๐บ๐ธ
TPI-Abuse
2026-08-25 03:55:54
(40 minutes ago)
(mod_security) mod_security (id:240335) triggered by 178.153.255.42 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 178.153.255.42 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 23:55:48.595177 2026] [security2:error] [pid 3702:tid 3702] [client 178.153.255.42:49334] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 178.153.255.42 (+1 hits since last alert)|oliverhardy.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "oliverhardy.com"] [uri "/xmlrpc.php"] [unique_id "ao0SRPLHU8gSggYKr-8woAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 01:51:41
(2 hours ago)
(mod_security) mod_security (id:240335) triggered by 178.153.255.42 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 178.153.255.42 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 21:51:33.077715 2026] [security2:error] [pid 25904:tid 25904] [client 178.153.255.42:57826] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 178.153.255.42 (+1 hits since last alert)|zeetec.nl|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "zeetec.nl"] [uri "/xmlrpc.php"] [unique_id "aoz1Jbytb8jhgx4MfVQWsgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-08-25 00:43:58
(3 hours ago)
cloudlinux2 fail2ban: 2026-08-25 02:40:31,790 fail2ban.filter [1464]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-08-25 02:40:31,790 fail2ban.filter [1464]: INFO [plesk-modsecurity] Found 178.153.255.42 - 2026-08-25 02:40:31cloudlinux2 fail2ban: 2026-08-25 02:40:51,515 fail2ban.filter [1464]: INFO [plesk-modsecurity] Found 217.181.66.64 - 2026-08-25 02:40:51cloudlinux2 fail2ban: 2026-08-25 02:40:52,227 fail2ban.filter [1464]: INFO [plesk-wordpress] Found 217.181.86.53 - 2026-08-25 02:40:51cloudlinux2 fail2ban: 2026-08-25 02:40:57,741 fail2ban.filter [1464]: INFO [plesk-wordpress] Found 217.181.77.92 - 2026-08-25 02:40:57cloudlinux2 fail2ban: 2026-08-25 02:40:53,435 fail2ban.filter [1464]: INFO [plesk-wordpress] Found 217.181.82.78 - 2026-08-25 02:40:53cloudlinux2 fail2ban: 2026-08-25 02:40:54,872 fail2ban.filter [1464]: INFO [plesk-wordpress] Found 217.181.82.175 - 2026-08-25 02:40:54cloudlinux2 fail2ban: 2026-08-25 02:40:56,480 fail2ban.filter [1464]: INFO [plesk-wordpress] Found 195.63.11.205 - 2026-08-25 02:40:55clo
show less
Web App Attack
๐ฉ๐ช
Marc
2026-08-24 21:33:31
(7 hours ago)
178.153.255.42 - - [24/Aug/2026:23:33:09 +0200] "POST /xmlrpc.php HTTP/1.1" 200 4832 "-" "Jetpack by ...
show more
178.153.255.42 - - [24/Aug/2026:23:33:09 +0200] "POST /xmlrpc.php HTTP/1.1" 200 4832 "-" "Jetpack by WordPress.com (Jetpack 12.5; WordPress 6.3)" 178.153.255.42 - - [24/Aug/2026:23:33:19 +0200] "POST /xmlrpc.php HTTP/1.1" 200 4833 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.2)" 178.153.255.42 - - [24/Aug/2026:23:33:29 +0200] "POST /xmlrpc.php HTTP/1.1" 200 4832 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.3)"
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 20:04:32
(8 hours ago)
(mod_security) mod_security (id:240335) triggered by 178.153.255.42 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 178.153.255.42 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 16:04:25.669788 2026] [security2:error] [pid 2629:tid 2629] [client 178.153.255.42:63314] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 178.153.255.42 (+1 hits since last alert)|zabyte.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "zabyte.net"] [uri "/xmlrpc.php"] [unique_id "aoyjydXBA7gJXRrBB9nYJQAAAD0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-24 17:46:42
(10 hours ago)
POST /xmlrpc.php HTTP/1.1
...
Brute-Force
๐ฎ๐น
CoreTech srl
2026-08-24 14:19:00
(14 hours ago)
cloudlinux2 fail2ban: 2026-08-24 16:14:27,332 fail2ban.filter [1464]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-08-24 16:14:27,332 fail2ban.filter [1464]: INFO [plesk-modsecurity] Found 178.153.255.42 - 2026-08-24 16:14:27cloudlinux2 fail2ban: 2026-08-24 16:15:12,390 fail2ban.filter [1464]: INFO [plesk-wordpress] Found 195.63.29.39 - 2026-08-24 16:15:12cloudlinux2 fail2ban: 2026-08-24 16:15:10,917 fail2ban.filter [1464]: INFO [plesk-wordpress] Found 195.63.6.173 - 2026-08-24 16:15:10cloudlinux2 fail2ban: 2026-08-24 16:15:11,654 fail2ban.filter [1464]: INFO [plesk-wordpress] Found 217.181.87.10 - 2026-08-24 16:15:11cloudlinux2 fail2ban: 2026-08-24 16:15:09,695 fail2ban.filter [1464]: INFO [plesk-modsecurity] Found 195.63.29.10 - 2026-08-24 16:15:09cloudlinux2 fail2ban: 2026-08-24 16:15:13,754 fail2ban.filter [1464]: INFO [plesk-wordpress] Found 195.63.20.158 - 2026-08-24 16:15:13cloudlinux2 fail2ban: 2026-08-24 16:15:13,209 fail2ban.filter [1464]: INFO [plesk-wordpress] Found 195.63.23.112 - 2026-08-24 16:15:12cloudli
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 10:27:09
(18 hours ago)
(mod_security) mod_security (id:240335) triggered by 178.153.255.42 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 178.153.255.42 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 06:27:01.853184 2026] [security2:error] [pid 25585:tid 25585] [client 178.153.255.42:32251] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 178.153.255.42 (+1 hits since last alert)|adonamusic.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "adonamusic.com"] [uri "/xmlrpc.php"] [unique_id "aowcddmQ3pFJC6MSs4tc-AAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 02:24:33
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 178.153.255.42 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 178.153.255.42 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 22:24:27.112868 2026] [security2:error] [pid 14061:tid 14061] [client 178.153.255.42:56238] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 178.153.255.42 (+1 hits since last alert)|dogarttoday.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "dogarttoday.com"] [uri "/xmlrpc.php"] [unique_id "aourW7CmJPBc9wDq6AzW8wAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
ljo
2026-08-24 01:21:01
(1 day ago)
178.153.255.42 - - [24/Aug/2026:03:19:25 +0200] "POST /xmlrpc.php HTTP/1.1" 200 5405 "-" "WordPress. ...
show more
178.153.255.42 - - [24/Aug/2026:03:19:25 +0200] "POST /xmlrpc.php HTTP/1.1" 200 5405 "-" "WordPress.com; https://wordpress.com"
178.153.255.42 - - [24/Aug/2026:03:19:35 +0200] "POST /xmlrpc.php HTTP/1.1" 200 5405 "-" "Jetpack by WordPress.com"
178.153.255.42 - - [24/Aug/2026:03:19:46 +0200] "POST /xmlrpc.php HTTP/1.1" 200 5405 "-" "Jetpack/13.0; WordPress/6.2; http://site44251038.com"
178.153.255.42 - - [24/Aug/2026:03:19:56 +0200] "POST /xmlrpc.php HTTP/1.1" 200 5405 "-" "Jetpack by WordPress.com (Jetpack 12.5; WordPress 6.4)"
178.153.255.42 - - [24/Aug/2026:03:20:07 +0200] "POST /xmlrpc.php HTTP/1.1" 200 5405 "-" "Jetpack/12.1; WordPress/6.1; http://site42222069.com"
178.153.255.42 - - [24/Aug/2026:03:20:18 +0200] "POST /xmlrpc.php HTTP/1.1" 200 5405 "-" "WordPress.com; https://wordpress.com"
178.153.255.42 - - [24/Aug/2026:03:20:28 +0200] "POST /xmlrpc.php HTTP/1.1" 200 5405 "-" "Jetpack by WordPress.com"
178.153.255.42 - - [24/Aug/2026:03:20:39 +0200] "POST /xmlrpc.php HTTP/1.1" 20
...
show less
Web App Attack
๐ณ๐ฑ
Site.eu
2026-08-24 00:39:37
(1 day ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐ฉ๐ช
Tha_14
2026-08-23 23:37:00
(1 day ago)
Limit on login attempts is reached
Brute-Force
๐บ๐ธ
integrantservices.com
2026-08-23 20:52:05
(1 day ago)
(wordpress) Failed wordpress login from 178.153.255.42 (QA/Qatar/-)
Brute-Force
๐ซ๐ท
dynamix
2026-08-23 18:48:59
(1 day ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐ฒ๐พ
Rizzy
2026-08-23 18:18:40
(1 day ago)
Multiple WAF Violations
Brute-Force
Web App Attack