Critical Threat
IP address 141.98.11.169 is a critical-risk address associated with WordPress login brute-force attacks, accumulating 181 abuse reports from automated honeypot sensors since August 2025 through May 2026. With a threat score of 10 out of 10 and a low activity frequency rating of 1 out of 10, this Lithuanian IP represents a persistent, automated threat actor conducting sustained credential stuffing against web authentication interfaces.
The IP routes through AS209605 operated by UAB Host Baltic, and the report volume of 181 complaints from 20 distinct honeypot sources confirms coordinated, distributed attack infrastructure rather than isolated scanning. Detection confidence stands at 72 percent, reflecting realistic uncertainty in attributing all activity to a single threat actor despite the consistent attack pattern. The nine-month reporting window from first detection in August 2025 through May 2026 demonstrates persistent engagement with vulnerable login endpoints rather than opportunistic or transient activity.
WordPress login brute-force attacks pose significant real-world risk because successful authentication grants attackers administrative control over the content management system, enabling data exfiltration, malware distribution, pivot attacks on connected infrastructure, and complete site defacement. The volume and persistence of reports indicate automated bot activity systematically testing credential combinations against exposed WordPress admin panels, exploiting weak or reused passwords across unprotected installations.
Site operators running WordPress or similar web applications should immediately block this IP at the firewall or network edge, implement strict rate-limiting on authentication endpoints, enforce strong password policies combined with two-factor authentication, and deploy defensive tools such as fail2ban to automatically ban repeated login failures. Continuous monitoring for distributed authentication patterns across multiple source IPs is essential, as this address may represent one node within a larger coordinated attack infrastructure.