Threat LevelCRITICAL72/1003 rule types across 2 attack categories
5 incidents on record · 3 rule types · active attack detected · persistent 24-day campaign · last seen 4d ago
| PTR | ip87-106-118-51.pbiaas.com |
| Org / ASN | De Ber Ionos Cloud Txl |
| Country | 🇩🇪 Germany |
| City | Berlin, State of Berlin |
| Timezone | Europe/Berlin |
Attack Analysis
WordPress: Brute Force Attack
This IP was blocked attempting to log into a WordPress site's wp-login.php — either from a disallowed country or after exceeding the allowed number of failed login attempts. Automated credential-stuffing and brute-force tools account for the overwhelming majority of this traffic; legitimate users rarely trigger a hard IP block on login alone.
Webshell Upload Scan
This IP rapidly probed multiple non-existent PHP paths in under 60 seconds — a hallmark of automated webshell scanning tools hunting for previously uploaded backdoors or vulnerable file-upload endpoints. If successful, a webshell grants the attacker full remote code execution on the server.
Suricata IDS Alert
Suricata intrusion detection flagged this IP for malicious network behaviour — including port scanning, exploit attempts, botnet activity, or known attack signatures. The specific signature is shown in the report list below.
Reports (5)
| Date | Severity | Description |
|---|---|---|
| 25 Sep 2026 - 16:22 | high | IDS: Suricata alert |
| 25 Sep 2026 - 16:22 | medium | IDS: Suricata alert — ET HUNTING Javascript Prototype Pollution Attempt via __proto__ in HTTP Body |
| 2 Sep 2026 - 17:53 | high | Web: Webshell scan — 3+ unknown PHP probes in 60s |
| 2 Sep 2026 - 17:52 | medium | WordPress Login Brute Force Attempt |
| 2 Sep 2026 - 04:01 | high | IDS: Suricata alert |
EagleEye Intelligence