๐ฎ๐ช
34.244.107.9
11 Oct 2025
[Sun Oct 12 01:56:49.897288 2025] [security2:error] [pid 4131567:tid 4131567] [client 34.244.107.9:5 ...
show more
[Sun Oct 12 01:56:49.897288 2025] [security2:error] [pid 4131567:tid 4131567] [client 34.244.107.9:57238] [client 34.244.107.9] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "buusbudde.dk"] [uri "/"] [unique_id "aOruwdCcSbbfwd_ysM_sgwAAAAc"]
[Sun Oct 12 01:56:49.903617 2025] [security2:error] [pid 4096604:tid 4096604] [client 34.244.107.9:57237] [client 34.244.107.9] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CR
...
show less
Web App Attack
๐จ๐ฆ
64.15.129.100
11 Oct 2025
[Sat Oct 11 12:01:05.509784 2025] [php:error] [pid 1842775:tid 1842775] [client 64.15.129.100:63241] ...
show more
[Sat Oct 11 12:01:05.509784 2025] [php:error] [pid 1842775:tid 1842775] [client 64.15.129.100:63241] script '/home/www/buusbudde.dk/public_html/stylesheet.php' not found or unable to stat
[Sat Oct 11 12:02:32.789204 2025] [php:error] [pid 1687319:tid 1687319] [client 64.15.129.100:53508] script '/home/www/buusbudde.dk/public_html/css.php' not found or unable to stat
...
show less
Web App Attack
๐จ๐ฆ
64.15.129.119
11 Oct 2025
[Sat Oct 11 12:01:35.054371 2025] [security2:error] [pid 1842742:tid 1842742] [client 64.15.129.119: ...
show more
[Sat Oct 11 12:01:35.054371 2025] [security2:error] [pid 1842742:tid 1842742] [client 64.15.129.119:8494] [client 64.15.129.119] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "buusbudde.dk"] [uri "/"] [unique_id "aOoq_4wBJehL8vQMH7DTLAAAAAM"], referer: https://buusbudde.dk/?checkwaf=%27%22%5C%3E%3Cscript%3Ealert%28%27XSS%27%29%3C%2Fscript%3E
[Sat Oct 11 12:01:35.418337 2025] [security2:error] [pid 1842776:tid 1842776] [client 64.15.129.119:15681] [client 64.15.129.119] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATI
...
show less
Web App Attack
๐จ๐ฆ
64.15.129.118
11 Oct 2025
[Sat Oct 11 12:01:35.056210 2025] [security2:error] [pid 1842776:tid 1842776] [client 64.15.129.118: ...
show more
[Sat Oct 11 12:01:35.056210 2025] [security2:error] [pid 1842776:tid 1842776] [client 64.15.129.118:6738] [client 64.15.129.118] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 15)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "buusbudde.dk"] [uri "/"] [unique_id "aOoq_x-l9CRuYuzorDUCvgAAAA0"]
[Sat Oct 11 12:01:35.416399 2025] [security2:error] [pid 1843647:tid 1843647] [client 64.15.129.118:55099] [client 64.15.129.118] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 15)"] [severit
...
show less
Web App Attack
๐จ๐ฆ
64.15.129.109
11 Oct 2025
[Sat Oct 11 12:01:28.082616 2025] [security2:error] [pid 1687319:tid 1687319] [client 64.15.129.109: ...
show more
[Sat Oct 11 12:01:28.082616 2025] [security2:error] [pid 1687319:tid 1687319] [client 64.15.129.109:55698] [client 64.15.129.109] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "buusbudde.dk"] [uri "/phpbb/composer.json"] [unique_id "aOoq-BONU66gx9Y5bKfRlQAAAAY"]
[Sat Oct 11 12:01:35.412026 2025] [security2:error] [pid 1836211:tid 1836211] [client 64.15.129.109:49490] [client 64.15.129.109] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Sc
...
show less
Web App Attack
๐จ๐ฆ
192.175.111.241
11 Oct 2025
[Sat Oct 11 12:00:37.666977 2025] [security2:error] [pid 1836208:tid 1836208] [client 192.175.111.24 ...
show more
[Sat Oct 11 12:00:37.666977 2025] [security2:error] [pid 1836208:tid 1836208] [client 192.175.111.241:62466] [client 192.175.111.241] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "buusbudde.dk"] [uri "/"] [unique_id "aOoqxfTgq040zvvMlyLjGwAAAAA"]
[Sat Oct 11 12:01:23.077215 2025] [security2:error] [pid 1843647:tid 1843647] [client 192.175.111.241:24282] [client 192.175.111.241] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [
...
show less
Web App Attack
๐ฉ๐ช
139.59.133.50
10 Oct 2025
[Sat Oct 11 01:09:40.234560 2025] [security2:error] [pid 3550807:tid 3550807] [client 139.59.133.50: ...
show more
[Sat Oct 11 01:09:40.234560 2025] [security2:error] [pid 3550807:tid 3550807] [client 139.59.133.50:42154] [client 139.59.133.50] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.buusbudde.dk"] [uri "/ab2g"] [unique_id "aOmSNHgW2TClXHHT-M6R4gAAAAA"], referer: https://87.104.65.148/ab2g
[Sat Oct 11 01:09:40.432383 2025] [security2:error] [pid 3550812:tid 3550812] [client 139.59.133.50:50906] [client 139.59.133.50] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomal
...
show less
Web App Attack
๐ฎ๐ฉ
180.252.134.148
10 Oct 2025
[Fri Oct 10 22:10:04.899519 2025] [security2:error] [pid 2864652:tid 2864652] [client 180.252.134.14 ...
show more
[Fri Oct 10 22:10:04.899519 2025] [security2:error] [pid 2864652:tid 2864652] [client 180.252.134.148:63433] [client 180.252.134.148] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "buusbudde.dk"] [uri "/.git/"] [unique_id "aOloHE1kRyazX10pKobW6gAAABE"]
[Fri Oct 10 22:10:05.852145 2025] [security2:error] [pid 3165372:tid 3165372] [client 180.252.134.148:63122] [client 180.252.134.148] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5
...
show less
Web App Attack
๐ง๐ท
45.166.154.126
10 Oct 2025
45.166.154.126 - - [10/Oct/2025:18:06:23 +0200] "POST /xmlrpc.php HTTP/1.1" 301 253 "-" "Mozilla/5.0 ...
show more
45.166.154.126 - - [10/Oct/2025:18:06:23 +0200] "POST /xmlrpc.php HTTP/1.1" 301 253 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36"
45.166.154.126 - - [10/Oct/2025:18:06:36 +0200] "POST /xmlrpc.php HTTP/1.1" 301 241 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36"
45.166.154.126 - - [10/Oct/2025:18:06:38 +0200] "GET /xmlrpc.php HTTP/1.1" 301 253 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36"
...
show less
Web App Attack
๐ฎ๐ณ
122.175.19.198
10 Oct 2025
122.175.19.198 - - [10/Oct/2025:18:01:19 +0200] "POST /xmlrpc.php HTTP/1.1" 301 253 "-" "Mozilla/5.0 ...
show more
122.175.19.198 - - [10/Oct/2025:18:01:19 +0200] "POST /xmlrpc.php HTTP/1.1" 301 253 "-" "Mozilla/5.0 (Windows NT 10.0; x64) AppleWebKit/537.36 (KHTML, like Gecko) Safari/12.0.0.0 Safari/537.36"
122.175.19.198 - - [10/Oct/2025:18:01:27 +0200] "POST /xmlrpc.php HTTP/1.1" 301 241 "-" "Mozilla/5.0 (Windows NT 10.0; x86) AppleWebKit/537.36 (KHTML, like Gecko) Firefox/89.0.0.0 Safari/537.36"
122.175.19.198 - - [10/Oct/2025:18:01:27 +0200] "GET /xmlrpc.php HTTP/1.1" 301 253 "-" "Mozilla/5.0 (Windows NT 10.0; x86) AppleWebKit/537.36 (KHTML, like Gecko) Firefox/89.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐ณ๐ฑ
45.148.10.115
10 Oct 2025
[Fri Oct 10 09:53:10.636015 2025] [php:error] [pid 845616:tid 845616] [client 45.148.10.115:46626] s ...
