Threat LevelHIGH63/1004 rule types across 3 attack categories
3 incidents on record · 4 rule types · active attacker + blocklisted · active over 5 days · last seen 10d ago
| PTR | N/A |
| Org / ASN | Oracle Corporation |
| Country | 🇮🇹 Italy |
| City | Rivoli, Piedmont |
| Timezone | Europe/Rome |
Attack Analysis
WordPress Username Enumeration
This IP probed the WordPress ?author= parameter to enumerate valid usernames (e.g. ?author=1, ?author=2). Harvested usernames are then fed into credential stuffing or password brute-force attacks. This is purely reconnaissance — there is no legitimate reason to systematically probe author IDs.
Listed on 2 threat-intelligence blocklists
- FireHOL level2 — FireHOL level2 lists addresses seen attacking in the last 48 hours across many sensors. It is large and volatile: addresses enter and leave quickly, so on its own this is weaker, recent-activity evidence.
- This site (WordPress attackers, 90 days) — This site's own data: an IP that attacked WordPress sites and was reported here within the last 90 days. Independent of the third-party lists above.
Webshell Upload Scan
This IP rapidly probed multiple non-existent PHP paths in under 60 seconds — a hallmark of automated webshell scanning tools hunting for previously uploaded backdoors or vulnerable file-upload endpoints. If successful, a webshell grants the attacker full remote code execution on the server.
Reports (3)
| Date | Severity | Description |
|---|---|---|
| 20 Sep 2026 - 01:20 | high | Web: Webshell scan — 3+ unknown PHP probes in 60s |
| 20 Sep 2026 - 01:20 | low | FireHOL level2 (48h recent-attacker feed, large & volatile), unwantedip.eagleeye-intelligence.com (WordPress-targeting IPs, 90d) |
| 14 Sep 2026 - 14:14 | high | WordPress: User enumeration — 3+ author probes in 60s |
EagleEye Intelligence