๐บ๐ธ
TPI-Abuse
2026-09-26 11:55:28
(4 days ago)
(mod_security) mod_security (id:210350) triggered by 103.198.154.137 (103.198.154.137-pbb.net.pk): 1 ...
show more
(mod_security) mod_security (id:210350) triggered by 103.198.154.137 (103.198.154.137-pbb.net.pk): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 07:55:25.584741 2026] [security2:error] [pid 2481:tid 2481] [client 103.198.154.137:48016] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||normteslaa.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "normteslaa.com"] [uri "/"] [unique_id "areyrQG3FS95OL_l_0rXBgAAAAI"], referer: https://bulkbacklinkanalysis.online/dir/organic-growth-links-149938
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 11:14:21
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 103.198.154.137 (103.198.154.137-pbb.net.pk): 1 ...
show more
(mod_security) mod_security (id:210350) triggered by 103.198.154.137 (103.198.154.137-pbb.net.pk): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 07:14:14.820157 2026] [security2:error] [pid 24924:tid 24924] [client 103.198.154.137:25328] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||greetingcardspersonalized.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "greetingcardspersonalized.com"] [uri "/"] [unique_id "aq_ABrQCPcR8bW0GKbv-0AAAAAM"], referer: https://sitewebseo.com/dir/trusted-link-building-85919
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
rh24
2026-05-17 14:50:09
(4 months ago)
(xmlrpc_405) XMLRPC-Bot 405 103.198.154.137 (PK/Pakistan/103.198.154.137-pbb.net.pk)
Hacking
๐จ๐ฆ
Paulo Henrique dos Santos Nichio
2026-05-11 10:34:20
(4 months ago)
(ls_brute) LiteSpeed Brute Force Attack 103.198.154.137 (PK/Pakistan/103.198.154.137-pbb.net.pk): 3 ...
show more
(ls_brute) LiteSpeed Brute Force Attack 103.198.154.137 (PK/Pakistan/103.198.154.137-pbb.net.pk): 3 in the last 600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 2026-05-11 07:33:56.703983 [WARN] [3224225] [T0] [103.198.154.137:60580-30#APVH_www.padariacompao.com.br:443] Brute force detected for IP [103.198.154.137], throttle.
2026-05-11 07:34:07.709395 [WARN] [3224225] [T0] [103.198.154.137:60580-31#APVH_www.padariacompao.com.br:443] Brute force detected for IP [103.198.154.137], throttle.
2026-05-11 07:34:18.703999 [WARN] [3224225] [T0] [103.198.154.137:60580-32#APVH_www.padariacompao.com.br:443] Brute force detected for IP [103.198.154.137], throttle.
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-05-11 09:00:18
(4 months ago)
(mod_security) mod_security (id:240335) triggered by 103.198.154.137 (103.198.154.137-pbb.net.pk): 1 ...
show more
(mod_security) mod_security (id:240335) triggered by 103.198.154.137 (103.198.154.137-pbb.net.pk): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 11 05:00:10.984069 2026] [security2:error] [pid 32109:tid 32109] [client 103.198.154.137:53426] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.198.154.137 (+1 hits since last alert)|intrinsicdiscovery.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "intrinsicdiscovery.com"] [uri "/xmlrpc.php"] [unique_id "agGamh3nw7I7eMRUPmr4SQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-04-28 10:55:13
(5 months ago)
103.198.154.137 - - [28/Apr/2026:12:54:51 +0200] "POST /xmlrpc.php HTTP/1.1" 200 430 "-" "Jetpack/12 ...
show more
103.198.154.137 - - [28/Apr/2026:12:54:51 +0200] "POST /xmlrpc.php HTTP/1.1" 200 430 "-" "Jetpack/12.1; WordPress/6.3; http://site53571603.com"
103.198.154.137 - - [28/Apr/2026:12:55:01 +0200] "POST /xmlrpc.php HTTP/1.1" 200 430 "-" "Jetpack/12.0; WordPress/6.3; http://site33200646.com"
103.198.154.137 - - [28/Apr/2026:12:55:12 +0200] "POST /xmlrpc.php HTTP/1.1" 200 430 "-" "Jetpack/12.5; WordPress/6.3; http://site81393880.com"
show less
Hacking
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-04-28 10:39:42
(5 months ago)
103.198.154.137 - - [28/Apr/2026:12:39:20 +0200] "POST /xmlrpc.php HTTP/1.1" 200 430 "-" "WordPress. ...
show more
103.198.154.137 - - [28/Apr/2026:12:39:20 +0200] "POST /xmlrpc.php HTTP/1.1" 200 430 "-" "WordPress.com; https://wordpress.com"
103.198.154.137 - - [28/Apr/2026:12:39:30 +0200] "POST /xmlrpc.php HTTP/1.1" 200 430 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.2)"
103.198.154.137 - - [28/Apr/2026:12:39:41 +0200] "POST /xmlrpc.php HTTP/1.1" 200 430 "-" "Jetpack/12.5; WordPress/6.4; http://site99195168.com"
show less
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2025-12-02 11:04:49
(9 months ago)
[Tue Dec 02 17:07:27.181424 2025] [security2:error] [pid 72401:tid 140357732820672] [client 103.198. ...
show more
[Tue Dec 02 17:07:27.181424 2025] [security2:error] [pid 72401:tid 140357732820672] [client 103.198.154.137:53394] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "Brave" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.20.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "252"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: Brave found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Brave Chrome/78.0.3904.108 Safari/537.36 request_line = GET /index.php/profil/meteorologi/list-all-categories/555557786-peringatan-dini-3-harian-jawa-timur-hari-jumat-minggu-tanggal-10-12-januari-2020-update-dari-analisis-hari-jumat-10-januari-2020 HTTP/1.1"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/profil/meteorologi/list-all-categories/555557786-peringatan-dini-3-harian-jawa-timur-hari-jumat-minggu-tanggal-10-12-januari-2020-update-dari-analisis-h
...
show less
Hacking
Web App Attack
๐ณ๐ฑ
exxos
2025-08-01 03:57:49
(1 year ago)
HTTP1.x attacks
DDoS Attack
๐ช๐ธ
Global Cyber Police
2025-07-28 08:37:07
(1 year ago)
Malicious bot activity detected: Hitting honeypot page. Part of massive botnet.
DDoS Attack
Hacking
SQL Injection
Spoofing
Brute-Force
Bad Web Bot
Web App Attack