High Risk
IP address 93.123.109.165 is a high-risk threat actor originating from Bulgaria, operated by Techoff Srv Limited through ASN AS48090, with a threat level rating of 8 out of 10 and a confidence score of 81 percent. This address has accumulated 933 total abuse reports across automated honeypot sensors over approximately five months, indicating sustained and aggressive malicious activity since its first recorded report in January 2026. The dominant threat vectors involve WordPress credential attacks, with the most recent reports documenting 19 WordPress login brute-force attempts and 16 WordPress admin brute-force attempts, alongside broader hacking activity including exploitation attempts and brute-force intrusion patterns.
The detection data reveals persistent, high-frequency hostile probing across multiple content management systems. Automated honeypot sensors logged the activity consistently from January through May 2026, generating a significant volume of 933 reports sourced from 20 separate honeypot nodes. The geographic origin in Bulgaria and the network operator Techoff Srv Limited provide context for the infrastructure supporting these attacks, while the ASN assignment suggests a hosting or service provider relationship that may be leveraged for modular attack campaigns. The 81% confidence score indicates reasonable certainty that this activity represents genuine malicious intent rather than misclassification, though a portion of the signals carry some uncertainty typical of automated detection systems.
The reported threat categories collectively indicate a coordinated campaign targeting web applications, specifically content management systems like WordPress and Drupal. WordPress brute-force attacks attempt to compromise administrative credentials through automated credential guessing, while the additional attack-pattern evidence shows wp-config access attempts and path traversal techniques targeting configuration files and directory structures. The recidive jail detections confirm this IP has been repeatedly flagged across multiple defensive systems, demonstrating a determined attacker unwilling to relent after initial blocks. These combined vectors create a realistic risk of unauthorized administrative access, website defacement, data exfiltration, or further lateral movement within compromised hosting environments.