Investigation Workspace

Entity: 2a09:bac5:952b:1cd2::2df:73 (Ip)

Entity Details
Type
Ip
ASN
AS13335 - Cloudflare, Inc.
Threat Intelligence
This IPv6 address exhibits highly malicious behavior, accessing numerous suspicious PHP paths indicative of web shell activity or exploitation attempts. All requests were flagged as threats and actively denied by WAF rules, suggesting an ongoing attack, likely from the same source as 104.28.246.113.
Linked Entities
Hostnames Targeted
Hostname Request Count
akamai.darcherif.fr 68
Paths Targeted (with Request Counts)
Path Request Count
_sec/cp_challenge/challenge 26
222.php 1
wp-admin/txets.php 1
php8.php 1
shlo.php 1
akcc.php 1
cord.php 1
file.php 1
133.php 1
abcd.php 1
dex.php 1
bolt.php 1
zwso.php 1
postnews.php 1
wp-editor.php 1
class-t.api.php 1
files.php 1
file2.php 1
blurbs.php 1
bless.php 1
style.php 1
gifclass.php 1
flower.php 1
chosen.php 1
witmm.php 1
ioxi-o.php 1
shelp.php 1
lufix1.php 1
wp-admin/admin-ajax.php 1
wp-includes/style.php 1
wp-admin/style.php 1
wp-content/postnews.php 1
wp-admin/postnews.php 1
wp-content/themes/style.php 1
wp-admin/zwso.php 1
wp-admin/css/index.php 1
wp-content/style.php 1
wp-content/txets.php 1
wp-content/index.php 1
ahax.php 1
wp-content/plugins/hellopress/wp_mna.php 1
wp-content/plugins/index.php 1
txets.php 1
🚫

Block

This IPv6 address exhibits highly malicious behavior, accessing numerous suspicious PHP paths indicative of web shell activity or exploitation attempts. All requests were flagged as threats and actively denied by WAF rules, suggesting an ongoing attack, likely from the same source as 104.28.246.113.

2026-03-01 17:12:07