Significant Threat
IP 77.90.185.245 is a high-risk address operated by Inside Network LTD (AS215476) in Germany that has been linked to WordPress login brute-force attacks and broader authentication brute-force campaigns, with 158 abuse reports and a threat level of 8/10 indicating credible risk to any publicly accessible web authentication system.
The address was first reported in November 2025 and remained active through January 2026, representing approximately two months of sustained malicious activity. Of the 158 total reports, 20 specifically document WordPress login brute-force attempts while 13 detail general brute-force activity against authentication systems. Detection came from 7 automated honeypot sensors and 13 community reports, indicating broad coverage across both automated and human-reported sighting networks. With a confidence score of 85%, the data strongly supports the classification of this IP as an active threat actor within the scanned timeframe.
WordPress login brute-force attacks systematically target web-based authentication endpoints by cycling through credential combinations in an attempt to gain unauthorized administrative access. Automated honeypot sensors detected the characteristic "wordpress-escalation" pattern consistent with tools designed to identify and exploit weak WordPress admin credentials. The concrete risk to an exposed site is unauthorized admin panel access, which can lead to website defacement, data exfiltration, malware distribution infrastructure, or further lateral movement within connected systems.
Site operators should block or rate-limit IP 77.90.185.245 at the firewall or WAF level to immediately sever the attacking connection. Implementing multi-factor authentication on all administrative accounts and relocating the WordPress login URL to a non-standard path substantially raises the difficulty for automated credential-testing tools. Deploying or configuring fail2ban with WordPress-specific filter rules will automatically ban repeat offenders matching the observed attack signatures. Finally, continuous monitoring of authentication logs for high-volume failed-login events from this address enables rapid incident response.