🇨🇭
SOC [GOLINE SA]
2026-09-03 09:23:28
(2 days ago)
[RoutePulse | 2026-09-03T09:23:28Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 104.207.58. ...
show more
[RoutePulse | 2026-09-03T09:23:28Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 104.207.58.198 · AS200373 Drei-K-Tech-GmbH 3xK Tech GmbH
EVIDENCE: Cisco VPN RA Brute force on Cisco FTDv — distributed attack (8 attempts/15min)
DETECTION: Conviction Engine SPRT + 14-detector ML stack (6-model weighted ensemble) + 5-pillar threat scoring
ACTION: BGP null route injected at RoutePulse network edge
show less
Brute-Force
Hacking
🇸🇪
shab
2026-09-03 08:39:20
(2 days ago)
Suspicious VPN activity
Brute-Force
🇮🇹
VHosting
2026-08-25 22:00:12
(1 week ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇫🇷
Sklurk
2026-08-05 02:21:34
(1 month ago)
Web App Attack
Web App Attack
🇫🇷
Sklurk
2026-07-29 01:26:40
(1 month ago)
Web App Attack
Web App Attack
🇫🇷
Sklurk
2026-06-23 03:56:21
(2 months ago)
Web App Attack
Web App Attack
🇫🇷
Sklurk
2026-06-20 02:05:22
(2 months ago)
Web App Attack
Web App Attack
🇺🇸
TPI-Abuse
2025-12-29 05:04:32
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.58.198 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.58.198 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 00:04:27.798475 2025] [security2:error] [pid 2980:tid 2983] [client 104.207.58.198:30039] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gabegabel.com"] [uri "/.git/HEAD"] [unique_id "aVIL2xVtsv2QY781bBrRKgAAAME"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-12-29 03:37:53
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.58.198 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.58.198 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 28 22:37:45.451904 2025] [security2:error] [pid 20191:tid 20191] [client 104.207.58.198:52821] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "railsolutionsmexico.com"] [uri "/.env"] [unique_id "aVH3ieoYTJv_UV-EsU0wxQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-27 21:37:59
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.58.198 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.58.198 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 27 16:37:37.643932 2025] [security2:error] [pid 27327:tid 27327] [client 104.207.58.198:14639] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "firebelly.org"] [uri "/.svn/wc.db"] [unique_id "aSjEoaMqU6a6c5rZd3cqRAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇱🇻
garmtech.com
2025-11-24 08:53:02
(9 months ago)
Attempted access to sensitive endpoint (/.svn/wc.db) detected. Automated scan or unauthorized probin ...
show more
Attempted access to sensitive endpoint (/.svn/wc.db) detected. Automated scan or unauthorized probing.
show less
Web App Attack
🇺🇸
TPI-Abuse
2025-11-24 05:46:08
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.58.198 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.58.198 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 00:46:00.191067 2025] [security2:error] [pid 20676:tid 20676] [client 104.207.58.198:27461] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ctrl-p.saltcityprint.com"] [uri "/.svn/wc.db"] [unique_id "aSPxGDOjO3-ZpkqSKOOJygAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-24 04:00:36
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.58.198 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.58.198 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 23 23:00:26.700197 2025] [security2:error] [pid 4083:tid 4083] [client 104.207.58.198:21493] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.guitarinfoplace.com"] [uri "/.env"] [unique_id "aSPYWs9_ma4EwgBPcwPLJAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
Rosh
2025-10-14 23:06:18
(10 months ago)
[10/15/25 01:06:18] SSH: illegal login attempts
Brute-Force
SSH
Anonymous
2025-10-10 15:51:09
(10 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH