Report for IP: 65.181.113.41

Threat LevelMEDIUM34/1002 rule types
2 incidents on record · 2 rule types · persistent 31-day campaign · last seen 26d ago
PTR s12079.fra1.stableserver.net
Org / ASN WHG Hosting Services Ltd
Country 🇩🇪 Germany
City Frankfurt am Main, Hesse
Timezone Europe/Berlin

Attack Analysis

WordPress: Author Enumeration
This IP probed the WordPress ?author= parameter to enumerate valid usernames, feeding a list of real accounts into subsequent credential-stuffing attacks. Pure reconnaissance with no legitimate use case.
WordPress XML-RPC Abuse
This IP targeted xmlrpc.php, a legacy WordPress endpoint that has been abused for brute-force authentication attacks, credential stuffing, and DDoS amplification. Any direct access to xmlrpc.php is an attack or reconnaissance attempt; modern WordPress sites should disable it entirely.

Reports (2)

Date Severity Description
3 Sep 2026 - 16:10 low User Enum — Author Scan
3 Aug 2026 - 06:04 high WordPress: xmlrpc.php accessed