Threat LevelHIGH62/1003 rule types across 2 attack categories
4 incidents on record · 3 rule types · active attack detected · last seen 19d ago
| PTR | grazilian.info |
| Org / ASN | AS6698 Virtual Systems LLC |
| Country | 🇺🇦 Ukraine |
| City | Kyiv, Kyiv City |
| Timezone | Europe/Kyiv |
Attack Analysis
Geo-Blocked Country
This IP was blocked purely based on its country of origin — the site owner has restricted access from this IP's geographic location due to a pattern of unwanted traffic from that region. This does not necessarily mean the specific IP itself has attacked anything; it reflects a blanket country-level policy.
Plugin/Theme Version Fingerprinting Probe
This IP requested an installed plugin or theme's readme.txt/changelog.txt directly over HTTP — the file's "Stable tag:" line names the exact installed version, which an attacker cross-references against known CVEs for that version before firing the real exploit. WordPress.org's own tooling reads this file server-side, never over HTTP.
Webshell Upload Scan
This IP rapidly probed multiple non-existent PHP paths in under 60 seconds — a hallmark of automated webshell scanning tools hunting for previously uploaded backdoors or vulnerable file-upload endpoints. If successful, a webshell grants the attacker full remote code execution on the server.
Reports (4)
| Date | Severity | Description |
|---|---|---|
| 11 Sep 2026 - 11:16 | high | Web: Webshell scan — 3+ unknown PHP probes in 60s |
| 11 Sep 2026 - 11:15 | low | Geo Blocker — Country Match |
| 11 Sep 2026 - 08:12 | low | Query Guard — Path Plugin Theme Readme Probe |
| 11 Sep 2026 - 06:24 | low | Geo Blocker — Country Match |
EagleEye Intelligence