🇨🇿
lp
2026-09-14 00:22:47
(1 day ago)
Unauthorized VPN login attempts: 2 attempts were recorded from 45.148.233.210
2026-09-14T01:11:42+02 ...
show more
Unauthorized VPN login attempts: 2 attempts were recorded from 45.148.233.210
2026-09-14T01:11:42+02:00 vpn Access-Reject 'admin' station: 45.148.233.210 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
2026-09-14T01:13:15+02:00 vpn Access-Reject 'PDS' station: 45.148.233.210 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
🇨🇿
Countryman
2026-09-13 00:10:01
(2 days ago)
repeated unauthorized VPN login attempt, user sweep
VPN IP
Hacking
Brute-Force
🇨🇿
lp
2026-09-12 10:51:40
(3 days ago)
Unauthorized VPN login attempts: 3 attempts were recorded from 45.148.233.210
2026-09-12T12:36:20+02 ...
show more
Unauthorized VPN login attempts: 3 attempts were recorded from 45.148.233.210
2026-09-12T12:36:20+02:00 vpn Access-Reject 'vpn6' station: 45.148.233.210 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
2026-09-12T12:37:59+02:00 vpn Access-Reject 'vpn1' station: 45.148.233.210 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
2026-09-12T12:39:38+02:00 vpn Access-Reject 'vpn7' station: 45.148.233.210 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
🇨🇭
SOC [GOLINE SA]
2026-09-09 15:30:24
(5 days ago)
[RoutePulse | 2026-09-09T15:30:23Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 45.148.233. ...
show more
[RoutePulse | 2026-09-09T15:30:23Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 45.148.233.210 · AS26548 PureVoltage Hosting Inc. · The Netherlands
EVIDENCE: Cisco VPN RA Brute force on Cisco FTDv — portal under siege (89 real failed logins / 15 min): 2 attacker IPs in 45.148.233.0/24 from campaign AS26548 PUREVOLTAGE-INC - PureVoltage Hosting Inc. (139 IPs over the campaign); the attacker reuse · /24 aggregate member of 45.148.233.0/24
DETECTION: Conviction Engine SPRT + 14-detector ML stack (6-model weighted ensemble) + 5-pillar threat scoring
ACTION: BGP null route injected at RoutePulse network edge
show less
Brute-Force
Hacking
🇨🇭
SOC [GOLINE SA]
2026-09-09 12:40:42
(5 days ago)
[RoutePulse | 2026-09-09T12:40:42Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 45.148.233. ...
show more
[RoutePulse | 2026-09-09T12:40:42Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 45.148.233.210 · AS26548 PureVoltage Hosting Inc. · The Netherlands
EVIDENCE: Shunned on the Cisco FTD VPN gateway — Cisco VPN RA Brute force on Cisco FTDv — shunned by the FTD's own threat detection (adopted by RoutePulse: TTL, strike, diary)
DETECTION: Conviction Engine SPRT + 14-detector ML stack (6-model weighted ensemble) + 5-pillar threat scoring
ACTION: BGP null route injected at RoutePulse network edge
show less
Brute-Force
Hacking
🇺🇸
TPI-Abuse
2026-06-17 16:17:08
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 45.148.233.210 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 45.148.233.210 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 17 12:17:02.621106 2026] [security2:error] [pid 3828:tid 3828] [client 45.148.233.210:44573] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||holtzheimer.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "holtzheimer.net"] [uri "/wp-json/wp/v2/users"] [unique_id "ajLIfpaY1Gqc8RJHA4dVTgAAAAc"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-06-16 01:38:05
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 45.148.233.210 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 45.148.233.210 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 21:37:57.946259 2026] [security2:error] [pid 7051:tid 7051] [client 45.148.233.210:63301] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||elfinforest.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "elfinforest.net"] [uri "/wp-json/wp/v2/users"] [unique_id "ajCo9dzXT4EoYBNrLbwT4QAAAA0"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
nationaleventpros.com
2026-06-14 19:12:05
(3 months ago)
WordPress login attempt
Brute-Force
🇺🇸
TPI-Abuse
2026-05-29 08:56:08
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 45.148.233.210 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 45.148.233.210 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 29 04:56:04.204140 2026] [security2:error] [pid 1368:tid 1368] [client 45.148.233.210:13217] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||marveldirectory.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "marveldirectory.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ahlUpDyMzrw9WddoFd_umgAAAAE"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-05-28 00:11:52
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 45.148.233.210 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 45.148.233.210 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 27 20:11:48.222223 2026] [security2:error] [pid 19592:tid 19592] [client 45.148.233.210:17731] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||sahinozalit.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "sahinozalit.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aheIRP6BW_7wgUg5My5JwwAAABU"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-05-18 04:10:16
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 45.148.233.210 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 45.148.233.210 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 18 00:10:08.587945 2026] [security2:error] [pid 11404:tid 11404] [client 45.148.233.210:27605] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||donnysimonton.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "donnysimonton.com"] [uri "/wp-json/wp/v2/users"] [unique_id "agqRIFtgZqhOy0CP32A8QQAAAAo"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-04-28 10:28:02
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 45.148.233.210 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 45.148.233.210 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 28 06:27:58.400289 2026] [security2:error] [pid 13263:tid 13263] [client 45.148.233.210:30193] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||erinrusso.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "erinrusso.com"] [uri "/wp-json/wp/v2/users"] [unique_id "afCLrqOvDjfEzxSdNTA6bgAAAAQ"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-04-19 10:07:26
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 45.148.233.210 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 45.148.233.210 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 19 06:07:19.978300 2026] [security2:error] [pid 3885963:tid 3885963] [client 45.148.233.210:48521] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||cvtheory.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "cvtheory.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aeSpV7hmHVBTM2gqQz0LkwAAAAc"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-03-17 22:37:39
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 45.148.233.210 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 45.148.233.210 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 17 18:37:34.630656 2026] [security2:error] [pid 18435:tid 18435] [client 45.148.233.210:17377] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bladesoflegend.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bladesoflegend.com"] [uri "/wp-json/wp/v2/users"] [unique_id "abnXrh8pIO1dvqOCflDZ0gAAAAc"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇿
lp
2025-11-10 07:23:30
(10 months ago)
Unauthorized VPN login attempts: 1 attempts were recorded from 45.148.233.210
2025-11-10T06:56:34+01 ...
show more
Unauthorized VPN login attempts: 1 attempts were recorded from 45.148.233.210
2025-11-10T06:56:34+01:00 vpn Access-Reject 'benjamin.robinson' station: 45.148.233.210 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack