🇨🇭
SOC [GOLINE SA]
2026-09-03 20:38:36
(6 days ago)
[RoutePulse | 2026-09-03T20:38:36Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 65.111.15.1 ...
show more
[RoutePulse | 2026-09-03T20:38:36Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 65.111.15.124
EVIDENCE: Shunned on the Cisco FTD VPN gateway — Cisco VPN RA Brute force on Cisco FTDv — distributed attack (3 attempts/15min) — shun on the VPN gateway
DETECTION: Conviction Engine SPRT + 14-detector ML stack (6-model weighted ensemble) + 5-pillar threat scoring
ACTION: BGP null route injected at RoutePulse network edge
show less
Brute-Force
Hacking
Anonymous
2026-08-09 15:56:13
(1 month ago)
DEAGICO WEBFORM SPAM 65.111.15.124 (65.111.15.124)
Web Spam
🇱🇻
garmtech.com
2026-05-17 16:00:40
(3 months ago)
IM360 WAF: Old style account creation and modification in Joomla! MV:registration
Web App Attack
🇦🇺
RedBear IT
2026-03-26 10:00:37
(5 months ago)
"DDoS against public endpoint"
DDoS Attack
🇺🇸
nowyouknow
2026-01-30 11:47:17
(7 months ago)
Malicious Traffic/Form Submission
Phishing
Web Spam
🇪🇸
10dencehispahard SL
2026-01-26 12:08:57
(7 months ago)
Wordpress probing for vulnerabilities
Hacking
Exploited Host
🇮🇹
VHosting
2026-01-03 05:00:12
(8 months ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2025-12-29 08:16:24
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.15.124 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.15.124 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 03:16:18.524728 2025] [security2:error] [pid 32384:tid 32384] [client 65.111.15.124:34873] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rosemeadefarms.com"] [uri "/.git/HEAD"] [unique_id "aVI40oV2TxwTeFtd4wG-RwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-12-29 07:37:44
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.15.124 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.15.124 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 02:37:37.491528 2025] [security2:error] [pid 19836:tid 19836] [client 65.111.15.124:49143] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "laradioactivitat.com"] [uri "/.svn/wc.db"] [unique_id "aVIvwWfqAsbCcRVRvbyM6gAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
i-turnradio.nl
2025-12-10 17:03:13
(8 months ago)
2025-12-10 @ 18:03:12 (CET) ~ Blocked based on risk assessment and prior abuse reports
Web App Attack
🇺🇸
TPI-Abuse
2025-12-07 13:07:41
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.15.124 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.15.124 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 07 08:07:34.428678 2025] [security2:error] [pid 21980:tid 21980] [client 65.111.15.124:24423] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "exhaustthelimits.org"] [uri "/.svn/wc.db"] [unique_id "aTV8Fg_8CSgUiqnyHy_ItgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
jjnxpct
2025-12-07 04:54:46
(9 months ago)
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting UR ...
show more
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting URI: /.env (Rule ID: 930130) - Restricted File Access Attempt [Suspicious: .env found within REQUEST_FILENAME: /.env]
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2025-12-06 12:18:27
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.15.124 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.15.124 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 06 07:18:18.731850 2025] [security2:error] [pid 13030:tid 13054] [client 65.111.15.124:47701] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "seasonsgreeters.net"] [uri "/.git/HEAD"] [unique_id "aTQfCsr_yrJadsRL9ju8cAAAANY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-12-06 11:48:04
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.15.124 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.15.124 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 06 06:47:59.418268 2025] [security2:error] [pid 14760:tid 14760] [client 65.111.15.124:41991] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "royalchess.net"] [uri "/.svn/wc.db"] [unique_id "aTQX76598n_mTvYpRrEAxAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇵🇱
sefinek.net
2025-12-05 16:33:10
(9 months ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1. ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1.1 (GET method)
Endpoint: /
UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36 Vivaldi/5.3.2679.68
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot