Threat LevelCRITICAL72/1002 rule types
4 incidents on record · 2 rule types · active attack detected · persistent 16-day campaign · last seen 9d ago
| PTR | N/A |
| Org / ASN | Oracle Cloud Infrastructure (us-chicago-1) |
| Country | 🇺🇸 United States |
| City | Chicago, Illinois |
| Timezone | America/Chicago |
Attack Analysis
Suricata IDS Alert
Suricata intrusion detection flagged this IP for malicious network behaviour — including port scanning, exploit attempts, botnet activity, or known attack signatures. The specific signature is shown in the report list below.
Plugin/Theme Version Fingerprinting Probe
This IP requested an installed plugin or theme's readme.txt/changelog.txt directly over HTTP — the file's "Stable tag:" line names the exact installed version, which an attacker cross-references against known CVEs for that version before firing the real exploit. WordPress.org's own tooling reads this file server-side, never over HTTP.
Reports (4)
| Date | Severity | Description |
|---|---|---|
| 20 Sep 2026 - 22:02 | high | IDS: Suricata alert |
| 13 Sep 2026 - 10:59 | low | Query Guard — Path Plugin Theme Readme Probe |
| 4 Sep 2026 - 14:41 | medium | IDS: Suricata alert — ET INFO Go-http-client User-Agent Observed Inbound |
| 4 Sep 2026 - 14:41 | high | IDS: Suricata alert |
EagleEye Intelligence