๐บ๐ธ
cwytech
2026-06-18 08:31:50
(1 day ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/wp-us-login-only-high.
Bad Web Bot
Web App Attack
๐บ๐ธ
integrantservices.com
2026-06-18 08:03:02
(1 day ago)
(wordpress) Failed wordpress login from 103.198.154.186 (PK/Pakistan/103.198.154.186-pbb.net.pk)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-17 10:53:13
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 103.198.154.186 (103.198.154.186-pbb.net.pk): 1 ...
show more
(mod_security) mod_security (id:240335) triggered by 103.198.154.186 (103.198.154.186-pbb.net.pk): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 17 06:53:08.260814 2026] [security2:error] [pid 27532:tid 27532] [client 103.198.154.186:63202] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.198.154.186 (+1 hits since last alert)|kaldaragroup.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "kaldaragroup.com"] [uri "/xmlrpc.php"] [unique_id "ajJ8lGoLr8RWnN1qccir5AAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-17 06:21:34
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 103.198.154.186 (103.198.154.186-pbb.net.pk): 1 ...
show more
(mod_security) mod_security (id:240335) triggered by 103.198.154.186 (103.198.154.186-pbb.net.pk): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 17 02:21:30.651515 2026] [security2:error] [pid 31600:tid 31600] [client 103.198.154.186:40547] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.198.154.186 (+1 hits since last alert)|campos.tv|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "campos.tv"] [uri "/xmlrpc.php"] [unique_id "ajI86pB5UD8jbcvxOYcYmwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-16 15:17:24
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 103.198.154.186 (103.198.154.186-pbb.net.pk): 1 ...
show more
(mod_security) mod_security (id:240335) triggered by 103.198.154.186 (103.198.154.186-pbb.net.pk): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 11:17:18.937584 2026] [security2:error] [pid 4067:tid 4067] [client 103.198.154.186:56701] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.198.154.186 (+1 hits since last alert)|roguetechhub.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "roguetechhub.com"] [uri "/xmlrpc.php"] [unique_id "ajFo_stcK5PnzXvfG8ZRWAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 19:20:07
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 103.198.154.186 (103.198.154.186-pbb.net.pk): 1 ...
show more
(mod_security) mod_security (id:240335) triggered by 103.198.154.186 (103.198.154.186-pbb.net.pk): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 15:19:58.377959 2026] [security2:error] [pid 23768:tid 23768] [client 103.198.154.186:61522] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.198.154.186 (+1 hits since last alert)|hendersonhomes.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "hendersonhomes.com"] [uri "/xmlrpc.php"] [unique_id "ajBQXtuPZlKJb0ulk7u8wAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-15 18:15:07
(3 days ago)
[ssd1.kdns.gr] httpd-xmlrpc-post: sites=nbmedical.gr; logs=/var/log/httpd/domains/nbmedical.gr.log; ...
show more
[ssd1.kdns.gr] httpd-xmlrpc-post: sites=nbmedical.gr; logs=/var/log/httpd/domains/nbmedical.gr.log; samples=/xmlrpc.php
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 22:31:14
(4 days ago)
(mod_security) mod_security (id:240335) triggered by 103.198.154.186 (103.198.154.186-pbb.net.pk): 1 ...
show more
(mod_security) mod_security (id:240335) triggered by 103.198.154.186 (103.198.154.186-pbb.net.pk): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 18:31:08.298730 2026] [security2:error] [pid 11951:tid 11951] [client 103.198.154.186:56969] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.198.154.186 (+1 hits since last alert)|jerielster.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "jerielster.com"] [uri "/xmlrpc.php"] [unique_id "ai8rrNXtH2E5ODZLSkQTnAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 21:27:57
(4 days ago)
(mod_security) mod_security (id:240335) triggered by 103.198.154.186 (103.198.154.186-pbb.net.pk): 1 ...
show more
(mod_security) mod_security (id:240335) triggered by 103.198.154.186 (103.198.154.186-pbb.net.pk): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 17:27:50.049821 2026] [security2:error] [pid 7278:tid 7278] [client 103.198.154.186:19380] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.198.154.186 (+1 hits since last alert)|navarrete.ws|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "navarrete.ws"] [uri "/xmlrpc.php"] [unique_id "ai8c1q4JAcYcdJZdanjxjQAAACk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 20:25:11
(4 days ago)
(mod_security) mod_security (id:240335) triggered by 103.198.154.186 (103.198.154.186-pbb.net.pk): 1 ...
show more
(mod_security) mod_security (id:240335) triggered by 103.198.154.186 (103.198.154.186-pbb.net.pk): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 16:25:04.919459 2026] [security2:error] [pid 27857:tid 27857] [client 103.198.154.186:39877] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.198.154.186 (+1 hits since last alert)|stoneybluff.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "stoneybluff.com"] [uri "/xmlrpc.php"] [unique_id "ai8OIM5dKCycV-QqD3ooBQAAADk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TAY
2026-06-14 14:52:47
(5 days ago)
103.198.154.186 - - [14/Jun/2026:22:52:11 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5874 "-" "Jetpack/1 ...
show more
103.198.154.186 - - [14/Jun/2026:22:52:11 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5874 "-" "Jetpack/12.0; WordPress/6.4; http://site63227509.com"
103.198.154.186 - - [14/Jun/2026:22:52:23 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5874 "-" "WordPress.com; https://wordpress.com"
103.198.154.186 - - [14/Jun/2026:22:52:47 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5874 "-" "WordPress.com; https://wordpress.com"
...
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-14 09:21:16
(5 days ago)
(mod_security) mod_security (id:240335) triggered by 103.198.154.186 (103.198.154.186-pbb.net.pk): 1 ...
show more
(mod_security) mod_security (id:240335) triggered by 103.198.154.186 (103.198.154.186-pbb.net.pk): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 05:21:10.275776 2026] [security2:error] [pid 14507:tid 14521] [client 103.198.154.186:49570] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.198.154.186 (+1 hits since last alert)|tkfay.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "tkfay.com"] [uri "/xmlrpc.php"] [unique_id "ai5yhsukFiMoYk57ys6DzQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 07:47:27
(5 days ago)
(mod_security) mod_security (id:240335) triggered by 103.198.154.186 (103.198.154.186-pbb.net.pk): 1 ...
show more
(mod_security) mod_security (id:240335) triggered by 103.198.154.186 (103.198.154.186-pbb.net.pk): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 03:47:21.832267 2026] [security2:error] [pid 28544:tid 28544] [client 103.198.154.186:40211] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.198.154.186 (+1 hits since last alert)|zerotaxlab.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "zerotaxlab.com"] [uri "/xmlrpc.php"] [unique_id "ai5ciayZDmk9Dn6g6CW88gAAAGE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-06-13 19:03:04
(5 days ago)
trying wp-login.php/xmlrpc.php 33 times in 1 minutes
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-13 17:40:17
(5 days ago)
(mod_security) mod_security (id:240335) triggered by 103.198.154.186 (103.198.154.186-pbb.net.pk): 1 ...
show more
(mod_security) mod_security (id:240335) triggered by 103.198.154.186 (103.198.154.186-pbb.net.pk): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 13:40:12.031210 2026] [security2:error] [pid 17203:tid 17203] [client 103.198.154.186:32789] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.198.154.186 (+1 hits since last alert)|pastorjohndunning.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "pastorjohndunning.com"] [uri "/xmlrpc.php"] [unique_id "ai2V_GMhzi2vRVw8V1ktnwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack