๐บ๐ธ
TPI-Abuse
2026-06-24 17:11:25
(2 hours ago)
(mod_security) mod_security (id:240335) triggered by 103.72.85.48 (static-48-85-72-103.ebonenet.com) ...
show more
(mod_security) mod_security (id:240335) triggered by 103.72.85.48 (static-48-85-72-103.ebonenet.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 13:11:20.890300 2026] [security2:error] [pid 528:tid 528] [client 103.72.85.48:48346] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.72.85.48 (+1 hits since last alert)|stacyfarm.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "stacyfarm.com"] [uri "/xmlrpc.php"] [unique_id "ajwPuAT3STV3q06zIGdP_wAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-24 11:58:51
(8 hours ago)
(mod_security) mod_security (id:240335) triggered by 103.72.85.48 (static-48-85-72-103.ebonenet.com) ...
show more
(mod_security) mod_security (id:240335) triggered by 103.72.85.48 (static-48-85-72-103.ebonenet.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 07:58:42.489120 2026] [security2:error] [pid 7323:tid 7344] [client 103.72.85.48:46929] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.72.85.48 (+1 hits since last alert)|darrylrichards.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "darrylrichards.com"] [uri "/xmlrpc.php"] [unique_id "ajvGcsmtItfZt3zBtXRmegAAARM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Jason Howell
2026-06-24 10:32:02
(9 hours ago)
103.72.85.48 - - [24/Jun/2026:05:22:59 -0500] "POST /xmlrpc.php HTTP/1.1" 200 4775 "-" "Jetpack by W ...
show more
103.72.85.48 - - [24/Jun/2026:05:22:59 -0500] "POST /xmlrpc.php HTTP/1.1" 200 4775 "-" "Jetpack by WordPress.com"
103.72.85.48 - - [24/Jun/2026:05:25:06 -0500] "POST /xmlrpc.php HTTP/1.1" 200 4774 "-" "Jetpack/12.1; WordPress/6.4; http://site63690223.com"
103.72.85.48 - - [24/Jun/2026:05:27:47 -0500] "POST /xmlrpc.php HTTP/1.1" 200 4774 "-" "WordPress.com; https://wordpress.com"
103.72.85.48 - - [24/Jun/2026:05:29:55 -0500] "POST /xmlrpc.php HTTP/1.1" 200 4774 "-" "Jetpack/12.1; WordPress/6.3; http://site77287570.com"
103.72.85.48 - - [24/Jun/2026:05:32:02 -0500] "POST /xmlrpc.php HTTP/1.1" 200 4774 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.4)"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-24 10:27:21
(9 hours ago)
(mod_security) mod_security (id:240335) triggered by 103.72.85.48 (static-48-85-72-103.ebonenet.com) ...
show more
(mod_security) mod_security (id:240335) triggered by 103.72.85.48 (static-48-85-72-103.ebonenet.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 06:27:15.468645 2026] [security2:error] [pid 7386:tid 7386] [client 103.72.85.48:47404] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.72.85.48 (+1 hits since last alert)|americanureport.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "americanureport.com"] [uri "/xmlrpc.php"] [unique_id "ajuxAysIB40ZcIxXCtUymQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-24 09:55:14
(10 hours ago)
(mod_security) mod_security (id:240335) triggered by 103.72.85.48 (static-48-85-72-103.ebonenet.com) ...
show more
(mod_security) mod_security (id:240335) triggered by 103.72.85.48 (static-48-85-72-103.ebonenet.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 05:55:04.310122 2026] [security2:error] [pid 15967:tid 15967] [client 103.72.85.48:49230] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.72.85.48 (+1 hits since last alert)|soonerstone.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "soonerstone.com"] [uri "/xmlrpc.php"] [unique_id "ajupeI6gncf1DIV4awveCQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
dbmwebdesign
2026-06-24 06:40:20
(13 hours ago)
WordPress login brute-force detected by Fail2Ban in plesk-wordpress jail
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-23 23:48:31
(20 hours ago)
(mod_security) mod_security (id:240335) triggered by 103.72.85.48 (static-48-85-72-103.ebonenet.com) ...
show more
(mod_security) mod_security (id:240335) triggered by 103.72.85.48 (static-48-85-72-103.ebonenet.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 23 19:48:23.663613 2026] [security2:error] [pid 27204:tid 27212] [client 103.72.85.48:47905] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.72.85.48 (+1 hits since last alert)|minutosrobados.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "minutosrobados.com"] [uri "/xmlrpc.php"] [unique_id "ajsbR8SlSBzuI02NpaEY-gAAAMY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-23 21:39:25
(22 hours ago)
(mod_security) mod_security (id:240335) triggered by 103.72.85.48 (static-48-85-72-103.ebonenet.com) ...
show more
(mod_security) mod_security (id:240335) triggered by 103.72.85.48 (static-48-85-72-103.ebonenet.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 23 17:39:15.723911 2026] [security2:error] [pid 14953:tid 14982] [client 103.72.85.48:49067] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.72.85.48 (+1 hits since last alert)|bortec-corp.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "bortec-corp.com"] [uri "/xmlrpc.php"] [unique_id "ajr9AxGZKSVJ-pySi-ApJAAAAFE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
wlt-blocker
2026-06-23 21:26:28
(22 hours ago)
Unauthorized access to webpage admin
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-23 19:27:14
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 103.72.85.48 (static-48-85-72-103.ebonenet.com) ...
show more
(mod_security) mod_security (id:225170) triggered by 103.72.85.48 (static-48-85-72-103.ebonenet.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 23 15:27:09.011740 2026] [security2:error] [pid 24692:tid 24692] [client 103.72.85.48:49073] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||tonytremblayauthor.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "tonytremblayauthor.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajreDaw3kq0KFn8QillqOgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TAY
2026-06-23 15:52:14
(1 day ago)
103.72.85.48 - - [23/Jun/2026:23:51:53 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5887 "-" "WordPress.co ...
show more
103.72.85.48 - - [23/Jun/2026:23:51:53 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5887 "-" "WordPress.com; https://wordpress.com"
103.72.85.48 - - [23/Jun/2026:23:52:03 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5887 "-" "Jetpack/12.1; WordPress/6.1; http://site85421276.com"
103.72.85.48 - - [23/Jun/2026:23:52:14 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5887 "-" "Jetpack/12.5; WordPress/6.1; http://site26940633.com"
...
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-23 15:28:48
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 103.72.85.48 (static-48-85-72-103.ebonenet.com) ...
show more
(mod_security) mod_security (id:240335) triggered by 103.72.85.48 (static-48-85-72-103.ebonenet.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 23 11:28:40.844612 2026] [security2:error] [pid 29346:tid 29346] [client 103.72.85.48:48302] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.72.85.48 (+1 hits since last alert)|sharawi-gum.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "sharawi-gum.com"] [uri "/xmlrpc.php"] [unique_id "ajqmKLacmcMjIZ9Usy0l5AAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack