Threat LevelHIGH53/1002 rule types across 2 attack categories
5 incidents on record ยท 2 rule types ยท confirmed on global blocklist ยท last seen 8d ago
| PTR | column-market.vmheaven.io |
| Org / ASN | TechTies Inc |
| Country | ๐ณ๐ฑ The Netherlands |
| City | Amsterdam, North Holland |
| Timezone | Europe/Amsterdam |
Attack Analysis
IDS: Blocklist โ Spamhaus DROP
This IP is on the Spamhaus DROP list โ a dataset of netblocks hijacked or leased by professional spam and cybercrime operations with no legitimate users. Traffic from DROP-listed ranges is considered hostile by design. Blocking is unconditional.
Backup & Database File Probe
This IP requested common backup file paths (.bak, .sql, .zip, wp-config.bak), hunting for database dumps or config files containing plaintext credentials. A single exposed wp-config.bak can hand an attacker full database access. This attack is automated and deliberate.
Reports (5)
| Date | Severity | Description |
|---|---|---|
| 22 Sep 2026 - 03:49 | high | IDS: Blocklist โ Spamhaus DROP listed IP โ ET DROP Spamhaus DROP Listed Traffic Inbound group 7 |
| 22 Sep 2026 - 02:02 | high | IDS: Blocklist โ Spamhaus DROP listed IP โ ET DROP Spamhaus DROP Listed Traffic Inbound group 7 |
| 21 Sep 2026 - 09:37 | high | IDS: Blocklist โ Spamhaus DROP listed IP โ ET DROP Spamhaus DROP Listed Traffic Inbound group 7 |
| 20 Sep 2026 - 23:56 | high | Web: Backup/database file probe |
| 20 Sep 2026 - 23:56 | high | IDS: Blocklist โ Spamhaus DROP listed IP โ ET DROP Spamhaus DROP Listed Traffic Inbound group 7 |
EagleEye Intelligence