Investigation Workspace

Entity: 20.211.123.94 (Ip)

Entity Details
Type
Ip
ASN
AS8075 - Microsoft Corporation
Threat Intelligence
Accessed highly suspicious paths indicative of web shell uploads, backdoors, or crypto mining attempts (xmr.php, upload.php, cgi-bin/).
Linked Entities
TLS Fingerprints (1)
Hostnames Targeted
Hostname Request Count
www.darcherif.fr 37
Paths Targeted (with Request Counts)
Path Request Count
as.php 1
wp-content/themes/ 1
ff1.php 1
xmr.php 1
fff.php 1
edit.php 1
cgi-bin/ 1
rip.php 1
bolt.php 1
adminfuns.php 1
lite.php 1
upload.php 1
ms-edit.php 1
class-t.api.php 1
update/da222.php 1
wp-act.php 1
admin.php 1
inputs.php 1
wp-includes/ 1
wk/index.php 1
wp-admin/maint/ 1
ioxi-o.php 1
wp-admin/js/ 1
wp-admin/ 1
.trash7206/index.php 1
wp-admin/js/widgets/ 1
wp-includes/js/crop/ 1
wp-admin/css/bolt.php 1
wp-content/themes/haha.php 1
wp-links-opml.php 1
wp-content/uploads/ 1
wp-content/themes/admin.php 1
wp-content/uploads/admin.php 1
wp-content/plugins/plugin/index.php 1
.well-known/logs233/index.php 1
wp-content/themes/theme/about.php 1
about.php 1
🚫

Block

Accessed highly suspicious paths indicative of web shell uploads, backdoors, or crypto mining attempts (xmr.php, upload.php, cgi-bin/).

2026-03-09 07:09:11