show more
[Fri Oct 10 09:53:10.636015 2025] [php:error] [pid 845616:tid 845616] [client 45.148.10.115:46626] script '/home/www/buusbudde.dk/public_html/phpinfo.php' not found or unable to stat
[Fri Oct 10 09:53:21.916704 2025] [php:error] [pid 896488:tid 896488] [client 45.148.10.115:58292] script '/home/www/buusbudde.dk/public_html/phpinfo.php' not found or unable to stat
...
show less
Web App Attack
๐ฎ๐ช
34.244.107.9
10 Oct 2025
[Fri Oct 10 03:42:14.432640 2025] [security2:error] [pid 3015566:tid 3015566] [client 34.244.107.9:6 ...
show more
[Fri Oct 10 03:42:14.432640 2025] [security2:error] [pid 3015566:tid 3015566] [client 34.244.107.9:62978] [client 34.244.107.9] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "buusbudde.dk"] [uri "/"] [unique_id "aOhkdgVYIK6s0wDu8WtLOAAAAAI"]
[Fri Oct 10 03:42:14.438884 2025] [security2:error] [pid 3630714:tid 3630714] [client 34.244.107.9:62979] [client 34.244.107.9] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CR
...
show less
Web App Attack
๐ณ๐ฑ
195.178.110.160
10 Oct 2025
[Fri Oct 10 02:37:36.460772 2025] [security2:error] [pid 3195471:tid 3195471] [client 195.178.110.16 ...
show more
[Fri Oct 10 02:37:36.460772 2025] [security2:error] [pid 3195471:tid 3195471] [client 195.178.110.160:41484] [client 195.178.110.160] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "buusbudde.dk"] [uri "/.env"] [unique_id "aOhVULZgc6oTu9BCdTqODAAAAAA"]
[Fri Oct 10 02:37:36.636390 2025] [security2:error] [pid 3013264:tid 3013264] [client 195.178.110.160:41492] [client 195.178.110.160] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)
...
show less
Web App Attack
๐ฒ๐พ
103.8.27.102
09 Oct 2025
[Fri Oct 10 00:58:10.993151 2025] [security2:error] [pid 3082741:tid 3082741] [client 103.8.27.102:5 ...
show more
[Fri Oct 10 00:58:10.993151 2025] [security2:error] [pid 3082741:tid 3082741] [client 103.8.27.102:55830] [client 103.8.27.102] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "buusbudde.dk"] [uri "/app/.env"] [unique_id "aOg-An8HjoeJVyc7h9dt_AAAAAo"]
[Fri Oct 10 00:58:10.994282 2025] [security2:error] [pid 3013264:tid 3013264] [client 103.8.27.102:55774] [client 103.8.27.102] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [seve
...
show less
Web App Attack
๐ฎ๐ณ
64.227.174.86
09 Oct 2025
[Thu Oct 09 23:36:38.532661 2025] [security2:error] [pid 2760095:tid 2760095] [client 64.227.174.86: ...
show more
[Thu Oct 09 23:36:38.532661 2025] [security2:error] [pid 2760095:tid 2760095] [client 64.227.174.86:56984] [client 64.227.174.86] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.buusbudde.dk"] [uri "/ab2g"] [unique_id "aOgq5k9F4is74IplAr5WYQAAAA4"], referer: https://87.104.65.148/ab2g
[Thu Oct 09 23:36:39.796421 2025] [security2:error] [pid 2786855:tid 2786855] [client 64.227.174.86:57000] [client 64.227.174.86] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomal
...
show less
Web App Attack
๐บ๐ธ
162.240.233.90
09 Oct 2025
[Thu Oct 09 18:04:24.983529 2025] [authz_core:error] [pid 1878197:tid 1878197] [client 162.240.233.9 ...
show more
[Thu Oct 09 18:04:24.983529 2025] [authz_core:error] [pid 1878197:tid 1878197] [client 162.240.233.90:53834] AH01630: client denied by server configuration: /home/www/buusbudde.dk/mimer/\nSet-Cookie:crlfinjection=crlfinjection
[Thu Oct 09 18:04:24.983534 2025] [authz_core:error] [pid 1898184:tid 1898184] [client 162.240.233.90:53842] AH01630: client denied by server configuration: /home/www/buusbudde.dk/mimer/plugins
[Thu Oct 09 18:04:24.983541 2025] [authz_core:error] [pid 1905839:tid 1905839] [client 162.240.233.90:53870] AH01630: client denied by server configuration: /home/www/buusbudde.dk/mimer/Business
...
show less
Hacking
๐ณ๐ฑ
196.251.84.213
09 Oct 2025
[Thu Oct 09 12:57:46.414773 2025] [security2:error] [pid 893246:tid 893246] [client 196.251.84.213:3 ...
show more
[Thu Oct 09 12:57:46.414773 2025] [security2:error] [pid 893246:tid 893246] [client 196.251.84.213:36824] [client 196.251.84.213] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "sky.buusbudde.dk"] [uri "/.env"] [unique_id "aOeVKtTLnUYS4TEHii9-HgAAAAI"]
[Thu Oct 09 12:57:56.759799 2025] [security2:error] [pid 924452:tid 924452] [client 196.251.84.213:43028] [client 196.251.84.213] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [
...
show less
Web App Attack
๐ซ๐ท
75.119.138.114
09 Oct 2025
[Thu Oct 09 10:29:50.282959 2025] [security2:error] [pid 459378:tid 459378] [client 75.119.138.114:4 ...
show more
[Thu Oct 09 10:29:50.282959 2025] [security2:error] [pid 459378:tid 459378] [client 75.119.138.114:46222] [client 75.119.138.114] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.buusbudde.dk"] [uri "/.env"] [unique_id "aOdyfsNEo2r-A2o1_1c3HQAAAAE"]
[Thu Oct 09 10:29:50.350842 2025] [security2:error] [pid 348167:tid 348167] [client 75.119.138.114:46236] [client 75.119.138.114] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [
...
show less
Web App Attack
๐ฎ๐ช
34.244.107.9
09 Oct 2025
[Thu Oct 09 02:49:43.533562 2025] [security2:error] [pid 2788599:tid 2788599] [client 34.244.107.9:6 ...
show more
[Thu Oct 09 02:49:43.533562 2025] [security2:error] [pid 2788599:tid 2788599] [client 34.244.107.9:64772] [client 34.244.107.9] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "buusbudde.dk"] [uri "/"] [unique_id "aOcGp-7H-2qLyQwx2RSL8wAAAAQ"]
[Thu Oct 09 02:49:43.547536 2025] [security2:error] [pid 2996346:tid 2996346] [client 34.244.107.9:64770] [client 34.244.107.9] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CR
...
show less
Web App Attack
๐ฎ๐ณ
106.222.211.135
08 Oct 2025
106.222.211.135 - - [08/Oct/2025:20:11:35 +0200] "POST /xmlrpc.php HTTP/1.1" 301 253 "-" "Mozilla/5. ...
show more
106.222.211.135 - - [08/Oct/2025:20:11:35 +0200] "POST /xmlrpc.php HTTP/1.1" 301 253 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7; x64) AppleWebKit/537.36 (KHTML, like Gecko) Edge/96.0.0.0 Safari/537.36"
106.222.211.135 - - [08/Oct/2025:20:11:44 +0200] "POST /xmlrpc.php HTTP/1.1" 301 241 "-" "Mozilla/5.0 (Linux; Android 10; x86) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36"
106.222.211.135 - - [08/Oct/2025:20:11:44 +0200] "GET /xmlrpc.php HTTP/1.1" 301 253 "-" "Mozilla/5.0 (Linux; Android 10; x86) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐ณ๐ฑ
195.178.110.160
08 Oct 2025
[Wed Oct 08 19:23:36.647346 2025] [security2:error] [pid 1557134:tid 1557134] [client 195.178.110.16 ...
show more
[Wed Oct 08 19:23:36.647346 2025] [security2:error] [pid 1557134:tid 1557134] [client 195.178.110.160:41462] [client 195.178.110.160] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "buusbudde.dk"] [uri "/.env"] [unique_id "aOaeGHQPEXtHK3wga1J82QAAAAQ"]
[Wed Oct 08 19:23:36.823380 2025] [security2:error] [pid 1344003:tid 1344003] [client 195.178.110.160:41468] [client 195.178.110.160] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)
...
show less
Web App Attack
๐บ๐ฆ
62.60.130.228
08 Oct 2025
62.60.130.228 - - [08/Oct/2025:13:48:42 +0200] "GET /wp-login.php HTTP/1.1" 301 243 "https://www.bin ...
show more
62.60.130.228 - - [08/Oct/2025:13:48:42 +0200] "GET /wp-login.php HTTP/1.1" 301 243 "https://www.bing.com/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 12_6_2) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.2.1 Safari/605.1.15"
62.60.130.228 - - [08/Oct/2025:13:48:42 +0200] "GET /wp-login.php HTTP/1.1" 301 255 "https://www.bing.com/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 12_6_2) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.2.1 Safari/605.1.15"
62.60.130.228 - - [08/Oct/2025:13:48:43 +0200] "GET /wp-login.php HTTP/1.1" 302 219 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.6099.130 Safari/537.36"
...
show less
Web App Attack
๐ฑ๐น
91.224.92.120
08 Oct 2025
91.224.92.120 - - [08/Oct/2025:13:37:51 +0200] "GET /wp-login.php HTTP/1.1" 301 243 "https://www.fac ...
show more
91.224.92.120 - - [08/Oct/2025:13:37:51 +0200] "GET /wp-login.php HTTP/1.1" 301 243 "https://www.facebook.com/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15) Gecko/20100101 Firefox/119.0.1"
91.224.92.120 - - [08/Oct/2025:13:37:52 +0200] "GET /wp-login.php HTTP/1.1" 301 255 "https://www.facebook.com/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15) Gecko/20100101 Firefox/119.0.1"
91.224.92.120 - - [08/Oct/2025:13:37:52 +0200] "GET /wp-login.php HTTP/1.1" 302 219 "https://www.google.de/search?q=wordpress" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.6099.130 Safari/537.36"
...
show less
Web App Attack
๐ซ๐ท
173.249.56.8
08 Oct 2025
173.249.56.8 - - [08/Oct/2025:12:50:53 +0200] "GET /wp-login.php HTTP/1.1" 301 243 "-" "Mozilla/5.0 ...
show more
173.249.56.8 - - [08/Oct/2025:12:50:53 +0200] "GET /wp-login.php HTTP/1.1" 301 243 "-" "Mozilla/5.0 (Windows NT 11.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.6045.159 Safari/537.36"
173.249.56.8 - - [08/Oct/2025:12:50:53 +0200] "GET /wp-login.php HTTP/1.1" 301 255 "-" "Mozilla/5.0 (Windows NT 11.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.6045.159 Safari/537.36"
173.249.56.8 - - [08/Oct/2025:12:50:54 +0200] "GET /wp-login.php HTTP/1.1" 302 219 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 11_7_2) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6.1 Safari/605.1.15"
...
show less
Web App Attack
๐ฎ๐ณ
38.137.52.155
08 Oct 2025
38.137.52.155 - - [08/Oct/2025:06:27:53 +0200] "POST /xmlrpc.php HTTP/1.1" 301 253 "-" "Mozilla/5.0 ...
show more
38.137.52.155 - - [08/Oct/2025:06:27:53 +0200] "POST /xmlrpc.php HTTP/1.1" 301 253 "-" "Mozilla/5.0 (Linux; Android 10; x64) AppleWebKit/537.36 (KHTML, like Gecko) Edge/89.0.0.0 Safari/537.36"
38.137.52.155 - - [08/Oct/2025:06:28:02 +0200] "POST /xmlrpc.php HTTP/1.1" 301 241 "-" "Mozilla/5.0 (Windows NT 6.3; x64) AppleWebKit/537.36 (KHTML, like Gecko) Firefox/75.0.0.0 Safari/537.36"
38.137.52.155 - - [08/Oct/2025:06:28:02 +0200] "GET /xmlrpc.php HTTP/1.1" 301 253 "-" "Mozilla/5.0 (Windows NT 6.3; x64) AppleWebKit/537.36 (KHTML, like Gecko) Firefox/75.0.0.0 Safari/537.36"
...
show less
Web App Attack