High Risk
IP 93.123.109.165, originating from Bulgaria and operated by Techoff Srv Limited under ASN AS48090, is a high-risk address with a threat level of 8 out of 10, linked primarily to WordPress login brute-force attacks and associated web-application exploitation attempts. With 1,062 total abuse reports and an activity frequency rated 8 out of 10, this IP has demonstrated persistent, high-volume hostile activity over a seven-month window from January to July 2026. The dominant threat profile targets WordPress administrative interfaces, indicating a deliberate focus on compromising content management systems through credential stuffing and automated login guessing.
The evidence base is substantial and credible: 1,062 reports from 20 distinct sources, with 19 originating from automated honeypot sensors and 1 from community reporting. The confidence score of 85% reflects the volume and consistency of detections. Geolocation places the source in Bulgaria, and the ASN operator Techoff Srv Limited manages the network block from which this activity emanates. The attack-pattern logs reveal not only WordPress-focused brute-force attempts but also concurrent Drupal probing, path traversal probes, and repeated violations triggering the recidive jail, meaning this address has been blocked previously yet continues operating across multiple attack campaigns.
WordPress brute-force attacks systematically iterate username and password combinations against the wp-login.php endpoint, exploiting weak administrator credentials to gain unauthorized backend access. Successful compromise grants attackers persistent website control, enabling malicious redirects, data exfiltration, malware deployment, or further network pivoting. The simultaneous Drupal and path traversal activity broadens the threat surface, suggesting this IP sweeps for vulnerabilities across multiple content management platforms rather than specializing in a single vector. The recidive classification indicates this actor has been previously banned and returned, demonstrating persistence and intent.
Site operators exposing WordPress or Drupal instances should immediately block or rate-limit traffic from this IP at the firewall or load-balancer level. Enforcing multi-factor authentication on all administrative accounts and implementing account lockout policies after a small number of failed login attempts significantly raises the bar against automated credential guessing. Deploying defensive tools such as fail2ban with WordPress-specific jails and applying strict access controls on administrative paths will reduce exposure. Continuous monitoring of authentication logs for the patterns and frequency observed from this source address is strongly advised.