🇨🇭
SOC [GOLINE SA]
2026-09-03 21:23:46
(2 days ago)
[RoutePulse | 2026-09-03T21:23:46Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 216.26.231. ...
show more
[RoutePulse | 2026-09-03T21:23:46Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 216.26.231.46
EVIDENCE: Shunned on the Cisco FTD VPN gateway — Cisco VPN RA Brute force on Cisco FTDv — distributed attack (3 attempts/15min) — shun on the VPN gateway
DETECTION: Conviction Engine SPRT + 14-detector ML stack (6-model weighted ensemble) + 5-pillar threat scoring
ACTION: BGP null route injected at RoutePulse network edge
show less
Brute-Force
Hacking
🇩🇪
NxtGenIT
2026-09-03 05:55:28
(3 days ago)
CiscoASA Honeypot hit, Payload: "GET /+CSCOE+/logon.html?fcadbadd=1 HTTP/1.1" 200 -,
Brute-Force
🇫🇷
Sklurk
2026-09-01 02:20:55
(5 days ago)
Web App Attack
Web App Attack
🇫🇷
Sklurk
2026-08-11 00:04:50
(3 weeks ago)
Web App Attack
Web App Attack
🇫🇷
Sklurk
2026-07-30 01:29:26
(1 month ago)
Web App Attack
Web App Attack
🇪🇸
librebit
2026-06-24 03:19:27
(2 months ago)
Brute force
Brute-Force
🇬🇧
relianoid.com
2026-04-28 09:14:49
(4 months ago)
POST Abuse detected by Relianoid OSS Load Balancer - relianoid.com
Web Spam
🇦🇺
RedBear IT
2026-03-26 10:00:37
(5 months ago)
"DDoS against public endpoint"
DDoS Attack
Anonymous
2026-03-23 22:18:19
(5 months ago)
Forum/form spam
Web Spam
Anonymous
2026-02-07 22:54:59
(6 months ago)
Forum/form spam
Web Spam
🇺🇸
TPI-Abuse
2025-11-24 08:44:32
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.231.46 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.231.46 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 03:44:26.276244 2025] [security2:error] [pid 12227:tid 12227] [client 216.26.231.46:42185] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.gmroyalties.com"] [uri "/.svn/wc.db"] [unique_id "aSQa6ms11k2GGC92N0IrewAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-24 06:59:11
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.231.46 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.231.46 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 01:59:05.232367 2025] [security2:error] [pid 12103:tid 12134] [client 216.26.231.46:60521] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.x2apparel.com"] [uri "/.svn/wc.db"] [unique_id "aSQCOed3pxroRSWDTtpctwAAAME"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-24 06:42:23
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.231.46 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.231.46 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 01:42:13.846364 2025] [security2:error] [pid 26082:tid 26082] [client 216.26.231.46:38127] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.suedblick.com"] [uri "/.env"] [unique_id "aSP-RTKyLqUOdGsmZ_59eQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-16 06:58:54
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 216.26.231.46 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 216.26.231.46 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 16 01:58:51.703601 2025] [security2:error] [pid 1168:tid 1168] [client 216.26.231.46:25077] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.todddavis.net|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.todddavis.net"] [uri "/s3cmd.ini"] [unique_id "aRl2K2oc5Xj_j0_E8gGPYAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-10-29 13:28:17
(10 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack