Investigation Workspace

Entity: 2a09:bac5:9529:3af::5e:1f (Ip)

Entity Details
Type
Ip
ASN
AS13335 - Cloudflare, Inc.
Threat Intelligence
All requests were flagged as threats, accessing suspicious PHP files in administrative and theme directories typical of web shell or backdoor activity, and triggered WAF deny rules. This indicates active, malicious exploitation attempts.
Linked Entities
Hostnames Targeted
Hostname Request Count
akamai.darcherif.fr 57
Paths Targeted (with Request Counts)
Path Request Count
_sec/cp_challenge/challenge 15
222.php 1
wp-admin/txets.php 1
php8.php 1
shlo.php 1
akcc.php 1
cord.php 1
file.php 1
133.php 1
abcd.php 1
dex.php 1
bolt.php 1
zwso.php 1
postnews.php 1
wp-editor.php 1
class-t.api.php 1
files.php 1
file2.php 1
blurbs.php 1
bless.php 1
style.php 1
gifclass.php 1
flower.php 1
chosen.php 1
witmm.php 1
ioxi-o.php 1
shelp.php 1
lufix1.php 1
wp-admin/admin-ajax.php 1
wp-includes/style.php 1
wp-admin/style.php 1
wp-content/postnews.php 1
wp-admin/postnews.php 1
wp-content/themes/style.php 1
wp-admin/zwso.php 1
wp-admin/css/index.php 1
wp-content/style.php 1
wp-content/txets.php 1
wp-content/index.php 1
ahax.php 1
wp-content/plugins/hellopress/wp_mna.php 1
wp-content/plugins/index.php 1
txets.php 1
🚫

Block

All requests were flagged as threats, accessing suspicious PHP files in administrative and theme directories typical of web shell or backdoor activity, and triggered WAF deny rules. This indicates active, malicious exploitation attempts.

2026-02-13 12:13:56