Threat LevelMEDIUM42/1004 rule types across 3 attack categories
4 incidents on record · 4 rule types · confirmed on global blocklist · active over 2 days · last seen 25d ago
| PTR | cloud-5cd989.managed-vps.net |
| Org / ASN | NS1 Ltd. |
| Country | 🇧🇬 Bulgaria |
| City | Sofia, Sofia-Capital |
| Timezone | Europe/Sofia |
Attack Analysis
WordPress XML-RPC Abuse
This IP accessed xmlrpc.php on a site where the owner has explicitly disabled it. xmlrpc.php is a legacy WordPress endpoint long abused for brute-force login attempts (via its multicall method) and DDoS pingback amplification; sites that don't need it disable it outright, making any access attempt inherently unwanted.
Listed on 1 threat-intelligence blocklist
- This site (WordPress attackers, 90 days) — This site's own data: an IP that attacked WordPress sites and was reported here within the last 90 days. Independent of the third-party lists above.
Geo-Blocked Country
This IP was blocked purely based on its country of origin — the site owner has restricted access from this IP's geographic location due to a pattern of unwanted traffic from that region. This does not necessarily mean the specific IP itself has attacked anything; it reflects a blanket country-level policy.
Reports (4)
| Date | Severity | Description |
|---|---|---|
| 4 Sep 2026 - 21:02 | low | Geo Blocker — Country Match |
| 4 Sep 2026 - 16:14 | low | unwantedip.eagleeye-intelligence.com (WordPress-targeting IPs, 90d) |
| 2 Sep 2026 - 12:07 | high | WordPress: xmlrpc.php accessed |
| 2 Sep 2026 - 12:07 | medium | Query Guard — Xmlrpc Access |
EagleEye Intelligence