|
๐ซ๐ท
35.180.156.52
|
|
24/Mar/2026:06:20:29.910523 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
24/Mar/2026:06:20:29.910523 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 35.180.156.52] ModSecurity: Warning. Pattern match "(?:\\\\\\\\$(?:\\\\\\\\((?:\\\\\\\\(.*\\\\\\\\)|.*)\\\\\\\\)|\\\\\\\\{.*\\\\\\\\})|[<>]\\\\\\\\(.*\\\\\\\\))" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "367"] [id "932130"] [msg "Remote Command Execution: Unix Shell Expression Found"] [data "Matched Data: $((41*271)) found within ARGS:0: {then: $1:__proto__:then status: resolved_model reason: -1 value: {then:$b1337} _response: {_prefix: var res=process.mainmodule.require(child_process).execsync(echo $((41*271)) | base64 -w 0).tostring().trim() throw object.assign(new error(next_redirect) {digest: `next_redirect push/login?a=${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-shell"] [tag "platform-unix"] [tag "attack-rce
...
show less
|
Web App Attack
|
|
๐บ๐ธ
65.49.20.69
|
|
24/Mar/2026:06:25:25.180436 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
24/Mar/2026:06:25:25.180436 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 65.49.20.69] ModSecurity: Warning. Pattern match "^[\\\\\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [data "141.224.196.208"] [severity "WARNING"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "141.224.196.208"] [uri "/.git/config"] [unique_id "acIgRfPPprMnWFEI_65xwAAAAAU"]
24/Mar/2026:06:25:25.180436 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 65.49.20.69] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"] [id "930130"] [msg "Restricted Fil
...
show less
|
Web App Attack
|
|
๐ง๐ท
45.205.1.8
|
|
24/Mar/2026:06:14:07.018402 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
24/Mar/2026:06:14:07.018402 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 45.205.1.8] ModSecurity: Warning. Pattern match "^[\\\\\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [data "141.224.196.208:443"] [severity "WARNING"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "141.224.196.208"] [uri "/"] [unique_id "acIdn5ESi1KIz1BffdLy6wAAABA"]
24/Mar/2026:06:14:07.789684 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 45.205.1.8] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/share/modsecurity-crs/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "44"] [id "911100"] [msg
...
show less
|
Web App Attack
|
|
๐ณ๐ฑ
93.123.109.214
|
|
24/Mar/2026:05:25:33.299130 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
24/Mar/2026:05:25:33.299130 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 93.123.109.214] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "mak.vetspons.nl"] [uri "/.env"] [unique_id "acISPQnOjKdvLW50Mq80UQAAAAM"]
24/Mar/2026:05:25:33.299130 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 93.123.109.214] ModSecurity: Warning. Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg
...
show less
|
Web App Attack
|
|
๐บ๐ธ
137.184.61.56
|
|
24/Mar/2026:05:01:45.492953 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
24/Mar/2026:05:01:45.492953 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 137.184.61.56] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/usr/share/modsecurity-crs/rules/REQUEST-913-SCANNER-DETECTION.conf"] [line "55"] [id "913100"] [msg "Found User-Agent associated with security scanner"] [data "Matched Data: zgrab found within REQUEST_HEADERS:User-Agent: mozilla/5.0 zgrab/0.x"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-reputation-scanner"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/118/224/541/310"] [tag "PCI/6.5.10"] [hostname "141.224.196.208"] [uri "/"] [unique_id "acIMqWYXgOMhaeztpvruXAAAAAc"]
24/Mar/2026:05:01:45.492953 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 137.184.61.56] ModSecurity: Warning. Pattern match "^[\\\\\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-c
...
