178.128.123.119

listedScannerRegular

Case file

First seen on 2026-10-01T08:10:08Z, most recently active on 2026-10-02T12:33:09Z.

Recorded 8 attack-shaped requests across 2 separate days.

Its traffic probed a list of common site paths looking for an unprotected admin panel or staging copy; it also requested xmlrpc.php, which exposes a multicall method commonly abused to spray WordPress credentials and relay pingback floods.

Seen from 2 of our sensors: edge, nl4-web.

Scored into the "Scanner" level, carrying the badge Regular.

Routed via AS14061 (DigitalOcean, LLC), an ASN we classify as hosting.

Publicly listed on this board, but not currently blocked on any of our hosts.

Enrichment

rDNSnone
ASNAS14061 — DigitalOcean, LLC
ASN typehosting
CountrySingapore (SG)
Flagsnone observed

External references: GreyNoise, Shodan, AbuseIPDB

Timeline

Evidence (newest first, up to 50)

Time (UTC)VantageSiteClassStatusEvidence
2026-10-02T12:33:08Zedgevictorantonov.comrequested xmlrpc.php, which exposes a multicall method commonly abused to spray WordPress credentials and relay pingback floods{"ts":"2026-10-02T12:33:08Z","ip":"178.128.123.119","zone":"victorantonov.com","host":"victorantonov.com","path":"//xmlrpc.php","method":"GET","query":"<truncated>","ua":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36","action":"block"…
2026-10-02T12:33:09Z – 2026-10-02T12:33:09Z ×3nl4-webvictorantonov.com3 × probed a list of common site paths looking for an unprotected admin panel or staging copy404178.128.123.119 - - [02/Oct/2026:15:33:09 +0300] "GET //wp/ HTTP/1.1" 404 236 "https://www.viconecta.com.br//wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" (3 distinct paths)
2026-10-01T08:10:09Z – 2026-10-01T08:10:10Z ×3nl4-websvestnik.com3 × probed a list of common site paths looking for an unprotected admin panel or staging copy404178.128.123.119 - - [01/Oct/2026:11:10:10 +0300] "GET //wp/ HTTP/1.1" 404 236 "www.svenlindroos.com/wordpress//wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" (3 distinct paths)
2026-10-01T08:10:08Znl4-websvestnik.comrequested xmlrpc.php, which exposes a multicall method commonly abused to spray WordPress credentials and relay pingback floods404178.128.123.119 - - [01/Oct/2026:11:10:08 +0300] "GET //xmlrpc.php? HTTP/1.1" 404 16 "www.svenlindroos.com/wordpress//wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"

Report history

No abuse report sent for this address yet.

Not currently correlated with any campaign.

Dispute or removal: [email protected] — reference 178.128.123.119 (mailbox goes live with phase 3). See /threats/about for the method and the 7-day review window.

card.svg (used as this page's og:image)