Significant Threat
IP 170.106.107.87 is a high-risk address associated with 158 abuse reports spanning September 2025 through May 2026, with automated honeypot sensors and community sources documenting persistent web application probing, WordPress-targeted attacks, and distributed denial-of-service attempts originating from this US-hosted Tencent infrastructure endpoint.
Analysis of the 158 total reports reveals sustained malicious activity across an eight-month window at a moderate frequency level. Automated honeypot sensors generated 14 of these reports while community contributors filed 6, indicating both infrastructure-level detection and peer awareness of the threat. The dominant threat vector consists of web application attacks at 14 reported instances, followed by general hacking activity at 10 reports. WordPress-specific abuse comprises a significant portion of the remaining activity: unauthorized WP-Cron execution was documented 5 times, user enumeration attempts via the author parameter appeared once, and distributed denial-of-service activity was reported 5 times. Suricata telemetry from honeypot sensors captured HTTP request header repetition anomalies consistent with automated vulnerability scanning, and specific attempts to exploit the author parameter indicate targeted reconnaissance against WordPress installations. The IP resolves to Tencent Building, Kejizhongyi Avenue under AS132203, a network operator typically associated with Chinese technology infrastructure despite the US geographic classification.
Web application attacks encompass exploitation of software vulnerabilities including injection flaws, authentication bypasses, and sensitive data exposure, posing direct risk to any exposed HTTP services. The documented header repetition patterns and author parameter probing suggest automated reconnaissance designed to identify vulnerable WordPress instances and enumerate valid user accounts for subsequent credential attacks. WP-Cron abuse represents a concrete threat because unauthorized triggering of scheduled tasks can exhaust server resources, inject malicious content, or facilitate further compromise of WordPress environments. The presence of DDoS reports indicates potential participation in coordinated traffic amplification or botnet activity, expanding the threat profile beyond targeted web attacks alone.