Investigation Workspace

Entity: 158.158.41.149 (Ip)

Entity Details
Type
Ip
ASN
AS8075 - Microsoft Corporation
Threat Intelligence
All 115 requests from this IP address were detected as threats, accessing suspicious PHP files commonly associated with web shell activities or malicious scripts. The WAF flagged all accessed paths, and a security rule already triggered an IPBLOCK.
Linked Entities
Hostnames Targeted
Hostname Request Count
akamai.darcherif.fr 115
Paths Targeted (with Request Counts)
Path Request Count
bak.php 2
erty.php 2
lp6.php 1
bgymj.php 1
sa.php7 1
s.php 1
55.php 1
166.php 1
ajax.php 1
new4.php 1
wp-content/plugins/hellopress/wp_filemanager.php 1
666.php 1
ws66.php 1
tx78.php 1
amp.php 1
term.php 1
66.php 1
abc.php 1
init.php 1
jp.php 1
asax.php 1
sbhu.php 1
bolt.php 1
a4.php 1
tool.php 1
t.php 1
callback.php 1
file59.php 1
grsiuk.php 1
ms-edit.php 1
sid3.php 1
edit-tags.php 1
wp-p2r3q9c8k4.php 1
wp-admin/css/bolt.php 1
wp-content/radio.php 1
myfile.php 1
ioxi-o.php 1
bootstrap.php 1
gifclass.php 1
seetox.php 1
pouhg.php 1
install.php 1
wefile.php 1
admin-footer.php 1
hplfuns.php 1
plugins.php 1
black.php 1
wp-act.php 1
gettest.php 1
apk.php 1
🚫

Block

All 115 requests from this IP address were detected as threats, accessing suspicious PHP files commonly associated with web shell activities or malicious scripts. The WAF flagged all accessed paths, and a security rule already triggered an IPBLOCK.

2026-03-03 03:51:07