Threat LevelMEDIUM43/1002 rule types across 2 attack categories
2 incidents on record · 2 rule types · confirmed on global blocklist · active over 2 days · last seen 3d ago
| PTR | N/A |
| Org / ASN | IPv4Center.com Lease |
| Country | 🇮🇪 Ireland |
| City | Dublin, Leinster |
| Timezone | Europe/Dublin |
Attack Analysis
WordPress Username Enumeration
This IP probed the WordPress ?author= parameter to enumerate valid usernames (e.g. ?author=1, ?author=2). Harvested usernames are then fed into credential stuffing or password brute-force attacks. This is purely reconnaissance — there is no legitimate reason to systematically probe author IDs.
Listed on 1 threat-intelligence blocklist
- FireHOL level2 — FireHOL level2 lists addresses seen attacking in the last 48 hours across many sensors. It is large and volatile: addresses enter and leave quickly, so on its own this is weaker, recent-activity evidence.
Reports (2)
| Date | Severity | Description |
|---|---|---|
| 26 Sep 2026 - 13:57 | low | FireHOL level2 (48h recent-attacker feed, large & volatile) |
| 24 Sep 2026 - 20:06 | high | WordPress: User enumeration — 3+ author probes in 60s |
EagleEye Intelligence