AbuseIPDB » 103.98.63.228
103.98.63.228 was found in our database!
This IP was reported 9 times. Confidence of
Abuse
is 17% : ?
ISP
Thamizhaga Internet Communications Private Limited
Usage Type
Fixed Line ISP
ASN
AS136336
Domain Name
ticfiber.in
Country
๐ฎ๐ณ
India
City
Tharangambadi, Tamil Nadu
IP info including ISP, Usage Type, and Location provided
by IPInfo . Updated weekly.
IP Abuse Reports for 103.98.63.228 :
This IP address has been reported a total of
9
times from
7 distinct
sources.
103.98.63.228 was first reported on
January 2nd 2021 , and the most recent report was
1 week ago .
Old Reports:
The most recent abuse report for this IP address is from
1 week ago
. It is possible that this IP is no longer involved in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
๐บ๐ธ
TPI-Abuse
2026-06-03 06:23:02
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 103.98.63.228 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 103.98.63.228 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 02:22:58.317823 2026] [security2:error] [pid 5788:tid 5788] [client 103.98.63.228:26855] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.98.63.228 (+1 hits since last alert)|medusakenya.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "medusakenya.com"] [uri "/xmlrpc.php"] [unique_id "ah_IQjbI0MZvaTcEyXLSqAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-03 05:50:27
(1 week ago)
103.98.63.228 - - [03/Jun/2026:07:50:05 +0200] "POST /xmlrpc.php HTTP/1.1" 200 593 "-" "Jetpack by W ...
show more
103.98.63.228 - - [03/Jun/2026:07:50:05 +0200] "POST /xmlrpc.php HTTP/1.1" 200 593 "-" "Jetpack by WordPress.com"
103.98.63.228 - - [03/Jun/2026:07:50:06 +0200] "POST /xmlrpc.php HTTP/1.1" 200 403 "-" "Jetpack by WordPress.com"
103.98.63.228 - - [03/Jun/2026:07:50:14 +0200] "POST /xmlrpc.php HTTP/1.1" 200 593 "-" "WordPress.com; https://wordpress.com"
103.98.63.228 - - [03/Jun/2026:07:50:16 +0200] "POST /xmlrpc.php HTTP/1.1" 200 403 "-" "WordPress.com; https://wordpress.com"
103.98.63.228 - - [03/Jun/2026:07:50:25 +0200] "POST /xmlrpc.php HTTP/1.1" 200 593 "-" "Jetpack/12.0; WordPress/6.3; http://site34770909.com"
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-03 05:24:23
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 103.98.63.228 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 103.98.63.228 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 01:24:18.636831 2026] [security2:error] [pid 25075:tid 25075] [client 103.98.63.228:18017] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.98.63.228 (+1 hits since last alert)|method1.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "method1.net"] [uri "/xmlrpc.php"] [unique_id "ah-6gv-PaupVafKtJ99zPwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Xarcotic
2026-05-11 15:45:54
(1 month ago)
SSH login on honeypot.
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-03-11 02:22:15
(3 months ago)
(mod_security) mod_security (id:211030) triggered by 103.98.63.228 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:211030) triggered by 103.98.63.228 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 10 22:22:07.460201 2026] [security2:error] [pid 23128:tid 23128] [client 103.98.63.228:21157] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at ARGS. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "17"] [id "211030"] [rev "3"] [msg "COMODO WAF: LDAP Injection Attack||www.powerkiteforum.com|F|2"] [data "Matched Data: (('~'||( found within ARGS: 0"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "www.powerkiteforum.com"] [uri "/viewthread.php"] [unique_id "abDRz_rsC00_4_c5G6QRcgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
exxos
2025-09-18 15:03:01
(8 months ago)
HTTP1.x attacks
DDoS Attack
๐ฉ๐ช
IP Analyzer
2024-01-07 21:30:31
(2 years ago)
Unauthorized connection attempt from IP address 103.98.63.228 on Port 445(SMB)
Port Scan
๐ฒ๐พ
Sean64
2021-06-28 01:59:16
(4 years ago)
Jun 28 13:59:15 sean postfix/smtpd[3260490]: NOQUEUE: reject: RCPT from unknown[103.98.63.228]: 554 ...
show more
Jun 28 13:59:15 sean postfix/smtpd[3260490]: NOQUEUE: reject: RCPT from unknown[103.98.63.228]: 554 5.7.1 Service unavailable; Client host [103.98.63.228] blocked using zen.spamhaus.org; https://www.spamhaus.org/query/ip/103.98.63.228 / https://www.spamhaus.org/sbl/query/SBLCSS; from=<[email protected] > to=<[email protected] > proto=ESMTP helo=<[103.98.63.228]>
...
show less
Email Spam
Brute-Force
๐ฉ๐ช
Hiffo
2021-01-02 06:24:56
(5 years ago)
1609586696 - 01/02/2021 12:24:56 Host: 103.98.63.228/103.98.63.228 Port: 445 TCP Blocked
Port Scan
Showing 1 to
9
of 9 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ
Recently Reported IPs: