Significant Threat
IP 116.118.2.113 is a high-risk address originating from Vietnam, operated by Saigon Postel Corporation (AS7602), that has generated 296 abuse reports with a threat level of 8/10, indicating persistent and aggressive automated attack behavior primarily targeting WordPress installations and authentication systems. The IP address demonstrates a clear pattern of credential-based attacks, with 17 automated honeypot sensors and 3 community sources reporting malicious activity between February and April 2026. Dominant threat categories include general hacking attempts, WordPress login brute-force campaigns, traditional brute-force authentication attacks, port scanning, and WordPress XML-RPC exploitation, collectively accounting for the majority of the 296 total reports filed against this address. The detection data reveals that fail2ban systems alone recorded over 147 violations across multiple security jails, confirming sustained offensive operations that have triggered automated defensive responses across numerous victim environments. This IP presents a concrete risk to any publicly accessible web service, particularly WordPress-based sites, because the documented attack patterns exploit weak or default credentials, abuse the WordPress XML-RPC interface for distributed authentication attacks, and attempt to probe system files for known vulnerabilities. The volume and diversity of techniques suggest an automated bot operating continuously rather than isolated manual probing. Site operators should immediately block or rate-limit this IP at the firewall level, enforce multi-factor authentication on all administrative accounts, disable unused XML-RPC functionality on WordPress deployments, and implement fail2ban or equivalent dynamic blocking tools to automatically ban repeat offenders matching known attack signatures. Regular monitoring of access logs for the patterns detected by honeypot sensors can help identify if this threat actor has already compromised any exposed services.