Investigation Workspace

Entity: 104.28.235.59 (Ip)

Entity Details
Type
Ip
ASN
AS13335 - Cloudflare, Inc.
Threat Intelligence
Critical threat detected: 100% of requests (42/42) flagged by WAF and triggered security rule 3990001 (Generic Web Application Attack). Accessing suspicious PHP files commonly associated with web shells and compromised WordPress sites (e.g., wp-admin/css/index.php, akcc.php).
Linked Entities
TLS Fingerprints (1)
Hostnames Targeted
Hostname Request Count
akamai.darcherif.fr 43
Paths Targeted (with Request Counts)
Path Request Count
style.php 2
222.php 1
wp-admin/postnews.php 1
php8.php 1
shlo.php 1
akcc.php 1
cord.php 1
file.php 1
133.php 1
abcd.php 1
dex.php 1
bolt.php 1
zwso.php 1
postnews.php 1
wp-editor.php 1
class-t.api.php 1
files.php 1
file2.php 1
blurbs.php 1
bless.php 1
ahax.php 1
gifclass.php 1
flower.php 1
chosen.php 1
witmm.php 1
ioxi-o.php 1
shelp.php 1
lufix1.php 1
wp-admin/admin-ajax.php 1
wp-includes/style.php 1
wp-admin/style.php 1
wp-content/postnews.php 1
wp-content/themes/style.php 1
wp-admin/txets.php 1
wp-admin/zwso.php 1
wp-admin/css/index.php 1
wp-content/style.php 1
wp-content/txets.php 1
wp-content/index.php 1
wp-content/plugins/hellopress/wp_mna.php 1
wp-content/plugins/index.php 1
txets.php 1
🚫

Block

Critical threat detected: 100% of requests (42/42) flagged by WAF and triggered security rule 3990001 (Generic Web Application Attack). Accessing suspicious PHP files commonly associated with web shells and compromised WordPress sites (e.g., wp-admin/css/index.php, akcc.php).

2026-02-14 14:40:09