|
π³π±
93.123.109.214
|
|
26/Mar/2026:10:13:39.086359 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
26/Mar/2026:10:13:39.086359 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 93.123.109.214] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "ins.vetspons.nl"] [uri "/.env"] [unique_id "acT4wwD2BP8iFgSQACTD7AAAAAY"]
26/Mar/2026:10:13:39.086359 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 93.123.109.214] ModSecurity: Warning. Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg
...
show less
|
Web App Attack
|
|
π§π·
45.205.1.8
|
|
26/Mar/2026:09:17:07.722443 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
26/Mar/2026:09:17:07.722443 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 45.205.1.8] ModSecurity: Warning. Pattern match "^[\\\\\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [data "141.224.196.208:443"] [severity "WARNING"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "141.224.196.208"] [uri "/"] [unique_id "acTrg8PD38oMmlR4j_JKVwAAAAU"]
26/Mar/2026:09:17:08.619765 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 45.205.1.8] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/share/modsecurity-crs/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "44"] [id "911100"] [msg
...
show less
|
Web App Attack
|
|
π§π·
45.205.1.8
|
|
26/Mar/2026:08:16:53.380822 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
26/Mar/2026:08:16:53.380822 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 45.205.1.8] ModSecurity: Warning. Pattern match "^[\\\\\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [data "141.224.196.208:443"] [severity "WARNING"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "141.224.196.208"] [uri "/"] [unique_id "acTdZZa-544PlC0L5X069gAAAAE"]
26/Mar/2026:08:16:54.048230 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 45.205.1.8] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/share/modsecurity-crs/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "44"] [id "911100"] [msg
...
show less
|
Web App Attack
|
|
πΊπΈ
71.6.238.202
|
|
26/Mar/2026:07:31:55.109566 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
26/Mar/2026:07:31:55.109566 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 71.6.238.202] ModSecurity: Warning. String match within "/accept-charset/ /content-encoding/ /proxy/ /lock-token/ /content-range/ /if/" at TX:header_name_accept-charset. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1128"] [id "920450"] [msg "HTTP header is restricted by policy (/accept-charset/)"] [data "Restricted header detected: /accept-charset/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/12.1"] [hostname "im.vetspons.nl"] [uri "/"] [unique_id "acTS2yTN3j2aqOoBqvEq5AAAAAI"]
26/Mar/2026:07:31:55.109566 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 71.6.238.202] ModSecurity: Warning. Operator GE matched 5 at TX:anomaly_score. [file "/usr/share
...
show less
|
Web App Attack
|
|
π«π·
185.177.72.52
|
|
26/Mar/2026:07:28:57.489935 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
26/Mar/2026:07:28:57.489935 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 185.177.72.52] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1056"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".bak"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "mak.vetspons.nl"] [uri "/info.php.bak"] [unique_id "acTSKd
...
show less
|
Web App Attack
|
|
πΊπΈ
71.6.238.77
|
|
26/Mar/2026:07:19:20.875003 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
26/Mar/2026:07:19:20.875003 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 71.6.238.77] ModSecurity: Warning. String match within "/accept-charset/ /content-encoding/ /proxy/ /lock-token/ /content-range/ /if/" at TX:header_name_accept-charset. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1128"] [id "920450"] [msg "HTTP header is restricted by policy (/accept-charset/)"] [data "Restricted header detected: /accept-charset/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/12.1"] [hostname "versie.vetspons.nl"] [uri "/"] [unique_id "acTP6NuiYUDTGyBMQs8qqQAAAAU"]
26/Mar/2026:07:19:20.875003 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 71.6.238.77] ModSecurity: Warning. Operator GE matched 5 at TX:anomaly_score. [file "/usr/sha
...
show less
|
Web App Attack
|
|
π©πͺ
45.135.193.131
|
|
26/Mar/2026:07:24:15.840299 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
26/Mar/2026:07:24:15.840299 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 45.135.193.131] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "ramongames.nl"] [uri "/.env"] [unique_id "acTRD_2J4GOL0vj2PRhoOQAAAAc"]
26/Mar/2026:07:24:15.840299 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 45.135.193.131] ModSecurity: Warning. Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "
...
