62.60.130.227

blockedBruteRegularToolkit

Case file

First seen on 2026-09-12T20:04:12Z, most recently active on 2026-10-02T05:01:48Z.

Recorded 14 attack-shaped requests across 7 separate days.

Its traffic matched a catalogue rule; it also requested xmlrpc.php, which exposes a multicall method commonly abused to spray WordPress credentials and relay pingback floods; it also probed a WordPress admin/content path used to fingerprint the installation or hunt for an exposed upload/plugin surface.

Seen on our edge, web sensors.

Scored into the "Brute" level, carrying the badges Regular, Toolkit.

Routed via AS215930 (Cipher Operations Doo Beograd - Novi Beograd), an ASN we classify as residential.

Blocked on every one of our hosts and at our edge since 2026-10-04T15:29:58Z, through 2026-11-03T15:29:58Z.

Enrichment

rDNSnone
ASNAS215930 — Cipher Operations Doo Beograd - Novi Beograd
ASN typeresidential
CountryIran (IR)
Flagsnone observed

External references: GreyNoise, Shodan, AbuseIPDB

Timeline

Evidence (newest first, up to 50)

Time (UTC)VantageSiteClassStatusEvidence
2026-09-20T10:32:44Zedgevictorantonov.commatched a catalogue rule{"ts":"2026-09-20T10:32:44Z","ip":"62.60.130.227","zone":"victorantonov.com","host":"victorantonov.com","path":"/","method":"POST","query":"<truncated>","ua":"Mozilla/5.0","action":"block","source":"firewallManaged","rule_id":"<redacted>","country":"LT","asn_org":"CIPHER OPERATIONS DOO BEOGRAD - NOV…
2026-09-19T21:27:21Zedgevictorantonov.commatched a catalogue rule{"ts":"2026-09-19T21:27:21Z","ip":"62.60.130.227","zone":"victorantonov.com","host":"victorantonov.com","path":"/","method":"POST","query":"<truncated>","ua":"Mozilla/5.0","action":"block","source":"firewallManaged","rule_id":"<redacted>","country":"LT","asn_org":"CIPHER OPERATIONS DOO BEOGRAD - NOV…
2026-09-16T12:46:27Zedgevictorantonov.commatched a catalogue rule{"ts":"2026-09-16T12:46:27Z","ip":"62.60.130.227","zone":"victorantonov.com","host":"victorantonov.com","path":"/","method":"POST","query":"<truncated>","ua":"Mozilla/5.0","action":"block","source":"firewallManaged","rule_id":"<redacted>","country":"LT","asn_org":"CIPHER OPERATIONS DOO BEOGRAD - NOV…
2026-09-15T12:29:30Zedgevictorantonov.commatched a catalogue rule{"ts":"2026-09-15T12:29:30Z","ip":"62.60.130.227","zone":"victorantonov.com","host":"victorantonov.com","path":"/","method":"POST","query":"<truncated>","ua":"Mozilla/5.0","action":"block","source":"firewallManaged","rule_id":"<redacted>","country":"LT","asn_org":"CIPHER OPERATIONS DOO BEOGRAD - NOV…
2026-09-12T20:04:12Zedgevictorantonov.commatched a catalogue rule{"ts":"2026-09-12T20:04:12Z","ip":"62.60.130.227","zone":"victorantonov.com","host":"victorantonov.com","path":"/","method":"POST","query":"<truncated>","ua":"Mozilla/5.0","action":"block","source":"firewallManaged","rule_id":"<redacted>","country":"LT","asn_org":"CIPHER OPERATIONS DOO BEOGRAD - NOV…
2026-10-01T19:48:19Zwebservbg.comrequested xmlrpc.php, which exposes a multicall method commonly abused to spray WordPress credentials and relay pingback floods40462.60.130.227 - - [01/Oct/2026:22:48:19 +0300] "GET /xmlrpc.php HTTP/1.1" 404 16 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
2026-10-01T19:48:19Zwebservbg.comprobed a WordPress admin/content path used to fingerprint the installation or hunt for an exposed upload/plugin surface40462.60.130.227 - - [01/Oct/2026:22:48:19 +0300] "GET /wp-json/ HTTP/1.1" 404 236 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
2026-10-01T19:48:18Zwebservbg.comrequested wp-login.php to check whether this site runs WordPress40462.60.130.227 - - [01/Oct/2026:22:48:18 +0300] "GET /wp-login.php HTTP/1.1" 404 16 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
2026-10-02T05:01:48Zwebmotoristi.eurequested xmlrpc.php, which exposes a multicall method commonly abused to spray WordPress credentials and relay pingback floods40462.60.130.227 - - [02/Oct/2026:08:01:48 +0300] "GET /xmlrpc.php HTTP/1.1" 404 16 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
2026-10-02T05:01:48Zwebmotoristi.euprobed a WordPress admin/content path used to fingerprint the installation or hunt for an exposed upload/plugin surface40462.60.130.227 - - [02/Oct/2026:08:01:48 +0300] "GET /wp-json/ HTTP/1.1" 404 236 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
2026-10-02T05:01:47Zwebmotoristi.eurequested wp-login.php to check whether this site runs WordPress40462.60.130.227 - - [02/Oct/2026:08:01:47 +0300] "GET /wp-login.php HTTP/1.1" 404 16 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
2026-10-01T22:07:07Zwebbgpoet.comrequested xmlrpc.php, which exposes a multicall method commonly abused to spray WordPress credentials and relay pingback floods40462.60.130.227 - - [02/Oct/2026:01:07:07 +0300] "GET /xmlrpc.php HTTP/1.1" 404 16 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
2026-10-01T22:07:07Zwebbgpoet.comprobed a WordPress admin/content path used to fingerprint the installation or hunt for an exposed upload/plugin surface40462.60.130.227 - - [02/Oct/2026:01:07:07 +0300] "GET /wp-json/ HTTP/1.1" 404 236 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
2026-10-01T22:07:07Zwebbgpoet.comrequested wp-login.php to check whether this site runs WordPress40462.60.130.227 - - [02/Oct/2026:01:07:07 +0300] "GET /wp-login.php HTTP/1.1" 404 16 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"

Not currently correlated with any campaign.

Dispute or removal: [email protected] — reference 62.60.130.227. See /threats/about for the method and the 7-day review window.

card.svg (used as this page's og:image)