Investigation Workspace

Entity: 20.78.169.245 (Ip)

Entity Details
Type
Ip
ASN
AS8075 - Microsoft Corporation
Threat Intelligence
Accessed multiple highly suspicious PHP files (e.g., moon.php, xx.php, wp_filemanager.php, wp-content/plugin.php) commonly associated with webshells, backdoor attempts, and WordPress exploitation.
Linked Entities
TLS Fingerprints (1)
Hostnames Targeted
Hostname Request Count
www.darcherif.fr 271
Paths Targeted (with Request Counts)
Path Request Count
wp-includes/Text.php 3
wp-content/plugin.php 3
wp-content/ 3
wp-includes/css/index.php 3
wp-includes/style-engine.php 3
wp-includes/theme-compat/wp-login.php 2
.well-known 2
wp-includes/images/smilies/ 2
wp-includes/header.php 2
assets/images/index.php 2
wp-content/languages/themes/num.php 2
wp-admin/class-db.php 2
wp-includes/images/wlw/ 2
wp-includes/SimplePie/Parse/about.php 2
wp-content/languages/ 2
options-reading.php 2
wp-content/content.php 2
wp-content/themes/ 2
wp-admin/admin-post.php 2
wp-admin/.srv_70b.php 2
wp-links.php/wp-content/plugins/wp-content/uploa 2
wp-includes/images/crystal/ 2
wp-content/languages.php 2
wp-includes/rest-api/fields/ 2
wp_filemanager.php 2
.well-known/home.php 2
wp-includes/Requests/library.php 2
wp-content/upgrade 2
wp-admin/js/my.php 2
wp-admin/.wp_be8.php 2
modules/mod_footer.php 2
wp-admin/link-add.php 2
wp-includes/blocks/post-author/ 2
wp-includes/wp-includes/ 2
wp-includes/fonts/admin.php 2
wp-includes/1.php 2
wp-includes/style-engine/ 2
wp-content/post.php 2
wp-includes/js/tinymce/skins/lightgray/ 2
.well-known/pki-validation/ 2
wp-includes/rest-api/index.php 2
wp-logs.php 2
wordpress/wp-admin/maint/ 2
item.php 2
wp-includes/images/crystal.php 2
wp-content/themes/6566deq1/classmap.php 2
xx.php 2
wp-content/plugins/all-in-one-wp-security-and-firewall/templates/wp.php 2
elp.php 2
wp-includes/PHPMailer/purna.php 2
🚫

Block

Accessed multiple highly suspicious PHP files (e.g., moon.php, xx.php, wp_filemanager.php, wp-content/plugin.php) commonly associated with webshells, backdoor attempts, and WordPress exploitation.

2026-03-03 17:26:03