Extension filtering seems to be the most common attack (Graph 1, 2 and 3) type such attacks are mostly not real attacks. The extension “.ashx” shouldn’t pose problem. Therefore we suggest adding it to the exception list. (Through custom settings.). Clearly setting this could have reduced the logs by more than 95%.