🇨🇿
Countryman
2026-09-04 00:10:01
(4 days ago)
repeated unauthorized VPN login attempt, user sweep
VPN IP
Hacking
Brute-Force
🇨🇿
lp
2026-09-03 21:25:42
(4 days ago)
Unauthorized VPN login attempts: 2 attempts were recorded from 45.3.51.206
2026-09-03T21:47:41+02:00 ...
show more
Unauthorized VPN login attempts: 2 attempts were recorded from 45.3.51.206
2026-09-03T21:47:41+02:00 vpn Access-Reject 'administrator' station: 45.3.51.206 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
2026-09-03T21:49:20+02:00 vpn Access-Reject 'hasibe.coruhlu' station: 45.3.51.206 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
🇨🇭
SOC [GOLINE SA]
2026-09-02 16:51:07
(5 days ago)
[RoutePulse | 2026-09-02T16:51:07Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 45.3.51.206 ...
show more
[RoutePulse | 2026-09-02T16:51:07Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 45.3.51.206
EVIDENCE: Cisco VPN RA Brute force on Cisco FTDv — distributed attack (6 attempts/15min)
DETECTION: Conviction Engine SPRT + 14-detector ML stack (6-model weighted ensemble) + 5-pillar threat scoring
ACTION: BGP null route injected at RoutePulse network edge
show less
Brute-Force
Hacking
🇫🇷
Sklurk
2026-07-07 15:27:54
(2 months ago)
Web App Attack
Web App Attack
🇩🇪
F242
2026-05-22 20:04:45
(3 months ago)
Wordpress Login or XMLRPC abuse
Web App Attack
🇺🇸
TPI-Abuse
2026-02-24 09:39:23
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.51.206 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.51.206 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 24 04:39:15.889620 2026] [security2:error] [pid 25917:tid 25917] [client 45.3.51.206:18727] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "edmontonareahomes.digitalracemedia.com"] [uri "/.git/config"] [unique_id "aZ1xw3VHl0H9F1QisiaJFgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-02-23 22:10:23
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.51.206 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.51.206 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 23 17:10:20.162412 2026] [security2:error] [pid 19538:tid 19538] [client 45.3.51.206:45405] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fantasyfootballing.chavarri.com"] [uri "/.git/config"] [unique_id "aZzQTPqRykGvIdm5k03ukAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-02-23 17:20:24
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.51.206 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.51.206 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 23 12:20:21.303992 2026] [security2:error] [pid 19846:tid 19846] [client 45.3.51.206:62401] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "localislekker.infojeffreysbay.com"] [uri "/.git/config"] [unique_id "aZyMVSz8e_S3PNLBcC0M0QAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇱🇻
garmtech.com
2026-01-29 22:55:33
(7 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 00-55.45.3.51.206.web-spammers ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 00-55.45.3.51.206.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
🇺🇸
oralunal
2025-12-30 22:57:20
(8 months ago)
IP banned by Fail2Ban in jail ente-suss ente.com-ssl_log mvfnds
...
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-12-22 18:59:50
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 45.3.51.206 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 45.3.51.206 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 22 13:59:43.769774 2025] [security2:error] [pid 8556:tid 8556] [client 45.3.51.206:12089] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.phantomkennels.com|F|2"] [data "[email protected] "] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.phantomkennels.com"] [uri "/[email protected] "] [unique_id "aUmVHxjSe0wQLxUL4nzPcwAAAAU"], referer: https://www.phantomkennels.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
techboy117
2025-11-14 00:31:07
(9 months ago)
Blocking due to password spraying.
Brute-Force
Anonymous
2025-10-29 06:34:38
(10 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
🇮🇩
BPS-StatisticsIndonesia
2025-10-27 20:01:14
(10 months ago)
WP Admin Scan Activities
Web App Attack
🇮🇩
BPS-StatisticsIndonesia
2025-10-23 17:17:21
(10 months ago)
WP Admin Scan Activities
Web App Attack