🇨🇭
SOC [GOLINE SA]
2026-08-06 09:49:03
(2 hours ago)
[RoutePulse | 2026-08-06T09:49:03Z | RTBH-INJECTED]
ATTACK CLASS: volumetric
SOURCE: 89.248.163.25 · ...
show more
[RoutePulse | 2026-08-06T09:49:03Z | RTBH-INJECTED]
ATTACK CLASS: volumetric
SOURCE: 89.248.163.25 · AS202425 IP Volume inc · The Netherlands
EVIDENCE: Multi-source convergence on threat indicators
INTEL: AbuseIPDB 94% | RoutePulse score 98/100
CONVICTION: Tier 4, LLR 9.11 (multi-source SPRT)
MITRE: T1498 Network Denial of Service, T1499 Endpoint DoS
DETECTION: Conviction Engine SPRT + 14-detector ML stack (6-model weighted ensemble) + 5-pillar threat scoring
ACTION: BGP null route injected at RoutePulse network edge
show less
DDoS Attack
🇨🇭
SOC [GOLINE SA]
2026-08-06 03:51:51
(8 hours ago)
[RoutePulse | 2026-08-06T03:51:50Z]
ATTACK: Threat IP Active
SOURCE: 89.248.163.25 · AS202425 IP Vol ...
show more
[RoutePulse | 2026-08-06T03:51:50Z]
ATTACK: Threat IP Active
SOURCE: 89.248.163.25 · AS202425 IP Volume inc · The Netherlands
EVIDENCE: severity=warning · 12 flows · 720 KB
INTEL: AbuseIPDB 94% (602 reports) | RoutePulse score 97/100
24H PERSISTENCE: 61 events (SIEM Firewall Scan×33, Threat IP Active×28)
CONVICTION: Tier 4, LLR 9.11, 3.5 independent groups (multi-source SPRT)
MITRE: T1071 Application Layer Protocol
DETECTION: sFlow/IPFIX flow analysis + 14-detector ML stack (6-model weighted ensemble) + threat-intel correlation
ACTION: Pre-blackhole intelligence report (live monitoring continues)
show less
Hacking
Exploited Host
🇨🇭
SOC [GOLINE SA]
2026-08-06 03:24:15
(8 hours ago)
[RoutePulse | 2026-08-06T03:24:15Z]
ATTACK: Threat IP Active
SOURCE: 89.248.163.25 · AS202425 IP Vol ...
show more
[RoutePulse | 2026-08-06T03:24:15Z]
ATTACK: Threat IP Active
SOURCE: 89.248.163.25 · AS202425 IP Volume inc · The Netherlands
EVIDENCE: severity=warning · 10 flows · 600 KB
INTEL: AbuseIPDB 94% (602 reports) | RoutePulse score 97/100
24H PERSISTENCE: 56 events (SIEM Firewall Scan×31, Threat IP Active×25)
CONVICTION: Tier 4, LLR 9.11, 3.5 independent groups (multi-source SPRT)
MITRE: T1071 Application Layer Protocol
DETECTION: sFlow/IPFIX flow analysis + 14-detector ML stack (6-model weighted ensemble) + threat-intel correlation
ACTION: Pre-blackhole intelligence report (live monitoring continues)
show less
Hacking
Exploited Host
🇨🇭
SOC [GOLINE SA]
2026-08-06 02:29:14
(9 hours ago)
[RoutePulse | 2026-08-06T02:29:14Z]
ATTACK: Threat IP Active
SOURCE: 89.248.163.25 · AS202425 IP Vol ...
show more
[RoutePulse | 2026-08-06T02:29:14Z]
ATTACK: Threat IP Active
SOURCE: 89.248.163.25 · AS202425 IP Volume inc · The Netherlands
EVIDENCE: severity=warning · 11 flows · 660 KB
INTEL: AbuseIPDB 94% (602 reports) | RoutePulse score 97/100
24H PERSISTENCE: 55 events (SIEM Firewall Scan×30, Threat IP Active×25)
CONVICTION: Tier 4, LLR 9.11, 3.5 independent groups (multi-source SPRT)
MITRE: T1071 Application Layer Protocol
DETECTION: sFlow/IPFIX flow analysis + 14-detector ML stack (6-model weighted ensemble) + threat-intel correlation
ACTION: Pre-blackhole intelligence report (live monitoring continues)
show less
Hacking
Exploited Host
🇨🇭
SOC [GOLINE SA]
2026-08-06 01:10:55
(10 hours ago)
[RoutePulse | 2026-08-06T01:10:55Z]
ATTACK: Threat IP Active
SOURCE: 89.248.163.25 · AS202425 IP Vol ...
show more
[RoutePulse | 2026-08-06T01:10:55Z]
ATTACK: Threat IP Active
SOURCE: 89.248.163.25 · AS202425 IP Volume inc · The Netherlands
EVIDENCE: severity=warning · 10 flows · 600 KB
INTEL: AbuseIPDB 94% (602 reports) | RoutePulse score 97/100
24H PERSISTENCE: 54 events (SIEM Firewall Scan×29, Threat IP Active×25)
CONVICTION: Tier 4, LLR 9.11, 3.5 independent groups (multi-source SPRT)
MITRE: T1071 Application Layer Protocol
DETECTION: sFlow/IPFIX flow analysis + 14-detector ML stack (6-model weighted ensemble) + threat-intel correlation
ACTION: Pre-blackhole intelligence report (live monitoring continues)
show less
Hacking
Exploited Host
🇨🇭
SOC [GOLINE SA]
2026-08-06 00:55:55
(11 hours ago)
[RoutePulse | 2026-08-06T00:55:55Z]
ATTACK: Threat IP Active
SOURCE: 89.248.163.25 · AS202425 IP Vol ...
show more
[RoutePulse | 2026-08-06T00:55:55Z]
ATTACK: Threat IP Active
SOURCE: 89.248.163.25 · AS202425 IP Volume inc · The Netherlands
EVIDENCE: severity=warning · 12 flows · 720 KB
INTEL: AbuseIPDB 94% (602 reports) | RoutePulse score 97/100
24H PERSISTENCE: 51 events (SIEM Firewall Scan×28, Threat IP Active×23)
CONVICTION: Tier 4, LLR 9.11, 3.5 independent groups (multi-source SPRT)
MITRE: T1071 Application Layer Protocol
DETECTION: sFlow/IPFIX flow analysis + 14-detector ML stack (6-model weighted ensemble) + threat-intel correlation
ACTION: Pre-blackhole intelligence report (live monitoring continues)
show less
Hacking
Exploited Host
🇨🇭
pingusurmars
2026-08-06 00:44:55
(11 hours ago)
Blocked by UFW on ampereone [13470/tcp]
Source port: 49190
TTL: 247
Packet length: 40
TOS: 0x00
Thi ...
show more
Blocked by UFW on ampereone [13470/tcp]
Source port: 49190
TTL: 247
Packet length: 40
TOS: 0x00
This report was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
🇨🇭
pingusurmars
2026-08-06 00:22:11
(11 hours ago)
Blocked by UFW on amperetwo [16197/tcp]
Source port: 49190
TTL: 247
Packet length: 40
TOS: 0x00
Thi ...
show more
Blocked by UFW on amperetwo [16197/tcp]
Source port: 49190
TTL: 247
Packet length: 40
TOS: 0x00
This report was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
🇨🇭
SOC [GOLINE SA]
2026-08-06 00:07:47
(11 hours ago)
[RoutePulse | 2026-08-06T00:07:47Z]
ATTACK: Threat IP Active
SOURCE: 89.248.163.25 · AS202425 IP Vol ...
show more
[RoutePulse | 2026-08-06T00:07:47Z]
ATTACK: Threat IP Active
SOURCE: 89.248.163.25 · AS202425 IP Volume inc · The Netherlands
EVIDENCE: severity=warning · 11 flows · 660 KB
INTEL: AbuseIPDB 94% (602 reports) | RoutePulse score 97/100
24H PERSISTENCE: 50 events (SIEM Firewall Scan×27, Threat IP Active×23)
CONVICTION: Tier 4, LLR 9.11, 3.5 independent groups (multi-source SPRT)
MITRE: T1071 Application Layer Protocol
DETECTION: sFlow/IPFIX flow analysis + 14-detector ML stack (6-model weighted ensemble) + threat-intel correlation
ACTION: Pre-blackhole intelligence report (live monitoring continues)
show less
Hacking
Exploited Host
🇨🇭
SOC [GOLINE SA]
2026-08-05 23:32:16
(12 hours ago)
[RoutePulse | 2026-08-05T23:32:16Z]
ATTACK: Threat IP Active
SOURCE: 89.248.163.25 · AS202425 IP Vol ...
show more
[RoutePulse | 2026-08-05T23:32:16Z]
ATTACK: Threat IP Active
SOURCE: 89.248.163.25 · AS202425 IP Volume inc · The Netherlands
EVIDENCE: severity=warning · 12 flows · 700 KB
INTEL: AbuseIPDB 94% (602 reports) | RoutePulse score 97/100
24H PERSISTENCE: 47 events (SIEM Firewall Scan×25, Threat IP Active×22)
CONVICTION: Tier 4, LLR 9.11, 3.5 independent groups (multi-source SPRT)
MITRE: T1071 Application Layer Protocol
DETECTION: sFlow/IPFIX flow analysis + 14-detector ML stack (6-model weighted ensemble) + threat-intel correlation
ACTION: Pre-blackhole intelligence report (live monitoring continues)
show less
Hacking
Exploited Host
🇨🇭
SOC [GOLINE SA]
2026-08-05 23:12:23
(12 hours ago)
[RoutePulse | 2026-08-05T23:12:23Z]
ATTACK: Threat IP Active
SOURCE: 89.248.163.25 · AS202425 IP Vol ...
show more
[RoutePulse | 2026-08-05T23:12:23Z]
ATTACK: Threat IP Active
SOURCE: 89.248.163.25 · AS202425 IP Volume inc · The Netherlands
EVIDENCE: severity=warning · 12 flows · 720 KB
INTEL: AbuseIPDB 94% (602 reports) | RoutePulse score 97/100
24H PERSISTENCE: 46 events (SIEM Firewall Scan×25, Threat IP Active×21)
CONVICTION: Tier 4, LLR 9.11, 3.5 independent groups (multi-source SPRT)
MITRE: T1071 Application Layer Protocol
DETECTION: sFlow/IPFIX flow analysis + 14-detector ML stack (6-model weighted ensemble) + threat-intel correlation
ACTION: Pre-blackhole intelligence report (live monitoring continues)
show less
Hacking
Exploited Host
🇫🇷
Hostynet
2026-08-05 21:24:12
(14 hours ago)
Port scan detected by MikroTik PSD matcher (21 distinct destination ports in 3 seconds from single s ...
show more
Port scan detected by MikroTik PSD matcher (21 distinct destination ports in 3 seconds from single source). Source automatically blacklisted for 1 week.
show less
Port Scan
🇨🇭
SOC [GOLINE SA]
2026-08-05 21:05:04
(15 hours ago)
[RoutePulse | 2026-08-05T21:05:04Z]
ATTACK: Threat IP Active
SOURCE: 89.248.163.25 · AS202425 IP Vol ...
show more
[RoutePulse | 2026-08-05T21:05:04Z]
ATTACK: Threat IP Active
SOURCE: 89.248.163.25 · AS202425 IP Volume inc · The Netherlands
EVIDENCE: severity=warning · 15 flows · 900 KB
INTEL: AbuseIPDB 94% (602 reports) | RoutePulse score 97/100
24H PERSISTENCE: 41 events (SIEM Firewall Scan×22, Threat IP Active×19)
CONVICTION: Tier 4, LLR 9.11, 3.5 independent groups (multi-source SPRT)
MITRE: T1071 Application Layer Protocol
DETECTION: sFlow/IPFIX flow analysis + 14-detector ML stack (6-model weighted ensemble) + threat-intel correlation
ACTION: Pre-blackhole intelligence report (live monitoring continues)
show less
Hacking
Exploited Host
🇨🇭
SOC [GOLINE SA]
2026-08-05 14:42:54
(21 hours ago)
[RoutePulse | 2026-08-05T14:42:53Z]
ATTACK: Threat IP Active
SOURCE: 89.248.163.25 · AS202425 IP Vol ...
show more
[RoutePulse | 2026-08-05T14:42:53Z]
ATTACK: Threat IP Active
SOURCE: 89.248.163.25 · AS202425 IP Volume inc · The Netherlands
EVIDENCE: severity=warning · 14 flows · 840 KB
INTEL: AbuseIPDB 94% (602 reports) | RoutePulse score 95/100
24H PERSISTENCE: 30 events (Threat IP Active×15, SIEM Firewall Scan×15)
CONVICTION: Tier 4, LLR 9.11, 3.5 independent groups (multi-source SPRT)
MITRE: T1071 Application Layer Protocol
DETECTION: sFlow/IPFIX flow analysis + 14-detector ML stack (6-model weighted ensemble) + threat-intel correlation
ACTION: Pre-blackhole intelligence report (live monitoring continues)
show less
Hacking
Exploited Host
🇨🇭
SOC [GOLINE SA]
2026-08-05 13:33:32
(22 hours ago)
[RoutePulse | 2026-08-05T13:33:32Z]
ATTACK: Threat IP Active
SOURCE: 89.248.163.25 · AS202425 IP Vol ...
show more
[RoutePulse | 2026-08-05T13:33:32Z]
ATTACK: Threat IP Active
SOURCE: 89.248.163.25 · AS202425 IP Volume inc · The Netherlands
EVIDENCE: severity=warning · 11 flows · 660 KB
INTEL: AbuseIPDB 94% (602 reports) | RoutePulse score 95/100
24H PERSISTENCE: 27 events (SIEM Firewall Scan×14, Threat IP Active×13)
CONVICTION: Tier 4, LLR 9.11, 3.5 independent groups (multi-source SPRT)
MITRE: T1071 Application Layer Protocol
DETECTION: sFlow/IPFIX flow analysis + 14-detector ML stack (6-model weighted ensemble) + threat-intel correlation
ACTION: Pre-blackhole intelligence report (live monitoring continues)
show less
Hacking
Exploited Host