show less
|
Web App Attack
|
|
π§π·
45.205.1.8
|
|
26/Mar/2026:07:12:57.714094 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
26/Mar/2026:07:12:57.714094 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 45.205.1.8] ModSecurity: Warning. Pattern match "^[\\\\\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [data "141.224.196.208:443"] [severity "WARNING"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "141.224.196.208"] [uri "/"] [unique_id "acTOaa695pA6VG5oRPbDZAAAAAQ"]
26/Mar/2026:07:12:58.850631 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 45.205.1.8] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/share/modsecurity-crs/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "44"] [id "911100"] [msg
...
show less
|
Web App Attack
|
|
π³π±
46.151.178.13
|
|
26/Mar/2026:07:06:13.280300 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
26/Mar/2026:07:06:13.280300 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 46.151.178.13] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/share/modsecurity-crs/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "44"] [id "911100"] [msg "Method is not allowed by policy"] [data "PROPFIND"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "141.224.196.208"] [uri "/"] [unique_id "acTM1VjlYOS-VckT1CQ8DAAAAA4"]
26/Mar/2026:07:06:13.280300 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 46.151.178.13] ModSecurity: Warning. Pattern match "^[\\\\\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "H
...
show less
|
Web App Attack
|
|
πΊπΈ
71.6.236.163
|
|
26/Mar/2026:06:51:01.491565 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
26/Mar/2026:06:51:01.491565 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 71.6.236.163] ModSecurity: Warning. String match within "/accept-charset/ /content-encoding/ /proxy/ /lock-token/ /content-range/ /if/" at TX:header_name_accept-charset. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1128"] [id "920450"] [msg "HTTP header is restricted by policy (/accept-charset/)"] [data "Restricted header detected: /accept-charset/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/12.1"] [hostname "ins.vetspons.nl"] [uri "/"] [unique_id "acTJRQD2BP8iFgSQACTB1AAAAAY"]
26/Mar/2026:06:51:01.491565 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 71.6.236.163] ModSecurity: Warning. Operator GE matched 5 at TX:anomaly_score. [file "/usr/shar
...
show less
|
Web App Attack
|
|
π³π±
45.144.212.97
|
|
26/Mar/2026:06:27:20.581552 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
26/Mar/2026:06:27:20.581552 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 45.144.212.97] ModSecurity: Warning. Pattern match "^[\\\\\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [data "141.224.196.208"] [severity "WARNING"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "141.224.196.208"] [uri "/.env"] [unique_id "acTDuGGSG35nqNLw7QgwZgAAAAY"]
26/Mar/2026:06:27:20.581552 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 45.144.212.97] ModSecurity: Warning. String match within "/accept-charset/ /content-encoding/ /proxy/ /lock-token/ /content-range/ /if/" at TX:header_name_accept-charset. [file "/usr/share/modsecurity-crs/rules/REQ
...
show less
|
Web App Attack
|
|
πΊπΈ
71.6.239.121
|
|
26/Mar/2026:06:09:15.497458 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
26/Mar/2026:06:09:15.497458 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 71.6.239.121] ModSecurity: Warning. String match within "/accept-charset/ /content-encoding/ /proxy/ /lock-token/ /content-range/ /if/" at TX:header_name_accept-charset. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1128"] [id "920450"] [msg "HTTP header is restricted by policy (/accept-charset/)"] [data "Restricted header detected: /accept-charset/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/12.1"] [hostname "ex.vetspons.nl"] [uri "/"] [unique_id "acS_e_NqD9C5F9q8hw1D1wAAAAk"]
26/Mar/2026:06:09:15.497458 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 71.6.239.121] ModSecurity: Warning. Operator GE matched 5 at TX:anomaly_score. [file "/usr/share
...
show less
|
Web App Attack
|
|
πΊπΈ
71.6.238.67
|
|
26/Mar/2026:05:57:34.210476 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
26/Mar/2026:05:57:34.210476 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 71.6.238.67] ModSecurity: Warning. String match within "/accept-charset/ /content-encoding/ /proxy/ /lock-token/ /content-range/ /if/" at TX:header_name_accept-charset. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1128"] [id "920450"] [msg "HTTP header is restricted by policy (/accept-charset/)"] [data "Restricted header detected: /accept-charset/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/12.1"] [hostname "activeer.vetspons.nl"] [uri "/"] [unique_id "acS8vnoPNkiX1FIdSwuJGAAAAAc"]
26/Mar/2026:05:57:34.210476 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 71.6.238.67] ModSecurity: Warning. Operator GE matched 5 at TX:anomaly_score. [file "/usr/s
...
