๐บ๐ธ
TPI-Abuse
2026-08-20 01:23:14
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 80.80.172.211 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 80.80.172.211 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 21:23:06.874628 2026] [security2:error] [pid 18371:tid 18371] [client 80.80.172.211:57532] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 80.80.172.211 (+1 hits since last alert)|tomkatkaraoke.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "tomkatkaraoke.com"] [uri "/xmlrpc.php"] [unique_id "aoZW-s3Iw9HKn32tkjIlOQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-20 00:51:31
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 80.80.172.211 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 80.80.172.211 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 20:51:26.624033 2026] [security2:error] [pid 31963:tid 31963] [client 80.80.172.211:52448] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 80.80.172.211 (+1 hits since last alert)|lemoulinavent.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "lemoulinavent.org"] [uri "/xmlrpc.php"] [unique_id "aoZPjsePgPqL2o_OIRIeHAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-19 23:47:48
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 80.80.172.211 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 80.80.172.211 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 19:47:40.244081 2026] [security2:error] [pid 26332:tid 26332] [client 80.80.172.211:59088] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 80.80.172.211 (+1 hits since last alert)|hiidied.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "hiidied.com"] [uri "/xmlrpc.php"] [unique_id "aoZAnB7igChUTjrdVN4lRQAAAHE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-19 22:16:53
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 80.80.172.211 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 80.80.172.211 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 18:16:50.130064 2026] [security2:error] [pid 21453:tid 21478] [client 80.80.172.211:63830] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 80.80.172.211 (+1 hits since last alert)|fastesttrademark.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "fastesttrademark.com"] [uri "/xmlrpc.php"] [unique_id "aoYrUpl9SPCUysmlCWamWAAAAVY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
konseptit
2026-08-19 21:44:30
(3 days ago)
(wordpress) Failed wordpress login from 80.80.172.211 (XK/Kosovo/-)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-19 21:38:11
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 80.80.172.211 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 80.80.172.211 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 17:38:04.534253 2026] [security2:error] [pid 11817:tid 11817] [client 80.80.172.211:61777] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||apexhumanoidrobots.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "apexhumanoidrobots.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aoYiPIHy4hxO3iLPHSFdYgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
rh24
2026-08-19 21:02:21
(3 days ago)
(wordpress) Failed wordpress login from 80.80.172.211 (XK/Kosovo/-): (CF_ENABLE)
Brute-Force
๐บ๐ธ
integrantservices.com
2026-08-19 16:34:37
(3 days ago)
(wordpress) Failed wordpress login from 80.80.172.211 (XK/Kosovo/-)
Brute-Force
๐จ๐ฆ
polycoda
2026-08-19 16:25:05
(3 days ago)
AutoBlock: ๐ WordPress Login Brute Force (20X or 30X) (Decay-Based)
Brute-Force
Web App Attack
๐ช๐ธ
10dencehispahard SL
2022-02-16 03:12:04
(4 years ago)
Multiple failed login attempts on various servers [wordpress-xmlrpc]
Brute-Force
Web App Attack