64.89.160.157

listedBruteRegularToolkit

Case file

First seen on 2026-09-27T20:48:29Z, most recently active on 2026-10-04T19:56:01Z.

Recorded 13 attack-shaped requests across 4 separate days.

Its traffic probed a list of common site paths looking for an unprotected admin panel or staging copy; it also requested xmlrpc.php, which exposes a multicall method commonly abused to spray WordPress credentials and relay pingback floods; it also probed a WordPress admin/content path used to fingerprint the installation or hunt for an exposed upload/plugin surface.

Seen on our edge, web sensors.

Scored into the "Brute" level, carrying the badges Regular, Toolkit.

Routed via AS36680 (Netiface LLC), an ASN we classify as residential.

Publicly listed on this board, but not currently blocked on any of our hosts.

Enrichment

rDNSnone
ASNAS36680 — Netiface LLC
Routing ASN (differs)AS403005
ASN typeresidential
CountryUnited States (US)
Flagsnone observed

External references: GreyNoise, Shodan, AbuseIPDB

Timeline

Evidence (newest first, up to 50)

Time (UTC)VantageSiteClassStatusEvidence
2026-10-04T19:56:01Zwebtechauthors.eurequested xmlrpc.php, which exposes a multicall method commonly abused to spray WordPress credentials and relay pingback floods404GET /xmlrpc.php -> 404
2026-10-04T19:41:19Z – 2026-10-04T19:41:21Zwebtechauthors.eu6 × probed a list of common site paths looking for an unprotected admin panel or staging copy404GET /dev -> 404 (6 distinct paths)
2026-10-04T19:41:18Zwebtechauthors.euprobed a WordPress admin/content path used to fingerprint the installation or hunt for an exposed upload/plugin surface404GET /wp-admin/install.php -> 404
2026-10-04T19:41:18Zwebtechauthors.eumade a request that matched no known pattern404GET /wp-admin/setup-config.php -> 404
2026-10-04T19:41:18Zwebtechauthors.euprobed a list of common site paths looking for an unprotected admin panel or staging copy404GET /wordpress -> 404
2026-10-03T21:46:35Zwebvictorantonov.com2 × made a request that matched no known pattern404GET /wp-content/plugins/apikey/apikey.php.suspected? -> 404 (2 distinct paths)
2026-10-03T21:46:35Zwebvictorantonov.comfuzzed a short, random filename looking for a forgotten script that responds404GET /uotacthg.php? -> 404
2026-10-03T21:46:35Zwebvictorantonov.commade a request that matched no known pattern404GET /wp-content/plugins/fix/up.php -> 404
2026-10-03T21:46:35Zwebvictorantonov.comchecked for a backdoor file planted under a WordPress theme directory404GET /wp-content/themes/seotheme/db.php? -> 404
2026-09-28T03:22:05Zedgevictorantonov.comrequested xmlrpc.php, which exposes a multicall method commonly abused to spray WordPress credentials and relay pingback floodsGET /xmlrpc.php
2026-09-27T20:48:30Zedgevictorantonov.comprobed a WordPress admin/content path used to fingerprint the installation or hunt for an exposed upload/plugin surfaceGET /wp-admin/install.php
2026-09-27T20:48:29Zedgevictorantonov.commade a request that matched no known patternGET /wp-admin/setup-config.php

Not currently correlated with any campaign.

Dispute or removal: [email protected] — reference 64.89.160.157. See /threats/about for the method and the 7-day review window.

card.svg (used as this page's og:image)