🇨🇭
SOC [GOLINE SA]
2026-09-08 15:39:56
(4 days ago)
[RoutePulse | 2026-09-08T15:39:56Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 45.136.25.1 ...
show more
[RoutePulse | 2026-09-08T15:39:56Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 45.136.25.115
EVIDENCE: Shunned on the Cisco FTD VPN gateway — Cisco VPN RA Brute force on Cisco FTDv — distributed attack (3 attempts/15min) — shun on the VPN gateway
DETECTION: Conviction Engine SPRT + 14-detector ML stack (6-model weighted ensemble) + 5-pillar threat scoring
ACTION: BGP null route injected at RoutePulse network edge
show less
Brute-Force
Hacking
🇸🇪
OnTheEdge
2026-09-08 13:55:30
(4 days ago)
Password spraying. Multiple unauthorized login attempts
Hacking
Web App Attack
🇨🇦
DRI
2026-09-02 17:27:35
(1 week ago)
Web attack/Malicious activity detected
Web App Attack
🇫🇮
JimArchon72
2026-08-20 08:55:02
(3 weeks ago)
2026/08/20 08:50:44 "GET /wp-login.php?action=register HTTP/1.1"
Web App Attack
🇺🇸
TPI-Abuse
2026-06-14 18:37:34
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 45.136.25.115 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.136.25.115 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 14:37:30.822731 2026] [security2:error] [pid 13744:tid 13744] [client 45.136.25.115:20709] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||noel-designs.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "noel-designs.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ai706qOeTBn_YoiJ9bjW3wAAADg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-06-10 09:20:01
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 45.136.25.115 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.136.25.115 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 05:19:56.832862 2026] [security2:error] [pid 19172:tid 19172] [client 45.136.25.115:40683] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||chadfishman.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "chadfishman.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiksPPdXjuaXAKa_omgF1wAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇱🇻
garmtech.com
2026-01-01 20:27:46
(8 months ago)
IM360 WAF: Attempt to upload malware
Hacking
🇺🇸
TPI-Abuse
2025-12-20 21:23:04
(8 months ago)
(mod_security) mod_security (id:210350) triggered by 45.136.25.115 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 45.136.25.115 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 20 16:22:55.896858 2025] [security2:error] [pid 4985:tid 4985] [client 45.136.25.115:61639] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.londongroup.info|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.londongroup.info"] [uri "/xmlrpc.php"] [unique_id "aUcTr_S-KMZw8BZYKwxnAwAAAA4"], referer: http://www.londongroup.info/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇱🇻
garmtech.com
2025-12-03 22:57:00
(9 months ago)
IM360 WAF: Attempt to upload malware
Hacking
🇱🇻
garmtech.com
2025-12-01 02:00:10
(9 months ago)
IM360 WAF: Attempt to upload malware
Hacking
🇺🇸
fbarela
2025-11-16 02:01:02
(9 months ago)
FortiGate SSL VPN login failures.
Hacking
Brute-Force
🇨🇭
backslash
2025-11-11 15:55:15
(10 months ago)
block ruleset CC531825F9395F9A07FB06C1247C46770A2690F8
Bad Web Bot