Report for IP: 5.175.189.36

Threat LevelMEDIUM35/1001 rule type
1 incident on record · last seen 7d ago
PTR N/A
Org / ASN GHOSTNET GmbH
Country 🇳🇱 The Netherlands
City Amsterdam, North Holland
Timezone Europe/Amsterdam

Attack Analysis

🇳🇱 Netherlands · Amsterdam · 206479 · Ghostnet GmbH
Backup & Database File Probe
This IP requested common backup file paths (.bak, .sql, .zip, wp-config.bak), hunting for database dumps or config files containing plaintext credentials. A single exposed wp-config.bak can hand an attacker full database access. This attack is automated and deliberate.

Reports (1)

Date Severity Description
25 Jul 2026 - 08:28 high Web: Backup/database file probe