Maximum Danger
IP 91.224.92.99 is a high-risk address associated with automated credential-stuffing and brute-force campaigns against web authentication endpoints, with a threat level of 10/10 and 220 independent abuse reports spanning approximately nine months of sustained hostile activity. This Lithuanian-operated IP (AS209605, UAB Host Baltic) demonstrates a persistent activity frequency of 8/10, indicating near-continuous scanning and authentication-attack behavior that places any exposed service at significant compromise risk.
Security monitoring systems detected this address across 9 automated honeypot sensors and 11 community reporting sources between August 2025 and May 2026, generating a confidence score of 83% for the attributed threat categories. The predominant attack vectors involve brute-force attempts (11 reports) and WordPress login brute-force campaigns (9 reports), consistent with automated toolchains targeting content-management system authentication pages. The geographic attribution to the United Kingdom appears inconsistent with the Lithuanian ASN ownership, suggesting possible use of proxy infrastructure or compromised endpoints to obfuscate true origin.
Brute-force attacks systematically iterate through authentication credentials, exploiting weak or commonly reused passwords to gain unauthorized access to web-facing systems. WordPress login targeting specifically focuses on administrative portals, which if compromised provide full website control, data exfiltration capabilities, and potential pivot points into connected infrastructure. The volume and persistence of activity from this IP suggests involvement in coordinated credential-testing campaigns rather than opportunistic opportunistic scanning.
Administrators should immediately block this IP at the network perimeter and implement defensive tools such as fail2ban with appropriate escalation thresholds. Enforcing strong password policies, enabling multi-factor authentication on all administrative interfaces, and applying rate limiting to authentication endpoints will substantially reduce exposure to brute-force campaigns. Continuous monitoring of authentication logs for this source address is recommended to detect any attempted circumventing of blocking measures.