Substantial Risk
IP 185.177.72.38, registered to Bucklog SARL in France and operating within AS211590, presents a high-risk threat profile with a threat level of 8 out of 10 and a confidence score of 79 percent based on 208 total abuse reports submitted by automated honeypot sensors across a 10-month observation window from August 2025 through May 2026.
The overwhelming majority of reported activity centres on WordPress-targeted credential attacks, encompassing 17 WP Login Brute Force incidents and 13 WP Admin Brute Force attempts, collectively accounting for roughly 91 percent of categorized threats. Fail2ban logs corroborate this pattern with 50 violations flagging wp-config access attempts and 20 violations documenting Drupal admin probing, indicating the actor is systematically enumerating common CMS administration endpoints. A Suricata alert noting protocol mismatches in both directions and a single Exploited Host classification suggest this address may host malicious tooling or serve as a pivot point for multi-stage intrusion campaigns. The low activity frequency of 1 out of 10 implies deliberate, spaced-out attempts designed to evade threshold-based detection rather than high-volume automated script attacks.
WordPress brute force activity poses a concrete risk to any publicly exposed wp-login.php or wp-admin interfaces, where credential stuffing can grant attackers administrative access, enabling malware deployment, data exfiltration or further lateral movement within a compromised environment. The concurrent Drupal enumeration suggests the actor maintains flexibility to adapt attacks to whichever content management system is detected, increasing the practical danger to organisations running either platform without multi-factor authentication or strict IP-based access controls.
Site operators should immediately restrict wp-admin and administrative interfaces to trusted IP ranges using allowlisting rules in web server configurations or firewall policies. Implementing multi-factor authentication on all administrative accounts and applying rate-limiting rules via tools such as fail2ban or equivalent intrusion prevention solutions will substantially reduce the viability of credential guessing campaigns. Regular auditing for unused administrative endpoints, prompt patching of CMS installations and deployment of Web Application Firewall rules capable of detecting anomalous POST request patterns offer layered defence against the enumeration and access techniques observed from this address.