Investigation Workspace

Entity: 159.54.153.72 (Ip)

Entity Details
Type
Ip
ASN
AS31898 - Oracle Corporation
Threat Intelligence
Repeated access to 'wp-login.php', a common target for brute-force attacks, from a geographically distinct IP address. This indicates a high likelihood of malicious probing or an attempted credential stuffing attack.
Linked Entities
TLS Fingerprints (1)
Hostnames Targeted
Hostname Request Count
www.darcherif.fr 6
Paths Targeted (with Request Counts)
Path Request Count
wp-login.php 6
ℹ️

Watchlist

Access to 'wp-login.php' often indicates reconnaissance or brute-force attempts. Although no direct threats were detected and request volume is low, continued monitoring is warranted for potential unauthorized access attempts.

2026-03-05 11:05:27
ℹ️

Watchlist

Accessed 'wp-login.php', a common attack target, but no direct threats detected by WAF or security rules in this interaction. AI confidence score is medium, indicating continued suspicion.

2026-03-05 11:45:39
ℹ️

Watchlist

Entity previously flagged with medium AI severity and moderate confidence (0.7), but no recent malicious activity or requests detected in the current observation window. Requires continued monitoring.

2026-03-05 12:35:54
ℹ️

Watchlist

Entity was previously added to the watchlist with medium AI confidence; no new suspicious activity detected in the current context to warrant removal, continued monitoring is advised.

2026-03-05 17:06:38
ℹ️

Ignore

Despite being on the watchlist with a previous AI confidence score, the entity shows no current activity (0 total requests, 0 detected threat requests), no security rule hits, and no other indicators of compromise in the provided context.

2026-03-05 22:07:31
🚫

Block

Repeated access to 'wp-login.php', a common target for brute-force attacks, from a geographically distinct IP address. This indicates a high likelihood of malicious probing or an attempted credential stuffing attack.

2026-03-05 22:17:38