๐บ๐ธ
TPI-Abuse
2026-07-22 14:39:15
(1 hour ago)
(mod_security) mod_security (id:240335) triggered by 103.93.104.208 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 103.93.104.208 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 10:39:08.860196 2026] [security2:error] [pid 1632522:tid 1632522] [client 103.93.104.208:56892] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.93.104.208 (+1 hits since last alert)|ideaofauniversity.website|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "ideaofauniversity.website"] [uri "/xmlrpc.php"] [unique_id "amDWDJ9sRHLvRqXwZd4wSgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-22 14:32:03
(1 hour ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐ณ๐ฑ
Site.eu
2026-07-22 13:22:11
(2 hours ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐ฉ๐ช
pscriptos
2026-07-22 13:19:36
(3 hours ago)
{"ClientAddr":"103.93.104.208:64143","ClientHost":"103.93.104.208","ClientPort":"64143","ClientUsern ...
show more
{"ClientAddr":"103.93.104.208:64143","ClientHost":"103.93.104.208","ClientPort":"64143","ClientUsername":"-","DownstreamContentSize":418,"DownstreamStatus":403,"Duration":169862915,"OriginContentSize":418,"OriginDuration":166653385,"OriginStatus":403,"Overhead":3209530,"RequestAddr":"www.cleveradmin.de","RequestContentSize":705,"RequestCount":1742259,"RequestHost":"www.cleveradmin.de","RequestMethod":"POST","RequestPath":"/xmlrpc.php","RequestPort":"-","RequestProtocol":"HTTP/1.1","RequestScheme":"https","RetryAttempts":0,"RouterName":"cleveradmin-www-websecure@file","ServiceAddr":"172.16.80.10:80","ServiceName":"cleveradmin-www@file","ServiceURL":"http://172.16.80.10:80","StartLocal":"2026-07-22T15:19:16.520784222+02:00","StartUTC":"2026-07-22T13:19:16.520784222Z","TLSCipher":"TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256","TLSVersion":"1.2","entryPointName":"websecure","level":"info","msg":"","time":"2026-07-22T15:19:16+02:00"}
{"ClientAddr":"103.93.104.208:64143","ClientHost":"103.93.104.20
...
show less
Brute-Force
Web App Attack
๐ช๐ธ
masterguru
2026-07-22 12:19:09
(4 hours ago)
(xmlrpc) Failed xmlrpc access from 103.93.104.208 (IN/India/-): 5 in the last 3600 secs (0-122)
Hacking
๐ช๐ธ
alferez
2026-07-22 11:53:28
(4 hours ago)
xmlrpc.php attack DOS
Hacking
Exploited Host
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-07-22 11:48:05
(4 hours ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
IN/India/-
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 11:18:39
(5 hours ago)
(mod_security) mod_security (id:240335) triggered by 103.93.104.208 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 103.93.104.208 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 07:18:33.806518 2026] [security2:error] [pid 674138:tid 674138] [client 103.93.104.208:62341] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.93.104.208 (+1 hits since last alert)|brushmileage.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "brushmileage.org"] [uri "/xmlrpc.php"] [unique_id "amCnCbXMdoy0U127yify3gAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 09:16:34
(7 hours ago)
(mod_security) mod_security (id:240335) triggered by 103.93.104.208 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 103.93.104.208 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 05:16:27.557861 2026] [security2:error] [pid 4147294:tid 4147294] [client 103.93.104.208:282] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.93.104.208 (+1 hits since last alert)|eye7graphics.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "eye7graphics.com"] [uri "/xmlrpc.php"] [unique_id "amCKa6dw-SsfsJ69WKC_6wAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-22 08:06:05
(8 hours ago)
Trying to access config files
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 06:22:56
(9 hours ago)
(mod_security) mod_security (id:240335) triggered by 103.93.104.208 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 103.93.104.208 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 02:22:50.190184 2026] [security2:error] [pid 380252:tid 380252] [client 103.93.104.208:23759] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.93.104.208 (+1 hits since last alert)|stellabluesales.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "stellabluesales.com"] [uri "/xmlrpc.php"] [unique_id "amBhupaUxH4AC2009-omAAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-07-22 05:53:19
(10 hours ago)
[WedJul2207:53:16.4074222026][security2:error][pid3720017:tid3720056][client103.93.104.208:0]ModSecu ...
show more
[WedJul2207:53:16.4074222026][security2:error][pid3720017:tid3720056][client103.93.104.208:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"170\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"sito-online.ch\"][uri\"/xmlrpc.php\"][unique_id\"amBazFWuDLH6Uvq_A2nLEgAAARM\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 05:44:33
(10 hours ago)
(mod_security) mod_security (id:240335) triggered by 103.93.104.208 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 103.93.104.208 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 01:44:27.461242 2026] [security2:error] [pid 381201:tid 381201] [client 103.93.104.208:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.93.104.208 (+1 hits since last alert)|bbproductionsonline.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "bbproductionsonline.com"] [uri "/xmlrpc.php"] [unique_id "amBYu8uxVczvcX62sk17IAAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-07-21 15:05:46
(1 day ago)
CrowdSec: crowdsecurity/http-bf-wordpress_bf_xmlrpc | req: /xmlrpc.php | UA: WordPress.com; https:// ...
show more
CrowdSec: crowdsecurity/http-bf-wordpress_bf_xmlrpc | req: /xmlrpc.php | UA: WordPress.com; https://wordpress.com
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 14:36:45
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 103.93.104.208 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 103.93.104.208 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 10:36:40.568958 2026] [security2:error] [pid 4995:tid 4995] [client 103.93.104.208:818] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.93.104.208 (+1 hits since last alert)|desertalfas.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "desertalfas.org"] [uri "/xmlrpc.php"] [unique_id "al-D-DE3m95h3Ci9f9GvzQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack