๐บ๐ธ
TPI-Abuse
2026-06-26 18:44:03
(10 hours ago)
(mod_security) mod_security (id:240335) triggered by 103.130.204.54 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 103.130.204.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 26 14:43:46.240411 2026] [security2:error] [pid 19046:tid 19046] [client 103.130.204.54:52729] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.130.204.54 (+1 hits since last alert)|doreenkimura.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "doreenkimura.com"] [uri "/xmlrpc.php"] [unique_id "aj7IYq3wvgv4V0EZFdLT8gAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-06-26 17:28:28
(11 hours ago)
13.866 requests with url.path */xmlrpc.php
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-26 16:57:41
(12 hours ago)
(mod_security) mod_security (id:240335) triggered by 103.130.204.54 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 103.130.204.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 26 12:57:27.448852 2026] [security2:error] [pid 5896:tid 5910] [client 103.130.204.54:32771] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.130.204.54 (+1 hits since last alert)|mysticscon.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "mysticscon.com"] [uri "/xmlrpc.php"] [unique_id "aj6vd8un9jtSYRs3LVofYQAAAIw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
sasbau
2026-06-26 16:09:34
(12 hours ago)
103.130.204.54 - - [26/Jun/2026:18:09:14 +0200] "POST /xmlrpc.php HTTP/1.1" 403 146 "-" "Jetpack/13. ...
show more
103.130.204.54 - - [26/Jun/2026:18:09:14 +0200] "POST /xmlrpc.php HTTP/1.1" 403 146 "-" "Jetpack/13.0; WordPress/6.3; http://site92847165.com"
103.130.204.54 - - [26/Jun/2026:18:09:23 +0200] "POST /xmlrpc.php HTTP/1.1" 403 146 "-" "WordPress.com; https://wordpress.com"
103.130.204.54 - - [26/Jun/2026:18:09:33 +0200] "POST /xmlrpc.php HTTP/1.1" 403 146 "-" "Jetpack by WordPress.com (Jetpack 12.5; WordPress 6.3)"
show less
Brute-Force
Web App Attack
๐บ๐ธ
integrantservices.com
2026-06-26 15:53:25
(13 hours ago)
(wordpress) Failed wordpress login from 103.130.204.54 (IN/India/-)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-26 15:42:26
(13 hours ago)
(mod_security) mod_security (id:240335) triggered by 103.130.204.54 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 103.130.204.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 26 11:42:09.281086 2026] [security2:error] [pid 5838:tid 5838] [client 103.130.204.54:17727] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.130.204.54 (+1 hits since last alert)|marcosbarraza.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "marcosbarraza.net"] [uri "/xmlrpc.php"] [unique_id "aj6d0dUPgA6Ostdnewl9BgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Dolphi
2026-06-26 15:40:09
(13 hours ago)
Excessive POST /xmlrpc.php requests
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-26 14:45:45
(14 hours ago)
(mod_security) mod_security (id:240335) triggered by 103.130.204.54 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 103.130.204.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 26 10:45:28.114149 2026] [security2:error] [pid 19699:tid 19699] [client 103.130.204.54:20925] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.130.204.54 (+1 hits since last alert)|edgebiopharma.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "edgebiopharma.com"] [uri "/xmlrpc.php"] [unique_id "aj6QiFBMdBszi7JIl4FbuwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2026-06-26 14:42:18
(14 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack