Investigation Workspace

Entity: 158.158.32.105 (Ip)

Entity Details
Type
Ip
ASN
AS8075 - Microsoft Corporation
Threat Intelligence
All requests flagged by WAF, accessing highly suspicious PHP files (e.g., webshells), and already subject to an IPBLOCK security rule. This indicates severe malicious activity.
Linked Entities
Hostnames Targeted
Hostname Request Count
akamai.darcherif.fr 178
Paths Targeted (with Request Counts)
Path Request Count
av.php 2
wp-content/admin.php 2
sc.php 2
wp9.php 2
path.php 2
assets/css/index.php 2
ms-edit.php 2
yos.php 1
wp-p2r3q9c8k4.php 1
about.php 1
adminfuns.php 1
w2025.php 1
alfashell.php 1
BDKR28WP.php 1
class-t.api.php 1
gptsh.php 1
bgymj.php 1
wziar1.php 1
invisi.php 1
file59.php 1
elabel.php 1
txets.php 1
wp-act.php 1
inputs.php 1
rithin.php 1
plss3.php 1
lp6.php 1
database.php 1
ss.php 1
wp-the.php 1
wp-blog.php 1
bengi.php 1
gettest.php 1
akses.php 1
jocundly.php 1
nw_ok.php 1
miansha.php 1
maxro.php 1
oirsbfkm.php 1
goods.php 1
wp-michan.php 1
filefuns.php 1
fvvff.php 1
wp-content/plugins/index.php 1
gssdd.php 1
wp-content/ 1
wsvvs.php 1
bless.php 1
wp-includes/js/dist/ 1
settings.php 1
🚫

Block

All requests flagged by WAF, accessing highly suspicious PHP files (e.g., webshells), and already subject to an IPBLOCK security rule. This indicates severe malicious activity.

2026-03-10 18:13:03