๐บ๐ธ
TPI-Abuse
2026-08-22 05:26:18
(3 hours ago)
(mod_security) mod_security (id:240335) triggered by 80.95.94.149 (80-95-94-149.pool.digikabel.hu): ...
show more
(mod_security) mod_security (id:240335) triggered by 80.95.94.149 (80-95-94-149.pool.digikabel.hu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 01:26:12.172311 2026] [security2:error] [pid 3861:tid 3861] [client 80.95.94.149:63350] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 80.95.94.149 (+1 hits since last alert)|ucommsi.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "ucommsi.com"] [uri "/xmlrpc.php"] [unique_id "aoky9Osz9RvNDCyrjXyzOQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 04:53:47
(3 hours ago)
(mod_security) mod_security (id:240335) triggered by 80.95.94.149 (80-95-94-149.pool.digikabel.hu): ...
show more
(mod_security) mod_security (id:240335) triggered by 80.95.94.149 (80-95-94-149.pool.digikabel.hu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 00:53:42.684405 2026] [security2:error] [pid 12525:tid 12525] [client 80.95.94.149:51978] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 80.95.94.149 (+1 hits since last alert)|godcanuseyou.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "godcanuseyou.com"] [uri "/xmlrpc.php"] [unique_id "aokrVnNjj4w3BdClMQldVgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 04:23:39
(4 hours ago)
(mod_security) mod_security (id:240335) triggered by 80.95.94.149 (80-95-94-149.pool.digikabel.hu): ...
show more
(mod_security) mod_security (id:240335) triggered by 80.95.94.149 (80-95-94-149.pool.digikabel.hu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 00:23:31.735802 2026] [security2:error] [pid 23304:tid 23304] [client 80.95.94.149:57307] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 80.95.94.149 (+1 hits since last alert)|cnphilos.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "cnphilos.com"] [uri "/xmlrpc.php"] [unique_id "aokkQ7jVl57hg97Pn8IPjwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 02:49:54
(5 hours ago)
(mod_security) mod_security (id:240335) triggered by 80.95.94.149 (80-95-94-149.pool.digikabel.hu): ...
show more
(mod_security) mod_security (id:240335) triggered by 80.95.94.149 (80-95-94-149.pool.digikabel.hu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 22:49:48.266347 2026] [security2:error] [pid 24607:tid 24607] [client 80.95.94.149:62297] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 80.95.94.149 (+1 hits since last alert)|convtek.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "convtek.com"] [uri "/xmlrpc.php"] [unique_id "aokOTKEHstCypwF3meUGewAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-08-22 02:48:33
(5 hours ago)
[DC: IP:151.1.252.27] ntopng alert: blacklisted_server_contact
Hacking
Anonymous
2026-08-22 02:18:18
(6 hours ago)
[redacted] 80.95.94.149 - - [22/Aug/2026:04:17:24 +0200] "POST /xmlrpc.php HTTP/1.1" 200 418 "-" "Je ...
show more
[redacted] 80.95.94.149 - - [22/Aug/2026:04:17:24 +0200] "POST /xmlrpc.php HTTP/1.1" 200 418 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.1)"
[redacted] 80.95.94.149 - - [22/Aug/2026:04:17:35 +0200] "POST /xmlrpc.php HTTP/1.1" 200 418 "-" "Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.3)"
hirsch.de 80.95.94.149 - - [22/Aug/2026:04:17:39 +0200] "POST /xmlrpc.php HTTP/1.1" 200 418 "-" "Jetpack by WordPress.com"
[redacted] 80.95.94.149 - - [22/Aug/2026:04:17:45 +0200] "POST /xmlrpc.php HTTP/1.1" 200 418 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.3)"
hirsch.de 80.95.94.149 - - [22/Aug/2026:04:17:49 +0200] "POST /xmlrpc.php HTTP/1.1" 200 418 "-" "Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.3)"
[redacted] 80.95.94.149 - - [22/Aug/2026:04:17:56 +0200] "POST /xmlrpc.php HTTP/1.1" 200 418 "-" "Jetpack by WordPress.com"
hirsch.de 80.95.94.149 - - [22/Aug/2026:04:18:00 +0200] "POST /xmlrpc.php HT
...
