๐บ๐ธ
kosada.com
2026-08-26 09:27:23
(1 day ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-24 11:48:18
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 103.3.222.130 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 103.3.222.130 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 07:48:13.540009 2026] [security2:error] [pid 2987:tid 3007] [client 103.3.222.130:22268] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.3.222.130 (+1 hits since last alert)|vancekelly.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "vancekelly.com"] [uri "/xmlrpc.php"] [unique_id "aowvfa2GOyfrdxks29y7EwAAAEw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-08-24 11:44:27
(3 days ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 15:20:41
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 103.3.222.130 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 103.3.222.130 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 11:20:35.823695 2026] [security2:error] [pid 10642:tid 10642] [client 103.3.222.130:26307] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.3.222.130 (+1 hits since last alert)|globalsolutions.technology|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "globalsolutions.technology"] [uri "/xmlrpc.php"] [unique_id "aosPwwuIO4oDGSTW88SWTAAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
xmission.com
2026-08-06 10:47:54
(3 weeks ago)
Blocked by UFW (TCP on 60973)
Source port: 27522
TTL: 108
Packet length: 52
TOS: 0x08
This report ( ...
show more
Blocked by UFW (TCP on 60973)
Source port: 27522
TTL: 108
Packet length: 52
TOS: 0x08
This report (for 103.3.222.130) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐ฎ๐ฉ
sockominfo
2026-07-08 08:00:53
(1 month ago)
User login to application from malicious IP 103.3.222.130.. Threat Score: 4.2/10 (MEDIUM). Confidenc ...
show more
User login to application from malicious IP 103.3.222.130.. Threat Score: 4.2/10 (MEDIUM). Confidence: 40%. CVSS v3.1: 0/10 (None). CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:N. Bayesian Probability: 68%. MITRE ATT&CK: T1016 (System Network Configuration Discovery). Tactic: TA0001. Freshness: Fresh. Source Reputation: UNKNOWN. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-07-08 07:00:54
(1 month ago)
User login to application from malicious IP 103.3.222.130.. Threat Score: 4.3/10 (MEDIUM). Confidenc ...
show more
User login to application from malicious IP 103.3.222.130.. Threat Score: 4.3/10 (MEDIUM). Confidence: 40%. CVSS v3.1: 0/10 (None). CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:N. Bayesian Probability: 68%. MITRE ATT&CK: T1016 (System Network Configuration Discovery). Tactic: TA0001. Freshness: Fresh. Source Reputation: UNKNOWN. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-07-08 06:00:09
(1 month ago)
User login to application from malicious IP 103.3.222.130.. Threat Score: 0/10 (INFORMATIONAL). Repo ...
show more
User login to application from malicious IP 103.3.222.130.. Threat Score: 0/10 (INFORMATIONAL). Reported by TangerangKota-CSIRT
show less
Hacking
Web App Attack
๐ฐ๐ท
zlhIcd
2026-06-26 12:20:18
(2 months ago)
103.3.222.130 - - [16/Jun/2026:10:34:43 +0900] "GET /pcwiki/index.php?days=14&from=20251223220453&hi ...
show more
103.3.222.130 - - [16/Jun/2026:10:34:43 +0900] "GET /pcwiki/index.php?days=14&from=20251223220453&hideanons=1&hideminor=1&hidemyself=1&title=%ED%8A%B9%EC%88%98%EA%B8%B0%EB%8A%A5:%EB%A7%81%ED%81%AC%EC%B5%9C%EA%B7%BC%EB%B0%94%EB%80%9C HTTP/1.1" 404 460 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 15_3_0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.6533.72 Safari/537.36"
...
show less
Web Spam
SQL Injection
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-06-18 23:00:09
(2 months ago)
User login to application from malicious IP 103.3.222.130.. Threat Score: 0/10 (INFORMATIONAL). Repo ...
show more
User login to application from malicious IP 103.3.222.130.. Threat Score: 0/10 (INFORMATIONAL). Reported by TangerangKota-CSIRT
show less
Hacking
Web App Attack
๐ช๐ธ
librebit
2026-03-18 07:05:14
(5 months ago)
Brute force
Brute-Force
๐น๐ท
rtbh.com.tr
2026-03-17 20:12:07
(5 months ago)
list.rtbh.com.tr report: tcp/0
Brute-Force
๐น๐ท
rtbh.com.tr
2026-03-16 20:12:05
(5 months ago)
list.rtbh.com.tr report: tcp/0
Brute-Force
๐ซ๐ท
Papy Abuse
2026-03-16 14:47:33
(5 months ago)
postfix-sasl
Brute-Force
Anonymous
2026-03-16 09:44:12
(5 months ago)
$f2bV_matches
Email Spam
Brute-Force