show less
|
Web App Attack
|
|
πΊπΈ
71.6.239.40
|
|
26/Mar/2026:05:35:27.951210 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
26/Mar/2026:05:35:27.951210 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 71.6.239.40] ModSecurity: Warning. String match within "/accept-charset/ /content-encoding/ /proxy/ /lock-token/ /content-range/ /if/" at TX:header_name_accept-charset. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1128"] [id "920450"] [msg "HTTP header is restricted by policy (/accept-charset/)"] [data "Restricted header detected: /accept-charset/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/12.1"] [hostname "mak.vetspons.nl"] [uri "/"] [unique_id "acS3jz6h8RQuXaTGQsIx9AAAAAQ"]
26/Mar/2026:05:35:27.951210 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 71.6.239.40] ModSecurity: Warning. Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/
...
show less
|
Web App Attack
|
|
π§π·
45.205.1.8
|
|
26/Mar/2026:05:28:14.594618 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
26/Mar/2026:05:28:14.594618 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 45.205.1.8] ModSecurity: Warning. Pattern match "^[\\\\\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [data "141.224.196.208:443"] [severity "WARNING"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "141.224.196.208"] [uri "/"] [unique_id "acS13u1oUuLSfjN5v1OrdAAAAAo"]
26/Mar/2026:05:28:15.344744 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 45.205.1.8] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/share/modsecurity-crs/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "44"] [id "911100"] [msg
...
show less
|
Web App Attack
|
|
πΊπΈ
71.6.237.38
|
|
26/Mar/2026:05:08:04.598192 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
26/Mar/2026:05:08:04.598192 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 71.6.237.38] ModSecurity: Warning. String match within "/accept-charset/ /content-encoding/ /proxy/ /lock-token/ /content-range/ /if/" at TX:header_name_accept-charset. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1128"] [id "920450"] [msg "HTTP header is restricted by policy (/accept-charset/)"] [data "Restricted header detected: /accept-charset/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/12.1"] [hostname "jordymarije.nl"] [uri "/"] [unique_id "acSxJNuiYUDTGyBMQs8o8QAAAAU"]
26/Mar/2026:05:08:04.598192 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 71.6.237.38] ModSecurity: Warning. Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/m
...
show less
|
Web App Attack
|
|
π³π±
195.178.110.246
|
|
26/Mar/2026:05:09:10.003749 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
26/Mar/2026:05:09:10.003749 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 195.178.110.246] ModSecurity: Warning. Pattern match "^[\\\\\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [data "141.224.196.208"] [severity "WARNING"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "141.224.196.208"] [uri "/.env"] [unique_id "acSxZWyyipfqVXc-5JA6BAAAAAk"]
26/Mar/2026:05:09:10.003749 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 195.178.110.246] ModSecurity: Warning. String match within "/accept-charset/ /content-encoding/ /proxy/ /lock-token/ /content-range/ /if/" at TX:header_name_accept-charset. [file "/usr/share/modsecurity-crs/rules
...
show less
|
Web App Attack
|
|
πΊπΈ
64.62.197.77
|
|
26/Mar/2026:03:59:14.990037 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
26/Mar/2026:03:59:14.990037 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 64.62.197.77] ModSecurity: Warning. Pattern match "^[\\\\\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [data "141.224.196.208"] [severity "WARNING"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "141.224.196.208"] [uri "/.git/config"] [unique_id "acShApg8ImLMD0b31gO3oAAAAAA"]
26/Mar/2026:03:59:14.990037 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 64.62.197.77] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"] [id "930130"] [msg "Restricted F
...
show less
|
Web App Attack
|
|
πΊπΈ
159.65.170.51
|
|
26/Mar/2026:03:39:14.774904 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
26/Mar/2026:03:39:14.774904 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 159.65.170.51] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "ramongames.nl"] [uri "/.env"] [unique_id "acScUu3NSno6eQEclV5QqAAAAAs"]
26/Mar/2026:03:39:14.774904 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 159.65.170.51] ModSecurity: Warning. Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "In
...
