๐จ๐ญ
SOC [GOLINE SA]
2026-09-03 10:43:31
(6 hours ago)
[RoutePulse | 2026-09-03T10:43:31Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 65.111.1.42 ...
show more
[RoutePulse | 2026-09-03T10:43:31Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 65.111.1.42 ยท AS200373 Drei-K-Tech-GmbH 3xK Tech GmbH
EVIDENCE: Cisco VPN RA Brute force on Cisco FTDv โ distributed attack (6 attempts/15min)
DETECTION: Conviction Engine SPRT + 14-detector ML stack (6-model weighted ensemble) + 5-pillar threat scoring
ACTION: BGP null route injected at RoutePulse network edge
show less
Brute-Force
Hacking
๐บ๐ธ
drewf.ink
2026-08-29 20:46:17
(4 days ago)
[20:46] Attempted HTTPS access to the GlobalProtect prelogin endpoint on the web honeypot (VPN gatew ...
show more
[20:46] Attempted HTTPS access to the GlobalProtect prelogin endpoint on the web honeypot (VPN gateway fingerprinting/recon)
show less
Web App Attack
Anonymous
2026-05-03 10:00:48
(4 months ago)
Forum/form spam
Web Spam
๐ฆ๐บ
RedBear IT
2026-03-26 10:00:37
(5 months ago)
"DDoS against public endpoint"
DDoS Attack
Anonymous
2026-03-20 23:05:31
(5 months ago)
Forum/form spam
Web Spam
๐บ๐ธ
fbarela
2026-01-14 07:00:12
(7 months ago)
FortiGate SSL VPN login failures.
Hacking
Brute-Force
Anonymous
2025-12-22 16:48:16
(8 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
Anonymous
2025-12-19 13:25:56
(8 months ago)
Attempted brute force login to web vpn 1 time(s); last attempt for 2025.12.19 is noted in report tim ...
show more
Attempted brute force login to web vpn 1 time(s); last attempt for 2025.12.19 is noted in report timestamp
show less
Hacking
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-11-26 10:04:56
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.1.42 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.1.42 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 05:04:48.702963 2025] [security2:error] [pid 22221:tid 22221] [client 65.111.1.42:49251] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.artglass-jerusalem.net"] [uri "/.svn/wc.db"] [unique_id "aSbQwCJ_Zpo30pQveqEq-AAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 05:45:27
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.1.42 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.1.42 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 00:45:16.124908 2025] [security2:error] [pid 11213:tid 11213] [client 65.111.1.42:23863] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.davidbine.net"] [uri "/.svn/wc.db"] [unique_id "aSaT7FX8XWmmZE1auAm21gAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 01:11:29
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.1.42 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.1.42 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 20:11:21.765474 2025] [security2:error] [pid 17928:tid 17928] [client 65.111.1.42:37845] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "danasedge.cain2016.org"] [uri "/.svn/wc.db"] [unique_id "aSZTuTademNuc9Tb8CKU-QAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2025-11-26 01:01:37
(9 months ago)
Attempted access to sensitive endpoint (/.env) detected. Automated scan or unauthorized probing.
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 00:56:51
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.1.42 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.1.42 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 19:56:44.696630 2025] [security2:error] [pid 31461:tid 31461] [client 65.111.1.42:18095] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.tduniverse.net"] [uri "/.env"] [unique_id "aST-zDZTHzDD8CEQsdWZAgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 08:30:18
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.1.42 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.1.42 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 03:30:11.132093 2025] [security2:error] [pid 9543:tid 9543] [client 65.111.1.42:44155] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.taxgroupsd.com"] [uri "/.svn/wc.db"] [unique_id "aSQXk8bkryVvG5PEXa-6PwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-14 05:31:12
(9 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack