🇨🇿
lp
2026-09-09 15:23:04
(2 days ago)
Unauthorized VPN login attempts: 3 attempts were recorded from 45.159.22.167
2026-09-09T16:59:01+02: ...
show more
Unauthorized VPN login attempts: 3 attempts were recorded from 45.159.22.167
2026-09-09T16:59:01+02:00 vpn Access-Reject 'qadjtx' station: 45.159.22.167 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
2026-09-09T17:00:22+02:00 vpn Access-Reject 'bpm' station: 45.159.22.167 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
2026-09-09T17:01:42+02:00 vpn Access-Reject 'ac7' station: 45.159.22.167 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
🇸🇪
OnTheEdge
2026-09-09 00:39:54
(3 days ago)
Password spraying. Multiple unauthorized login attempts
Hacking
Web App Attack
🇨🇭
SOC [GOLINE SA]
2026-09-08 15:44:59
(3 days ago)
[RoutePulse | 2026-09-08T15:44:59Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 45.159.22.1 ...
show more
[RoutePulse | 2026-09-08T15:44:59Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 45.159.22.167
EVIDENCE: Shunned on the Cisco FTD VPN gateway — Cisco VPN RA Brute force on Cisco FTDv — distributed attack (3 attempts/15min) — shun on the VPN gateway
DETECTION: Conviction Engine SPRT + 14-detector ML stack (6-model weighted ensemble) + 5-pillar threat scoring
ACTION: BGP null route injected at RoutePulse network edge
show less
Brute-Force
Hacking
Anonymous
2026-09-04 22:24:25
(1 week ago)
FPROCO WEBEXPLOIT 45.159.22.167 (45.159.22.167)
Web App Attack
🇩🇪
Lino Project
2026-08-26 12:27:22
(2 weeks ago)
45.159.22.167 - - [26/Aug/2026:14:27:21 +0200] "GET /wp-login.php HTTP/2.0" 403 282 "-" "Mozilla/5.0 ...
show more
45.159.22.167 - - [26/Aug/2026:14:27:21 +0200] "GET /wp-login.php HTTP/2.0" 403 282 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.0 Safari/605.1.15"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Yepngo
2026-08-23 23:11:16
(2 weeks ago)
45.159.22.167 - - [24/Aug/2026:01:08:55 +0200] "POST /wp-login.php HTTP/2.0" 200 12486 "https://yepn ...
show more
45.159.22.167 - - [24/Aug/2026:01:08:55 +0200] "POST /wp-login.php HTTP/2.0" 200 12486 "https://yepngo.com/wp-login.php" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
45.159.22.167 - - [24/Aug/2026:01:11:15 +0200] "POST /wp-login.php HTTP/2.0" 200 12492 "https://yepngo.com/wp-login.php" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
...
show less
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-08-14 16:36:56
(4 weeks ago)
(mod_security) mod_security (id:225170) triggered by 45.159.22.167 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.159.22.167 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 14 12:36:49.203059 2026] [security2:error] [pid 18914:tid 18927] [client 45.159.22.167:62921] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||slelectric.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "slelectric.com"] [uri "/wp-json/wp/v2/users"] [unique_id "an9EIRbHDx6BdDTP20wZ5wAAAMk"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-09 15:28:28
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 45.159.22.167 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.159.22.167 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 09 11:28:23.928161 2026] [security2:error] [pid 2387631:tid 2387631] [client 45.159.22.167:22557] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||machinetoolsjwk.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "machinetoolsjwk.com"] [uri "/wp-json/wp/v2/users"] [unique_id "anicl_xT4bKCU28cr27duwAAAAQ"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-07 18:28:06
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 45.159.22.167 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.159.22.167 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 14:28:02.049186 2026] [security2:error] [pid 3040779:tid 3040779] [client 45.159.22.167:24047] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||sharkfamily.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "sharkfamily.com"] [uri "/wp-json/wp/v2/users"] [unique_id "anYjsiaTEWsh8Ic_rG9rogAAADk"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-03 21:44:43
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 45.159.22.167 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.159.22.167 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 03 17:44:38.395787 2026] [security2:error] [pid 400765:tid 400765] [client 45.159.22.167:55319] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||siczewicz.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "siczewicz.com"] [uri "/wp-json/wp/v2/users"] [unique_id "anELxkphYopkE6tebLWb1gAAAAA"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-07-30 08:18:40
(1 month ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-07-30 03:26:57
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 45.159.22.167 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.159.22.167 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 23:26:52.092594 2026] [security2:error] [pid 779643:tid 779643] [client 45.159.22.167:61511] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||marveldirectory.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "marveldirectory.com"] [uri "/wp-json/wp/v2/users"] [unique_id "amrEfEXKPRN1Y6rck9xrUwAAACA"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-16 21:00:27
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 45.159.22.167 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.159.22.167 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 16 17:00:21.277017 2026] [security2:error] [pid 12503:tid 12503] [client 45.159.22.167:50003] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||primacomm.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "primacomm.com"] [uri "/wp-json/wp/v2/users"] [unique_id "allGZdAOFaWmKbRnz0DBOwAAAAM"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-13 12:26:35
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 45.159.22.167 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.159.22.167 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 13 08:26:29.135467 2026] [security2:error] [pid 3305012:tid 3305012] [client 45.159.22.167:40775] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||moellerlaw.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "moellerlaw.com"] [uri "/wp-json/wp/v2/users"] [unique_id "alTZdYPpTUxPt7FZaPfx4wAAABA"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Savvii
2026-07-11 18:48:12
(2 months ago)
20 attempts against mh_ha-misbehave-ban on bud
Brute-Force
Bad Web Bot
Web App Attack