show less
|
Web App Attack
|
|
π§π·
45.205.1.8
|
|
26/Mar/2026:03:31:40.359116 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
26/Mar/2026:03:31:40.359116 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 45.205.1.8] ModSecurity: Warning. Pattern match "^[\\\\\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [data "141.224.196.208:443"] [severity "WARNING"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "141.224.196.208"] [uri "/"] [unique_id "acSajIQgwehqPVLwnbAdOwAAAA0"]
26/Mar/2026:03:31:41.504856 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 45.205.1.8] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/share/modsecurity-crs/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "44"] [id "911100"] [msg
...
show less
|
Web App Attack
|
|
π³π±
195.178.110.162
|
|
26/Mar/2026:03:30:55.610596 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
26/Mar/2026:03:30:55.610596 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 195.178.110.162] ModSecurity: Warning. Pattern match "^[\\\\\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [data "141.224.196.208"] [severity "WARNING"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "141.224.196.208"] [uri "/.env"] [unique_id "acSaXzWVQ1bXdSuTpK3HxwAAAA8"]
26/Mar/2026:03:30:55.610596 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 195.178.110.162] ModSecurity: Warning. String match within "/accept-charset/ /content-encoding/ /proxy/ /lock-token/ /content-range/ /if/" at TX:header_name_accept-charset. [file "/usr/share/modsecurity-crs/rules
...
show less
|
Web App Attack
|
|
πΊπΈ
20.98.140.180
|
|
26/Mar/2026:03:22:18.698907 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
26/Mar/2026:03:22:18.698907 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 20.98.140.180] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/usr/share/modsecurity-crs/rules/REQUEST-913-SCANNER-DETECTION.conf"] [line "55"] [id "913100"] [msg "Found User-Agent associated with security scanner"] [data "Matched Data: zgrab found within REQUEST_HEADERS:User-Agent: mozilla/5.0 zgrab/0.x"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-reputation-scanner"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/118/224/541/310"] [tag "PCI/6.5.10"] [hostname "141.224.196.208"] [uri "/owa/auth/logon.aspx"] [unique_id "acSYWr0ch8Tcc5NCMdrJpAAAAAU"]
26/Mar/2026:03:22:18.698907 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 20.98.140.180] ModSecurity: Warning. Pattern match "^[\\\\\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/
...
show less
|
Web App Attack
|
|
π³π±
46.151.178.13
|
|
26/Mar/2026:03:12:36.628611 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
26/Mar/2026:03:12:36.628611 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 46.151.178.13] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/share/modsecurity-crs/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "44"] [id "911100"] [msg "Method is not allowed by policy"] [data "PROPFIND"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "141.224.196.208"] [uri "/"] [unique_id "acSWFL0ch8Tcc5NCMdrJkwAAAAU"]
26/Mar/2026:03:12:36.628611 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 46.151.178.13] ModSecurity: Warning. Pattern match "^[\\\\\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "H
...
show less
|
Web App Attack
|
|
π³π±
93.123.109.214
|
|
26/Mar/2026:02:52:10.228754 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
26/Mar/2026:02:52:10.228754 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 93.123.109.214] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "ins.vetspons.nl"] [uri "/.env"] [unique_id "acSRSlQWsjvf6JxwaPdNowAAAAg"]
26/Mar/2026:02:52:10.228754 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 93.123.109.214] ModSecurity: Warning. Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg
...
show less
|
Web App Attack
|
|
π³π±
195.178.110.187
|
|
26/Mar/2026:02:49:29.780124 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
26/Mar/2026:02:49:29.780124 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 195.178.110.187] ModSecurity: Warning. String match within "/accept-charset/ /content-encoding/ /proxy/ /lock-token/ /content-range/ /if/" at TX:header_name_accept-charset. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1128"] [id "920450"] [msg "HTTP header is restricted by policy (/accept-charset/)"] [data "Restricted header detected: /accept-charset/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/12.1"] [hostname "activeer.vetspons.nl"] [uri "/.git/config"] [unique_id "acSQqQD2BP8iFgSQACS89wAAAAY"]
26/Mar/2026:02:49:29.780124 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 195.178.110.187] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FI
...
show less
|
Web App Attack
|