Investigation Workspace

Entity: 35.245.125.98 (Ip)

Entity Details
Type
Ip
ASN
AS396982 - Google LLC
Threat Intelligence
Engaging in widespread WordPress vulnerability scanning attempts (wlwmanifest.xml), flagged by WAF on multiple paths, detected as a bot browser impersonator, and has already triggered an IPBLOCK deny rule. A disproportionately high number of threat requests were detected.
Linked Entities
TLS Fingerprints (1)
Hostnames Targeted
Hostname Request Count
akamai.darcherif.fr 31
Paths Targeted (with Request Counts)
Path Request Count
_sec/cp_challenge/challenge 10
/ 3
xmlrpc.php 1
wp/wp-includes/wlwmanifest.xml 1
website/wp-includes/wlwmanifest.xml 1
site/wp-includes/wlwmanifest.xml 1
shop/wp-includes/wlwmanifest.xml 1
news/wp-includes/wlwmanifest.xml 1
media/wp-includes/wlwmanifest.xml 1
sito/wp-includes/wlwmanifest.xml 1
cms/wp-includes/wlwmanifest.xml 1
wp-includes/wlwmanifest.xml 1
blog/wp-includes/wlwmanifest.xml 1
2019/wp-includes/wlwmanifest.xml 1
wp2/wp-includes/wlwmanifest.xml 1
wp1/wp-includes/wlwmanifest.xml 1
2018/wp-includes/wlwmanifest.xml 1
wordpress/wp-includes/wlwmanifest.xml 1
web/wp-includes/wlwmanifest.xml 1
test/wp-includes/wlwmanifest.xml 1
🚫

Block

Engaging in widespread WordPress vulnerability scanning attempts (wlwmanifest.xml), flagged by WAF on multiple paths, detected as a bot browser impersonator, and has already triggered an IPBLOCK deny rule. A disproportionately high number of threat requests were detected.

2026-02-20 17:01:21