🇨🇿
Countryman
2026-09-12 00:10:01
(15 hours ago)
repeated unauthorized VPN login attempt, user sweep
VPN IP
Hacking
Brute-Force
🇨🇭
SOC [GOLINE SA]
2026-09-10 22:54:37
(1 day ago)
[RoutePulse | 2026-09-10T22:54:37Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 45.66.208.4 ...
show more
[RoutePulse | 2026-09-10T22:54:37Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 45.66.208.42
EVIDENCE: Shunned on the Cisco FTD VPN gateway — Cisco VPN RA Brute force on Cisco FTDv — shunned by the FTD's own threat detection (adopted by RoutePulse: TTL, strike, diary)
DETECTION: Conviction Engine SPRT + 14-detector ML stack (6-model weighted ensemble) + 5-pillar threat scoring
ACTION: BGP null route injected at RoutePulse network edge
show less
Brute-Force
Hacking
🇺🇸
nationaleventpros.com
2026-09-05 04:19:17
(1 week ago)
WordPress login attempt
Brute-Force
🇫🇷
dynamix
2026-09-03 20:27:59
(1 week ago)
Multiple WAF Violations
Web App Attack
🇺🇸
nationaleventpros.com
2026-09-03 00:38:24
(1 week ago)
WordPress login attempt
Brute-Force
🇺🇸
nationaleventpros.com
2026-08-20 17:40:48
(3 weeks ago)
WordPress login attempt
Brute-Force
🇮🇹
CoreTech srl
2026-08-19 19:43:57
(3 weeks ago)
cloudlinux2 fail2ban: 2026-08-19 21:39:05,830 fail2ban.filter [1468]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-08-19 21:39:05,830 fail2ban.filter [1468]: INFO [plesk-wordpress] Found 45.146.55.237 - 2026-08-19 21:39:05cloudlinux2 fail2ban: 2026-08-19 21:39:01,419 fail2ban.filter [1468]: INFO [plesk-wordpress] Found 45.146.55.237 - 2026-08-19 21:39:00cloudlinux2 fail2ban: 2026-08-19 21:39:15,648 fail2ban.filter [1468]: INFO [plesk-wordpress] Found 134.255.243.210 - 2026-08-19 21:39:14cloudlinux2 fail2ban: 2026-08-19 21:39:39,602 fail2ban.filter [1468]: INFO [plesk-wordpress] Found 45.146.55.153 - 2026-08-19 21:39:39cloudlinux2 fail2ban: 2026-08-19 21:39:42,649 fail2ban.filter [1468]: INFO [plesk-modsecurity] Found 45.66.208.42 - 2026-08-19 21:39:42cloudlinux2 fail2ban: 2026-08-19 21:40:17,629 fail2ban.filter [1468]: INFO [plesk-modsecurity] Found 34.78.110.28 - 2026-08-19 21:40:17cloudlinux2 fail2ban: 2026-08-19 21:40:19,246 fail2ban.filter [1468]: INFO [plesk-modsecurity] Found 34.78.110.28 - 2026-08-19 21:40:18clou
show less
Web App Attack
🇺🇸
kosada.com
2026-08-18 20:26:52
(3 weeks ago)
Web password guessing
Brute-Force
🇺🇸
TPI-Abuse
2026-08-07 12:01:25
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 45.66.208.42 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 45.66.208.42 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 08:01:19.183657 2026] [security2:error] [pid 1474762:tid 1474762] [client 45.66.208.42:19689] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||step1nutrition.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "step1nutrition.com"] [uri "/wp-json/wp/v2/users"] [unique_id "anXJD2JF9Zf7QgyZ37X4lgAAAAE"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-05 21:13:12
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 45.66.208.42 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 45.66.208.42 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 05 17:13:05.662497 2026] [security2:error] [pid 23382:tid 23382] [client 45.66.208.42:49507] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||abramson-offner.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "abramson-offner.com"] [uri "/wp-json/wp/v2/users"] [unique_id "anOnYZE5HQdbO8be6l_PrQAAABU"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇪🇸
librebit
2026-07-08 10:40:29
(2 months ago)
Brute force
Brute-Force
🇫🇷
Tilellit.PRO
2026-07-02 04:05:28
(2 months ago)
tilellit/wp-armour-ban
Hacking
🇺🇸
TPI-Abuse
2026-06-29 18:23:11
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 45.66.208.42 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 45.66.208.42 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 29 14:23:05.643155 2026] [security2:error] [pid 25343:tid 25443] [client 45.66.208.42:35611] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||paidsearchconsulting.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "paidsearchconsulting.com"] [uri "/wp-json/wp/v2/users"] [unique_id "akK4CY_cAbeTccrbH-28LwAAAcQ"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Tilellit.PRO
2026-06-29 13:42:25
(2 months ago)
Fail2Ban banned 45.66.208.42 for security violations in jail wp-armour. Log: 2026/06/29 13:42:24 [er ...
show more
Fail2Ban banned 45.66.208.42 for security violations in jail wp-armour. Log: 2026/06/29 13:42:24 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 45.66.208.42 | Target: wplogin" , client: 45.66.208.42, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
🇫🇷
Tilellit.PRO
2026-06-28 08:27:01
(2 months ago)
Fail2Ban banned 45.66.208.42 for security violations in jail wp-armour. Log: 2026/06/28 08:27:01 [er ...
show more
Fail2Ban banned 45.66.208.42 for security violations in jail wp-armour. Log: 2026/06/28 08:27:01 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 45.66.208.42 | Target: wplogin" , client: 45.66.208.42, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam