Threat LevelHIGH51/1003 rule types across 2 attack categories
3 incidents on record · 3 rule types · active attack detected · last seen 15d ago
| PTR | N/A |
| Org / ASN | DigitalOcean, LLC |
| Country | 🇸🇬 Singapore |
| City | Singapore, South West |
| Timezone | Asia/Singapore |
Attack Analysis
WordPress: Brute Force Attack
This IP was blocked attempting to log into a WordPress site's wp-login.php — either from a disallowed country or after exceeding the allowed number of failed login attempts. Automated credential-stuffing and brute-force tools account for the overwhelming majority of this traffic; legitimate users rarely trigger a hard IP block on login alone.
WordPress: Author Enumeration
This IP probed the WordPress ?author= parameter to enumerate valid usernames, feeding a list of real accounts into subsequent credential-stuffing attacks. Pure reconnaissance with no legitimate use case.
WordPress Username Enumeration
This IP probed the WordPress ?author= parameter to enumerate valid usernames (e.g. ?author=1, ?author=2). Harvested usernames are then fed into credential stuffing or password brute-force attacks. This is purely reconnaissance — there is no legitimate reason to systematically probe author IDs.
Reports (3)
| Date | Severity | Description |
|---|---|---|
| 15 Sep 2026 - 06:46 | high | WordPress: User enumeration — 3+ author probes in 60s |
| 15 Sep 2026 - 06:45 | low | User Enum — Author Scan |
| 14 Sep 2026 - 22:33 | medium | WordPress Login Brute Force Attempt |
EagleEye Intelligence