Investigation Workspace

Entity: 104.28.203.58 (Ip)

Entity Details
Type
Ip
ASN
AS13335 - Cloudflare, Inc.
Threat Intelligence
All requests (100%) from this IP were flagged by WAF, accessing suspicious PHP files and WordPress admin paths, and triggered a security alert, indicating active malicious probing or exploitation attempts.
Linked Entities
TLS Fingerprints (1)
Hostnames Targeted
Hostname Request Count
akamai.darcherif.fr 83
Paths Targeted (with Request Counts)
Path Request Count
222.php 2
wp-content/plugins/index.php 2
zwso.php 2
php8.php 2
shlo.php 2
akcc.php 2
cord.php 2
file.php 2
133.php 2
abcd.php 2
dex.php 2
ahax.php 2
txets.php 2
postnews.php 2
wp-editor.php 2
class-t.api.php 2
files.php 2
file2.php 2
blurbs.php 2
bless.php 2
wp-admin/postnews.php 2
gifclass.php 2
flower.php 2
chosen.php 2
witmm.php 2
ioxi-o.php 2
shelp.php 2
lufix1.php 2
wp-admin/admin-ajax.php 2
wp-includes/style.php 2
wp-admin/style.php 2
wp-content/postnews.php 2
wp-content/themes/style.php 2
wp-admin/txets.php 2
wp-admin/zwso.php 2
wp-admin/css/index.php 2
wp-content/style.php 2
wp-content/txets.php 2
wp-content/index.php 2
wp-content/plugins/hellopress/wp_mna.php 2
bolt.php 2
style.php 1
🚫

Block

All requests (100%) from this IP were flagged by WAF, accessing suspicious PHP files and WordPress admin paths, and triggered a security alert, indicating active malicious probing or exploitation attempts.

2026-01-03 01:12:54