๐บ๐ธ
TPI-Abuse
2026-06-25 07:52:03
(1 hour ago)
(mod_security) mod_security (id:240335) triggered by 103.208.105.130 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 103.208.105.130 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 25 03:51:58.069702 2026] [security2:error] [pid 22758:tid 22758] [client 103.208.105.130:27289] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.208.105.130 (+1 hits since last alert)|csm-dtc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "csm-dtc.com"] [uri "/xmlrpc.php"] [unique_id "ajzeHqOQ3AV6nK9BaX6YNgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-06-25 05:05:29
(4 hours ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-24 10:51:45
(22 hours ago)
(mod_security) mod_security (id:240335) triggered by 103.208.105.130 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 103.208.105.130 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 06:51:40.263462 2026] [security2:error] [pid 13967:tid 13967] [client 103.208.105.130:21669] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.208.105.130 (+1 hits since last alert)|pearlhomesfw.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "pearlhomesfw.com"] [uri "/xmlrpc.php"] [unique_id "aju2vPqv5_-DWG2eLxrkJwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2026-06-24 10:49:36
(22 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
Anonymous
2026-06-24 09:18:58
(1 day ago)
[redacted] 103.208.105.130 - - [24/Jun/2026:11:18:15 +0200] "POST /xmlrpc.php HTTP/1.1" 403 831 "-" ...
show more
[redacted] 103.208.105.130 - - [24/Jun/2026:11:18:15 +0200] "POST /xmlrpc.php HTTP/1.1" 403 831 "-" "WordPress.com; https://wordpress.com"
[redacted] 103.208.105.130 - - [24/Jun/2026:11:18:26 +0200] "POST /xmlrpc.php HTTP/1.1" 403 832 "-" "Jetpack/12.5; WordPress/6.4; http://site15920437.com"
[redacted] 103.208.105.130 - - [24/Jun/2026:11:18:36 +0200] "POST /xmlrpc.php HTTP/1.1" 403 832 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.2)"
[redacted] 103.208.105.130 - - [24/Jun/2026:11:18:47 +0200] "POST /xmlrpc.php HTTP/1.1" 403 832 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.2)"
[redacted] 103.208.105.130 - - [24/Jun/2026:11:18:58 +0200] "POST /xmlrpc.php HTTP/1.1" 403 831 "-" "Jetpack by WordPress.com (Jetpack 12.5; WordPress 6.4)"
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-24 07:06:34
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 103.208.105.130 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 103.208.105.130 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 03:06:27.653267 2026] [security2:error] [pid 13450:tid 13450] [client 103.208.105.130:26885] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.208.105.130 (+1 hits since last alert)|billwegener.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "billwegener.net"] [uri "/xmlrpc.php"] [unique_id "ajuB88yKJH8H0YY7CmSzGQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-24 06:04:03
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 103.208.105.130 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 103.208.105.130 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 02:03:56.805336 2026] [security2:error] [pid 19378:tid 19378] [client 103.208.105.130:27068] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.208.105.130 (+1 hits since last alert)|balirealestateadvertiser.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "balirealestateadvertiser.com"] [uri "/xmlrpc.php"] [unique_id "ajtzTE99hQmyupcVK-smOgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-23 14:48:24
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 103.208.105.130 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 103.208.105.130 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 23 10:48:20.311935 2026] [security2:error] [pid 18989:tid 18989] [client 103.208.105.130:34409] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.208.105.130 (+1 hits since last alert)|mortuarymessageservices.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "mortuarymessageservices.com"] [uri "/xmlrpc.php"] [unique_id "ajqctAnRJS3wpnq61FJfDQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-06-23 12:44:15
(1 day ago)
xmlrpc request blocked, no referer. Pattern match "xmlrpc.php" at REQUEST_URI. (88010-201)
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-22 05:27:10
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 103.208.105.130 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 103.208.105.130 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 22 01:26:54.711073 2026] [security2:error] [pid 5119:tid 5217] [client 103.208.105.130:5878] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.208.105.130 (+1 hits since last alert)|vancekelly.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "vancekelly.com"] [uri "/xmlrpc.php"] [unique_id "ajjHngZdV1k-rop2HWx0jQAAAEU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-20 10:30:40
(4 days ago)
(mod_security) mod_security (id:240335) triggered by 103.208.105.130 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 103.208.105.130 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 20 06:30:36.047674 2026] [security2:error] [pid 14332:tid 14332] [client 103.208.105.130:9657] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.208.105.130 (+1 hits since last alert)|truthsabouthealthcare.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "truthsabouthealthcare.com"] [uri "/xmlrpc.php"] [unique_id "ajZrzCsm1FsSvu2lb143ZAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-06-20 10:28:36
(4 days ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐ซ๐ท
security.rdmc.fr
2026-03-31 02:03:19
(2 months ago)
VoIP Attack proto:UDP src:40910 dst:5060
Port Scan
Fraud VoIP
Anonymous
2026-03-30 23:24:52
(2 months ago)
Unauthorized connection attempt
Port Scan
Hacking
Exploited Host
๐บ๐ธ
TPI-Abuse
2026-02-28 07:17:09
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 103.208.105.130 (ws130-105.208.103.rcil.gov.in) ...
show more
(mod_security) mod_security (id:225170) triggered by 103.208.105.130 (ws130-105.208.103.rcil.gov.in): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 28 02:17:00.287617 2026] [security2:error] [pid 21266:tid 21266] [client 103.208.105.130:16507] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||reyadecostarica.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "reyadecostarica.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aaKWbLizdCkLLdQvxk_d2QAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack