Investigation Workspace

Entity: 20.214.142.73 (Ip)

Entity Details
Type
Ip
ASN
AS8075 - Microsoft Corporation
Threat Intelligence
Attempted access to multiple highly suspicious paths indicative of webshells, cryptocurrency miners (xmr.php), and unauthorized file uploads like bolt.php and upload.php. This behavior strongly suggests compromise attempts or active malicious activity.
Linked Entities
TLS Fingerprints (1)
Hostnames Targeted
Hostname Request Count
www.darcherif.fr 102
Paths Targeted (with Request Counts)
Path Request Count
adminfuns.php 2
wp-admin/js/widgets/ 2
ioxi-o.php 2
wp-content/uploads/ 2
admin.php 2
wp-content/themes/admin.php 2
wp-content/uploads/admin.php 2
wp-content/themes/haha.php 1
.trash7206/index.php 1
wp-includes/Requests/src/Response/about.php 1
wp-content/upgrade/index.php 1
wp-includes/Requests/src/Cookie/ 1
wp-content/plugins/plugin/index.php 1
wp-admin/images/admin.php 1
wp-includes/js/dist/script-modules/block-library/search/about.php 1
wp-content/admin-header.php 1
wp-includes/customize/class-wp-customize-cropped-image-control.php 1
wp-content/plugins/classic-editor/wp-login.php 1
wp-includes/Requests/alfa-rex.php 1
wp-admin/css/colors/blue/index.php 1
wp-content/themes/about.php 1
wp-includes/Text/xwx1.php 1
wp-includes/assets/about.php 1
wp-includes/images/media/ 1
wp-content/plugins/admin.php 1
wp-includes/block-patterns/ 1
wp-includes/Text/index.php 1
wp-content/plugins/about.php 1
admin/controller/extension/extension/ 1
.well-known/logs233/index.php 1
wp-includes/Text/Diff/Renderer/ 1
wp-includes/style-engine/ 1
wp-content/plugins/yanierin/akc.php 1
css/classwithtostring.php 1
wp-content/plugins/Ultimate_VC_Addons/assets/alfa-rex.php7 1
wp-includes/images/smilies/about.php 1
wp-links-opml.php 1
index/function.php 1
wp-content/uploads/2025/ 1
wp-content/themes/theme/about.php 1
wp-content/index.php 1
wp-content/content.php 1
wp-admin/includes/ 1
wp-content/themes/ 1
wp-admin/css/bolt.php 1
wp-includes/js/crop/ 1
wp-includes/images/wp-login.php 1
wp-content/about.php 1
as.php 1
wp-includes/Requests/about.php 1
🚫

Block

Attempted access to multiple highly suspicious paths indicative of webshells, cryptocurrency miners (xmr.php), and unauthorized file uploads like bolt.php and upload.php. This behavior strongly suggests compromise attempts or active malicious activity.

2026-03-08 05:29:44