Threat LevelMEDIUM45/1003 rule types across 3 attack categories
3 incidents on record · 3 rule types · confirmed on global blocklist · persistent 12-day campaign · last seen 16d ago
| PTR | N/A |
| Org / ASN | DigitalOcean, LLC |
| Country | 🇬🇧 United Kingdom |
| City | Slough, England |
| Timezone | Europe/London |
Attack Analysis
Backup & Database File Probe
This IP requested common backup file paths (.bak, .sql, .zip, wp-config.bak), hunting for database dumps or config files containing plaintext credentials. A single exposed wp-config.bak can hand an attacker full database access. This attack is automated and deliberate.
Geo-Blocked Country
This IP was blocked purely based on its country of origin — the site owner has restricted access from this IP's geographic location due to a pattern of unwanted traffic from that region. This does not necessarily mean the specific IP itself has attacked anything; it reflects a blanket country-level policy.
Listed on 1 threat-intelligence blocklist
- FireHOL level2 — FireHOL level2 lists addresses seen attacking in the last 48 hours across many sensors. It is large and volatile: addresses enter and leave quickly, so on its own this is weaker, recent-activity evidence.
Reports (3)
| Date | Severity | Description |
|---|---|---|
| 14 Sep 2026 - 03:34 | low | FireHOL level2 (48h recent-attacker feed, large & volatile) |
| 13 Sep 2026 - 11:35 | low | Geo Blocker — Country Match |
| 2 Sep 2026 - 02:10 | high | Web: Backup/database file probe |
EagleEye Intelligence