Severe Risk
IP 62.60.130.210 is a critical-risk address originating from Iran under ASN AS215930 (Tawsie Technology), associated with 333 abuse reports documenting persistent WordPress login brute-force activity across an eight-month observation window from September 2025 through May 2026. The threat level is rated at the maximum 10/10, with an activity frequency score of 8/10, indicating sustained and aggressive attack behaviour against publicly accessible authentication endpoints.
The detection profile draws from 20 distinct sources — five automated honeypot sensors and 15 community submissions — confirming coordinated password-spray campaigns against WordPress installations. Of the total reports, 25 explicitly document brute-force activity, with the balance spanning related malicious authentication patterns. Attack-pattern analysis reveals systematic probes targeting multiple distinct usernames within compressed timeframes, consistent with automated credential-stuffing operations using wordlist-based or dictionary-driven password guessing. The volume and consistency of these reports indicate the IP is likely operating through compromised infrastructure or dedicated attack hardware rather than opportunistic scanning.
WordPress login brute-force attacks exploit authentication systems by systematically testing credential combinations until valid access is obtained. Successful compromise grants attackers administrative control over the content management system, enabling website defacement, data exfiltration, malware hosting, and lateral movement into connected databases or hosting environments. The targeted organizations documented in the attack logs span European entities, suggesting this infrastructure participates in broad, non-targeted credential-guessing campaigns across the global internet rather than focused attacks on specific victims.
Site operators running WordPress should block IP 62.60.130.210 at the firewall or web application firewall level immediately. Implement fail2ban or equivalent intrusion-prevention tools configured with strict login-throttling thresholds and temporary subnet-based blocking after repeated authentication failures. Enforce strong password policies and mandate multi-factor authentication for all administrative accounts. Regularly audit authentication logs for the probing patterns described — repeated failed logins across multiple usernames within short intervals — and consider restricting wp-login.php access to trusted IP ranges or requiring VPN-based access for administrative interfaces.