๐บ๐ธ
TPI-Abuse
2026-06-11 15:45:35
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 81.88.34.55 (host229.alfahosting-server.de): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 81.88.34.55 (host229.alfahosting-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 11:45:27.700911 2026] [security2:error] [pid 8448:tid 8448] [client 81.88.34.55:25906] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.allotrope.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.allotrope.com"] [uri "/wp-json/wp/v2/users"] [unique_id "airYFwnJZ3cDjyadeJtWqAAAAC0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-06-11 13:03:08
(1 week ago)
Blocked by CSF 13 firewall - Rule: DE/Germany/host229.alfahosting-server.de
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-11 00:24:09
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 81.88.34.55 (host229.alfahosting-server.de): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 81.88.34.55 (host229.alfahosting-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 20:24:04.126353 2026] [security2:error] [pid 12738:tid 12738] [client 81.88.34.55:30944] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.scswat.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.scswat.org"] [uri "/wp-json/wp/v2/users"] [unique_id "aioAJFVBzNxV21TwTJeJrQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-10 23:16:42
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 81.88.34.55 (host229.alfahosting-server.de): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 81.88.34.55 (host229.alfahosting-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 19:16:38.426611 2026] [security2:error] [pid 31557:tid 31579] [client 81.88.34.55:64746] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.tkfay.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.tkfay.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ainwVphPgTv5a2JmvT7iggAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-10 12:12:46
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 81.88.34.55 (host229.alfahosting-server.de): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 81.88.34.55 (host229.alfahosting-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 08:12:41.497204 2026] [security2:error] [pid 29443:tid 29443] [client 81.88.34.55:2264] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.cycontechnology.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.cycontechnology.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ailUuWHuDKiz4NAQMCJMsQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 12:51:42
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 81.88.34.55 (host229.alfahosting-server.de): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 81.88.34.55 (host229.alfahosting-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 08:51:35.132577 2026] [security2:error] [pid 29206:tid 29206] [client 81.88.34.55:60406] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.feministvoice.blog|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.feministvoice.blog"] [uri "/wp-json/wp/v2/users"] [unique_id "aigMV6NS9oDNhwKHIfJf-QAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-08 22:16:20
(1 week ago)
[redacted] 81.88.34.55 - - [09/Jun/2026:00:16:17 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Moz ...
show more
[redacted] 81.88.34.55 - - [09/Jun/2026:00:16:17 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:64.0) Gecko/20100101 Firefox/64.0"
[redacted] 81.88.34.55 - - [09/Jun/2026:00:16:17 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0"
[redacted] 81.88.34.55 - - [09/Jun/2026:00:16:17 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:50.0) Gecko/20100101 Firefox/50.0"
[redacted] 81.88.34.55 - - [09/Jun/2026:00:16:17 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:86.0) Gecko/20100101 Firefox/86.0"
[redacted] 81.88.34.55 - - [09/Jun/2026:00:16:17 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:65.0) Gecko/20100101 Firefox/65.0"
[redacted] 81.88.34.55 - - [09/J
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 19:24:22
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 81.88.34.55 (host229.alfahosting-server.de): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 81.88.34.55 (host229.alfahosting-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 15:24:14.168635 2026] [security2:error] [pid 470:tid 470] [client 81.88.34.55:56650] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.humbliaslaw.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.humbliaslaw.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aicW3rCgF8h_Nr2KGf55PQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 08:44:18
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 81.88.34.55 (host229.alfahosting-server.de): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 81.88.34.55 (host229.alfahosting-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 04:44:13.207594 2026] [security2:error] [pid 9804:tid 9813] [client 81.88.34.55:22530] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.brucejoell.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.brucejoell.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiaA3RvHey55eIVMjeIItQAAAQY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 07:29:35
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 81.88.34.55 (host229.alfahosting-server.de): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 81.88.34.55 (host229.alfahosting-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 03:29:27.517383 2026] [security2:error] [pid 17489:tid 17489] [client 81.88.34.55:24928] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.esysapps.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.esysapps.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiZvV7Z1MvdQkaITVT93fQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 03:08:29
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 81.88.34.55 (host229.alfahosting-server.de): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 81.88.34.55 (host229.alfahosting-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 23:08:23.895796 2026] [security2:error] [pid 15275:tid 15275] [client 81.88.34.55:62634] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.georgegourmet.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.georgegourmet.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiYyJwL6LARx96Z7W30s1gAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2026-06-08 01:02:41
(1 week ago)
(wp_login_try) srv103 WP Login Attempt 81.88.34.55 (DE/Germany/host229.alfahosting-server.de): 10 in ...
show more
(wp_login_try) srv103 WP Login Attempt 81.88.34.55 (DE/Germany/host229.alfahosting-server.de): 10 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-07 06:51:17
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 81.88.34.55 (host229.alfahosting-server.de): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 81.88.34.55 (host229.alfahosting-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 02:51:13.627522 2026] [security2:error] [pid 21110:tid 21110] [client 81.88.34.55:52264] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||kmelson.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "kmelson.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiUU4d8EcXQtXFZE0oMPewAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-06 17:44:17
(2 weeks ago)
[redacted] 81.88.34.55 - - [06/Jun/2026:19:44:09 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Moz ...
show more
[redacted] 81.88.34.55 - - [06/Jun/2026:19:44:09 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:54.0) Gecko/20100101 Firefox/54.0"
[redacted] 81.88.34.55 - - [06/Jun/2026:19:44:10 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:61.0) Gecko/20100101 Firefox/61.0"
[redacted] 81.88.34.55 - - [06/Jun/2026:19:44:10 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:59.0) Gecko/20100101 Firefox/59.0"
[redacted] 81.88.34.55 - - [06/Jun/2026:19:44:11 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:46.0) Gecko/20100101 Firefox/46.0"
[redacted] 81.88.34.55 - - [06/Jun/2026:19:44:12 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:47.0) Gecko/20100101 Firefox/47.0"
[redacted] 81.88.34.55 - - [06/Jun/2026:19:44:12 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216
...
show less
Hacking
Web App Attack
๐บ๐ธ
Dolphi
2026-06-06 14:00:03
(2 weeks ago)
Excessive POST /xmlrpc.php requests
Brute-Force
Web App Attack