Threat LevelCRITICAL72/1002 rule types
2 incidents on record · 2 rule types · active attack detected · active over 4 days · last seen 18d ago
| PTR | N/A |
| Org / ASN | Oracle Cloud Infrastructure (ap-singapore-1) |
| Country | 🇸🇬 Singapore |
| City | Singapore, Central Singapore |
| Timezone | Asia/Singapore |
Attack Analysis
Plugin/Theme Version Fingerprinting Probe
This IP requested an installed plugin or theme's readme.txt/changelog.txt directly over HTTP — the file's "Stable tag:" line names the exact installed version, which an attacker cross-references against known CVEs for that version before firing the real exploit. WordPress.org's own tooling reads this file server-side, never over HTTP.
Suricata IDS Alert
Suricata intrusion detection flagged this IP for malicious network behaviour — including port scanning, exploit attempts, botnet activity, or known attack signatures. The specific signature is shown in the report list below.
Reports (2)
| Date | Severity | Description |
|---|---|---|
| 11 Sep 2026 - 18:58 | high | IDS: Suricata alert |
| 7 Sep 2026 - 13:40 | low | Query Guard — Path Plugin Theme Readme Probe |
EagleEye Intelligence