62.60.130.227
Case file
First seen on 2026-09-12T20:04:12Z, most recently active on 2026-10-02T05:01:48Z.
Recorded 14 attack-shaped requests across 7 separate days.
Its traffic matched a catalogue rule; it also requested xmlrpc.php, which exposes a multicall method commonly abused to spray WordPress credentials and relay pingback floods; it also probed a WordPress admin/content path used to fingerprint the installation or hunt for an exposed upload/plugin surface.
Seen on our edge, web sensors.
Scored into the "Brute" level, carrying the badges Regular, Toolkit.
Routed via AS215930 (Cipher Operations Doo Beograd - Novi Beograd), an ASN we classify as residential.
Blocked on every one of our hosts and at our edge since 2026-10-04T15:29:58Z, through 2026-11-03T15:29:58Z.
Enrichment
| rDNS | none |
|---|---|
| ASN | AS215930 — Cipher Operations Doo Beograd - Novi Beograd |
| ASN type | residential |
| Country | Iran (IR) |
| Flags | none observed |
Timeline
- 2026-09-121
- 2026-09-151
- 2026-09-161
- 2026-09-191
- 2026-09-201
- 2026-10-016
- 2026-10-023
Evidence (newest first, up to 50)
| Time (UTC) | Vantage | Site | Class | Status | Evidence |
|---|---|---|---|---|---|
| 2026-09-20T10:32:44Z | edge | victorantonov.com | matched a catalogue rule | {"ts":"2026-09-20T10:32:44Z","ip":"62.60.130.227","zone":"victorantonov.com","host":"victorantonov.com","path":"/","method":"POST","query":"<truncated>","ua":"Mozilla/5.0","action":"block","source":"firewallManaged","rule_id":"<redacted>","country":"LT","asn_org":"CIPHER OPERATIONS DOO BEOGRAD - NOV… | |
| 2026-09-19T21:27:21Z | edge | victorantonov.com | matched a catalogue rule | {"ts":"2026-09-19T21:27:21Z","ip":"62.60.130.227","zone":"victorantonov.com","host":"victorantonov.com","path":"/","method":"POST","query":"<truncated>","ua":"Mozilla/5.0","action":"block","source":"firewallManaged","rule_id":"<redacted>","country":"LT","asn_org":"CIPHER OPERATIONS DOO BEOGRAD - NOV… | |
| 2026-09-16T12:46:27Z | edge | victorantonov.com | matched a catalogue rule | {"ts":"2026-09-16T12:46:27Z","ip":"62.60.130.227","zone":"victorantonov.com","host":"victorantonov.com","path":"/","method":"POST","query":"<truncated>","ua":"Mozilla/5.0","action":"block","source":"firewallManaged","rule_id":"<redacted>","country":"LT","asn_org":"CIPHER OPERATIONS DOO BEOGRAD - NOV… | |
| 2026-09-15T12:29:30Z | edge | victorantonov.com | matched a catalogue rule | {"ts":"2026-09-15T12:29:30Z","ip":"62.60.130.227","zone":"victorantonov.com","host":"victorantonov.com","path":"/","method":"POST","query":"<truncated>","ua":"Mozilla/5.0","action":"block","source":"firewallManaged","rule_id":"<redacted>","country":"LT","asn_org":"CIPHER OPERATIONS DOO BEOGRAD - NOV… | |
| 2026-09-12T20:04:12Z | edge | victorantonov.com | matched a catalogue rule | {"ts":"2026-09-12T20:04:12Z","ip":"62.60.130.227","zone":"victorantonov.com","host":"victorantonov.com","path":"/","method":"POST","query":"<truncated>","ua":"Mozilla/5.0","action":"block","source":"firewallManaged","rule_id":"<redacted>","country":"LT","asn_org":"CIPHER OPERATIONS DOO BEOGRAD - NOV… | |
| 2026-10-01T19:48:19Z | web | servbg.com | requested xmlrpc.php, which exposes a multicall method commonly abused to spray WordPress credentials and relay pingback floods | 404 | 62.60.130.227 - - [01/Oct/2026:22:48:19 +0300] "GET /xmlrpc.php HTTP/1.1" 404 16 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" |
| 2026-10-01T19:48:19Z | web | servbg.com | probed a WordPress admin/content path used to fingerprint the installation or hunt for an exposed upload/plugin surface | 404 | 62.60.130.227 - - [01/Oct/2026:22:48:19 +0300] "GET /wp-json/ HTTP/1.1" 404 236 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" |
| 2026-10-01T19:48:18Z | web | servbg.com | requested wp-login.php to check whether this site runs WordPress | 404 | 62.60.130.227 - - [01/Oct/2026:22:48:18 +0300] "GET /wp-login.php HTTP/1.1" 404 16 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" |
| 2026-10-02T05:01:48Z | web | motoristi.eu | requested xmlrpc.php, which exposes a multicall method commonly abused to spray WordPress credentials and relay pingback floods | 404 | 62.60.130.227 - - [02/Oct/2026:08:01:48 +0300] "GET /xmlrpc.php HTTP/1.1" 404 16 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" |
| 2026-10-02T05:01:48Z | web | motoristi.eu | probed a WordPress admin/content path used to fingerprint the installation or hunt for an exposed upload/plugin surface | 404 | 62.60.130.227 - - [02/Oct/2026:08:01:48 +0300] "GET /wp-json/ HTTP/1.1" 404 236 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" |
| 2026-10-02T05:01:47Z | web | motoristi.eu | requested wp-login.php to check whether this site runs WordPress | 404 | 62.60.130.227 - - [02/Oct/2026:08:01:47 +0300] "GET /wp-login.php HTTP/1.1" 404 16 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" |
| 2026-10-01T22:07:07Z | web | bgpoet.com | requested xmlrpc.php, which exposes a multicall method commonly abused to spray WordPress credentials and relay pingback floods | 404 | 62.60.130.227 - - [02/Oct/2026:01:07:07 +0300] "GET /xmlrpc.php HTTP/1.1" 404 16 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" |
| 2026-10-01T22:07:07Z | web | bgpoet.com | probed a WordPress admin/content path used to fingerprint the installation or hunt for an exposed upload/plugin surface | 404 | 62.60.130.227 - - [02/Oct/2026:01:07:07 +0300] "GET /wp-json/ HTTP/1.1" 404 236 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" |
| 2026-10-01T22:07:07Z | web | bgpoet.com | requested wp-login.php to check whether this site runs WordPress | 404 | 62.60.130.227 - - [02/Oct/2026:01:07:07 +0300] "GET /wp-login.php HTTP/1.1" 404 16 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" |
Not currently correlated with any campaign.
Dispute or removal: [email protected] — reference 62.60.130.227. See /threats/about for the method and the 7-day review window.
card.svg (used as this page's og:image)