Anonymous
2026-08-25 20:48:25
(1 day ago)
[redacted] 153.117.49.78 - - [25/Aug/2026:22:47:43 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "J ...
show more
[redacted] 153.117.49.78 - - [25/Aug/2026:22:47:43 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 153.117.49.78 - - [25/Aug/2026:22:47:52 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 153.117.49.78 - - [25/Aug/2026:22:48:03 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.5; WordPress 6.1)"
[redacted] 153.117.49.78 - - [25/Aug/2026:22:48:13 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 153.117.49.78 - - [25/Aug/2026:22:48:25 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/13.0; WordPress/6.1; http://site25336038.com"
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 13:57:43
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 153.117.49.78 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 153.117.49.78 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 09:57:29.937330 2026] [security2:error] [pid 8961:tid 8961] [client 153.117.49.78:34406] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 153.117.49.78 (+1 hits since last alert)|cmcnow.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "cmcnow.com"] [uri "/xmlrpc.php"] [unique_id "ao2fSZsfj8kS7BRjbEBjAgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
cwytech
2026-08-25 13:55:53
(1 day ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/wordpress-xmlrpc-bf-slow-high.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 13:29:21
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 153.117.49.78 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 153.117.49.78 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 09:29:11.900641 2026] [security2:error] [pid 1219375:tid 1219436] [client 153.117.49.78:32869] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 153.117.49.78 (+1 hits since last alert)|hmpdecors.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "hmpdecors.com"] [uri "/xmlrpc.php"] [unique_id "ao2Yp5IROdEggxSAdOlwZgAAAZY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 12:55:31
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 153.117.49.78 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 153.117.49.78 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 08:55:19.370767 2026] [security2:error] [pid 22565:tid 22565] [client 153.117.49.78:32994] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 153.117.49.78 (+1 hits since last alert)|nolaanime.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "nolaanime.com"] [uri "/xmlrpc.php"] [unique_id "ao2Qt20GMPh0ecr65oVwtwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 10:44:44
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 153.117.49.78 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 153.117.49.78 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 06:44:30.287472 2026] [security2:error] [pid 23190:tid 23190] [client 153.117.49.78:34526] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 153.117.49.78 (+1 hits since last alert)|matt-bechtel.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "matt-bechtel.com"] [uri "/xmlrpc.php"] [unique_id "ao1yDpIu5L3Q7OCBU6TGfAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐น๐ท
oalver
2026-08-24 22:10:41
(2 days ago)
Detected by SiberKapan threat intelligence platform (siberkapan.org). Attack types: nginx_path_signa ...
show more
Detected by SiberKapan threat intelligence platform (siberkapan.org). Attack types: nginx_path_signature. Sources: nginx. Details: path_signature: request to /xmlrpc.php (HTTP 200). First seen: 2026-08-24. Risk score: 30/100.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 16:06:58
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 153.117.49.78 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 153.117.49.78 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 12:06:45.002452 2026] [security2:error] [pid 26635:tid 26644] [client 153.117.49.78:33514] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 153.117.49.78 (+1 hits since last alert)|councilofforeignministers.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "councilofforeignministers.com"] [uri "/xmlrpc.php"] [unique_id "aoxsFAVXn7ZOQj5QVRTTtAAAAYc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
Fanjoe
2026-08-24 11:53:46
(2 days ago)
Aug 24 13:53:36 raspberrypi wordpress\(fanjoe.be\)\[5597\]: XML-RPC authentication attempt for unkno ...
show more
Aug 24 13:53:36 raspberrypi wordpress\(fanjoe.be\)\[5597\]: XML-RPC authentication attempt for unknown user admin from 153.117.49.78\
show less
Brute-Force
Web App Attack
๐ซ๐ท
Kenshin869
2026-08-24 09:59:14
(2 days ago)
Wordpress unauthorized access attempt
Brute-Force
๐บ๐ธ
IndigoRidge
2026-08-23 11:17:23
(3 days ago)
153.117.49.78 - - [23/Aug/2026:07:15:13 -0400] "POST /xmlrpc.php HTTP/1.1" 200 5072 "-" "WordPress.c ...
show more
153.117.49.78 - - [23/Aug/2026:07:15:13 -0400] "POST /xmlrpc.php HTTP/1.1" 200 5072 "-" "WordPress.com; https://wordpress.com"
153.117.49.78 - - [23/Aug/2026:07:15:45 -0400] "POST /xmlrpc.php HTTP/1.1" 200 5072 "-" "WordPress.com; https://wordpress.com"
153.117.49.78 - - [23/Aug/2026:07:16:29 -0400] "POST /xmlrpc.php HTTP/1.1" 200 5072 "-" "WordPress.com; https://wordpress.com"
153.117.49.78 - - [23/Aug/2026:07:17:01 -0400] "POST /xmlrpc.php HTTP/1.1" 200 5072 "-" "WordPress.com; https://wordpress.com"
153.117.49.78 - - [23/Aug/2026:07:17:22 -0400] "POST /xmlrpc.php HTTP/1.1" 200 5072 "-" "WordPress.com; https://wordpress.com"
...
show less
Web App Attack
๐บ๐ธ
cwytech
2026-08-21 20:57:47
(5 days ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/wordpress-xmlrpc-bf-high.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 07:26:58
(3 weeks ago)
(mod_security) mod_security (id:240335) triggered by 153.117.49.78 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 153.117.49.78 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 03:26:48.281373 2026] [security2:error] [pid 1839201:tid 1839201] [client 153.117.49.78:33892] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 153.117.49.78 (+1 hits since last alert)|visionremota.info|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "visionremota.info"] [uri "/xmlrpc.php"] [unique_id "am2fuF1c2ANNzFaCZLkBqQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-29 21:35:54
(4 weeks ago)
(mod_security) mod_security (id:240335) triggered by 153.117.49.78 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 153.117.49.78 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 17:35:40.976757 2026] [security2:error] [pid 3757945:tid 3757945] [client 153.117.49.78:32859] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 153.117.49.78 (+1 hits since last alert)|handankoc.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "handankoc.net"] [uri "/xmlrpc.php"] [unique_id "ampyLAX50eJIcM4upg_5SgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
masterguru
2026-07-29 21:05:15
(4 weeks ago)
(xmlrpc) Failed xmlrpc access from 153.117.49.78 (PK/Pakistan/-): 5 in the last 3600 secs (0-122)
Hacking