🇨🇭
SOC [GOLINE SA]
2026-09-10 23:04:43
(3 hours ago)
[RoutePulse | 2026-09-10T23:04:43Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 45.148.235. ...
show more
[RoutePulse | 2026-09-10T23:04:43Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 45.148.235.84 · AS26548 PureVoltage Hosting Inc. · Israel
EVIDENCE: Shunned on the Cisco FTD VPN gateway — Cisco VPN RA Brute force on Cisco FTDv — slow spray: 3 failed logins over 1 h (one every ~20 min, under every 15-min threshold and the FTD hold-down) — rung 1-bis (doc 247 §10.2)
DETECTION: Conviction Engine SPRT + 14-detector ML stack (6-model weighted ensemble) + 5-pillar threat scoring
ACTION: BGP null route injected at RoutePulse network edge
show less
Brute-Force
Hacking
🇸🇪
OnTheEdge
2026-09-09 15:18:47
(1 day ago)
Password spraying. Multiple unauthorized login attempts
Hacking
Web App Attack
🇨🇭
SOC [GOLINE SA]
2026-09-09 14:41:24
(1 day ago)
[RoutePulse | 2026-09-09T14:41:24Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 45.148.235. ...
show more
[RoutePulse | 2026-09-09T14:41:24Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 45.148.235.84 · AS26548 PureVoltage Hosting Inc. · Israel
EVIDENCE: Shunned on the Cisco FTD VPN gateway — Cisco VPN RA Brute force on Cisco FTDv — distributed attack (3 attempts/15min) — shun on the VPN gateway
DETECTION: Conviction Engine SPRT + 14-detector ML stack (6-model weighted ensemble) + 5-pillar threat scoring
ACTION: BGP null route injected at RoutePulse network edge
show less
Brute-Force
Hacking
🇺🇸
TPI-Abuse
2026-05-14 14:59:35
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 45.148.235.84 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.148.235.84 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 14 10:59:30.216579 2026] [security2:error] [pid 29098:tid 29098] [client 45.148.235.84:38565] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||kerrywelt.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "kerrywelt.com"] [uri "/wp-json/wp/v2/users"] [unique_id "agXjUhAzzTBIX-fKzDR1cgAAAAk"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Lino Project
2026-05-14 12:18:08
(3 months ago)
45.148.235.84 - - [14/May/2026:14:18:08 +0200] "POST /xmlrpc.php HTTP/1.1" 403 3987 "-" "Mozilla/5.0 ...
show more
45.148.235.84 - - [14/May/2026:14:18:08 +0200] "POST /xmlrpc.php HTTP/1.1" 403 3987 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0 CriOS/79.0.3945.117 Mobile/15E148 Safari/604.1"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
🇱🇻
garmtech.com
2026-04-07 04:20:56
(5 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 07-20.45.148.235.84.web-spamme ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 07-20.45.148.235.84.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
🇩🇪
Lino Project
2026-04-06 11:56:52
(5 months ago)
45.148.235.84 - - [06/Apr/2026:13:56:52 +0200] "POST /xmlrpc.php HTTP/1.1" 403 3978 "-" "Mozilla/5.0 ...
show more
45.148.235.84 - - [06/Apr/2026:13:56:52 +0200] "POST /xmlrpc.php HTTP/1.1" 403 3978 "-" "Mozilla/5.0 (Linux; Android 9; COL-L29) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.136 Mobile Safari/537.36"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
DocNetzwerk
2026-03-21 04:53:15
(5 months ago)
(wordpress) Failed wordpress login from 45.148.235.84 (IL/Israel/-)
Brute-Force
🇩🇪
C C
2026-02-23 11:15:57
(6 months ago)
Distributed proxy crawl wave (89 requests, 89 unique IPs in 55 sec)
Bad Web Bot
Web App Attack
🇱🇻
garmtech.com
2026-02-15 19:20:26
(6 months ago)
IM360 WAF: Old style account creation and modification in Joomla! MV:registration
Web App Attack
🇺🇸
TPI-Abuse
2026-01-23 01:31:52
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 45.148.235.84 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.148.235.84 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 22 20:31:44.237703 2026] [security2:error] [pid 26586:tid 26586] [client 45.148.235.84:13577] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||soudertonbigred.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "soudertonbigred.org"] [uri "/wp-json/wp/v2/users"] [unique_id "aXLPgJm8mNa7_cj1xwQYBQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-01-22 09:44:10
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 45.148.235.84 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.148.235.84 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 22 04:44:03.187134 2026] [security2:error] [pid 844525:tid 844525] [client 45.148.235.84:58537] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||deolu.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "deolu.org"] [uri "/wp-json/wp/v2/users"] [unique_id "aXHxY9cYYarOdnRQfI46AAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Packets-Decreaser.NET
2025-09-15 01:02:43
(11 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
Anonymous
2025-06-19 15:50:19
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2025-06-17 10:01:31
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH