🇨🇭
SOC [GOLINE SA]
2026-09-02 08:59:55
(2 weeks ago)
[RoutePulse | 2026-09-02T08:59:55Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 65.111.15.7 ...
show more
[RoutePulse | 2026-09-02T08:59:55Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 65.111.15.76 · AS200373 3xK Tech GmbH · United States
EVIDENCE: Cisco VPN RA Brute force on Cisco FTDv — high-volume source (22 attempts/15min)
DETECTION: Conviction Engine SPRT + 14-detector ML stack (6-model weighted ensemble) + 5-pillar threat scoring
ACTION: BGP null route injected at RoutePulse network edge
show less
Brute-Force
Hacking
🇩🇪
conseilgouz
2026-08-29 12:11:58
(2 weeks ago)
sle-6 : Trying access system files=>/wp-login.php(wp-login.php)
Hacking
Anonymous
2026-08-29 05:38:46
(3 weeks ago)
Network service scanning detected by FortiGate; source quarantined.
Port Scan
🇮🇹
VHosting
2026-08-28 13:25:04
(3 weeks ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-02-09 20:40:50
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.15.76 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.15.76 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 15:40:42.701029 2026] [security2:error] [pid 1433:tid 1433] [client 65.111.15.76:36399] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gamerah.net"] [uri "/admin/.env"] [unique_id "aYpGSvpNUbZZ_BLFwyapXwAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-02-09 20:08:35
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.15.76 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.15.76 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 15:08:28.372535 2026] [security2:error] [pid 5643:tid 5643] [client 65.111.15.76:32197] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "galengetting.com"] [uri "/.env.local"] [unique_id "aYo-vFzqnd5QcvoMuguNHAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-02-09 11:04:18
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.15.76 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.15.76 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 06:04:08.164802 2026] [security2:error] [pid 10081:tid 10081] [client 65.111.15.76:43329] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gaksato.com"] [uri "/site/.git/config"] [unique_id "aYm_KE9Ff0MPHmZrcfmooAAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-02-08 21:13:44
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.15.76 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.15.76 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 08 16:13:37.303874 2026] [security2:error] [pid 19941:tid 19941] [client 65.111.15.76:15533] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fsmfl.com"] [uri "/api/.env"] [unique_id "aYj8gU78cxHcC0TNkKkJfAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Packets-Decreaser.NET
2025-11-30 13:09:49
(9 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
🇦🇺
MAGIC
2025-11-19 04:09:07
(10 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
Anonymous
2025-11-14 08:50:41
(10 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
🇨🇦
wil.com
2025-10-29 10:12:03
(10 months ago)
GlobalProtect login attempts with user ertika.
VPN IP
Brute-Force
🇨🇦
wil.com
2025-10-29 05:40:27
(10 months ago)
GlobalProtect login attempts with user skinnerjt.
VPN IP
Brute-Force
🇩🇪
ps-center
2025-10-27 04:22:00
(10 months ago)
C1-W: TCP-Scanner. Port: 22
Port Scan
Anonymous
2025-10-13 17:41:48
(11 months ago)
Dictionary attack on Palo Alto GlobalProtect VPN portal (port 443) detected via repeated login failu ...
show more
Dictionary attack on Palo Alto GlobalProtect VPN portal (port 443) detected via repeated login failures with varying usernames.
show less
Brute-Force