AbuseIPDB » 125.163.248.121
125.163.248.121 was found in our database!
This IP was reported 8 times. Confidence of
Abuse
is 22% : ?
ISP
PT TELKOM INDONESIA
Usage Type
Fixed Line ISP
ASN
AS7713
Domain Name
telkom.co.id
Country
๐ฎ๐ฉ
Indonesia
City
Sidoarjo, East Java
IP info including ISP, Usage Type, and Location provided
by IPInfo . Updated weekly.
IP Abuse Reports for 125.163.248.121 :
This IP address has been reported a total of
8
times from
4 distinct
sources.
125.163.248.121 was first reported on
June 5th 2026 , and the most recent report was
2 weeks ago .
Old Reports:
The most recent abuse report for this IP address is from
2 weeks ago
. It is possible that this IP is no longer involved in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
๐ช๐ธ
masterguru
2026-06-09 05:53:53
(2 weeks ago)
(xmlrpc) Failed xmlrpc access from 125.163.248.121 (ID/Indonesia/-): 5 in the last 3600 secs (0-122)
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-09 01:49:06
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 125.163.248.121 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 125.163.248.121 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 21:48:59.523033 2026] [security2:error] [pid 9864:tid 9864] [client 125.163.248.121:64099] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 125.163.248.121 (+1 hits since last alert)|tomkatkaraoke.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "tomkatkaraoke.com"] [uri "/xmlrpc.php"] [unique_id "aidxC4BMzJdugSCRKHAkpgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 00:50:42
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 125.163.248.121 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 125.163.248.121 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 20:50:34.926480 2026] [security2:error] [pid 28872:tid 28872] [client 125.163.248.121:62391] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 125.163.248.121 (+1 hits since last alert)|versallis.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "versallis.com"] [uri "/xmlrpc.php"] [unique_id "aidjWjEJDSYkSCZVaG9TZgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-09 00:12:17
(2 weeks ago)
[redacted] 125.163.248.121 - - [09/Jun/2026:02:11:34 +0200] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" ...
show more
[redacted] 125.163.248.121 - - [09/Jun/2026:02:11:34 +0200] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" "Jetpack by WordPress.com"
[redacted] 125.163.248.121 - - [09/Jun/2026:02:11:44 +0200] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" "Jetpack by WordPress.com (Jetpack 12.5; WordPress 6.1)"
[redacted] 125.163.248.121 - - [09/Jun/2026:02:11:55 +0200] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" "WordPress.com; https://wordpress.com"
[redacted] 125.163.248.121 - - [09/Jun/2026:02:12:06 +0200] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" "Jetpack/13.0; WordPress/6.1; http://site60233049.com"
[redacted] 125.163.248.121 - - [09/Jun/2026:02:12:16 +0200] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" "WordPress.com; https://wordpress.com"
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 00:25:41
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 125.163.248.121 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 125.163.248.121 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 20:25:33.989804 2026] [security2:error] [pid 8116:tid 8134] [client 125.163.248.121:55586] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 125.163.248.121 (+1 hits since last alert)|nabsci.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "nabsci.com"] [uri "/xmlrpc.php"] [unique_id "aiYL_Y8MaVe3iSiRp_s8swAAAVA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-06-05 07:02:55
(3 weeks ago)
xmlrpc request blocked, no referer. Pattern match "xmlrpc.php" at REQUEST_URI. (88010-201)
Hacking
Anonymous
2026-06-05 03:58:22
(3 weeks ago)
[da.kdns.gr] httpd-xmlrpc-post: sites=diadromi.com; logs=/var/log/httpd/domains/diadromi.com.log; sa ...
show more
[da.kdns.gr] httpd-xmlrpc-post: sites=diadromi.com; logs=/var/log/httpd/domains/diadromi.com.log; samples=/xmlrpc.php
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-05 01:46:07
(3 weeks ago)
(mod_security) mod_security (id:240335) triggered by 125.163.248.121 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 125.163.248.121 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 21:45:57.893463 2026] [security2:error] [pid 13865:tid 13865] [client 125.163.248.121:52214] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 125.163.248.121 (+1 hits since last alert)|travelwithjenniferb.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "travelwithjenniferb.com"] [uri "/xmlrpc.php"] [unique_id "aiIqVVbHJzh62Ggzd6v-CgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Showing 1 to
8
of 8 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ
Recently Reported IPs: