๐ฎ๐ณ
106.215.164.157
08 Oct 2025
106.215.164.157 - - [08/Oct/2025:06:21:24 +0200] "POST /xmlrpc.php HTTP/1.1" 301 253 "-" "Mozilla/5. ...
show more
106.215.164.157 - - [08/Oct/2025:06:21:24 +0200] "POST /xmlrpc.php HTTP/1.1" 301 253 "-" "Mozilla/5.0 (Windows NT 6.2; x86) AppleWebKit/537.36 (KHTML, like Gecko) Firefox/87.0.0.0 Safari/537.36"
106.215.164.157 - - [08/Oct/2025:06:21:32 +0200] "POST /xmlrpc.php HTTP/1.1" 301 241 "-" "Mozilla/5.0 (Windows NT 6.3; arm64) AppleWebKit/537.36 (KHTML, like Gecko) Firefox/94.0.0.0 Safari/537.36"
106.215.164.157 - - [08/Oct/2025:06:21:33 +0200] "GET /xmlrpc.php HTTP/1.1" 301 253 "-" "Mozilla/5.0 (Windows NT 6.3; arm64) AppleWebKit/537.36 (KHTML, like Gecko) Firefox/94.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐บ๐ธ
208.84.101.35
08 Oct 2025
208.84.101.35 - - [08/Oct/2025:05:43:57 +0200] "GET /wp-login.php HTTP/1.1" 301 243 "-" "Mozilla/5.0 ...
show more
208.84.101.35 - - [08/Oct/2025:05:43:57 +0200] "GET /wp-login.php HTTP/1.1" 301 243 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.0.0 Safari/537.36"
208.84.101.35 - - [08/Oct/2025:05:43:58 +0200] "GET /wp-login.php HTTP/1.1" 301 255 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.0.0 Safari/537.36"
208.84.101.35 - - [08/Oct/2025:05:44:01 +0200] "GET /wp-login.php HTTP/1.1" 302 219 "https://wordpress.org/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 13_6_1; rv:121.0) Gecko/20100101 Firefox/121.0"
...
show less
Web App Attack
๐ท๐บ
45.135.232.178
08 Oct 2025
45.135.232.178 - - [08/Oct/2025:03:50:01 +0200] "GET /xmlrpc.php HTTP/1.1" 301 253 "https://juliabud ...
show more
45.135.232.178 - - [08/Oct/2025:03:50:01 +0200] "GET /xmlrpc.php HTTP/1.1" 301 253 "https://juliabudde.com/xmlrpc.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:141.0) Gecko/20100101 Firefox/141.0"
45.135.232.178 - - [08/Oct/2025:03:50:01 +0200] "GET /xmlrpc.php HTTP/1.1" 301 253 "https://juliabudde.com/xmlrpc.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.0.0 Safari/537.36"
45.135.232.178 - - [08/Oct/2025:03:50:03 +0200] "GET /wp-login.php?wp_lang=en_US HTTP/1.1" 301 269 "https://juliabudde.com/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐ฎ๐ช
34.244.107.9
07 Oct 2025
[Wed Oct 08 00:25:21.426164 2025] [security2:error] [pid 1952028:tid 1952028] [client 34.244.107.9:4 ...
show more
[Wed Oct 08 00:25:21.426164 2025] [security2:error] [pid 1952028:tid 1952028] [client 34.244.107.9:49908] [client 34.244.107.9] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "buusbudde.dk"] [uri "/"] [unique_id "aOWTUSaFuzMF08FqzByi-AAAAAQ"]
[Wed Oct 08 00:25:21.431333 2025] [security2:error] [pid 1936605:tid 1936605] [client 34.244.107.9:49910] [client 34.244.107.9] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 7)"] [severity "CR
...
show less
Web App Attack
๐ณ๐ฑ
45.148.10.203
07 Oct 2025
[Tue Oct 07 21:31:47.073876 2025] [security2:error] [pid 1397309:tid 1397309] [client 45.148.10.203: ...
show more
[Tue Oct 07 21:31:47.073876 2025] [security2:error] [pid 1397309:tid 1397309] [client 45.148.10.203:34208] [client 45.148.10.203] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "buusbudde.dk"] [uri "/portal/.env"] [unique_id "aOVqo4xbzJsCQyyimGMd3QAAAAU"]
[Tue Oct 07 21:31:47.097046 2025] [security2:error] [pid 1397309:tid 1397309] [client 45.148.10.203:34208] [client 45.148.10.203] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"
...
show less
Web App Attack
๐จ๐ณ
118.123.1.32
07 Oct 2025
[Tue Oct 07 18:37:52.042378 2025] [php:error] [pid 933615:tid 933615] [client 118.123.1.32:34894] sc ...
show more
[Tue Oct 07 18:37:52.042378 2025] [php:error] [pid 933615:tid 933615] [client 118.123.1.32:34894] script '/home/www/buusbudde.dk/public_html/index.php' not found or unable to stat, referer: https://87.104.65.148/index.php
[Tue Oct 07 18:37:53.092099 2025] [php:error] [pid 933707:tid 933707] [client 118.123.1.32:35150] script '/home/www/buusbudde.dk/public_html/index.php' not found or unable to stat, referer: https://87.104.65.148/index.php
...
show less
Web App Attack
๐น๐ณ
196.203.77.251
07 Oct 2025
196.203.77.251 - - [07/Oct/2025:14:42:32 +0200] "POST /xmlrpc.php HTTP/1.1" 301 253 "-" "Mozilla/5.0 ...
show more
196.203.77.251 - - [07/Oct/2025:14:42:32 +0200] "POST /xmlrpc.php HTTP/1.1" 301 253 "-" "Mozilla/5.0 (Windows NT 10.0; x64) AppleWebKit/537.36 (KHTML, like Gecko) Firefox/70.0.0.0 Safari/537.36"
196.203.77.251 - - [07/Oct/2025:14:42:40 +0200] "POST /xmlrpc.php HTTP/1.1" 301 241 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Opera/78.0.0.0 Safari/537.36"
196.203.77.251 - - [07/Oct/2025:14:42:40 +0200] "GET /xmlrpc.php HTTP/1.1" 301 253 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Opera/78.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐ง๐ท
179.108.2.132
07 Oct 2025
[Tue Oct 07 09:32:42.079555 2025] [php:error] [pid 3300966:tid 3300966] [client 179.108.2.132:39048] ...
show more
[Tue Oct 07 09:32:42.079555 2025] [php:error] [pid 3300966:tid 3300966] [client 179.108.2.132:39048] script '/home/www/buusbudde.dk/public_html/xmlrpc.php' not found or unable to stat
[Tue Oct 07 09:40:26.134302 2025] [php:error] [pid 3356969:tid 3356969] [client 179.108.2.132:39707] script '/home/www/buusbudde.dk/public_html/xmlrpc.php' not found or unable to stat
...
show less
Web App Attack
๐ณ๐ฑ
195.178.110.160
07 Oct 2025
[Tue Oct 07 07:30:02.812044 2025] [security2:error] [pid 2337106:tid 2337106] [client 195.178.110.16 ...
show more
[Tue Oct 07 07:30:02.812044 2025] [security2:error] [pid 2337106:tid 2337106] [client 195.178.110.160:51620] [client 195.178.110.160] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "buusbudde.dk"] [uri "/.env"] [unique_id "aOSlWq7JOY9siCI4I3V8VQAAAAI"]
[Tue Oct 07 07:30:02.972376 2025] [security2:error] [pid 3023989:tid 3023989] [client 195.178.110.160:51634] [client 195.178.110.160] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)
...
show less
Web App Attack
๐บ๐ธ
162.240.153.125
07 Oct 2025
[Tue Oct 07 04:49:28.916525 2025] [authz_core:error] [pid 2304255:tid 2304255] [client 162.240.153.1 ...
show more
[Tue Oct 07 04:49:28.916525 2025] [authz_core:error] [pid 2304255:tid 2304255] [client 162.240.153.125:48446] AH01630: client denied by server configuration: /home/www/buusbudde.dk/mimer/rest
[Tue Oct 07 04:49:28.945897 2025] [authz_core:error] [pid 2185314:tid 2185314] [client 162.240.153.125:48488] AH01630: client denied by server configuration: /home/www/buusbudde.dk/mimer/wp-json
[Tue Oct 07 04:49:28.946576 2025] [authz_core:error] [pid 2226570:tid 2226570] [client 162.240.153.125:48460] AH01630: client denied by server configuration: /home/www/buusbudde.dk/mimer/
...
show less
Hacking
๐ณ๐ฑ
146.190.20.213
07 Oct 2025
[Tue Oct 07 02:21:52.936623 2025] [security2:error] [pid 1537320:tid 1537320] [client 146.190.20.213 ...
show more
[Tue Oct 07 02:21:52.936623 2025] [security2:error] [pid 1537320:tid 1537320] [client 146.190.20.213:33914] [client 146.190.20.213] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.buusbudde.dk"] [uri "/ab2g"] [unique_id "aORdIPmVoA1nVmLfgkvezwAAAAA"], referer: https://87.104.65.148/ab2g
[Tue Oct 07 02:21:53.087033 2025] [security2:error] [pid 1401050:tid 1401050] [client 146.190.20.213:33932] [client 146.190.20.213] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound An
...
show less
Web App Attack
๐จ๐ด
181.119.67.171
06 Oct 2025
181.119.67.171 - - [06/Oct/2025:21:22:25 +0200] "POST /xmlrpc.php HTTP/1.1" 301 253 "-" "Mozilla/5.0 ...
show more
181.119.67.171 - - [06/Oct/2025:21:22:25 +0200] "POST /xmlrpc.php HTTP/1.1" 301 253 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36"
181.119.67.171 - - [06/Oct/2025:21:22:33 +0200] "POST /xmlrpc.php HTTP/1.1" 301 241 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36"
181.119.67.171 - - [06/Oct/2025:21:22:34 +0200] "GET /xmlrpc.php HTTP/1.1" 301 253 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36"
...
show less
Web App Attack
๐บ๐ธ
162.240.161.123
06 Oct 2025
[Mon Oct 06 14:35:30.907593 2025] [security2:error] [pid 3633606:tid 3633606] [client 162.240.161.12 ...
show more
[Mon Oct 06 14:35:30.907593 2025] [security2:error] [pid 3633606:tid 3633606] [client 162.240.161.123:38854] [client 162.240.161.123] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "buusbudde.dk"] [uri "/.env"] [unique_id "aOO3kgZT4tLUTq8qrXgJfwAAAA0"]
[Mon Oct 06 14:35:30.935108 2025] [security2:error] [pid 3682027:tid 3682027] [client 162.240.161.123:38844] [client 162.240.161.123] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)
...
show less
Web App Attack
๐ฎ๐ช
34.244.107.9
06 Oct 2025
[Mon Oct 06 03:04:25.663496 2025] [security2:error] [pid 863549:tid 863549] [client 34.244.107.9:499 ...
show more
[Mon Oct 06 03:04:25.663496 2025] [security2:error] [pid 863549:tid 863549] [client 34.244.107.9:49938] [client 34.244.107.9] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "buusbudde.dk"] [uri "/nmaplowercheck1759712665"] [unique_id "aOMVmUpX89NdeJmWiJMYNAAAAB4"]
[Mon Oct 06 03:04:25.664288 2025] [security2:error] [pid 1370126:tid 1370126] [client 34.244.107.9:49940] [client 34.244.107.9] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Sco
...
show less
Web App Attack
๐ณ๐ฑ
195.178.110.160
05 Oct 2025
[Mon Oct 06 00:24:10.447637 2025] [security2:error] [pid 863549:tid 863549] [client 195.178.110.160: ...
show more
[Mon Oct 06 00:24:10.447637 2025] [security2:error] [pid 863549:tid 863549] [client 195.178.110.160:53370] [client 195.178.110.160] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "buusbudde.dk"] [uri "/.env"] [unique_id "aOLwCkpX89NdeJmWiJMX-gAAAB4"]
[Mon Oct 06 00:24:10.583492 2025] [security2:error] [pid 863547:tid 863547] [client 195.178.110.160:53376] [client 195.178.110.160] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [
...
show less
Web App Attack
๐ฎ๐ณ
38.137.19.203
05 Oct 2025
38.137.19.203 - - [05/Oct/2025:15:40:25 +0200] "POST /xmlrpc.php HTTP/1.1" 301 253 "-" "Mozilla/5.0 ...
show more
38.137.19.203 - - [05/Oct/2025:15:40:25 +0200] "POST /xmlrpc.php HTTP/1.1" 301 253 "-" "Mozilla/5.0 (Linux; Android 10; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.0.0 Safari/537.36"
38.137.19.203 - - [05/Oct/2025:15:40:34 +0200] "POST /xmlrpc.php HTTP/1.1" 301 241 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7; x86) AppleWebKit/537.36 (KHTML, like Gecko) Firefox/75.0.0.0 Safari/537.36"
38.137.19.203 - - [05/Oct/2025:15:40:34 +0200] "GET /xmlrpc.php HTTP/1.1" 301 253 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7; x86) AppleWebKit/537.36 (KHTML, like Gecko) Firefox/75.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐ฎ๐ณ
45.127.44.10
05 Oct 2025
45.127.44.10 - - [05/Oct/2025:15:40:24 +0200] "POST /xmlrpc.php HTTP/1.1" 301 253 "-" "Mozilla/5.0 ( ...
show more
45.127.44.10 - - [05/Oct/2025:15:40:24 +0200] "POST /xmlrpc.php HTTP/1.1" 301 253 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/94.0.0.0 Safari/537.36"
45.127.44.10 - - [05/Oct/2025:15:40:33 +0200] "POST /xmlrpc.php HTTP/1.1" 301 241 "-" "Mozilla/5.0 (Linux; Android 10; x64) AppleWebKit/537.36 (KHTML, like Gecko) Safari/10.0.0.0 Safari/537.36"
45.127.44.10 - - [05/Oct/2025:15:40:33 +0200] "GET /xmlrpc.php HTTP/1.1" 301 253 "-" "Mozilla/5.0 (Linux; Android 10; x64) AppleWebKit/537.36 (KHTML, like Gecko) Safari/10.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐ง๐ท
179.160.117.121
05 Oct 2025
179.160.117.121 - - [05/Oct/2025:15:40:22 +0200] "POST /xmlrpc.php HTTP/1.1" 301 253 "-" "Mozilla/5. ...
show more
179.160.117.121 - - [05/Oct/2025:15:40:22 +0200] "POST /xmlrpc.php HTTP/1.1" 301 253 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36"
179.160.117.121 - - [05/Oct/2025:15:40:30 +0200] "POST /xmlrpc.php HTTP/1.1" 301 241 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36"
179.160.117.121 - - [05/Oct/2025:15:40:31 +0200] "GET /xmlrpc.php HTTP/1.1" 301 253 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36"
...
show less
Web App Attack
๐จ๐ญ
212.11.64.8
05 Oct 2025
[Sun Oct 05 03:28:30.456742 2025] [security2:error] [pid 288044:tid 288044] [client 212.11.64.8:3829 ...
show more
[Sun Oct 05 03:28:30.456742 2025] [security2:error] [pid 288044:tid 288044] [client 212.11.64.8:38294] [client 212.11.64.8] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "buusbudde.dk"] [uri "/.git/"] [unique_id "aOHJvvpKS-Hfu_VvFaiOAwAAAAY"]
[Sun Oct 05 03:28:30.634821 2025] [security2:error] [pid 204970:tid 204970] [client 212.11.64.8:38300] [client 212.11.64.8] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITI
...
show less
Web App Attack
๐ณ๐ฑ
213.209.157.253
05 Oct 2025
213.209.157.253 - - [05/Oct/2025:02:53:06 +0200] "GET /.git/config HTTP/1.1" 401 381 "-" "EmailWolf ...
show more
213.209.157.253 - - [05/Oct/2025:02:53:06 +0200] "GET /.git/config HTTP/1.1" 401 381 "-" "EmailWolf 1.00"
...
show less
Bad Web Bot
๐ฎ๐ช
34.244.107.9
04 Oct 2025
[Sun Oct 05 00:44:41.608610 2025] [security2:error] [pid 203951:tid 203951] [client 34.244.107.9:629 ...
show more
[Sun Oct 05 00:44:41.608610 2025] [security2:error] [pid 203951:tid 203951] [client 34.244.107.9:62932] [client 34.244.107.9] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "buusbudde.dk"] [uri "/nmaplowercheck1759617881"] [unique_id "aOGjWYdTTBDhOFz08H3VIgAAAAs"]
[Sun Oct 05 00:44:41.613335 2025] [security2:error] [pid 203961:tid 203961] [client 34.244.107.9:62933] [client 34.244.107.9] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score
...
show less
Web App Attack
๐ฎ๐ฑ
2.54.170.98
04 Oct 2025
2.54.170.98 - - [04/Oct/2025:22:22:30 +0200] "POST /xmlrpc.php HTTP/1.1" 301 253 "-" "Mozilla/5.0 (W ...
show more
2.54.170.98 - - [04/Oct/2025:22:22:30 +0200] "POST /xmlrpc.php HTTP/1.1" 301 253 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36"
2.54.170.98 - - [04/Oct/2025:22:22:32 +0200] "POST /xmlrpc.php HTTP/1.1" 301 241 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36"
2.54.170.98 - - [04/Oct/2025:22:22:32 +0200] "GET /xmlrpc.php HTTP/1.1" 301 253 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36"
...
show less
Web App Attack
๐ณ๐ฑ
93.123.109.60
04 Oct 2025
[Sat Oct 04 20:22:08.800073 2025] [security2:error] [pid 3658248:tid 3658248] [client 93.123.109.60: ...
show more
[Sat Oct 04 20:22:08.800073 2025] [security2:error] [pid 3658248:tid 3658248] [client 93.123.109.60:55392] [client 93.123.109.60] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "buusbudde.dk"] [uri "/.env"] [unique_id "aOFl0JONbhGkhUtHnTYlCQAAAAQ"]
[Sat Oct 04 20:22:09.023305 2025] [security2:error] [pid 3658248:tid 3658248] [client 93.123.109.60:55392] [client 93.123.109.60] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [seve
...
show less
Web App Attack
๐ฉ๐ฐ
37.96.40.170
04 Oct 2025
[Sat Oct 04 16:18:30.248578 2025] [security2:error] [pid 2899021:tid 2899021] [client 37.96.40.170:4 ...
show more
[Sat Oct 04 16:18:30.248578 2025] [security2:error] [pid 2899021:tid 2899021] [client 37.96.40.170:4785] [client 37.96.40.170] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "safe.buusbudde.dk"] [uri "/auth/login_flow"] [unique_id "aOEstisSMIG4swWDeqP8xgAAAAg"]
[Sat Oct 04 16:18:38.674886 2025] [security2:error] [pid 2942259:tid 2942259] [client 37.96.40.170:4771] [client 37.96.40.170] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score:
...
show less
Web App Attack
๐ธ๐ฌ
206.189.149.220
04 Oct 2025
[Sat Oct 04 13:59:05.901995 2025] [php:error] [pid 2424698:tid 2424698] [client 206.189.149.220:5399 ...
show more
[Sat Oct 04 13:59:05.901995 2025] [php:error] [pid 2424698:tid 2424698] [client 206.189.149.220:53991] script '/home/www/buusbudde.dk/public_html/xmlrpc.php' not found or unable to stat
[Sat Oct 04 13:59:06.610692 2025] [php:error] [pid 1976307:tid 1976307] [client 206.189.149.220:54002] script '/home/www/buusbudde.dk/public_html/wp-login.php' not found or unable to stat
...
show less
Web App Attack