203.159.90.72
In feed-residential.txt
Blocked on our servers, including web requests through Cloudflare, since UTC, through UTC, and in feed-residential.txt.
Record
- Score
- 42/100each request counts half as much after 30 days
- Attack-shaped requests
- 240all time
- Active days
- 8UTC days
- First seen
- Last seen
- Servers hit
- 2
- Targets
- 5sites
- Times blocked
- 1by the evidence rules
Its traffic requested a WordPress core file used to fingerprint the installed version and active plugins; it also requested xmlrpc.php, which exposes a multicall method commonly abused to spray WordPress credentials and relay pingback floods; it also probed a list of common site paths looking for an unprotected admin panel or staging copy.
Surfaces: web-app. Attack types: password spraying, scanning. Seen by: edge, web.
Activity, last 90 days
Active on 8 of the last 90 UTC days. Current block: to .
Daily counts
| Day (UTC) | Requests |
|---|---|
| 36 | |
| 18 | |
| 36 | |
| 60 | |
| 3 | |
| 18 | |
| 23 | |
| 46 |
- At least 23 requests a minute at its peak ( UTC; identical requests in the same second are stored once).
- Methods: GET 228, POST 3.
- The servers we watch answered: 404 221, 403 21, 200 1 (totals only, from our web servers).
Evidence
Newest first, the latest 50 stored requests grouped into runs. Times are UTC. The user agent is shown as its family only.
| Time | Site | What happened | Request | User agent | Seen by |
|---|---|---|---|---|---|
| urbanmoto.eu | 4× probed a list of common site paths looking for an unprotected admin panel or staging copy (4 distinct paths) | /test | none | web | |
| urbanmoto.eu | requested xmlrpc.php, which exposes a multicall method commonly abused to spray WordPress credentials and relay pingback floods | /xmlrpc.php | none | web | |
| urbanmoto.eu | made a request that matched no known pattern | /wp-includes | none | web | |
| urbanmoto.eu | 16× requested a WordPress core file used to fingerprint the installed version and active plugins (16 distinct paths) | GET //sito/wp-includes/wlwmanifest.xml | browser claim | web | |
| urbanmoto.eu | requested xmlrpc.php, which exposes a multicall method commonly abused to spray WordPress credentials and relay pingback floods | GET //xmlrpc.php? | browser claim | web | |
| urbanmoto.eu | requested a WordPress core file used to fingerprint the installed version and active plugins | GET //wp-includes/wlwmanifest.xml | browser claim | web | |
| urbanmoto.eu | 4× probed a list of common site paths looking for an unprotected admin panel or staging copy (4 distinct paths) | /test | none | web | |
| urbanmoto.eu | requested xmlrpc.php, which exposes a multicall method commonly abused to spray WordPress credentials and relay pingback floods | /xmlrpc.php | none | web | |
| urbanmoto.eu | made a request that matched no known pattern | /wp-includes | none | web | |
| urbanmoto.eu | 16× requested a WordPress core file used to fingerprint the installed version and active plugins (16 distinct paths) | GET //sito/wp-includes/wlwmanifest.xml | browser claim | web | |
| urbanmoto.eu | requested xmlrpc.php, which exposes a multicall method commonly abused to spray WordPress credentials and relay pingback floods | GET //xmlrpc.php? | browser claim | web | |
| urbanmoto.eu | requested a WordPress core file used to fingerprint the installed version and active plugins | GET //wp-includes/wlwmanifest.xml | browser claim | web | |
| urbanmoto.eu | 2× probed a list of common site paths looking for an unprotected admin panel or staging copy (2 distinct paths) | /test | none | web | |
Network
- ASN
- AS210558 1337 Services GmbH
- Network type
- home broadband
- Reverse DNS
- none
- Country
- The Netherlands NL
- Flags
- none observed
- Abuse contact
- found in the registry
- Checked
Campaign
Sends the same user agent (family: browser claim) and asks for the same paths as 14 other addresses, seen together from to . Paths: //wp-includes/wlwmanifest.xml //xmlrpc.php? //blog/wp-includes/wlwmanifest.xml //web/wp-includes/wlwmanifest.xml //wordpress/wp-includes/wlwmanifest.xml.