This IP address has been reported a total of
24
times from
20 distinct
sources.
112.198.104.220 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
[FriSep1811:34:02.7467682026][security2:error][pid1548511:tid1548637][client112.198.104.220:0]ModSec ...
show more[FriSep1811:34:02.7467682026][security2:error][pid1548511:tid1548637][client112.198.104.220:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"614\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"4-server.com\"][uri\"/xmlrpc.php\"][unique_id\"aq0Fiij4Pwqkn9jymCja-AAAAZY\"]
show less
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 112.198.104.220 (PH/Philippines/-): ...
show moreLF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 112.198.104.220 (PH/Philippines/-): 1 in the last 3600 secs
show less
Malicious web request: probing for secrets, traversal or a known exploit path | method: POST | path: ...
show moreMalicious web request: probing for secrets, traversal or a known exploit path | method: POST | path: /xmlrpc.php | ua: Mozilla/5.0 (Windows NT 10.0; arm64) AppleWebKit/537.36 (KHTML, like Gecko) Safari/15.0.0.0 Safari/537.36 | 2026-09-15 06:48 UTC
show less
[MonSep1404:44:03.5092432026][security2:error][pid1196504:tid1196618][client112.198.104.220:0]ModSec ...
show more[MonSep1404:44:03.5092432026][security2:error][pid1196504:tid1196618][client112.198.104.220:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"170\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"brunocampagna.com\"][uri\"/xmlrpc.php\"][unique_id\"aqdfc5fOgWK8mRmH68Ue5QAAANI\"]
show less
Automated honeypot detection. honeypot against a Next.js application. Paths: /xmlrpc.php. Blocked at ...
show moreAutomated honeypot detection. honeypot against a Next.js application. Paths: /xmlrpc.php. Blocked at the edge.
show less