Threat LevelMEDIUM36/1001 rule type
6 incidents on record · persistent 18-day campaign · last seen 11d ago
| PTR | N/A |
| Org / ASN | Cloudflare WARP |
| Country | 🇺🇸 United States |
| City | St Louis, Missouri |
| Timezone | America/Chicago |
Attack Analysis
Directory Brute-Force (Active Scan)
This IP triggered 10 or more HTTP 4xx errors within 60 seconds — the signature of a vulnerability scanner cycling through wordlists of common admin paths, config files, and endpoints. Tools like Nikto, Dirbuster, and Gobuster produce exactly this pattern.
Reports (6)
| Date | Severity | Description |
|---|---|---|
| 21 Jul 2026 - 05:40 | high | Web: Active scan — 10+ 4xx errors in 60s |
| 21 Jul 2026 - 05:31 | high | Web: Active scan — 10+ 4xx errors in 60s |
| 21 Jul 2026 - 05:30 | high | Web: Active scan — 10+ 4xx errors in 60s |
| 3 Jul 2026 - 07:00 | high | Web: Active scan — 10+ 4xx errors in 60s |
| 3 Jul 2026 - 06:46 | high | Web: Active scan — 10+ 4xx errors in 60s |
| 3 Jul 2026 - 06:45 | high | Web: Active scan — 10+ 4xx errors in 60s |
EagleEye Intelligence