Report for IP: 176.65.132.251

Threat LevelHIGH70/1007 rule types across 3 attack categories
8 incidents on record · 7 rule types · active attacker + blocklisted · persistent 8-day campaign · last seen 2d ago
PTR N/A
Org / ASN TechTies Inc
Country 🇳🇱 The Netherlands
City Amsterdam, North Holland
Timezone Europe/Amsterdam

Attack Analysis

IDS: Blocklist — Spamhaus DROP
This IP is on the Spamhaus DROP list — a dataset of netblocks hijacked or leased by professional spam and cybercrime operations with no legitimate users. Traffic from DROP-listed ranges is considered hostile by design. Blocking is unconditional.
WordPress: Brute Force Attack
This IP was blocked attempting to log into a WordPress site's wp-login.php — either from a disallowed country or after exceeding the allowed number of failed login attempts. Automated credential-stuffing and brute-force tools account for the overwhelming majority of this traffic; legitimate users rarely trigger a hard IP block on login alone.
Plugin/Theme Version Fingerprinting Probe
This IP requested an installed plugin or theme's readme.txt/changelog.txt directly over HTTP — the file's "Stable tag:" line names the exact installed version, which an attacker cross-references against known CVEs for that version before firing the real exploit. WordPress.org's own tooling reads this file server-side, never over HTTP.
local blocklist
Listed on 4 threat-intelligence blocklists
  • Spamhaus DROP — Spamhaus DROP lists netblocks hijacked or leased by professional spam and cybercrime operations. Very low false-positive rate: no legitimate traffic is expected from these ranges.
  • FireHOL level1 — FireHOL level1 merges DShield, Spamhaus DROP, bogon ranges and Feodo botnet servers into one curated list built for very low false positives. When DShield or Spamhaus DROP also match, this one adds no independent evidence, since it already contains them.
  • FireHOL level2 — FireHOL level2 lists addresses seen attacking in the last 48 hours across many sensors. It is large and volatile: addresses enter and leave quickly, so on its own this is weaker, recent-activity evidence.
  • This site (WordPress attackers, 90 days) — This site's own data: an IP that attacked WordPress sites and was reported here within the last 90 days. Independent of the third-party lists above.
Curated, low-false-positive lists match, so this is a high-confidence bad address.

Reports (8)

Date Severity Description
27 Sep 2026 - 19:35 low local blocklist
27 Sep 2026 - 19:35 low Spamhaus DROP (hijacked/spammer netblocks), FireHOL level1 (DShield+Spamhaus DROP+bogons+Feodo, merged, low-FP), FireHOL level2 (48h recent-attacker feed, large & volatile), unwantedip.eagleeye-intelligence.com (WordPress-targeting IPs, 90d)
27 Sep 2026 - 19:35 low Query Guard — Path Plugin Theme Readme Probe
27 Sep 2026 - 19:34 low Query Guard — Path Plugin Theme Readme Probe
23 Sep 2026 - 16:16 high IDS: Blocklist — Spamhaus DROP listed IP
22 Sep 2026 - 20:34 medium WordPress Login Brute Force Attempt
20 Sep 2026 - 12:46 high IDS: Blocklist — Spamhaus DROP listed IP — ET DROP Spamhaus DROP Listed Traffic Inbound group 35
19 Sep 2026 - 13:41 high IDS: Blocklist — Spamhaus DROP listed IP — ET DROP Spamhaus DROP Listed Traffic Inbound group 35