Threat LevelHIGH62/1003 rule types across 3 attack categories
7 incidents on record · 3 rule types · active attack detected · persistent 9-day campaign · last seen 24d ago
| PTR | N/A |
| Org / ASN | Microsoft Azure Cloud (westus3) |
| Country | 🇺🇸 United States |
| City | Phoenix, Arizona |
| Timezone | America/Phoenix |
Attack Analysis
Webshell Upload Scan
This IP rapidly probed multiple non-existent PHP paths in under 60 seconds — a hallmark of automated webshell scanning tools hunting for previously uploaded backdoors or vulnerable file-upload endpoints. If successful, a webshell grants the attacker full remote code execution on the server.
Drupal: Maintenance Script Accessed
This IP requested a Drupal maintenance or install script (install.php, update.php, cron.php). These scripts can expose sensitive configuration data or allow unauthorized site modifications if not properly protected.
WordPress XML-RPC Abuse
This IP targeted xmlrpc.php, a legacy WordPress endpoint that has been abused for brute-force authentication attacks, credential stuffing, and DDoS amplification. Any direct access to xmlrpc.php is an attack or reconnaissance attempt; modern WordPress sites should disable it entirely.
Reports (7)
| Date | Severity | Description |
|---|---|---|
| 7 Jul 2026 - 21:02 | high | Web: xmlrpc.php accessed |
| 7 Jul 2026 - 21:01 | high | Web: xmlrpc.php accessed |
| 7 Jul 2026 - 21:00 | medium | Drupal: Maintenance script accessed |
| 7 Jul 2026 - 20:59 | medium | Drupal: Maintenance script accessed |
| 7 Jul 2026 - 20:59 | high | Web: Webshell scan — 3+ unknown PHP probes in 60s |
| 29 Jun 2026 - 05:45 | medium | Drupal: Maintenance script accessed |
| 29 Jun 2026 - 05:45 | high | Web: Webshell scan — 3+ unknown PHP probes in 60s |
EagleEye Intelligence