Investigation Workspace

Entity: 3%7e2d3399e1bbf557f5 (Tls)

Entity Details
Type
Tls
Linked Entities
IPs Linked to TLS Fingerprint (2)
Hostnames Targeted
Hostname Request Count
www.darcherif.fr 349
Paths Targeted (with Hostname Counts)
Path Distinct Hostnames
.well-known/ans.php 1
wp-admin/css/index.php 1
wp-content/about.php 1
shell20211028.php 1
wp-content/wso.php 1
wp-admin/css/about.php 1
assets/css/403.php 1
wp-site-analytics.php 1
.well-known/lo.php 1
wp-content/index.php 1
.tmb/class_api.php 1
images/resumes/by.php 1
index/function.php 1
cgi-bin/xmrlpc.php 1
wp-admin/user/xmrlpc.php 1
wp-content/ccx/index.php 1
.well-known/acme-challenge/license.php 1
wp-includes/Requests/Text/admin.php 1
wp-content/plugins/linkpreview/db.php 1
wp-content/plugins/revslider/includes/external/page/index.php 1
wp-admin/css/colors/index.php 1
wp-admin/images/about.php 1
.well-known/acme-challenge/xmrlpc.php 1
wp-includes/js/tinymce/skins/lightgray/img/index.php 1
wp-content/gallery/about.php 1
wp-includes/block-patterns/about.php 1
wp-content/plugins/wp-apxupx.php 1
wp-content/languages/plugins/admin.php 1
.well-known/pki-validation/xmrlpc.php 1
wp-content/banners/about.php 1
.well-known/pki-validation/about.php 1
wp-includes/SimplePie/about.php 1
wp-includes/assets/wp-trackback.php 1
wp-content/themes/travelscape/json.php 1
wp-content/plugins/Cache/Cache.php 1
wp-content/plugins/core/include.php 1
wp-content/plugins/hellopress/wp_filemanager.php 1
wp-content/themes/about.php 1
.well-known/pki-validation/worksec.php 1
wp-content/plugins/seoplugins/mar.php 1
wp-content/themes/seotheme/db.php 1
wp-includes/ID3/about.php 1
wp-content/plugins/index.php 1
wp-includes/blocks/table/int/tmpl/index.php 1
wp-admin/css/colors/blue/about.php 1
wp-admin/network/xmrlpc.php 1
wp-includes/IXR/about.php 1
wp-includes/block-supports/abe.php 1
wp-content/plugins/contact-form-7/includes/js/jquery-ui/themes/smoothness/admin.php 1
wp-includes/Requests/about.php 1
🚫

Block

All requests associated with this TLS fingerprint were flagged by WAF, triggered critical LFI-ANOMALY and reputation-based deny rules, and accessed highly suspicious paths indicative of web shell or exploitation attempts.

2025-12-22 08:06:40