Threat LevelMEDIUM40/1002 rule types
2 incidents on record · 2 rule types · confirmed on global blocklist · active over 5 days · last seen 13d ago
| PTR | N/A |
| Org / ASN | Oracle Cloud Infrastructure (us-phoenix-1) |
| Country | 🇺🇸 United States |
| City | Phoenix, Arizona |
| Timezone | America/Phoenix |
Attack Analysis
Listed on 1 threat-intelligence blocklist
- FireHOL level2 — FireHOL level2 lists addresses seen attacking in the last 48 hours across many sensors. It is large and volatile: addresses enter and leave quickly, so on its own this is weaker, recent-activity evidence.
Plugin/Theme Version Fingerprinting Probe
This IP requested an installed plugin or theme's readme.txt/changelog.txt directly over HTTP — the file's "Stable tag:" line names the exact installed version, which an attacker cross-references against known CVEs for that version before firing the real exploit. WordPress.org's own tooling reads this file server-side, never over HTTP.
Reports (2)
| Date | Severity | Description |
|---|---|---|
| 16 Sep 2026 - 15:01 | low | Query Guard — Path Plugin Theme Readme Probe |
| 11 Sep 2026 - 14:28 | low | FireHOL level2 (48h recent-attacker feed, large & volatile) |
EagleEye Intelligence