🇺🇸
IndigoRidge
2026-09-11 09:18:48
(1 day ago)
178.152.80.217 - - [11/Sep/2026:05:17:11 -0400] "POST /xmlrpc.php HTTP/1.1" 200 5310 "-" "WordPress. ...
show more
178.152.80.217 - - [11/Sep/2026:05:17:11 -0400] "POST /xmlrpc.php HTTP/1.1" 200 5310 "-" "WordPress.com; https://wordpress.com"
178.152.80.217 - - [11/Sep/2026:05:17:21 -0400] "POST /xmlrpc.php HTTP/1.1" 200 5310 "-" "WordPress.com; https://wordpress.com"
178.152.80.217 - - [11/Sep/2026:05:18:15 -0400] "POST /xmlrpc.php HTTP/1.1" 200 5310 "-" "WordPress.com; https://wordpress.com"
178.152.80.217 - - [11/Sep/2026:05:18:37 -0400] "POST /xmlrpc.php HTTP/1.1" 200 5310 "-" "WordPress.com; https://wordpress.com"
178.152.80.217 - - [11/Sep/2026:05:18:48 -0400] "POST /xmlrpc.php HTTP/1.1" 200 5310 "-" "WordPress.com; https://wordpress.com"
...
show less
Web App Attack
🇬🇧
Aetherweb Ark
2026-09-11 08:57:48
(1 day ago)
(mod_security) mod_security (id:35002) triggered by 178.152.80.217 (QA/Qatar/-): N in the last X sec ...
show more
(mod_security) mod_security (id:35002) triggered by 178.152.80.217 (QA/Qatar/-): N in the last X secs
show less
Web App Attack
🇬🇧
NotCool
2026-09-11 08:35:42
(1 day ago)
(XMLRPC) WP XMLPRC Attack 178.152.80.217 (QA/Qatar/-): 50 in the last 3600 secs
Web App Attack
🇺🇸
TPI-Abuse
2026-08-18 09:04:32
(3 weeks ago)
(mod_security) mod_security (id:240335) triggered by 178.152.80.217 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 178.152.80.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 05:04:26.587064 2026] [security2:error] [pid 4992:tid 5251] [client 178.152.80.217:60489] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 178.152.80.217 (+1 hits since last alert)|captechinc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "captechinc.com"] [uri "/xmlrpc.php"] [unique_id "aoQgGlYI0w1KDh7dVexuCwAAAUI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-18 09:03:51
(3 weeks ago)
[redacted] 178.152.80.217 - - [18/Aug/2026:11:03:08 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" " ...
show more
[redacted] 178.152.80.217 - - [18/Aug/2026:11:03:08 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.3)"
[redacted] 178.152.80.217 - - [18/Aug/2026:11:03:18 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.5; WordPress 6.2)"
[redacted] 178.152.80.217 - - [18/Aug/2026:11:03:29 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 178.152.80.217 - - [18/Aug/2026:11:03:40 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 178.152.80.217 - - [18/Aug/2026:11:03:51 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
...
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-08-18 08:10:51
(3 weeks ago)
(mod_security) mod_security (id:240335) triggered by 178.152.80.217 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 178.152.80.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 04:10:46.520584 2026] [security2:error] [pid 15309:tid 15309] [client 178.152.80.217:57539] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 178.152.80.217 (+1 hits since last alert)|judithcaldwell.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "judithcaldwell.com"] [uri "/xmlrpc.php"] [unique_id "aoQThlRpYNcI-D6QdNa-9wAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Petros Stefanakis
2026-08-18 08:10:50
(3 weeks ago)
(wordpress) Failed wordpress login from 178.152.80.217 (QA/Qatar/-)
Brute-Force
🇫🇷
Kenshin869
2026-08-17 15:35:41
(3 weeks ago)
Wordpress unauthorized access attempt
Brute-Force
🇺🇸
TPI-Abuse
2026-08-12 17:59:54
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 178.152.80.217 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 178.152.80.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 12 13:59:49.020270 2026] [security2:error] [pid 22694:tid 22694] [client 178.152.80.217:55038] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 178.152.80.217 (+1 hits since last alert)|lysedzija.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "lysedzija.com"] [uri "/xmlrpc.php"] [unique_id "any0lV5V35IzsB90qRheCAAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-17 17:13:49
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 178.152.80.217 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 178.152.80.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 13:13:43.957796 2026] [security2:error] [pid 13752:tid 13752] [client 178.152.80.217:60921] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 178.152.80.217 (+1 hits since last alert)|cosplayculture.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "cosplayculture.com"] [uri "/xmlrpc.php"] [unique_id "alpix5arV7xEvbmGxw-zKAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack