๐บ๐ธ
TPI-Abuse
2026-07-28 12:21:16
(12 hours ago)
(mod_security) mod_security (id:240335) triggered by 103.13.42.13 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 103.13.42.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 08:21:09.030153 2026] [security2:error] [pid 10621:tid 10684] [client 103.13.42.13:60385] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.13.42.13 (+1 hits since last alert)|hearthandhomestudio.art|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "hearthandhomestudio.art"] [uri "/xmlrpc.php"] [unique_id "amietWP1pi90egdLV7FmagAAAUI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-28 10:42:30
(14 hours ago)
(mod_security) mod_security (id:240335) triggered by 103.13.42.13 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 103.13.42.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 06:42:25.209125 2026] [security2:error] [pid 2792966:tid 2792966] [client 103.13.42.13:59527] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.13.42.13 (+1 hits since last alert)|goldcountrygermanamericanclub.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "goldcountrygermanamericanclub.org"] [uri "/xmlrpc.php"] [unique_id "amiHkdOmmbFCx8xnBX8K4QAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Marc
2026-07-28 10:22:17
(14 hours ago)
103.13.42.13 - - [28/Jul/2026:12:21:55 +0200] "POST /xmlrpc.php HTTP/1.1" 200 4669 "-" "Jetpack by W ...
show more
103.13.42.13 - - [28/Jul/2026:12:21:55 +0200] "POST /xmlrpc.php HTTP/1.1" 200 4669 "-" "Jetpack by WordPress.com" 103.13.42.13 - - [28/Jul/2026:12:22:06 +0200] "POST /xmlrpc.php HTTP/1.1" 200 4670 "-" "Jetpack by WordPress.com" 103.13.42.13 - - [28/Jul/2026:12:22:16 +0200] "POST /xmlrpc.php HTTP/1.1" 200 4670 "-" "Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.2)"
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 09:12:02
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 103.13.42.13 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 103.13.42.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 05:11:58.312878 2026] [security2:error] [pid 3232:tid 3232] [client 103.13.42.13:28647] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.13.42.13 (+1 hits since last alert)|lemoulinavent.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "lemoulinavent.org"] [uri "/xmlrpc.php"] [unique_id "al3mXmj2UB9L4epXA5NTTQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-16 17:33:50
(1 week ago)
SMTP brute force - auth failed
Brute-Force
Exploited Host
๐ณ๐ฑ
maxxsense
2026-07-16 02:54:45
(1 week ago)
(postfix-unknown) Failed postfix unknown login with username [redacted] from 103.13.42.13 (IN/India/ ...
show more
(postfix-unknown) Failed postfix unknown login with username [redacted] from 103.13.42.13 (IN/India/-)
show less
Hacking
๐ฎ๐น
CoreTech srl
2026-07-16 02:52:33
(1 week ago)
mail3-dc1 04:47:53.343 [122.63.71.175] SMTP Login failed: Incorrect password for user [mcarminati@id ...
show more
mail3-dc1 04:47:53.343 [122.63.71.175] SMTP Login failed: Incorrect password for user [[email protected] ]mail3-dc1 04:47:53.343 [122.63.71.175] SMTP Login failed: Invalid username ([email protected] ) and password combination.is-6411d9d7 04:48:02.607 [122.139.222.251] SMTP Login failed: Domain [rodo.it] not foundis-6411d9d7 04:48:02.607 [122.139.222.251] SMTP Login failed: That domain was not found. Double check your email address.is-63909a28 04:48:34.511 [103.13.42.13] SMTP Login failed: Incorrect password for user [[email protected] ]is-63909a28 04:48:34.511 [103.13.42.13] SMTP Login failed: Invalid username ([email protected] ) and password combination.Smartermail 04:48:54.067 [182.8.161.3] SMTP Login failed: Incorrect password for user [[email protected] ]Smartermail 04:48:54.067 [182.8.161.3] SMTP Login failed: Invalid username ([email protected] ) and password combination.is-6411d9d7 04:50:21.921 [182.10.100.205] SMTP Login failed: Inval
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-11 09:51:36
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 103.13.42.13 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 103.13.42.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 11 05:51:28.803185 2026] [security2:error] [pid 32756:tid 32756] [client 103.13.42.13:43705] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.13.42.13 (+1 hits since last alert)|jaragoodrich.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "jaragoodrich.com"] [uri "/xmlrpc.php"] [unique_id "alISIB3-iHgDi0GlaM5HLAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
rh24
2026-07-06 05:15:21
(3 weeks ago)
(wordpress) Failed wordpress login from 103.13.42.13 (IN/India/-): (CF_ENABLE)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-18 11:09:50
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 103.13.42.13 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 103.13.42.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 18 07:09:47.073982 2026] [security2:error] [pid 10597:tid 10597] [client 103.13.42.13:48567] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.13.42.13 (+1 hits since last alert)|modalguitarist.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "modalguitarist.com"] [uri "/xmlrpc.php"] [unique_id "ajPR-xz7Xd1gAScaIq8czgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
integrantservices.com
2026-06-18 11:08:03
(1 month ago)
(wordpress) Failed wordpress login from 103.13.42.13 (IN/India/-)
Brute-Force
๐ณ๐ฑ
tmiland
2026-06-02 06:50:05
(1 month ago)
(wordpress_xmlrpc) WordPress XMLPRC Attack 103.13.42.13 (IN/India/-): 3 in the last 3600 secs; IP: 1 ...
show more
(wordpress_xmlrpc) WordPress XMLPRC Attack 103.13.42.13 (IN/India/-): 3 in the last 3600 secs; IP: 103.13.42.13; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 103.13.42.13 - - [02/Jun/2026:08:49:38 +0200] "POST /xmlrpc.php HTTP/1.1" 200 415 "-" "Jetpack/12.0; WordPress/6.3; http://site58643708.com" 103.13.42.13 - - [02/Jun/2026:08:49:46 +0200] "POST /xmlrpc.php HTTP/1.1" 200 415 "-" "WordPress.com; https://wordpress.com" 103.13.42.13 - - [02/Jun/2026:08:49:57 +0200] "POST /xmlrpc.php HTTP/1.1" 200 415 "-" "Jetpack by WordPress.com"
show less
Brute-Force
Anonymous
2026-06-02 06:48:44
(1 month ago)
Attac
Brute-Force
Anonymous
2026-05-25 07:09:14
(2 months ago)
Attac
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-05-25 06:40:24
(2 months ago)
(mod_security) mod_security (id:240335) triggered by 103.13.42.13 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 103.13.42.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 25 02:40:17.302503 2026] [security2:error] [pid 22640:tid 22640] [client 103.13.42.13:19081] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.13.42.13 (+1 hits since last alert)|lockdownclaim.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "lockdownclaim.com"] [uri "/xmlrpc.php"] [unique_id "ahPu0VO3EadxZ-PJeTjwQgAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack