π©πͺ
4server
2026-06-30 11:30:47
(36 minutes ago)
[TueJun3013:30:32.7166992026][security2:error][pid128485:tid128608][client103.121.6.1:0]ModSecurity: ...
show more
[TueJun3013:30:32.7166992026][security2:error][pid128485:tid128608][client103.121.6.1:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"170\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"ilcartiglio.ch\"][uri\"/xmlrpc.php\"][unique_id\"akOo2GZulLopyDD_2C4WhQAAAQQ\"]
show less
Port Scan
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-30 10:55:42
(1 hour ago)
(mod_security) mod_security (id:240335) triggered by 103.121.6.1 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240335) triggered by 103.121.6.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 30 06:55:29.166037 2026] [security2:error] [pid 6002:tid 6002] [client 103.121.6.1:41485] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.121.6.1 (+1 hits since last alert)|papapizza.pizza|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "papapizza.pizza"] [uri "/xmlrpc.php"] [unique_id "akOgoWSAJV1U4Q6Z7o_RlAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
kosada.com
2026-06-29 09:21:14
(1 day ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
πΊπΈ
integrantservices.com
2026-06-29 08:27:19
(1 day ago)
(wordpress) Failed wordpress login from 103.121.6.1 (PK/Pakistan/-)
Brute-Force
π³π±
Site.eu
2026-06-29 07:51:12
(1 day ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
πΊπΈ
TPI-Abuse
2026-06-29 07:21:02
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 103.121.6.1 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240335) triggered by 103.121.6.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 29 03:20:46.397012 2026] [security2:error] [pid 28225:tid 28225] [client 103.121.6.1:14644] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.121.6.1 (+1 hits since last alert)|lemoulinavent.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "lemoulinavent.org"] [uri "/xmlrpc.php"] [unique_id "akIczriTyRDEPuI0jfev3wAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-28 18:42:21
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 103.121.6.1 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240335) triggered by 103.121.6.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 28 14:42:06.476743 2026] [security2:error] [pid 10140:tid 10140] [client 103.121.6.1:15065] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.121.6.1 (+1 hits since last alert)|ardath.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "ardath.net"] [uri "/xmlrpc.php"] [unique_id "akFq_rfDEC02dCb6rJ3DcAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
masterguru
2026-06-28 18:40:03
(1 day ago)
xmlrpc request blocked, no referer. Pattern match "xmlrpc.php" at REQUEST_URI. (88010-201)
Hacking
πΊπΈ
TPI-Abuse
2026-06-28 15:59:15
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 103.121.6.1 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240335) triggered by 103.121.6.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 28 11:58:58.785386 2026] [security2:error] [pid 27361:tid 27361] [client 103.121.6.1:27340] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.121.6.1 (+1 hits since last alert)|aseguratuauto.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "aseguratuauto.com"] [uri "/xmlrpc.php"] [unique_id "akFEwpNhIpparNOWwlrG5wAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π²πΎ
Rizzy
2026-06-25 07:46:05
(5 days ago)
Multiple WAF Violations
Brute-Force
Web App Attack
π«π·
bazter.pro
2026-06-20 13:39:03
(1 week ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-20 13:08:47
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 103.121.6.1 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240335) triggered by 103.121.6.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 20 09:08:32.204976 2026] [security2:error] [pid 774:tid 774] [client 103.121.6.1:14725] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.121.6.1 (+1 hits since last alert)|rohanbyles.com.au|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "rohanbyles.com.au"] [uri "/xmlrpc.php"] [unique_id "ajaQ0I5o6JHbXD2qlGZmtwAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-20 10:25:10
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 103.121.6.1 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240335) triggered by 103.121.6.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 20 06:24:53.036273 2026] [security2:error] [pid 30985:tid 30985] [client 103.121.6.1:31664] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.121.6.1 (+1 hits since last alert)|celebritybikinigossip.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "celebritybikinigossip.com"] [uri "/xmlrpc.php"] [unique_id "ajZqdQNRlmeV9Tms62G0QwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
konseptit
2026-06-20 07:48:22
(1 week ago)
(wordpress) Failed wordpress login from 103.121.6.1 (PK/Pakistan/-)
Brute-Force
π³π±
Site.eu
2026-06-19 15:53:01
(1 week ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH