Investigation Workspace

Entity: 20.187.125.76 (Ip)

Entity Details
Type
Ip
ASN
AS8075 - Microsoft Corporation
Threat Intelligence
All requests (100%) were detected as threats, flagged by WAF, and denied by an IPBLOCK rule. Accessed suspicious PHP paths indicative of web shell or vulnerability scanning attempts.
Linked Entities
Hostnames Targeted
Hostname Request Count
akamai.darcherif.fr 131
Paths Targeted (with Request Counts)
Path Request Count
wp-content/plugins/hellopress/wp_filemanager.php 3
404.php 3
wp-content/uploads/index.php 2
rip.php 2
install.php 2
byp.php 2
z.php 2
403.php 2
inputs.php 2
wp-includes/admin.php 2
index/function.php 2
i.php 2
gdn.php 2
x.php 2
elp.php 2
56c53.php 1
wp-content/plugins/index.php 1
wp-admin/css/colors/blue/file.php 1
wp-content/admin.php 1
6kDPjgFTmvS.php 1
cgi-bin/index.php 1
55b76.php 1
wp-config-sample.php 1
wp-admin/maint/index.php 1
fimai.php 1
orouu.php 1
plugins/function.php 1
chosen.php 1
wp-admin/user-new.php 1
.well-known/wp-login.php 1
favicon.php 1
zqhfn.php 1
kalso.php 1
.well-known/index.php 1
a5e0a.php 1
admin/function.php 1
function/function.php 1
wp-admin/user/index.php 1
.well-known/acme-challenge/admin.php 1
wp-content/themes/twentytwenty/404.php 1
wp-includes/css/index.php 1
wp-includes/js/jcrop/Jcrop.php 1
wp-content/themes/seotheme/mar.php 1
wp-includes/Text/wp-login.php 1
wp-admin/css/index.php 1
wp-admin/css/wp-login.php 1
wp-admin/maint/wp-login.php 1
wp-content/languages/plugins/index.php 1
wp-includes/Requests/about.php 1
autoload_classmap.php 1
🚫

Block

All requests (100%) were detected as threats, flagged by WAF, and denied by an IPBLOCK rule. Accessed suspicious PHP paths indicative of web shell or vulnerability scanning attempts.

2026-02-21 12:55:37