Investigation Workspace

Entity: 20.63.98.207 (Ip)

Entity Details
Type
Ip
ASN
AS8075 - Microsoft Corporation
Threat Intelligence
Attempted to access multiple suspicious .php files indicative of web shell activity, 100% of requests were flagged by WAF and explicitly denied by IPBLOCK rule.
Linked Entities
Hostnames Targeted
Hostname Request Count
akamai.darcherif.fr 36
Paths Targeted (with Request Counts)
Path Request Count
erty.php 2
fs.php 1
wp-access.php 1
ff1.php 1
wp5.php 1
god.php 1
un.php 1
ws60.php 1
fot.php 1
xa.php 1
cu.php 1
motu.php 1
kj.php 1
xqq.php 1
nw.php 1
ms.php 1
vx.php 1
06.php 1
X57.php 1
new4.php 1
666.php 1
66.php 1
sbhu.php 1
file59.php 1
grsiuk.php 1
ms-edit.php 1
seetox.php 1
wp-content/plugins/hellopress/wp_filemanager.php 1
wp-the.php 1
wp-blog.php 1
pouhg.php 1
plugins.php 1
myfile.php 1
wp-admin/css/bolt.php 1
work.php 1
🚫

Block

Attempted to access multiple suspicious .php files indicative of web shell activity, 100% of requests were flagged by WAF and explicitly denied by IPBLOCK rule.

2026-02-26 11:09:19