🇧🇷
ICS Labs
2026-08-25 12:47:15
(1 week ago)
ICS Labs identified 103.153.130.123 as a malicious indicator from threat intelligence.
DDoS Attack
Hacking
Exploited Host
🇧🇷
ICS Labs
2026-06-03 12:08:55
(3 months ago)
ICS Labs identified 103.153.130.123 as a malicious indicator from threat intelligence.
DDoS Attack
Hacking
Exploited Host
Anonymous
2026-05-28 04:37:42
(3 months ago)
*Port Scan* detected from 103.153.130.123 (BD/Bangladesh/-). 5 hits in the last 40 seconds
Brute-Force
Port Scan
🇺🇸
TPI-Abuse
2026-04-21 13:29:02
(4 months ago)
(mod_security) mod_security (id:240335) triggered by 103.153.130.123 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 103.153.130.123 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 21 09:28:54.285437 2026] [security2:error] [pid 3010470:tid 3010470] [client 103.153.130.123:55929] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.153.130.123 (+1 hits since last alert)|matt-bechtel.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "matt-bechtel.com"] [uri "/xmlrpc.php"] [unique_id "aed7lgRu6hyXYGQrOlRguwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-04-16 13:16:16
(4 months ago)
(mod_security) mod_security (id:240335) triggered by 103.153.130.123 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 103.153.130.123 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 16 09:16:09.544449 2026] [security2:error] [pid 956602:tid 956602] [client 103.153.130.123:50716] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.153.130.123 (+1 hits since last alert)|protection4allsecurity.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "protection4allsecurity.com"] [uri "/xmlrpc.php"] [unique_id "aeDhGccw-9hbiN3xwQPVVAAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-04-13 12:20:26
(4 months ago)
(mod_security) mod_security (id:240335) triggered by 103.153.130.123 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 103.153.130.123 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 13 08:20:18.330788 2026] [security2:error] [pid 3819607:tid 3819633] [client 103.153.130.123:49907] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.153.130.123 (+1 hits since last alert)|campingcosmetics.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "campingcosmetics.com"] [uri "/xmlrpc.php"] [unique_id "adzfgjakN5hsGwV74uPk7AAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-04-12 12:59:43
(4 months ago)
(mod_security) mod_security (id:240335) triggered by 103.153.130.123 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 103.153.130.123 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 12 08:59:39.131006 2026] [security2:error] [pid 3013292:tid 3013300] [client 103.153.130.123:53737] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.153.130.123 (+1 hits since last alert)|datuinc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "datuinc.com"] [uri "/xmlrpc.php"] [unique_id "aduXO7nE6BRdK_Cdl6L4CQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇮
6kilowatti
2026-04-08 11:12:54
(4 months ago)
103.153.130.123 - - [08/Apr/2026:14:12:54 +0300] "POST /xmlrpc.php HTTP/1.1" 404 27 "-" "WordPress.c ...
show more
103.153.130.123 - - [08/Apr/2026:14:12:54 +0300] "POST /xmlrpc.php HTTP/1.1" 404 27 "-" "WordPress.com; https://wordpress.com"
103.153.130.123 - [08/Apr/2026:14:12:54 +0300] "POST /xmlrpc.php HTTP/1.1" 404 2048 "-" "WordPress.com; https://wordpress.com"
...
show less
Web App Attack
🇫🇷
Kenshin869
2026-04-08 08:30:38
(4 months ago)
Wordpress unauthorized access attempt
Brute-Force
🇫🇷
SpaceHost-Server
2026-04-05 22:25:48
(5 months ago)
Brute-Force
Web App Attack
🇫🇷
Kenshin869
2026-03-31 10:57:12
(5 months ago)
Wordpress unauthorized access attempt
Brute-Force
Anonymous
2026-03-30 13:15:57
(5 months ago)
apache vulnerability scan
Web App Attack
🇺🇸
TPI-Abuse
2026-03-18 12:00:22
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 103.153.130.123 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 103.153.130.123 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 18 08:00:16.827746 2026] [security2:error] [pid 32079:tid 32106] [client 103.153.130.123:50127] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||lamcohomecare.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "lamcohomecare.com"] [uri "/wp-json/wp/v2/users"] [unique_id "abqT0EhfjWhKpfrF0reDUgAAAJc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
ambor
2026-03-17 15:18:08
(5 months ago)
Honeypot access: WordPress XML-RPC attack attempt. Path: /xmlrpc.php
Brute-Force
Web App Attack
Anonymous
2026-02-03 14:42:30
(7 months ago)
DDoS botnet 510.000+ IPs; URL with bing/trustpilot/githubhelp and %C2%A4 or \xc2\xa4. NEW 09/2025: a ...
show more
DDoS botnet 510.000+ IPs; URL with bing/trustpilot/githubhelp and %C2%A4 or \xc2\xa4. NEW 09/2025: amplification attacks via third-parties e.g. HTTP_USER_AGENT facebookexternalhit/meta-externalagent/meta-externalfetcher or IPs from googleusercontent.com with fake HTTP_REFERER foxnews.com/newsweek.com/upwork.com/activision.com/... Port 443.
show less
DDoS Attack
Bad Web Bot
Web App Attack