Threat LevelHIGH48/1002 rule types
16 incidents · 2 rule types · persistent 45-day campaign · last seen 1d ago
| PTR | N/A |
| Org / ASN | Cloudflare WARP |
| Country | 🇧🇩 Bangladesh |
| City | Dhaka, Dhaka Division |
| Timezone | Asia/Dhaka |
Attack Analysis
WordPress XML-RPC Abuse
This IP targeted xmlrpc.php, a legacy WordPress endpoint that has been abused for brute-force authentication attacks, credential stuffing, and DDoS amplification. Any direct access to xmlrpc.php is an attack or reconnaissance attempt; modern WordPress sites should disable it entirely.
WordPress Username Enumeration
This IP probed the WordPress ?author= parameter to enumerate valid usernames (e.g. ?author=1, ?author=2). Harvested usernames are then fed into credential stuffing or password brute-force attacks. This is purely reconnaissance — there is no legitimate reason to systematically probe author IDs.
Reports (16)
| Date | Severity | Description |
|---|---|---|
| 28 Sep 2026 - 21:16 | high | WordPress: User enumeration — 3+ author probes in 60s |
| 24 Sep 2026 - 01:21 | high | WordPress: xmlrpc.php accessed |
| 24 Sep 2026 - 01:20 | high | WordPress: xmlrpc.php accessed |
| 24 Sep 2026 - 01:19 | high | WordPress: xmlrpc.php accessed |
| 22 Sep 2026 - 01:08 | high | WordPress: xmlrpc.php accessed |
| 21 Sep 2026 - 11:35 | high | WordPress: xmlrpc.php accessed |
| 8 Sep 2026 - 03:37 | high | WordPress: xmlrpc.php accessed |
| 8 Sep 2026 - 03:28 | high | WordPress: xmlrpc.php accessed |
| 28 Aug 2026 - 01:04 | high | Web: xmlrpc.php accessed |
| 28 Aug 2026 - 01:02 | high | Web: xmlrpc.php accessed |
| 26 Aug 2026 - 20:46 | high | Web: xmlrpc.php accessed |
| 26 Aug 2026 - 20:30 | high | Web: xmlrpc.php accessed |
| 15 Aug 2026 - 03:35 | high | Web: xmlrpc.php accessed |
| 15 Aug 2026 - 03:34 | high | Web: xmlrpc.php accessed |
| 15 Aug 2026 - 03:33 | high | Web: xmlrpc.php accessed |
| 15 Aug 2026 - 03:32 | high | Web: xmlrpc.php accessed |
EagleEye Intelligence