🇨🇦
45.194.92.80
23 seconds ago
[RoutePulse | 2026-09-10T23:20:24Z]
ATTACK: Threat IP Active
SOURCE: 45.194.92.80 · AS215925 Vpsvaul ...
show more
[RoutePulse | 2026-09-10T23:20:24Z]
ATTACK: Threat IP Active
SOURCE: 45.194.92.80 · AS215925 Vpsvault.host Ltd · United States
EVIDENCE: severity=critical · 10 flows · 1 KB
INTEL: AbuseIPDB 100% (134 reports) | feeds: AbuseIPDB_IP_Blacklist,Spamhaus DROP (15) | RoutePulse score 98/100
24H PERSISTENCE: 36 events (SIEM Firewall Scan×17, SIEM Firewall Threat Intel×15, Threat IP Active×4)
CONVICTION: Tier 4, LLR 9.11, 3.25 independent groups (multi-source SPRT)
MITRE: T1071 Application Layer Protocol
DETECTION: sFlow/IPFIX flow analysis + 14-detector ML stack (6-model weighted ensemble) + threat-intel correlation
ACTION: Pre-blackhole intelligence report (live monitoring continues)
show less
Hacking
Exploited Host
🇺🇸
103.81.231.212
1 minute ago
[RoutePulse | 2026-09-10T23:19:34Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 103.81.231. ...
show more
[RoutePulse | 2026-09-10T23:19:34Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 103.81.231.212 · AS203020 HostRoyale HostRoyale Technologies Pvt Ltd
EVIDENCE: Shunned on the Cisco FTD VPN gateway — Cisco VPN RA Brute force on Cisco FTDv — slow spray: 3 failed logins over 6 h (one every ~188 min, under every 15-min threshold and the FTD hold-down) — rung 1-bis (doc 247 §10.2)
DETECTION: Conviction Engine SPRT + 14-detector ML stack (6-model weighted ensemble) + 5-pillar threat scoring
ACTION: BGP null route injected at RoutePulse network edge
show less
Brute-Force
Hacking
🇩🇪
91.246.51.228
1 minute ago
[RoutePulse | 2026-09-10T23:19:31Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 91.246.51.2 ...
show more
[RoutePulse | 2026-09-10T23:19:31Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 91.246.51.228
EVIDENCE: Shunned on the Cisco FTD VPN gateway — Cisco VPN RA Brute force on Cisco FTDv — shunned by the FTD's own threat detection (adopted by RoutePulse: TTL, strike, diary)
DETECTION: Conviction Engine SPRT + 14-detector ML stack (6-model weighted ensemble) + 5-pillar threat scoring
ACTION: BGP null route injected at RoutePulse network edge
show less
Brute-Force
Hacking
🇫🇷
193.151.191.242
6 minutes ago
[RoutePulse | 2026-09-10T23:14:28Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 193.151.191 ...
show more
[RoutePulse | 2026-09-10T23:14:28Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 193.151.191.242
EVIDENCE: Shunned on the Cisco FTD VPN gateway — Cisco VPN RA Brute force on Cisco FTDv — shunned by the FTD's own threat detection (adopted by RoutePulse: TTL, strike, diary)
DETECTION: Conviction Engine SPRT + 14-detector ML stack (6-model weighted ensemble) + 5-pillar threat scoring
ACTION: BGP null route injected at RoutePulse network edge
show less
Brute-Force
Hacking
🇺🇸
45.148.124.176
6 minutes ago
[RoutePulse | 2026-09-10T23:14:28Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 45.148.124. ...
show more
[RoutePulse | 2026-09-10T23:14:28Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 45.148.124.176
EVIDENCE: Shunned on the Cisco FTD VPN gateway — Cisco VPN RA Brute force on Cisco FTDv — shunned by the FTD's own threat detection (adopted by RoutePulse: TTL, strike, diary)
DETECTION: Conviction Engine SPRT + 14-detector ML stack (6-model weighted ensemble) + 5-pillar threat scoring
ACTION: BGP null route injected at RoutePulse network edge
show less
Brute-Force
Hacking
🇧🇬
78.128.114.46
9 minutes ago
IDS Alert: ET CINS Active Threat Intelligence Poor Reputation IP group 112 === ATTACK === Signature: ...
show more
IDS Alert: ET CINS Active Threat Intelligence Poor Reputation IP group 112 === ATTACK === Signature: ET CINS Active Threat Intelligence Poor Reputation IP group 112 | SID: 2403411 | Severity: 2 | Category: Misc Attack === SOURCE === IP: 78.128.114.46 (IPv4) | Port: 51869 | Country: Bulgaria | ISP: Tamatiya-EOOD | rDNS: ip-114-46.4vendeta.com === TARGET === Host: insightvm.goline.ch | IP: 185.54.80.24 | Port: 3364 | Protocol: TCP | App: N/A === RESPONSE === Time: 2026-09-11 01:11:04 | Action: Blocked
show less
Exploited Host
Hacking
🇺🇸
77.220.194.106
11 minutes ago
[RoutePulse | 2026-09-10T23:09:27Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 77.220.194. ...
show more
[RoutePulse | 2026-09-10T23:09:27Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 77.220.194.106
EVIDENCE: Shunned on the Cisco FTD VPN gateway — Cisco VPN RA Brute force on Cisco FTDv — shunned by the FTD's own threat detection (adopted by RoutePulse: TTL, strike, diary)
DETECTION: Conviction Engine SPRT + 14-detector ML stack (6-model weighted ensemble) + 5-pillar threat scoring
ACTION: BGP null route injected at RoutePulse network edge
show less
Brute-Force
Hacking
🇬🇧
45.82.76.120
11 minutes ago
IDS Alert: ET CINS Active Threat Intelligence Poor Reputation IP group 60 === ATTACK === Signature: ...
show more
IDS Alert: ET CINS Active Threat Intelligence Poor Reputation IP group 60 === ATTACK === Signature: ET CINS Active Threat Intelligence Poor Reputation IP group 60 | SID: 2403359 | Severity: 2 | Category: Misc Attack === SOURCE === IP: 45.82.76.120 (IPv4) | Port: 40476 | Country: Germany | ISP: DETAI | rDNS: None === TARGET === Host: insightvm.goline.ch | IP: 185.54.80.24 | Port: 11371 | Protocol: TCP | App: N/A === RESPONSE === Time: 2026-09-11 01:09:09 | Action: Blocked
show less
Exploited Host
Hacking
🇺🇸
66.132.195.80
15 minutes ago
IDS Alert: ET DROP Dshield Block Listed Source group 1 === ATTACK === Signature: ET DROP Dshield Blo ...
show more
IDS Alert: ET DROP Dshield Block Listed Source group 1 === ATTACK === Signature: ET DROP Dshield Block Listed Source group 1 | SID: 2402000 | Severity: 2 | Category: Misc Attack === SOURCE === IP: 66.132.195.80 (IPv4) | Port: 45774 | Country: United States | ISP: CENSY | rDNS: 80.195.132.66.censys-scanner.com === TARGET === Host: insightvm.goline.ch | IP: 185.54.80.24 | Port: 60418 | Protocol: TCP | App: N/A === RESPONSE === Time: 2026-09-11 01:05:23 | Action: Blocked
show less
Exploited Host
Hacking
🇺🇸
45.148.235.84
16 minutes ago
[RoutePulse | 2026-09-10T23:04:43Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 45.148.235. ...
show more
[RoutePulse | 2026-09-10T23:04:43Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 45.148.235.84 · AS26548 PureVoltage Hosting Inc. · Israel
EVIDENCE: Shunned on the Cisco FTD VPN gateway — Cisco VPN RA Brute force on Cisco FTDv — slow spray: 3 failed logins over 1 h (one every ~20 min, under every 15-min threshold and the FTD hold-down) — rung 1-bis (doc 247 §10.2)
DETECTION: Conviction Engine SPRT + 14-detector ML stack (6-model weighted ensemble) + 5-pillar threat scoring
ACTION: BGP null route injected at RoutePulse network edge
show less
Brute-Force
Hacking
🇺🇸
142.252.120.227
16 minutes ago
[RoutePulse | 2026-09-10T23:04:42Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 142.252.120 ...
show more
[RoutePulse | 2026-09-10T23:04:42Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 142.252.120.227 · AS62240 Clouvider Limited · United States
EVIDENCE: Shunned on the Cisco FTD VPN gateway — Cisco VPN RA Brute force on Cisco FTDv — slow spray: 3 failed logins over 6 h (one every ~183 min, under every 15-min threshold and the FTD hold-down) — rung 1-bis (doc 247 §10.2)
DETECTION: Conviction Engine SPRT + 14-detector ML stack (6-model weighted ensemble) + 5-pillar threat scoring
ACTION: BGP null route injected at RoutePulse network edge
show less
Brute-Force
Hacking
🇺🇸
193.202.80.13
16 minutes ago
[RoutePulse | 2026-09-10T23:04:42Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 193.202.80. ...
show more
[RoutePulse | 2026-09-10T23:04:42Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 193.202.80.13 · AS26548 PureVoltage Hosting Inc. · Israel
EVIDENCE: Shunned on the Cisco FTD VPN gateway — Cisco VPN RA Brute force on Cisco FTDv — shunned by the FTD's own threat detection (adopted by RoutePulse: TTL, strike, diary)
DETECTION: Conviction Engine SPRT + 14-detector ML stack (6-model weighted ensemble) + 5-pillar threat scoring
ACTION: BGP null route injected at RoutePulse network edge
show less
Brute-Force
Hacking
🇺🇸
194.104.11.149
16 minutes ago
[RoutePulse | 2026-09-10T23:04:42Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 194.104.11. ...
show more
[RoutePulse | 2026-09-10T23:04:42Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 194.104.11.149
EVIDENCE: Cisco VPN RA Brute force on Cisco FTDv — portal under siege (35 real failed logins / 15 min): 2 attacker IPs in 194.104.11.0/24 from campaign AS26548 PUREVOLTAGE-INC - PureVoltage Hosting Inc. (228 IPs over the campaign); the attacker reuse · /24 aggregate member of 194.104.11.0/24
DETECTION: Conviction Engine SPRT + 14-detector ML stack (6-model weighted ensemble) + 5-pillar threat scoring
ACTION: BGP null route injected at RoutePulse network edge
show less
Brute-Force
Hacking
🇺🇸
140.235.2.167
16 minutes ago
[RoutePulse | 2026-09-10T23:04:39Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 140.235.2.1 ...
show more
[RoutePulse | 2026-09-10T23:04:39Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 140.235.2.167
EVIDENCE: Cisco VPN RA Brute force on Cisco FTDv — portal under siege (35 real failed logins / 15 min): 1 attacker IP in 140.235.2.0/24 from campaign AS26548 PUREVOLTAGE-INC - PureVoltage Hosting Inc. (228 IPs over the campaign); the attacker reuses · /24 aggregate member of 140.235.2.0/24
DETECTION: Conviction Engine SPRT + 14-detector ML stack (6-model weighted ensemble) + 5-pillar threat scoring
ACTION: BGP null route injected at RoutePulse network edge
show less
Brute-Force
Hacking
🇺🇸
5.181.170.171
16 minutes ago
[RoutePulse | 2026-09-10T23:04:31Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 5.181.170.1 ...
show more
[RoutePulse | 2026-09-10T23:04:31Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 5.181.170.171
EVIDENCE: Shunned on the Cisco FTD VPN gateway — Cisco VPN RA Brute force on Cisco FTDv — distributed attack (3 attempts/15min) — shun on the VPN gateway
DETECTION: Conviction Engine SPRT + 14-detector ML stack (6-model weighted ensemble) + 5-pillar threat scoring
ACTION: BGP null route injected at RoutePulse network edge
show less
Brute-Force
Hacking
🇷🇺
91.238.67.159
17 minutes ago
FortiGate detected brute force login attempt from IPv4 address 91.238.67.159
Brute-Force
SSH
🇺🇸
23.247.136.239
18 minutes ago
[RoutePulse | 2026-09-10T23:02:24Z]
ATTACK: Threat IP Active
SOURCE: 23.247.136.239 · AS46997 Black ...
show more
[RoutePulse | 2026-09-10T23:02:24Z]
ATTACK: Threat IP Active
SOURCE: 23.247.136.239 · AS46997 Black Mesa Corporation · United States
EVIDENCE: severity=critical · 16 flows · 1 KB
INTEL: AbuseIPDB 100% (79 reports) | feeds: AbuseIPDB_IP_Blacklist (74) | RoutePulse score 99/100
24H PERSISTENCE: 65 events (SIEM Firewall Scan×36, SIEM Firewall Threat Intel×17, Host Baseline Shift×9, Threat IP Active×3)
CONVICTION: Tier 4, LLR 9.11, 3 independent groups (multi-source SPRT)
MITRE: T1071 Application Layer Protocol
DETECTION: sFlow/IPFIX flow analysis + 14-detector ML stack (6-model weighted ensemble) + threat-intel correlation
ACTION: Pre-blackhole intelligence report (live monitoring continues)
show less
Hacking
Exploited Host
🇺🇸
45.145.131.159
21 minutes ago
[RoutePulse | 2026-09-10T22:59:28Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 45.145.131. ...
show more
[RoutePulse | 2026-09-10T22:59:28Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 45.145.131.159
EVIDENCE: Shunned on the Cisco FTD VPN gateway — Cisco VPN RA Brute force on Cisco FTDv — shunned by the FTD's own threat detection (adopted by RoutePulse: TTL, strike, diary)
DETECTION: Conviction Engine SPRT + 14-detector ML stack (6-model weighted ensemble) + 5-pillar threat scoring
ACTION: BGP null route injected at RoutePulse network edge
show less
Brute-Force
Hacking
🇫🇷
193.151.191.248
21 minutes ago
[RoutePulse | 2026-09-10T22:59:27Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 193.151.191 ...
show more
[RoutePulse | 2026-09-10T22:59:27Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 193.151.191.248
EVIDENCE: Shunned on the Cisco FTD VPN gateway — Cisco VPN RA Brute force on Cisco FTDv — shunned by the FTD's own threat detection (adopted by RoutePulse: TTL, strike, diary)
DETECTION: Conviction Engine SPRT + 14-detector ML stack (6-model weighted ensemble) + 5-pillar threat scoring
ACTION: BGP null route injected at RoutePulse network edge
show less
Brute-Force
Hacking
🇺🇸
77.220.193.253
21 minutes ago
[RoutePulse | 2026-09-10T22:59:27Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 77.220.193. ...
show more
[RoutePulse | 2026-09-10T22:59:27Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 77.220.193.253
EVIDENCE: Shunned on the Cisco FTD VPN gateway — Cisco VPN RA Brute force on Cisco FTDv — shunned by the FTD's own threat detection (adopted by RoutePulse: TTL, strike, diary)
DETECTION: Conviction Engine SPRT + 14-detector ML stack (6-model weighted ensemble) + 5-pillar threat scoring
ACTION: BGP null route injected at RoutePulse network edge
show less
Brute-Force
Hacking
🇺🇸
172.110.223.207
24 minutes ago
IDS Alert: ET SCAN Sipvicious Scan === ATTACK === Signature: ET SCAN Sipvicious Scan | SID: 2008578 ...
show more
IDS Alert: ET SCAN Sipvicious Scan === ATTACK === Signature: ET SCAN Sipvicious Scan | SID: 2008578 | Severity: 2 | Category: Attempted Information Leak === SOURCE === IP: 172.110.223.207 (IPv4) | Port: 6493 | Country: Philippines | ISP: RIPE | rDNS: None === TARGET === Host: wireguard.goline.ch | IP: 185.54.80.7 | Port: 5060 | Protocol: UDP | App: failed === RESPONSE === Time: 2026-09-11 00:56:16 | Action: Blocked
show less
Port Scan
🇺🇸
45.66.208.42
26 minutes ago
[RoutePulse | 2026-09-10T22:54:37Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 45.66.208.4 ...
show more
[RoutePulse | 2026-09-10T22:54:37Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 45.66.208.42
EVIDENCE: Shunned on the Cisco FTD VPN gateway — Cisco VPN RA Brute force on Cisco FTDv — shunned by the FTD's own threat detection (adopted by RoutePulse: TTL, strike, diary)
DETECTION: Conviction Engine SPRT + 14-detector ML stack (6-model weighted ensemble) + 5-pillar threat scoring
ACTION: BGP null route injected at RoutePulse network edge
show less
Brute-Force
Hacking
🇺🇸
77.220.194.191
26 minutes ago
[RoutePulse | 2026-09-10T22:54:36Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 77.220.194. ...
show more
[RoutePulse | 2026-09-10T22:54:36Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 77.220.194.191
EVIDENCE: Shunned on the Cisco FTD VPN gateway — Cisco VPN RA Brute force on Cisco FTDv — shunned by the FTD's own threat detection (adopted by RoutePulse: TTL, strike, diary)
DETECTION: Conviction Engine SPRT + 14-detector ML stack (6-model weighted ensemble) + 5-pillar threat scoring
ACTION: BGP null route injected at RoutePulse network edge
show less
Brute-Force
Hacking
🇺🇸
45.148.124.35
26 minutes ago
[RoutePulse | 2026-09-10T22:54:35Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 45.148.124. ...
show more
[RoutePulse | 2026-09-10T22:54:35Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 45.148.124.35
EVIDENCE: Shunned on the Cisco FTD VPN gateway — Cisco VPN RA Brute force on Cisco FTDv — shunned by the FTD's own threat detection (adopted by RoutePulse: TTL, strike, diary)
DETECTION: Conviction Engine SPRT + 14-detector ML stack (6-model weighted ensemble) + 5-pillar threat scoring
ACTION: BGP null route injected at RoutePulse network edge
show less
Brute-Force
Hacking
🇺🇸
185.88.100.162
26 minutes ago
[RoutePulse | 2026-09-10T22:54:35Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 185.88.100. ...
show more
[RoutePulse | 2026-09-10T22:54:35Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 185.88.100.162 · AS26548 PUREVOLTAGE-INC - PureVoltage Hosting Inc.
EVIDENCE: Cisco VPN RA Brute force on Cisco FTDv — portal under siege (43 real failed logins / 15 min): 2 attacker IPs in 185.88.100.0/24 from campaign AS26548 PUREVOLTAGE-INC - PureVoltage Hosting Inc. (218 IPs over the campaign); the attacker reuse · /24 aggregate member of 185.88.100.0/24
DETECTION: Conviction Engine SPRT + 14-detector ML stack (6-model weighted ensemble) + 5-pillar threat scoring
ACTION: BGP null route injected at RoutePulse network edge
show less
Brute-Force
Hacking