 2025] [authz_core:error] [pid 14:tid 14] [client 16.170.167.174:38642] A ...
show more
[Wed Dec 17 01:45:24.274263 2025] [authz_core:error] [pid 14:tid 14] [client 16.170.167.174:38642] AH01630: client denied by server configuration: proxy:http://10.74.0.1:10082/
[Wed Dec 17 01:45:24.291195 2025] [authz_core:error] [pid 14:tid 14] [client 16.170.167.174:38642] AH01630: client denied by server configuration: proxy:http://10.74.0.1:10082/apps
[Wed Dec 17 01:45:24.307243 2025] [authz_core:error] [pid 14:tid 14] [client 16.170.167.174:38642] AH01630: client denied by server configuration: proxy:http://10.74.0.1:10082/api/action
...
show less
Hacking
๐ง๐ท
177.192.15.38
16 Dec 2025
177.192.15.38 - - [16/Dec/2025:19:42:53 +0100] "POST /xmlrpc.php HTTP/1.1" 301 2986 "-" "Mozilla/5.0 ...
show more
177.192.15.38 - - [16/Dec/2025:19:42:53 +0100] "POST /xmlrpc.php HTTP/1.1" 301 2986 "-" "Mozilla/5.0 (Windows NT 6.3; x64) AppleWebKit/537.36 (KHTML, like Gecko) Edge/81.0.0.0 Safari/537.36"
177.192.15.38 - - [16/Dec/2025:19:42:58 +0100] "POST /xmlrpc.php HTTP/1.1" 301 2956 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7; x64) AppleWebKit/537.36 (KHTML, like Gecko) Opera/66.0.0.0 Safari/537.36"
177.192.15.38 - - [16/Dec/2025:19:42:58 +0100] "GET /xmlrpc.php HTTP/1.1" 301 644 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7; x64) AppleWebKit/537.36 (KHTML, like Gecko) Opera/66.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐ต๐ญ
110.54.167.156
14 Dec 2025
110.54.167.156 - - [15/Dec/2025:00:31:50 +0100] "POST /xmlrpc.php HTTP/1.1" 301 3216 "-" "Mozilla/5. ...
show more
110.54.167.156 - - [15/Dec/2025:00:31:50 +0100] "POST /xmlrpc.php HTTP/1.1" 301 3216 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7; x86) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/82.0.0.0 Safari/537.36"
110.54.167.156 - - [15/Dec/2025:00:31:55 +0100] "POST /xmlrpc.php HTTP/1.1" 301 3189 "-" "Mozilla/5.0 (Windows NT 6.2; x64) AppleWebKit/537.36 (KHTML, like Gecko) Opera/76.0.0.0 Safari/537.36"
110.54.167.156 - - [15/Dec/2025:00:31:55 +0100] "GET /xmlrpc.php HTTP/1.1" 301 637 "-" "Mozilla/5.0 (Windows NT 6.2; x64) AppleWebKit/537.36 (KHTML, like Gecko) Opera/76.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐บ๐ธ
3.230.155.201
14 Dec 2025
[Sun Dec 14 23:07:58.410052 2025] [authz_core:error] [pid 415:tid 415] [client 3.230.155.201:35143] ...
show more
[Sun Dec 14 23:07:58.410052 2025] [authz_core:error] [pid 415:tid 415] [client 3.230.155.201:35143] AH01630: client denied by server configuration: proxy:http://10.74.0.1:10082/
[Sun Dec 14 23:07:58.530418 2025] [authz_core:error] [pid 415:tid 415] [client 3.230.155.201:35143] AH01630: client denied by server configuration: proxy:http://10.74.0.1:10082/favicon.ico
[Sun Dec 14 23:07:58.650018 2025] [authz_core:error] [pid 415:tid 415] [client 3.230.155.201:35143] AH01630: client denied by server configuration: proxy:http://10.74.0.1:10082/favicon.png
...
show less
Hacking
๐ธ๐ฌ
103.244.113.66
24 Nov 2025
2025-11-24T13:17:38.985979+01:00 mimer sshd[1389948]: Connection from 103.244.113.66 port 64913 on 1 ...
show more
2025-11-24T13:17:38.985979+01:00 mimer sshd[1389948]: Connection from 103.244.113.66 port 64913 on 192.168.2.4 port 29120 rdomain ""
2025-11-24T13:17:38.986662+01:00 mimer sshd[1389948]: banner exchange: Connection from 103.244.113.66 port 64913: invalid format
...
show less
SSH
๐น๐ท
185.17.139.52
24 Nov 2025
2025-11-24T13:09:17.724589+01:00 mimer sshd[1362715]: Connection from 185.17.139.52 port 28680 on 19 ...
show more
2025-11-24T13:09:17.724589+01:00 mimer sshd[1362715]: Connection from 185.17.139.52 port 28680 on 192.168.2.4 port 29120 rdomain ""
2025-11-24T13:09:17.724992+01:00 mimer sshd[1362715]: banner exchange: Connection from 185.17.139.52 port 28680: invalid format
...
show less
SSH
๐ต๐ฑ
153.92.19.153
23 Nov 2025
2025-11-23T17:09:59.615518+01:00 mimer sshd[1634408]: Connection from 153.92.19.153 port 28396 on 19 ...
show more
2025-11-23T17:09:59.615518+01:00 mimer sshd[1634408]: Connection from 153.92.19.153 port 28396 on 192.168.2.4 port 29120 rdomain ""
2025-11-23T17:09:59.615892+01:00 mimer sshd[1634408]: banner exchange: Connection from 153.92.19.153 port 28396: invalid format
...
show less
SSH
๐ณ๐ฑ
88.210.63.3
04 Nov 2025
2025-11-04T18:45:44.184563+01:00 mimer sshd[3425369]: Connection from 88.210.63.3 port 65388 on 192. ...
show more
2025-11-04T18:45:44.184563+01:00 mimer sshd[3425369]: Connection from 88.210.63.3 port 65388 on 192.168.2.4 port 29120 rdomain ""
2025-11-04T18:45:44.185049+01:00 mimer sshd[3425369]: banner exchange: Connection from 88.210.63.3 port 65388: invalid format
...
show less
SSH
๐ง๐ฌ
79.124.59.78
04 Nov 2025
2025-11-04T02:57:53.534791+01:00 mimer sshd[373054]: Connection from 79.124.59.78 port 61000 on 192. ...
show more
2025-11-04T02:57:53.534791+01:00 mimer sshd[373054]: Connection from 79.124.59.78 port 61000 on 192.168.2.4 port 29120 rdomain ""
2025-11-04T02:57:53.575590+01:00 mimer sshd[373054]: error: kex_exchange_identification: Connection closed by remote host
...
show less
SSH
๐จ๐ฆ
64.15.129.106
18 Oct 2025
[Sat Oct 18 14:00:44.037295 2025] [security2:error] [pid 2528294:tid 2528294] [client 64.15.129.106: ...
show more
[Sat Oct 18 14:00:44.037295 2025] [security2:error] [pid 2528294:tid 2528294] [client 64.15.129.106:38014] [client 64.15.129.106] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "buusbudde.dk"] [uri "/"] [unique_id "aPOBbH8wKBpSP4--6iqX7QAAACE"]
[Sat Oct 18 14:01:46.679333 2025] [security2:error] [pid 2536514:tid 2536514] [client 64.15.129.106:22506] [client 64.15.129.106] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 15)"] [severit
...
show less
Web App Attack
๐จ๐ฆ
64.15.129.104
18 Oct 2025
[Sat Oct 18 14:00:45.950472 2025] [security2:error] [pid 2528292:tid 2528292] [client 64.15.129.104: ...
show more
[Sat Oct 18 14:00:45.950472 2025] [security2:error] [pid 2528292:tid 2528292] [client 64.15.129.104:33330] [client 64.15.129.104] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "buusbudde.dk"] [uri "/"] [unique_id "aPOBbVBvi664qxlGZyCWYQAAACA"]
[Sat Oct 18 14:01:46.617920 2025] [security2:error] [pid 2535591:tid 2535591] [client 64.15.129.104:60124] [client 64.15.129.104] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 15)"] [severit
...
show less
Web App Attack
๐จ๐ฆ
192.175.111.232
18 Oct 2025
[Sat Oct 18 14:01:01.197987 2025] [security2:error] [pid 2535591:tid 2535591] [client 192.175.111.23 ...
show more
[Sat Oct 18 14:01:01.197987 2025] [security2:error] [pid 2535591:tid 2535591] [client 192.175.111.232:30532] [client 192.175.111.232] ModSecurity: Access denied with code 403 (phase 4). Operator GE matched 4 at TX:outbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-959-BLOCKING-EVALUATION.conf"] [line "77"] [id "959100"] [msg "Outbound Anomaly Score Exceeded (Total Score: 4)"] [ver "OWASP_CRS/3.3.4"] [tag "anomaly-evaluation"] [hostname "buusbudde.dk"] [uri "/images/layout/"] [unique_id "aPOBfVDykhzYMwxu5j983wAAAAc"]
[Sat Oct 18 14:01:01.889877 2025] [security2:error] [pid 2527897:tid 2527897] [client 192.175.111.232:25224] [client 192.175.111.232] ModSecurity: Access denied with code 403 (phase 4). Operator GE matched 4 at TX:outbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-959-BLOCKING-EVALUATION.conf"] [line "77"] [id "959100"] [msg "Outbound Anomaly Score Exceeded (Total Score: 4)"] [ver "OWASP_CRS/3.3.4"] [tag "anomaly-evaluation"] [hos
...
show less
Web App Attack
๐บ๐ฆ
185.5.253.146
18 Oct 2025
185.5.253.146 - - [18/Oct/2025:11:32:10 +0200] "POST /xmlrpc.php HTTP/1.1" 301 253 "-" "Mozilla/5.0 ...
show more
185.5.253.146 - - [18/Oct/2025:11:32:10 +0200] "POST /xmlrpc.php HTTP/1.1" 301 253 "-" "Mozilla/5.0 (Windows NT 6.2; x64) AppleWebKit/537.36 (KHTML, like Gecko) Edge/100.0.0.0 Safari/537.36"
185.5.253.146 - - [18/Oct/2025:11:32:11 +0200] "POST /xmlrpc.php HTTP/1.1" 301 241 "-" "Mozilla/5.0 (Windows NT 10.0; arm64) AppleWebKit/537.36 (KHTML, like Gecko) Edge/89.0.0.0 Safari/537.36"
185.5.253.146 - - [18/Oct/2025:11:32:11 +0200] "GET /xmlrpc.php HTTP/1.1" 301 253 "-" "Mozilla/5.0 (Windows NT 10.0; arm64) AppleWebKit/537.36 (KHTML, like Gecko) Edge/89.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐ฑ๐น
62.60.130.228
18 Oct 2025
62.60.130.228 - - [18/Oct/2025:07:55:17 +0200] "GET /wp-login.php HTTP/1.1" 301 243 "-" "Mozilla/5.0 ...
show more
62.60.130.228 - - [18/Oct/2025:07:55:17 +0200] "GET /wp-login.php HTTP/1.1" 301 243 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.6045.159 Safari/537.36"
62.60.130.228 - - [18/Oct/2025:07:55:17 +0200] "GET /wp-login.php HTTP/1.1" 301 255 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.6045.159 Safari/537.36"
62.60.130.228 - - [18/Oct/2025:07:55:18 +0200] "GET /wp-login.php HTTP/1.1" 302 219 "https://wordpress.org/" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:120.0.1) Gecko/20100101 Firefox/120.0.1"
...
show less
Web App Attack
๐บ๐ธ
138.68.29.230
18 Oct 2025
[Sat Oct 18 06:58:20.238965 2025] [security2:error] [pid 863681:tid 863681] [client 138.68.29.230:48 ...
show more
[Sat Oct 18 06:58:20.238965 2025] [security2:error] [pid 863681:tid 863681] [client 138.68.29.230:48178] [client 138.68.29.230] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.buusbudde.dk"] [uri "/ab2g"] [unique_id "aPMebM1OdEOpFUW2CsO7cAAAAA8"], referer: https://87.104.65.148/ab2g
[Sat Oct 18 06:58:21.557410 2025] [security2:error] [pid 1110921:tid 1110921] [client 138.68.29.230:48182] [client 138.68.29.230] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly
...
show less
Web App Attack
๐ฎ๐ช
34.243.187.106
18 Oct 2025
[Sat Oct 18 03:07:50.557174 2025] [security2:error] [pid 3998865:tid 3998865] [client 34.243.187.106 ...
show more
[Sat Oct 18 03:07:50.557174 2025] [security2:error] [pid 3998865:tid 3998865] [client 34.243.187.106:42518] [client 34.243.187.106] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 7)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "buusbudde.dk"] [uri "/sdk"] [unique_id "aPLoZlTyCC_8CjGAcUnknAAAAAY"]
[Sat Oct 18 03:07:50.566152 2025] [security2:error] [pid 142042:tid 142042] [client 34.243.187.106:42526] [client 34.243.187.106] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [sev
...
show less
Web App Attack
๐ฎ๐ช
34.244.107.9
18 Oct 2025
[Sat Oct 18 02:07:51.281892 2025] [security2:error] [pid 4040670:tid 4040670] [client 34.244.107.9:5 ...
show more
[Sat Oct 18 02:07:51.281892 2025] [security2:error] [pid 4040670:tid 4040670] [client 34.244.107.9:50821] [client 34.244.107.9] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "buusbudde.dk"] [uri "/"] [unique_id "aPLaV2NeQdkVqI80yBxHywAAAAk"]
[Sat Oct 18 02:07:51.281892 2025] [security2:error] [pid 4090131:tid 4090131] [client 34.244.107.9:50823] [client 34.244.107.9] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CR
...
show less
Web App Attack
๐ฑ๐น
141.98.11.189
17 Oct 2025
141.98.11.189 - - [18/Oct/2025:01:24:49 +0200] "GET /wp-login.php HTTP/1.1" 301 243 "https://wordpre ...
show more
141.98.11.189 - - [18/Oct/2025:01:24:49 +0200] "GET /wp-login.php HTTP/1.1" 301 243 "https://wordpress.org/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Safari/605.1.15"
141.98.11.189 - - [18/Oct/2025:01:24:50 +0200] "GET /wp-login.php HTTP/1.1" 301 255 "https://wordpress.org/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Safari/605.1.15"
141.98.11.189 - - [18/Oct/2025:01:24:51 +0200] "GET /wp-login.php HTTP/1.1" 302 219 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐ฉ๐ช
193.174.89.19
17 Oct 2025
[Fri Oct 17 12:12:38.442843 2025] [security2:error] [pid 1316823:tid 1316823] [client 193.174.89.19: ...
show more
[Fri Oct 17 12:12:38.442843 2025] [security2:error] [pid 1316823:tid 1316823] [client 193.174.89.19:31080] [client 193.174.89.19] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "buusbudde.dk"] [uri "/fhir-server/api/v4/metadata"] [unique_id "aPIWlr8Dewy5RAQFl_EZtAAAAAA"]
[Fri Oct 17 12:12:38.444311 2025] [security2:error] [pid 1316823:tid 1316823] [client 193.174.89.19:31080] [client 193.174.89.19] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (
...
show less
Web App Attack
๐ณ๐ฑ
45.148.10.143
17 Oct 2025
[Fri Oct 17 11:44:23.339030 2025] [security2:error] [pid 1209042:tid 1209042] [client 45.148.10.143: ...
show more
[Fri Oct 17 11:44:23.339030 2025] [security2:error] [pid 1209042:tid 1209042] [client 45.148.10.143:57188] [client 45.148.10.143] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "buusbudde.dk"] [uri "/.env"] [unique_id "aPIP90DqSZR7L8pn6KVOagAAAAg"]
[Fri Oct 17 11:44:51.603326 2025] [security2:error] [pid 1212329:tid 1212329] [client 45.148.10.143:40550] [client 45.148.10.143] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [seve
...
show less
Web App Attack
๐ท๐บ
109.196.67.14
16 Oct 2025
[Thu Oct 16 14:14:16.126402 2025] [authz_core:error] [pid 875908:tid 875908] [client 109.196.67.14:3 ...
show more
[Thu Oct 16 14:14:16.126402 2025] [authz_core:error] [pid 875908:tid 875908] [client 109.196.67.14:3874] AH01630: client denied by server configuration: proxy:http://192.168.2.4:10082/phpinfo.php
[Thu Oct 16 14:14:16.233255 2025] [authz_core:error] [pid 892947:tid 892947] [client 109.196.67.14:2880] AH01630: client denied by server configuration: proxy:http://192.168.2.4:10082/i.php
[Thu Oct 16 14:14:16.278596 2025] [authz_core:error] [pid 894747:tid 894747] [client 109.196.67.14:3113] AH01630: client denied by server configuration: proxy:http://192.168.2.4:10082/p.php
...
show less
Hacking