🇨🇭
SOC [GOLINE SA]
2026-09-08 03:34:54
(6 hours ago)
[RoutePulse | 2026-09-08T03:34:54Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 170.168.175 ...
show more
[RoutePulse | 2026-09-08T03:34:54Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 170.168.175.244 · AS59651 Alex Largman · Poland
EVIDENCE: Shunned on the Cisco FTD VPN gateway — Cisco VPN RA Brute force on Cisco FTDv — shunned by the FTD's own threat detection (adopted by RoutePulse: TTL, strike, diary)
DETECTION: Conviction Engine SPRT + 14-detector ML stack (6-model weighted ensemble) + 5-pillar threat scoring
ACTION: BGP null route injected at RoutePulse network edge
show less
Brute-Force
Hacking
🇺🇸
agabeckov
2026-09-08 02:49:56
(7 hours ago)
Fail2Ban detected brute-force attempt on Cisco Anyconnect
VPN IP
Brute-Force
🇪🇸
librebit
2026-07-16 07:20:13
(1 month ago)
Brute force
Brute-Force
🇺🇸
TPI-Abuse
2026-03-29 15:03:03
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 170.168.175.244 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 170.168.175.244 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 29 11:02:58.693642 2026] [security2:error] [pid 25401:tid 25401] [client 170.168.175.244:13745] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||ibcnu.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "ibcnu.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ack_InCPJuHL5-TUc08NRgAAAAo"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-03-26 20:04:16
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 170.168.175.244 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 170.168.175.244 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 26 16:04:10.027192 2026] [security2:error] [pid 14722:tid 14722] [client 170.168.175.244:58107] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||oxygenfarm.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "oxygenfarm.com"] [uri "/wp-json/wp/v2/users"] [unique_id "acWROh5JwbZpDu8vgesILAAAAAo"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-03-20 01:22:13
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 170.168.175.244 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 170.168.175.244 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 21:22:07.685325 2026] [security2:error] [pid 27360:tid 27360] [client 170.168.175.244:35955] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||flugstad.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "flugstad.net"] [uri "/wp-json/wp/v2/users"] [unique_id "abyhP5BGAmZL5UY27cyj5QAAAAE"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-03-16 07:56:11
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 170.168.175.244 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 170.168.175.244 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 16 03:56:07.414196 2026] [security2:error] [pid 13552:tid 13552] [client 170.168.175.244:43839] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||gonzalez.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "gonzalez.com"] [uri "/wp-json/wp/v2/users"] [unique_id "abe3l6UzKb9-NGbtQqt12AAAAAc"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-02-26 21:37:38
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 170.168.175.244 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 170.168.175.244 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 26 16:37:32.796721 2026] [security2:error] [pid 31682:tid 31682] [client 170.168.175.244:49059] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||elitehomesfl.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "elitehomesfl.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aaC9HJ7uUuqgKSAgDRdNWAAAAA0"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-12-10 14:52:11
(8 months ago)
"Participant in large-scale DDoS Attack in which data injection was attmpted to gain unauthorized ac ...
show more
"Participant in large-scale DDoS Attack in which data injection was attmpted to gain unauthorized access"
show less
DDoS Attack
SQL Injection
Exploited Host
Anonymous
2025-12-04 18:16:14
(9 months ago)
botnet
DDoS Attack