🇨🇭
SOC [GOLINE SA]
2026-09-09 15:24:16
(8 hours ago)
[RoutePulse | 2026-09-09T15:24:16Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 185.61.219. ...
show more
[RoutePulse | 2026-09-09T15:24:16Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 185.61.219.130 · AS26548 PureVoltage Hosting Inc. · Russia
EVIDENCE: Shunned on the Cisco FTD VPN gateway — Cisco VPN RA Brute force on Cisco FTDv — shunned by the FTD's own threat detection (adopted by RoutePulse: TTL, strike, diary)
DETECTION: Conviction Engine SPRT + 14-detector ML stack (6-model weighted ensemble) + 5-pillar threat scoring
ACTION: BGP null route injected at RoutePulse network edge
show less
Brute-Force
Hacking
🇺🇸
TPI-Abuse
2026-04-27 08:20:47
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 185.61.219.130 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 185.61.219.130 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 27 04:20:41.351021 2026] [security2:error] [pid 13287:tid 13287] [client 185.61.219.130:19827] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.deargrampy.net|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.deargrampy.net"] [uri "/s3cmd.ini"] [unique_id "ae8cWUVjtTSuKRc8j52EyAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-04-26 22:59:43
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 185.61.219.130 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 185.61.219.130 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 26 18:59:36.992225 2026] [security2:error] [pid 15540:tid 15540] [client 185.61.219.130:64901] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.cheapbats.liddlesports.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.cheapbats.liddlesports.com"] [uri "/s3cmd.ini"] [unique_id "ae6Y2K4KIDjGT7IAHh_6hwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-01-23 01:30:22
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 185.61.219.130 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 185.61.219.130 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 22 20:29:54.563726 2026] [security2:error] [pid 4185450:tid 4185497] [client 185.61.219.130:39639] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||cynosurepressurewashing.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "cynosurepressurewashing.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aXLPEmHpI7prtPBYNVaC7gAAAFc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-01-23 00:01:54
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 185.61.219.130 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 185.61.219.130 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 22 19:01:49.025013 2026] [security2:error] [pid 6674:tid 6674] [client 185.61.219.130:23759] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||virtualmediamasters.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "virtualmediamasters.net"] [uri "/wp-json/wp/v2/users"] [unique_id "aXK6beRPUIT8uKykz7j-LQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇩
BPS-StatisticsIndonesia
2025-11-13 02:51:04
(9 months ago)
XML RPC Scan Activities
Brute-Force
Web App Attack
Anonymous
2025-10-29 10:44:36
(10 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
🇦🇺
oncord
2025-10-13 12:14:41
(10 months ago)
Form spam
Web Spam
🇳🇱
WeCloudit-Anti-Abuse
2025-10-01 00:20:04
(11 months ago)
WAF: Block IP which is in the web-spammers RBL 2- wsit
Email Spam
Brute-Force
🇬🇧
oncord
2025-09-12 16:44:30
(11 months ago)
Form spam
Web Spam
🇳🇱
exxos
2025-08-29 09:03:02
(1 year ago)
Rapid register abuse
Web Spam
🇩🇪
Bedios GmbH
2025-02-24 12:34:45
(1 year ago)
Wordpress hacking attempt
Web App Attack
Anonymous
2025-02-20 22:15:39
(1 year ago)
wordpress-trap
Web App Attack
Anonymous
2024-11-22 19:08:15
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2024-11-21 13:19:37
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH