94.26.106.122
Case file
First seen on 2026-09-30T23:09:16Z, most recently active on 2026-10-04T08:24:46Z.
Recorded 14 attack-shaped requests across 4 separate days.
Its traffic requested wp-login.php to check whether this site runs WordPress; it also probed a WordPress admin/content path used to fingerprint the installation or hunt for an exposed upload/plugin surface.
Seen from 3 of our sensors: edge, nl4-web, s19-web.
Scored into the "Brute" level, carrying the badge Regular.
Routed via AS197170 (TechTies Inc.), an ASN we classify as hosting.
Publicly listed on this board, but not currently blocked on any of our hosts.
Enrichment
| rDNS | none |
|---|---|
| ASN | AS197170 — TechTies Inc. |
| ASN type | hosting |
| Country | Germany (DE) |
| Flags | none observed |
Timeline
- 2026-09-302
- 2026-10-026
- 2026-10-035
- 2026-10-041
Evidence (newest first, up to 50)
| Time (UTC) | Vantage | Site | Class | Status | Evidence |
|---|---|---|---|---|---|
| 2026-10-04T08:24:46Z | s19-web | haived.com | requested wp-login.php to check whether this site runs WordPress | 404 | 94.26.106.122 - - [04/Oct/2026:08:24:46 +0000] "GET /wp-login.php HTTP/1.1" 404 84 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.6099.130 Safari/537.36" rt=0.001 cf=<redacted>-FRA |
| 2026-10-03T22:57:47Z | nl4-web | servbg.com | requested wp-login.php to check whether this site runs WordPress | 404 | 94.26.106.122 - - [04/Oct/2026:01:57:47 +0300] "GET /wp-login.php HTTP/1.1" 404 16 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.6099.130 Safari/537.36" |
| 2026-10-03T21:53:43Z | nl4-web | schetio.com | matched a catalogue rule | 404 | 94.26.106.122 - - [04/Oct/2026:00:53:43 +0300] "GET /administrator/ HTTP/1.1" 404 236 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) Gecko/20100101 Firefox/120.0.1" |
| 2026-10-03T21:53:43Z | nl4-web | schetio.com | requested wp-login.php to check whether this site runs WordPress | 404 | 94.26.106.122 - - [04/Oct/2026:00:53:43 +0300] "GET /wp-login.php HTTP/1.1" 404 16 "-" "Mozilla/5.0 (X11; Linux x86_64) Gecko/20100101 Firefox/121.0" |
| 2026-10-03T03:56:11Z | nl4-web | schetio.com | probed a WordPress admin/content path used to fingerprint the installation or hunt for an exposed upload/plugin surface | 404 | 94.26.106.122 - - [03/Oct/2026:06:56:11 +0300] "GET /wp-admin/ HTTP/1.1" 404 236 "https://www.facebook.com/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7; rv:120.0) Gecko/20100101 Firefox/120.0" |
| 2026-10-03T03:56:11Z – 2026-10-03T03:56:11Z ×2 | nl4-web | schetio.com | 2 × requested wp-login.php to check whether this site runs WordPress | 404 | 94.26.106.122 - - [03/Oct/2026:06:56:11 +0300] "GET /wp-login.php HTTP/1.1" 404 16 "https://duckduckgo.com/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 13_6_1; rv:119.0) Gecko/20100101 Firefox/119.0" |
| 2026-10-02T22:09:15Z | nl4-web | zmey.eu | probed a WordPress admin/content path used to fingerprint the installation or hunt for an exposed upload/plugin surface | 404 | 94.26.106.122 - - [03/Oct/2026:01:09:15 +0300] "GET /wp-admin/ HTTP/1.1" 404 236 "https://wordpress.org/" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/118.0.0.0 Safari/537.36" |
| 2026-10-02T22:09:15Z – 2026-10-02T22:09:15Z ×2 | nl4-web | zmey.eu | 2 × requested wp-login.php to check whether this site runs WordPress | 404 | 94.26.106.122 - - [03/Oct/2026:01:09:15 +0300] "GET /wp-login.php HTTP/1.1" 404 16 "-" "Mozilla/5.0 (Windows NT 11.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.0.0 Safari/537.36" |
| 2026-10-02T18:41:52Z | edge | victorantonov.com | probed a WordPress admin/content path used to fingerprint the installation or hunt for an exposed upload/plugin surface | {"ts":"2026-10-02T18:41:52Z","ip":"94.26.106.122","zone":"victorantonov.com","host":"victorantonov.com","path":"/wp-admin/","method":"GET","query":"","ua":"Mozilla/5.0 (Macintosh; Intel Mac OS X 13_6_1) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Safari/605.1.15","action":"managed_challeng… | |
| 2026-10-02T18:41:50Z – 2026-10-02T18:41:51Z ×2 | edge | victorantonov.com | 2 × matched a catalogue rule | {"ts":"2026-10-02T18:41:51Z","ip":"94.26.106.122","zone":"victorantonov.com","host":"victorantonov.com","path":"/wp-login.php","method":"GET","query":"","ua":"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7; rv:121.0) Gecko/20100101 Firefox/121.0","action":"managed_challenge","source":"firewallCustom… | |
| 2026-09-30T23:09:16Z | nl4-web | servbg.com | probed a WordPress admin/content path used to fingerprint the installation or hunt for an exposed upload/plugin surface | 404 | 94.26.106.122 - - [01/Oct/2026:02:09:16 +0300] "GET /wp-admin/ HTTP/1.1" 404 236 "-" "Mozilla/5.0 (Windows NT 11.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36" |
| 2026-09-30T23:09:16Z | nl4-web | servbg.com | requested wp-login.php to check whether this site runs WordPress | 404 | 94.26.106.122 - - [01/Oct/2026:02:09:16 +0300] "GET /wp-login.php HTTP/1.1" 404 16 "https://www.google.com/search?" "Mozilla/5.0 (Macintosh; Intel Mac OS X 13_6_1) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Safari/605.1.15" |
| 2026-10-02T21:29:05Z | nl4-web | recmydays.com | probed a WordPress admin/content path used to fingerprint the installation or hunt for an exposed upload/plugin surface | 404 | 94.26.106.122 - - [03/Oct/2026:00:29:05 +0300] "GET /wp-admin/ HTTP/1.1" 404 1237 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" |
| 2026-10-02T21:29:05Z | nl4-web | recmydays.com | requested wp-login.php to check whether this site runs WordPress | 404 | 94.26.106.122 - - [03/Oct/2026:00:29:05 +0300] "GET /wp-login.php HTTP/1.1" 404 16 "https://duckduckgo.com/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 13_6_1) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Safari/605.1.15" |
Report history
No abuse report sent for this address yet.
Not currently correlated with any campaign.
Dispute or removal: [email protected] — reference 94.26.106.122 (mailbox goes live with phase 3). See /threats/about for the method and the 7-day review window.
card.svg (used as this page's og:image)