๐ช๐ธ
alferez
2026-07-23 22:29:22
(1 day ago)
xmlrpc.php attack DOS
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 19:24:37
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 103.225.223.126 (103-225-223-126.connectel.com. ...
show more
(mod_security) mod_security (id:240335) triggered by 103.225.223.126 (103-225-223-126.connectel.com.pk): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 15:24:30.119239 2026] [security2:error] [pid 2891243:tid 2891254] [client 103.225.223.126:62177] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.225.223.126 (+1 hits since last alert)|koalacogs.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "koalacogs.com"] [uri "/xmlrpc.php"] [unique_id "amJqbjRnfK5YQ-ibrEc_YAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-24 17:58:43
(1 month ago)
Attac
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-24 00:40:59
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 103.225.223.126 (103-225-223-126.connectel.com. ...
show more
(mod_security) mod_security (id:240335) triggered by 103.225.223.126 (103-225-223-126.connectel.com.pk): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 23 20:40:55.712236 2026] [security2:error] [pid 9001:tid 9001] [client 103.225.223.126:6787] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.225.223.126 (+1 hits since last alert)|jennyfiore.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "jennyfiore.com"] [uri "/xmlrpc.php"] [unique_id "ajsnl_UDEDNYShSYCYAelgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-23 23:55:01
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 103.225.223.126 (103-225-223-126.connectel.com. ...
show more
(mod_security) mod_security (id:240335) triggered by 103.225.223.126 (103-225-223-126.connectel.com.pk): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 23 19:54:53.431093 2026] [security2:error] [pid 18361:tid 18361] [client 103.225.223.126:55702] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.225.223.126 (+1 hits since last alert)|prayers4america.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "prayers4america.com"] [uri "/xmlrpc.php"] [unique_id "ajsczXaCNr9Fa--fgZY0tAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-06-23 23:36:27
(1 month ago)
4.033 requests with url.path */xmlrpc.php
Brute-Force
Bad Web Bot
Anonymous
2026-06-22 23:35:03
(1 month ago)
103.225.223.126 - - [23/Jun/2026:01:34:44 +0200] "POST /xmlrpc.php HTTP/1.1" 200 403 "-" "Jetpack by ...
show more
103.225.223.126 - - [23/Jun/2026:01:34:44 +0200] "POST /xmlrpc.php HTTP/1.1" 200 403 "-" "Jetpack by WordPress.com (Jetpack 12.5; WordPress 6.4)"
103.225.223.126 - - [23/Jun/2026:01:34:41 +0200] "POST /xmlrpc.php HTTP/1.1" 200 624 "-" "Jetpack by WordPress.com (Jetpack 12.5; WordPress 6.4)"
103.225.223.126 - - [23/Jun/2026:01:34:50 +0200] "POST /xmlrpc.php HTTP/1.1" 200 624 "-" "Jetpack/12.1; WordPress/6.2; http://site56501547.com"
103.225.223.126 - - [23/Jun/2026:01:34:51 +0200] "POST /xmlrpc.php HTTP/1.1" 200 403 "-" "Jetpack/12.1; WordPress/6.2; http://site56501547.com"
103.225.223.126 - - [23/Jun/2026:01:35:02 +0200] "POST /xmlrpc.php HTTP/1.1" 200 403 "-" "WordPress.com; https://wordpress.com"
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-22 21:33:16
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 103.225.223.126 (103-225-223-126.connectel.com. ...
show more
(mod_security) mod_security (id:240335) triggered by 103.225.223.126 (103-225-223-126.connectel.com.pk): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 22 17:33:08.720495 2026] [security2:error] [pid 10146:tid 10146] [client 103.225.223.126:36476] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.225.223.126 (+1 hits since last alert)|swcbsa.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "swcbsa.org"] [uri "/xmlrpc.php"] [unique_id "ajmqFCj9ephbHDCZhjmk0gAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
integrantservices.com
2026-06-22 21:32:01
(1 month ago)
(wordpress) Failed wordpress login from 103.225.223.126 (PK/Pakistan/103-225-223-126.connectel.com.p ...
show more
(wordpress) Failed wordpress login from 103.225.223.126 (PK/Pakistan/103-225-223-126.connectel.com.pk)
show less
Brute-Force
๐ฌ๐ง
Apache
2026-06-22 17:19:34
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 103.225.223.126 (PK/Pakistan/103-225-223-126.co ...
show more
(mod_security) mod_security (id:240335) triggered by 103.225.223.126 (PK/Pakistan/103-225-223-126.connectel.com.pk): 5 in the last 300 secs
show less
Brute-Force
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-06-20 22:58:26
(1 month ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
PK/Pakistan/103-225-223-126.connectel.com.pk
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-20 17:48:14
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 103.225.223.126 (103-225-223-126.connectel.com. ...
show more
(mod_security) mod_security (id:240335) triggered by 103.225.223.126 (103-225-223-126.connectel.com.pk): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 20 13:48:10.139435 2026] [security2:error] [pid 3107:tid 3107] [client 103.225.223.126:24704] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.225.223.126 (+1 hits since last alert)|clipper1970.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "clipper1970.com"] [uri "/xmlrpc.php"] [unique_id "ajbSWs8IoWftUOX2-BgWowAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
pscriptos
2026-06-20 17:42:23
(1 month ago)
{"ClientAddr":"103.225.223.126:21656","ClientHost":"103.225.223.126","ClientPort":"21656","ClientUse ...
show more
{"ClientAddr":"103.225.223.126:21656","ClientHost":"103.225.223.126","ClientPort":"21656","ClientUsername":"-","DownstreamContentSize":418,"DownstreamStatus":403,"Duration":631668965,"OriginContentSize":418,"OriginDuration":627523830,"OriginStatus":403,"Overhead":4145135,"RequestAddr":"www.cleveradmin.de","RequestContentSize":705,"RequestCount":762655,"RequestHost":"www.cleveradmin.de","RequestMethod":"POST","RequestPath":"/xmlrpc.php","RequestPort":"-","RequestProtocol":"HTTP/1.1","RequestScheme":"https","RetryAttempts":0,"RouterName":"cleveradmin-www-websecure@file","ServiceAddr":"172.16.80.10:80","ServiceName":"cleveradmin-www@file","ServiceURL":"http://172.16.80.10:80","StartLocal":"2026-06-20T19:42:01.686980147+02:00","StartUTC":"2026-06-20T17:42:01.686980147Z","TLSCipher":"TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256","TLSVersion":"1.2","entryPointName":"websecure","level":"info","msg":"","time":"2026-06-20T19:42:02+02:00"}
{"ClientAddr":"103.225.223.126:21656","ClientHost":"103.225.223
...
show less
Brute-Force
Web App Attack
Anonymous
2026-06-20 00:41:05
(1 month ago)
103.225.223.126 - - [20/Jun/2026:02:40:43 +0200] "POST /xmlrpc.php HTTP/1.1" 200 593 "-" "Jetpack/12 ...
show more
103.225.223.126 - - [20/Jun/2026:02:40:43 +0200] "POST /xmlrpc.php HTTP/1.1" 200 593 "-" "Jetpack/12.5; WordPress/6.4; http://site68269546.com"
103.225.223.126 - - [20/Jun/2026:02:40:44 +0200] "POST /xmlrpc.php HTTP/1.1" 200 403 "-" "Jetpack/12.5; WordPress/6.4; http://site68269546.com"
103.225.223.126 - - [20/Jun/2026:02:40:53 +0200] "POST /xmlrpc.php HTTP/1.1" 200 593 "-" "WordPress.com; https://wordpress.com"
103.225.223.126 - - [20/Jun/2026:02:40:53 +0200] "POST /xmlrpc.php HTTP/1.1" 200 403 "-" "WordPress.com; https://wordpress.com"
103.225.223.126 - - [20/Jun/2026:02:41:04 +0200] "POST /xmlrpc.php HTTP/1.1" 200 593 "-" "Jetpack/13.0; WordPress/6.3; http://site52114359.com"
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-20 00:12:57
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 103.225.223.126 (103-225-223-126.connectel.com. ...
show more
(mod_security) mod_security (id:240335) triggered by 103.225.223.126 (103-225-223-126.connectel.com.pk): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 20:12:53.493298 2026] [security2:error] [pid 21909:tid 21909] [client 103.225.223.126:26433] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.225.223.126 (+1 hits since last alert)|iconflgc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "iconflgc.com"] [uri "/xmlrpc.php"] [unique_id "ajXbBR9G1KbwvBLy18w-SQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack