🇺🇸
kosada.com
2026-08-30 17:37:17
(1 week ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
🇺🇸
TPI-Abuse
2026-08-23 18:49:58
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 103.104.214.61 (103-104-214-61.lmpl.net): 1 in ...
show more
(mod_security) mod_security (id:240335) triggered by 103.104.214.61 (103-104-214-61.lmpl.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 14:49:53.572400 2026] [security2:error] [pid 21117:tid 21117] [client 103.104.214.61:3277] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.104.214.61 (+1 hits since last alert)|fredlandia.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "fredlandia.com"] [uri "/xmlrpc.php"] [unique_id "aotA0eK-IWWRhpkxxHkt1AAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-23 17:47:52
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 103.104.214.61 (103-104-214-61.lmpl.net): 1 in ...
show more
(mod_security) mod_security (id:240335) triggered by 103.104.214.61 (103-104-214-61.lmpl.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 13:47:47.172306 2026] [security2:error] [pid 14828:tid 14828] [client 103.104.214.61:41205] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.104.214.61 (+1 hits since last alert)|fundingangelinvestors.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "fundingangelinvestors.com"] [uri "/xmlrpc.php"] [unique_id "aosyQ0UJf-qKsFOkOFktcAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
WeekendWeb
2026-08-23 15:11:49
(2 weeks ago)
Wordpress Vunerability attack
Web App Attack
🇺🇸
TPI-Abuse
2026-08-23 14:44:51
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 103.104.214.61 (103-104-214-61.lmpl.net): 1 in ...
show more
(mod_security) mod_security (id:240335) triggered by 103.104.214.61 (103-104-214-61.lmpl.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 10:44:44.732904 2026] [security2:error] [pid 1134:tid 1134] [client 103.104.214.61:22565] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.104.214.61 (+1 hits since last alert)|newlifecommunitycare.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "newlifecommunitycare.org"] [uri "/xmlrpc.php"] [unique_id "aosHXBRGZnNRRdQVvdtoVwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-23 13:41:48
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 103.104.214.61 (103-104-214-61.lmpl.net): 1 in ...
show more
(mod_security) mod_security (id:240335) triggered by 103.104.214.61 (103-104-214-61.lmpl.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 09:41:43.931648 2026] [security2:error] [pid 23108:tid 23108] [client 103.104.214.61:63182] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.104.214.61 (+1 hits since last alert)|wildlandconservancy.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "wildlandconservancy.com"] [uri "/xmlrpc.php"] [unique_id "aor4l4eiWjYv-Qm19dn0yQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-08-23 13:29:57
(2 weeks ago)
4.743 requests with url.path */xmlrpc.php
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-08-23 12:40:44
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 103.104.214.61 (103-104-214-61.lmpl.net): 1 in ...
show more
(mod_security) mod_security (id:240335) triggered by 103.104.214.61 (103-104-214-61.lmpl.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 08:40:36.036952 2026] [security2:error] [pid 5953:tid 5953] [client 103.104.214.61:32497] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.104.214.61 (+1 hits since last alert)|billwegener.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "billwegener.net"] [uri "/xmlrpc.php"] [unique_id "aorqRKMmHlIpf73c78iiJQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
ljo
2026-08-23 12:39:14
(2 weeks ago)
103.104.214.61 - - [23/Aug/2026:14:37:38 +0200] "POST /xmlrpc.php HTTP/1.1" 200 5498 "-" "Jetpack/12 ...
show more
103.104.214.61 - - [23/Aug/2026:14:37:38 +0200] "POST /xmlrpc.php HTTP/1.1" 200 5498 "-" "Jetpack/12.0; WordPress/6.2; http://site49474844.com"
103.104.214.61 - - [23/Aug/2026:14:37:49 +0200] "POST /xmlrpc.php HTTP/1.1" 200 5498 "-" "Jetpack/12.5; WordPress/6.2; http://site41895478.com"
103.104.214.61 - - [23/Aug/2026:14:37:59 +0200] "POST /xmlrpc.php HTTP/1.1" 200 5498 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.4)"
103.104.214.61 - - [23/Aug/2026:14:38:09 +0200] "POST /xmlrpc.php HTTP/1.1" 200 5498 "-" "Jetpack by WordPress.com"
103.104.214.61 - - [23/Aug/2026:14:38:21 +0200] "POST /xmlrpc.php HTTP/1.1" 200 5498 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.2)"
103.104.214.61 - - [23/Aug/2026:14:38:31 +0200] "POST /xmlrpc.php HTTP/1.1" 200 5498 "-" "WordPress.com; https://wordpress.com"
103.104.214.61 - - [23/Aug/2026:14:38:43 +0200] "POST /xmlrpc.php HTTP/1.1" 200 5498 "-" "WordPress.com; https://wordpress.com"
103.104.214.61 - - [23/Aug/2026:14:38:51 +0200]
...
show less
Web App Attack
Anonymous
2026-08-23 08:51:05
(2 weeks ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
Anonymous
2026-08-22 17:43:08
(2 weeks ago)
(wordpress) Failed wordpress login from 103.104.214.61 (PK/Pakistan/103-104-214-61.lmpl.net)
Brute-Force
Anonymous
2026-08-22 11:54:50
(2 weeks ago)
[server.tmg.gr] httpd-xmlrpc-post: sites=www.crisis-management2018.eu; logs=/var/log/httpd/domains/c ...
show more
[server.tmg.gr] httpd-xmlrpc-post: sites=www.crisis-management2018.eu; logs=/var/log/httpd/domains/crisis-management2018.eu.log; samples=/xmlrpc.php
show less
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-08-22 11:24:34
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 103.104.214.61 (103-104-214-61.lmpl.net): 1 in ...
show more
(mod_security) mod_security (id:240335) triggered by 103.104.214.61 (103-104-214-61.lmpl.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 07:24:26.672179 2026] [security2:error] [pid 21850:tid 21850] [client 103.104.214.61:9421] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.104.214.61 (+1 hits since last alert)|baselinesc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "baselinesc.com"] [uri "/xmlrpc.php"] [unique_id "aomG6iWcd5IWNF3SBgIaggAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-22 07:49:42
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 103.104.214.61 (103-104-214-61.lmpl.net): 1 in ...
show more
(mod_security) mod_security (id:240335) triggered by 103.104.214.61 (103-104-214-61.lmpl.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 03:49:38.954134 2026] [security2:error] [pid 6531:tid 6531] [client 103.104.214.61:55818] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.104.214.61 (+1 hits since last alert)|tcomputerguy.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "tcomputerguy.com"] [uri "/xmlrpc.php"] [unique_id "aolUkjxB43V_sJAMgb_s6AAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
ConsulHosting
2026-08-22 07:34:11
(2 weeks ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack