Investigation Workspace

Entity: 20.151.11.236 (Ip)

Entity Details
Type
Ip
ASN
AS8075 - Microsoft Corporation
Threat Intelligence
Highly malicious activity detected: 100% of requests flagged by WAF, multiple suspicious PHP files accessed indicative of web shell attempts or compromises, and hit an IPBLOCK security rule.
Linked Entities
Hostnames Targeted
Hostname Request Count
akamai.darcherif.fr 159
Paths Targeted (with Request Counts)
Path Request Count
av.php 2
wp-content/admin.php 2
sc.php 2
assets/css/index.php 2
wp9.php 2
path.php 2
ms-edit.php 2
txets.php 1
classwithtostring.php 1
w2025.php 1
adminfuns.php 1
BDKR28WP.php 1
class-t.api.php 1
bgymj.php 1
wp-act.php 1
inputs.php 1
rithin.php 1
Zjokrx.php 1
alfashell.php 1
plss3.php 1
ok356.php 1
database.php 1
wp-the.php 1
file59.php 1
wp-blog.php 1
gettest.php 1
bengi.php 1
akses.php 1
elabel.php 1
jocundly.php 1
miansha.php 1
maxro.php 1
goods.php 1
wp-content/plugins/index.php 1
fvvff.php 1
bless.php 1
gssdd.php 1
wp-content/ 1
wsvvs.php 1
pass2.php 1
style.php 1
wp-update.php 1
wp-michan.php 1
wp-content/plugins/hellopress/wp_filemanager.php 1
wp-includes/assets/index.php 1
wp-content/cong.php 1
wp-admin/images/wp-conflg.php 1
wp-includes/js/dist/ 1
%E8%93%9D%E7%99%BD%E9%93%BE%E6%8E%A5.php 1
about.php 1
🚫

Block

Highly malicious activity detected: 100% of requests flagged by WAF, multiple suspicious PHP files accessed indicative of web shell attempts or compromises, and hit an IPBLOCK security rule.

2026-03-05 11:45:39