๐บ๐ธ
TPI-Abuse
2026-07-27 14:15:37
(7 hours ago)
(mod_security) mod_security (id:240335) triggered by 103.208.104.55 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 103.208.104.55 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 10:15:29.999549 2026] [security2:error] [pid 1512854:tid 1512854] [client 103.208.104.55:22920] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.208.104.55 (+1 hits since last alert)|midcityrotary.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "midcityrotary.org"] [uri "/xmlrpc.php"] [unique_id "amdoAQ4g8-WbBjWQs5SAjwAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-07-27 10:20:42
(10 hours ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-27 10:05:55
(11 hours ago)
Fail2Ban: WordPress XML-RPC brute-force attack detected.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 09:07:48
(12 hours ago)
(mod_security) mod_security (id:240335) triggered by 103.208.104.55 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 103.208.104.55 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 05:07:38.610496 2026] [security2:error] [pid 27375:tid 27375] [client 103.208.104.55:20721] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.208.104.55 (+1 hits since last alert)|marshdcs.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "marshdcs.com"] [uri "/xmlrpc.php"] [unique_id "amcf2t0UN_PmPnhIYNLsIQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
BlueWire Hosting
2026-07-27 06:52:21
(14 hours ago)
Wordpress brute force attempt
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 05:07:15
(16 hours ago)
(mod_security) mod_security (id:240335) triggered by 103.208.104.55 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 103.208.104.55 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 01:07:09.739767 2026] [security2:error] [pid 4123860:tid 4123869] [client 103.208.104.55:39792] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.208.104.55 (+1 hits since last alert)|leadingedgesupply.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "leadingedgesupply.com"] [uri "/xmlrpc.php"] [unique_id "ambnfdwD5fwbr1lHKi7jNgAAAEg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-25 13:53:57
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 103.208.104.55 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 103.208.104.55 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 09:53:53.268750 2026] [security2:error] [pid 1679211:tid 1679211] [client 103.208.104.55:42745] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.208.104.55 (+1 hits since last alert)|saynotoofland.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "saynotoofland.org"] [uri "/xmlrpc.php"] [unique_id "amS_8buPEVSyIAZArZeI3AAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-25 12:50:48
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 103.208.104.55 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 103.208.104.55 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 08:50:44.895626 2026] [security2:error] [pid 1673427:tid 1673427] [client 103.208.104.55:42685] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.208.104.55 (+1 hits since last alert)|evelynkay.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "evelynkay.com"] [uri "/xmlrpc.php"] [unique_id "amSxJOrzKwF1mmj-XnJ2-AAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
neckaralb-admin.de
2026-07-25 12:17:36
(2 days ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐ฎ๐น
CoreTech srl
2026-07-25 09:38:56
(2 days ago)
cloudlinux2 fail2ban: 2026-07-25 11:34:20,744 fail2ban.filter [1816]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-07-25 11:34:20,744 fail2ban.filter [1816]: INFO [plesk-modsecurity] Found 103.208.104.55 - 2026-07-25 11:34:20cloudlinux2 fail2ban: 2026-07-25 11:34:31,425 fail2ban.filter [1816]: INFO [plesk-modsecurity] Found 103.208.104.55 - 2026-07-25 11:34:31cloudlinux2 fail2ban: 2026-07-25 11:34:31,725 fail2ban.actions [1816]: NOTICE [plesk-modsecurity] Ban 103.208.104.55cloudlinux2 fail2ban: 2026-07-25 11:34:31,731 fail2ban.filter [1816]: INFO [recidive] Found 103.208.104.55 - 2026-07-25 11:34:31cloudlinux2 fail2ban: 2026-07-25 11:36:11,125 fail2ban.filter [1816]: INFO [plesk-modsecurity] Found 49.37.11.179 - 2026-07-25 11:36:11cloudlinux2 fail2ban: 2026-07-25 11:36:21,879 fail2ban.actions [1816]: NOTICE [plesk-modsecurity] Ban 49.37.11.179cloudlinux2 fail2ban: 2026-07-25 11:36:21,885 fail2ban.filter [1816]: INFO [recidive] Found 49.37.11.179 - 2026-07-25 11:36:21cloudlinux2 fail2ban: 2026-07-25 11:36:21,680 fail2ban.filte
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-25 08:04:53
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 103.208.104.55 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 103.208.104.55 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 04:04:47.496930 2026] [security2:error] [pid 1030803:tid 1030803] [client 103.208.104.55:9294] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.208.104.55 (+1 hits since last alert)|yuichiro.us|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "yuichiro.us"] [uri "/xmlrpc.php"] [unique_id "amRuHzhF1zX_WI62Xf9UggAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
integrantservices.com
2026-07-25 08:02:43
(2 days ago)
(wordpress) Failed wordpress login from 103.208.104.55 (IN/India/-)
Brute-Force
Anonymous
2026-07-25 05:26:46
(2 days ago)
WordPress Brute Force
Brute-Force
๐บ๐ธ
Dolphi
2026-07-24 14:00:04
(3 days ago)
Excessive POST /xmlrpc.php requests
Brute-Force
Web App Attack
๐ฉ๐ช
wpadm4
2026-07-24 13:18:13
(3 days ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack