64.89.160.157
Case file
First seen on 2026-09-27T20:48:29Z, most recently active on 2026-10-04T19:56:01Z.
Recorded 13 attack-shaped requests across 4 separate days.
Its traffic probed a list of common site paths looking for an unprotected admin panel or staging copy; it also requested xmlrpc.php, which exposes a multicall method commonly abused to spray WordPress credentials and relay pingback floods; it also probed a WordPress admin/content path used to fingerprint the installation or hunt for an exposed upload/plugin surface.
Seen on our edge, web sensors.
Scored into the "Brute" level, carrying the badges Regular, Toolkit.
Routed via AS36680 (Netiface LLC), an ASN we classify as residential.
Publicly listed on this board, but not currently blocked on any of our hosts.
Enrichment
| rDNS | none |
|---|---|
| ASN | AS36680 — Netiface LLC |
| Routing ASN (differs) | AS403005 |
| ASN type | residential |
| Country | United States (US) |
| Flags | none observed |
Timeline
- 2026-09-271
- 2026-09-281
- 2026-10-032
- 2026-10-049
Evidence (newest first, up to 50)
| Time (UTC) | Vantage | Site | Class | Status | Evidence |
|---|---|---|---|---|---|
| 2026-10-04T19:56:01Z | web | techauthors.eu | requested xmlrpc.php, which exposes a multicall method commonly abused to spray WordPress credentials and relay pingback floods | 404 | GET /xmlrpc.php -> 404 |
| 2026-10-04T19:41:19Z – 2026-10-04T19:41:21Z | web | techauthors.eu | 6 × probed a list of common site paths looking for an unprotected admin panel or staging copy | 404 | GET /dev -> 404 (6 distinct paths) |
| 2026-10-04T19:41:18Z | web | techauthors.eu | probed a WordPress admin/content path used to fingerprint the installation or hunt for an exposed upload/plugin surface | 404 | GET /wp-admin/install.php -> 404 |
| 2026-10-04T19:41:18Z | web | techauthors.eu | made a request that matched no known pattern | 404 | GET /wp-admin/setup-config.php -> 404 |
| 2026-10-04T19:41:18Z | web | techauthors.eu | probed a list of common site paths looking for an unprotected admin panel or staging copy | 404 | GET /wordpress -> 404 |
| 2026-10-03T21:46:35Z | web | victorantonov.com | 2 × made a request that matched no known pattern | 404 | GET /wp-content/plugins/apikey/apikey.php.suspected? -> 404 (2 distinct paths) |
| 2026-10-03T21:46:35Z | web | victorantonov.com | fuzzed a short, random filename looking for a forgotten script that responds | 404 | GET /uotacthg.php? -> 404 |
| 2026-10-03T21:46:35Z | web | victorantonov.com | made a request that matched no known pattern | 404 | GET /wp-content/plugins/fix/up.php -> 404 |
| 2026-10-03T21:46:35Z | web | victorantonov.com | checked for a backdoor file planted under a WordPress theme directory | 404 | GET /wp-content/themes/seotheme/db.php? -> 404 |
| 2026-09-28T03:22:05Z | edge | victorantonov.com | requested xmlrpc.php, which exposes a multicall method commonly abused to spray WordPress credentials and relay pingback floods | GET /xmlrpc.php | |
| 2026-09-27T20:48:30Z | edge | victorantonov.com | probed a WordPress admin/content path used to fingerprint the installation or hunt for an exposed upload/plugin surface | GET /wp-admin/install.php | |
| 2026-09-27T20:48:29Z | edge | victorantonov.com | made a request that matched no known pattern | GET /wp-admin/setup-config.php |
Not currently correlated with any campaign.
Dispute or removal: [email protected] — reference 64.89.160.157. See /threats/about for the method and the 7-day review window.
card.svg (used as this page's og:image)