Investigation Workspace

Entity: 20.219.138.200 (Ip)

Entity Details
Type
Ip
ASN
AS8075 - Microsoft Corporation
Threat Intelligence
Accessing highly suspicious paths indicative of scanning, backdoor attempts, and vulnerability probing (e.g., info.php, db.php, upload.php, sx.php, htaccess.php, admin directories, wp-content/themes/haha.php).
Linked Entities
TLS Fingerprints (1)
Hostnames Targeted
Hostname Request Count
www.darcherif.fr 343
Paths Targeted (with Request Counts)
Path Request Count
wp-admin/js/widgets/ 7
adminfuns.php 7
admin.php 7
ioxi-o.php 7
wp-content/uploads/admin.php 7
wp-content/themes/admin.php 7
wp-content/uploads/ 7
wp-content/themes/haha.php 4
bolt.php 4
wp-admin/css/bolt.php 4
wp-includes/js/crop/ 4
wp-links-opml.php 4
as.php 4
wp-admin/ 4
wp-admin/js/ 4
wp-content/plugins/plugin/index.php 4
wp-admin/maint/ 4
wk/index.php 4
wp-includes/ 4
inputs.php 4
.well-known/logs233/index.php 4
wp-content/themes/theme/about.php 4
wp-act.php 4
update/da222.php 4
class-t.api.php 4
ms-edit.php 4
.trash7206/index.php 4
rip.php 4
xmr.php 4
fff.php 4
edit.php 4
upload.php 4
cgi-bin/ 4
ff1.php 4
about.php 4
lite.php 4
wp-content/themes/ 4
wp-includes/images/smilies/about.php 3
wp-content/plugins/yanierin/akc.php 3
wp-includes/Text/xwx1.php 3
wp-includes/images/wp-login.php 3
wp-includes/assets/about.php 3
wp-includes/images/media/ 3
wp-content/plugins/admin.php 3
wp-content/themes/about.php 3
wp-includes/block-patterns/ 3
wp-includes/Text/index.php 3
wp-includes/Text/Diff/Renderer/ 3
wp-includes/style-engine/ 3
cong.php 3
🚫

Block

Accessing highly suspicious paths indicative of scanning, backdoor attempts, and vulnerability probing (e.g., info.php, db.php, upload.php, sx.php, htaccess.php, admin directories, wp-content/themes/haha.php).

2026-03-10 01:15:57