Threat LevelCRITICAL72/1002 rule types across 2 attack categories
8 incidents on record · 2 rule types · active attack detected · persistent 22-day campaign · seen 24h ago
| PTR | N/A |
| Org / ASN | Oracle Cloud Infrastructure (ap-singapore-1) |
| Country | 🇸🇬 Singapore |
| City | Singapore, Central Singapore |
| Timezone | Asia/Singapore |
Attack Analysis
Backup & Database File Probe
This IP requested common backup file paths (.bak, .sql, .zip, wp-config.bak), hunting for database dumps or config files containing plaintext credentials. A single exposed wp-config.bak can hand an attacker full database access. This attack is automated and deliberate.
Suricata IDS Alert
Suricata intrusion detection flagged this IP for malicious network behaviour — including port scanning, exploit attempts, botnet activity, or known attack signatures. The specific signature is shown in the report list below.
Reports (8)
| Date | Severity | Description |
|---|---|---|
| 29 Sep 2026 - 00:46 | medium | IDS: Suricata alert — ET INFO Request to Hidden Environment File - Inbound |
| 27 Sep 2026 - 00:52 | medium | IDS: Suricata alert — ET INFO Request to Hidden Environment File - Inbound |
| 23 Sep 2026 - 00:22 | medium | IDS: Suricata alert — ET INFO Request to Hidden Environment File - Inbound |
| 22 Sep 2026 - 00:58 | medium | IDS: Suricata alert — ET INFO Request to Hidden Environment File - Inbound |
| 20 Sep 2026 - 00:52 | medium | IDS: Suricata alert — ET INFO Request to Hidden Environment File - Inbound |
| 13 Sep 2026 - 00:26 | medium | IDS: Suricata alert — ET INFO Request to Hidden Environment File - Inbound |
| 7 Sep 2026 - 10:13 | medium | IDS: Suricata alert — ET INFO Request to Hidden Environment File - Inbound |
| 7 Sep 2026 - 10:13 | high | Web: Backup/database file probe |
EagleEye Intelligence