Investigation Workspace

Entity: 3%7e2d3399e1bbf557f5 (Tls)

Entity Details
Type
Tls
Linked Entities
IPs Linked to TLS Fingerprint (2)
Hostnames Targeted
Hostname Request Count
www.darcherif.fr 349
Paths Targeted (with Request Counts)
Path Request Count
wp-admin/js/about.php 4
shell20211028.php 4
wp-login.php 4
.well-known/acme-challenge/cloud.php 4
themes.php 4
wp-content/shell20211028.php 4
wp-includes/ID3/about.php 4
wp-includes/Text/about.php 4
wp-2019.php 4
.well-known/admin.php 4
wp-content/about.php 2
wp-content/plugins/index.php 2
index/function.php 2
.tmb/class_api.php 2
cgi-bin/xmrlpc.php 2
wp-admin/user/xmrlpc.php 2
wp-content/ccx/index.php 2
.well-known/acme-challenge/license.php 2
wp-includes/Requests/Text/admin.php 2
wp-content/plugins/linkpreview/db.php 2
wp-content/plugins/revslider/includes/external/page/index.php 2
wp-admin/css/colors/index.php 2
wp-content/index.php 2
wp-admin/images/about.php 2
.well-known/acme-challenge/xmrlpc.php 2
wp-includes/js/tinymce/skins/lightgray/img/index.php 2
wp-content/gallery/about.php 2
wp-includes/block-patterns/about.php 2
wp-content/plugins/wp-apxupx.php 2
wp-content/languages/plugins/admin.php 2
.well-known/pki-validation/xmrlpc.php 2
wp-content/banners/about.php 2
.well-known/pki-validation/about.php 2
.well-known/lo.php 2
wp-includes/SimplePie/about.php 2
wp-site-analytics.php 2
wp-content/themes/travelscape/json.php 2
wp-content/plugins/Cache/Cache.php 2
wp-includes/assets/wp-trackback.php 2
assets/css/403.php 2
wp-content/plugins/hellopress/wp_filemanager.php 2
wp-admin/css/about.php 2
wp-content/wso.php 2
wp-content/themes/about.php 2
.well-known/pki-validation/worksec.php 2
wp-content/plugins/seoplugins/mar.php 2
wp-content/plugins/core/include.php 2
wp-includes/IXR/about.php 2
wp-admin/network/xmrlpc.php 2
images/resumes/by.php 2
🚫

Block

All requests associated with this TLS fingerprint were flagged by WAF, triggered critical LFI-ANOMALY and reputation-based deny rules, and accessed highly suspicious paths indicative of web shell or exploitation attempts.

2025-12-22 08:06:40