🇨🇭
SOC [GOLINE SA]
2026-09-08 03:44:53
(9 hours ago)
[RoutePulse | 2026-09-08T03:44:53Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 31.134.12.4 ...
show more
[RoutePulse | 2026-09-08T03:44:53Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 31.134.12.40 · AS43444 BNS-AS Fast Servers (Pty) Ltd
EVIDENCE: Shunned on the Cisco FTD VPN gateway — Cisco VPN RA Brute force on Cisco FTDv — distributed attack (3 attempts/15min) — shun on the VPN gateway
DETECTION: Conviction Engine SPRT + 14-detector ML stack (6-model weighted ensemble) + 5-pillar threat scoring
ACTION: BGP null route injected at RoutePulse network edge
show less
Brute-Force
Hacking
🇳🇿
Tripwire
2026-07-13 09:36:53
(1 month ago)
Wordpress login attempts
Brute-Force
Web App Attack
🇳🇿
Tripwire
2026-07-02 18:34:16
(2 months ago)
Wordpress login attempts
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-04-10 12:19:17
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 31.134.12.40 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 31.134.12.40 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 10 08:19:11.941459 2026] [security2:error] [pid 3901715:tid 3901715] [client 31.134.12.40:52721] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||ekur-art.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "ekur-art.com"] [uri "/wp-json/wp/v2/users"] [unique_id "adjqvzFKx78kQZ_P2GeJ-AAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
filstal.org
2026-04-10 04:52:26
(4 months ago)
Security scan or malicious bot activity detected by Fail2Ban
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-04-09 02:21:22
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 31.134.12.40 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 31.134.12.40 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 08 22:21:16.280450 2026] [security2:error] [pid 1997549:tid 1997554] [client 31.134.12.40:12583] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||cocoonprojects.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "cocoonprojects.com"] [uri "/wp-json/wp/v2/users"] [unique_id "adcNHHvnxOxiWi-UghiJ6gAAAUE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-04-09 00:00:48
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 31.134.12.40 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 31.134.12.40 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 08 20:00:44.619774 2026] [security2:error] [pid 4073952:tid 4073952] [client 31.134.12.40:11975] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||clayrivers.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "clayrivers.com"] [uri "/wp-json/wp/v2/users"] [unique_id "adbsLBXHdPN48tUv33wIsgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-04-08 01:11:32
(5 months ago)
31.134.12.40 - - [08/Apr/2026:03:11:30 +0200] "GET /wp-json/wp/v2/users HTTP/2.0" 301 169 "-" "Go-ht ...
show more
31.134.12.40 - - [08/Apr/2026:03:11:30 +0200] "GET /wp-json/wp/v2/users HTTP/2.0" 301 169 "-" "Go-http-client/2.0"
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-03-21 10:58:03
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 31.134.12.40 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 31.134.12.40 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 21 06:58:00.241584 2026] [security2:error] [pid 8156:tid 8156] [client 31.134.12.40:64707] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.zezel.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.zezel.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ab55uHrva5rjtHEJ48J5wQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
backslash
2026-03-14 07:18:49
(5 months ago)
Bad Web Bot
Anonymous
2026-01-27 18:34:56
(7 months ago)
Attempted brute force login to web vpn 1 time(s); last attempt for 2026.01.27 is noted in report tim ...
show more
Attempted brute force login to web vpn 1 time(s); last attempt for 2026.01.27 is noted in report timestamp
show less
Hacking
Brute-Force
🇺🇸
fbarela
2025-10-12 03:00:17
(10 months ago)
FortiGate SSL VPN login failures.
Hacking
Brute-Force