๐จ๐ญ
SOC [GOLINE SA]
2026-09-02 17:10:53
(4 hours ago)
[RoutePulse | 2026-09-02T17:10:53Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 193.56.28.2 ...
show more
[RoutePulse | 2026-09-02T17:10:53Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 193.56.28.2
EVIDENCE: Cisco VPN RA Brute force on Cisco FTDv โ distributed attack (6 attempts/15min)
DETECTION: Conviction Engine SPRT + 14-detector ML stack (6-model weighted ensemble) + 5-pillar threat scoring
ACTION: BGP null route injected at RoutePulse network edge
show less
Brute-Force
Hacking
๐ฉ๐ช
Goetz
2026-08-27 12:24:50
(6 days ago)
FortiGate SSL VPN login failures.
Hacking
Brute-Force
๐จ๐ญ
backslash
2026-08-13 12:03:01
(2 weeks ago)
block ruleset 486D2EE5E731CC049D1E480D68D04DFFE28AADF1
Bad Web Bot
๐ซ๐ท
Sklurk
2026-08-04 03:11:23
(4 weeks ago)
Web App Attack
Web App Attack
๐ซ๐ท
Sklurk
2026-07-08 00:00:44
(1 month ago)
Web App Attack
Web App Attack
๐ฎ๐น
VHosting
2025-12-24 00:20:33
(8 months ago)
Detected attack and reported by a human
DDoS Attack
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
SSH
๐ต๐ฑ
sefinek.net
2025-12-11 01:38:46
(8 months ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /.git/HEAD
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-12-09 02:36:00
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 193.56.28.2 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 193.56.28.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 08 21:35:54.454742 2025] [security2:error] [pid 15209:tid 15209] [client 193.56.28.2:44789] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "feathersolar.com"] [uri "/.env"] [unique_id "aTeLCm2J7Ft0IqF3pVWAxwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-08 13:45:33
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 193.56.28.2 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 193.56.28.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 08 08:45:27.180010 2025] [security2:error] [pid 10787:tid 10787] [client 193.56.28.2:50635] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dynamic-therapy-mn.com"] [uri "/.env"] [unique_id "aTbWd2mjt4qTQgwJMFEpiQAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-08 07:41:23
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 193.56.28.2 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 193.56.28.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 08 02:41:17.692344 2025] [security2:error] [pid 7477:tid 7477] [client 193.56.28.2:20671] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "trlservice.com"] [uri "/.svn/wc.db"] [unique_id "aTaBHSx3WGAJ0RbTgCWg2QAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-08 03:02:19
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 193.56.28.2 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 193.56.28.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 07 22:02:14.094374 2025] [security2:error] [pid 30824:tid 30832] [client 193.56.28.2:41307] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "2020comeback.com"] [uri "/.svn/wc.db"] [unique_id "aTY_thPW5Ja0QHb4_sHHZAAAAUY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-07 12:34:25
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 193.56.28.2 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 193.56.28.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 07 07:34:17.711468 2025] [security2:error] [pid 4078:tid 4078] [client 193.56.28.2:40957] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "carra.org"] [uri "/.git/HEAD"] [unique_id "aTV0Se5ATs-dzujD44xiMwAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-06 11:02:57
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 193.56.28.2 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 193.56.28.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 06 06:02:53.317394 2025] [security2:error] [pid 18245:tid 18245] [client 193.56.28.2:35221] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "i-slim.net"] [uri "/.git/HEAD"] [unique_id "aTQNXQMPrHBRMxc2U8Ey5wAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-05 10:51:25
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 193.56.28.2 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 193.56.28.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Dec 05 05:51:16.973540 2025] [security2:error] [pid 10345:tid 10345] [client 193.56.28.2:26245] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "2ezgroup.com"] [uri "/.svn/wc.db"] [unique_id "aTK5JCKriCDtsQzftNBm3AAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-05 05:45:24
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 193.56.28.2 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 193.56.28.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Dec 05 00:45:19.987409 2025] [security2:error] [pid 7236:tid 7236] [client 193.56.28.2:54765] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "loriarsenault.com"] [uri "/.env"] [unique_id "aTJxb6Eipk0VnGkwBq1LDQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack