|
๐ณ๐ฑ
196.251.71.69
|
|
196.251.71.69 - - [16/Oct/2025:12:47:23 +0200] "GET /wp-login.php HTTP/1.1" 301 243 "-" "Mozilla/5.0 ...
show more
196.251.71.69 - - [16/Oct/2025:12:47:23 +0200] "GET /wp-login.php HTTP/1.1" 301 243 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.2 Safari/605.1.15"
196.251.71.69 - - [16/Oct/2025:12:47:28 +0200] "GET /wp-login.php HTTP/1.1" 301 255 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.2 Safari/605.1.15"
196.251.71.69 - - [16/Oct/2025:12:47:30 +0200] "GET /wp-login.php HTTP/1.1" 302 219 "https://www.bing.com/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 13_6_1; rv:121.0) Gecko/20100101 Firefox/121.0"
...
show less
|
Web App Attack
|
|
๐ฎ๐น
37.116.138.65
|
|
37.116.138.65 - - [16/Oct/2025:10:07:51 +0200] "POST /xmlrpc.php HTTP/1.1" 301 253 "-" "Mozilla/5.0 ...
show more
37.116.138.65 - - [16/Oct/2025:10:07:51 +0200] "POST /xmlrpc.php HTTP/1.1" 301 253 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Safari/10.0.0.0 Safari/537.36"
37.116.138.65 - - [16/Oct/2025:10:08:00 +0200] "POST /xmlrpc.php HTTP/1.1" 301 241 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; arm64) AppleWebKit/537.36 (KHTML, like Gecko) Safari/15.0.0.0 Safari/537.36"
37.116.138.65 - - [16/Oct/2025:10:08:00 +0200] "GET /xmlrpc.php HTTP/1.1" 301 253 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; arm64) AppleWebKit/537.36 (KHTML, like Gecko) Safari/15.0.0.0 Safari/537.36"
...
show less
|
Web App Attack
|
|
๐จ๐ฆ
134.122.35.177
|
|
[Wed Oct 15 22:37:37.003830 2025] [security2:error] [pid 2436753:tid 2436753] [client 134.122.35.177 ...
show more
[Wed Oct 15 22:37:37.003830 2025] [security2:error] [pid 2436753:tid 2436753] [client 134.122.35.177:60604] [client 134.122.35.177] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.buusbudde.dk"] [uri "/ab2g"] [unique_id "aPAGEYZg5oJRkNwt7WIcywAAAAg"], referer: https://87.104.65.148/ab2g
[Wed Oct 15 22:37:37.926270 2025] [security2:error] [pid 2412762:tid 2412762] [client 134.122.35.177:60628] [client 134.122.35.177] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound An
...
show less
|
Web App Attack
|
|
๐บ๐ธ
162.240.151.141
|
|
[Wed Oct 15 22:01:25.118060 2025] [security2:error] [pid 2436539:tid 2436539] [client 162.240.151.14 ...
show more
[Wed Oct 15 22:01:25.118060 2025] [security2:error] [pid 2436539:tid 2436539] [client 162.240.151.141:59092] [client 162.240.151.141] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "gallery.buusbudde.dk"] [uri "/.aws/credentials"] [unique_id "aO_9lSZMpOgTfWlI2bF_MwAAAAA"]
[Wed Oct 15 22:01:25.162491 2025] [security2:error] [pid 2095711:tid 2095711] [client 162.240.151.141:59106] [client 162.240.151.141] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Excee
...
show less
|
Web App Attack
|
|
๐ฑ๐น
62.60.130.229
|
|
62.60.130.229 - - [15/Oct/2025:20:43:58 +0200] "GET /wp-login.php HTTP/1.1" 301 243 "https://www.red ...
show more
62.60.130.229 - - [15/Oct/2025:20:43:58 +0200] "GET /wp-login.php HTTP/1.1" 301 243 "https://www.reddit.com/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.6261.57 Safari/537.36"
62.60.130.229 - - [15/Oct/2025:20:43:58 +0200] "GET /wp-login.php HTTP/1.1" 301 255 "https://www.reddit.com/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.6261.57 Safari/537.36"
62.60.130.229 - - [15/Oct/2025:20:43:59 +0200] "GET /wp-login.php HTTP/1.1" 302 219 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 12_6_2) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Safari/605.1.15"
...
show less
|
Web App Attack
|
|
๐บ๐ธ
162.240.153.125
|
|
[Wed Oct 15 18:55:41.076506 2025] [security2:error] [pid 1963228:tid 1963228] [client 162.240.153.12 ...
show more
[Wed Oct 15 18:55:41.076506 2025] [security2:error] [pid 1963228:tid 1963228] [client 162.240.153.125:45290] [client 162.240.153.125] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "gallery.buusbudde.dk"] [uri "/Apriso/MessageProcessor/FlexNetMessageProcessor.svc"] [unique_id "aO_SDWeND4P4coXBd_SONwAAAAo"]
[Wed Oct 15 18:55:41.092752 2025] [security2:error] [pid 2034056:tid 2034056] [client 162.240.153.125:45298] [client 162.240.153.125] ModSecurity: Access denied with code 403 (phase 4). Operator GE matched 4 at TX:outbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-959-BLOCKING-EVALUATION.conf"] [line "77"] [
...
show less
|
Web App Attack
|
|
๐ฉ๐ฐ
85.191.52.225
|
|
[Wed Oct 15 15:45:03.958945 2025] [security2:error] [pid 1334946:tid 1334946] [client 85.191.52.225: ...
show more
[Wed Oct 15 15:45:03.958945 2025] [security2:error] [pid 1334946:tid 1334946] [client 85.191.52.225:51051] [client 85.191.52.225] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "sky.buusbudde.dk"] [uri "/remote.php/dav/files/mbudde/InstantUpload/Camera/2025/10/20251015_150900.jpg"] [unique_id "aO-lXu1XUuvXfQ67tEb5bQAAABk"]
[Wed Oct 15 15:45:04.702672 2025] [security2:error] [pid 1334946:tid 1334946] [client 85.191.52.225:51051] [client 85.191.52.225] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"]
...
show less
|
Web App Attack
|
|
๐ฎ๐ถ
45.157.54.27
|
|
45.157.54.27 - - [15/Oct/2025:14:57:27 +0200] "POST /xmlrpc.php HTTP/1.1" 301 253 "-" "Mozilla/5.0 ( ...
show more
45.157.54.27 - - [15/Oct/2025:14:57:27 +0200] "POST /xmlrpc.php HTTP/1.1" 301 253 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36"
45.157.54.27 - - [15/Oct/2025:14:57:27 +0200] "POST /xmlrpc.php HTTP/1.1" 301 253 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36"
45.157.54.27 - - [15/Oct/2025:14:57:28 +0200] "POST /xmlrpc.php HTTP/1.1" 301 241 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36"
...
show less
|
Web App Attack
|
|
๐ฎ๐ช
34.244.107.9
|
|
[Wed Oct 15 02:58:48.832960 2025] [security2:error] [pid 2551686:tid 2551686] [client 34.244.107.9:5 ...
show more
[Wed Oct 15 02:58:48.832960 2025] [security2:error] [pid 2551686:tid 2551686] [client 34.244.107.9:51230] [client 34.244.107.9] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "buusbudde.dk"] [uri "/"] [unique_id "aO7xyCEkY-B1alFR3re7hAAAAAw"]
[Wed Oct 15 02:58:48.838178 2025] [security2:error] [pid 2551685:tid 2551685] [client 34.244.107.9:51229] [client 34.244.107.9] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CR
...
show less
|
Web App Attack
|
|
๐ฉ๐ฟ
154.244.122.61
|
|
154.244.122.61 - - [14/Oct/2025:16:30:21 +0200] "POST /xmlrpc.php HTTP/1.1" 301 253 "-" "Mozilla/5.0 ...
show more
154.244.122.61 - - [14/Oct/2025:16:30:21 +0200] "POST /xmlrpc.php HTTP/1.1" 301 253 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Opera/72.0.0.0 Safari/537.36"
154.244.122.61 - - [14/Oct/2025:16:30:29 +0200] "POST /xmlrpc.php HTTP/1.1" 301 241 "-" "Mozilla/5.0 (Windows NT 6.3; arm64) AppleWebKit/537.36 (KHTML, like Gecko) Edge/99.0.0.0 Safari/537.36"
154.244.122.61 - - [14/Oct/2025:16:30:29 +0200] "GET /xmlrpc.php HTTP/1.1" 301 253 "-" "Mozilla/5.0 (Windows NT 6.3; arm64) AppleWebKit/537.36 (KHTML, like Gecko) Edge/99.0.0.0 Safari/537.36"
...
show less
|
Web App Attack
|
|
๐ต๐ญ
112.201.229.124
|
|
112.201.229.124 - - [14/Oct/2025:16:24:55 +0200] "POST /xmlrpc.php HTTP/1.1" 301 253 "-" "Mozilla/5. ...
show more
112.201.229.124 - - [14/Oct/2025:16:24:55 +0200] "POST /xmlrpc.php HTTP/1.1" 301 253 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; x86) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36"
112.201.229.124 - - [14/Oct/2025:16:25:04 +0200] "POST /xmlrpc.php HTTP/1.1" 301 241 "-" "Mozilla/5.0 (Windows NT 6.3; x86) AppleWebKit/537.36 (KHTML, like Gecko) Edge/90.0.0.0 Safari/537.36"
112.201.229.124 - - [14/Oct/2025:16:25:04 +0200] "GET /xmlrpc.php HTTP/1.1" 301 253 "-" "Mozilla/5.0 (Windows NT 6.3; x86) AppleWebKit/537.36 (KHTML, like Gecko) Edge/90.0.0.0 Safari/537.36"
...
show less
|
Web App Attack
|
|
๐บ๐ธ
172.58.126.235
|
|
172.58.126.235 - - [14/Oct/2025:16:24:51 +0200] "POST /xmlrpc.php HTTP/1.1" 301 253 "-" "Mozilla/5.0 ...
show more
172.58.126.235 - - [14/Oct/2025:16:24:51 +0200] "POST /xmlrpc.php HTTP/1.1" 301 253 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36"
172.58.126.235 - - [14/Oct/2025:16:24:56 +0200] "POST /xmlrpc.php HTTP/1.1" 301 241 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36"
172.58.126.235 - - [14/Oct/2025:16:24:56 +0200] "GET /xmlrpc.php HTTP/1.1" 301 253 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36"
...
show less
|
Web App Attack
|
|
๐บ๐ธ
50.41.11.157
|
|
50.41.11.157 - - [14/Oct/2025:16:24:05 +0200] "POST /xmlrpc.php HTTP/1.1" 301 253 "-" "Mozilla/5.0 ( ...
show more
50.41.11.157 - - [14/Oct/2025:16:24:05 +0200] "POST /xmlrpc.php HTTP/1.1" 301 253 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36"
50.41.11.157 - - [14/Oct/2025:16:24:09 +0200] "POST /xmlrpc.php HTTP/1.1" 301 241 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36"
50.41.11.157 - - [14/Oct/2025:16:24:09 +0200] "GET /xmlrpc.php HTTP/1.1" 301 253 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36"
...
show less
|
Web App Attack
|
|
๐ซ๐ท
92.184.119.218
|
|
92.184.119.218 - - [14/Oct/2025:16:22:35 +0200] "POST /xmlrpc.php HTTP/1.1" 301 253 "-" "Mozilla/5.0 ...
show more
92.184.119.218 - - [14/Oct/2025:16:22:35 +0200] "POST /xmlrpc.php HTTP/1.1" 301 253 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36"
92.184.119.218 - - [14/Oct/2025:16:22:37 +0200] "POST /xmlrpc.php HTTP/1.1" 301 241 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36"
92.184.119.218 - - [14/Oct/2025:16:22:37 +0200] "GET /xmlrpc.php HTTP/1.1" 301 253 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36"
...
show less
|
Web App Attack
|
|
๐ฎ๐ถ
45.157.54.27
|
|
45.157.54.27 - - [14/Oct/2025:13:07:28 +0200] "POST /xmlrpc.php HTTP/1.1" 301 253 "-" "Mozilla/5.0 ( ...
show more
45.157.54.27 - - [14/Oct/2025:13:07:28 +0200] "POST /xmlrpc.php HTTP/1.1" 301 253 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36"
45.157.54.27 - - [14/Oct/2025:13:07:28 +0200] "POST /xmlrpc.php HTTP/1.1" 301 253 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36"
45.157.54.27 - - [14/Oct/2025:13:07:28 +0200] "POST /xmlrpc.php HTTP/1.1" 301 241 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36"
...
show less
|
Web App Attack
|
|
๐ฑ๐น
141.98.11.188
|
|
141.98.11.188 - - [14/Oct/2025:11:02:12 +0200] "GET /wp-login.php HTTP/1.1" 301 243 "https://t.co/" ...
show more
141.98.11.188 - - [14/Oct/2025:11:02:12 +0200] "GET /wp-login.php HTTP/1.1" 301 243 "https://t.co/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 13_6_1) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15"
141.98.11.188 - - [14/Oct/2025:11:02:12 +0200] "GET /wp-login.php HTTP/1.1" 301 255 "https://t.co/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 13_6_1) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15"
141.98.11.188 - - [14/Oct/2025:11:02:14 +0200] "GET /wp-login.php HTTP/1.1" 302 219 "https://www.google.com/search?q=wordpress" "Mozilla/5.0 (Windows NT 11.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/118.0.0.0 Safari/537.36"
...
show less
|
Web App Attack
|
|
๐ณ๐ฑ
45.148.10.249
|
|
[Tue Oct 14 08:46:40.456856 2025] [security2:error] [pid 3183044:tid 3183044] [client 45.148.10.249: ...
show more
[Tue Oct 14 08:46:40.456856 2025] [security2:error] [pid 3183044:tid 3183044] [client 45.148.10.249:37514] [client 45.148.10.249] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.buusbudde.dk"] [uri "/.git/config"] [unique_id "aO3x0KcDwphhsaxFdJHC1AAAAAE"]
[Tue Oct 14 08:46:40.632740 2025] [security2:error] [pid 3187358:tid 3187358] [client 45.148.10.249:37518] [client 45.148.10.249] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score:
...
show less
|
Web App Attack
|
|
๐ธ๐ฌ
159.89.198.71
|
|
[Tue Oct 14 06:50:15.013639 2025] [security2:error] [pid 2271062:tid 2271062] [client 159.89.198.71: ...
show more
[Tue Oct 14 06:50:15.013639 2025] [security2:error] [pid 2271062:tid 2271062] [client 159.89.198.71:35514] [client 159.89.198.71] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "buusbudde.dk"] [uri "/laravel/.env"] [unique_id "aO3Wh4xMgIHriBsrNBemSwAAAAU"]
[Tue Oct 14 06:50:15.013896 2025] [security2:error] [pid 2297202:tid 2297202] [client 159.89.198.71:35478] [client 159.89.198.71] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)
...
show less
|
Web App Attack
|
|
๐บ๐ฆ
62.60.130.228
|
|
62.60.130.228 - - [14/Oct/2025:04:25:31 +0200] "GET /wp-login.php HTTP/1.1" 301 243 "https://twitter ...
show more
62.60.130.228 - - [14/Oct/2025:04:25:31 +0200] "GET /wp-login.php HTTP/1.1" 301 243 "https://twitter.com/" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:119.0.1) Gecko/20100101 Firefox/119.0.1"
62.60.130.228 - - [14/Oct/2025:04:25:31 +0200] "GET /wp-login.php HTTP/1.1" 301 255 "https://twitter.com/" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:119.0.1) Gecko/20100101 Firefox/119.0.1"
62.60.130.228 - - [14/Oct/2025:04:25:32 +0200] "GET /wp-login.php HTTP/1.1" 302 219 "https://www.google.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36 Edg/120.0.2210.133"
...
show less
|
Web App Attack
|
|
๐ง๐ท
187.61.135.245
|
|
187.61.135.245 - - [14/Oct/2025:00:37:14 +0200] "POST /xmlrpc.php HTTP/1.1" 301 253 "-" "Mozilla/5.0 ...
show more
187.61.135.245 - - [14/Oct/2025:00:37:14 +0200] "POST /xmlrpc.php HTTP/1.1" 301 253 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; x86) AppleWebKit/537.36 (KHTML, like Gecko) Edge/86.0.0.0 Safari/537.36"
187.61.135.245 - - [14/Oct/2025:00:37:26 +0200] "POST /xmlrpc.php HTTP/1.1" 301 241 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7; x86) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36"
187.61.135.245 - - [14/Oct/2025:00:37:28 +0200] "GET /xmlrpc.php HTTP/1.1" 301 253 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7; x86) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36"
...
show less
|
Web App Attack
|
|
๐ง๐ท
177.92.49.56
|
|
177.92.49.56 - - [14/Oct/2025:00:34:07 +0200] "POST /xmlrpc.php HTTP/1.1" 301 253 "-" "Mozilla/5.0 ( ...
show more
177.92.49.56 - - [14/Oct/2025:00:34:07 +0200] "POST /xmlrpc.php HTTP/1.1" 301 253 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; x86) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/101.0.0.0 Safari/537.36"
177.92.49.56 - - [14/Oct/2025:00:34:15 +0200] "POST /xmlrpc.php HTTP/1.1" 301 241 "-" "Mozilla/5.0 (Windows NT 6.2; arm64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.0.0 Safari/537.36"
177.92.49.56 - - [14/Oct/2025:00:34:16 +0200] "GET /xmlrpc.php HTTP/1.1" 301 253 "-" "Mozilla/5.0 (Windows NT 6.2; arm64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.0.0 Safari/537.36"
...
show less
|
Web App Attack
|
|
๐ซ๐ท
90.70.97.160
|
|
90.70.97.160 - - [14/Oct/2025:00:33:58 +0200] "POST /xmlrpc.php HTTP/1.1" 301 253 "-" "Mozilla/5.0 ( ...
show more
90.70.97.160 - - [14/Oct/2025:00:33:58 +0200] "POST /xmlrpc.php HTTP/1.1" 301 253 "-" "Mozilla/5.0 (Windows NT 10.0; arm64) AppleWebKit/537.36 (KHTML, like Gecko) Edge/97.0.0.0 Safari/537.36"
90.70.97.160 - - [14/Oct/2025:00:34:02 +0200] "POST /xmlrpc.php HTTP/1.1" 301 241 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7; x86) AppleWebKit/537.36 (KHTML, like Gecko) Safari/11.0.0.0 Safari/537.36"
90.70.97.160 - - [14/Oct/2025:00:34:02 +0200] "GET /xmlrpc.php HTTP/1.1" 301 253 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7; x86) AppleWebKit/537.36 (KHTML, like Gecko) Safari/11.0.0.0 Safari/537.36"
...
show less
|
Web App Attack
|
|
๐ฎ๐ช
34.244.107.9
|
|
[Mon Oct 13 02:52:33.152141 2025] [security2:error] [pid 581027:tid 581027] [client 34.244.107.9:615 ...
show more
[Mon Oct 13 02:52:33.152141 2025] [security2:error] [pid 581027:tid 581027] [client 34.244.107.9:61524] [client 34.244.107.9] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 7)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "buusbudde.dk"] [uri "/sdk"] [unique_id "aOxNUft-9P3GsQwYC-aaVwAAAAM"]
[Mon Oct 13 02:52:33.155447 2025] [security2:error] [pid 932523:tid 932523] [client 34.244.107.9:61523] [client 34.244.107.9] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRI
...
show less
|
Web App Attack
|
|
๐บ๐ธ
174.138.56.49
|
|
[Sun Oct 12 21:03:38.790295 2025] [security2:error] [pid 3777177:tid 3777177] [client 174.138.56.49: ...
show more
[Sun Oct 12 21:03:38.790295 2025] [security2:error] [pid 3777177:tid 3777177] [client 174.138.56.49:36636] [client 174.138.56.49] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.buusbudde.dk"] [uri "/ab2g"] [unique_id "aOv7ihIGVR22Dsuaa5Ec9QAAAAc"], referer: https://87.104.65.148/ab2g
[Sun Oct 12 21:03:39.592574 2025] [security2:error] [pid 3861919:tid 3861919] [client 174.138.56.49:36658] [client 174.138.56.49] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomal
...
show less
|
Web App Attack
|
|
๐ฐ๐ท
222.107.159.49
|
|
[Sun Oct 12 04:06:44.224244 2025] [authz_core:error] [pid 641878:tid 641878] [client 222.107.159.49: ...
show more
[Sun Oct 12 04:06:44.224244 2025] [authz_core:error] [pid 641878:tid 641878] [client 222.107.159.49:63246] AH01630: client denied by server configuration: /home/www/buusbudde.dk/mimer/wordpress, referer: http://mimer.buusbudde.dk/wordpress
[Sun Oct 12 04:10:31.654154 2025] [authz_core:error] [pid 549201:tid 549201] [client 222.107.159.49:65475] AH01630: client denied by server configuration: /home/www/buusbudde.dk/mimer/Wordpress, referer: http://mimer.buusbudde.dk/Wordpress
[Sun Oct 12 04:13:11.681197 2025] [authz_core:error] [pid 558097:tid 558097] [client 222.107.159.49:65223] AH01630: client denied by server configuration: /home/www/buusbudde.dk/mimer/WORDPRESS, referer: http://mimer.buusbudde.dk/WORDPRESS
...
show less
|
Hacking
|