There’s been a number of news stories on mass password guessing attacks on WordPress sites – none of which is anything new or exciting. The possibility some of these attacks are being done by a large botnet has seemed to shaken some folks.
http://blog.hostgator.com/2013/04/11/global-wordpress-brute-force-flood/
http://blog.sucuri.net/2013/04/mass-wordpress-brute-force-attacks-myth-or-reality.html
http://krebsonsecurity.com/2013/04/brute-force-attacks-build-wordpress-botnet/
Well, being the chummy, log sharing chap I am here’s a list of the naughty machines that have been trying to logging with the admin username on my lovely blog site.
My top security tip is rename the admin account to something less obvious: Elvis, pancake, tree, duh! or metalmicky would thwart this rather simplistic attack. A decent passphrase would be another fine option too…
Needless to say most of the attacking IP addresses are from the land of the free and the home of the weak password: The United States of America.65 out of the 151 in the table below.
I found a niffy web site that allowed me to make this pretty visual map of the attackers location http://batchiplocator.webatu.com/
Shame they only allow 110 addresses to be entered for display on the geo-ip map, but it very handy for putting together a blog post like this.
Add the following naught password guessing IPs to block lists, see if these have hit your logs too or even report them to their abuse@ ISP emails. It’s up to you.
These IP addresses are from the 14th of April up to today (18th of April).
| ip | country |
| 193.180.115.113 | Austria |
| 85.158.215.36 | Belgium |
| 177.180.13.250 | Brazil |
| 187.85.82.38 | Brazil |
| 78.142.63.82 | Bulgaria |
| 199.204.214.208 | Canada |
| 184.107.150.58 | Canada |
| 108.163.128.206 | Canada |
| 108.163.188.186 | Canada |
| 198.144.157.117 | Canada |
| 24.64.120.194 | Canada |
| 190.98.219.99 | Chile |
| 210.14.78.21 | China |
| 223.87.0.177 | China |
| 111.13.87.150 | China |
| 218.203.105.26 | China |
| 61.234.146.186 | China |
| 61.175.223.134 | China |
| 211.167.112.14 | China |
| 14.17.29.112 | China |
| 41.222.196.37 | Congo, The Democratic Republic of the |
| 185.15.196.72 | Europe |
| 94.23.234.227 | France |
| 188.165.202.45 | France |
| 5.135.158.104 | France |
| 109.1.137.192 | France |
| 81.252.211.149 | France |
| 194.231.138.35 | Germany |
| 194.116.187.25 | Germany |
| 83.243.57.33 | Germany |
| 87.253.162.6 | Germany |
| 188.40.166.133 | Germany |
| 31.22.104.28 | Germany |
| 85.10.195.141 | Germany |
| 176.9.78.117 | Germany |
| 85.214.27.40 | Germany |
| 46.165.198.100 | Germany |
| 85.25.73.37 | Germany |
| 188.40.69.202 | Germany |
| 78.46.34.77 | Germany |
| 180.188.194.54 | Hong Kong |
| 124.244.59.238 | Hong Kong |
| 94.199.51.8 | Hungary |
| 210.210.178.20 | Indonesia |
| 115.124.72.62 | Indonesia |
| 118.99.79.123 | Indonesia |
| 42.62.176.150 | Indonesia |
| 180.244.193.110 | Indonesia |
| 77.237.73.3 | Iran, Islamic Republic of |
| 85.119.183.223 | Italy |
| 202.232.236.66 | Japan |
| 210.188.201.41 | Japan |
| 115.187.79.147 | Japan |
| 202.214.8.82 | Japan |
| 2.135.238.162 | Kazakhstan |
| 176.123.0.114 | Moldova, Republic of |
| 176.123.0.105 | Moldova, Republic of |
| 91.214.200.45 | Moldova, Republic of |
| 176.123.0.237 | Moldova, Republic of |
| 176.123.0.231 | Moldova, Republic of |
| 176.123.0.94 | Moldova, Republic of |
| 77.235.47.247 | Netherlands |
| 194.247.30.126 | Netherlands |
| 80.95.160.178 | Netherlands |
| 146.0.79.23 | Netherlands |
| 89.44.200.154 | Romania |
| 92.114.86.81 | Romania |
| 93.187.140.18 | Romania |
| 89.38.207.234 | Romania |
| 80.86.105.174 | Romania |
| 80.78.247.92 | Russian Federation |
| 178.208.91.196 | Russian Federation |
| 151.248.123.211 | Russian Federation |
| 212.49.116.20 | Russian Federation |
| 119.31.233.40 | Singapore |
| 80.35.80.139 | Spain |
| 80.28.254.179 | Spain |
| 61.19.248.138 | Thailand |
| 95.173.186.104 | Turkey |
| 31.210.86.205 | Turkey |
| 37.247.99.82 | Turkey |
| 94.138.206.66 | Turkey |
| 37.57.25.225 | Ukraine |
| 31.202.217.135 | Ukraine |
| 95.154.234.101 | United Kingdom |
| 80.68.95.137 | United Kingdom |
| 216.224.169.123 | United States |
| 184.154.36.210 | United States |
| 67.205.24.238 | United States |
| 96.127.139.170 | United States |
| 74.208.66.177 | United States |
| 65.254.40.154 | United States |
| 70.32.112.125 | United States |
| 64.202.240.136 | United States |
| 209.51.142.178 | United States |
| 199.195.143.121 | United States |
| 24.234.3.189 | United States |
| 184.105.235.28 | United States |
| 66.36.228.123 | United States |
| 207.58.185.126 | United States |
| 184.154.115.10 | United States |
| 69.163.164.44 | United States |
| 199.180.252.22 | United States |
| 66.55.144.244 | United States |
| 173.245.6.132 | United States |
| 65.254.168.168 | United States |
| 67.215.243.250 | United States |
| 216.224.175.71 | United States |
| 72.29.68.51 | United States |
| 74.207.224.242 | United States |
| 69.174.254.88 | United States |
| 74.117.61.88 | United States |
| 174.127.117.77 | United States |
| 72.32.68.101 | United States |
| 69.195.198.111 | United States |
| 198.1.127.222 | United States |
| 208.113.170.83 | United States |
| 204.93.60.103 | United States |
| 204.93.60.174 | United States |
| 207.58.139.238 | United States |
| 204.93.60.208 | United States |
| 204.93.60.84 | United States |
| 216.172.147.251 | United States |
| 204.93.60.164 | United States |
| 204.93.60.75 | United States |
| 50.22.236.98 | United States |
| 204.93.60.12 | United States |
| 50.117.80.66 | United States |
| 204.93.60.58 | United States |
| 216.172.147.234 | United States |
| 184.168.112.26 | United States |
| 199.223.214.154 | United States |
| 8.29.131.248 | United States |
| 184.168.109.23 | United States |
| 23.27.237.205 | United States |
| 208.116.36.230 | United States |
| 198.98.113.47 | United States |
| 65.60.19.242 | United States |
| 72.167.13.19 | United States |
| 50.117.80.168 | United States |
| 216.172.147.57 | United States |
| 198.144.116.91 | United States |
| 184.168.114.10 | United States |
| 204.93.60.9 | United States |
| 208.115.125.60 | United States |
| 204.93.60.207 | United States |
| 23.27.238.51 | United States |
| 198.144.116.100 | United States |
| 50.117.80.38 | United States |
| 50.31.98.92 | United States |
| 209.73.151.229 | United States |

