Substantial Risk
IP 141.98.11.117 is a high-risk address operating from Lithuania (AS209605, UAB Host Baltic) that represents a significant and ongoing threat, with 467 abuse reports filed over a six-month window and a threat level of 8/10. This IP has demonstrated a diverse and aggressive attack profile, most prominently targeting authentication systems via brute-force methods and WordPress installations through multiple exploitation techniques. The sustained volume and variety of malicious activity, combined with 100% confidence in the attribution, make this address a clear candidate for immediate blocking at the network perimeter.
The detection data reveals this address was first reported in January 2026 and remained active through June 2026, generating reports from 11 automated honeypot sensors and 9 community sources. The 467 total reports translate to an activity frequency rating of 8/10, indicating near-continuous malicious behaviour throughout the observation period. The reported threat categories span credential-based attacks, application-layer exploitation, and distributed denial-of-service activity, with brute-force attacks (including dedicated WordPress login brute-force attempts) and general hacking activity forming the dominant categories. The network is operated by UAB Host Baltic, a Lithuanian hosting provider, suggesting the address is likely part of a dedicated attack infrastructure rather than a compromised end-user device.
The brute-force activity observed from this address follows a well-established pattern of systematically attempting common and default credentials against exposed authentication endpoints. Community reports indicate these attempts include credential stuffing using administrative username combinations, which poses a direct risk of unauthorized access to poorly secured web applications and administrative panels. Simultaneously, the WordPress-specific attack vectors—including media library abuse, author enumeration, and plugin exploitation—target the most common content management system vulnerabilities exposed on the internet today. The presence of DDoS attack reports further indicates this address may participate in coordinated disruption campaigns beyond individual server compromise attempts.