This IP address has been reported a total of
32
times from
20 distinct
sources.
95.173.223.145 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
France
with 3
reports;
Australia
with 2
reports;
Germany
with 2
reports.
The most common categories in these recent reports were:
Web Spam
4
times;
Web App Attack
4
times;
Hacking
3
times;
Brute-Force
2
times;
DDoS Attack
1
time;
Other
1
time.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
[ThuOct0122:13:51.8636212026][security2:error][pid4099456:tid4099465][client95.173.223.145:0]ModSecu ...
show more[ThuOct0122:13:51.8636212026][security2:error][pid4099456:tid4099465][client95.173.223.145:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\<\?/\?\?script\|\(\?:\<\|\<\?/\)\(\?:\(\?:java\|vb\)script\|about\|applet\|activex\|chrome\|qx\?ss\|embed\)\|\<\?/\?i\?frame\\\\\\\\b\|\<\?imgsrc\?=\|\<\?basehref\?=\)\"atARGS:your-message.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"1010\"][id\"340147\"][rev\"163\"][msg\"Atomicorp.comWAFRules:PotentialCrossSiteScriptingAttack\"][data\"\<imgsrc=\"][severity\"CRITICAL\"][hostname\"www.benvenutialfood.ch\"][uri\"/contatti/\"][unique_id\"ar6-_6d4ByFGjz51rmNRewAAAQc\"]\,referer:http://www.benvenutialfood.ch/contatti/
show less
Two SSH sessions from 95.173.223.145 using weak credentials administrator/1234 with OpenSSH 10.0-hpn ...
show moreTwo SSH sessions from 95.173.223.145 using weak credentials administrator/1234 with OpenSSH 10.0-hpn14v15. The attacker attempted port forwarding to five remote IP addresses across ports 80 and 443, suggesting reconnaissance for command and control infrastructure or lateral movement capabilities, though no command execution or malware artifacts were recovered during the activity window.
show less
Attacker from 95.173.223.145 established 2 SSH sessions using weak credentials (administrator/1234) ...
show moreAttacker from 95.173.223.145 established 2 SSH sessions using weak credentials (administrator/1234) and attempted port forwarding to 4 external destinations across ports 80 and 443, suggesting potential data exfiltration or command and control communication setup. No command execution or malware artifacts were recovered during the sessions.
show less
Two SSH sessions established using weak credentials (administrator/1234) with OpenSSH 10.0 client. N ...
show moreTwo SSH sessions established using weak credentials (administrator/1234) with OpenSSH 10.0 client. No commands executed, but attacker attempted port forwarding to multiple external hosts on ports 80 and 443, suggesting reconnaissance or preparation for lateral movement or data exfiltration.
show less
[rede-188] 2025-04-08 17:07:40, Client: 95.173.223.145:60029, Protocol: 6, Unauthorized activity to ...
show more[rede-188] 2025-04-08 17:07:40, Client: 95.173.223.145:60029, Protocol: 6, Unauthorized activity to HTTP: GET /
show less