🇨🇭
SOC [GOLINE SA]
2026-09-02 17:52:56
(12 minutes ago)
[RoutePulse | 2026-09-02T17:52:56Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 45.3.41.1 · ...
show more
[RoutePulse | 2026-09-02T17:52:56Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 45.3.41.1 · AS200373 Drei-K-Tech-GmbH 3xK Tech GmbH
EVIDENCE: Cisco VPN RA Brute force on Cisco FTDv — distributed attack (8 attempts/15min)
DETECTION: Conviction Engine SPRT + 14-detector ML stack (6-model weighted ensemble) + 5-pillar threat scoring
ACTION: BGP null route injected at RoutePulse network edge
show less
Brute-Force
Hacking
🇩🇪
Goetz
2026-09-02 15:07:00
(2 hours ago)
FortiGate SSL VPN login failures.
Hacking
Brute-Force
🇫🇷
Sklurk
2026-08-01 00:58:43
(1 month ago)
Web App Attack
Web App Attack
🇫🇷
Sklurk
2026-07-18 00:35:55
(1 month ago)
Web App Attack
Web App Attack
🇫🇷
Sklurk
2026-07-08 00:54:14
(1 month ago)
Web App Attack
Web App Attack
🇬🇧
PeravixGroup
2026-05-07 11:57:48
(3 months ago)
Honeypot detection: Docker daemon unauthorized access / container escape attempt on port 2375. Sever ...
show more
Honeypot detection: Docker daemon unauthorized access / container escape attempt on port 2375. Severity: MEDIUM. Aaran.cloud
show less
Hacking
Exploited Host
🇩🇪
Packets-Decreaser.NET
2025-12-29 14:00:48
(8 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
🇺🇸
TPI-Abuse
2025-11-26 14:22:12
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.41.1 (-): 1 in the last 300 secs; Ports: * ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.41.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 09:22:06.630963 2025] [security2:error] [pid 31678:tid 31678] [client 45.3.41.1:58069] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.qxz.cc"] [uri "/.svn/wc.db"] [unique_id "aScNDqgy94kd0Zo9il4MNwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-26 08:44:00
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.41.1 (-): 1 in the last 300 secs; Ports: * ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.41.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 03:43:55.210003 2025] [security2:error] [pid 16498:tid 16498] [client 45.3.41.1:11973] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.mosheimlib.org"] [uri "/.env"] [unique_id "aSa9y9ubuyH196OF4FpvEQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-26 07:09:38
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.41.1 (-): 1 in the last 300 secs; Ports: * ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.41.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 02:09:32.902621 2025] [security2:error] [pid 29401:tid 29401] [client 45.3.41.1:44557] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lifebooksource.teamspiro.com"] [uri "/.svn/wc.db"] [unique_id "aSanrCnRWQ9kti8pe45F_wAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-26 05:59:21
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.41.1 (-): 1 in the last 300 secs; Ports: * ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.41.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 00:59:13.808867 2025] [security2:error] [pid 20224:tid 20224] [client 45.3.41.1:32205] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.wmodradio.com"] [uri "/.git/HEAD"] [unique_id "aSaXMYxhoZFBTCcKGP8yOAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-26 01:21:13
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.41.1 (-): 1 in the last 300 secs; Ports: * ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.41.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 20:21:07.403721 2025] [security2:error] [pid 25956:tid 25956] [client 45.3.41.1:54983] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.3wf.com"] [uri "/.git/HEAD"] [unique_id "aSZWA9_rOHWTw0Mc-FyQVAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-25 06:38:47
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.41.1 (-): 1 in the last 300 secs; Ports: * ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.41.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 01:38:37.739946 2025] [security2:error] [pid 20736:tid 20736] [client 45.3.41.1:34533] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.friedasbookfinds.com"] [uri "/.git/HEAD"] [unique_id "aSVO7d0dyOigOtISkFY4WAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-25 05:28:11
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.41.1 (-): 1 in the last 300 secs; Ports: * ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.41.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 00:28:03.107324 2025] [security2:error] [pid 6714:tid 6714] [client 45.3.41.1:52037] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.podbillspec.com"] [uri "/.git/HEAD"] [unique_id "aSU-YwLzLNPFsMycwU_jbQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-25 04:46:46
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.41.1 (-): 1 in the last 300 secs; Ports: * ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.41.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 23:46:39.656783 2025] [security2:error] [pid 621:tid 621] [client 45.3.41.1:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.dentguyvt.com"] [uri "/.svn/wc.db"] [unique_id "aSU0r931rsKUO5VIWJtRswAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack