Anonymous
2026-08-28 20:58:47
(1 day ago)
178.77.182.54 - - [28/Aug/2026:22:58:45 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428
...
Brute-Force
Bad Web Bot
Anonymous
2026-08-28 20:06:35
(1 day ago)
178.77.182.54 - - [28/Aug/2026:22:06:23 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428
178.77.182.54 - - ...
show more
178.77.182.54 - - [28/Aug/2026:22:06:23 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428
178.77.182.54 - - [28/Aug/2026:22:06:33 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428
...
show less
Brute-Force
Bad Web Bot
Anonymous
2026-08-27 20:06:05
(2 days ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
🇩🇪
ghostwarriors
2026-08-26 19:50:27
(3 days ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-25 05:18:47
(5 days ago)
(mod_security) mod_security (id:240335) triggered by 178.77.182.54 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 178.77.182.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 01:18:40.123466 2026] [security2:error] [pid 30210:tid 30210] [client 178.77.182.54:4628] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 178.77.182.54 (+1 hits since last alert)|laecovillage.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "laecovillage.org"] [uri "/xmlrpc.php"] [unique_id "ao0lsBoJamoJLZQWYg49KAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-24 14:40:55
(5 days ago)
(mod_security) mod_security (id:240335) triggered by 178.77.182.54 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 178.77.182.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 10:40:46.913129 2026] [security2:error] [pid 9780:tid 9780] [client 178.77.182.54:3260] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 178.77.182.54 (+1 hits since last alert)|anthonyanimalclinic.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "anthonyanimalclinic.net"] [uri "/xmlrpc.php"] [unique_id "aoxX7jP2cZQjEJacramgSwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-24 13:08:06
(6 days ago)
(mod_security) mod_security (id:240335) triggered by 178.77.182.54 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 178.77.182.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 09:08:02.658251 2026] [security2:error] [pid 6480:tid 6480] [client 178.77.182.54:2971] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 178.77.182.54 (+1 hits since last alert)|hvacmechanalysis.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "hvacmechanalysis.com"] [uri "/xmlrpc.php"] [unique_id "aoxCMraQh1IxODv5W6INkQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-23 21:24:26
(6 days ago)
(mod_security) mod_security (id:240335) triggered by 178.77.182.54 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 178.77.182.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 17:24:21.725139 2026] [security2:error] [pid 12029:tid 12029] [client 178.77.182.54:3456] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 178.77.182.54 (+1 hits since last alert)|lighthousescm.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "lighthousescm.com"] [uri "/xmlrpc.php"] [unique_id "aotlBSZF9o7ZHsxhzxJKvwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-23 19:53:40
(6 days ago)
(mod_security) mod_security (id:240335) triggered by 178.77.182.54 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 178.77.182.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 15:53:35.756680 2026] [security2:error] [pid 18753:tid 18753] [client 178.77.182.54:4765] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 178.77.182.54 (+1 hits since last alert)|axiomemail.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "axiomemail.net"] [uri "/xmlrpc.php"] [unique_id "aotPv4UTRgBOnIKAIsfZUAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-22 23:08:47
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 178.77.182.54 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 178.77.182.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 19:08:39.335620 2026] [security2:error] [pid 13198:tid 13198] [client 178.77.182.54:4909] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 178.77.182.54 (+1 hits since last alert)|iostation.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "iostation.com"] [uri "/xmlrpc.php"] [unique_id "aoor95eSkWBOCB5CDOPdPAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-08-22 20:24:56
(1 week ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
Anonymous
2026-08-22 16:16:34
(1 week ago)
(wordpress) Failed wordpress login from 178.77.182.54 (JO/Jordan/-)
Brute-Force
🇺🇸
TPI-Abuse
2026-08-22 15:17:49
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 178.77.182.54 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 178.77.182.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 11:17:44.804209 2026] [security2:error] [pid 21081:tid 21081] [client 178.77.182.54:2200] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 178.77.182.54 (+1 hits since last alert)|xhumanlikerobots.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "xhumanlikerobots.com"] [uri "/xmlrpc.php"] [unique_id "aom9mJgPj2nCTQOEz85rBwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-22 12:38:35
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 178.77.182.54 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 178.77.182.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 08:38:29.751134 2026] [security2:error] [pid 14974:tid 14974] [client 178.77.182.54:5359] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 178.77.182.54 (+1 hits since last alert)|newmooncafe.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "newmooncafe.com"] [uri "/xmlrpc.php"] [unique_id "aomYRZP6lO6Z1P-oQwXpagAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
EGP Abuse Dept
2026-03-15 03:53:08
(5 months ago)
Scanning for port/service exploits on tpc-036.mach3builders.nl
Port Scan
Hacking