This IP address has been reported a total of
23
times from
17 distinct
sources.
45.228.136.150 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
France
with 3
reports;
United States of America
with 3
reports;
Brazil
with 1
report.
The most common categories in these recent reports were:
DDoS Attack
4
times;
Bad Web Bot
4
times;
Web App Attack
2
times;
Exploited Host
2
times;
Hacking
1
time;
Other
2
times.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
[Fri Oct 02 09:10:01.142321 2026] [security2:error] [pid 52674:tid 140639140206272] [client 45.228.1 ...
show more[Fri Oct 02 09:10:01.142321 2026] [security2:error] [pid 52674:tid 140639140206272] [client 45.228.136.150:0] ModSecurity: Access denied with code 403 (phase 1). Match of "pm matomo.staklim-malang.info " against "SERVER_NAME" required. [file "/etc/modsecurity/coreruleset-4.29.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "208"] [id "440235"] [msg "BAD REQUEST Bro"] [data " Matched Data ARGS charset: - Matched Data TX.1: found within Content-Type multipart form Matched Data: %3a found within SERVER_NAME: staklim-jatim.bmkg.go.id request_line = GET /index.php/using-joomla/extensions/components/content-component/archived-articles?catid=472&id=1159%3Aprakiraan-cuaca-daerah-malang-dan-batu-seminggu-ke-depan-berlaku-tanggal-27-september-03-oktober-2016 HTTP/1.1 Request URI RAW = /index.php/using-joomla/extensions/components/content-component/archived-articles?catid=472&id=115..."] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/using-joomla/extensions/components/content-comp
...
show less
Repeated requests classified as pathological web bot behavior, for example: /[redacted]?topics[13]=2 ...
show moreRepeated requests classified as pathological web bot behavior, for example: /[redacted]?topics[13]=28&topics[16]=50&topics[17]=53&topics[18]=89 (HTTP/2.0 port 443, user agent: "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36")
show less
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0. ...
show moreMozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36
show less
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/143.0.0.0 Sa ...
show moreMozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/143.0.0.0 Safari/537.36
show less
UDP flood (DDoS) vs AS215599: 335 pkts / 0.48 MB to UDP 80/8443 across 185 dst IP(s), 2026-08-19 21: ...
show moreUDP flood (DDoS) vs AS215599: 335 pkts / 0.48 MB to UDP 80/8443 across 185 dst IP(s), 2026-08-19 21:46 to 2026-08-20 00:36 CEST. No legitimate service on these UDP ports (7-day baseline 0 GB/day). Carpet-bombing of a /24, likely botnet-compromised host. Evidence: sFlow + hardware ACL counters.
show less
UDP flood (DDoS) vs AS215599: 335 pkts / 0.48 MB to UDP 80/8443 across 185 dst IP(s), 2026-08-19 21: ...
show moreUDP flood (DDoS) vs AS215599: 335 pkts / 0.48 MB to UDP 80/8443 across 185 dst IP(s), 2026-08-19 21:46 to 2026-08-20 00:36 CEST. No legitimate service on these UDP ports (7-day baseline 0 GB/day). Carpet-bombing of a /24, likely botnet-compromised host. Evidence: sFlow + hardware ACL counters.
show less
Application-layer flood: hammering search, login or AJAX endpoints far beyond any human use | path: ...
show moreApplication-layer flood: hammering search, login or AJAX endpoints far beyond any human use | path: /31-meilleur-velo-entre-3000-et-4000-euros
show less
Attack Signature Blocked: /wishlist/index/add/product/11169/form_key/6NKVNgFmgNK5L6r4/ (Magento Site ...
show moreAttack Signature Blocked: /wishlist/index/add/product/11169/form_key/6NKVNgFmgNK5L6r4/ (Magento Site) (Botnet activity attributed to: Angara Technologies Group / mikhail-smirnov-79830322)
show less