Anonymous
2026-09-03 16:38:21
(3 days ago)
IP matched detection query 50 and more bad rqs apache.
Hacking
Bad Web Bot
Brute-Force
Web App Attack
🇩🇪
abdubhai
2026-09-03 13:33:44
(3 days ago)
103.153.130.45 - - [03/Sep/2026:
...
Brute-Force
🇺🇸
lostswordfish.com
2026-08-27 11:26:07
(1 week ago)
Wordfence waf block on pameganslaw
Web App Attack
🇺🇸
kosada.com
2026-08-25 15:12:42
(1 week ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
🇩🇪
ghostwarriors
2026-08-23 10:20:52
(2 weeks ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FD-IX
2026-08-23 10:17:01
(2 weeks ago)
Fail2Ban: WordPress XML-RPC brute-force attack detected.
Bad Web Bot
Web App Attack
🇩🇪
konseptit
2026-08-12 13:41:02
(3 weeks ago)
(wordpress) Failed wordpress login from 103.153.130.45 (BD/Bangladesh/-)
Brute-Force
Anonymous
2026-08-10 10:12:45
(3 weeks ago)
[redacted] 103.153.130.45 - - [10/Aug/2026:12:12:02 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" " ...
show more
[redacted] 103.153.130.45 - - [10/Aug/2026:12:12:02 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 103.153.130.45 - - [10/Aug/2026:12:12:12 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.2)"
[redacted] 103.153.130.45 - - [10/Aug/2026:12:12:23 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 103.153.130.45 - - [10/Aug/2026:12:12:34 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.2)"
[redacted] 103.153.130.45 - - [10/Aug/2026:12:12:44 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.1; WordPress/6.2; http://site30535255.com"
...
show less
Hacking
Web App Attack
Anonymous
2026-08-01 07:04:09
(1 month ago)
[redacted] 103.153.130.45 - - [01/Aug/2026:09:03:26 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" " ...
show more
[redacted] 103.153.130.45 - - [01/Aug/2026:09:03:26 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 103.153.130.45 - - [01/Aug/2026:09:03:36 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.4)"
[redacted] 103.153.130.45 - - [01/Aug/2026:09:03:47 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.5; WordPress 6.2)"
[redacted] 103.153.130.45 - - [01/Aug/2026:09:03:57 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.0; WordPress/6.1; http://site97653585.com"
[redacted] 103.153.130.45 - - [01/Aug/2026:09:04:08 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
...
show less
Hacking
Web App Attack
🇺🇸
kosada.com
2026-07-31 06:12:08
(1 month ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
🇺🇸
TPI-Abuse
2026-07-27 07:07:18
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 103.153.130.45 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 103.153.130.45 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 03:07:12.085172 2026] [security2:error] [pid 2027554:tid 2027666] [client 103.153.130.45:54514] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.153.130.45 (+1 hits since last alert)|thecraftsycat.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "thecraftsycat.com"] [uri "/xmlrpc.php"] [unique_id "amcDoLDxnYCJnHxdRqiXMwAAAkw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-19 11:21:49
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 103.153.130.45 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 103.153.130.45 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 07:21:46.625542 2026] [security2:error] [pid 3629472:tid 3629472] [client 103.153.130.45:53435] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.153.130.45 (+1 hits since last alert)|kadinisi.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "kadinisi.org"] [uri "/xmlrpc.php"] [unique_id "alyzSutICBlrmXKEei-OsgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
DonAtari
2026-07-19 06:28:21
(1 month ago)
DShield firewall scan - TCP to port 8000
Brute-Force
SSH
Anonymous
2026-07-17 16:03:46
(1 month ago)
Distributed web crawl botnet attack (like Mellowtel), likely illicit scraping of AI training data to ...
show more
Distributed web crawl botnet attack (like Mellowtel), likely illicit scraping of AI training data to bypass firewall/robots.txt restrictions in printer-friendly.asp
show less
Exploited Host
Bad Web Bot
🇺🇸
TPI-Abuse
2026-07-14 13:28:35
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 103.153.130.45 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 103.153.130.45 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 14 09:28:30.786753 2026] [security2:error] [pid 11479:tid 11479] [client 103.153.130.45:52555] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.153.130.45 (+1 hits since last alert)|tracytappan.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "tracytappan.net"] [uri "/xmlrpc.php"] [unique_id "alY5fpKWfLxkG0Ia5Yu-lQAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack