41.105.48.43
Case file
First seen on 2026-10-04T18:22:06Z, most recently active on 2026-10-04T18:22:06Z.
Recorded 1 attack-shaped request across 1 separate day.
Its traffic requested xmlrpc.php, which exposes a multicall method commonly abused to spray WordPress credentials and relay pingback floods.
Seen from 1 of our sensors: nl4-web.
Scored into the "Script Kiddie" level, carrying the badge Tourist.
Routed via AS36947 (Telecom Algeria), an ASN we classify as residential.
Recorded internally; has not yet crossed the bar for a public listing.
Enrichment
| rDNS | none |
|---|---|
| ASN | AS36947 — Telecom Algeria |
| ASN type | residential |
| Country | Algeria (DZ) |
| Flags | none observed |
Timeline
- 2026-10-041
Evidence (newest first, up to 50)
| Time (UTC) | Vantage | Site | Class | Status | Evidence |
|---|---|---|---|---|---|
| 2026-10-04T18:22:06Z | nl4-web | stefanpetkov.day | requested xmlrpc.php, which exposes a multicall method commonly abused to spray WordPress credentials and relay pingback floods | 404 | 41.105.48.43 - - [04/Oct/2026:21:22:06 +0300] "POST /xmlrpc.php HTTP/1.1" 404 16 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7; x64) AppleWebKit/537.36 (KHTML, like Gecko) Opera/74.0.0.0 Safari/537.36" |
Report history
No abuse report sent for this address yet.
Not currently correlated with any campaign.
Dispute or removal: [email protected] — reference 41.105.48.43 (mailbox goes live with phase 3). See /threats/about for the method and the 7-day review window.
card.svg (used as this page's og:image)