show less
|
Web App Attack
|
|
๐ณ๐ฑ
77.83.39.162
|
|
24/Mar/2026:04:54:03.912245 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
24/Mar/2026:04:54:03.912245 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 77.83.39.162] ModSecurity: Warning. Pattern match "^[\\\\\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [data "141.224.196.208"] [severity "WARNING"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "141.224.196.208"] [uri "/.git/refs/tags/"] [unique_id "acIK2-eojuDqSiKjBwdFFgAAAAs"]
24/Mar/2026:04:54:03.912245 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 77.83.39.162] ModSecurity: Warning. String match within "/accept-charset/ /content-encoding/ /proxy/ /lock-token/ /content-range/ /if/" at TX:header_name_accept-charset. [file "/usr/share/modsecurity-crs/
...
show less
|
Web App Attack
|
|
๐ง๐ท
45.205.1.8
|
|
24/Mar/2026:04:40:40.564396 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
24/Mar/2026:04:40:40.564396 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 45.205.1.8] ModSecurity: Warning. Pattern match "^[\\\\\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [data "141.224.196.208:443"] [severity "WARNING"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "141.224.196.208"] [uri "/"] [unique_id "acIHuKhsoevyKseGvaP9xwAAABA"]
24/Mar/2026:04:40:41.305017 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 45.205.1.8] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/share/modsecurity-crs/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "44"] [id "911100"] [msg
...
show less
|
Web App Attack
|
|
๐ณ๐ฑ
195.178.110.18
|
|
24/Mar/2026:04:33:15.622124 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
24/Mar/2026:04:33:15.622124 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 195.178.110.18] ModSecurity: Warning. String match within "/accept-charset/ /content-encoding/ /proxy/ /lock-token/ /content-range/ /if/" at TX:header_name_accept-charset. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1128"] [id "920450"] [msg "HTTP header is restricted by policy (/accept-charset/)"] [data "Restricted header detected: /accept-charset/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/12.1"] [hostname "worldcup.jordymarije.nl"] [uri "/.git/config"] [unique_id "acIF-5iu8BBgcSsj9hRAhQAAABY"]
24/Mar/2026:04:33:15.622124 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 195.178.110.18] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_F
...
show less
|
Web App Attack
|
|
๐ฎ๐ณ
34.47.182.97
|
|
24/Mar/2026:04:00:50.403641 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
24/Mar/2026:04:00:50.403641 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 34.47.182.97] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "jordymarije.nl"] [uri "/.git/config"] [unique_id "acH-YrlczyEbPk63RNDOlgAAABY"]
24/Mar/2026:04:00:50.403641 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 34.47.182.97] ModSecurity: Warning. Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "94
...
show less
|
Web App Attack
|
|
๐ง๐ช
154.47.27.236
|
|
24/Mar/2026:03:59:34.735980 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
24/Mar/2026:03:59:34.735980 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 154.47.27.236] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "familievandemaat.nl"] [uri "/.env"] [unique_id "acH-FtYIEQDGy1TyoPCDcQAAABQ"]
24/Mar/2026:03:59:34.735980 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 154.47.27.236] ModSecurity: Warning. Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [m
...
show less
|
Web App Attack
|
|
๐ซ๐ท
185.177.72.50
|
|
24/Mar/2026:03:48:20.033331 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
24/Mar/2026:03:48:20.033331 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 185.177.72.50] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "familievandemaat.nl"] [uri "/.env.production"] [unique_id "acH7dNyL4NEGohB0uMsv8wAAAAI"]
24/Mar/2026:03:48:20.033331 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 185.177.72.50] ModSecurity: Warning. Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line
...
show less
|
Web App Attack
|
|
๐ฎ๐ณ
13.233.184.193
|
|
24/Mar/2026:03:33:07.093833 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
24/Mar/2026:03:33:07.093833 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 13.233.184.193] ModSecurity: Warning. Pattern match "(?:\\\\\\\\$(?:\\\\\\\\((?:\\\\\\\\(.*\\\\\\\\)|.*)\\\\\\\\)|\\\\\\\\{.*\\\\\\\\})|[<>]\\\\\\\\(.*\\\\\\\\))" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "367"] [id "932130"] [msg "Remote Command Execution: Unix Shell Expression Found"] [data "Matched Data: $((41*271)) found within ARGS:0: {then: $1:__proto__:then status: resolved_model reason: -1 value: {then:$b1337} _response: {_prefix: var res=process.mainmodule.require(child_process).execsync(echo $((41*271)) | base64 -w 0).tostring().trim() throw object.assign(new error(next_redirect) {digest: `next_redirect push/login?a=${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-shell"] [tag "platform-unix"] [tag "attack-rc
...
show less
|
Web App Attack
|
|
๐ง๐ท
45.205.1.8
|
|
24/Mar/2026:03:30:29.094820 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
24/Mar/2026:03:30:29.094820 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 45.205.1.8] ModSecurity: Warning. Pattern match "^[\\\\\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [data "141.224.196.208:443"] [severity "WARNING"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "141.224.196.208"] [uri "/"] [unique_id "acH3RW-LIqQQJwzqbE6KkwAAAAU"]
24/Mar/2026:03:30:29.796500 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 45.205.1.8] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/share/modsecurity-crs/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "44"] [id "911100"] [msg
...
show less
|
Web App Attack
|
|
๐ณ๐ฑ
172.94.9.253
|
|
24/Mar/2026:03:22:26.200534 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
24/Mar/2026:03:22:26.200534 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 172.94.9.253] ModSecurity: Warning. Pattern match "^[\\\\\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [data "141.224.196.208"] [severity "WARNING"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "141.224.196.208"] [uri "/.git/config"] [unique_id "acH1YiTeRrrrlG_gu_VN5AAAAA8"]
24/Mar/2026:03:22:26.200534 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 172.94.9.253] ModSecurity: Warning. String match within "/accept-charset/ /content-encoding/ /proxy/ /lock-token/ /content-range/ /if/" at TX:header_name_accept-charset. [file "/usr/share/modsecurity-crs/rule
...
show less
|
Web App Attack
|
|
๐ซ๐ท
185.177.72.50
|
|
24/Mar/2026:02:42:10.159211 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
24/Mar/2026:02:42:10.159211 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 185.177.72.50] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "familievandemaat.nl"] [uri "/.env"] [unique_id "acHr8rCXPzFMlvImPCe5EgAAAAE"]
24/Mar/2026:02:42:10.159211 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 185.177.72.50] ModSecurity: Warning. Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [m
...
show less
|
Web App Attack
|
|
๐ง๐ท
45.205.1.8
|
|
24/Mar/2026:02:00:50.914392 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
24/Mar/2026:02:00:50.914392 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 45.205.1.8] ModSecurity: Warning. Pattern match "^[\\\\\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [data "141.224.196.208:443"] [severity "WARNING"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "141.224.196.208"] [uri "/"] [unique_id "acHiQkfMWr94DfHt5oj5ewAAAAk"]
24/Mar/2026:02:00:53.801240 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 45.205.1.8] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/share/modsecurity-crs/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "44"] [id "911100"] [msg
...
show less
|
Web App Attack
|
|
๐ซ๐ท
81.22.222.85
|
|
24/Mar/2026:01:52:08.901858 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
24/Mar/2026:01:52:08.901858 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 81.22.222.85] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "familievandemaat.nl"] [uri "/.env"] [unique_id "acHgOK1pMKMivtJhdgbKcQAAAAg"]
24/Mar/2026:01:52:08.901858 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 81.22.222.85] ModSecurity: Warning. Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg
...
show less
|
Web App Attack
|
|
๐ฉ๐ช
176.9.23.49
|
|
24/Mar/2026:01:48:37.506841 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
24/Mar/2026:01:48:37.506841 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 176.9.23.49] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "jordymarije.nl"] [uri "/.env"] [unique_id "acHfZa1pMKMivtJhdgbKbgAAAAg"]
24/Mar/2026:01:48:37.506841 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 176.9.23.49] ModSecurity: Warning. Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbou
...
show less
|
Web App Attack
|
|
๐ณ๐ฑ
176.65.149.253
|
|
24/Mar/2026:01:42:49.984111 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
24/Mar/2026:01:42:49.984111 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 176.65.149.253] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "550"] [id "920280"] [msg "Request Missing a Host Header"] [severity "WARNING"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "ramongames.nl"] [uri "/.env"] [unique_id "acHeCWz_iuMBT_IJ1cUuFgAAAAM"]
24/Mar/2026:01:42:49.984111 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 176.65.149.253] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found
...
show less
|
Web App Attack
|
|
๐ฑ๐น
141.98.11.171
|
|
24/Mar/2026:01:20:43.541399 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
24/Mar/2026:01:20:43.541399 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 141.98.11.171] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "mak.vetspons.nl"] [uri "/.env"] [unique_id "acHY2w1CaxRa6RxTvdJuvAAAAAU"]
24/Mar/2026:01:20:43.541399 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 141.98.11.171] ModSecurity: Warning. Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "
...
show less
|
Web App Attack
|
|
๐ง๐ท
45.205.1.8
|
|
24/Mar/2026:00:54:38.292809 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
24/Mar/2026:00:54:38.292809 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 45.205.1.8] ModSecurity: Warning. Pattern match "^[\\\\\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [data "141.224.196.208:443"] [severity "WARNING"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "141.224.196.208"] [uri "/"] [unique_id "acHSvhk-B0l5-7iZrCM0nwAAAA4"]
24/Mar/2026:00:54:38.931006 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 45.205.1.8] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/share/modsecurity-crs/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "44"] [id "911100"] [msg
...
show less
|
Web App Attack
|
|
๐บ๐ธ
162.243.174.155
|
|
24/Mar/2026:00:11:36.742824 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
24/Mar/2026:00:11:36.742824 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 162.243.174.155] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "familievandemaat.nl"] [uri "/.env"] [unique_id "acHIqP5JNl9P030mJAzk4AAAAAA"]
24/Mar/2026:00:11:36.742824 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 162.243.174.155] ModSecurity: Warning. Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"
...
show less
|
Web App Attack
|
|
๐ง๐ท
45.205.1.8
|
|
23/Mar/2026:23:50:31.475445 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
23/Mar/2026:23:50:31.475445 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 45.205.1.8] ModSecurity: Warning. Pattern match "^[\\\\\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [data "141.224.196.208:443"] [severity "WARNING"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "141.224.196.208"] [uri "/"] [unique_id "acHDt0kgbLd_jY39Ess3pwAAAAQ"]
23/Mar/2026:23:50:32.865190 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 45.205.1.8] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/share/modsecurity-crs/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "44"] [id "911100"] [msg
...
show less
|
Web App Attack
|
|
๐บ๐ธ
20.65.195.59
|
|
23/Mar/2026:23:35:05.712766 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
23/Mar/2026:23:35:05.712766 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 20.65.195.59] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/usr/share/modsecurity-crs/rules/REQUEST-913-SCANNER-DETECTION.conf"] [line "55"] [id "913100"] [msg "Found User-Agent associated with security scanner"] [data "Matched Data: zgrab found within REQUEST_HEADERS:User-Agent: mozilla/5.0 zgrab/0.x"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-reputation-scanner"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/118/224/541/310"] [tag "PCI/6.5.10"] [hostname "141.224.196.208"] [uri "/developmentserver/metadatauploader"] [unique_id "acHAGd35CDg9K3cbB-Zm_gAAAAI"]
23/Mar/2026:23:35:05.712766 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 20.65.195.59] ModSecurity: Warning. Pattern match "^[\\\\\\\\d.:]+$" at REQUEST_HEADERS:Host.
...
show less
|
Web App Attack
|
|
๐ซ๐ท
185.177.72.30
|
|
23/Mar/2026:22:41:51.376488 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
23/Mar/2026:22:41:51.376488 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 185.177.72.30] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1056"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "familievandemaat.nl"] [uri "/info.php.bak"] [unique_id "ac
...
show less
|
Web App Attack
|