๐จ๐ฟ
Countryman
2026-09-04 00:10:01
(1 week ago)
repeated unauthorized VPN login attempt, user sweep
VPN IP
Hacking
Brute-Force
๐ธ๐ช
OnTheEdge
2026-09-03 23:44:44
(1 week ago)
Password spraying. Multiple unauthorized login attempts
Hacking
Web App Attack
๐จ๐ญ
SOC [GOLINE SA]
2026-09-03 11:43:23
(1 week ago)
[RoutePulse | 2026-09-03T11:43:23Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 45.3.50.213 ...
show more
[RoutePulse | 2026-09-03T11:43:23Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 45.3.50.213 ยท AS200373 Drei-K-Tech-GmbH 3xK Tech GmbH
EVIDENCE: Cisco VPN RA Brute force on Cisco FTDv โ distributed attack (6 attempts/15min)
DETECTION: Conviction Engine SPRT + 14-detector ML stack (6-model weighted ensemble) + 5-pillar threat scoring
ACTION: BGP null route injected at RoutePulse network edge
show less
Brute-Force
Hacking
๐ซ๐ท
Sklurk
2026-08-05 01:19:56
(1 month ago)
Web App Attack
Web App Attack
๐ช๐ธ
librebit
2026-05-17 03:37:54
(4 months ago)
Brute force
Brute-Force
Anonymous
2026-05-03 19:21:02
(4 months ago)
Forum/form spam
Web Spam
๐ฉ๐ช
LRob
2026-05-02 17:15:10
(4 months ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
Anonymous
2026-05-02 12:49:18
(4 months ago)
(wordpress) Failed wordpress login from 45.3.50.213 (US/United States/-)
Brute-Force
๐ฉ๐ช
Lino Project
2026-04-01 03:42:48
(5 months ago)
45.3.50.213 - - [01/Apr/2026:05:42:48 +0200] "GET /xmlrpc.php HTTP/1.1" 403 3963 "https://www.primob ...
show more
45.3.50.213 - - [01/Apr/2026:05:42:48 +0200] "GET /xmlrpc.php HTTP/1.1" 403 3963 "https://www.primobio.it/mio-account/?action=register" "Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.0.0 Safari/537.36"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-03-29 20:04:09
(5 months ago)
Forum/form spam
Web Spam
๐ฉ๐ช
HandyTreff.de
2026-03-10 19:55:05
(6 months ago)
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -41.598 (Bad < -10 / Very Bad < -20 ...
show more
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -41.598 (Bad < -10 / Very Bad < -20 / Extreme < -35) | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 12_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0
show less
Web App Attack
Bad Web Bot
๐ซ๐ฎ
Shaik Sai Meera
2025-12-09 22:10:11
(9 months ago)
IM360 WAF: Hidden file access
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-12-09 19:49:51
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.50.213 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.50.213 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 09 14:49:44.055281 2025] [security2:error] [pid 28427:tid 28427] [client 45.3.50.213:18459] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ic1surplus.com"] [uri "/.env"] [unique_id "aTh9WK0foZQPCmwX5NPk8AAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-09 16:06:15
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.50.213 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.50.213 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 09 11:06:07.525310 2025] [security2:error] [pid 6825:tid 6825] [client 45.3.50.213:40163] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "blessedhavenfarm.com"] [uri "/.env"] [unique_id "aThI7zJ4uhLicMP9q5jkBwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-08 20:05:50
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.50.213 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.50.213 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 08 15:05:43.165021 2025] [security2:error] [pid 23111:tid 23229] [client 45.3.50.213:56313] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vinylnotespodcast.com"] [uri "/.svn/wc.db"] [unique_id "aTcvl5XKR_ztMqm8Wgj_JwAAAQM"]
show less
Brute-Force
Bad Web Bot
Web App Attack