Threat LevelMEDIUM46/1002 rule types across 2 attack categories
3 incidents on record · 2 rule types · active attack detected · last seen 22d ago
| PTR | N/A |
| Org / ASN | Oracle Corporation |
| Country | 🇸🇬 Singapore |
| City | Singapore, South East |
| Timezone | Asia/Singapore |
Attack Analysis
WordPress Username Enumeration
This IP probed the WordPress ?author= parameter to enumerate valid usernames (e.g. ?author=1, ?author=2). Harvested usernames are then fed into credential stuffing or password brute-force attacks. This is purely reconnaissance — there is no legitimate reason to systematically probe author IDs.
WordPress: High-Speed Login Flood
This IP attempted 5 or more WordPress logins within 30 seconds — an aggressive brute-force attack that sacrifices stealth for speed. This rate of requests is impossible for a human and indicates an automated tool hammering the login endpoint.
Reports (3)
| Date | Severity | Description |
|---|---|---|
| 9 Jul 2026 - 13:35 | high | WordPress: Brute force — 5+ logins in 30s |
| 9 Jul 2026 - 13:12 | high | WordPress: Brute force — 5+ logins in 30s |
| 9 Jul 2026 - 13:11 | high | Web: User enumeration — 3+ author probes in 60s |
EagleEye Intelligence