🇨🇭
SOC [GOLINE SA]
2026-09-03 09:48:31
(32 minutes ago)
[RoutePulse | 2026-09-03T09:48:31Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 216.26.225. ...
show more
[RoutePulse | 2026-09-03T09:48:31Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 216.26.225.90 · AS200373 Drei-K-Tech-GmbH 3xK Tech GmbH
EVIDENCE: Cisco VPN RA Brute force on Cisco FTDv — distributed attack (6 attempts/15min)
DETECTION: Conviction Engine SPRT + 14-detector ML stack (6-model weighted ensemble) + 5-pillar threat scoring
ACTION: BGP null route injected at RoutePulse network edge
show less
Brute-Force
Hacking
🇫🇷
Sklurk
2026-08-02 02:17:40
(1 month ago)
Web App Attack
Web App Attack
🇫🇷
Sklurk
2026-08-01 01:43:08
(1 month ago)
Web App Attack
Web App Attack
🇫🇷
Sklurk
2026-07-31 01:42:12
(1 month ago)
Web App Attack
Web App Attack
🇺🇸
octageeks.com
2026-04-30 04:06:29
(4 months ago)
Wordpress malicious attack:[octaxmlrpc]
Web App Attack
Anonymous
2026-03-24 19:14:04
(5 months ago)
Forum/form spam
Web Spam
🇺🇸
TPI-Abuse
2026-01-24 10:15:14
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 216.26.225.90 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 216.26.225.90 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 24 05:15:06.307253 2026] [security2:error] [pid 10030:tid 10030] [client 216.26.225.90:35987] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||havelocktruckandauto.ca|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "havelocktruckandauto.ca"] [uri "/lock.db"] [unique_id "aXSbqksDEIlrS6e4OR_acQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-01-13 22:24:46
(7 months ago)
216.26.225.90 - - [13/Jan/2026:22:24:40 +0000] "GET /.env HTTP/1.1" 404 437 "-" "Mozilla/5.0 (Macint ...
show more
216.26.225.90 - - [13/Jan/2026:22:24:40 +0000] "GET /.env HTTP/1.1" 404 437 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
🇵🇱
sefinek.net
2025-12-31 04:22:29
(8 months ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1. ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1.1 (GET method)
Endpoint: /genshin-stella-mod
UA: Mozilla/5.0 (Linux x86_64; rv:114.0) Gecko/20100101 Firefox/114.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇮🇹
VHosting
2025-12-24 07:50:06
(8 months ago)
Detected attack and reported by a human
DDoS Attack
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
SSH
🇺🇸
TPI-Abuse
2025-12-02 20:10:05
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.225.90 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.225.90 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 15:09:57.631204 2025] [security2:error] [pid 11628:tid 11628] [client 216.26.225.90:20789] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wbcsnet.com"] [uri "/.env"] [unique_id "aS9HlYU9iBHBJAJJcMcaXwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-12-02 13:23:55
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.225.90 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.225.90 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 08:23:47.730668 2025] [security2:error] [pid 29195:tid 29195] [client 216.26.225.90:26687] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "goodfrequencies.com"] [uri "/.svn/wc.db"] [unique_id "aS7oY6dyO1IG8yaJ3SmeqQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-12-02 09:31:35
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.225.90 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.225.90 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 04:31:27.970162 2025] [security2:error] [pid 22109:tid 22109] [client 216.26.225.90:22855] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jaragoodrich.com"] [uri "/.git/HEAD"] [unique_id "aS6x71AwORePQZ898yLz_AAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-12-02 08:07:34
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.225.90 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.225.90 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 03:07:29.503935 2025] [security2:error] [pid 6998:tid 6998] [client 216.26.225.90:19213] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "joshuarawlings.com"] [uri "/.env"] [unique_id "aS6eQS7OoYVQa-W0nBrDegAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-12-02 04:46:46
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.225.90 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.225.90 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 01 23:46:42.896155 2025] [security2:error] [pid 1888135:tid 1888135] [client 216.26.225.90:40207] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lucasadams.com"] [uri "/.git/HEAD"] [unique_id "aS5vMtkGqLBOhbn9XTj9dAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack