Hi, So we've seen a number of our customers having a specific subnet based in St Petersburg, Russia (176.113.115.0/24), trying to bruteforce their VPN servers, using either L2TP, and SSTP.
As its appears across numerous customers, all on different ISPs (some Virgin Media, some GTT, Some BT). Can anyone confirm if they are seeing similar traffic across their networks? Just for peace of mind. I know it's probably just a script kiddy with a bot, but with it seemingly going through our customers during the week, just want to eliminate it being anything else. I have attempted to contact the abuse address, to no avail at present. Kind regards, Simon.
