Investigation Workspace

Entity: 20.89.40.149 (Ip)

Entity Details
Type
Ip
Threat Intelligence
Engaging in highly suspicious reconnaissance and potential exploitation attempts, indicated by requests to non-standard PHP files (e.g., 'ioxi-o.php', 'chosen.php', 'sf.php'), probe for 'cgi-bin/', and unusual plugin directory access ('wp-content/plugins/WordPressCore/'). Matches previous medium severity AI assessment.
Linked Entities
TLS Fingerprints (1)
Hostnames Targeted
Hostname Request Count
www.darcherif.fr 35
Paths Targeted (with Request Counts)
Path Request Count
sf.php 1
index/function.php 1
file.php 1
cgi-bin/ 1
rip.php 1
info.php 1
wp-admin/images/ 1
adminfuns.php 1
about.php 1
uploads/ 1
defaults.php 1
admin.php 1
wp-includes/ 1
wp-trackback.php 1
wk/index.php 1
goods.php 1
wp-good.php 1
.well-known/ 1
xmlrpc.php 1
chosen.php 1
ioxi-o.php 1
autoload_classmap.php 1
wp-content/admin.php 1
wp-includes/PHPMailer/ 1
wp-includes/images/ 1
classwithtostring.php 1
wp-includes/html-api/ 1
wp-content/plugins/index.php 1
wp-content/uploads/ 1
wp-content/themes/admin.php 1
wp-admin/css/colors/ectoplasm/ 1
wp-content/plugins/WordPressCore/ 1
wp-content/themes/index.php 1
wp-includes/Requests/src/Response/about.php 1
class-t.api.php 1
ℹ️

Watchlist

No detected threats or WAF flags, but some accessed paths ('wp-admin/css/', 'cgi-bin/', 'wp-content/plugins/') could indicate probing or reconnaissance attempts. Requires further monitoring.

2026-02-22 22:18:19
🚫

Block

Engaging in highly suspicious reconnaissance and potential exploitation attempts, indicated by requests to non-standard PHP files (e.g., 'ioxi-o.php', 'chosen.php', 'sf.php'), probe for 'cgi-bin/', and unusual plugin directory access ('wp-content/plugins/WordPressCore/'). Matches previous medium severity AI assessment.

2026-02-22 23:28:45