Report for IP: 20.125.96.254

Threat LevelHIGH62/1003 rule types across 3 attack categories
7 incidents on record · 3 rule types · active attack detected · persistent 9-day campaign · last seen 24d ago
PTR N/A
Org / ASN Microsoft Azure Cloud (westus3)
Country 🇺🇸 United States
City Phoenix, Arizona
Timezone America/Phoenix

Attack Analysis

🇺🇸 United States · Phoenix · 8075 · Microsoft Corporation
Webshell Upload Scan
This IP rapidly probed multiple non-existent PHP paths in under 60 seconds — a hallmark of automated webshell scanning tools hunting for previously uploaded backdoors or vulnerable file-upload endpoints. If successful, a webshell grants the attacker full remote code execution on the server.
Drupal: Maintenance Script Accessed
This IP requested a Drupal maintenance or install script (install.php, update.php, cron.php). These scripts can expose sensitive configuration data or allow unauthorized site modifications if not properly protected.
WordPress XML-RPC Abuse
This IP targeted xmlrpc.php, a legacy WordPress endpoint that has been abused for brute-force authentication attacks, credential stuffing, and DDoS amplification. Any direct access to xmlrpc.php is an attack or reconnaissance attempt; modern WordPress sites should disable it entirely.

Reports (7)

Date Severity Description
7 Jul 2026 - 21:02 high Web: xmlrpc.php accessed
7 Jul 2026 - 21:01 high Web: xmlrpc.php accessed
7 Jul 2026 - 21:00 medium Drupal: Maintenance script accessed
7 Jul 2026 - 20:59 medium Drupal: Maintenance script accessed
7 Jul 2026 - 20:59 high Web: Webshell scan — 3+ unknown PHP probes in 60s
29 Jun 2026 - 05:45 medium Drupal: Maintenance script accessed
29 Jun 2026 - 05:45 high Web: Webshell scan — 3+ unknown PHP probes in 60s