Report for IP: 161.118.209.161

Threat LevelCRITICAL72/1002 rule types
2 incidents on record · 2 rule types · active attack detected · active over 4 days · last seen 18d ago
PTR N/A
Org / ASN Oracle Cloud Infrastructure (ap-singapore-1)
Country 🇸🇬 Singapore
City Singapore, Central Singapore
Timezone Asia/Singapore

Attack Analysis

Plugin/Theme Version Fingerprinting Probe
This IP requested an installed plugin or theme's readme.txt/changelog.txt directly over HTTP — the file's "Stable tag:" line names the exact installed version, which an attacker cross-references against known CVEs for that version before firing the real exploit. WordPress.org's own tooling reads this file server-side, never over HTTP.
Suricata IDS Alert
Suricata intrusion detection flagged this IP for malicious network behaviour — including port scanning, exploit attempts, botnet activity, or known attack signatures. The specific signature is shown in the report list below.

Reports (2)

Date Severity Description
11 Sep 2026 - 18:58 high IDS: Suricata alert
7 Sep 2026 - 13:40 low Query Guard — Path Plugin Theme Readme Probe