High Risk
IP 149.102.230.138 is a high-risk address operating from Germany that presents a 7/10 threat level based on 198 abuse reports filed against it during May 2026, with automated honeypot sensors flagging it primarily for WordPress-targeted exploitation including bad web bot activity, web application attacks, fake SEO manipulation attempts, and media library abuse.
Originating from AS212238 (Datacamp Limited), this IP demonstrated an activity frequency rating of 8/10 over a concentrated one-month reporting window, indicating sustained rather than opportunistic hostile behavior. The 20 automated honeypot sources that generated these reports recorded consistent patterns including empty User-Agent headers and specific probes targeting WordPress upload directories at /wp-content/uploads/, a known enumeration and abuse vector. With a 91% confidence score, the threat attribution is highly reliable, and the volume of distinct report categories suggests a versatile automated attack toolkit rather than a single-purpose scanner.
The dominant threat categories reveal a deliberate focus on WordPress environments. Bad web bot activity indicates automated tools that bypass ethical crawling practices, scraping content or probing for vulnerabilities without compliance. Web application attacks aligned with OWASP Top 10 patterns pose risks including cross-site scripting, file inclusion, and configuration weaknesses. The WP Fake SEO Bot category suggests attempts to manipulate search rankings through deceptive ping requests or content injection, while media library abuse targeting upload directories could enable unauthorized file storage, malware distribution, or reconnaissance for further exploitation. Together these patterns indicate an IP engaged in systematic WordPress reconnaissance and compromise preparation.
Site operators should immediately block or rate-limit connections from this address at the firewall or load balancer level and implement bot detection solutions capable of identifying and blocking requests with empty User-Agent strings. Deploying a web application firewall with WordPress-specific rule sets will mitigate web app attack vectors, while ensuring upload directories are non-executable and properly permissioned closes the media library abuse pathway. Monitoring access logs for the observed patterns and enforcing strong authentication on administrative endpoints provides additional defense-in-depth against the hostile automation this IP represents.