Report for IP: 93.152.221.173

Threat LevelHIGH54/1004 rule types across 4 attack categories
4 incidents on record · 4 rule types · confirmed on global blocklists · persistent 17-day campaign · last seen 13d ago
PTR N/A
Org / ASN TechTies Inc
Country 🇩🇪 Germany
City Frankfurt am Main, Hesse
Timezone Europe/Berlin

Attack Analysis

Listed on 2 threat-intelligence blocklists
  • Spamhaus DROP — Spamhaus DROP lists netblocks hijacked or leased by professional spam and cybercrime operations. Very low false-positive rate: no legitimate traffic is expected from these ranges.
  • FireHOL level1 — FireHOL level1 merges DShield, Spamhaus DROP, bogon ranges and Feodo botnet servers into one curated list built for very low false positives. When DShield or Spamhaus DROP also match, this one adds no independent evidence, since it already contains them.
Curated, low-false-positive lists match, so this is a high-confidence bad address.
WordPress XML-RPC Abuse
This IP targeted xmlrpc.php, a legacy WordPress endpoint that has been abused for brute-force authentication attacks, credential stuffing, and DDoS amplification. Any direct access to xmlrpc.php is an attack or reconnaissance attempt; modern WordPress sites should disable it entirely.
Git Repository Exposure Probe
This IP requested the /.git/ directory, attempting to download source code, commit history, database credentials, and API keys from an accidentally exposed Git repository. Automated tools can reconstruct an entire codebase from an exposed .git folder. No legitimate client ever requests this path.
IDS: Blocklist — Spamhaus DROP
This IP is on the Spamhaus DROP list — a dataset of netblocks hijacked or leased by professional spam and cybercrime operations with no legitimate users. Traffic from DROP-listed ranges is considered hostile by design. Blocking is unconditional.

Reports (4)

Date Severity Description
16 Sep 2026 - 10:57 high WordPress: xmlrpc.php accessed
11 Sep 2026 - 18:06 high IDS: Blocklist — Spamhaus DROP listed IP
11 Sep 2026 - 18:06 low Spamhaus DROP (hijacked/spammer netblocks), FireHOL level1 (DShield+Spamhaus DROP+bogons+Feodo, merged, low-FP)
30 Aug 2026 - 07:10 high Web: Git repo exposure probe