41.105.48.43

recordedScript KiddieTourist

Case file

First seen on 2026-10-04T18:22:06Z, most recently active on 2026-10-04T18:22:06Z.

Recorded 1 attack-shaped request across 1 separate day.

Its traffic requested xmlrpc.php, which exposes a multicall method commonly abused to spray WordPress credentials and relay pingback floods.

Seen from 1 of our sensors: nl4-web.

Scored into the "Script Kiddie" level, carrying the badge Tourist.

Routed via AS36947 (Telecom Algeria), an ASN we classify as residential.

Recorded internally; has not yet crossed the bar for a public listing.

Enrichment

rDNSnone
ASNAS36947 — Telecom Algeria
ASN typeresidential
CountryAlgeria (DZ)
Flagsnone observed

External references: GreyNoise, Shodan, AbuseIPDB

Timeline

Evidence (newest first, up to 50)

Time (UTC)VantageSiteClassStatusEvidence
2026-10-04T18:22:06Znl4-webstefanpetkov.dayrequested xmlrpc.php, which exposes a multicall method commonly abused to spray WordPress credentials and relay pingback floods40441.105.48.43 - - [04/Oct/2026:21:22:06 +0300] "POST /xmlrpc.php HTTP/1.1" 404 16 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7; x64) AppleWebKit/537.36 (KHTML, like Gecko) Opera/74.0.0.0 Safari/537.36"

Report history

No abuse report sent for this address yet.

Not currently correlated with any campaign.

Dispute or removal: [email protected] — reference 41.105.48.43 (mailbox goes live with phase 3). See /threats/about for the method and the 7-day review window.

card.svg (used as this page's og:image)