Maximum Danger
IP 87.120.191.67 is a maximum-threat-address with a 10/10 threat level that has generated 309 community reports documenting coordinated WordPress-targeted intrusion activity, including configuration exposure attempts, cron-based abuse, and denial-of-service probing originating from infrastructure operated by Vpsvault.host Ltd under ASN AS215925.
Automated honeypot sensors and 20 distinct community sources documented this address during February 2026, with reports clustering around four dominant categories: WP Config Exposure (20 reports), Hacking (20 reports), WP Cron Abuse (18 reports), and DDoS Attack (18 reports). The detection data shows the address repeatedly targeting WordPress installations through suspicious backup-related POST requests and unauthorized automated task execution. Despite the US country attribution, the hosting provider Vpsvault.host Ltd operates the associated network, suggesting the observed malicious traffic may originate from a different geographic source using this infrastructure as a relay point. The 58% confidence score indicates a moderately high certainty that this activity represents genuine malicious behavior rather than misclassification.
The dominant attack patterns reflect a deliberate campaign against WordPress deployments. Configuration exposure attempts aim to retrieve critical files containing database credentials and cryptographic keys, which could enable full site compromise. Unauthorized cron execution allows attackers to schedule malicious tasks within the target environment, while the backup-related request patterns suggest the address is scanning for misconfigured archives that may contain sensitive data. The concurrent DDoS activity indicates this infrastructure participates in coordinated attack operations beyond targeted exploitation.
Site operators should block this address at the network perimeter immediately and audit access logs for any matching source traffic. Implementing rate-limiting on authentication endpoints, hardening WordPress configuration file permissions, and disabling unused automated scheduling features will reduce exposure to the observed attack vectors. Maintaining current plugin and core updates, combined with intrusion detection monitoring for WordPress-specific signatures, provides layered defense against the techniques documented from this source.