Investigation Workspace

Entity: 104.28.235.60 (Ip)

Entity Details
Type
Ip
ASN
AS13335 - Cloudflare, Inc.
Threat Intelligence
All requests (100%) from this IP were detected as threats, all accessed paths (suspicious PHP files and WordPress admin paths) were flagged by WAF, and a critical 'IPBLOCK-BURST4-318403' deny rule was triggered. Its associated ASN (AS13335) is already blocklisted for widespread malicious activity.
Linked Entities
TLS Fingerprints (1)
Hostnames Targeted
Hostname Request Count
akamai.darcherif.fr 72
Paths Targeted (with Request Counts)
Path Request Count
_sec/cp_challenge/challenge 23
abcd.php 2
zwso.php 2
wp-admin/admin-ajax.php 2
shelp.php 2
file2.php 2
cord.php 2
dex.php 2
222.php 1
wp-content/themes/style.php 1
file.php 1
bolt.php 1
txets.php 1
postnews.php 1
wp-editor.php 1
class-t.api.php 1
files.php 1
akcc.php 1
blurbs.php 1
bless.php 1
style.php 1
gifclass.php 1
flower.php 1
chosen.php 1
witmm.php 1
ioxi-o.php 1
shlo.php 1
lufix1.php 1
php8.php 1
wp-includes/style.php 1
wp-admin/style.php 1
wp-content/postnews.php 1
wp-admin/postnews.php 1
wp-admin/txets.php 1
wp-admin/zwso.php 1
wp-admin/css/index.php 1
wp-content/style.php 1
wp-content/txets.php 1
wp-content/index.php 1
ahax.php 1
wp-content/plugins/hellopress/wp_mna.php 1
wp-content/plugins/index.php 1
133.php 1
🚫

Block

All requests (100%) from this IP were detected as threats, all accessed paths (suspicious PHP files and WordPress admin paths) were flagged by WAF, and a critical 'IPBLOCK-BURST4-318403' deny rule was triggered. Its associated ASN (AS13335) is already blocklisted for widespread malicious activity.

2026-01-25 23:29:59