Investigation Workspace

Entity: 193.143.1.12 (Ip)

Entity Details
Type
Ip
ASN
AS198953 - Proton66 OOO
Threat Intelligence
The IP 193.143.1.12 from Russia (RU) shows an extremely high rate of detected threat requests (84 over 21 total), engaged in aggressive WordPress enumeration (targeting 'wlwmanifest.xml', 'xmlrpc.php', 'feed/'), triggered a critical 'BOT-BROWSER-IMPERSONATOR' alert, and hit a critical WAF deny rule ('IPBLOCK-BURST4-318403'). Its associated ASN AS198953 is already blocklisted for identical and persistent malicious activity from multiple other IPs, confirming a severe and coordinated threat.
Linked Entities
TLS Fingerprints (1)
Hostnames Targeted
Hostname Request Count
akamai.darcherif.fr 21
Paths Targeted (with Request Counts)
Path Request Count
_sec/cp_challenge/challenge 5
/ 1
feed/ 1
xmlrpc.php 1
wp/wp-includes/wlwmanifest.xml 1
site/wp-includes/wlwmanifest.xml 1
shop/wp-includes/wlwmanifest.xml 1
2020/wp-includes/wlwmanifest.xml 1
cms/wp-includes/wlwmanifest.xml 1
2021/wp-includes/wlwmanifest.xml 1
blog/wp-includes/wlwmanifest.xml 1
2019/wp-includes/wlwmanifest.xml 1
wp-includes/ID3/license.txt 1
wp1/wp-includes/wlwmanifest.xml 1
wordpress/wp-includes/wlwmanifest.xml 1
web/wp-includes/wlwmanifest.xml 1
test/wp-includes/wlwmanifest.xml 1
🚫

Block

The IP 193.143.1.12 from Russia (RU) shows an extremely high rate of detected threat requests (84 over 21 total), engaged in aggressive WordPress enumeration (targeting 'wlwmanifest.xml', 'xmlrpc.php', 'feed/'), triggered a critical 'BOT-BROWSER-IMPERSONATOR' alert, and hit a critical WAF deny rule ('IPBLOCK-BURST4-318403'). Its associated ASN AS198953 is already blocklisted for identical and persistent malicious activity from multiple other IPs, confirming a severe and coordinated threat.

2026-02-06 15:12:28