show less
Hacking
Web App Attack
๐บ๐ธ
integrantservices.com
2026-08-22 01:16:45
(7 hours ago)
(wordpress) Failed wordpress login from 80.95.94.149 (HU/Hungary/80-95-94-149.pool.digikabel.hu)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-22 00:48:04
(7 hours ago)
(mod_security) mod_security (id:240335) triggered by 80.95.94.149 (80-95-94-149.pool.digikabel.hu): ...
show more
(mod_security) mod_security (id:240335) triggered by 80.95.94.149 (80-95-94-149.pool.digikabel.hu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 20:47:59.059894 2026] [security2:error] [pid 12452:tid 12452] [client 80.95.94.149:63155] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 80.95.94.149 (+1 hits since last alert)|robinsnestingplace.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "robinsnestingplace.net"] [uri "/xmlrpc.php"] [unique_id "aojxvxTCPiuiMAyyU5ZleAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-21 23:29:02
(9 hours ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐ฉ๐ช
Marc
2026-08-21 14:50:02
(17 hours ago)
80.95.94.149 - - [21/Aug/2026:16:49:40 +0200] "POST /xmlrpc.php HTTP/1.1" 200 4788 "-" "WordPress.co ...
show more
80.95.94.149 - - [21/Aug/2026:16:49:40 +0200] "POST /xmlrpc.php HTTP/1.1" 200 4788 "-" "WordPress.com; https://wordpress.com" 80.95.94.149 - - [21/Aug/2026:16:49:50 +0200] "POST /xmlrpc.php HTTP/1.1" 200 4835 "-" "WordPress.com; https://wordpress.com" 80.95.94.149 - - [21/Aug/2026:16:50:01 +0200] "POST /xmlrpc.php HTTP/1.1" 200 4835 "-" "Jetpack/12.1; WordPress/6.4; http://site89694853.com"
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 11:18:31
(21 hours ago)
(mod_security) mod_security (id:240335) triggered by 80.95.94.149 (80-95-94-149.pool.digikabel.hu): ...
show more
(mod_security) mod_security (id:240335) triggered by 80.95.94.149 (80-95-94-149.pool.digikabel.hu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 07:18:26.792258 2026] [security2:error] [pid 25173:tid 25173] [client 80.95.94.149:63134] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 80.95.94.149 (+1 hits since last alert)|semisysteme.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "semisysteme.com"] [uri "/xmlrpc.php"] [unique_id "aog0AtDiDFCwpz8_mtAfHgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 10:14:45
(22 hours ago)
(mod_security) mod_security (id:240335) triggered by 80.95.94.149 (80-95-94-149.pool.digikabel.hu): ...
show more
(mod_security) mod_security (id:240335) triggered by 80.95.94.149 (80-95-94-149.pool.digikabel.hu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 06:14:39.803871 2026] [security2:error] [pid 28912:tid 28912] [client 80.95.94.149:55194] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 80.95.94.149 (+1 hits since last alert)|barigby.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "barigby.com"] [uri "/xmlrpc.php"] [unique_id "aoglD8dGtWxPMaId0ja0-QAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
ConsulHosting
2026-08-21 08:56:43
(23 hours ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
๐ฉ๐ช
PHAM
2026-08-21 06:05:23
(1 day ago)
Shield Guard: Blocklist: IP signalรฉe (blocklist_de) | Scanner: wordpress.com (+55) | Chemin suspect: ...
show more
Shield Guard: Blocklist: IP signalรฉe (blocklist_de) | Scanner: wordpress.com (+55) | Chemin suspect: /xmlrpc.php
show less
Web App Attack
Port Scan
๐ณ๐ฑ
Site.eu
2026-08-21 04:34:15
(1 day ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH